DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 05/28/2026 has been fully considered and entered into record. Claims 1-20 remain pending in the application. Claims 1, 8, 9, 15, 19 and 20 have been amended.
Response to Arguments
Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the present rejection constitutes a new ground of rejection. The present rejection no longer relies upon Govindan and Jun for the disputed limitations. Instead, the rejection relies upon Crabtree, in view of Crabtree et al. (US 20220377093 A1), and further in view of GOVINDAN and JUN for teachings set forth in the rejection.
In particular, the present rejection relies upon Crabtree for teachings directed to constructing user profiles, device profiles, and resource profiles for the organizational users, organizational devices, and organizational resources, respectively, wherein the user profiles include at least access patterns and roles within the organization, and wherein the user profiles, device profiles, and resource profiles are constructed based on analyzing historical behavior patterns, which form the basis of the amended claim limitations. Accordingly, Applicant’s arguments directed to the prior combination of references are not applicable to, and therefore do not persuade against, the present rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 5, 8, 9, 15, 19 and 20 are rejected under 35 U.S.C. §103 as being unpatentable over Crabtree et al.(US 20220377093 A1) [hereinafter "Crabtree"] in view of et al. (WO 2020016906 A1 ) [hereinafter "GOVINDAN"] and in view of JUN et al. (CN118626287 A) [hereinafter “JUN”].
As per claim 1, Crabtree discloses a computerized method for detecting and handling security threats in an organizational network of an organization,(Crabtree, [0120]” This method 800 for behavioral analytics enables proactive and high-speed reactive defense capabilities against a variety of cyberattack threats,”) the computerized method comprising: (a) collecting event data that pertain to users within the organization ("organizational users"), devices within the organization ("organizational devices"), and resources within the organization ("organizational resources"),(Crabtree, [0122]” state observation service 140 may receive data from a variety of connected systems 1001 such as (for example, including but not limited to) servers, domains, databases, or user directories. ”) the organizational users, organizational device, and organizational resources being included in the organizational network; (Crabtree, [0126]” … correlate events with actual infrastructure elements, such as servers or accounts.”) (b) constructing user profiles, device profiles, and resource profiles for the organizational users, (Crabtree, [0095]” A human activity monitoring engine 1801 may be used to monitor user behavior”) organizational devices, (Crabtree, [0095]” a device activity monitoring engine 1803 may be used to monitor device-based behavior,”) and organizational resources, (Crabtree, [0095]” a system activity monitoring engine 1802 may be used to monitor activity in any of a number of software or network systems, and an organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization.”) respectively, wherein the user profiles include at least access patterns (Crabtree, [0081], [0096]” These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology; gateway firewall programming; internal firewall configuration; directory services protocols and configuration; and permissions profiles for both users and for access to sensitive information, … All captured data are then analyzed to predict the normal usage patterns of network” and “engine 1801 may collect data from a variety of sources 1901, including (but not limited to) communications via various channels (such as email, web-based chat, text messages, or phone calls), access logs for accounts or services, software installation or utilization statistics, work times or locations, or account login and logout records…These behavior data points may then be analyzed”) and roles within the organization, (Crabtree, [0083], [0080]” Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207” and “ the system issues action-focused alert information to all predesignated parties specifically tailored to their roles…”) and wherein the user profiles, device profiles, and resource profiles are constructed based on analyzing historical behavior patterns; (Crabtree, [0096], [0095]” These behavior data points may then be analyzed by comparing observed behavioral data 1903 against expected behavior 1902 according to an established behavioral model developed using statistical and machine learning techniques” and “large amounts of data from numerous sources may be analyzed and used to form behavior profiles, which may then be compared to actual observed behavior.”) (c) constructing Organizational Context information that pertains to organizational users, (Crabtree, [0095]” A human activity monitoring engine 1801…organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization”) organizational devices,(Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. As shown, a customer site 2410 may connect an internal directory server 2411 to system 1800, providing access to internal users, groups, roles, devices, servers, systems, and other information”) and organizational resources(Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) wherein the Organizational Context information includes user roles in the organization, (Crabtree, [0080]” the system issues action-focused alert information to all predesignated parties specifically tailored to their roles”) device types, (Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) and data classifications; (Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. …..providing access to internal users, groups, roles, devices, servers, systems, and other information”) .
Crabtree does not explicitly disclose (d) constructing a time-series of events, enriched with said Organizational Context information; (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, JUN in the same field of endeavor discloses (d) constructing a time-series of events, enriched with said Organizational Context information; ([JUN,[0018], [0019], [0020]]'' The log data is clustered to obtain clustered log data, and the clustered log data is time-series converted to obtain time-series converted log data.''...'' The call chain data is segmented based on a preset sliding window to obtain call tracking data for each window, and the call tracking data for each window is time-series calculated to obtain time-series call chain data.''...’ Based on the normalized metric data, the time-series-processed log data, and the time-series-processed call chain data, a time-series-processed Pod monitoring data sample is formed''. The Examiner interprets this disclosure as corresponding to the claimed constructing a time-series of events, enriched with said Organizational Context information, because JUN expressly constructs time-series data and combines multiple contextual enterprise data types into a unified· processed sample.).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN. One of ordinary skill in the art would have been motivated to do so because incorporating JUN’s time-series event data analysis into Crabtree security monitoring system would have improved anomaly detection accuracy and automated alert generation in Crabtree's enterprise detection system.
The combination of Crabtree and JUN fails to disclose (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, GOVINDAN in the same field of endeavor (e) analyzing said time-series of events( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” The sorted one or more events/ traced path…determined from the received information is compared with a behaviour pattern associated with the user”)using a Machine Learning process( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” a deviation…more events may be determined using Artificial Intelligence (AI) techniques like unsupervised machine learning algorithm”) that detects an anomalous event, ( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Further, an intrusion may be detected based on the determined deviation using a supervised machine learning algorithm”) and automatically generating an alert message( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Furthermore, an alert may be sent to the analyst (110) indicating the intrusion and a set of possible inferences for the detected intrusion”) pertaining to and describing said anomalous event. (GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” indicating the intrusion and a set of possible inferences for the detected intrusion”).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN to further include (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event as suggested by GOVINDAN. One of ordinary skill in the art would have been motivated to do so because incorporating machine-learning-based behavioral analysis into Crabtree system enhanced by JUN’s time-series event construction would have predictably enabled automated analysis of enterprise time-series event data to detect anomalous behavior and automatically generate descriptive alert messages, thereby improving the accuracy, efficiency, and responsiveness of organizational security monitoring using known machine-learning techniques for their intended purpose.
As per claim 5, the references as combined above disclose the computerized method of The computerized method of claim 1. wherein step (e) comprises: (e1) detecting an anomalous data-point in said time-series of events; ([GOVINDAN, [SUMMARY]] "Furthermore, the method includes determining a deviation between the [sorted one or more events] and a behaviour pattern comprising, events routinely followed by the user. Finally, the method includes [detecting an intrusion] based on the determined deviation, wherein an alert is generated upon detecting the intrusion") (e2) based on Organizational Context information, determining that said anomalous data-point more probably corresponds to a security threat; ([GOVINDAN, DETAILED DESCRIPTION OF THE[AltContent: textbox (')]DISCLOSURE]”For example, the user login at 6:00AM along with the login of one or more peer employees of the enterprise between 5:45 AM and 6: 15 AM, may not be detected as the intrusion. On the contrary, tire user alone logging in at 6:00 AM may be detected as the intrusion”) and therefore, generating and sending an alert message that pertains to said anomalous data-point.
