Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Regarding claim 6, claim 6 depends from claim 3 and recites "a third action is based on the second anomaly category." Claim 3 recites a first, a second, and a third anomaly category. Claim 5, which also depends from claim 3, recites that "a second action is based on the second anomaly category (the second anomaly category) that claim 5 associates with the second action, while no action is associated with the third anomaly category recited in claim 3. It is unclear whether claim 6's recitation of "the second anomaly category" is correct or is a typographical error for "the third anomaly category." As a result, the metes and bounds of the claim cannot be determined with reasonable certainty. Clarification and/or correction is required.
Regarding claim 16, claim 16 recites a substantially identical limitation and is rejected under 35 U.S.C. 112(b) for the same reasons set forth above with respect to claim 6.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The references relied upon in the following rejections are:
Albero et al. (US-20210110407-A1), hereinafter “Albero.”
Jason et al. (US-20220269911-A1), hereinafter “Jason.”
Holland (WO-2022213202-A1), hereinafter “Holland.”
Shachaf et al. (US-20240143828-A1), hereinafter, “Shachaf.”
Li et al. (US-20260162416-A1), hereinafter, “Li.”
Konduru et al. (US-20250217241-A1), hereinafter “Konduru.”
Ogawa (US-12652306-B2), hereinafter “Ogawa.”
Claims 1, 8, 9, 10, 11, 18, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Albero in view of Jason, Holland, and Shachaf.
Regarding claim 1, claim 1 recites "A computing platform comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to" perform the recited operations. Albero provides for this limitation. Albero discloses a multi-source anomaly detection computing platform 110 with one or more processors 111, memory 112, and a communication interface 113 (Albero, [0029]). The memory stores instructions that, when executed by the processor, cause the platform to perform the described operations (Albero, [0029]).
Claim 1 further recites "train, based on historical screenshots, an artificial intelligence (AI) engine, wherein the training configures the AI engine to output an executable action to resolve an anomaly within an application session." Albero does not provide for training an AI engine based on screenshots. Jason provides for part of this limitation. Jason discloses training an auto-encoder, which is a neural network, on screenshots of a module. The auto-encoder is trained to receive screenshots and compare them to anticipated screenshots (Jason, [0029], [0041], [0005]). The disclosed auto-encoder corresponds to the claimed AI engine. The screenshots it is trained on correspond to the claimed historical screenshots. As discussed below for the outputting and executing limitations, the output action is an action that resolves an anomaly, as provided for by Albero.
Claim 1 further recites "configure one or more anomaly detection rules." Holland provides for this limitation. Holland discloses that an operator defines threats as access control lists (ACLs) and execution control lists (ECLs) (Holland, [0028]). The ACLs/ECLs are provided as one or more policy structures, which specify the operating-system events to be detected and acted upon (Holland, [0028], [0031]). The disclosed operator-defined policy structures correspond to the claimed configured anomaly detection rules.
Claim 1 further recites "deploy the one or more anomaly detection rules to a user device, wherein deploying the one or more anomaly detection rules configures the user device to enforce the one or more anomaly detection rules locally, and wherein the user device establishes a first application session with a first application server via a web browser." Holland provides for part of this limitation. Holland discloses that the policy structures are distributed to endpoints, and that endpoint detection and response (EDR) functionality runs on each endpoint (Holland, [0028]). An agent on the endpoint enforces the policies, and the policies can be added to, modified, and removed from the agent (Holland, [0058]). The disclosed distribution of the policy structures to the endpoint corresponds to the claimed deploying of the anomaly detection rules to a user device. The agent enforcing the policies at the endpoint corresponds to the claimed enforcing of the rules locally. However, Holland does not expressly provide for the user device establishing a first application session with a first application server via a web browser. Albero and Shachaf provide for this part of the limitation. Albero discloses that the system operates in a client-server configuration that permits a user to retrieve web pages from a web-based server (Albero, [0100]). Shachaf discloses that the captured screenshots are of applications and web pages in the user's browser window during the user's work (Shachaf, [0115], [0128]). The disclosed user retrieving web pages from a web-based server, while working in a browser window, corresponds to the claimed user device establishing a first application session with a first application server via a web browser.
