DETAILED ACTION
Notice of Pre-AIA or AIA Status
1.The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
2. Applicant's arguments filed on 06/05/2026 with respect to 112(f) claim interpretation have been fully considered but they are not persuasive.
3. Applicant argues that the terms “station” and “control module” should not be interpreted under 112(f) because the terms allegedly have well-understood structural meanings. Applicant further points to the specification disclosure and states that a station may include a process controller and control logic, and argues that module is understood in computing and control systems to refer to a hardware or software component.
4. Examiner would like to point out that the term “module” is recited as a generic component followed by extensive functional language, i.e., “configured to perform” receiving control values, determining anomalous activity, projecting cumulative damage, generating possible actions, identifying a combination of actions, and causing downstream stations to perform the combination. The claim does not identify particular structure components that perform these functions. Thus, the term “control module”, in the context of the claim, operates as generic placeholder for structure that performs the recited functions. And regarding the term “station”, the specification demonstrate that “station” is broadly used to encompass different types of processing structures. The mere disclosure of examples in the specification does not establish that the claim term itself connotes sufficient structure for performing the claimed functions. Accordingly, the claim terms are not merely reciting know structural components, rather, the claim relies substantially on the functional language to define what the “control module” and “station” are required to do. As such, the interpretation of “control module” and “station” under 112(f) is maintained.
5. Applicants have amended the independent claim(s) 21,28 and 35 and argues that none of the prior art of record discloses the new claimed limitation, which recites: “projecting a cumulative damage to the component, in a final state resulting from continued processing through one or more downstream stations”.
6. Examiner would like to point out that the new secondary reference Clarke (2009/0198464) teaches the above claimed limitation (see, the rejection , below).
Double Patenting
7. The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) -706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-l.jsp.
8. Claims 21-24,26,28-31,33 and 35-38 of the instant application are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1- 3,5,7-10,12,14-17 and 19 of U.S. Patent No 12,153,668. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the current application encompass the same subject matter as the patent claims [such as the manufacturing system includes one or more stations, a monitoring platform, and a control module. Each station of the one or more stations is configured to perform at least one step in a multi-step manufacturing process for a component. The monitoring platform is configured to monitor progression of the component throughout the multi-step manufacturing process. The control module is configured to detect a cyberattack to the manufacturing system. The control module is configured to perform operations. The operations include receiving control values for a first station of the one or more stations. The operations further include determining that there is a cyberattack based on the control values for the first station using one or more machine learning algorithms. The operations further include generating an alert to cease processing of the component. The operations further include correcting errors caused by the cyberattack.], but with obvious wording variations.
"A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi 759 F.2d at 896, 225 USPQat651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness- type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). " ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001).
Claim Interpretation - 35 USC § 112
9. The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. - An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP §2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step for”) in a claim with functional language creates a rebuttable presumption that the claim element is to be treated in accordance with 35 U.S.C. 112(f) (pre-AIA 35 U.S.C. 112, sixth paragraph). The presumption that 35 U.S.C. 112(f) (pre-AIA 35 U.S.C. 112, sixth paragraph) is invoked is rebutted when the function is recited with sufficient structure, material, or acts within the claim itself to entirely perform the recited function.
Absence of the word “means” (or “step for”) in a claim creates a rebuttable presumption that the claim element is not to be treated in accordance with 35 U.S.C112 (f) (pre-AIA 35 U.S.C. 112, sixth paragraph). The presumption that 35 U.S.C. 112(f) (pre-AIA 35 U.S.C. 112, sixth paragraph) is not invoked is rebutted when the claim element recites function but fails to recite sufficiently definite structure, material or acts to perform that function.
Claim elements in this application that use the word “means” (or “step for”) are presumed to invoke 35 U.S.C. 112(f) except as otherwise indicated in an Office action. Similarly, claim elements that do not use the word “means” (or “step for”) are presumed not to invoke 35 U.S.C.112 (f) except as otherwise indicated in an Office action.
