Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims 1, 17, 18, and 20 have been amended
Claims 9, 10, and 13 have been cancelled
Claims 1-8, 11, 12, and 14-20 are pending
Priority
This application is a continuation-in-part of U.S. patent application Ser. No. 18/759,047 by Bansal and Singh, filed on Jun. 28, 2024. Therefore, the effective filing date of this application is 06/28/2024.
Response to Arguments
Applicant’s arguments 06/24/2026 filed on have been fully considered.
With respect to the claim objection to claims 18 and 20. Some of the objections have been overcome. However, claims 18 and 20 are still being objected to for reciting “transmitting one or more instructions to implementing mitigation policy”. Examiner suggests changing “implementing” to “implement”.
With respect to the USC 112(f) interpretation for claims 1, 5, 7, and 18-20. Applicant has argued that “autonomous agent”, “application-layer web application firewalls", an "autonomous agent platform" are not nonce words. Examiner respectfully disagrees. These terms do not recite of necessary structure within the claims to implement these features to overcome the USC 112(f) interpretation. Therefore, the interpretation is maintained.
With respect to the double patenting rejection with respect to applications 18/896,115, 18/759,047, and 19/096,380. The rejection has been overcome due to Applicant filing an approved terminal disclaimer.
With respect to the USC 112(b) rejection for claims 1-20 mentioned in the non-final office action mailed on 04/07/2026. The rejection has been overcome due to Applicant’s filed amendments.
With respect to the USC 103 rejection for claim 1 Applicant has argued that none of the cited references teach of the amended limitation of “transmit, to a generative language model, an input prompt including a natural language instruction to classify traffic data characterizing the network traffic as corresponding or not corresponding to an application-layer distributed denial of service attack, and (2) receive, from the generative language model, a prompt completion identifying the application-layer distributed denial of service attack”. This limitation was originally recited in now cancelled claim 10. Claim 10 was rejected using TULCZYJEW. Applicant has argued that TULCZYJEW does not teach this feature. Examiner respectfully disagrees. TULCZYJEW teaches ([TULCZYJEW, para. 0004] “The application performs the communication network analysis on input information it receives using the specialized large language model, and generates a result of the communication network analysis.”) ([TULCZYJEW, para. 0005] “the network traffic capture files include packet capture (PCAP) files.”) ([TULCZYJEW, para. 0008] “ The input information is fed to the specialized large language model to generate a prediction output. The generated result indicates a presence of anomaly when the accuracy of the prediction output is lower than a threshold whereas the generated result indicates an absence of the anomaly when the accuracy of the prediction output is not lower than the threshold.”) ([TULCZYJEW, para. 0002] “A packet capture (PCAP) file is a digital data file that serves as a record of network traffic. The PCAP file is created by network sniffing tools or packet capture software, which capture and store individual network packets as they traverse a network interface or specific network segment.”) ([TULCZYJEW, para. 0072] “FIG. 8 is a block diagram of anomaly detector 802, according to one embodiment. Anomaly detector 802 receives PCAP files 804 and predicts the likelihood that there is an anomaly in network 108 or call flows.”) ([TULCZYJEW, para. 0073] “Input generator 808 receives raw PCAP files 804 and generates processed a sequence 810 of text derived from PCAP files 803 for sending to anomaly model 832.”) ([TULCZYJEW, para. 0074] “Anomaly model 832 is a specialized large language model that masks part of data in the sequence 810 of text and predicts the masked data. The part of data (e.g., token) to be masked may be determined randomly or be predetermined. Anomaly model 832 is trained to predict masked data and generates probability distribution of the predicted data. Anomaly model 832 generates prediction on the masked data and its probability distribution as its output 834, and sends output 834 to misprediction aggregator 836.”) ([TULCZYJEW, para. 0075] “Misprediction aggregator 836 receives output 834 from anomaly model 832 and compares it with the correct information. Specifically, misprediction aggregator 836 determines whether the prediction of the masked data coincides with the actual data before the masking to determine if the prediction made by anomaly model 832 is accurate. “) ([TULCZYJEW, para. 0076] “When it is determined that an anomaly is likely to be present, output generator 840 may generate an output 842 indicating the presence of anomaly.”) As can be seen from these citations TULCZYJEW teaches of transmitting to language model a PCAP file of network traffic that contains text and getting an output from the language model telling if there is an anomaly in the network traffic. TULCZYJEW teaches of a prompt including a natural language instruction ([TULCZYJEW, para. 0073] “Input generator 808 receives raw PCAP files 804 and generates processed a sequence 810 of text derived from PCAP files 803 for sending to anomaly model 832.”) the processes sequence of text is a natural language instruction that is being fed into the language model. A text input to a language model is a natural language prompt. Furthermore, TULCZYJEW’s anomaly model is detecting an anomaly the misprediction aggregator is a check to see if the prediction made by anomaly model is accurate. It is the anomaly model that is making the prediction, and the anomaly model is the language model. TULCZYJEW does not teach of application-layer distributed denial of service attack. However, this feature is taught by DORON. The same rejection applies.
