DETAILED ACTION
The action is responsive to the Application filed on 11/04/2024. Claims 1-20 are pending in the case. Claims 1, 11 and 20 are independent claims.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. As to claims 1, 10 and 20, the claims recites a method, apparatus and computer-readable medium for extracting event data from network logs that is generated by one or more entities, detecting a relationship between events in the event data, generating a prompt based on the relation to input into a language model and providing the prompt to the language model to generate a summary of events in the network. The limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events, as drafted, is a process that under its broadest reasonable interpretation, covers performance of the limitation as a manual extracting event data from logs, determining a relationship between the event data, determining a question / prompt based on the relationship and writing a summarization answer / output to the question / prompt but for the recitation of generic computer components. That is, other than reciting “a device”, “a processor”, “ a memory” and “network interfaces” (as recited in the method claim 1, apparatus claim 11 and computer-readable medium claim 20), nothing the claims elements precludes the step from practically being performed by a user manually extracting event data from logs to detect a relationship and generate a prompt / question and then determining and writing summarization answers / output to the prompt / question. For example, but for the “device”, “processor”, “memory” and “network interfaces” language, the extracting, detecting, generating and providing in the context of the claims encompasses the user manually extracting event data from logs to determine a relationship and providing and writing down a prompt / question based on the subset of content and some context. Similarly, the step of providing summarization answer output, is a process that, under its broadest reasonable interpretation, covers performance of the user manually answering the question or instruction that the prompt posits and writing the summarization output down. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claims recite an abstract idea.
This judicial exception is not integrated into a practical application. In particularly, the claims only recite two additional elements – using a device, processor and memory to perform the extracting, detecting, generating and providing steps. The devices, processors and memories in these steps are recited at a high-level of generality (i.e., as a generic processors and memories performing a generic computer function of extracting event data from logs, determining a relationship, generating a prompt and providing output) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using processors and memories to perform the steps of extracting, detecting, generating and providing amounts to no more than mere instruction to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claims are not patent eligible.
Claims 2 and 12 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of the logs ”compris[ing] unstructured text” does not integrate the judicial exception into a practical application. The limitations of the logs ”compris[ing] unstructured text” merely represents instructions to apply the judicial exceptions on a computer and the user manually extracting events from a different type of log available on the computer. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 2 and 12 are directed to an abstract idea.
Claims 3 and 13 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of a language model being a large language model does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions using a different kind of language model. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 3 and 13 are directed to an abstract idea.
Claims 4 and 14 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of “inserting text from one or more reference documents regarding computer networking into the prompt” does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually considering reference material about computer networking when determining a summarization answer to the prompt. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 4 and 14 are directed to an abstract idea.
Claims 5 and 15 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of providing the summary for review does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually reviewing their derived summarization answer. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 5 and 15 are directed to an abstract idea.
Claims 6 and 16 depends from claims 5 and 15, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of adjusting how the device generates event summaries based on feedback of a summary does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually reviewing their derived summarization answer and learning how to generate more suitable event summaries in the future. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 6 and 16 are directed to an abstract idea.
Claims 7 and 17 depends from claims 5 and 15, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of providing a generated plot or hyperlink in the summary does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually inserting a plot or a reference to a book or document in the manually derived summarization answer. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 7 and 17 are directed to an abstract idea.
Claims 8 and 18 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of determining a relationship between events by considering periodicity or a common location does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually considering periodicity and a common location in order to determine a relationship between events in a log. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 8 and 18 are directed to an abstract idea.
Claims 9 and 19 depends from claims 1 and 11, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of removing duplicate, overlapping or unnecessary data from logs does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually disregarding duplicate, overlapping or unnecessary data from the logs. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claims 9 and 19 are directed to an abstract idea.
Claim 10 depends from claim 1, and thus recites a similar limitation of extracting event data, detecting a relationship between events in the event data, generating a prompt based on the relationship and using the prompt to generate a summary of the events via a language model. For the reasons discussed for claim 1, this limitation recites an abstract idea. The steps of logs being generated by routers, switches or access points does not integrate the judicial exception into a practical application. The limitations merely represent instructions to apply the judicial exceptions on a computer and the user manually collecting and considering log data from routers, switches and access points. Thus, the additional elements do not integrate the recited judicial exception into a practical application and claim 10 is directed to an abstract idea.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-5, 8-15 and 18-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Kasap (US 20240414048 A1).