10. Claim 21 recites the limitation, “a manufacturing system, comprising: a plurality of stations, each station configured to perform at least one step in a multi-step manufacturing process for a component; and a control module configured to detect anomalous activity in the manufacturing system, the control module configured to perform operations, comprising: receiving control values for a first station of the plurality of stations,”, which have been interpreted under 35 U.S.C. 112, sixth paragraph, because it uses a non-structural term “station”, “module” coupled with functional language “configured to” without reciting sufficient structure to achieve the function. Furthermore, the non-structural term is not preceded by a structural modifier.
Since these claim limitations invoke 35 U.S.C. 112, sixth paragraph, claims are interpreted to cover the corresponding structure described in the specification that achieves the claimed function, and equivalents thereof.
A review of the specification shows that the following appears to be the corresponding structure described in the specification for the 35 U.S.C. 112, sixth paragraph limitation: See fig. 1 and associated paragraphs 0016-0017, 0022-0024 and 0026-0027 (the cited paragraphs state that the term “station”, “module” is understood to encompass a tangible entity...physically constructed).
If applicant wishes to provide further explanation or dispute the examiner’s interpretation of the corresponding structure, applicant must identify the corresponding structure with reference to the specification by page and line number, and to the drawing, if any, by reference characters in response to this Office action.
If applicant does not wish to have the claim limitation treated under 35 U.S.C. 112, sixth paragraph, applicant may amend the claim so that it will clearly not invoke 35 U.S.C. 112, sixth paragraph, or present a sufficient showing that the claim recites sufficient structure, material, or acts for performing the claimed function to preclude application of 35 U.S.C. 112, sixth paragraph.
For more information, see Supplementary Examination Guidelines for Determining Compliance with 35 U.S.C. §112 and for Treatment of Related Issues in Patent Applications, 76 FR 7162, 7167 (Feb. 9, 2011).
Claim Rejections - 35 USC § 103
11. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
12. Claim(s) 21-22, 24-29,31-36 and 38-40 are rejected under 35 U.S.C. 103 as being unpatentable over unpatentable over Abbaszadeh (US Pub.No.2018/0157831) in view of Fellows (US Pub.No.2019/0260781) and further in view of Clarke (US Pub.No.2009/0198464).
13. Regarding claims 21, 28 and 35 Abbaszadeh teaches a manufacturing system, a method and a non-transitory computer readable medium comprising: a plurality of stations, each station configured to perform at least one step in a multi-step manufacturing process for a component; and a control module configured to detect anomalous activity in the manufacturing system, the control module configured to perform operations, comprising: receiving control values for a first station of the plurality of stations, the control values comprising attributes of the first station; determining that anomalous activity is present in the manufacturing system based on the control values for the first station (Fig.1 and Para:0026 teaches to protect an industrial asset from cyber-threats in an automatic and accurate manner, the system 100 include a normal space data source 110 and a threatened space data source 120. The normal space data source 110 might store, for each of a plurality of monitoring nodes 130 (shown in FIG. 1 as “MN.sub.1,” “MN.sub.2,” . . . , “MN.sub.N” for “1, 2, . . . , N” different monitoring nodes [one or more stations herein]), a series of normal values over time that represent normal operation of an industrial asset (e.g., generated by a model or collected from actual monitoring node 130 data as illustrated by the dashed line in FIG. 1). The monitoring node might refer to, for example, sensor data, signals sent to actuators, motors, pumps, and auxiliary equipment, intermediary parameters that are not direct sensor signals not the signals sent to auxiliary equipment, and/or control logical(s). These may represent, for example, threat monitoring nodes that receive data from the threat monitoring system in a continuous fashion in the form of continuous signals or streams of data or combinations thereof. Moreover, the nodes will be used to monitor occurrences of cyber-threats or abnormal events. The threatened space data source 120 will store, for each of the monitoring nodes 130, a series of threatened values that represent a threatened operation of the industrial asset (e.g., when the system is experiencing a cyber-attack. Para:0003 and Fig.2, Para:0032-0035 teaches the threat detection computer platform will receive a plurality of real-time monitoring node signal values over time that represent a current operation of the industrial asset. For each stream of monitoring node signal values, the platform may generate a current monitoring node feature vector. The feature vector will also be estimated using a dynamic model associated with that monitoring node signal values. The monitoring node values will also be normalized. The platform will then compare the feature vector with a corresponding decision boundary for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node. The platform will detect that a particular monitoring node has passed the corresponding decision boundary and classify that particular monitoring node as being under attack);