As for the newly amended limitation of “and (2) historical data indicating effectiveness of the mitigation policy”. This limitation was originally recited in claim 13. Claim 13 was rejected using DORON2. DORON2 teaches ([DORON2, para. 0019] “The various disclosed embodiments include a method and system for proactive mitigation of distributed denial of service (DDoS) attacks. … One or more workflow schemes are selected or dynamically created to efficiently and proactively mitigate the detected next steps of the attack or of the attack campaign. The workflow schemes are selected based on currently available mitigation resources and the detected attack type's”) ([DORON2, para. 0035] “an insights generator 170 is configured to receive the enriched attack events data from the detector 160 … The insights include: predictions of future attacks to be utilized in selecting workflows for mitigating the future attacks. The enriched events data may be received when anomalies are detected by the detector 160.”) ([DORON2, para. 0051] “both OOP and inline mitigation, selecting a workflow scheme defining attack signatures utilized “in the past” at one customer, to mitigate the next coming attack. The attack signatures are part of the attack feeds.”) ([DORON2, para. 0069] “(“selection or creation of workflow schemes based on attack characteristics, by the PMAG 180, ensures accurate and fast mitigation of a current attack and/or a subsequent attack. For example, one of the determined attack characteristics may include the attack signature. The optimal workflow scheme provisioned to block traffic with the attack signatures”) ([DORON2, para. 0065] “Based on the attack characteristics and optimal set of mitigation resources, the PMAG 180 may select a workflow scheme that would optimally mitigate the attack. The selection may be from workflow schemes saved in the data repository 210.”). As seen from these citations DORON2 teaches of selecting optimal mitigation resources based on workflow schemes saved in a data repository and selecting a workflow scheme defining attack signatures utilized “in the past” at one customer, to mitigate the next coming attack. Therefore, DORON2 teaches this amended limitation.
Therefore, the combination of DORON-DEVARAJAN-TULCZYJEW-DORON2 teaches all limitations of claim 1. A similar response applies to independent claims 18 and 20.
Additional arguments are moot in view of new grounds of rejection necessitated by the claim amendments.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 06/25/2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner.
Claim Objections
Claims 18 and 20 are objected to because of the following informalities: Claims 18 and 20 recite the limitation “transmitting one or more instructions to implementing mitigation policy”. Examiner suggests amending this limitation to recite “transmitting one or more instructions to implement mitigation policy”. Appropriate correction is required.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are:
“… an autonomous agent platform configured to” in claim 1
“… autonomous agent to” in claim 1
“… autonomous agent being configured to” in claims 1, 5, 7, and 18-20
“… a plurality of application-layer web application firewalls … implementing the one or more mitigation policies” in claim 1
Because these claim limitation(s) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it is being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
See specification para. [0262, 0263, and 0266-0268] for functional support for autonomous agent platform
See specification para. [0266] for hardware support for autonomous agent platform
See specification para. [0262, 0268, 0276-0278] for functional support for autonomous agent
See specification para. [0266, 0267, 0270] for hardware support for autonomous agent
See specification para. [0168, 0169] for functional support for a plurality of application-layer web application firewalls
See specification para. [0331, 0064, 0067] for hardware support for a plurality of application-layer web application firewalls
If applicant does not intend to have these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 14, 16, and 18-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 14 and 16 recite of the limitation “the one or more mitigation policies”. There is a lack of antecedent basis for this limitation. Claim 1 has now been amended to recite “the mitigation policy”. For the purpose of examination, Examiner is interpreting this limitation as “the mitigation policy”. Appropriate correction is required.
Claims 18 and 20 recite the limitation “transmitting one or more instructions to implementing mitigation policy”. However, a previous limitation recites “determining a mitigation policy”. It is unclear if the mitigation policy that is implemented is the same one as the mitigation policy that is determined. For the purpose of examination, Examiner is interpreting them to be the same and interpreting the limitation as “transmitting one or more instructions to implement the mitigation policy”. Appropriate correction is required.