Claim 1 further recites "receive, based on the user device detecting a first anomaly using the one or more anomaly detection rules that were deployed by the computing platform, an encrypted screenshot from the user device." Holland provides for part of this limitation. Holland discloses that access/execution control functionality on the endpoint receives notifications of operating-system events (Holland, [0035]). The functionality matches those events to the deployed ACLs/ECLs and identifies whether a violation has occurred (Holland, [0035], [0037]). The disclosed endpoint identifying a violation of the deployed policies corresponds to the claimed user device detecting a first anomaly using the deployed anomaly detection rules. Holland does not expressly provide for the received information being an encrypted screenshot. Shachaf provides for this part of the limitation. Shachaf discloses that screenshots are encrypted and then stored or uploaded (Shachaf, [0124], [0136]). The disclosed encrypted screenshot corresponds to the claimed encrypted screenshot received from the user device.
Claim 1 further recites "decrypt the encrypted screenshot." Shachaf provides for this limitation. Shachaf discloses decrypting the encrypted, encoded screenshots (Shachaf, [0094], [0127]).
Claim 1 further recites "input the decrypted screenshot into the AI engine." Jason provides for this limitation. Jason discloses inputting the pre-processed screenshots into the auto-encoder (Jason, [0041]).
Claim 1 further recites "output, based on analyzing the decrypted screenshot using the AI engine, an action to resolve the first anomaly." Jason provides for part of this limitation. Jason discloses using the auto-encoder to analyze each screenshot by identifying a reconstruction error value for the screenshot (Jason, [0042]). Based on the reconstruction error value, an outlier is identified (Jason, [0045]). The disclosed use of the auto-encoder to analyze the screenshot corresponds to the claimed analyzing of the decrypted screenshot using the AI engine. Jason does not expressly provide for outputting an action that resolves the anomaly. Albero provides for this part of the limitation. Albero discloses that, when an anomaly is detected, data associated with the anomaly is compared to pre-stored rules (Albero, [0065], [0080]). If a pre-stored rule applies, an instruction or command is generated to resolve anomaly (Albero, [0066], [0080]). The disclosed generation of an instruction or command that resolves the anomaly corresponds to the claimed outputting of an action to resolve the first anomaly.
Claim 1 further recites "execute the action, wherein the executing comprises sending commands that resolve the first anomaly." Albero provides for this limitation. Albero discloses that the generated instruction or command is transmitted to one or more source computing systems, which carry out the instruction or command (Albero, [0068], [0080]). The disclosed transmission of the instruction or command to the source systems corresponds to the claimed executing of the action by sending commands that resolve the first anomaly.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Albero's anomaly detection and resolution platform to analyze the visual state of the application using Jason's screenshot-trained auto-encoder. Albero detects and resolves anomalies based on attribute data received from source systems. Albero does not analyze a screenshot to identify an anomalous outlier. Applying Jason's auto-encoder would allow the combination to determine, from the visual state of the application captured in a screenshot, the information used to resolve the detected anomaly.
It would further have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Albero so that the anomaly detection rules are deployed to an enforced at the user device, and so that the user device detects the anomaly, as provided for by Holland. Albero detects anomalies at the platform, from data received from source systems. Holland's endpoint agent enforces operator-defined policies that are distributed to the endpoint, and detects violations of those policies locally. Applying Holland's endpoint agent would allow the anomaly to be detected at the user device on which the application session runs, rather than only at the platform. Detecting anomalies at the device where they occur is a known and predictable way of monitoring for them.
It would further have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination so that the screenshot sent from the user device is encrypted before transmission and decrypted upon receipt, as provided for by Shachaf. The screenshot may contain sensitive information displayed in the application. Applying Shachaf's encryption and decryption of screenshots would protect the screenshot while it is transmitted from the user device to the computing platform. Thus, the combination provides for the limitations of claim 1.
Regarding claim 8, claim 8 depends from claim 1 and further recites "update, using a dynamic feedback loop and based on the inputting, the outputting, and the executing, the AI engine." Jason provides for this added limitation. Jason discloses receiving feedback information indicating whether or not an identified outlier permutation was correctly identified as an outlier (Jason, [0011], [0051]). Jason further discloses dynamically tuning the auto-encoder based on the feedback information (Jason, [0011], [0051]). The disclosed dynamic tuning of the auto-encoder, based on feedback about the outliers it identified, corresponds to the claimed dynamic feedback loop used to update the AI engine. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to update the AI engine of the combination using Jason's feedback-based tuning. Doing so would allow the AI engine to be refined based on the accuracy of its prior outputs, improving the accuracy of its subsequent outputs.