projecting a cumulative damage to the component as a result of the anomalous activity; generating, via one or more deep reinforcement learning techniques, and based on the determination, generating one or more actions (Para:0027 and Para:0032-0035 teaches the information from the normal space data source 110 and the threatened space data source 120 will be provided to a threat detection model creation computer 140 that uses this data to create a decision boundary (that is, a boundary that separates normal behavior from threatened behavior). The decision boundary will then be used by a threat detection computer 150 executing a threat detection model 155. The threat detection model 155 may, for example, monitor streams of data from the monitoring nodes 130 comprising data from sensor nodes, actuator nodes, and/or any other critical monitoring nodes (e.g., monitoring nodes MN.sub.1 through MN.sub.N), calculate at least one “feature” for each monitoring node based on the received data, and automatically output a threat alert signal to one or more remote monitoring devices 170 when appropriate (e.g., for display to a user). A threat alert signal might be transmitted to a unit controller, a plant Human-Machine Interface (HMI), or to a customer via a number of different transmission methods. Para:0035 teaches the mitigation action also includes the system will automatically shut down all or a portion of the industrial asset to let the detected potential cyber-attack be further investigated).
Abbaszadeh teaches all the above claimed limitations but does not expressly teach generating, a plurality of possible actions to minimize the cumulative damage to the component; and identifying a combination of one or more actions from the plurality of possible actions that yields a greatest correction in the cumulative damage; and causing one or more downstream stations to perform the combination of the one or more actions to minimize the cumulative damage to the component.
Fellows teaches generating, a plurality of possible actions to minimize the cumulative damage to the component; and identifying a combination of one or more actions from the plurality of possible actions that yields a greatest correction in the cumulative damage; and causing one or more downstream stations to perform the combination of the one or more actions to minimize the cumulative damage to the component (Para:0049-0050 teaches the cyber-threat module can assign a threat level parameter (e.g. score or probability) indicative of what level of threat does this malicious actor pose to the system. These can be combined/factored into a single score. The score may be an actual score, a percentage, a confidence value, or other indicator on a scale. The cyber-security appliance 100 is configurable in its user interface of the cyber-security appliance 100 on what type of automatic response actions, if any, the cyber-security appliance 100 may take when for different types of cyber threats that are equal to or above a configurable level of threat (threat level parameter) posed by a detected malicious actor/cyber-threat. The OT (operational technology) module, cyber-threat module, and informational technology module referencing their respective machine-learning models are capable of learning what ‘normal’ activity looks like within an example industrial network, and can identify and respond to emerging threats and potential malfunctions that would otherwise go unnoticed.
Para:0091, Para:0095-0096 teaches machine learning can be used to figure out what suggestions to make on the type of autonomous actions to take counter a potential cyber-threat the series of those actions. The autonomous response module can be configured to take specific limited options, such as block TCP connections as well as configure specific areas and scenarios requiring human approval or intervention before generating the response to the cyber-threat in that zone. The autonomous response module can take actions based on both severity of threat and actual impact on the industrial network of taking that action, where the real world physical consequences on a product in the industrial environment of taking an action can ruin or damage the product compared to shutting down access to a port in the digital information technology environment. Note, the autonomous response module can also take targeted autonomous actions on components in the OT (Industrial) environment facilitated by machine-learning models. For example, the autonomous response module can take a first minor corrective action and if that does not counter the cyber-threat, then start escalating the types of corrective actions to ultimately shutting down equipment).
Therefore, it would have been obvious to one of ordinary skill in the art before the invention was filing to modify Abbaszadeh to include generating, a plurality of possible actions to minimize the cumulative damage to the component; and identifying a combination of one or more actions from the plurality of possible actions that yields a greatest correction in the cumulative damage; and causing one or more downstream stations to perform the combination of the one or more actions to minimize the cumulative damage to the component, as taught by Fellows such a setup will give a predictable result of identifying a possible cyberattack based on the process data, and taking appropriate action to correct the damage caused by the cyberattack.
