Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 7/28/2026 have been fully considered, and are persuasive. The previously presented Double Patenting rejection has been withdrawn responsive to the amendments made to the present claim language as well as those made to the copending application. The arguments directed to the rejections made under 35 USC 103 are also persuasive, and responsive to the amended language, have been withdrawn. However, after further search and consideration, a new grounds of rejection is presently presented made further in view of the teachings of Pangeni (US-11159486-B2) and Prakash (US-7613815-B1).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1 – 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claim 1, said claim has been amended to recite a detecting step performed “based on one or more ports and payload form inspection of the traffic”. The precise meets and bounds of the recitation is unclear, rendering the claim as a whole indefinite. For example, it is unclear if “one or more ports and payload format inspection” requires:
at least multiple ports to be inspected (as “ports” is plural, thus “one” of “ports” implying multiple ports),
only one port to be inspected,
consideration or some other evaluation of ports that (potentially) falls short of being considered an “inspection”, along with an inspection of a payload format,
one or more port formats and at least a payload format to be inspected,
one inspection that may evaluate port formats as well as a payload format
inspection of both multiple port formats and a payload format,
etc.
In order to perform a complete examination, the above language has been interpreted broadly. Regarding claim 11, said claim includes language analogous to that above appearing in claim 1, and thus suffers from issues corresponding to those noted above. Regarding claims 2 – 10 and 12 – 20, each of said claims depends on one of claims 1 and 11, and fails to clarify the issues noted above.
Regarding claim 9, said claim has been amended to recite “maintaining a profile for each domain and port tuple”. There is a lack of antecedent basis for “each domain and port tuple”, rendering the claim as a whole unclear and indefinite. The lack of antecedent basis results in an indefinite relationship between the claim as a whole and the introduced “each domain and port tuple”, as there is no established relationship between this items (domain and port tuple) and the claim as a whole, and thus it is unclear what in the claim is being further limited (i.e., to what claim item is this domain and port tuple related or otherwise relevant to?)
Regarding claim 19, said claim includes language analogous to that above appearing in claim 9, and thus suffers from issues corresponding to those noted above.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 5 – 6, 8, 10 – 11, 15 – 16, 18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam (US-20220368726-A1) in view of John (US-7941827-B2), Pangeni (US-11159486-B2), and Prakash (US-7613815-B1).
Regarding claim 1, Balasubramaniam shows a method implemented by a cloud-based ([126]) system, the method comprising steps of: performing monitoring of traffic associated with the cloud-based system ([101,115] discussing tracking active directory traffic (AD) via “continuing AD monitoring”; see also [117]); inspecting the traffic ([117-118])) associated with the one or more active directory protocols ([91,101] discussing Active Directory, LDAP, and SMB); to determine one or more attack signatures ([117,120] discussing consideration of “a particular pattern of credential use” and “activities anomalous to . . . baseline”) performing one or more actions on the traffic responsive to the one or more attack signatures ([117,120] discussing “generating an alert” and “presenting . . . information needed for an actionable plan”), as well as further use of active directory logs ([121]). Balasubramaniam does not show performing inline monitoring, classifying the traffic as being associated with any of one or more active directory protocols, thus detecting active directory protocols, wherein the classifying includes automatically detecting the one or more active directory protocols base don one or more ports and payload format inspection of the traffic; John shows performing inline monitoring (col. 9 lines 5-10), classifying the traffic as being associated with any of one or more active directory protocols (col. 7 lines 39-52 and col. 14 lines 57-58), and detecting active directory protocols (col. 7 lines 18-52) wherein the classifying includes automatically (by a combination of the hardware and software discussed in col. 3 lines 34-39 and col. 4 lines 8-22) detecting the one or more active directory protocols based on one or more ports and payload format inspection of the traffic (col. 7 lines 6-52);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the monitoring and security disclosure of Balasubramaniam with the classification techniques of John in order to enable simplified packet classification, ensuring packets can be treated different based on their associated operations and protocols and thus that more sensitive or potentially dangerous traffic can receive additional attention.