As per claim 8, the references as combined above disclose the computerized method of claim 1. GOVINDAN further discloses the computerized method comprising: dynamically scoring a risk of detected anomalies, by performing:
detecting an anomaly in event data in said time-series of events; ([GOVINDAN, [SUMMARY]''] Furthermore, the method includes determining a deviation between the sorted one or more events and a behaviour pattern comprising, events routinely followed by the user. Finally, the method includes detecting an intrusion based on the determined deviation, wherein an alert is generated upon detecting the intrusion'')
applying a Machine Learning model ([GOVINDAN, claim 11]” determining one or more parameters indicative of a malicious activity by applying a supervised learning based classification
algorithm on the one or more events in the received information'') to assign a risk score based on Organizational Context information that relates to said anomaly.
As per claim 9, the references as combined above disclose the computerized method of claim 1. Crabtree further discloses the computerized method comprising: performing a profile-based anomaly detection of anomalies based on entity profiles, by:
comparing incoming event data against the user profiles, device profiles, and resource generated profiles;
identifying anomalies where the event deviates from typical behavior;
generating one or more alerts based on estimated severity of the anomaly. (Crabtree, [0019]” monitors network events and compares them against predicted behavior models to identify anomalies, assigns risk scores to the anomalies, and generates reports and alerts based on the risk scoring.”).
As per claim 15, the references as combined above disclose the computerized method of claim 1. Crabtree further discloses the computerized method comprising: detecting insider threats in said organizational network, by performing:
comparing real-time user behavior against established user profiles;(Crabtree, [0019]” monitors network events and compares them against predicted behavior models to identify anomalies, assigns risk scores to the anomalies, and generates reports and alerts based on the risk scoring.”)
detecting deviations that are indicative of insider threats; (Crabtree, [0099] [0019]” These behavior data points may then be analyzed by comparing observed behavioral data 2203 against expected behavior 2202 according to an established behavioral model developed using statistical and machine learning techniques… anomaly detector 2204 may then be used to identify mismatches between anticipated and actual behavior, which may then be provided as output to risk analysis and scoring engine 1810” and ”… identify anomalies, assigns risk scores to the anomalies”)
generating alerts upon detection of abnormal access (Crabtree, [0019]” monitors network events and compares them against predicted behavior models to identify anomalies, assigns risk scores to the anomalies, and generates reports and alerts based on the risk scoring.”).
to sensitive data. (Crabtree, [0102]” malicious actor 2610/2620 can take to access to organizational devices 2601-2605 or sensitive data 2606”).
As per claim 19, Crabtree discloses a system comprising: one or more hardware processors, that are configured to execute code, and that are operably associated with one or more memory units; (Crabtree, [0020]” a computing device comprising a processor and a memory; an activity monitoring engine comprising a first plurality of programming instructions stored in the memory and operating on the processor,”)
wherein the one or more hardware processors are configured to perform a computerized process for detecting and handling security threats in an organizational network of an organization, (Crabtree, [0120]” This method 800 for behavioral analytics enables proactive and high-speed reactive defense capabilities against a variety of cyberattack threats,”) the computerized process comprising:
(a) collecting event data that pertain to users within the organization ("organizational users"), devices within the organization ("organizational devices", and resources within the organization ("organizational resources")(Crabtree, [0122]” state observation service 140 may receive data from a variety of connected systems 1001 such as (for example, including but not limited to) servers, domains, databases, or user directories. ”) , the organizational users, organizational device, and organizational resources being included in the organizational network; (Crabtree, [0126]” … correlate events with actual infrastructure elements, such as servers or accounts.”)
(b) constructing user profiles, device profiles, and resource profiles for the organizational users, Crabtree, [0095]” A human activity monitoring engine 1801 may be used to monitor user behavior”) organizational devices, (Crabtree, [0095]” a device activity monitoring engine 1803 may be used to monitor device-based behavior,”) and organizational resources, (Crabtree, [0095]” a system activity monitoring engine 1802 may be used to monitor activity in any of a number of software or network systems, and an organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization.”) respectively, wherein the user profiles include at least access patterns(Crabtree, [0081], [0096]” These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology; gateway firewall programming; internal firewall configuration; directory services protocols and configuration; and permissions profiles for both users and for access to sensitive information, … All captured data are then analyzed to predict the normal usage patterns of network” and “engine 1801 may collect data from a variety of sources 1901, including (but not limited to) communications via various channels (such as email, web-based chat, text messages, or phone calls), access logs for accounts or services, software installation or utilization statistics, work times or locations, or account login and logout records…These behavior data points may then be analyzed”) and roles within the organization, (Crabtree, [0083], [0080]” Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207” and “ the system issues action-focused alert information to all predesignated parties specifically tailored to their roles…”) and wherein the user profiles, device profiles, and resource profiles are constructed based on analyzing historical behavior patterns; (Crabtree, [0096], [0095]” These behavior data points may then be analyzed by comparing observed behavioral data 1903 against expected behavior 1902 according to an established behavioral model developed using statistical and machine learning techniques” and “large amounts of data from numerous sources may be analyzed and used to form behavior profiles, which may then be compared to actual observed behavior.”)
(c) constructing Organizational Context information that pertains to organizational users, (Crabtree, [0095]” A human activity monitoring engine 1801…organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization”) organizational devices, ,(Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. As shown, a customer site 2410 may connect an internal directory server 2411 to system 1800, providing access to internal users, groups, roles, devices, servers, systems, and other information”) and organizational resources, (Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) wherein the Organizational Context information includes user roles in the organization, (Crabtree, [0080]” the system issues action-focused alert information to all predesignated parties specifically tailored to their roles”) device types, (Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) and data classifications; (Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. ….providing access to internal users, groups, roles, devices, servers, systems, and other information”) .
Crabtree does not explicitly disclose (d) constructing a time-series of events, enriched with said Organizational Context information;
(e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, JUN in the same field of endeavor discloses (d) constructing a time-series of events, enriched with said Organizational Context information; ([JUN,[0018], [0019], [0020]]'' The log data is clustered to obtain clustered log data, and the clustered log data is time-series converted to obtain time-series converted log data.''...'' The call chain data is segmented based on a preset sliding window to obtain call tracking data for each window, and the call tracking data for each window is time-series calculated to obtain time-series call chain data.''...’ Based on the normalized metric data, the time-series-processed log data, and the time-series-processed call chain data, a time-series-processed Pod monitoring data sample is formed''. The Examiner interprets this disclosure as corresponding to the claimed constructing a time-series of events, enriched with said Organizational Context information, because JUN expressly constructs time-series data and combines multiple contextual enterprise data types into a unified· processed sample.).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN. One of ordinary skill in the art would have been motivated to do so because incorporating JUN’s time-series event data analysis into Crabtree security monitoring system would have improved anomaly detection accuracy and automated alert generation in Crabtree's enterprise detection system.