Both Abbaszadeh in view of Fellows teaches all the above claimed limitations but do not expressly teach projecting a cumulative damage to the component, in a final state resulting from continued processing through one or more downstream stations.
Clarke teaches projecting a cumulative damage to the component, in a final state resulting from continued processing through one or more downstream stations (Figs.3,4 and Para:0026-0031 teaches extracting an image of an object, identifying object features; determines whether all the components have been inspected (element.39 in fig.3) and comparing the identified object features with corresponding component features. When the features do not match, the process proceeds to diagnose and indicate fault (elements.381 and 382 in fig.3). The process may then continue to inspect additional components until all components have been inspected.
As such, it tracks damage/degradation as a component moves through multiple stations; accumulating damage/ or fault associated with the repeated processing and predict/project the damage at a later/final stage).
Therefore, it would have been obvious to one of ordinary skill in the art before the invention was filing to modify Abbaszadeh in view of Fellow to include projecting a cumulative damage to the component, in a final state resulting from continued processing through one or more downstream stations, as taught by Clarke such a setup will give a predictable result of providing continued inspection and fault diagnosis when component features do not match the expected features.
14. Regarding claims 22,29 and 36 Abbaszadeh teaches the manufacturing system, the method and the non-transitory computer readable medium, wherein determining that anomalous activity is present in the manufacturing system based on the control values for the first station comprises: generating, using a Kalman filter (Para:0038 and Para:0059 teaches Kalman Filtering), an anomaly score for the first station based on the control values; and determining that the anomaly score exceeds a threshold value indicative of anomalous activity (Para:0059, Para:0032-0035 and Para:0026-0027 and to protect an industrial asset from cyber-threats in an automatic and accurate manner. . The system 100 may include a normal space data source 110 and a threatened space data source 120. The normal space data source 110 might store, for each of a plurality of “monitoring nodes” 130 (shown in FIG. 1 as “MN.sub.1,” “MN.sub.2,” . . . , “MN.sub.N” for “1, 2, . . . , N” different monitoring nodes), a series of normal values over time that represent normal operation of an industrial asset (e.g., generated by a model or collected from actual monitoring node 130 data as illustrated by the dashed line in FIG. 1). As used herein, the phrase “monitoring node” might refer to, for example, sensor data, signals sent to actuators, motors, pumps, and auxiliary equipment, intermediary parameters that are not direct sensor signals not the signals sent to auxiliary equipment, and/or control logical(s). These may represent, for example, threat monitoring nodes that receive data from the threat monitoring system in a continuous fashion in the form of continuous signals or streams of data or combinations thereof. Moreover, the nodes may be used to monitor occurrences of cyber-threats or abnormal events. The threatened space data source 120 might store, for each of the monitoring nodes 130, a series of threatened values [anomaly score herein] that represent a threatened operation of the industrial asset (e.g., when the system is experiencing a cyber-attack). Information from the normal space data source 110 and the threatened space data source 120 may be provided to a threat detection model creation computer 140 that uses this data to create a decision boundary (that is, a boundary that separates normal behavior from threatened behavior). The decision boundary may then be used by a threat detection computer 150 executing a threat detection model 155. The threat detection model 155 may, for example, monitor streams of data from the monitoring nodes 130 comprising data from sensor nodes, actuator nodes, and/or any other critical monitoring nodes (e.g., monitoring nodes MN.sub.1 through MN.sub.N), calculate at least one “feature” for each monitoring node based on the received data, and “automatically” output a threat alert signal to one or more remote monitoring devices 170 when appropriate e.g., for display to a user).