As to claim 1, Kasap discloses a method, comprising:
extracting, by a device, event data from logs generated by one or more entities in a computer network that are indicative of events that occurred in the computer network ("In receive system log operation 476, at least a part of the system log is retrieved. In aspects, the system log may include at least a part of one or more of various types of system logs in the 5G/6G MEC and core network system. Examples of the system log may include RAN log, core network log, and cloud log. (See, the system log 166a including the RAN log database 166b, the core network log database 166c, and the cloud log database 166d as shown in FIG. 1)," Kasap paragraph 0094; "In aspects, the root cause determiner 158 retrieves event data from the system log 166a, which indicate a problem that has occurred in the system 100," Kasap paragraph 0038);
detecting, by the device and using the event data, a relationship between the events that occurred in the computer network ("In some aspects, the knowledge base server may select a particular part of the system log for determining a root cause of a problem that appears in the particular part of the system log," Kasap paragraph 0094, getting parts of the log related to the root cause of a problem);
generating, by the device and based on the relationship, a prompt for input to a language model ("In generate question operation 480, a question is generated. The question may describe a request for identifying a root cause for a problem as indicated in the retrieved system log. See, the question 308 as shown in FIG. 3A," Kasap paragraph 0096; "In generate prompt operation 482, a prompt for identifying a root cause is generated. The prompt is generated by concatenating the grounding information as a prefix and the question in a natural language text. The method 400D that generates the prompt for a root cause analysis ends with the generate prompt operation 482," Kasap paragraph 0097); and
providing, by the device, the prompt to the language model, to generate a summary of the events that occurred in the computer network ("The question 308 indicates a query to the generative model to generate the answer 320. For example, the question 308 indicates 'here is a log of problem that I am facing with. Using the system log and the grounding information, what would be a root cause of the problem?' In aspects, the question may be in a natural language," Kasap paragraph 0053).
As to claim 2, Kasap further discloses the method as in claim 1, wherein the logs comprise unstructured text ("In aspects, event data includes a timestamp associated with an event, a type of the event (e.g., a status of a server and/or an application, a warning, an error, and the like), an identifier associated with program instruction (e.g., a code) as fingerprint data, descriptions of the event, and the like. The event data in the system log 166a may be retrievable by knowledge base server 152 for subsequent operations of a root cause analysis of an event," Kasap paragraph 0036, descriptions of the event are in the log (i.e., unstructured text)).
As to claim 3, Kasap further discloses the method as in claim 1, wherein the language model is a large language model (LLM) ("In aspects, some embodiments described herein use a generative model to automatically... determine a root cause for a problem or an event that has been recorded in a system log. In some aspects, the generative model is pre-trained using a limited type or amount of information. That is, the use of generative models (e.g., a generative language model, a large language model, a generative transformer model, and the like)," Kasap paragraph 0029).
As to claim 4, Kasap further discloses the method as in claim 1, wherein generating the prompt comprises:
inserting text from one or more reference documents regarding computer networking into the prompt ("In retrieve exception handler list operation 472, the exception handler function table is retrieved by the knowledge server. In aspects, the exception handler function table represents a natural language list that describe exception handlers and identifiers (e.g., fingerprint data) being used by codes of program instructions in at least a part of the 5G/6G MEC and core network system," Kasap paragraph 0092; "For example, an entry in the exception handler function table 300C indicates 'MEC-0001' as the function identifier 350 (e.g., fingerprint data), 'Exception_MemoryOverflow' as the function name 352, and 'Exception_MemoryOverflow function processes a memory overflow exception in an edge server.' In aspects, the exception handler function table 300C includes a list of exception handler functions that need to be in codes for program instructions. The knowledge base server (e.g., the knowledge base server 210 as shown in FIG. 2) maintains the exception handler function table (e.g., the exception handler function table 216 as shown in FIG. 2). In some aspects, the exception handler function table may include information associated with other types of functions in addition to the exception handler functions," Kasap paragraph 0061; "In generate grounding information part operation 478, grounding information is generated as a prefix for a prompt. In aspects, the grounding information includes the retrieved exception handler function table, the retrieved hierarchical function graph data, and the retrieved system log. The grounding information effectively restricts a root cause analysis as performed by the generative model to output its result within a domain as described by the grounding information," Kasap paragraph 0095; "In generate prompt operation 482, a prompt for identifying a root cause is generated. The prompt is generated by concatenating the grounding information as a prefix and the question in a natural language text. The method 400D that generates the prompt for a root cause analysis ends with the generate prompt operation 482," Kasap paragraph 0097, getting the exception handler function table which is information about different exception handlers and identifiers that are associated with a network (i.e., a reference document) and inserting the exception handler function table into the prompt).