The combination of Crabtree and JUN fails to disclose (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, GOVINDAN in the same field of endeavor (e) analyzing said time-series of events( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” The sorted one or more events/ traced path…determined from the received information is compared with a behaviour pattern associated with the user”)using a Machine Learning process( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” a deviation…more events may be determined using Artificial Intelligence (AI) techniques like unsupervised machine learning algorithm”) that detects an anomalous event, ( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Further, an intrusion may be detected based on the determined deviation using a supervised machine learning algorithm”) and automatically generating an alert message( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Furthermore, an alert may be sent to the analyst (110) indicating the intrusion and a set of possible inferences for the detected intrusion”) pertaining to and describing said anomalous event. (GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” indicating the intrusion and a set of possible inferences for the detected intrusion”).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN to further include (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event as suggested by GOVINDAN. One of ordinary skill in the art would have been motivated to do so because incorporating machine-learning-based behavioral analysis into Crabtree system enhanced by JUN’s time-series event construction would have predictably enabled automated analysis of enterprise time-series event data to detect anomalous behavior and automatically generate descriptive alert messages, thereby improving the accuracy, efficiency, and responsiveness of organizational security monitoring using known machine-learning techniques for their intended purpose.
As per claim 20, Crabtree discloses a non-transitory storage medium having stored thereon instructions that, (Crabtree, [0020]”… non-transitory machine-readable storage media include, but are not limited to, magnetic media such as hard disks, floppy disks, and magnetic tape; optical media such as CD-ROM disks; magneto-optical media such as optical disks, and hardware devices that are specially configured to store and perform program instructions”) when executed by a machine, cause the machine to perform a computerized process for detecting and handling security threats in an organizational network of an organization, (Crabtree, [0120]” This method 800 for behavioral analytics enables proactive and high-speed reactive defense capabilities against a variety of cyberattack threats,”) the computerized process comprising:
(a) collecting event data that pertain to users within the organization ("organizational users"), devices within the organization ("organizational devices", and resources within the organization ("organizational resources")(Crabtree, [0122]” state observation service 140 may receive data from a variety of connected systems 1001 such as (for example, including but not limited to) servers, domains, databases, or user directories. ”) , the organizational users, organizational device, and organizational resources being included in the organizational network; (Crabtree, [0126]” … correlate events with actual infrastructure elements, such as servers or accounts.”)
(b) constructing user profiles, device profiles, and resource profiles for the organizational users, Crabtree, [0095]” A human activity monitoring engine 1801 may be used to monitor user behavior”) organizational devices, (Crabtree, [0095]” a device activity monitoring engine 1803 may be used to monitor device-based behavior,”) and organizational resources, (Crabtree, [0095]” a system activity monitoring engine 1802 may be used to monitor activity in any of a number of software or network systems, and an organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization.”) respectively, wherein the user profiles include at least access patterns(Crabtree, [0081], [0096]” These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology; gateway firewall programming; internal firewall configuration; directory services protocols and configuration; and permissions profiles for both users and for access to sensitive information, … All captured data are then analyzed to predict the normal usage patterns of network” and “engine 1801 may collect data from a variety of sources 1901, including (but not limited to) communications via various channels (such as email, web-based chat, text messages, or phone calls), access logs for accounts or services, software installation or utilization statistics, work times or locations, or account login and logout records…These behavior data points may then be analyzed”) and roles within the organization, (Crabtree, [0083], [0080]” Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207” and “ the system issues action-focused alert information to all predesignated parties specifically tailored to their roles…”) and wherein the user profiles, device profiles, and resource profiles are constructed based on analyzing historical behavior patterns; (Crabtree, [0096], [0095]” These behavior data points may then be analyzed by comparing observed behavioral data 1903 against expected behavior 1902 according to an established behavioral model developed using statistical and machine learning techniques” and “large amounts of data from numerous sources may be analyzed and used to form behavior profiles, which may then be compared to actual observed behavior.”).
(c) constructing Organizational Context information that pertains to organizational users, (Crabtree, [0095]” A human activity monitoring engine 1801…organization activity monitoring engine 1804 may be used to monitor broader interactions and behaviors within an organization”) organizational devices, ,(Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. As shown, a customer site 2410 may connect an internal directory server 2411 to system 1800, providing access to internal users, groups, roles, devices, servers, systems, and other information”) and organizational resources, (Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) wherein the Organizational Context information includes user roles in the organization, (Crabtree, [0080]” the system issues action-focused alert information to all predesignated parties specifically tailored to their roles”) device types, (Crabtree, [0123]” a cyber-physical system graph may comprise a visualization of hierarchies and relationships between devices and resources in a security infrastructure, contextualizing security information with physical device relationships that are easily understandable for security personnel and users”) and data classifications; (Crabtree, [0117]” an exemplary application 2400 of a system 1800 for comprehensive data loss prevention and compliance management, as applied to a customer site 2410. …. providing access to internal users, groups, roles, devices, servers, systems, and other information”).
Crabtree does not explicitly disclose (d) constructing a time-series of events, enriched with said Organizational Context information;
(e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, JUN in the same field of endeavor discloses (d) constructing a time-series of events, enriched with said Organizational Context information; ([JUN,[0018], [0019], [0020]]'' The log data is clustered to obtain clustered log data, and the clustered log data is time-series converted to obtain time-series converted log data.''...'' The call chain data is segmented based on a preset sliding window to obtain call tracking data for each window, and the call tracking data for each window is time-series calculated to obtain time-series call chain data.''...’ Based on the normalized metric data, the time-series-processed log data, and the time-series-processed call chain data, a time-series-processed Pod monitoring data sample is formed''. The Examiner interprets this disclosure as corresponding to the claimed constructing a time-series of events, enriched with said Organizational Context information, because JUN expressly constructs time-series data and combines multiple contextual enterprise data types into a unified· processed sample.).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN. One of ordinary skill in the art would have been motivated to do so because incorporating JUN’s time-series event data analysis into Crabtree security monitoring system would have improved anomaly detection accuracy and automated alert generation in Crabtree's enterprise detection system.
The combination of Crabtree and JUN fails to disclose (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event.
However, GOVINDAN in the same field of endeavor (e) analyzing said time-series of events( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” The sorted one or more events/ traced path…determined from the received information is compared with a behaviour pattern associated with the user”)using a Machine Learning process( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” a deviation…more events may be determined using Artificial Intelligence (AI) techniques like unsupervised machine learning algorithm”) that detects an anomalous event, ( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Further, an intrusion may be detected based on the determined deviation using a supervised machine learning algorithm”) and automatically generating an alert message( GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” Furthermore, an alert may be sent to the analyst (110) indicating the intrusion and a set of possible inferences for the detected intrusion”) pertaining to and describing said anomalous event. (GOVINDAN [DETAILED DESCRIPTION OF THE DISCLOSURE]” indicating the intrusion and a set of possible inferences for the detected intrusion”).
Therefore, it would have been obvious before the effective filing date of the claimed invention
to modify Crabtree to include (d) constructing a time-series of events, enriched with said Organizational Context information as suggested by JUN to further include (e) analyzing said time-series of events using a Machine Learning process that detects an anomalous event, and automatically generating an alert message pertaining to and describing said anomalous event as suggested by GOVINDAN. One of ordinary skill in the art would have been motivated to do so because incorporating machine-learning-based behavioral analysis into Crabtree system enhanced by JUN’s time-series event construction would have predictably enabled automated analysis of enterprise time-series event data to detect anomalous behavior and automatically generate descriptive alert messages, thereby improving the accuracy, efficiency, and responsiveness of organizational security monitoring using known machine-learning techniques for their intended purpose.