15. Regarding claims 24,31 and 38 Abbaszadeh teaches the manufacturing system, the method and the non-transitory computer readable medium, wherein determining that anomalous activity is present in the manufacturing system based on the control values for the first station comprises: generating, using a deep learning model, a predicted quality metric for the component based on the control values; and determining that the predicted quality metric falls outside a range of acceptable values (Para:0026-0027 and Fig.2, Para:0032-0035 teaches a plurality of real-time monitoring node signal inputs may receive streams of monitoring node signal values over time that represent a current operation of an industrial asset. At least one of the monitoring nodes (e.g., control nodes, etc.) may be associated with, for example, sensor data, an auxiliary equipment input signal, a control intermediary parameter, valves, circuit breakers, and/or a control logic value. At S220, a threat detection computer platform may receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a feature vector for the current monitoring node using the current monitoring node signal values. At least one of the current monitoring node feature vectors is associated with principal components, statistical features, deep learning features, frequency domain features, time series analysis features, logical features, geographic or position-based locations, and/or interaction features. At S230, each generated current monitoring node feature vector may be compared to a corresponding decision boundary (e.g., a linear boundary, non-linear boundary, multi-dimensional boundary, etc.) for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node. According to some embodiments, at least one monitoring node is associated with a plurality of multi-dimensional decision boundaries and the comparison at S230 is performed in connection with each of those boundaries. Note that a decision boundary might be generated, for example, in accordance with a feature-based learning algorithm and a high-fidelity model or a normal operation of the industrial asset. At S240, an attack identified at S230 may be classified as either an “independent attack” or “dependent attack. At S250, the system may automatically transmit a threat alert signal (e.g., a notification message, etc.) based on results of the comparisons performed at S230 along with a classification of the attack (e.g., as determined at S240) and affected nodes. The threat might be associated with, for example, an actuator attack, a controller attack, a monitoring node attack, a plant state attack, spoofing, physical damage, unit availability, a unit trip, a loss of unit life, and/or asset damage requiring at least one new part. According to some embodiments, one or more response actions may be performed when a threat alert signal is transmitted. For example, the system might automatically shut down all or a portion of the industrial asset (e.g., to let the detected potential cyber-attack be further investigated). As other examples, one or more parameters might be automatically modified, a software application might be automatically triggered to capture data and/or isolate possible causes, etc).
16. Regarding claims 25,32 and 39 Abbaszadeh teaches the manufacturing system, the method and the non-transitory computer readable medium, wherein projecting the cumulative damage to the component as a result of the anomalous activity comprises: detecting damage or an error at a given station of the plurality of stations (Abbaszadeh: Para:0026-0027 and Fig.2, Para:0032-0035 teaches a plurality of real-time monitoring node signal inputs may receive streams of monitoring node signal values over time that represent a current operation of an industrial asset. At least one of the monitoring nodes (e.g., control nodes, etc.) may be associated with, for example, sensor data, an auxiliary equipment input signal, a control intermediary parameter, valves, circuit breakers, and/or a control logic value. At S220, a threat detection computer platform may receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a feature vector for the current monitoring node using the current monitoring node signal values. At least one of the current monitoring node feature vectors is associated with principal components, statistical features, deep learning features, frequency domain features, time series analysis features, logical features, geographic or position-based locations, and/or interaction features. At S230, each generated current monitoring node feature vector may be compared to a corresponding decision boundary (e.g., a linear boundary, non-linear boundary, multi-dimensional boundary, etc.) for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node. According to some embodiments, at least one monitoring node is associated with a plurality of multi-dimensional decision boundaries and the comparison at S230 is performed in connection with each of those boundaries. Note that a decision boundary might be generated, for example, in accordance with a feature-based learning algorithm and a high-fidelity model or a normal operation of the industrial asset. At S240, an attack identified at S230 may be classified as either an “independent attack” or “dependent attack. At S250, the system may automatically transmit a threat alert signal (e.g., a notification message, etc.) based on results of the comparisons performed at S230 along with a classification of the attack (e.g., as determined at S240) and affected nodes. The threat might be associated with, for example, an actuator attack, a controller attack, a monitoring node attack, a plant state attack, spoofing, physical damage, unit availability, a unit trip, a loss of unit life, and/or asset damage requiring at least one new part. According to some embodiments, one or more response actions may be performed when a threat alert signal is transmitted. For example, the system might automatically shut down all or a portion of the industrial asset (e.g., to let the detected potential cyber-attack be further investigated). As other examples, one or more parameters might be automatically modified, a software application might be automatically triggered to capture data and/or isolate possible causes, etc).
