DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant argues regarding the 112 rejection: Regarding claims 1-3, 9-12, 14-16, and 18-20, the Office has alleged that the corresponding independent claims recite "a method for detection of a cyber threat" in the preamble but that no detecting of any threat is recited in the claim limitations. Applicant submits that this rejection is based, at least in part, on a misidentification of the preambles of several claims. Claim 9 recites "A non-transitory computer readable medium," claim 10 recites "A threat detection system," and claim 18 recites "A network"-none of these claims recite "a method for detection of a cyber threat" as the Office states. The Office appears to have conflated the preamble language across different claim categories.
Examiner’s response: All independent claims other than claim 9 recite either a method for detection of a cyber threat, a cyber threat detection system, or a network comprising a threat detection system, which are all rejected under the same rationale. The rejection of claim 9 is withdrawn since it does not recite threat detection.
Applicant argues: Moreover, even for claims 1 and 21, which do recite a method for detection of a cyber- threat, the claim body recites steps that collectively constitute the methodology for cyber-threat detection. Specifically, the claims recite "analyzing the derived metrics using a first self-learning model trained on a normal behavior of at least the first entity," "analyzing one or more causal links between data associated with the first entity and data associated with a second entity gathered over one or more days," and "predicting an expected behavior of at least the first entity as to activity on the computer system based on the first self-learning model." These steps are the means by which the threat detection is performed. Furthermore, dependent claims 4 and 13 explicitly recite "determining. a cyber-threat risk parameter indicative of a likelihood of the cyber-threat," which directly addresses threat detection. A person of ordinary skill in the art would understand that the claimed steps of analyzing metrics against a self-learning model of normal behavior, analyzing causal links between entities, and predicting expected behavior are the core analytical operations that enable cyber-threat detection.
Examiner’s response: the steps listed perform no threat detection. They merely perform data collection and analysis to determine normal behavior, but they do not do any sort of comparison or analysis that suggests abnormal behavior. The Examiner notes that claims 4-8, 13, and 17 were not rejected in the previous office action under 112 for this point because they do recite steps that suggest detecting threats. The Examiner has made a note in the 112 rejection to provide additional clarification.
Applicant argues: Regarding claims 3 and 12, the Office has alleged that it is unclear what the "false positive" would be related to, since no threat detection is performed. Applicant submits that this concern follows from the preamble argument addressed above. In the context of cyber-threat detection as recited by claims 1 and 10, a person of ordinary skill in the art would understand "false positives" to mean instances where normal behavior is incorrectly flagged as a potential threat. The meaning is clear from the claim language itself.
Examiner’s Response: The claim language itself does not address threat detection. It only addresses looking at normal behavior, not abnormal behavior, as discussed above.
Applicant argues: Regarding claims 4 and 13, the Office has alleged that the phrase "considering the one or more causal links that include a comparison" is unclear. Applicant respectfully disagrees. The term "considering" as used in claims 4 and 13 in the context of "determining. a cyber-threat risk parameter" would be understood by one of ordinary skill in the art to mean that the causal links are factored into the risk parameter determination. As described in the specification, "the determining of the cyber-threat risk parameter taking the input data associated with the second entity into consideration may involve analysing causal links between data associated with the first entity and data associated with the second entity." See Specification, paragraph [0031]. The phrase "the one or more causal links that include a comparison" further defines the nature of the causal links being considered-it specifies that the causal links encompass a comparison between behaviors of the first and second entities based on their respective analyzed derived metrics. This is not an improper antecedent basis issue but rather a further characterization of the causal links already introduced in the independent claims.
Examiner’s Response: The claims are interpreted in light of the specification, but the claims themselves are what determine the legal limits of the invention. Therefore, they need to be described clearly so that one of ordinary skill in the art would fully understand the metes and bounds of the claimed invention. The wording of claims 4 and 13 is confusing and is not easy to follow. Therefore, the rejection of claims 4 and 13 is maintained for the reasons discussed in the 112 rejection.