Claims 2, 4, 7, 10, 12-16 are rejected under 35 U.S.C. §103 as being unpatentable over Crabtree et al.(US 20220377093 A1) [hereinafter "Crabtree"] in view of et al. (WO 2020016906 A1) [hereinafter "GOVINDAN"] and in view of JUN et al. (CN118626287 A) [hereinafter “JUN”] as applied to claim 1 above and further in view of MOHAPATRA et al.( US20240244070A1) [hereinafter “MOHAPATRA”] .
As per claim 2, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not explicitly disclose wherein step (e) comprises: applying to said time-series of events a Long Short-Term Memory (LSTM) analysis that, is configured (i) to detect patterns over time and to identify deviations from expected behavior, and (ii) to detect said anomalous event by analyzing event sequences and their respective Organizational Context information and that detects pattern. However, MOHAPATRA in the same field of endeavor discloses wherein step (e) comprises: applying to said time-series of events a Long Short-Term Memory (LSTM) analysis([MOHAPATRA, [0021]” …at least one convolution neural network (CNN) layer and at least one recurrent neural network (RNN) layer (e.g., a Long Short-Term Memory (LTSM) layer) to classify network flows,”) that, is configured (i) to detect patterns over time and to identify deviations from expected behavior, and (ii) to detect said anomalous event by analyzing event sequences and their respective Organizational Context information and that detects pattern([MOHAPATRA, [0017]” As described herein, training the anomaly detection model on tagged datasets that include both spatial patterns of anomalous behavior and temporal patterns of anomalous behavior, facilitates, for example, detecting new threats, having relatively high accuracy, and having relatively low latency throughput.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein step (e) comprises: applying to said time-series of events a Long Short-Term Memory (LSTM) analysis that, is configured (i) to detect patterns over time and to identify deviations from expected behavior, and (ii) to detect said anomalous event by analyzing event sequences and their respective Organizational Context information and that detects pattern as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating temporal pattern detection using an LSTM-based recurrent neural network improves anomaly detection accuracy while maintaining relatively low latency throughput.
As per claim 4, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not disclose wherein step (e) comprises: (e1) detecting an anomalous data-point in said time-series of events; (e2) based on Organizational Context information, determining that said anomalous data-point more probably does not correspond to a security threat; and therefore, discarding an alert that pertains to said anomalous data-point. However, MOHAPATRA in the same field of endeavor discloses wherein step (e) comprises: (e1) detecting an anomalous data-point in said time-series of events; ([MOHAPATRA, [0026]” For example, for each flow entry of base dataset 202, training label or tag information may indicate whether the flow entry represents anomalous behavior or not, such as a class label, attack type label, attack ID label, and/or attack description label. For example, the class label may broadly categorize flow entries into categories based on a known relationship between the flow entry and anomalous behavior. Such class labels may include (i) “Normal” indicating that the flow entry is not related to anomalous behavior, (ii) “Attacker” indicating that the flow entry is related to the party causing anomalous behavior, (iii) “Victim” indicating that the flow entry is related to the target of the anomalous behavior, (iv) “Suspicious” indicating that the flow entry may be related to anomalous behavior, and (v) “Unknown” indicating that the flow entry's relationship to anomalous behavior is unknown, etc”). (e2) based on Organizational Context information, determining that said anomalous data-point more probably does not correspond to a security threat; ([MOHAPATRA, [0026]” For example, a behavior label may be define based on the class label with the values of “anomalous” for flow entries with the “attacker,” “victim,” and “suspicious” class labels and “non-anomalous” for flow entries with the “normal” and “unknown” labels). Such label information may be used by model 114 to learn the underlying patterns between what information from the flow records is associated with what labels (e.g., which flow entries are labeled anomalous and which flow entries are labeled non-anomalous). Therefore, as new flow records are input into the model 114 after training, the model 114 will determine appropriate classification outputs (e.g., having the types of the training labels) for the flow records.” and therefore, discarding an alert that pertains to said anomalous data-point. ([MOHAPATRA, [0039]” The RNN layer provides temporal anomaly detection by detecting anomalous behavior connected to changes in features over time. In the illustrated example, the model 114 includes a type of RNN layer referred as a long short-term memory (LSTM) layer. The LSTM is composes of a network of nodes or cells that keep or discard information over time t. The output layer of the LSTM is data that quantifies the relationship, if any, of features over the time t. ”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include discloses wherein step (e) comprises: (e1) detecting an anomalous data-point in said time-series of events; (e2) based on Organizational Context information, determining that said anomalous data-point more probably does not correspond to a security threat; and therefore, discarding an alert that pertains to said anomalous data-point as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because Mohapatra teaches filtering anomalous events based on classification to determine whether an alert should be generated.
As per claim 7, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not disclose wherein step (d) comprises: obtaining data describing a set of events; identifying entities involved in each event; grouping the events into time-series based on entity types; analyzing each time-series for patterns or deviations using a Machine Learning models that is configured to detect anomalous activity. However MOHAPATRA discloses wherein step (d) comprises: obtaining data describing a set of events; ([MOHAPATRA, [0025], [0028]]” An example of a base dataset 202 includes a dataset of the Coburg Intrusion Detection Data Sets (CIDDS) in the CIDDS repository maintained by the Coburg University of Applied Sciences.”[0025]…” Data preprocessing sub-process 204 is configured to generate additional features for each flow entry based on the base dataset 202, such as to generate a modified dataset 203. These generated features in the modified dataset 203 may, for example, facilitate generation of the model 114 that … flow ID”[0028])identifying entities involved in each event; ([MOHAPATRA, [0025], [0030]-[0032]” Feature Name Feature Description Source IP Address IP Address of source of packets of flow Source Port Source port number of packets of flow Destination IP IP Address of destination of packets of flow Address Destination Port Destination port number of packets of flow Protocol Transport Protocol (e.g., Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Internet Control Message Protocol (ICMP), etc.) Time Initiated Start time the flow is first seen Duration Duration of the flow Bytes Number of transmitted bytes of the flow Packets Number of transmitted packets of the flow Flags Protocol flags (e.g., one or more TCP flags)” and “ As noted, a flow is defined as packets having a particular source IP address and port number, destination IP address and port number, and protocol. For example, a source IP address may be associated with a particular endpoint (referred to as a source endpoint of the flow) and the source port number may be associated with a particular application (referred to as a source application of the flow) running in the source endpoint.”)grouping the events into time-series based on entity types; analyzing each time-series for patterns or deviations using a Machine Learning models that is configured to detect anomalous activity([MOHAPATRA, [0034], [0028]” The normalized dataset 205 is input to a data serialization subprocess 206 to generate serialized dataset 207. The data serialization subprocess 206 groups flow entries together into temporal buckets 212a, 212b, 212c . . . 212n (collectively “temporal buckets 212”) to facilitate detecting temporal patterns in the features that are indicative of anomalous behavior.” and “These generated features in the modified dataset 203 may, for example, facilitate generation of the model 114 that has more comprehensive spatial anomaly detection than a model trained with the based dataset 202. The modified dataset 203 includes the features of the base dataset 202 and these additional features discussed herein. Additionally, the data preprocessor 204 may assign each flow, as defined by the 5-tuple, a unique identifier (sometimes referred to as a “flow ID”). The flow ID is assigned, as a feature, to each flow entry that is associated with a given flow. Because a given flow may have multiple entries, each entry corresponding to a different time period and/or observation point, multiple flow entries may be assigned to a single flow ID.” [0028]
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein step (d) comprises: obtaining data describing a set of events; identifying entities involved in each event; grouping the events into time-series based on entity types; analyzing each time-series for patterns or deviations using a Machine Learning models that is configured to detect anomalous activity as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating feature extraction and temporal grouping of flow records will improve detection of anomalous activity.