17. Regarding claims 26,33 and 40 Abbaszadeh teaches the manufacturing system, the method and the non-transitory computer readable medium, further comprising: issuing an alert indicating a presence of anomalous activity, wherein the alert is a signal that stops or ceases processing of each of the plurality of stations (Abbaszadeh: Para:0026-0027 and Fig.2, Para:0032-0035 teaches a plurality of real-time monitoring node signal inputs may receive streams of monitoring node signal values over time that represent a current operation of an industrial asset. At least one of the monitoring nodes (e.g., control nodes, etc.) may be associated with, for example, sensor data, an auxiliary equipment input signal, a control intermediary parameter, valves, circuit breakers, and/or a control logic value. At S220, a threat detection computer platform may receive the streams of monitoring node signal values and, for each stream of monitoring node signal values, generate a feature vector for the current monitoring node using the current monitoring node signal values. At least one of the current monitoring node feature vectors is associated with principal components, statistical features, deep learning features, frequency domain features, time series analysis features, logical features, geographic or position-based locations, and/or interaction features. At S230, each generated current monitoring node feature vector may be compared to a corresponding decision boundary (e.g., a linear boundary, non-linear boundary, multi-dimensional boundary, etc.) for that monitoring node, the decision boundary separating a normal state from an abnormal state for that monitoring node. According to some embodiments, at least one monitoring node is associated with a plurality of multi-dimensional decision boundaries and the comparison at S230 is performed in connection with each of those boundaries. Note that a decision boundary might be generated, for example, in accordance with a feature-based learning algorithm and a high-fidelity model or a normal operation of the industrial asset. At S240, an attack identified at S230 may be classified as either an “independent attack” or “dependent attack. At S250, the system may automatically transmit a threat alert signal (e.g., a notification message, etc.) based on results of the comparisons performed at S230 along with a classification of the attack (e.g., as determined at S240) and affected nodes. The threat might be associated with, for example, an actuator attack, a controller attack, a monitoring node attack, a plant state attack, spoofing, physical damage, unit availability, a unit trip, a loss of unit life, and/or asset damage requiring at least one new part. According to some embodiments, one or more response actions may be performed when a threat alert signal is transmitted. For example, the system might automatically shut down all or a portion of the industrial asset (e.g., to let the detected potential cyber-attack be further investigated). As other examples, one or more parameters might be automatically modified, a software application might be automatically triggered to capture data and/or isolate possible causes, etc).
18. Regarding claims 27 and 34 Abbaszadeh teaches the manufacturing system, and the method wherein the control values are attributes or parameters associated with the first station (Para:0059, Para:0032-0035 and Para:0026-0027 and to protect an industrial asset from cyber-threats in an automatic and accurate manner. . The system 100 may include a normal space data source 110 and a threatened space data source 120. The normal space data source 110 might store, for each of a plurality of “monitoring nodes” 130 (shown in FIG. 1 as “MN.sub.1,” “MN.sub.2,” . . . , “MN.sub.N” for “1, 2, . . . , N” different monitoring nodes), a series of normal values over time that represent normal operation of an industrial asset (e.g., generated by a model or collected from actual monitoring node 130 data as illustrated by the dashed line in FIG. 1). As used herein, the phrase “monitoring node” might refer to, for example, sensor data, signals sent to actuators, motors, pumps, and auxiliary equipment, intermediary parameters that are not direct sensor signals not the signals sent to auxiliary equipment, and/or control logical(s). These may represent, for example, threat monitoring nodes that receive data from the threat monitoring system in a continuous fashion in the form of continuous signals or streams of data or combinations thereof. Moreover, the nodes may be used to monitor occurrences of cyber-threats or abnormal events. The threatened space data source 120 might store, for each of the monitoring nodes 130, a series of threatened values [anomaly score herein] that represent a threatened operation of the industrial asset (e.g., when the system is experiencing a cyber-attack). Information from the normal space data source 110 and the threatened space data source 120 may be provided to a threat detection model creation computer 140 that uses this data to create a decision boundary (that is, a boundary that separates normal behavior from threatened behavior). The decision boundary may then be used by a threat detection computer 150 executing a threat detection model 155. The threat detection model 155 may, for example, monitor streams of data from the monitoring nodes 130 comprising data from sensor nodes, actuator nodes, and/or any other critical monitoring nodes (e.g., monitoring nodes MN.sub.1 through MN.sub.N), calculate at least one “feature” for each monitoring node based on the received data, and “automatically” output a threat alert signal to one or more remote monitoring devices 170 when appropriate e.g., for display to a user).