Applicant argues: Firstly, regarding claims 7, 16, and 20, the Office has acknowledged that the cited prior art does not teach a three-dimensional (3D) graphical user interface and has dismissed this feature as merely "a design choice well within the purview of the skilled artisan." See Office Action, paragraph 41. Applicant respectfully disagree and contends that this assertion, by itself, fails to establish a prima facie case of obviousness. The Examiner has not cited any reference teaching 3D visualization in the context of cyber-threat detection, nor articulated any motivation Applicant respectfully points out that claims 7, 16, and 20 specifically require "projecting the behavior on a three-dimensional (3D) graphical user interface that conveys a connection topology corresponding to the computer system." The specification describes this as a specific technical feature, disclosing "[a]utomatic network wide, self-organising, 3D projection of cyber threat across packet flow, connection topology and changing endpoint attributes." See Specification, paragraph [0017]. The specification further describes that "[a] topology of the network under scrutiny is projected automatically as a graph based on device communication relationships via an interactive 3D remote observer perspective interface." See Specification, paragraph [0086]. Simply labeling a claimed feature as a "design choice" without evidentiary support or reasoned analysis does not satisfy the Office's burden under 35 U.S.C. § 103. Applicant respectfully submits that the Examiner has failed to establish a prima facie case of obviousness for claims 7, 16, and 20.
Examiner’s response: The Examiner used the Mayer reference which teaches Mayer a system that provides visualization of network wide risk analysis in the form of a GUI with customizable at a glance views of the network – see figures 4A and 4B (threat views), abstract, and column 13 lines 1-8. The Examiner showed that it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings provided by the cited references, by displaying the cyber threats/flagged behavior across packet flow and connections of a network on a GUI, for the purpose of visualization, thus enhancing user experience, based upon the beneficial teachings provided by Mayer. Mayer only did not teach that the GUI was 3D. Firstly, there are only two choices. Two dimensional or three dimensional. In addition, using a three-dimensional GUI would be a design choice clearly within the purview of the skilled artisan, who would choose either 2D or 3D. As evidence that this was routine, the Examiner is providing Robinson et al. (US 2014/0181208) which teaches depicting network mapping in three dimensions – see claims 1-3, and 7.
Applicant argues: Regarding independent claims 1, 9, 10, and 18, Applicant submits that the Office's mapping of individual claim elements across multiple references fails to account for the integrated combination of features required by the claims. As recited by claim 1 (and similarly by claims 9, 10, and 18), the claims require, in combination: (a) "analyzing the derived metrics using a first self-learning model trained on a normal behavior of at least the first entity," (b) "analyzing one or more causal links between data associated with the first entity and data associated with a second entity gathered over one or more days," (c) "predicting an expected behavior of at least the first entity as to activity on the computer system based on the first self- learning model," and (d) "developing a pattern of life as the first self-learning model for at least the first entity, trained on the normal behavior of at least the first entity, based on the data associated with the first entity gathered over the one or more days." Critically, the claims require the same first self-learning model to serve multiple integrated functions-it is trained on normal behavior of at least the first entity, it is used to analyze the derived metrics, it is used to predict expected behavior, and it constitutes the pattern of life developed for at least the first entity. At the same time, these independent claims separately require "analyzing one or more causal links between data associated with the first entity and data associated with a second entity gathered over one or more days." The Office has not provided evidence of a reference or combination of references teaching or suggesting a self-learning model that simultaneously develops a pattern of life for an entity, is trained on the normal behavior of that entity, and is used to predict expected behavior of that entity, while also requiring the separate step of analyzing causal links between data associated with the first entity and data associated with a second entity gathered over one or more days.
Examiner’s Response: The Examiner respectfully disagrees. The combination of Eynon, Brezinski, and Cohen-Ganor teaches the claim limitations as instantly recited. The Examiner has provided rationale and motivation for why these references are able to be combined to teach all of the claimed limitations. The Applicant has not specifically pointed out why any of the references are not combinable or why a particular motivation is erroneous. It must be remembered that the references are relied upon in combination and are not meant to be considered separately as in a vacuum. It is the combination of all of the cited and relied upon references which make up the state of the art with regard to the claimed invention. Applicant's claimed invention fails to patentably distinguish over the state of the art represented by the references.