As to claim 5, Kasap further discloses the method as in claim 1, further comprising:
providing the summary to a user interface for review ("displaying the description of the root cause," Kasap paragraph 0138).
As to claim 8, Kasap further discloses the method as in claim 1, wherein the device detects the relationship between the events based on at least one of: their periodicity or a common location in the computer network ("In some aspects, the knowledge base server may select a particular part of the system log for determining a root cause of a problem that appears in the particular part of the system log," Kasap paragraph 0094, getting parts of the log related to the root cause of a problem).
As to claim 9, Kasap further discloses the method as in claim 1, wherein extracting the event data from the logs generated by the one or more entities in the computer network comprises:
removing duplicate entries, overlapping attributes, or unnecessary fields from the logs ("In some aspects, the knowledge base server may select a particular part of the system log for determining a root cause of a problem that appears in the particular part of the system log," Kasap paragraph 0094, getting parts of the log related to the root cause of a problem (i.e., removing unnecessary parts of the log)).
As to claim 10, Kasap further discloses the method as in claim 1, wherein the one or more entities in the computer network comprise at least one of: a router, a switch, or an access point ("As illustrated, the on-premises edge 110 is a datacenter that is part of a cloud RAN, which includes service application 116a. In aspects, the on-premises edge 110 enables cloud integration with a radio access network (RAN). The on-premises edge 110 includes a switch 114 and edge servers 112," Kasap paragraph 0031; "In aspects, system log 166a receives event data from various parts of the system 100, including one or more service applications (e.g., the service application 116a, 116b, and 116c) and other executables and devices in the cell tower 102, the on-premises edge 110, the network edge 120, and the cloud 130. The system log 166a stores the event data," Kasap paragraph 0035).
As to claim 11, Kasap discloses an apparatus, comprising:
one or more network interfaces (“The computing device 600 may include one or more communication connections 616 allowing communications with other computing devices 650,” Kasap paragraph 0119);
a processor coupled to the one or more network interfaces and configured to execute one or more processes (“The method 400D can be executed as a set of computer-executable instructions executed by a computer system and encoded or stored on a computer readable medium. Further, the method 400D can be performed by gates or circuits associated with a processor, an ASIC, an FPGA, a SOC or other hardware device,” Kasap paragraph 0090); and
a memory configured to store a process that is executable by the processor, the process when executed configured (“The method 400D can be executed as a set of computer-executable instructions executed by a computer system and encoded or stored on a computer readable medium. Further, the method 400D can be performed by gates or circuits associated with a processor, an ASIC, an FPGA, a SOC or other hardware device,” Kasap paragraph 0090; “In another aspect, a system for determining a root cause of an event using a pre-trained generative model is provided. The system comprises a processor, and a memory storing computer-executable instructions that when executed by the processor cause the system to execute operations comprising retrieving a set of data including event data of a system log,” Kasap paragraph 0138) to:
extract event data from logs generated by one or more entities in a computer network that are indicative of events that occurred in the computer network ("In receive system log operation 476, at least a part of the system log is retrieved. In aspects, the system log may include at least a part of one or more of various types of system logs in the 5G/6G MEC and core network system. Examples of the system log may include RAN log, core network log, and cloud log. (See, the system log 166a including the RAN log database 166b, the core network log database 166c, and the cloud log database 166d as shown in FIG. 1)," Kasap paragraph 0094; "In aspects, the root cause determiner 158 retrieves event data from the system log 166a, which indicate a problem that has occurred in the system 100," Kasap paragraph 0038);
detect, using the event data, a relationship between the events that occurred in the computer network ("In some aspects, the knowledge base server may select a particular part of the system log for determining a root cause of a problem that appears in the particular part of the system log," Kasap paragraph 0094, getting parts of the log related to the root cause of a problem);