19. Claim(s) 23,30 and 37 are rejected under 35 U.S.C. 103 as being unpatentable over Abbaszadeh (US Pub.No.2018/0157831) in view of Fellows (US Pub.No.2019/0260781) and in view of Clarke (US Pub.No.2009/0198464) as applied to claims 21, 28 and 35 above and further in view of Cella (US Pub.No.2018/0321667).
20. Regarding claims 23, 30 and 37 Abbaszadeh teaches the manufacturing system, the method and the non-transitory computer readable medium, wherein determining that anomalous activity is present in the manufacturing system based on the control values for the first station comprises: generating, an anomaly score for the first station based on the control values; and determining that the anomaly score exceeds a threshold value indicative of anomalous activity (Para:0059, Para:0032-0035 and Para:0026-0027 and to protect an industrial asset from cyber-threats in an automatic and accurate manner. . The system 100 may include a normal space data source 110 and a threatened space data source 120. The normal space data source 110 might store, for each of a plurality of “monitoring nodes” 130 (shown in FIG. 1 as “MN.sub.1,” “MN.sub.2,” . . . , “MN.sub.N” for “1, 2, . . . , N” different monitoring nodes), a series of normal values over time that represent normal operation of an industrial asset (e.g., generated by a model or collected from actual monitoring node 130 data as illustrated by the dashed line in FIG. 1). As used herein, the phrase “monitoring node” might refer to, for example, sensor data, signals sent to actuators, motors, pumps, and auxiliary equipment, intermediary parameters that are not direct sensor signals not the signals sent to auxiliary equipment, and/or control logical(s). These may represent, for example, threat monitoring nodes that receive data from the threat monitoring system in a continuous fashion in the form of continuous signals or streams of data or combinations thereof. Moreover, the nodes may be used to monitor occurrences of cyber-threats or abnormal events. The threatened space data source 120 might store, for each of the monitoring nodes 130, a series of threatened values [anomaly score herein] that represent a threatened operation of the industrial asset (e.g., when the system is experiencing a cyber-attack). Information from the normal space data source 110 and the threatened space data source 120 may be provided to a threat detection model creation computer 140 that uses this data to create a decision boundary (that is, a boundary that separates normal behavior from threatened behavior). The decision boundary may then be used by a threat detection computer 150 executing a threat detection model 155. The threat detection model 155 may, for example, monitor streams of data from the monitoring nodes 130 comprising data from sensor nodes, actuator nodes, and/or any other critical monitoring nodes (e.g., monitoring nodes MN.sub.1 through MN.sub.N), calculate at least one “feature” for each monitoring node based on the received data, and “automatically” output a threat alert signal to one or more remote monitoring devices 170 when appropriate e.g., for display to a user).
Abbaszadeh in view of Fellows and in view of teaches all the above claimed limitations but does not expressly teach generating, using an autoencoder an anomaly score.
Cella teaches generating, using an autoencoder an anomaly score (Para:0924, 0946 and para:1111 teaches generating, using an autoencoder a score).
Therefore, it would have been obvious to one of ordinary skill in the art before the invention was filing to modify Abbaszadeh in view of Fellows and in view of Clarke to include generating, using an autoencoder an anomaly score, as taught by Cella such a setup will be used to self-learn an efficient network coding for transmission of analog sensor data from an industrial machine over one or more networks (para:0946).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEREENA T CATTUNGAL whose telephone number is (571)270-0506. The examiner can normally be reached Mon-Fri : 7:30 AM-5 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DEREENA T CATTUNGAL/Primary Examiner, Art Unit 2431