Regarding claim 9, claim 9 depends from claim 1 and further recites "generate a report, wherein the report comprises the first anomaly and the action that was executed." Holland provides for this added limitation. Holland discloses that a notification and/or log may be generated upon blocking an event (Holland, [0039]). Holland further discloses that, when a policy is violated and the violating action is blocked, a log is generated that outlines the blocking event (Holland, [0051]). The disclosed log, which is generated upon the blocking action being taken and which outlines the blocking of the violating event, corresponds to the claimed report comprising the first anomaly and the action that was executed. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate such a record in the combination when the resolving action is executed. Doing so creates a record documenting the detected anomaly and the action taken to resolve it.
Regarding claim 10, claim 10 depends from claim 9 and further recites "send, to an enterprise administrative device, the report and one or more commands directing the enterprise administrative device to display the report, wherein sending the one or more commands directing the enterprise administrative device to display the report causes the enterprise administrative device to display the report." Albero provides for this added limitation. Albero discloses that a notification regarding regarding a detected anomaly is transmitted to a computing device for display, such as to an administrator or other supervisory user for evaluation, next steps, and further processing (Albero, [0078]). The notification is transmitted to the device, and is received and displayed by a display of the device (Albero, [0063], [0064]). The disclosed transmission of the notification to the administrator's computing device, which causes the device to display it, corresponds to the claimed sending of the report to an enterprise administrative device and causing that device to display the report. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to transmit the report of the combination to the administrator's device for display, as provided for by Albero. Doing so provides and displays the record of the anomaly and the executed action for the personnel responsible for the system.
Regarding claim 11, claim 11 is a method claim that recites limitations substantially identical to the operations recited in claim 1, performed at a computing platform comprising at least one processor, a communication interface, and memory. The combination of Albero, Jason, Holland, and Shachaf provides for the limitations of claim 11 for the same reasons set forth above with respect to claim 1.
Regarding claim 18, claim 18 contains limitations substantially identical to those of claim 8, and is rejected for the same reasons set forth above with respect to claim 8.
Regarding claim 19, claim 19 contains limitations substantially identical to the combined limitations of claims 9 and 10, and is rejected for the same reasons set forth above with respect to claims 9 and 10.
Regarding claim 20, claim 20 recites "One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to" perform the recited operations. Albero provides for the non-transitory computer-readable media storing instructions. Albero discloses memory storing instructions that are executed by the processor to perform the described operations (Albero, [0029], [0030]). The remaining operations recited in claim 20 are substantially identical to those recited in claim 1, and are rejected for the same reasons set forth above with respect to claim 1.
Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Albero in view of Jason, Holland, and Shachaf, and in further view of Li.
Regarding claim 7, claim 7 depends from claim 1 and further recites "training the AI engine to analyze the historical screenshots using a natural language processing algorithm or an optical character recognition (OCR) algorithm." As discussed above with respect to claim 1, the combination provides for training the AI engine on historical screenshots. The combination does not expressly provide for the training using a natural language processing algorithm or an OCR algorithm. Li provides for this added limitation. Li discloses interpreting natural language as executable actions (Li, [0068]). Li further discloses performing a natural language command grounding task using a neural network that analyzes a screenshot (Li, [0053], [0068]). The disclosed use of natural language processing corresponds to the claimed natural language processing algorithm. This satisfies the recited limitation because the limitation requires only one of a natural language processing algorithm or an OCR algorithm. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to train the AI engine of the combination using Li's natural language processing. Doing so would allow the engine to interpret text displayed in the screenshot when analyzing the screenshot.
Regarding claim 17, claim 17 contains limitations substantially identical to those of claim 7, and is rejected for the same reasons set forth above with respect to claim 7.
Claims 2, 3, 4, 5, 6, 12, 13, 14, 15, and 16 are rejected under U.S.C. 103 as being unpatentable over Albero in view of Jason, Holland, and Shachaf, and in further view of Konduru and Ogawa.