Applicant argues: Thirdly, claims 3 and 12 are rejected under 35 U.S.C. §103 as being unpatentable over Eynon in view of Brezinski, Cohen-Ganor and Fortier (US Publication No. 2012/0317645). Regarding claims 3 and 12, these claims require "mitigating false positives by at least considering unusual behavior by the first user as normal behavior by the first user when similar unusual behavior is conducted by the second user." This requires a direct comparison between two specific identified entities-the first user and the second user-whose causal links are being analyzed per the parent claims. The Examiner has not shown that the cited prior art teaches this specific mechanism of false positive mitigation through a targeted comparison between two identified entities.
Examiner’s response: Again, the Applicant has not pointed out what is erroneous in the specific prior art rejection that was made. Fortier teaches: By comparing behavior on the user's computing device with behavior noted by users of thousands or more other devices, the system can have a high degree of confidence whether an application is acting normally or not. Thus, even if a user does not use an application feature often (but other users do), the system will avoid false positives and protect the user appropriately from rogue application behavior - see [0015]. Fortier also teaches: By accumulating behavior data from multiple users, the system can develop a more complete assessment of behavior that is normal or unexpected for the application - see [0021]. Therefore, Fortier suggests that if other users are performing what is first believed to be unusual behavior, than the behavior is deemed to be usual to avoid false positives. 37. It would have also been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon, Brezinski, and Cohen-Ganor by characterizing unusual behavior as usual if other users are also performing the same behavior, in order to avoid false positives, based upon the beneficial teachings provided by Fortier. It must be remembered that the references are relied upon in combination and are not meant to be considered separately as in a vacuum. It is the combination of all of the cited and relied upon references which make up the state of the art with regard to the claimed invention. Applicant's claimed invention fails to patentably distinguish over the state of the art represented by the references.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-17 of U.S. Patent No. 10,268,821 in view of Brezinski (US 9,348,742), and further in view of Cohen-Ganor et al. (US 8,661,538).
The ‘821 patent teaches similar claims but does not teach that the model is a self-learning model trained on a normal behavior of at least the first entity or analyzing one or more links between data associated with the first entity and data associated with the second entity or determining the risk based on the link.
Brezinski teaches an unsupervised machine learning module (self-learning model) based on normal or typical behavior in order to detect anomalous behavior as well as a Bayesian (i.e., non-frequentist) self learning model – see column 10 lines 18-36 and column 6 lines 6-13, for example.
Further, Cohen-Ganor teaches a system wherein first and second fraud related risk scores associated with first and second nodes are provided. A relation strength (i.e., link) related to a relation between the first and second nodes may be determined. The relation strength and the node risk scores may be used to calculate a cluster risk score for a cluster of nodes – see [0006] and [0007].
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to modify the teachings of the ‘821 patent by using a self-learning model trained on normal behavior in order to reduce required resources and keep the system up to date on threats, based upon the beneficial teachings provided by Brezinski. These modifications would result in increased efficiency and security to the system. It would have also been obvious to one of ordinary skill in the art at the time the invention was filed to modify the teachings of Eynon and Brezinski analyzing links and using this to determine the risk score, in order to have a more accurate risk score based on connections with other entities, based upon the beneficial teachings provided by Cohen-Ganor. These modifications would result in increased security to the system.
Claims 1-22 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-17 of U.S. Patent No. 12,223,046.
The claims of ‘046 essentially anticipate the claims of the instant application.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-4, 9-12, 13-16, and 18-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claims 1-3, 9-12, 14, 15, 16, and 18-20 the corresponding independent claims listed above recite in the preamble “a method for detection of a cyber threat”/“threat detection system”. However, no detecting of any threat or any other reference as to how the threat is detected is recited in any of the claim limitations. Only the prediction of expected behavior is claimed. Therefore, it is unclear how any threat is detected or if a threat detection is part of the metes and bounds of the claim. Please note that claims 4-8, 13, and 17 recite the threat detection and are therefore not rejected for this issue.
Claims 3 and 12 recites the mitigation of false positives. However, it is unclear what the false positive would be related to, since no threat detection is performed. A false positive of what? This is not defined and is unclear.