generate, based on the relationship, a prompt for input to a language model ("In generate question operation 480, a question is generated. The question may describe a request for identifying a root cause for a problem as indicated in the retrieved system log. See, the question 308 as shown in FIG. 3A," Kasap paragraph 0096; "In generate prompt operation 482, a prompt for identifying a root cause is generated. The prompt is generated by concatenating the grounding information as a prefix and the question in a natural language text. The method 400D that generates the prompt for a root cause analysis ends with the generate prompt operation 482," Kasap paragraph 0097); and
provide the prompt to the language model, to generate a summary of the events that occurred in the computer network ("The question 308 indicates a query to the generative model to generate the answer 320. For example, the question 308 indicates 'here is a log of problem that I am facing with. Using the system log and the grounding information, what would be a root cause of the problem?' In aspects, the question may be in a natural language," Kasap paragraph 0053).
As to claim 12, it is substantially similar to claim 2 and is therefore rejected using the same rationale as above.
As to claim 13, it is substantially similar to claim 3 and is therefore rejected using the same rationale as above.
As to claim 14, it is substantially similar to claim 4 and is therefore rejected using the same rationale as above.
As to claim 15, it is substantially similar to claim 5 and is therefore rejected using the same rationale as above.
As to claim 18, it is substantially similar to claim 8 and is therefore rejected using the same rationale as above.
As to claim 19, it is substantially similar to claim 9 and is therefore rejected using the same rationale as above.
As to claim 20, Kasap discloses a tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process (“The method 400D can be executed as a set of computer-executable instructions executed by a computer system and encoded or stored on a computer readable medium. Further, the method 400D can be performed by gates or circuits associated with a processor, an ASIC, an FPGA, a SOC or other hardware device,” Kasap paragraph 0090) comprising:
extracting, by the device, event data from logs generated by one or more entities in a computer network that are indicative of events that occurred in the computer network ("In receive system log operation 476, at least a part of the system log is retrieved. In aspects, the system log may include at least a part of one or more of various types of system logs in the 5G/6G MEC and core network system. Examples of the system log may include RAN log, core network log, and cloud log. (See, the system log 166a including the RAN log database 166b, the core network log database 166c, and the cloud log database 166d as shown in FIG. 1)," Kasap paragraph 0094; "In aspects, the root cause determiner 158 retrieves event data from the system log 166a, which indicate a problem that has occurred in the system 100," Kasap paragraph 0038);
detecting, by the device and using the event data, a relationship between the events that occurred in the computer network ("In some aspects, the knowledge base server may select a particular part of the system log for determining a root cause of a problem that appears in the particular part of the system log," Kasap paragraph 0094, getting parts of the log related to the root cause of a problem);
generating, by the device and based on the relationship, a prompt for input to a language model ("In generate question operation 480, a question is generated. The question may describe a request for identifying a root cause for a problem as indicated in the retrieved system log. See, the question 308 as shown in FIG. 3A," Kasap paragraph 0096; "In generate prompt operation 482, a prompt for identifying a root cause is generated. The prompt is generated by concatenating the grounding information as a prefix and the question in a natural language text. The method 400D that generates the prompt for a root cause analysis ends with the generate prompt operation 482," Kasap paragraph 0097); and
providing, by the device, the prompt to the language model, to generate a summary of the events that occurred in the computer network ("The question 308 indicates a query to the generative model to generate the answer 320. For example, the question 308 indicates 'here is a log of problem that I am facing with. Using the system log and the grounding information, what would be a root cause of the problem?' In aspects, the question may be in a natural language," Kasap paragraph 0053).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 6 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Kasap (US 20240414048 A1) in view of Tellez et al. (US 11843622 B1, hereinafter Tellez).
