Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1-19 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant argues that the specification [0104] implies that an operational status is a “login status running state, access control status or compliance state”.
Examiner may not read specific details of the specification into claim limitations and must read the limitations with a broad but reasonable interpretation.
Applicant argues that Niv fails to teach “an actual condition at a particular time”. Examiner disagrees. Niv teaches anomaly detection in “real time” which would determine an entity state at the current time. (Column 13 lines 30-38) Examiner additionally points to Column 15 line 35 which states “a time associated with a security incident, entity type, entity identifier, entity account data”.
Applicant argues that Niv fails to teach a condition that “actually exist” Applicant points out that Niv does teach detecting events that are determined to not constitute a security incident, but ignores that Niv additionally determines events that *are* determined to be security incidents. Examiner at least points to Column 4 lines 32 to 62 which state detection of observed network activity are “spoofing attacks, malware, incoming connections from malicious sources” etc.
Applicant argues that Niv fails to teach that the event matches a predefined definition, since Niv teaches behavioral profiles.
Examiner argues that the term “predefined definition” as stated by Applicant must be read with a broad but reasonable interpretation.
Examiner believes that the Niv reference is sufficient to meet the claims as amended, and argues that the term “predefined definition” could be interpreted as “ a threshold”. Examiner points to Column 13 lines 40 which states “security policy may specify one or more conditions that may be indicative of a particular violation or security threat” Examiner interprets this “condition” as a predefined rule or definition. Examiner points to Column 15 lines 25-40 which state “anomalies greater than a threshold…determined security incident….anomalies associated with login attempts, geography, a restricted resource” Examiner considers for example, “login attempts above X threshold a login attack” to be a “definition….
However, in the interest of advancing prosecution Examiner includes Desai US 2003/0188189 to more explicitly teach the limitations as claimed.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Niv US 12,008,222 in view of Shurtleff US 2020/0162503 in view of Desai US 2003/0188189.
As per claims 1, 10, 11. Niv teaches A method for detecting a cybersecurity threat in a cloud computing environment, comprising: detecting an event based on accessing log data from a cloud log; the event including a user entity; deploying a runtime sensor on a resource the runtime sensor configured to detect runtime data (Column 5 lines 20-52) (Column 11 lines 15-35) (Column 13 lines 30-38) (agents on cloud nodes collecting runtime data, collecting logs of cloud operations, in real time) (Column 11 lines 35-45) (a behavior profile may be of a “principal”). (Column 18 lines 44-50) (a “principal” may be a user, or account). (Column 14 lines 53-63) (teaches profiling on entity where entity may be a principal or account)
Niv teaches determining a state for each entity of a plurality of entities deployed in a cloud computing environment, wherein the state of each entity is a status of an entity at a specific point in time and wherein at least a first state is based on detected runtime data and detected events of the cloud log. (Column 5 lines 20-36) (Column 11 lines 17-34) (Column 13 lines 30-38, lines 50-60) (Column 16 line 65 to Column 17 line 5) (teaches using runtime data and log data from the cloud to compare to determine the state of an entity at that time)
Niv teaches detecting an event of a first type, wherein the first type indicates a potential cybersecurity attack; determining that the event of the first type is a benign event based on the determined state; or a cyber security attack that matches a predefined definition (Column 13 lines 40-60) (Column 15 lines 19-50) (teaches event detection including anomalies that may be attacks or benign, based in part on predefined definitions or rules)
Niv teaches and initiating a mitigation action, in response to determining that the event of the first type is a non-benign event. (teaches a security platform that acquires audit logs of a cloud, detecting an event in real time, and determining if the event is an attack, or not, and performing remediation if the event is determined to be an attack)
(Column 11 lines 15-60) (Column 12 line 43 to Column 13 line 38) (Column 14 line 20- Column 15 line 25)
Shurtleff teaches event including an identifier of a user entity, and detecting runtime data on a data link layer of the resource. [0012][0034] [0037][0039] Table 2 (teaches telemetry system collecting network data including user name, detecting behaviors, MAC/IP addresses/link layer data, user anomalies, flagging the device for anomalies; )
It would have been obvious to one of ordinary skill in the art at the time before the priority data of the instant application to use Shurtleff with the prior art because it increases security.
Desai teaches a real time intrusion detection system. [0035] Desai teaches determining a state and event, the event being of a first type based on a determination by the runtime sensor that the event matches a predefined definition wherein the first type indicates a potential cyber attack. [0035][0048]-[0052][0066]-[0075] (detecting attack based on behavior based attack signatures, correlate security events) Desai teaches that the status of the entity is a status at a specific point in time wherein the state of the user is based on events of a cloud log [0025][0050][0066] (events are time stamped or signature is detected within a specific period of time)
It would have been obvious to use the definitions of Desai at the effective filing date of the current application because it improves the prior art in preventing security incidents.
As per claims 2, 12. Niv teaches the method of claim 1, further comprising: detecting an anomaly based on the detection of an event and a change in a baseline state of an entity within a predetermined time period of the detected event; and initiating a remediation action based on the detected anomaly. (Column 11 lines 16-35) (Column 14 lines 37 to Column 15 line 51) (teaches a baseline profile, detecting an event based on deviation from said profile, and initiating a remediation action)
As per claims 3, 13. Niv teaches the method of claim 1, further comprising: extracting the log data from the cloud log to detect the event. (Column 11 lines 17-52) (teaches using audit log data to detect events)
As per claims 4, 14 Niv teaches the method of claim 1, further comprising: parsing received aggregated runtime execution data to detect the event. (Column 16 line 65 to Column 17 line 6) (teaches continuous monitoring at runtime) (Column 13 lines 30-40) (real-time detection and analysis of logs)
As per claims 5, 15 Niv teaches the method of claim 1, further comprising: configuring the runtime sensor to detect the event. . (Column 16 line 65 to Column 17 line 6) (teaches continuous monitoring at runtime) (Column 13 lines 30-40) (real-time detection and analysis of logs)
As per claims 6, 16 Niv teaches the method of claim 1, further comprising: requesting access from a network to obtain the log data from the cloud log. (Column 11 lines 17-52) (teaches using audit log data to detect events at security platform) (Column 13 lines 2-10)
As per claims 7, 17 Niv teaches the method of claim 1, further comprising: querying data sources to determine a state of an entity including any one of: a data plane, a control plane, a Version Control System (VCS), an Identity Provider (IdP), and any combination thereof.
(Column 17 line 39 to Column 18 line 5) (teaches analysis of an audit log including control plane data)
As per claims 8, 18 Niv teaches the method of claim 1, further comprising: establishing a baseline of entity behavior based on any one of: previous runtime data, data from a data plane, data from a control plane, data from a VCS, data from an IdP, and any combination thereof. (Column 16 lines 4-24)(Column 17 line 39 to Column 18 line 5) (teaches analysis of an audit log to create a baseline/probabilistic model, including control plane data)
As per claims 9, 19 Niv teaches the method of claim 1, wherein log data includes any one of: data related to an event, an occurrence of an event, an event record, and any combination thereof. (Column 13 lines 30-50) (teaches analysis of an audit log which includes events)
Conclusion
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439