As per claim 10, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not explicitly disclose performing multi-entity time-series correlation by correlating anomalies across multiple entities, by performing: constructing time-series for each entity in an organizational network; analyzing the time-series data for individual entities; identifying correlations between time-series for different entities; detecting coordinated anomalies that affect multiple users, devices, or resources. However, MOHAPATRA in the same field of endeavor discloses performing multi-entity time-series correlation by correlating anomalies across multiple entities, by performing: constructing time-series for each entity in an organizational network; ([MOHAPATRA, [0018]” a network environment 100 of, for example, a datacenter. The network environment 100 includes a collector 102 and a plurality of endpoints (EPs) 104a through 104m (collectively “EPs 104”) connected via a network 106. In the illustrated example, the EPs 104 are organized into various subnetworks 108a, 108b, and 108c (collectively “subnetworks 108”). The subnetworks 108 may be, for example… network”). analyzing the time-series data for individual entities; identifying correlations between time-series for different entities; ([MOHAPATRA, [0017]” detect relationships between flows based on the features of the flows (such as derived based on and/or included in flow records). In certain aspects, the anomaly detection model is a multi-layer, hybrid neural network model.”). detecting coordinated anomalies that affect multiple users, devices, or resources. ([MOHAPATRA, [0020]” The collector 102 may collect and analyze the flow records 110 in order to determine security policies, identify dependencies, migrate workloads, and/or allocate network resources, etc. For example, the collector 102 may be associated with a service provider (e.g., a provider of a datacenter, etc.) that serves the plurality of endpoints 104. In the illustrated example, the collector 102 includes a risk analyzer 112. The risk analyzer 112 analyzes the flow records 110 to identify network traffic (e.g., corresponding to one or more flows) that does… detection model”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include performing multi-entity time-series correlation by correlating anomalies across multiple entities, by performing: constructing time-series for each entity in an organizational network; analyzing the time-series data for individual entities; identifying correlations between time-series for different entities; detecting coordinated anomalies that affect multiple users, devices, or resources as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating multi-entity time-series correlation techniques to improve identification of coordinated anomalous activity across multiple users, devices, or network resources.
As per claim 12, JUN discloses the computerized method of claim 1.The combination of GOVINDAN and JUN does not disclose the computerized method further comprising: in response to said alert message, automatically invoking one or more pre-defined mitigation processes or remediation processes, that are selected from a pool of processes by taking into account at least (i) one or more characteristics of the generated alert, and (ii) an estimated severity level of the generated alert. However, MOHAPATRA discloses the computerized method further comprising: in response to said alert message, automatically invoking one or more pre-defined mitigation processes or remediation processes, that are selected from a pool of processes by taking into account at least (i) one or more characteristics of the generated alert, and (ii) an estimated severity level of the generated alert([MOHAPATRA, [0020], [0021]” When anomalous network traffic is detected, the risk analyzer 112 may alert an administrator and/or provide a notification and/or instruction to another service to ameliorate the anomalous network traffic (e.g., update firewall settings to block traffic from one or more IP address sources, divert the network traffic from one or more IP address sources to an intermediary for inspection, instruct a network edge device to block network traffic from one or more IP address sources, etc.). In the illustrated example, the risk analyzer 112 deploys an anomaly detection model 114.”[0020] and “The model 114 is trained on one or more datasets to detect anomalies by analyzing spatial and temporal relationships within the flows captured by the flow records 110. In certain aspects, the at least one convolution layer is configured to detect spatial relationships. In certain aspects, the recurrent neural network layer is configured to detect temporal relationships.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include the computerized method further comprising: in response to said alert message, automatically invoking one or more pre-defined mitigation processes or remediation processes, that are selected from a pool of processes by taking into account at least (i) one or more characteristics of the generated alert, and (ii) an estimated severity level of the generated alert as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating automated selection and invocation of appropriate mitigation actions based on detected anomalous network characteristics.
As per claim 13, JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not disclose the computerized method further comprising: partitioning the time-series of events into overlapping segments; analyzing each segment for behavioral deviations using the Machine Learning model; detecting an anomaly in the partitioned data based on patterns across multiple segments. However MOHAPATRA in the same field of endeavor discloses the computerized method further comprising: partitioning the time-series of events into overlapping segments; ([MOHAPATRA, [0034]” The normalized dataset 205 is input to a data serialization subprocess 206 to generate serialized dataset 207. The data serialization subprocess 206 groups flow entries together into temporal buckets 212a, 212b, 212c . . . 212n (collectively “temporal buckets 212”) to facilitate detecting temporal patterns in the features that are indicative of anomalous behavior.”) analyzing each segment for behavioral deviations using the Machine Learning model; ([MOHAPATRA, [0035]” For example, the model training subprocess 208 inputs serialized dataset 207 into an untrained (or previously trained and being further trained) model 114 and receives output classifications for the serialized dataset 207, such as classifications of certain flow entries as anomalous or non-anomalous (or any other suitable classification such as corresponding to the training labels discussed herein) “and that ” the model 114 is trained using supervised learning.”[0021])detecting an anomaly in the partitioned data based on patterns across multiple segments([MOHAPATRA, [0039]” The RNN layer provides temporal anomaly detection by detecting anomalous behavior connected to changes in features over time”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include the computerized method further comprising: partitioning the time-series of events into overlapping segments; analyzing each segment for behavioral deviations using the Machine Learning model; detecting an anomaly in the partitioned data based on patterns across multiple segments as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating temporal segmentation with machine learning based temporal anomaly detection to improve identification of anomalous behavior time intervals.