Claim 19 depends on claim 18. Therefore, it also inherits the rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 4, 11, 12, 14-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over DORON (US-20180255094-A1) in view of DEVARAJAN (US-20200259792-A1), further in view of TULCZYJEW (US-20250184247-A1), and even further in view of DORON2 (US-20190199746-A1) hereinafter DORON-DEVARAJAN-TULCZYJEW-DORON2.
Regarding claim 1, DORON teaches “A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application … receiving a plurality of application-layer request messages from a plurality of sources; ([DORON, para. 0032] “FIG. 1 is an example network diagram of a multi-cloud architecture 100 utilized to describe the various disclosed embodiments. The multi-cloud architecture 100 includes a plurality of cloud computing platforms 110-1 through 110-N”) ([DORON, para. 0033] “Each of the cloud computing platforms 110-1 through 110-N, and the datacenter 120 executes a protected application 160 which is the protected entity. As noted above, a protected application 160 may be a web application, a cloud hosted application”) ([DORON, para. 0045] “The EUDs 210 are configured to access a protected application 160 … The access to the protected application 160 is through a network, such as the Internet, by means of a web browser or web application and the like installed on a EUD 210.”) ([DORON, para. 0060] “requested domain hosted in the cloud computing platform 110. For example, a request to a domain www.mysite.com”) an autonomous agent platform configured to instantiate and execute an autonomous agent to evaluate network traffic associated with a portion of the computing services environment, …; ([DORON, para. 0043] “The defense platform 140 includes a mitigation resource 250, a detector 260, and a controller 280.”) ([DORON, para. 0050] “the detector 260 in the defense platform 140 is configured to receive or collect one or more of: telemetries, alerts, and logs, that are related at least to traffic between the cloud computing platform 110 and the protected applications 160, from any reliable source regardless of its deployment. In a further embodiment, the detector 260 is configured to receive or collect telemetries from the monitoring system 235, a monitoring system 225 included in the CDN 220, or both.”) ([DORON, para. 0052] “the detector 260 is configured to operate as an application layer (layer-7) attack detector by analyzing telemetries related at least to incoming and outgoing traffic flows in order to detect flood HTTP and TCP DDoS attacks. Such analysis is based on the detection of abnormalities in the traffic flows as a deviation from normal applicative behavior. It should be noted that different types of flood DDoS attacks may be detected based on different telemetries. Specifically, the detector 260 is configured to detect TCP flood DDoS and various HTTP flood DDoS attacks.”) ([DORON, para. 0053] “the detector 260 is also configured to implement at least one detection engine … The detection engine may be configured to monitor the received telemetries, determine a set of features, and to detect flood DDoS attacks using, for example, a fuzzy logic mechanism, a machine learning based classifier, and the like. A feature is an individual measurable property of a phenomenon being observed. For example, a feature can be a number of HTTP requests per second.”) ([DORON, para. 0051] “The telemetries may be received continuously, at regular intervals (e.g., once per minute), and the like. “) [Examiner’s note: Examiner is interpreting the defense platform 140 as the autonomous agent platform and the detector 260 as autonomous agent.] an orchestration engine including one or more processors configured to determine a mitigation policy corresponding with one or more of the plurality of application … based on (1) identification of the application-layer distributed denial of service attack … ; and ([DORON, para. 0043] “The defense platform 140 includes a mitigation resource 250, a detector 260, and a controller 280.”) ([DORON, para. 0057] “In an embodiment, the mitigation resource 250 is communicatively connected to the ADC 270. Upon detection of the potential attack, the controller 280 may be configured to cause a DNS diversion from a normal path of traffic from the EUDs 210 to the mitigation resources 250.”) ([DORON, para. 0059] “The controller 280 is configured to control the traffic diversion to and from the platforms 110 and 140 as well all the mitigation functionalities. Specifically, in an embodiment, upon detection of a potential attack, the controller 280 is configured to signal a detected attack to the mitigation resource 250. The controller 280 is further configured to cause DNS traffic redirection from EUDs 210 to the defense platform 140 and, in particular, to the mitigation resource 250. The mitigation resource 250 is configured to clean the traffic by executing one or more mitigation actions”) ([DORON, para. 0061] “the mitigation resource 250 may be configured to determine when a previously detected flood DDoS attack is terminated. Upon such determination, the