DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending.
Information Disclosure Statement
The IDS filed 11/20/2024 has been considered by the Examiner.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a) as being anticipated by US Patent No. 12,536071 to Skarphedinsson et al. (hereinafter Skarphedinsson).
As to claims 1, 8, and 15, Skarphedinsson teaches:
a. A memory that stores historical interaction logs associated with previous data interactions performed in relation to a first user (Skarphedinsson, 7:21-37).
b. A processor communicatively coupled to the memory (Skarphedinsson, 7:21-37)and configured to:
i. Detect that a first data interaction has been performed in relation to the first user (alert generator monitors user behavior including initial authentication to gain access within the data center) (Skarphedinsson, 26:1-43).
ii. Determine, based on one or more historical interaction logs associated with the previous data interactions, that the first data interaction does not at least partially match with the previous data interactions performed in relation to the first user (anomalies occur when current user behavior does not match historic user behavior) (Skarphedinsson, 97:17-57).
iii. In response to determining that the first data interaction does not at least partially match with the previous data interactions performed in relation to the first user, determine that a data breach has potentially occurred (data breach is one example of anomalous activity) (Skarphedinsson, 97:17-57).
iv. Verify the data breach to confirm whether the data breach has occurred, wherein the verifying comprises one or more of the following:
a. Determining whether the first data interaction is in accordance with an interaction behavior pattern associated with the first user (there are four tiers of user behavior that are checked in order to determine if a data breach has occurred) (Skarphedinsson, 48:16-51).
b. Determining whether the first data interaction is in accordance with one or more relations between nodes of a knowledge graph that represents the previous data interactions performed in relation to the first user (knowledge graph can be used to determine any anomalies in user behavior) (Skarphedinsson, 104:63-105:28 (graph definition) and 106:27-44 (using the graph)).
c. Determine, based on the verifying, that the data breach is confirmed (determining that an anomalous event(s) has occurred) (Skarphedinsson, 111:31-53).
d. In response to determining that the data breach is confirmed, determine one or more remediation methods that are to be used to avoid theft of data as a result of the data breach (data platforms have remediation services) (Skarphedinsson, 4:21-34).
e. Implement the one or more remediation methods to avoid theft of data as a result [of] the data breach (carrying out remedial actions) (Skarphedinsson, 74:54-75:8).
As to claims 2, 9, and 16, Skarphedinsson teaches:
a. Obtaining the interaction behavior pattern associated with the first user, wherein the interaction behavior pattern comprises a first set of interaction parameters associated with a plurality of previous data interactions performed in relation to the first user (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67).
b. Extracting, from a first interaction log of the first data interaction, a second set of interaction parameters associated with the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67).
c. Comparing the second set of interaction parameters with the first set of interaction parameters (deviation from past logins indicates anomalous behavior and triggers an alert) (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67).
d. In response to determining that at least a threshold number of interaction parameters from the second set match with corresponding interaction parameters from the first set, determining that the data breach is not confirmed (matching parameters do not indicate anomalous behavior) (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67).
e. In response to determining that at least a threshold number of interaction parameters from the second set do not match with corresponding interaction parameters from the first set, determining that the data breach is confirmed (deviation from past behavior indicates anomalous behavior and triggers an alert) (Skarphedinsson, 48:1-51, 52:60-67, and 111:31-53).
As to claims 3, 10, and 17, teaches:
a. Obtaining the knowledge graph that represents the previous data interactions performed in relation to the first user, wherein the knowledge graph represents the previous data interactions performed in relation to the first user as a plurality of nodes and relationships between the nodes (knowledge graph can be used to determine any anomalies in user behavior) (Skarphedinsson, 104:63-105:28 (graph definition) and 106:27-44 (using the graph)).
b. Determining whether the first data interaction matches with the nodes and corresponding relationships from the knowledge graph that are associated with one or more same or similar previous data interactions (matching patterns includes variations of the patterns) (Skarphedinsson, 111:24-53).
c. In response to determining that the first data interaction matches with at least a threshold number of the nodes and the corresponding relations from the knowledge graph, determining that the data breach is not confirmed (matching patterns do not indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ).
d. In response to determining that the first data interaction does not match with at least the threshold number of the nodes and the corresponding relations from the knowledge graph, determining that the data breach is confirmed (mismatching patterns indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ).
As to claims 4, 11, and 18, teaches:
a. Verify the data breach using an Artificial Intelligence (AI) mode, wherein the AI model is trained using the interaction behavior pattern and the knowledge graph (determining that an anomalous event(s) has occurred) (Skarphedinsson, 111:31-53).
b. Inputting to the AI model a first interaction log associated with the first data interaction (AI model uses at least a knowledge graph in processing interaction data) (Skarphedinsson, 103:45-62).
c. Obtaining an indication of whether the data breach is confirmed as a result output by the AI model (AI model outputs alerts of anomalous behavior) (Skarphedinsson, 105:1-20).
As to claims 5, 12, and 19, teaches:
a. Obtaining a first interaction log associated with the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67).
b. Identifying, from the historical interaction logs, the one or more historical interaction logs that are associated with previous data interactions that are [the] same or similar to the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage and compares them) (Skarphedinsson, 48:1-51 and 52:60-67).
c. Determining that the data breach has potentially occurred to response to determining that the first interaction log at least partially does not match with the one or more historical interaction logs (mismatching patterns indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ).
As to claims 6, 13, and 20, teaches:
a. The processor is further configured to monitor a plurality of communication channels configured for performing data interactions by users (monitoring a plurality of connections (communication channels)) (Skarphedinsson, 20:5-10 and fig. 2E).
b. Detect, based on the monitoring, that the first data interaction has been performed in relation to the first user using a first communication channel of the plurality of communication channels (monitoring the extended user session tracking) (Skarphedinsson, 39:42-64).
c. Determine that the data breach associated with the first communication channel can cause a second data breach associated with a second communication channel of the plurality of communication channels (a pattern associated with anomalous behavior (data breach) includes variations of the pattern) (Skarphedinsson, 111:24-53).
d. Determine one or more second remediation methods that are to be used to avoid theft of data associated with the second communication channel (data platforms have remediation services) (Skarphedinsson, 4:21-34).
e. Implement the one or more second remediation methods in real time to avoid theft of data associated with the second communication channel (carrying out remedial actions) (Skarphedinsson, 74:54-75:8).
As to claims 7 and 14, teaches the plurality of communication channels comprise email, social media, mobile application, and web application (email) (Skarphedinsson, 23:33-45).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM S POWERS whose telephone number is (571)272-8573. The examiner can normally be reached M-F 7:30-17:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached at (571) 272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/WILLIAM S POWERS/Primary Examiner, Art Unit 2496