As per claim 14, JUN discloses the computerized method of claim 1.The combination of GOVINDAN and JUN does not disclose the computerized method further comprising: predicting future anomalies in the organizational network, by performing: collecting and grouping event data into time-series; applying the Machine Learning model to said time-series to predict future behavior based on historical data; generating alerts for potential future anomalies before they occur. However, MOHAPATRA discloses the computerized method further comprising: predicting future anomalies in the organizational network, by performing: collecting and grouping event data into time-series; ([MOHAPATRA, [0034], [0035], [0039]” The data serialization subprocess 206 groups flow entries together based on flow entries that share the same (i) flow ID and (ii) have a timestamp that falls within a particular range. The timestamp may be a timestamp of when the flow record was generated at the observation point. That is, for each flow ID, the flow entries are separated into the temporal buckets 212 of width t.sub.B, where t.sub.B is a period of time, based on the timestamps of the flow entries”[0034] and “The serialized dataset 207 is input to a model training subprocess 208. The model training subprocess 208 trains the model 114 based on the serialized dataset 207”[0035]) applying the Machine Learning model to said time-series to predict future behavior based on historical data; ([MOHAPATRA, [0035], [0036]]” The serialized dataset 207 is input to a model training subprocess 208. The model training subprocess 208 trains the model 114 based on the serialized dataset 207” and “the model training subprocess 208 may determine whether the trained model 114 has met a desired level of accuracy using a validation dataset, which may be a different dataset than used to train model 114.”…” The RNN layer provides temporal anomaly detection by detecting anomalous behavior connected to changes in features over time” ). generating alerts for potential future anomalies before they occur. ([MOHAPATRA, [0043]” The dense SoftMax layer 318 transforms the output of the third dropout layer 316 into a number of output classifications 320 classifying the flow entries of the serialized dataset 207. Because, in the illustrated example the model 114 determines whether a flow belongs in one of two classes (e.g., anomalous and not anomalous, etc.), the dense SoftMax layer 318 outputs two classifications. Each output is then converted to a probability vector, where values in the vector corresponds to the probability of the sample belonging to one of the output classes. When the model is trained, the dropout layers 308, 312, and 316 are removed.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include disclose the computerized method further comprising: predicting future anomalies in the organizational network, by performing: collecting and grouping event data into time-series; applying the Machine Learning model to said time-series to predict future behavior based on historical data; generating alerts for potential future anomalies before they occur as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating temporal sequence modeling with machine learning-based predictive anomaly detection to proactively identify anomalous behavior before it manifests in the network.
As per claim 16, JUN discloses the computerized method of claim 1. JUN does not explicitly disclose the computerized method comprising: selectively suppressing benign or non-risky system-generated alerts based on Organizational Context, by performing: detecting an anomaly using time-series analysis; evaluating the anomaly against the Organizational Context information, including at least user roles and historical behavior; determining a likelihood of a false positive error based on said Organizational Context information; suppressing or discarded the alert if the behavior is deemed non-threatening or non-risky to the organization in view of said Organizational Context information. However, MOHAPATRA in the same field of endeavor discloses the computerized method comprising: selectively suppressing benign or non-risky system-generated alerts based on Organizational Context, by performing: detecting an anomaly using time-series analysis; ([MOHAPATRA, [0039]” The RNN layer provides temporal anomaly detection by detecting anomalous behavior connected to changes in features over time. In the illustrated example, the model 114 includes a type of RNN layer referred as a long short-term memory (LSTM) layer. The LSTM is composes of a network of nodes or cells that keep or discard information over time t. The output layer of the LSTM is data that quantifies the relationship, if any, of features over the time t.”) evaluating the anomaly against the Organizational Context information ([MOHAPATRA, [0026]). “Further, each entry in base dataset 202 may be correlated with training label or tag information, which may be stored in a same data structure as base dataset 202 is stored, or in a separate data structure. For example, for each flow entry of base dataset 202, training label or tag information may indicate whether the flow entry represents anomalous behavior or not, such as a class label, attack type label, attack ID label, and/or attack description label. For example, the class label may broadly categorize flow entries into categories based on a known relationship between the flow entry and anomalous behavior. Such class labels may include (i) “Normal” indicating that the flow entry is not related to anomalous behavior, (ii) “Attacker” indicating that the flow entry is related to the party causing anomalous behavior, (iii) “Victim…flow record”) including at least user roles and historical behavior; ([MOHAPATRA, [0035]” The model training subprocess 208 may iteratively input serialized dataset 207 into model 114, compare the output to the training labels, and adjust parameters, until the trained model 114 performs at a desired level of accuracy (e.g., a desired percentage of correct classification among the flow entries in the serialized dataset 207).”). determining a likelihood of a false positive error based on said Organizational Context information; ([MOHAPATRA, [0036]” In certain aspects, the model training subprocess 208 may determine whether the trained model 114 has met a desired level of accuracy using a validation dataset, which may be a different dataset than used to train model 114.”) suppressing or discarded the alert if the behavior is deemed non-threatening or non-risky to the organization in view of said Organizational Context information ([MOHAPATRA, [0020], [0043]]” In the illustrated example, the collector 102 includes a risk analyzer 112. The risk analyzer 112 analyzes the flow records 110 to identify network traffic (e.g., corresponding to one or more flows) that does not appear to follow normal patterns that are commonly seen on a particular network (sometimes referred to as “anomalous network traffic” or “anomalous behavior” in the network). Anomalous network traffic may be caused by malicious actors trying to damage or otherwise interfere with one of more EPs 104 or other network components, or by errors in one or more components (e.g., routing components) within the network. When anomalous network traffic is detected, the risk analyzer 112 may alert an administrator and/or provide a notification and/or instruction to another service to ameliorate the anomalous network traffic (e.g., update firewall settings to block traffic from one or more IP address sources,”[0020] and “The output of the third dropout layer 316 is fed into a dense SoftMax layer 318. The dense SoftMax layer 318 transforms the output of the third dropout layer 316 into a number of output classifications 320 classifying the flow entries of the serialized dataset 207. Because, in the illustrated example the model 114 determines whether a flow belongs in one of two classes (e.g., anomalous and not anomalous, etc.), the dense SoftMax layer 318 outputs two classifications. Each output is then converted to a probability vector, where values in the vector corresponds to the probability of the sample belonging to one of the output classes. When the model is trained, the dropout layers 308, 312, and 316 are removed.”[0043]).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include the computerized method comprising: selectively suppressing benign or non-risky system-generated alerts based on Organizational Context, by performing: detecting an anomaly using time-series analysis; evaluating the anomaly against the Organizational Context information, including at least user roles and historical behavior; determining a likelihood of a false positive error based on said Organizational Context information; suppressing or discarded the alert if the behavior is deemed non-threatening or non-risky to the organization in view of said Organizational Context information as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating organizational context and historical behavioral analysis to reduce false positive alerts and improve alert precision.
Claim 3 is rejected under 35 U.S.C. §103 as being unpatentable over Crabtree et al.(US 20220377093 A1) [hereinafter "Crabtree"] in view of et al. (WO 2020016906 A1) [hereinafter "GOVINDAN"] and in view of JUN et al. (CN118626287 A) [hereinafter “JUN”] as applied to claim 1 above and in view of Yan et al. [hereinafter “Yan”] "Anomaly Detection Approach for Sensor Networks in Coal Mine Solid Backfilling Working Faces Based on Transformer" .