Regarding claim 2, claim 2 depends from claim 1 and further recites that "the one or more anomaly detection rules further comprise: a first rule based on the user device detecting a missing heartbeat from an application server that is hosting the first application session that the user device accesses via a web browser; a second rule based on detecting a different internet protocol (IP) address than an expected IP address; and a third rule based on detecting an application rendering error."
As discussed above with respect to claim 1, Albero in view of Jason, Holland, and Shachaf provides for the limitations of claim 1, including configuring one or more anomaly detection rules. The combination does not expressly provide for the first and second rules recited in claim 2.
Konduru provides for the first rule (A rule based on detecting a missing heartbeat from an application server). Konduru discloses that each fault-tolerance component periodically receives a heartbeat message from the other components (Konduru, [0078]). A failure to receive a heartbeat message within a threshold period of time, such as 10 seconds, indicates that a failure has occurred (Konduru, [0078], [0230]). The disclosed detection of a heartbeat message that is not received in time corresponds to the claimed rule based on detecting a missing heartbeat from an application server.
Ogawa provides for the second rule (a rule based on detecting a different IP address than an expected IP address). Ogawa discloses determining whether a number of different IP addresses attempt to access the same user account (Ogawa, (108)). Such activity is determined to be suspicious (Ogawa, (108)). Ogawa further discloses establishing a baseline or pattern of the typical or normal characteristics, patterns, and behaviors associated with a user (Ogawa, (68)). Activity that does not match the normal pattern is detected (Ogawa, (69)). The disclosed baseline of normal patterns corresponds to the claimed expected IP address, and the disclosed detection of a different IP address accessing the same user account corresponds to the claimed rule based on detecting a different IP address than an expected IP address.
Jason, already relied upon above in the combination, provides for the third rule (a rule based on detecting an application rendering error). Jason discloses detecting permutations of displayable content that are not visually correct, that is, not displayed as they are intended to be displayed (Jason, [0018]). The detected defects include visual defects such as unreadable information (Jason, [0020]). The displayable content includes web pages and user interfaces (Jason, [0058]). Content that is not displayed as it is intended to be displayed is an error in rendering the application's interface. The disclosed detection therefore corresponds to the claimed detection of an application rendering error.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include Konduru's detection of a missing heartbeat in the combination. Doing so allows the system to detect when the application server hosting the user's session has failed, as indicated by a missing heartbeat. It would further have been obvious to include Ogawa's detection of a different IP address accessing the same account. Doing so allows the system to detect when a user's session is accessed from an unexpected IP address. It would further have been obvious to include Jason's detection of displayable content that is not displayed as intended. Doing so allows the system to also detect when the application's interface fails to render correctly. Each of these is known way of identifying a particular type of anomaly affecting a user's application session. Adding them to the combination expands the set of anomalies that the combination can detect.
Regarding claim 3, claim 3 depends from claim 2 and further recites that the anomaly detection rules are categorized into anomaly categories comprising "a first anomaly category based on a site switch, wherein the first rule corresponds to the first anomaly category; a second anomaly category based on a session hijacking attempt, wherein the second rule corresponds to the second anomaly category; and a third anomaly category based on an application error, wherein the third rule corresponds to the third anomaly category."
Konduru provides for the first anomaly category (a site switch). Konduru discloses a failover in which, upon failure of a primary instance, a backup instance takes over for the failed primary instance (Konduru, [0055]. [0216]). The disclosed switch from the failed primary instance to the backup instance corresponds to the claimed site switch. This category corresponds to the first rule because the takeover is triggered by the detected missing heartbeat.
Ogawa provides for the second anomaly category (a session hijacking attempt). Ogawa discloses that access to the same user account from a number of different IP addresses is treated as suspicious activity associated with compromised access (Ogawa, (108)). The disclosed compromised access to a user account from a different IP address corresponds to the claimed session hijacking attempt, and corresponds to the second rule.
Jason provides for the third anomaly category (an application error). Jason discloses that the detected outlier permutations contain visual defects in the displayed content (Jason, [0020]). A visual defect in the displayed content is an error in the display of the application. The disclosed visual defect therefore corresponds to the claimed application error, and corresponds to the third rule.
The motivations to combine set forth above with respect to claim 2 apply equally to the corresponding categories of claim 3.
