DETAILED ACTION
Claims 31-39, 41-49 and 51-59 are pending. Claims 1-30, 40, 50 and 60 are canceled. Claims 31, 41 and 51 are amended. This is in response to Applicants’ arguments and amendments filed on June 24, 2026.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claims 31, 41 and 51 have been considered but are moot because the new ground of rejection necessitated by the amendments to the claims.
The 112 rejection is withdrawn in view of the amendments to the claims.
Regarding the 101 rejection, the rejection is maintained because the computer program product is interpreted as a piece of software. Whether this software resides on any physical medium such as a hard drive or a CD, etc. does not make it eligible as one of the four patent eligible subject matters.
This action is Final.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claim 31-39 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 9 of U.S. Patent No. 12,223,048. Although the claims at issue are not identical, they are not patentably distinct from each other because they both recite similar features as follows:
Claim 31 Claims 1 & 9 of Patent 12,223,048
receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms;
processing the plurality of detection events using a machine learning model to identify attack patterns defined within the plurality of detection events, thus defining one or more identified attack patterns;
defining a new customer specific technology rule based upon the one or more identified attack patterns; directly detecting security events on one or more pieces of customer technology using the new customer specific technology rule including:
detecting a currently ongoing activity within the one or more computing platforms; determining that the currently ongoing activity matches a portion of an identified attack pattern; and initiating an investigation concerning the currently ongoing activity to determine if the currently ongoing activity includes
additional aspects of the identified attack pattern;
directly executing a remedial action plan via the one or more pieces of customer technology.
receiving a plurality of detection events concerning a plurality of security events occurring on the multiple security-relevant subsystems within the one or more computing platforms;
processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository, thus defining one or more identified attack patterns;
defining a new detection rule based, at least in part, upon the one or more identified attack patterns and the one or more current detection rules, wherein defining the new detection rule includes: defining a universal rule;
(claim 9) initiating an investigation of current activity within the one or more computing platforms based, at least in part, upon the current activity being similar to the one or more identified attack patterns.
directly executing a remedial action plan via the one or more pieces of customer technology.
Claims 41-49 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 10 and 18 of U.S. Patent No. 12,223,048. Although the claims at issue are not identical, they are not patentably distinct from each other for the same reasoning presented in claim 31 rejection.
Claims 51-59 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 19 and 27 of U.S. Patent No. 12,223,048. Although the claims at issue are not identical, they are not patentably distinct from each other for the same reasoning presented in claim 31 rejection.
This is an anticipatory rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 41-49 are rejected because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because computer program product is interpreted as software per se. Note that the claims recite the computer program product residing on the computer readable medium (CRM) where the CRM is defined as hardware does not make the claim eligible. To overcome the rejection, Applicant can rewrite the claim as a non-transitory computer readable medium comprising a computer program product having a plurality of instructions stored thereon etc.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 31-60 are rejected under 35 U.S.C. 103 as being unpatentable over Pub CA-2428192-C (hereinafter Newton) in view of Pub WO-2017193036-A1 (hereinafter Zhao) and further in view of Patent 10,313,379 (hereinafter Han)
Regarding claim 31, Newton discloses a computer-implemented method, executed on a computing device, comprising:
receiving a plurality of detection events concerning a plurality of security events occurring on multiple security-relevant subsystems within one or more computing platforms (Figs. 1-3, pages 6-10 disclose the master NID 12 (Network Intelligence Database) with NID device agents for IDS 42, firewall 44, servers 46 (web,
email), PCs 48 and routers 50 to provide protection for any security event detected as an improved IDS);
Newton does not expressly disclose processing the plurality of detection events using a machine learning model to identify attack patterns defined within the plurality of detection events, thus defining one or more identified attack patterns. Zhao discloses analyzing events for malware using machine learning model such as Apriori, Support Vector, Neural network, etc. For example, Zhao provides an example to determine informative sequence patterns in the filename/filepath in order to differentiate legitimate filenames/filepaths from suspicious filenames/filepaths (Figs 1-2, 6 and par. [0025]-[0044] and [0054]-[0058]). Therefore, it would have been obvious before the effective filing date of the claimed invention to modify Newton with Zhao to further teach the aforementioned feature. One would have done so for dynamically detecting and analyzing malware in order to provide effective and accurate protection against malware with the utilization of machine learning models.