As per claim 3, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not explicitly disclose wherein step (e) comprises: applying to said time-series of events a Temporal Fusion Transformers (TFT) analysis, that is configured (i) to detect patterns over time and to identify deviations from expected behavior, and (ii) to detect said anomalous event by analyzing event sequences and their respective Organizational Context information and that detects pattern. However, Yan in the same field of endeavor discloses disclose wherein step (e) comprises: applying to said time-series of events a Temporal Fusion Transformers (TFT) analysis, ([Yan, Conclusion, II-B]” The time series prediction module utilizes the Temporal Fusion Transformers model” … “The Time Fusion Transformers (TFT) model is a Transformer-based time series forecasting model… This model incorporates a variable selection network to improve prediction performance”) that is configured
(i)to detect patterns over time and to identify deviations ([Yan, II-C]” The goal of the anomaly detection module is to compute the prediction errors of the time series prediction model and determine whether the actual values deviate from the normal range based on these errors”)
from expected behavior, ([Yan, II-B, Introduction]” The Time Fusion Transformers (TFT) model is a Transformer-based time series forecasting model” …” This model incorporates a variable selection network… enabling the model to choose the important sequences from the input sequences”…” The self-attention mechanism in the Transformer model has been widely employed for prediction and anomaly detection by uncovering potential correlations in data”) and
(ii)to detect said [anomalous event] by analyzing event sequences and their respective Organizational Context information and that[ detects pattern]. ([Yan, II-C]” When the prediction has a significant deviation from the actual value, it indicates the [presence of an outlier or anomaly]….If the prediction error exceeds the fixed threshold, the actual value is classified as an anomaly, indicating a deviation from the normal range.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein step (e) comprises: applying to said time-series of events a Temporal Fusion Transformers (TFT) analysis, that is configured (i) to detect patterns over time and to identify deviations from expected behavior, and (ii) to detect said anomalous event by analyzing event sequences and their respective Organizational Context information and that detects pattern as suggested by Yan. One of ordinary skill in the art would have been motivated to do so because transformer-based temporal sequence models, such as Temporal Fusion Transformers, were known to improve learning of temporal patterns and deviations in time-series data compared to recurrent models.
Claims 6, 11 are rejected under 35 U.S.C. §103 as being unpatentable over Crabtree et al.(US 20220377093 A1) [hereinafter "Crabtree"] in view of et al. (WO 2020016906 A1) [hereinafter "GOVINDAN"] and in view of JUN et al. (CN118626287 A) [hereinafter “JUN”] as applied to claim 1 above and in view of Wüest et al. (US20250200175A1) [hereinafter “Wüest”].
As per claim 6, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not disclose wherein step (d) comprises: enriching the time-series of events by commanding a Large Language Model (LLM) to enrich the time-series of events based on data extracted from organizational sources. However, Wüest in the same field of endeavor discloses wherein step (d) comprises: enriching the time-series of events by commanding a Large Language Model (LLM) to enrich the time-series of events based on data extracted from organizational sources. ([Wüest, [0040]-[0043], [0053]]” Training component 114 is configured to generate a training dataset by generating multiple sequences of events from each provenance graph generated. In some aspects, the sequences from one graph may have overlapping events. In some aspects, all events originate from a common provenance graph and are sorted by timestamp.”[0040]), “For example, training component 114 may gather all recent events from one specific provenance graph, order them according to their timestamps”, “In some aspects, the events may also be modeled as a graph, and used for training a graph neural network, which can subsequently be used to classify nodes, links, or graphs as malicious. The result of this step is global model 118 trained on global behavior data to predict maliciousness for a sequence of events” and further “The sequences, as extracted from provenance graphs, connect different events, such as file creations, processes executions, registry modifications, network communications, etc. For example, during training, training component 114 may mask N amount of events in a sequence, and global model 118 may be trained to predict said masked events (e.g., predict the next event given a sequence of events). For example, given the first three events in sequence 206, global model 118 is trained to predict the last two events.”
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include discloses wherein step (e) comprises: (e1) detecting an anomalous data-point in said time-series of events; (e2) based on Organizational Context information, determining that said anomalous data-point more probably does not correspond to a security threat; and therefore, discarding an alert that pertains to said anomalous data-point as suggested by Wüest. One of ordinary skill in the art would have been motivated to do so because incorporating enrichment of the time-series of events using a transformer-based machine learning model would improve contextual anomaly detection accuracy by modeling sequential event dependencies and reducing false positives.
As per claim 11, JUN discloses the computerized method of claim 1.The combination of GOVINDAN and JUN does not disclose the computerized method further comprising: (f1) generating alerts for detected anomalies; (f2) receiving user feedback about accuracy of the alerts and severity of the alerts; (f3) storing the user feedback in a feedback database; (f4) incorporating the user feedback into a subsequent anomaly detection process by refining the Machine Learning model based on said user feedback about prior alerts. However, Wüest discloses the computerized method further comprising: (f1) generating alerts for detected anomalies; ([Wüest, [0047]” If the probability of maliciousness is greater than a pre-defined threshold probability, security module 106 generates an alert indicating malicious activity, and provides the set of events with the alert”) (f2) receiving user feedback about accuracy of the alerts and severity of the alerts; ([Wüest, [0046]” Information about suspicious events, including timestamps, is stored in a global database for future model retraining. This ensures that the global model 118 and each tuned model 122 is regularly updated to respond more effectively to emerging threats.”) (f3) storing the user feedback in a feedback database; ([Wüest, [0046]” Information about suspicious events, including timestamps, is stored in a global database for future model retraining.”)(f4) incorporating the user feedback into a subsequent anomaly detection process by refining the Machine Learning model based on said user feedback about prior alerts. ([Wüest, [0046]” Information about suspicious events, including timestamps, is stored in a global database for future model retraining. This ensures that the global model 118 and each tuned model 122 is regularly updated to respond more effectively to emerging threats.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include the computerized method further comprising: (f1) generating alerts for detected anomalies; (f2) receiving user feedback about accuracy of the alerts and severity of the alerts; (f3) storing the user feedback in a feedback database; (f4) incorporating the user feedback into a subsequent anomaly detection process by refining the Machine Learning model based on said user feedback about prior alerts as suggested by Wüest . One of ordinary skill in the art would have been motivated to do so because incorporating feedback-based model retraining would improves anomaly detection accuracy and adaptability.
Claims 17 and 18 are rejected under 35 U.S.C. §103 as being unpatentable over Crabtree et al.(US 20220377093 A1) [hereinafter "Crabtree"] in view of et al. (WO 2020016906 A1) [hereinafter "GOVINDAN"] and in view of JUN et al. (CN118626287 A) [hereinafter “JUN”] as applied to claim 1 above, and in view of MOHAPATRA et al.( US20240244070A1) [hereinafter “MOHAPATRA”] and further in view of Peter et al. (US 9230280 B1)[hereinafter “Peter”].