Regarding claim 4, claim 4 depends from claim 3 and further recites that "a first action is based on the first anomaly category, and wherein the first action comprises: generating instructions based on the analyzing the decrypted screenshot using the AI engine; and sending, to a second application server, the instructions, that when received by a second application server, directs the second application server to re-create the first application session of the first application server."
As discussed above, the combination provides for analyzing the decrypted screenshot using the AI engine and outputting an action based on the analysis. Konduru provides for the added limitation of a second application server that receives instructions and re-creates the first application session. Konduru discloses a failover in which a backup instance takes over for the failed primary instance (Konduru, [0055]). The pre-failure state of the failed primary instance is recovered and restored (Konduru, [0004]). When the backup instance receives a takeover ready message, the backup instance reinstates the current state and resumes processing for the customers (Konduru, [0248], [0216]). The disclosed backup instance, which receives a message and in response restores the pre-failure state of the failed primary and serving the customers, corresponds to the claimed second application server that receives the instructions and re-creates the first application session of the first application server. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include Konduru's failover in the combination. Doing so restores the first server's state on a backup application server when the server hosting the user's session fails, so that service to the user continues.
Regarding claim 5, claim 5 depends from claim 3 and further recites that "a second action is based on the second anomaly category, and wherein the second action comprises: disconnecting a session hijacking device from the user device; and blocking an internet protocol (IP) address associated with the session hijacking device to block the session hijacking device from a subsequent connection to the user device."
Ogawa provides for this added limitation. Ogawa discloses executing real-time actions (Ogawa, (41)). The actions include terminating the communication session with a particular user (Ogawa, (70)). The disclosed termination of the session corresponds to the claimed disconnecting of a session hijacking device. Ogawa further discloses tightening security restrictions as to which IP addresses can access data (Ogawa, (57)). Ogawa also discloses taking action against a suspicious IP address (Ogawa, (85)). These disclosures correspond to the claimed blocking of an IP address associated with the session hijacking device to block it from a subsequent connection. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include Ogawa's termination of the session and restriction of the IP address in the combination. Doing so disconnects the intruding device, and blocks its IP address from reconnecting, when a session is accessed from an unexpected IP address indicating a hijacking attempt.
Regarding claim 6, claim 6 depends from claim 3 and further recites that "a third action is based on the second anomaly category, and wherein the third action comprises: identifying a proper team to further analyze the first anomaly; and sending an alert to the proper team."
Albero, already relied upon above in combination, provides for this added limitation. For a detected anomaly, Albero discloses extracting data that identifies the user associated with the anomaly, the role of that user, and the supervisor of that user (Albero, [0060]). Albero further discloses generating a notification that identifies the one or more users associated with the anomaly, such as the employee and the supervisor of that user (Albero, [0060]). Albero further discloses generating a notification that identifies the one or more users associated with the anomaly, such as the employee and the supervisor (Albero, [0061], [0077]). The notification is transmitted to an administrator or other supervisory user for evaluation, next steps, and further processing (Albero, [0063], [0078]). Under the broadest reasonable interpretation of "a proper team to further analyze the first anomaly," the personnel that Albero identifies as responsible for the anomaly (the associated user, that user's role, and that user's supervisor) correspond to the claimed proper team. Albero's transmission of the notification to those personnel, for evaluation and further processing, corresponds to the claimed sending of an alert to the proper team to further analyze the anomaly. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use Albero's identification of the responsible personnel and transmission of the notification for this added limitation. Doing so routes a detected anomaly that requires further analysis to the personnel responsible for analyzing it, and alerts them.
Regarding claim 12, claim 12 contains limitations substantially identical to those of claim 2, and is rejected for the same reasons set forth above with respect to claim 2.
Regarding claim 13, claim 13 contains limitations substantially identical to those of claim 3, and is rejected for the same reasons set forth above with respect to claim 3.
Regarding claim 14, contains limitations substantially identical to those of claim 4, and is rejected for the same reasons set forth above with respect to claim 4
Regarding claim 15, claim 15 contains limitations substantially identical to those of claim 5, and is rejected for the same reasons set forth above with respect to claim 5
Regarding claim 16, contains limitations substantially identical to those of claim 6, and is rejected for the same reasons set forth above with respect to claim 6.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZAIN J AHMED whose telephone number is (571)270-0251. The examiner can normally be reached 8am - 4pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432