DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
This office action is a response to an amendment filed on 06/19/2026. Claims 1, 13 and 14 are amended, claims 11 and 12 are cancelled, and claims 15-22 are newly added. Claims 1-10 and 13-22 are currently pending.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/20/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant’s remarks, see page 6, with respect to the non-statutory double patenting rejections have been fully considered. The terminal disclaimer filed on 06/19/2026 disclaiming the terminal portion of any patent granted on this application which would extend beyond the expiration date of US Patent Number 12212583 has been reviewed and is accepted. The terminal disclaimer has been recorded. The non-statutory double patenting rejections are withdrawn in light of the filed terminal disclaimer.
Applicant’s remarks, see page 6, with respect to the rejections under 35 USC 101 have been fully considered and are persuasive, therefore the rejections have been withdrawn.
Applicant’s remarks, see pages 6-7, with respect to the rejections under 35 USC 102 and 103 have been fully considered and are persuasive, therefore the rejections have been withdrawn. However, upon further consideration, a new ground(s) of rejection is made, necessitated by the amendments.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-6, 8, 13, 14, 16-19 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Burnside et al. (US 2010/0235879), hereinafter Burnside, in view of Benjamin (US 2006/0191010). Burnside is cited by Applicant in the IDS filed 12/10/2024.
Regarding claim 1, Burnside discloses a system, comprising:
a processor configured to (Burnside, [0011]):
receive a set of security events associated, collectively, with a plurality of sessions (Burnside, [0034]: sensors report session-related events to a session database; [0051]: the events are compared to a security policy (i.e., they are security events); [0059]: the events are posted in bunches (sets) to the session database; [0048]: session database links event to principals (sessions); [0050]: session database determines relationships between events and principals. [Paragraphs [0048] and [0050] indicate that the session database receives events associated with a plurality of principals (sessions)]);
use at least some of the received events in the set to generate a graph, wherein nodes in the graph correspond to at least some of the received security events in the set, and wherein edges in the graph correspond to identifiable patterns of correlation (IPCs) (Burnside, [0056]: session database processes events to build a graph where vertices are events and edges are links between the events; [0040]: links represent correlations between attributes of the events (i.e., identifiable patterns of correlation)); and
determine that the generated graph matches a prebuilt scenario (Burnside, [0066]-[0067]: The shape of a graph is compared to known shapes (prebuilt scenarios) in a black list. If a match occurs, the session associated with the graph is punished), wherein the prebuilt scenario was created at least in part by (Burnside, [0062], [0069]: generating the graphs from recorded requests and system interactions, and using those graphs to create or shape a policy comprising predefined session graphs (prebuilt scenarios)) and take a remedial action in response (Burnside, [0066]-[0067]: The shape of a graph is compared to known shapes (prebuilt scenarios) in a black list. If a match occurs, the session associated with the graph is punished (remedial action)); and
a memory coupled to the processor and configured to provide the processor with instructions (Burnside, [0012]).
Burnside does not explicitly disclose simulating an attack using a particular vulnerability and capturing associated network events.
However, Benjamin discloses simulating an attack using a particular vulnerability and capturing associated network events (Benjamin, [0076]: vulnerability assessment is performed by generating attacks against virtual machines; [0081]: an exploit is based on a known bug; [0064]-[0065]: packets received during each executed activity are recorded; the recorded information is used to create new intrusion detection rules).
It would have been obvious to one of ordinary skill in the art, having the teachings of Burnside and Benjamin before him or her before the effective filing date of the claimed invention, to modify a method for creating predefined session graphs from recorded requests and system interactions as taught by Burnside, to include utilizing packet patterns captured during simulated attacks against known vulnerabilities as taught by Benjamin. The motivation for doing so would have been to provide predefined session graphs representative of attacks against known vulnerabilities, thereby facilitating detection of attacks against those vulnerabilities.
Regarding claim 3, Burnside discloses wherein at least one security event included in the set is an application activity (Burnside, [0034], [0038]: sensors report events for software/applications).
Regarding claim 4, Burnside discloses wherein at least one security event included in the set is a device network behavior (Burnside, [0032], [0035]: sensors post events regarding the behavior of firewalls, web servers, databases, etc.).
Regarding claim 5, Burnside discloses wherein at least one security event included in the set is an anomaly detection output (Burnside, [0074]: attacker sending a request that deviates from policy rules).
Regarding claim 6, Burnside discloses wherein at least one IPC is one of: an IP address, a URL, an application, or a port number (Burnside, [0050]: correlation (IPC) is based on ports and addresses).
Regarding claim 8, Burnside discloses wherein at least one IPC is a sequence of events (Burnside, [0040]: correlated/linked events are causally related – one event is a successor of another).