As per claim 17, JUN discloses the computerized method of claim 1.The combination of GOVINDAN and JUN does not disclose wherein step (a) of collecting event data further comprises: collecting event data that pertains at least to (a1) communications between the organization and a third-party entity, (a2) payments between the organization and the third-party entity; wherein the time-series of events is analyzed by a process that is configured to detect abnormal communications or abnormal payments from the organization towards the third-party entity. However, MOHAPATRA discloses wherein step (a) of collecting event data further comprises: collecting event data that pertains at least to (a1) communications between the organization and a third-party entity, ([MOHAPATRA, [0030]” The generated features may also include based on a “direction” of a flow. A flow may also be assigned a “direction” as either a “request direction flow” (also referred to as “forward packets” or “forward flow”) or a “response direction flow” (also referred to as “backward packets” or “backward flow”). As noted, a flow is defined as packets having a particular source IP address and port number, destination IP address and port number, and protocol. For example, a source IP address may be associated with a particular endpoint (referred to as a source endpoint of the flow) and the source port number may be associated with a particular application (referred to as a source application of the flow) running in the source endpoint. Further, a destination IP address may be associated with a particular endpoint (referred to as a destination endpoint of the flow) and the destination port number may be associated with a particular application (referred to as a destination application of the flow) running in the destination endpoint… direction flow.”) wherein the time-series of events is analyzed by a process that is configured to detect abnormal communications or abnormal payments from the organization towards the third-party entity([MOHAPATRA, [0034], [0039], [0020], [0013]” …to generate serialized dataset 207. The data serialization subprocess 206 groups flow entries together into temporal buckets 212a, 212b, 212c . . . 212n (collectively “temporal buckets 212”) to facilitate detecting temporal patterns in the features that are indicative of anomalous behavior.”[0034], “temporal anomaly detection by detecting anomalous behavior connected to changes in features over time”,[0039], “ The risk analyzer 112 analyzes the flow records 110 to identify network traffic (e.g., corresponding to one or more flows) that does not appear to follow normal patterns that are commonly seen on a particular network (sometimes referred to as “anomalous network traffic” or “anomalous behavior” in the network).”[0020], “For example, as packets corresponding to a flow pass through a particular observation point, the observation point may generate a flow record indicating information about the flow as observed, such as the 5-tuple indicated in the headers of the packets, start and end timestamps of when packets of the flow were first and last observed (e.g., within a defined time interval or period, such as per a timer or from when the flow is initiated to when it is terminated), the number of packets and/or bytes observed for the flow (e.g., within the defined time interval or period), input and output interface numbers indicated in the headers of the packets, TCP flags and encapsulated protocol indicated in the headers of the packets, routing information indicated in the headers of the packets, and/or the like. As different observation points may observe the same flow”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein step (a) of collecting event data further comprises: collecting event data that pertains at least to (a1) communications between the organization and a third-party entity and wherein the time-series of events is analyzed by a process that is configured to detect abnormal communications or abnormal payments from the organization towards the third-party entity as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating partner entity communication data to enable anomaly detection across organizational interactions.
The combination of GOVINDAN, JUN and MOHAPATRA does not disclose collecting event data that pertains at least to ([Peter (31), (26)” Link: A connection between two data objects, based on, for example, a relationship, an event, and/or matching properties. Links may be directional, such as one representing a payment from person A to B, or bidirectional” and that “a data entity may represent an entity such as a person, a place, an organization, an account, a computer, an activity, a market instrument, a trade of a market instrument, an email message…noun.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein step (a) of collecting event data further comprises: collecting event data that pertains at least to (a1) communications between the organization and a third-party entity and wherein the time-series of events is analyzed by a process that is configured to detect abnormal communications or abnormal payments from the organization towards the third-party entity as taught by MOHAPATRA to further include collecting event data that pertains at least to(a2) payments between the organization and the third-party entity as suggested by Peter. One of ordinary skill in the art would have been motivated to do so because incorporating entity-to-entity payment link data to enhance detection of anomalous financial interactions would improve detection coverage across both communication and financial activity domains.
As per claim 18, the combination of GOVINDAN and JUN discloses the computerized method of claim 1. The combination of GOVINDAN and JUN does not disclose wherein said process is configured to automatically detect at least one of: (I) an event of sending an information item from the organization to said third-party entity, wherein the information item does not belong to a type of information items that are typically sent from the organization to said third-party entity; (II) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send any communications to said third-party entity; (III) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send said type of information items to said third-party entity; (IV) an event of payment to a new bank account of said third-party entity. However, MOHAPATRA discloses wherein said process is configured to automatically detect at least one of: (I) an event of sending an information item from the organization to said third-party entity, wherein the information item does not belong to a type of information items that are typically sent from the organization to said third-party entity; ([MOHAPATRA, [0030]” The generated features may also include based on a “direction” of a flow. A flow may also be assigned a “direction” as either a “request direction flow” (also referred to as “forward packets” or “forward flow”) or a “response direction flow” (also referred to as “backward packets” or “backward flow”). As noted, …. direction flow.”) (II) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send any communications to said third-party entity; ([MOHAPATRA, [0034]” The normalized dataset 205 is input to a data serialization subprocess 206 to generate serialized dataset 207. The data serialization subprocess 206 groups flow entries together into temporal buckets 212a, 212b, 212c . . . 212n (collectively “temporal buckets 212”) to facilitate detecting temporal patterns in the features that are indicative of anomalous behavior….five”])(III) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send said type of information items to said third-party entity; ([MOHAPATRA, [0034]]” The normalized dataset 205 is input to a data serialization subprocess 206 to generate serialized dataset 207. The data serialization subprocess 206 groups [flow entries] together into temporal buckets 212a, 212b, 212c . . . 212n (collectively “temporal buckets 212”) to facilitate detecting temporal patterns in the features that are indicative of anomalous behavior…. five”. The Examiner interprets the flow entries as representing communications between endpoints, including a source endpoint within the organization and a destination endpoint that corresponds to a third-party entity).
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein said process is configured to automatically detect at least one of: (I) an event of sending an information item from the organization to said third-party entity, wherein the information item does not belong to a type of information items that are typically sent from the organization to said third-party entity; (II) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send any communications to said third-party entity; (III) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send said type of information items to said third-party entity as suggested by MOHAPATRA. One of ordinary skill in the art would have been motivated to do so because incorporating communication pattern anomaly detection based on deviations from normal communications between the organization and the third-party entity would improve detection accuracy and adaptability.
The combination of JUN and MOHAPATRA does not disclose wherein said process is configured to automatically detect at least one of.([Peter, (26)])” Data Entity (Entity), Data Object (Object), or Data Item (Item): A data container for information representing specific things in the world that have a number of definable properties. For example, a data entity may represent an entity such as a person, a place, an organization, an account, a computer, an activity, a market instrument, a trade of a market instrument, an email message, an email thread, a chat message, a chat thread, or other noun. A data entity may represent an event that happens at a point in time or for a duration. A data entity may represent a document or other unstructured data source such as an e-mail message or thread, a chat message or thread, a news report, or a written paper or article. Each data entity may be associated with a unique identifier that uniquely identifies the data entity” The Examiner interprets “new bank account” as “data entity”, “data object”, “data item”.)
Therefore, it would have been obvious before the effective filing date of the claimed invention to modify GOVINDAN to include wherein said process is configured to automatically detect at least one of: (I) an event of sending an information item from the organization to said third-party entity, wherein the information item does not belong to a type of information items that are typically sent from the organization to said third-party entity; (II) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send any communications to said third-party entity; (III) an event of sending an information item from the organization to said third-party entity, wherein the information item is sent by a sender within the organization that does not typically send said type of information items to said third-party entity as suggested by MOHAPATRA to further include wherein said process is configured to automatically detect at least one of (IV) an event of payment to a new bank account of said third-party entity as taught by Peter. One of ordinary skill in the art would have been motivated to do so because incorporating detection anomalous financial transactions, including payments to new bank accounts, improves fraud detection accuracy and adaptability.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure:
BO et al, (CN110232082A) discloses “the invention relates to an anomaly detection method for continuous space-time refueling data”.
HONG-BO et al, (CN110598851A) discloses Time series data anomaly detection method fusing LSTM and GAN.
Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Komi N. AMEVIGBE whose telephone number is (571)272-3381. The examiner can normally be reached Monday-Friday 2pm-10pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.N.A./
Examiner, Art Unit 2493
/CARL G COLIN/Supervisory Patent Examiner, Art Unit 2493