Regarding claims 4 and 13, the phrase “wherein the determining the cyber-threat risk parameter comprises…considering the one or more causal links that include a comparison between a behavior of the first entity based on the analyzed derived metrics associated with the first entity to a behavior of the second entity based on analyzed, derived metrics associated with the second entity”. This limitation is very unclear and difficult to follow. First, the word “considering” is unclear. How is the information “considered”? Does someone just think about it? Is it actually applied somehow? Is it actually analyzed and applied? Further, it is unclear what a “causal link” is in relation to the comparison of the derived behavior metrics. Does the one metric cause the other metric? Further again, the phrase “the one or more causal links that include a comparison…” does not make sense because it has not been previously stated that the causal links include a comparison. Using that phrase “the causal links that include” implies a previously recited causal links that have already been specified to include the comparison. Altogether, the metes and bounds of this limitation are difficult to define and need to be clarified. This limitation will be examined as best understood by the Examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 4-6, 8-11, 13-15, and 17-19 are rejected under 35 U.S.C. 103 as being unpatentable over Eynon et al. (US 2010/0125908), in view of Brezinski (US 9,348,742), and further in view of Cohen-Ganor et al. (US 8,661,538
Regarding claims 1, 9, 10, and 18 Eynon teaches a method (and corresponding medium, system, and network) for detection of a cyber threat (fraud detection – see [0032]) to a computer system, the method arranged to be performed by one or more processing apparatuses, the method comprising:
Deriving metrics representative of characteristics of received input data including data related to activity on the computer system (Plurality of parameters or fields (i.e., metrics) are represented in vector format, each vector represents a different user of the website, etc. – see abstract, for example).
Analyzing the derived metrics using a model (Analysis is performed, vector is compared with other vectors in the same or similar vector spaces (i.e., model)) – see abstract and [0012], for example).
Eynon does not teach that the model is a first self-learning model trained on a normal behavior of at least the first entity, predicting an expected behavior of at least the first entity as to activity on the computer system based on the first self-learning model, or developing a pattern of life as the first self-learning model for at least the first entity, trained on the normal behavior of at least the first entity based on data associated with the first entity gathered over the one or more days
Brezinski teaches an unsupervised machine learning module (self-learning model) based on normal or typical behavior in order to detect anomalous behavior – see column 10 lines 18-36, for example. Brezinski further teaches a normal behavior threshold used by the first model that corresponds to a normal pattern of life for the computing system, where the first self-learning model of normal behavior is updated when new input data is received that is deemed within the limits of normal behavior (Classified as true positive or true negatives, which indicates either normal/typical performance (e.g., pattern of life based on data gathered over time) or anomalous behavior (threat detection system spots behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life, flags as anomalous, requires further investigation– see column 10 lines 18-36.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon by using a self-learning model trained on normal behavior and predicting expected behaviors and comparing the metrics with the predicted behavior in order to reduce required resources and keep the system up to date on threats, based upon the beneficial teachings provided by Brezinski. These modifications would result in increased efficiency and security to the system.
Eynon and Brezinksi do not teach analyzing one or more causal links between data associated with the first entity and data associated with a second entity gathered over one or more days.
Cohen-Ganor teaches a system wherein first and second fraud related risk scores associated with first and second nodes are provided. A relation strength (i.e., link) related to a relation between the first and second nodes may be determined. The relation strength and the node risk scores may be used to calculate a cluster risk score for a cluster of nodes – see [0006] and [0007].
It would have also been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon and Brezinski by analyzing links and using this to determine the risk score, in order to have a more accurate risk score based on connections with other entities, based upon the beneficial teachings provided by Cohen-Ganor. These modifications would result in increased security to the system
Regarding claim 18, Brezinksi also teaches that the pattern of life is dynamically updated as more information is gathered (i.e., self-learning), as discussed above.
Regarding claims 2, 11, and 19, Eynon teaches that the first entity is a first user or a first device forming part of the computer system, and the second entity is a second user of a second device forming part of the computer system (Analyzing actions of multiple users on a website (i.e., computer system is users which interact with particular website) – see abstract, for example).