As to claim 6, Kasap discloses the method as in claim 5, however Kasap does not appear to explicitly disclose a limitation further comprising:
adjusting how the device generates event summaries using the language model based on feedback for the summary from the user interface.
Tellez teaches a limitation further comprising:
adjusting how the device generates event summaries using the language model based on feedback for the summary from the user interface ("For example, a user can configure DNS log data 1626 or event data 1632 to be sent to a security ML service 1606 running in a cloud provider network 1602 or elsewhere, where the security ML service 1606 can then use ML models 1614 to perform the domain classification processes described herein. A security ML service 1606 may further train custom models for individual users or accounts based on user feedback to results obtained from a base ML model, as described elsewhere herein, and store such local ML models using storage resources of the cloud provider network 1602," Tellez column 194 lines 11-21).
Accordingly it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Kasap to adjust output of the language model based on feedback as taught by Tellez. One would have been motivated to make such a combination so that the user could have control to improve the output of the language model in situations where the output is considered poor or unsuitable by the user thus increasing the utility of the generated answer output.
As to claim 16, it is substantially similar to claim 6 and is therefore rejected using the same rationale as above.
Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Kasap (US 20240414048 A1) in view of Salji (US 20210273959 A1).
As to claim 7, Kasap discloses the method as in claim 5, however Kasap does not appear to explicitly disclose a limitation further comprising:
providing a generated plot or a hyperlink in conjunction with the summary of events to the user interface.
Salji teaches a limitation further comprising:
providing a generated plot or a hyperlink in conjunction with the summary of events to the user interface ("The analyzer module can reference machine learning models that are trained on the normal behaviour of email activity and user activity associated with at least the email system, where the analyzer module cooperates with the assessment module to determine a threat risk parameter that factors in ‘the likelihood that a chain of one or more unusual behaviours of the email activity and user activity under analysis fall outside of derived normal benign behaviour;’ and thus, are likely malicious behaviour," Salji paragraph 0124; "In an example, a behavioural pattern analysis of what are the unusual behaviours of the network/system/device/user under analysis by the machine learning models may be as follows. The cyber security appliance uses unusual behaviour deviating from the normal behaviour and then builds a chain of unusual behaviour and the causal links between the chain of unusual behaviour to detect cyber threats (for example see FIG. 4). FIG. 4 illustrates a block diagram of an embodiment of an example chain of unusual behaviour for the email(s) deviating from a normal pattern of life in connection with the rest of the network under analysis. The unusual pattern can be determined by filtering out what activities/events/alerts that fall within the window of what is the normal pattern of life for that network/system/device/user under analysis, and then the pattern of the behaviour of the activities/events/alerts that are left, after the filtering, can be analyzed to determine whether that pattern is indicative of a behaviour of a malicious actor—human, program, or other threat," Salji paragraph 0125; Salji Figure 4 displayed Graph).
Accordingly it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Kasap to allow the language model to output plots as part of the answer as taught by Salji. One would have been motivated to make such a combination so that more types of output could be supported by the finished product thus enhancing the utility of the generated output.
As to claim 17, it is substantially similar to claim 7 and is therefore rejected using the same rationale as above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
US 20190205182 A1 to Sivasubramanian et al. discloses a unified monitoring interface where network logs are analyzed to generate insight output including charts, graphs and visualizations;
US 20230370334 A1 to Mannengal et al. discloses networked device discovery and management where network logs are analyzed to output answers about the logs and giving feedback on the answer to retrain a machine learning model; and
US 20240356945 A1 to Kumar et al. discloses method, apparatus, system, and non-transitory computer readable medium for detecting anomalous user access behaviors where machine learning models analyze network events to determine anomalies.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL SAMWEL whose telephone number is (313) 446-6549. The examiner can normally be reached Monday through Thursday 8:00-6:00 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kieu Vu can be reached at (571) 272-4057. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DANIEL SAMWEL/ Primary Examiner, Art Unit 2171