The above combination does not show: where the inline monitoring is of traffic associated with a plurality of tenants of the cloud-based system; generating one or more logs based on the inspecting and wherein the one or logs are exported, over secure connections, to a log routing system of the cloud-based system for storage and analytics. Pangeni shows where the inline monitoring is of traffic associated with (col. 4 lines 56-67) a plurality of tenants of the cloud-based system (col. 4 lines 37-38 and lines 56-67); generating one or more logs based on the inspection (col. 2 lines 36-45, col. 6 line 43 – col. 7 line 8) and wherein the one or logs are exported, over secure connections (col. 6 line 67 – col. 7 line 8, col. 20 line 64 – col. 21 line 25), to a log routing system (col. 7 line 50-col. 8 line 14, col. 20 lines 1-34) of the cloud-based system for storage and analytics (col. 6 line 42 – col. 7 line 8, col. 17 lines 25-60). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the monitoring and security disclosure of the above combination with the cloud-based in-line monitoring and log creation of Pangeni in order to improve the security posture of the resultant system (Pangeni, col. 4 lines 30-36).
The above combination does not show wherein each of the one or more logs is associated with one of the one or more protocols. Prakash shows wherein each of the one or more logs is associated with one of the one or more protocols (col. 3 lines 20-33, col. 4 lines 43-50, col. 5 lines 35-38).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the monitoring and security disclosure of the above combination with the log creation techniques of Prakash enable more customization options for the logged data, improving the maintainability of the resultant disclosure while also better ensuring desired customization options are supported (Prakash, col. 4 lines 32-46).
Regarding claim 5, the above combination further shows wherein the one or more actions include alerting users of a tenant of the cloud-based system (Balasubramaniam, [115]) responsive to detecting one or more attack signatures (Balasubramaniam, [117,120]).
Regarding claim 6, the above combination further shows wherein the alerting includes providing remediation steps for mitigating a potential attack (Balasubramaniam, [120] discussing “actionable recommendations” and [121] discussing “predictive change to infrastructure recommendations”).
Regarding claim 8, the above combination further shows wherein the inspecting (Balasubramaniam, [100-101]) is performed for each of the plurality of tenants based on an inspection profile (Balasubramaniam, [118,120] discussing a “baseline profile”) of each of the plurality of tenants (Pangeni, col. 4 lines 37-38 and lines 56-67).
Regarding claim 10, the above combination further shows wherein the inspecting is performed at an application connector (Balasubramaniam, [42,53]) of the cloud-based system (Pangeni, col. 4 lines 37-38).
Regarding claim 11, the limitations of said claim are addressed in the analysis of claim 1.
Regarding claim 15, the limitations of said claim are addressed in the analysis of claim 5.
Regarding claim 16, the limitations of said claim are addressed in the analysis of claim 6.
Regarding claim 18, the limitations of said claim are addressed in the analysis of claim 8.
Regarding claim 20, the limitations of said claim are addressed in the analysis of claim 10.
Claims 2 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam in view of John, Pangeni, and Prakash as applied to claim 1 above, further in view of Tsironis (US-20180316705-A1).
Regarding claim 2, the above combination shows wherein the inline monitoring includes inspection of traffic associated with the one or more tenants as well processing and analysis of active directory activity (Pangeni, col. 4 lines 37-38; John col. 7 lines 6-52). The above combination does not show: where the inspection is real-time and live, and generating one or more trend visualizations based on the one or more logs, the one or more trend visualizations including a trend timeline chart associated with each of the one or more protocols. Tsironis shows where the inspection is real-time and live ([98]), and generating one or more trend visualizations based on the one or more logs ([159,163,168]), the one or more trend visualizations including a trend timeline chart associated with each of the one or more protocols (Fig. 10, [163-164, 168-170]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the trend-based analysis of Tsironis in order to improve the resultant systems’ capabilities in detecting irregularities that may indicate an attack or other undesirable system condition.
Regarding claim 12, the limitations of said claim are addressed in the analysis of claim 2.
Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam in view of John, Pangeni, and Prakash, as applied to claim 1 above, further in view of Church (US-20070169194-A1).
Regarding claim 3, the above combination shows wherein the inline monitoring (John, col. 9 lines 5-10, Balasubramaniam, [95]) includes real-time, live inspection (Pangeni, col. 4 lines 56-67) of Kerberos, Light-weight Directory Access Protocol (LDAP), Server Message Block (SMB) (Balasubramaniam, [91]).