Regarding claims 4 and 13, Eynon (in combination with Cohen-Ganor) teaches determining, in accordance with the analyzed derived metrics, a cyber-threat risk parameter indicative of a likelihood of a cyber-threat (Analysis is performed to determine if new sessions are similar or dissimilar to previously known sessions. Score calculator compares session vectors with exemplar vectors, indications that actions deviation from expected website behavior, an alert is generated that contains a corresponding score. Score is computed by comparing distance between vector and exemplar vector, and if score indicates that the individual vector deviates in any meaningful way, fraud detection is alerted) – see abstract, [0012], [0032], [0035], and claim 19. Eynon teaches that “if the generated score indicates the individual vector deviates from the exemplar vector in a meaningful way, the appropriate action is taken. Some appropriate actions to take include sending alerts to various website fraud detection systems” – see [0032]. Thus, this implies that the score does relate to a likelihood of fraud. However, if not explicitly disclosed (i.e., if Eynon only teaches that the score indicates deviation from normal behavior) it would have been obvious to one of ordinary skill in the art at the time the invention was filed, that the score itself indicate the likelihood of a cyber-attack, in order that fraud detection systems could be implemented. In addition, Cohen-Ganor teaches that the causal link is used for fraud detection, as discussed above.
In addition Brezinski teaches determining the cyber threat risk parameter comprises (i) comparing the analyzed, derived metric with the predicted expected behavior and (ii) comparing whether the parameters of the analyzed, derived metrics fall outside the parameters set by a threat parameter benchmark and (Classified as true positive or true negatives, which indicates either normal/typical (e.g., predicting expected behavior) performance or anomalous (e.g., comparing) behavior) - see column 10 lines 18-36. This would intrinsically require a threshold/benchmark of some type in order to be classified as normal/typical.
Further, Cohen-Ganor teaches (iii) considering the one or more causal links that include a comparison between a behavior of the first entity based on the analyzed derived metrics associated with the first entity to a behavior of the second entity based on analyzed derived metrics associated with the second entity (see 112 above). Cohen-Ganor teaches the casual link being a relational strength (i.e., comparison) between entities related to fraud risk, as described above.
Regarding claims 5 and 14, Brezinski further teaches where the pattern of life for the first entity is dynamically updated as more information is gathered over time of operation of the first self-learning model monitoring the first entity, where what is consider the normal behavior is used as a moving benchmark, allowing the threat detection system to spot behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life (a normal behavior threshold used by the first model that corresponds to a normal pattern of life for the computing system, where the first self-learning model of normal behavior is updated when new input data is received that is deemed within the limits of normal behavior (Classified as true positive or true negatives, which indicates either normal/typical performance (e.g., pattern of life based on data gathered over time) or anomalous behavior (threat detection system spots behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life, flags as anomalous, requires further investigation– see column 10 lines 18-36. This would also intrinsically require a threshold/benchmark of some type in order to be classified as normal/typical (i.e., normal pattern of life).
Regarding claims 6 and 15, Brezinski further teaches that the threat detection system is configured to identity the behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life as anomalous, requiring further investigation (Classified as true positive or true negatives, which indicates either normal/typical performance (e.g., pattern of life based on data gathered over time) or anomalous behavior (threat detection system spots behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life, flags as anomalous, requires further investigation– see column 10 lines 18-36).
Regarding claims 8 and 17, Eynon teaches: Determining, in accordance with the analyzed derived metrics, a cyber-threat risk parameter indicative of a likelihood of a cyber-threat (Analysis is performed to determine if new sessions are similar or dissimilar to previously known sessions. Score calculator compares session vectors with exemplar vectors, indications that actions deviation from expected website behavior, an alert is generated that contains a corresponding score. Score is computed by comparing distance between vector and exemplar vector, and if score indicates that the individual vector deviates in any meaningful way, fraud detection is alerted) – see abstract, [0012], [0032], [0035], and claim 19
Eynon teaches that “if the generated score indicates the individual vector deviates from the exemplar vector in a meaningful way, the appropriate action is taken. Some appropriate actions to take include sending alerts to various website fraud detection systems” – see [0032]. Thus, this implies that the score does relate to a likelihood of cyber-threat.
In addition, Brezinski teaches an unsupervised machine learning module (self-learning model) based on normal or typical behavior in order to detect anomalous behavior – see column 10 lines 18-36, for example. The combination of references implies a change in a pattern of activity (going from normal to unusual behavior, as discussed above).