controller 280 returns to a peace mode of operation, i.e., DNS traffic redirection is terminated and the DNS operation is returned to its original operation”) [Examiner’s note: Examiner is interpreting the controller 280 as the orchestration engine and redirecting traffic to the mitigation resource to be cleaned as a mitigation policy] a plurality of application-layer web application … corresponding to the plurality of application … and implementing the mitigation policy to prevent a subset of subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. ([DORON, para. 0057] “In an embodiment, the mitigation resource 250 is communicatively connected to the ADC 270. Upon detection of the potential attack, the controller 280 may be configured to cause a DNS diversion from a normal path of traffic from the EUDs 210 to the mitigation resources 250. That is, when the DNS diversion has occurred, instead of flowing the traffic to the protected cloud-hosted application 160, traffic from the EUDs 210 is diverted to the defense platform 140.”) ([DORON, para. 0058] “The mitigation resource 250 performs one or more mitigation actions on the traffic and forwards legitimate clean traffic back toward the protected application 160 through the ADC 270.”) ([DORON, para. 0059] “The controller 280 is configured to control the traffic diversion to and from the platforms 110 and 140 as well all the mitigation functionalities. Specifically, in an embodiment, upon detection of a potential attack, the controller 280 is configured to signal a detected attack to the mitigation resource 250.”) ([DORON, para. 0060] “the DNS traffic redirection (for diverting traffic originally directed to the cloud computing platform 110 to the defense platform 140) includes automatically modifying a DNS record entry to point to a virtual IP (VIP) address representing a resource in the defense platform 140 and not to an IP address of the requested domain hosted in the cloud computing platform 110. For example, a request to a domain “www.mysite.com” would be replaced with “po.mysite.clouddetectorner””) ([DORON, para. 0101] “the mitigation resource cleans the traffic by removing malicious traffic”).
However, DORON does not teach of “a plurality of application gateways … a plurality of application-layer web application firewalls”.
In analogous teaching DEVARAJAN teaches of “a plurality of application gateways ([DEVARAJAN, para. 0007] “The present disclosure relates to a cloud-based Intrusion Prevention System (IPS).”) ([DEVARAJAN, para. 0049] “In an embodiment, each of the processing nodes 110 may include Internet gateways and one or more servers, and the processing nodes 110 may be distributed through a geographic region”) ([DEVARAJAN, para. 0054] “In an embodiment, an enterprise gateway may be configured so that user requests are routed through the processing node 110 by establishing a communication tunnel between the enterprise gateway and the processing node 110.”) … a plurality of application-layer web application firewalls ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls. … the firewall systems and methods are described implemented through or in conjunction with a distributed, cloud-based security system and the firewall systems and methods can be integrated with sandboxing”) ([DEVARAJAN, para. 0057] “The enterprise 200 may, for example, include a firewall (FW) 202 protecting an internal network that may include one or more enterprise servers 216 … Another firewall 203 may protect an enterprise subnet that can include user computers 206 and 208”) ([DEVARAJAN, para. 0092] “The firewall 602, through the cloud system 500, can offer granular Layer 3 (L3) through Layer 7 (L7) control of applications, in a multi-tenant cloud infrastructure. This also includes integrated logging functionality, giving customers visibility into applications down to the L3 applications running on their networks.”)
Thus, given the teaching of DEVARAJAN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of firewalls and gateways DEVARAJAN into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON. One of ordinary skill in the art would have been motivated to do so because DEVARAJAN recognizes the need to improve network protection ([DEVARAJAN, para. 0006] “there is a need for next-generation firewall systems and methods that can adapt to the evolving network.”) ([DEVARAJAN, para. 0007] “The present disclosure relates to a cloud-based Intrusion Prevention System (IPS). A cloud-based IPS enables IPS threat protection where traditional IPS systems cannot”)
However, DORON-DEVARAJAN does not teach “the autonomous agent being configured (1) transmit, to a generative language model, an input prompt including a natural language instruction to classify traffic data characterizing the network traffic as corresponding or not corresponding to an [application-layer distributed denial of service] attack, and (2) receive, from the generative language model, a prompt completion identifying the [application-layer distributed denial of service] attack … and (2) historical data indicating effectiveness of the mitigation policy”.