The above combination does not show consideration of Distributed Computing Environment/Remote Procedure Calls (DCERPC) traffic. Church shows consideration of Distributed Computing Environment/Remote Procedure Calls (DCERPC) traffic ([103]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the additional protocol support discussed in Church in order to better identify the wide variety of protocols encountered in networking environments and thus better ensure the desired treatment is provided to the monitored traffic.
Regarding claim 13, the limitations of said claim are addressed in the analysis of claim 3.
Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam in view of John, Pangeni, and Prakash as applied to claim 1 above, further in view of Mokhtar (Mokhtar, Basem Ibrahim, et al. "Active directory attacks—steps, types, and signatures." Electronics 11.16: 2629. (Year: 2022))
Regarding claim 4, the above combination shows claim 1. The above combination does not show wherein the one or more attack signatures include any of Kerberoasting, AS-REP roasting, Service Principal Name (SPN) scanning, account enumeration, and credential dumping. Mokhtar shows: wherein one or more attack signatures include any of Kerberoasting, AS-REP roasting, Service Principal Name (SPN) scanning, account enumeration, and credential dumping (pg. 4 lines 6-7, pg. 7 lines 40-64, and pg. 19).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the Kerberoasting awareness of Mokhtar in order to improve the resiliency of the resultant system to a well-known prior art exploit.
Regarding claim 14, the limitations of said claim are addressed in the analysis of claim 4.
Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam in view of John, Pangeni, and Prakash as applied to claim 1 above, further in view of Bose (US-11405360-B1) and Plotnik (US-20160014077-A1).
Regarding claim 7, the above combination shows one or more actions responsive to one or more attack signatures (Balasubramaniam, [117,120]).
The above combination does not show blocking access to an active directory domain. Bose shows blocking access to an active directory domain (Figs. 4 and 5A, col. 15 lines 10-60).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the active directory protection of Bose in order to better ensure protection of system resources when potential attacks are detected. The above combination does not show wherein the blocking includes generating a synthetic response to a requesting entity, the synthetic response including any of a Kerberos error message, a Light-weight Directory Access Protocol (LDAP) protocol error or operations error message, and a Server Message Block (SMB) access denied message. Plotnik shows wherein the blocking includes generating a synthetic response to a requesting entity, the synthetic response including any of a Kerberos error message, a Light-weight Directory Access Protocol (LDAP) protocol error or operations error message, and a Server Message Block (SMB) access denied message ([1,27,41,76,92]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the attack responsiveness of Plotnik in order to better protect the resultant system via utilizing the awareness of specific attack types combined with known solutions/mitigations to said attacks.
Regarding claim 17, the limitations of said claim are addressed in the analysis of claim 7.
Claims 9 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramaniam in view of John, Pangeni, and Prakash as applied to claim 1 above, further in view of Lim (US-20070156659-A1) and Van Ewijk (US-20120084331-A1).
Regarding claim 9, the above combination shows the plurality of tenants (Pangeni, col. 4 lines 37-38). The above combination does not show receiving an inspection profile for performing the inspecting. Lim shows receiving an inspection profile for performing the inspecting ([519-520, 540, 562]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the profile provisioning of Lim in order to ensure each of the multiple tenants has control over how their resources are monitored. The above combination does not show: maintaining a profile for each domain and port tuple, wherein a protocol classification is saved in the profile for auto-detection of a subsequently processed stream associated with the domain and port tuple. Van Ewijk shows maintaining a profile for each domain and port tuple ([59-75]), wherein a protocol classification is saved in the profile ([9-15]) for auto-detection of a subsequently processed stream associated with the domain and port tuple (note that the concluding “for” clause is interpreted as corresponding to an indented use of the method of claim 8, and is addressed via anticipation of the preceding language).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the traffic profile use and traffic awareness of Van Ewijk in order to enable improved efficiency when monitoring and logging the received network traffic as well as providing more overall awareness of the network status (Van Ewijk, [1-2,8]).
Regarding claim 19, the limitations of said claim are addressed in the analysis of claim 9.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN M MACILWINEN whose telephone number is (571)272-9686. The examiner can normally be reached Monday - Friday, 9:00 - 5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571) 272 - 3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
JOHN MACILWINEN
Primary Examiner
Art Unit 2442
/JOHN M MACILWINEN/ Primary Examiner, Art Unit 2454