Claims 3 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Eynon et al. (US 2010/0125908), in view of Brezinski (US 9,348,742), and in view of Cohen-Ganor et al. (US 8,661,538, and further in view of Fortier (US 2012/0317645).
The teachings of Eynon, Brezinksi, and Cohen-Ganor are relied upon for the reasons set forth above.
Regarding claims 3 and 12, Eynon, Brezinksi, and Cohen-Ganor do not teach mitigating false positive by at least considering unusual behavior by the first user as normal behavior by the first user when similar unusual behavior is conducted by the second user.
Fortier teaches: By comparing behavior on the user's computing device with behavior noted by users of thousands or more other devices, the system can have a high degree of confidence whether an application is acting normally or not. Thus, even if a user does not use an application feature often (but other users do), the system will avoid false positives and protect the user appropriately from rogue application behavior – see [0015]. Fortier also teaches: By accumulating behavior data from multiple users, the system can develop a more complete assessment of behavior that is normal or unexpected for the application – see [0021]. Therefore, Fortier suggests that if other users are performing what is first believed to be unusual behavior, than the behavior is deemed to be usual to avoid false positives.
It would have also been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon, Brezinski, and Cohen-Ganor by characterizing unusual behavior as usual if other users are also performing the same behavior, in order to avoid false positives, based upon the beneficial teachings provided by Fortier.
Claims 7, 16, and 20 are rejected under 35 U.S.C. 103(a), as being unpatentable over Eynon et al. (US 2010/0125908) in view of Brezinski (US 9,348,742) and in view of Cohen-Ganor et al. (US 8,661,538), and further in view of Mayer et al. (US 7,890,869).
The teachings of Eynon, Brezinski, and Cohen-Ganor, and are relied upon for the reasons set forth above.
Regarding claims 7, 16, and 20, Eynon, Brezinski, Marvasti, Cohen-Ganor, and Nguyen do not teach that the results of the cyber risk threat parameter or the flagged behavior are projected on a 3D graphical user interface that conveys cyber threats across a packet flow and connection topology corresponding to the computing system.
Mayer teaches a system that provides visualization of network wide risk analysis in the form of a GUI with customizable at a glance views of the network – see figures 4A and 4B (threat views), abstract, and column 13 lines 1-8. Mayer does not teach that the GUI depicts in 3D. This is however considered a design choice well within the purview of the skilled artisan.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings provided by Eynon, Brezinski, and Cohen-Ganor, by displaying the cyber threats/flagged behavior across packet flow and connections of a network on a GUI, for the purpose of visualization, thus enhancing user experience, based upon the beneficial teachings provided by Mayer.
Claims 21 and 22 are rejected under 35 U.S.C. 103(a), as being unpatentable over Eynon et al. (US 2010/0125908) in view of Eiland et al. (US 2010/0107254) and in view of Brezinski (US 9,348,742) and in view of Marvasti (US 2008/0077358), and in view of Terrell et al. (US 8,938,532).
Regarding claims 21 and 22, Eynon teaches a method for detection of a cyber threat to a computer system, the method arranged to be performed by a processing apparatus, the method comprising:
Receiving input data associated with a first entity associated with the computer system, wherein the received input data includes data relating to activity on the computer system associated with the first entity (Plurality of parameters or fields (i.e., metrics) are represented in vector format, each vector represents a different user of the website, etc. – see abstract, for example).
Deriving metrics from the input data, the metrics representative of characteristics of the received input data (Plurality of parameters or fields (i.e., metrics) are represented in vector format, each vector represents a different user of the website, etc. – see abstract, for example).
Analyzing the metrics using one or more models (Analysis is performed, vector is compared with other vectors in the same or similar vector spaces (i.e., model)) – see abstract and [0012], for example. For detecting fraud (i.e., threat) – see [0032]).
