DETAILED ACTION
Claims 1-20 are pending and have been examined.
There are no new, nor canceled claims.
Applicant’s amendments necessitate new grounds of rejection. Accordingly, this Office action is made FINAL.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s amendments with arguments, see page 8, filed 6/18/2026, with respect to the objection to Claim 17 have been fully considered and are persuasive. The objection to Claim 17 has been withdrawn.
Applicant’s amendments with arguments, see pages 8 and 9, filed 6/18/2026, with respect to the rejection of Claims 1-2, 5-8,10-11, 14-17 and 19 under 35 U.S.C. 102; and the rejections of Claims 3-4, 9, 12-13, 18 and 20 and 19 under 35 U.S.C. 103 have been fully considered and are persuasive. Therefore, the rejections have been withdrawn. However, upon further consideration, a new grounds of rejection are made in view of the combination of Ahuja et al. and Kura et al., necessitated by amendments.
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1-2, 5-8, 10-11, 14-17 and 19 are rejected under 35 U.S.C. 35 U.S.C. 103 as being unpatentable over US 2018/0034778 A1 (Ahuja et al.), in view of US 2026/0149736 A1 (Kura et al.).
As to Claims 1, 10 and 19, Ahuja et al. anticipate a computer-implemented method (Ahuja et al. - ¶ [0156] and Abstract); a system comprising memory and one or more processors communicatively coupled to the memory (Ahuja et al. disclose the processor and memory - ¶ [0189]); and one or more non-transitory computer-readable storage media (Ahuja et al. disclose the processor and memory - ¶ [0189]), respectively, for degrading communication traffic, the method comprising:
monitoring, by one or more processors, a network traffic associated with one or more devices (Ahuja et al. recite: “Some types of computer network security applications involve deep packet inspection (DPI). At a high level, DPI involves monitoring network traffic for instances of viruses, spam, network intrusion attempts, protocol non-compliance, etc., by searching for patterns in the data portion, headers, and other protocol structures comprising network traffic.” - ¶ [0004]);
detecting, by the one or more processors, a predefined communication pattern in the monitored network traffic (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns.” - ¶ [0004]);
upon detecting the predefined communication pattern, generating a blocking event, the blocking event configured to degrade the network traffic associated with a specific application or service (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Blocking traffic degrades traffic flow); and
implementing the blocking event by instructing one or more network components to degrade the network traffic associated with the specific application or service, wherein the degradation reduces a communication quality over a predefined temporal period. (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Completely blocking malicious traffic forever {predefined to be the forever time period} reduces communication quality completely by reducing bandwidth to zero and increasing latency to infinity).
Ahuja et al. disclose upon detecting the predefined communication pattern, generating a blocking event, the blocking event configured to degrade the network traffic associated with a specific application or service; and implementing the blocking event by instructing one or more network components to degrade the network traffic associated with the specific application or service, wherein the degradation reduces a communication quality over a predefined temporal period, as cited above; and uses firewalls to implement the degradation (¶ [0039]). However, the degradation is not temporary, but instead permanent. However, Kura et al., in the same field of invention, also using firewalls for network security, discloses
temporarily degrading network traffic for security purposes (Kura et al. recite: “In an embodiment, the mitigation module 220 may block and/or mitigate login attempts associated with the detected anomaly. Further, the mitigation module 220 may block API traffic associated with the detected anomaly by dynamically adjusting firewall rules and updating access control lists. Also, the mitigation module 220 may apply different levels of traffic blocking and mitigation based on the severity of the detected anomaly, including temporary blocking and/or permanent blacklisting of sources. For example, after the anomaly detection module 218 flags an IP subnet where 40% of the IP addresses are deemed potentially malicious, the mitigation module 220 may immediately block all incoming traffic from this subnet to prevent further login attempts. In another scenario, if the threat level is deemed lower, the mitigation module 220 may implement a temporary block or rate limit traffic from the suspicious sources, allowing legitimate users time to verify their credentials without full disruption.” - ¶ [0048]).
It would have been obvious to one of ordinary skill in the art to combine temporary blocking of network traffic based on detected anomalies, taught by Kura et al., with the network degradation via permanent blocking based on network anomalies, taught by Ahuja et al., in order to alert and allow a system administrator the notification and time to determine if the blockage needs to be permanent or released if the administrator’s analysis justifies releasing the blockage (Kura et al. - ¶ [0009]).