In analogous teaching TULCZYJEW teaches “the autonomous agent being configured (1) transmit, to a generative language model, an input prompt including a natural language instruction to classify traffic data characterizing the network traffic as corresponding or not corresponding to an [application-layer distributed denial of service attack], and (2) receive, from the generative language model, a prompt completion identifying the [application-layer distributed denial of service] attack” ([TULCZYJEW, para. 0004] “The application performs the communication network analysis on input information it receives using the specialized large language model, and generates a result of the communication network analysis.”) ([TULCZYJEW, para. 0005] “the network traffic capture files include packet capture (PCAP) files.”) ([TULCZYJEW, para. 0008] “ The input information is fed to the specialized large language model to generate a prediction output. The generated result indicates a presence of anomaly when the accuracy of the prediction output is lower than a threshold whereas the generated result indicates an absence of the anomaly when the accuracy of the prediction output is not lower than the threshold.”) ([TULCZYJEW, para. 0002] “A packet capture (PCAP) file is a digital data file that serves as a record of network traffic. The PCAP file is created by network sniffing tools or packet capture software, which capture and store individual network packets as they traverse a network interface or specific network segment.”) ([TULCZYJEW, para. 0072] “FIG. 8 is a block diagram of anomaly detector 802, according to one embodiment. Anomaly detector 802 receives PCAP files 804 and predicts the likelihood that there is an anomaly in network 108 or call flows.”) ([TULCZYJEW, para. 0073] “Input generator 808 receives raw PCAP files 804 and generates processed a sequence 810 of text derived from PCAP files 803 for sending to anomaly model 832.”) ([TULCZYJEW, para. 0074] “Anomaly model 832 is a specialized large language model that masks part of data in the sequence 810 of text and predicts the masked data. The part of data (e.g., token) to be masked may be determined randomly or be predetermined. Anomaly model 832 is trained to predict masked data and generates probability distribution of the predicted data. Anomaly model 832 generates prediction on the masked data and its probability distribution as its output 834, and sends output 834 to misprediction aggregator 836.”) ([TULCZYJEW, para. 0075] “Misprediction aggregator 836 receives output 834 from anomaly model 832 and compares it with the correct information. Specifically, misprediction aggregator 836 determines whether the prediction of the masked data coincides with the actual data before the masking to determine if the prediction made by anomaly model 832 is accurate. “) ([TULCZYJEW, para. 0076] “When it is determined that an anomaly is likely to be present, output generator 840 may generate an output 842 indicating the presence of anomaly.”)
Thus, given the teaching of TULCZYJEW, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of an input prompt includes traffic by TULCZYJEW into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON-DEVARAJAN. One of ordinary skill in the art would have been motivated to do so because TULCZYJEW recognizes the need to efficiently analyze network data ([TULCZYJEW, para. 0003] “Network administrators and engineers heavily rely on PCAP files for insights into network behavior, error diagnosis, and anomaly detection. However, traditional error detection methods involving manual examination of raw data are time-consuming and error-prone”) ([TULCZYJEW, para. 0004] “Embodiments relate to generating a specialized large language model by performing transfer learning on a base large language model trained using network traffic capture files as training data.”)
TULCZYJEW does not teach of “application-layer distributed denial of service attack”. However, DORON teaches this limitation. The same rejection as above applies.
In another analogous teaching DORON2 teaches “determine a mitigation policy based on……. (2) historical data indicating effectiveness of the mitigation policy …” ([DORON2, para. 0019] “The various disclosed embodiments include a method and system for proactive mitigation of distributed denial of service (DDoS) attacks. … One or more workflow schemes are selected or dynamically created to efficiently and proactively mitigate the detected next steps of the attack or of the attack campaign. The workflow schemes are selected based on currently available mitigation resources and the detected attack type's”) ([DORON2, para. 0035] “an insights generator 170 is configured to receive the enriched attack events data from the detector 160 … The insights include: predictions of future attacks to be utilized in selecting workflows for mitigating the future attacks. The enriched events data may be received when anomalies are detected by the detector 160.”) ([DORON2, para. 0051] “both OOP and inline mitigation, selecting a workflow scheme defining attack signatures utilized “in the past” at one customer, to mitigate the next coming attack. The attack signatures are part of the attack feeds.”) ([DORON2, para. 0069] “(“selection or creation of workflow schemes based on attack characteristics, by the PMAG 180, ensures accurate and fast mitigation of a current attack and/or a subsequent attack. For example, one of the determined attack characteristics may include the attack signature. The optimal workflow scheme provisioned to block traffic with the attack signatures”) ([DORON2, para. 0065] “Based on the attack characteristics and optimal set of mitigation resources, the PMAG 180 may select a workflow scheme that would optimally mitigate the attack. The selection may be from workflow schemes saved in the data repository 210.”)