Newton discloses defining a new customer specific technology rule based upon the one or more identified attack patterns; directly detecting security events on one or more pieces of customer technology using the new customer specific technology rule (pages 9-11 disclose the Policy Enforcer allows an administrator to take conceptual ideas to configure services, and turns them into the technical rules sets that the devices require. Then, the NID device agents are agents that convert policy enforcer rules, which are in a generic format (e.g. universal rule) into specific rules for the device in question. For example, a NID device agent on a LINUX box, which turns the generic rule into a rule for the particular firewall technology on the LINUX box’s rule);
Newton discloses the Master NID comprises all customer NIDs in various platforms (pages 9-10: “…there are NID device agents for IDS 42, firewall 44, servers 46 (web, email), PCs 48 and routers 50…”. Also see the citation above for a policy designed particularly Linux OS). Hence, Newton teaches the new customer specific technology rule including:
detecting a currently ongoing activity within the one or more computing platforms and determining that the currently ongoing activity matches a portion of an identified attack pattern (any event detected not accepted by the policy enforcer is considered as an attack. In another word, any malicious event matched from the master NID will be identified as an attack pattern. See page 12 for the type of data the master NID stores). However, Newton does not expressly disclose in detail the new customer specific technology rule including:
initiating an investigation concerning the currently ongoing activity to determine if the currently ongoing activity includes additional aspects of the identified attack pattern. Han discloses a method for making security-related predictions by gathering information that includes both a plurality of signatures of a plurality of events that occurred on a plurality of computing systems (e.g. a plurality of devices in different platforms) in a consecutive time slots, where the gathered information to train a machine learning model to create a latent feature that represents security postures of the computing systems that correlate with signatures and incident labels and for each time slot in the consecutive time slots (Summary section). Han further discloses detecting a virus event to generate a signature of the virus detection event. Han also discloses signatures of the same events may be similar or identical. For example, a security product that produces a signature of a failed login attempt on one computing device may produce the same signature as the same product that observes a failed login attempt on a different computing device. In other aspect, different products may produce the same signatures for the same events (Fig. 3 and related text, the cited above is from col 7). Therefore, it would have been obvious before the effective filing date of the claimed invention to modify Newton and Zhao with Han to further teach the aforementioned feature. One would have done so using the malware prediction process based on machine learning models taught in Han to arrive at the claimed invention with reasonable expectation of success.
Newton discloses directly executing a remedial action plan via the one or more pieces of customer technology (page 10, last three paragraphs disclose the Policy Enhancer PE and NID agents work in tandem to provide remedial action).
Regarding claim 32, Newton discloses wherein the plurality of security events includes one or more of: Denial of Service (DoS) events; Distributed Denial of Service DDoS events; Man-in-the-Middle (MitM) events; phishing events; Password Attack events; SQL Injection events; Cross-Site Scripting (XSS) events; Insider Threat events; spamming events; malware events; web attacks; and exploitation events (pages 6-7 discloses a Network Intelligence database storing Hostility level on the Internet and Security event history).
Regarding claim 33, Newton discloses wherein the security-relevant subsystems include one or more of: CDN (i.e., Content Delivery Network) systems; DAM (i.e., Database Activity Monitoring) systems; UBA (i.e., User Behavior Analytics) systems; MDM (i.e., Mobile Device Management) systems; IAM (i.e., Identity and Access Management) systems; DNS (i.e., Domain Name Server) systems; Antivirus systems; operating systems; data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform (pages 6-7 discloses the Network Intelligence Database storing a large number of security-related properties).
Regarding claim 34, Newton discloses wherein the one or more computing platforms includes: a first computing platform of a first client; and at least a second computer platform of at least a second client (see claim 31 rejection for providing an IDS to a pluralities of customers).
Regarding claim 35, Newton discloses wherein one or more artifacts / log entries are associated with each of the plurality of detection events (Fig. 3 and pages 6-7 and 10-13 discloses there are different NID agents and each monitor each subsystem such as firewall, email server, enterprise PCs, etc.).
Regarding claim 36, the combination of Newton and Zhao discloses wherein processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events stored within the event repository includes: processing the event repository using a machine learning model to identify attack patterns defined within the plurality of detection events and their associated artifacts / log entries stored within the event repository (Zhao discloses using the more than one machine learning model to analyze events in a dataset. Newton discloses NID agents monitoring events across the plurality of security devices for identifying normal and abnormal data traffic patterns shown in Fig. 3).
Regarding claim 37, the combination of Newton and Zhao discloses soliciting human feedback concerning the one or more identified attack patterns; and utilizing the human feedback to train the machine learning model (Newton, pages 9-11 discloses using an administrator to defines rules for each customer based on current events obtained in the master database where the Policy Enforcer allows the administrator to take conceptual ideas to configure services, and turns them into the technical rules sets that the devices require. Then, the NID device agents are agents that convert policy enforcer rules, which are in a generic format (e.g. universal rule) into specific rules for the device in question).
Regarding claim 38, the combination of Newton and Zhao discloses defining a new detection rule based, at least in part, upon the one or more identified attack patterns (see claim 31 rejection for similar claimed feature).
Regarding claim 39, the combination of Newton and Zhao discloses modifying an existing detection rule based, at least in part, upon the one or more identified attack patterns (see claim 37 rejection. Moreover, Newton, page 10 discloses the Master NID feeds the customers' NIDs updates as new data are collected or changed).
Claims 41-49 and 51-49 are the system and product claims of claims 31-39. Therefore, claims 41-49 and 51-59 are rejected in view of claims 31-39 respectively.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Inquiry communication
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRI M TRAN whose telephone number is (571)270-1994. The examiner can normally be reached Mon-Fri: 9am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TRI M TRAN/Primary Examiner, Art Unit 2432