As to Claims 2 and 11, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively,
wherein the monitoring further comprises analyzing metadata associated with the network traffic to identify the predefined communication pattern, wherein the metadata includes one or more of: one or more domain names; one or more IP addresses; and one or more timestamps associated with the network traffic (Ahuja et al. disclose using IP addresses in identifying communication patterns - ¶ [0140]).
As to Claims 5 and 14, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively,
wherein the blocking event is configured to degrade the network traffic by reducing a bandwidth available to the specific application or service (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Completely blocking malicious traffic forever {predefined to be the forever time period} reduces communication quality completely by reducing bandwidth to zero and increasing latency to infinity; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Blocking traffic degrades traffic flow).
As to Claims 6 and 15, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively,
wherein the blocking event is configured to degrade the network traffic by increasing a latency of communications for the specific application or service (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Completely blocking malicious traffic forever {predefined to be the forever time period} reduces communication quality completely by reducing bandwidth to zero and increasing latency to infinity; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Blocking traffic degrades traffic flow).
As to Claims 7 and 16, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively, further comprising:
generating an alert in response to detecting the predefined communication pattern, wherein the alert includes one or more details of the detected predefined communication pattern and the one or more associated device (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Blocking traffic degrades traffic flow. Ahuja et al. also disclose using IP addresses in identifying communication patterns - ¶ [0140]. Triggering the act of blocking upon determining that a malicious pattern inherently includes the use of an internal alert to generate the trigger).
As to Claims 8 and 17, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively, further comprising:
dynamically adjusting the degradation of the communication quality based on real-time monitoring of the network traffic, wherein a degree of degradation is modified in response to changes in the detected predefined communication pattern (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006]. Completely blocking malicious traffic forever {predefined to be the forever time period} reduces communication quality completely by reducing bandwidth to zero and increasing latency to infinity. The degree is either to pass along or block).
Claims 3-4 and 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over the combination of Ahuja et al. and Kura et al., in view of US 2026/0058952 A1 (Mano et al.).
As to Claims 3 and 12, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively.
The combination of Ahuja et al. and Kura et al. discloses identifying the predetermined communication pattern as cited above, but do not expressly disclose wherein the predefined communication pattern comprises a sequence of network addresses accessed by the one or more devices, and the sequence of network addresses is identified by analyzing an order and frequency of network addresses accessed within a specified time frame. However, Mano et al. disclose
wherein the predefined communication pattern comprises a sequence of network addresses accessed by the one or more devices, and the sequence of network addresses is identified by analyzing an order and frequency of network addresses accessed within a specified time frame (Mano et al. recite: “Further, the proposed methodology for identifying if the requested internet address is trusted or malicious based on the predicted likelihood of the web browsing sequence of internet addresses improves accuracy, a confidence level of identifying the trusted or malicious internet addresses, a rate of true positives, a rate of false positives, and/or the like.” - ¶ [0106]).
It would have been obvious to one of ordinary skill in the art to combine wherein the predefined communication pattern comprises a sequence of network addresses accessed by the one or more devices, and the sequence of network addresses is identified by analyzing an order and frequency of network addresses accessed within a specified time frame, taught by Mano et al., with identifying the predetermined communication pattern, taught by the combination of Ahuja et al. and Kura et al., in order to add another layer of threat detection (Mano et al. - ¶ [0106]).
As to Claims 4 and 13, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively, including identifying the predefined communication pattern as cited above, but do not expressly disclose wherein detecting the predefined communication pattern comprises: identifying the predefined communication pattern based on a temporal correlation of network traffic events. However, Mano et al. disclose
wherein detecting the predefined communication pattern comprises: identifying the predefined communication pattern based on a temporal correlation of network traffic events (Mano et al. recite: “Further, the proposed methodology for identifying if the requested internet address is trusted or malicious based on the predicted likelihood of the web browsing sequence of internet addresses improves accuracy, a confidence level of identifying the trusted or malicious internet addresses, a rate of true positives, a rate of false positives, and/or the like.” - ¶ [0106]).
The motivation and obviousness arguments are the same as in Claim 3.
Claims 9, 18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over the combination of Ahuja et al. and Kura et al., in view of US 8,488,456 B2 (Battestilli et al.).
As to Claims 9 and 18, the combination of Ahuja et al. and Kura et al. discloses the computer-implemented method of claim 1; and the system of claim 10, respectively.