Regarding claim 13, the limitations have been addressed in the rejection of claim 1.
Regarding claim 14, the limitations have been addressed in the rejection of claim 1, and furthermore, Burnside discloses a computer program product embodied in a non-transitory computer readable medium and comprising computer instructions (Burnside, [0012]).
Regarding claims 16-19 and 21, the limitations have been addressed in the rejections of claims 3-6 and 8, respectively.
Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Burnside in view of Benjamin, further in view of Thrower et al. (US 8,225,407), hereinafter Thrower. Thrower is cited by Applicant in the IDS filed 12/10/2024.
Regarding claim 2, Burnside and Benjamin do not explicitly disclose wherein at least one security event included in the set is a threat signature matching event.
However, Thrower discloses wherein at least one security event included in the set is a threat signature matching event (Thrower, col 8, ln 20-58: a security event comprises an attempt to exploit a particular vulnerability that matches a signature for the attempt).
It would have been obvious to one of ordinary skill in the art, having the teachings of Burnside, Benjamin and Thrower before him or her before the effective filing date of the claimed invention, to modify a method for building graphs based on security events generated by sensors observing behavior on a network, in which the vertices of the graph represent the events as taught by Burnside and Benjamin, to include identifying a security event when an attempt to exploit a vulnerability (threat) signature is matched as taught by Thrower. The motivation for doing so would have been to utilize an effective mechanism for classifying events in order to aid in the analysis of security events (Thrower, col 8, ln 20-58).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Burnside in view of Benjamin, further in view of Rogers (US 2021/0352099). Rogers is cited by Applicant in the IDS filed 12/10/2024.
Regarding claim 7, Burnside and Benjamin do not explicitly disclose wherein at least one IPC is a time interval.
However, Rogers discloses wherein at least one IPC is a time interval (Rogers, [0230]: dependency edge (IPC) between nodes in a graph represents a validity duration for an event).
It would have been obvious to one of ordinary skill in the art, having the teachings of Burnside, Benjamin and Rogers before him or her before the effective filing date of the claimed invention, to modify a method for building graphs based on security events generated by sensors observing behavior on a network, in which the edges of the graph represent correlations (IPCs) between events as taught by Burnside and Benjamin, to include edges in the graph that represent validity durations for events as taught by Rogers. The motivation for doing so would have been to facilitate updating a graph when the dependency between nodes expires and is no longer valid.
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Burnside in view of Benjamin, further in view of Brown et al. (US 2018/0365289), hereinafter Brown. Brown is cited by Applicant in the IDS filed 12/10/2024.
Regarding claim 9, Burnside and Benjamin do not explicitly disclose wherein at least one IPC is a logged in user.
However, Brown discloses wherein at least one IPC is a logged in user (Brown, [0092]: edge type in a graph includes “user”).
It would have been obvious to one of ordinary skill in the art, having the teachings of Burnside, Benjamin and Brown before him or her before the effective filing date of the claimed invention, to modify a method for building graphs based on security events generated by sensors observing behavior on a network, in which the edges of the graph represent correlations (IPCs) between events as taught by Burnside and Benjamin, to include edges in the graph that represent users as taught by Brown. The motivation for doing so would have been to facilitate identifying which users are associated with nodes (events) in the graph.
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Burnside in view of Benjamin, further in view of Yogesh (WO 2013/098830 A1). Yogesh is cited by Applicant in the IDS filed 12/10/2024.
Regarding claim 10, Burnside and Benjamin do not explicitly disclose wherein at least one IPC is an external context.
However, Yogesh discloses wherein at least one IPC is an external context (Yogesh, pg. 83, ln 6-10: an edge between two nodes represents a relationship resulting from actions performed by external domains).
It would have been obvious to one of ordinary skill in the art, having the teachings of Burnside, Benjamin and Yogesh before him or her before the effective filing date of the claimed invention, to modify a method for building graphs based on security events generated by sensors observing behavior on a network, in which the edges of the graph represent correlations (IPCs) between events as taught by Burnside and Benjamin, to include edges in the graph that represent relationships resulting from actions performed by external domains as taught by Yogesh. The motivation for doing so would have been to produce a comprehensive graph by ensuring that all aspects related to an event are considered in the development of the graph.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LESA M KENNEDY whose telephone number is (571)431-0704. The examiner can normally be reached on Monday-Wednesday 9:30 am - 5:30 pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached on (571) 270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
The examiner also requests, in response to this Office Action, support be shown for language added to any original claims on amendment and any new claims. That is, indicate support for newly added claim language by specifically pointing to page(s) and line no(s) in the specification and/or drawing figure(s). This will assist the examiner in prosecuting the application.
/LESA M KENNEDY/Primary Examiner, Art Unit 2458