Determining, in accordance with the analyzed metrics, a cyber threat risk parameter indicative of a likelihood of a cyberthreat (Analysis is performed to determine if new sessions are similar or dissimilar to previously known sessions. Score calculator compares session vectors with exemplar vectors, indications that actions deviation from expected website behavior, an alert is generated that contains a corresponding score. Score is computed by comparing distance between vector and exemplar vector, and if score indicates that the individual vector deviates in any meaningful way, fraud detection is alerted) – see abstract, [0012], [0032], [0035], and claim 19).
wherein the derived metrics are network traffic related metrics associated with activity of the first entity on the computer system reflecting a usage of the computer system by the first entity – see [0028]. Eynon does not explicitly teach that this is over a period of time. However, the examiner takes official notice that it was notoriously well known in the art to monitor usage over a particular time period. This would ensure that the usage history is current and up to date. It would have been obvious to the skilled artisan before the effective filing date of the claimed invention to modify Eynon to include a time period for usage, for the purpose of having up to date information. See evidence US 2002/0174217 [0031] (“monitored network usage over corresponding periods of time”).
Eynon does not teach that the one or more models includes a first model arranged to analyze data for detecting a first type of threat, and a second model to analyze data for detecting a second type of threat.
Eiland teaches a method wherein multiple different types of attack models are supports for attacks associated with buffer overflow, Javascript, user-to-root, etc. – see [0020] and abstract.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings provided by Eynon, by using different models for different threats, for the purpose of using accurate and relevant models, thus enhancing security, based upon the beneficial teachings provided by Eiland.
Eynon and Eiland do not teach using a model of normal behavior of the first entity, using the model of normal behavior to determine likelihood of cyber-threat, updating the model of normal behavior of the first entity in accordance with the analyzing of the metrics, determining whether or not the cyber-threat is present by comparing the cyber-threat risk parameter with a threshold, and wherein the cyber-threat risk parameter is determined by comparing the analyzed metrics with the model of normal behavior of the first entity; and predicting an expected behavior of the first entity based on the model of normal behavior, wherein the determining the cyber-threat risk parameter comprises comparing the analyzed metrics with the expected behavior.
Brezinski teaches an unsupervised machine learning module (self-learning, which intrinsically updates) based on normal or typical behavior in order to detect anomalous behavior (i.e., cyber-threat) – see column 10 lines 18-36, for example. Brezinski further teaches a normal behavior threshold used by the first model that corresponds to a normal pattern of life for the computing system, where the first self-learning model of normal behavior is updated when new input data is received that is deemed within the limits of normal behavior (Classified as true positive or true negatives, which indicates either normal/typical performance (e.g., pattern of life based on data gathered over time) or anomalous behavior (threat detection system spots behavior for the first entity that seems to fall outside of the normal behavior for the pattern of life, flags as anomalous, requires further investigation– see column 10 lines 18-36. This would also intrinsically require a threshold/benchmark of some type in order to be classified as normal/typical (i.e., normal pattern of life). Classified as true positive or true negatives, which indicates either normal/typical (e.g., predicting expected behavior) performance or anomalous (e.g., comparing) behavior) – see column 10 lines 18-36.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon and Eiland by using a model trained on normal behavior and predicting expected behaviors and comparing the metrics with the predicted behavior, as well as updating the model, in order to reduce required resources and keep the system up to date on threats, based upon the beneficial teachings provided by Brezinski. These modifications would result in increased efficiency and security to the system.
Eynon, Eiland, and Brezenski do not teach that the threshold is a moving threshold.
Marvasti teaches dynamic (i.e., moving) thresholds that set maximums, minimums, ranges (i.e., benchmark of parameters) that model limits of normal behavior – see [0040] and [0045], for example.
It would have also been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Eynon, Eiland, and Brezinksi by using a moving benchmark of parameters, for the purpose of having a dynamic threshold, thus enhancing accuracy of the expected data, based upon the beneficial teachings provided by Marvasti.
Eynon, Eiland, Brezinski, Marvasti, do not teach that the derived metrics are derived from header analysis on an Internet Layer protocol level of the computer system.
Terrell teaches collecting with a data collection module, network layer header information from packet traffic in a network and anomalies are discovered based on that data - see abstract, column 14 lines 14-21 and claims 1 and 16, for example.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings provided by Eynon, Eiland, Brezinski, and Marvasti, by deriving the metrics from header analysis on an Internet layer protocol level, for the purpose of detecting anomalies, based upon the beneficial teachings provided by Terrell. This would increase security.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LISA C LEWIS whose telephone number is (571)270-7724. The examiner can normally be reached Monday - Thursday 7am-2pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LISA C LEWIS/Primary Examiner, Art Unit 2495