The combination of Ahuja et al. and Kura et al. discloses identifying the specific application; and wherein the identified specific application is used to apply an appropriate blocking event as cited above, but not based on a destination IP address and a port number associated with the network traffic. However, Battestilli et al. disclose:
identifying malware based on a destination IP address and a port number associated with the network traffic. (Battestilli et al. disclose the intrusion detection and anti-virus systems using IP packet flow data comprising the source and destination IP addresses and port numbers – Claim 1 and 5:26-38).
It would have been obvious to one of ordinary skill in the art to combine identifying malware based on a destination IP address and a port number associated with the network traffic, taught by Battestilli et al., with identifying the specific application; and wherein the identified specific application is used to apply an appropriate blocking event, taught by the combination of Ahuja et al. and Kura et al., in order to filter out malicious incoming packet transmissions (Battestilli et al. – 5:26-38).
As to Claim 20, the combination of Ahuja et al. and Kura et al. discloses the one or more non-transitory computer-readable storage media of claim 19, wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:
analyze metadata associated with the network traffic to identify the predefined communication pattern, wherein the metadata includes one or more of: one or more domain names; one or more IP addresses; and one or more timestamps associated with the network traffic (Ahuja et al. disclose using IP addresses in identifying communication patterns - ¶ [0140]);
dynamically adjust the degradation of the communication quality based on real-time monitoring of the network traffic, wherein a degree of degradation is modified in response to changes in the detected predefined communication pattern (Ahuja et al. recite: “a DPI process may monitor incoming and outgoing network traffic for patterns known to correspond to malicious or unwanted network traffic and block any traffic containing one or more of the known patterns”; and “FIG. 1 is a block diagram illustrating a security service configured to monitor traffic sent among an application and one or more servers through a routing network in accordance with the disclosed embodiments” - ¶ [0004, 0006, 0050]. Blocking traffic degrades traffic flow).
The combination of Ahuja et al. and Kura et al. discloses identifying the specific application; and wherein the identified specific application is used to apply an appropriate blocking event as cited above, but not based on a destination IP address and a port number associated with the network traffic. However, Battestilli et al. disclose:
identifying malware based on a destination IP address and a port number associated with the network traffic. (Battestilli et al. disclose the intrusion detection and anti-virus systems using IP packet flow data comprising the source and destination IP addresses and port numbers – Claim 1 and 5:26-38).
The motivation and obviousness arguments are the same as in Claim 9.
Interview Practice
USPTO Automated Interview Request (AIR)
The USPTO AIR is a new optional online interview scheduling tool that allows Applicants to request an interview with an Examiner for their pending patent application.
The USPTO AIR form is available on our website at: http://www.uspto.gov/patent/laws-and-regulations/interview-practice.
By submitting this type of interview request, the pending patent application will be in compliance with the written authorization requirement for Internet communication in accordance with MPEP §502.03. This authorization will be in effect until the Applicant provides a written withdrawal of authorization to the Examiner of record.
If you have questions or need assistance with the USPTO AIR form or with interview practice at the USPTO, please contact an Interview Specialist at http://www.uspto.gov/patent/laws-and-regulations/interview-practice/interview-specialist or send an email to ExaminerInterviewPractice@USPTO.GOV.
Examiner Notes:
A) Prior to conducting any interview (whether using AIR or not), Applicant(s) must submit an agenda including the proposed date and time, all arguments in writing, and proposed claim amendments (if applicable). Any proposed amendments or arguments not presented in the agenda will only be heard by the Examiner, but because the Examiner will not have heard them in advance and been given an equitable opportunity to consider them, no decision will be rendered, nor agreement made. ALL AGENDAS MUST BE RECEIVED BY THE EXAMINER AT LEAST 24 HOURS PRIOR TO THE START OF THE INTERVIEW, OR THE PREVIOUS BUSINESS DAY, WHICHEVER IS LONGER, or the interview may have to be rescheduled.
B) After-final interviews may be granted, but the agenda must be in compliance with MPEP 713.09 which limits the interview only to discussions of proposed amendments, or clarification for appeal. After-final interviews are not to be conducted for the purpose of rehashing previously made arguments. After seeing the agenda, Examiner will decide whether to grant or deny the interview.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RICHARD G KEEHN whose telephone number is (571)270-5007. The examiner can normally be reached M-F 9:00am - 5:00pm Eastern.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John A Follansbee can be reached at 571-272-3964. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RICHARD G KEEHN/Primary Examiner, Art Unit 2444