Thus, given the teaching of DORON2, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of selecting a mitigation policy by DORON2 into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON-DEVARAJAN-TULCZYJEW. One of ordinary skill in the art would have been motivated to do so because DORON2 recognizes the need to effectively mitigate a threat ([DORON2, para. 0007] “existing systems for mitigating ongoing attacks only react to already ongoing attacks, and, consequently, often fail to mitigate some or all of the damage from the attacks.”) ([DORON2, para. 0010] “Certain embodiments disclosed herein include a method for reducing a time to mitigate distributed denial of service (DDoS) attacks. … determining a set of optimal mitigation resources assigned to the secured environment; selecting, based on the set of optimal mitigation resources and the attack characteristics, at least one optimal workflow scheme”)
Regarding claim 18, this claim recites of a method that performs the features of computing services environment of claim 1. Therefore, claim 18 is rejected in a similar manner. DEVARAJAN further teaches “the one or more instructions being transmitted via a communication interface to one or more of a plurality of application-layer web application firewalls corresponding to the plurality of application gateways.” ([DEVARAJAN, para. 0126] “If Web policy and FW policy are configured for a Web application, Web policy is applied first and then FW policy will be enforced. The policy engine 694 is configured to enforce Web and firewall policies and to send the traffic 680 to the Internet 504.”) ([DEVARAJAN, para. 0127] “The firewall engine 690 analyzes the traffic through a network services/DPI engine (step 728), applies firewall policy (step 730)”) ([DEVARAJAN, para. 0167] “The user, behind a gateway, sends traffic via a primary IPSEC tunnel to the cloud system 500 for accessing the SaaS or the Internet 504 (step S1).”) ([DEVARAJAN, para. 0168] “when traffic is sent to the cloud node 502 (or the processing node 110), all traffic first hits the firewall engine.”)
The same motivation to modify DORON with DEVARAJAN as in the rejection of claim 1 applies.
Regarding claim 20, this claim recites of one or more non-transitory computer readable media having instructions stored thereon for performing a method similar to that of claims 1 and 18. Therefore, claim 20 is rejected in a similar manner as in the rejection of claims 1 and 18.
Regarding claim 4, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches “wherein the portion of the computing services environment corresponds to a domain accessible via the computing services environment. ([DORON, para. 0060] “the DNS traffic redirection (for diverting traffic originally directed to the cloud computing platform 110 to the defense platform 140) includes automatically modifying a DNS record entry to point to a virtual IP (VIP) address representing a resource in the defense platform 140 and not to an IP address of the requested domain hosted in the cloud computing platform 110. For example, a request to a domain “www.mysite.com” would be replaced with “po.mysite.clouddetectorner”, where such a fully qualified domain name (FQDN) is identified by a different domain name.”)
Regarding claim 11, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches “wherein the computing services environment is provided by a service provider, ([DORON, para. 0035] “The protection of the application 160 hosted in the multi-cloud architecture 100 against flood DDoS attacks is performed by means of the defense platform 140. In an embodiment, the defense platform 140 is a cloud computing platform managed by a cloud security vendor (or managed security service provider) that is not one of the service providers of the cloud computing platforms 110-1 through 110-N.”)
DEVARAJAN further teaches “… and an application-layer web application firewall of the plurality of application-layer web application firewalls resides in a cloud computing infrastructure hosted by a public cloud provider other than the service provider.” ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls … providing a software-based cloud solution, such as a Virtualized Network Function (VNF) in the cloud. The firewall systems and methods support application awareness to identify application regardless of port, protocol, evasive tactic, or Secure Sockets Layer (SSL)”) ([DEVARAJAN, para. 0084] “the cloud system 500 can be multi-tenant in that it operates with multiple different customers (enterprises), each possibly including different policies and rules. One advantage of the multi-tenancy and a large volume of users is the zero-day/zero-hour protection in that a new vulnerability can be detected and then instantly remediated across the entire cloud system 500.”) ([DEVARAJAN, para. 0092] “The firewall 602, through the cloud system 500, can offer granular Layer 3 (L3) through Layer 7 (L7) control of applications, in a multi-tenant cloud infrastructure.
The same motivation to modify DORON with DEVARAJAN as in the rejection of claim 1 applies.
Regarding claim 12, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches “wherein the computing services environment is provided by a service provider, ([DORON, para. 0035] “The protection of the application 160 hosted in the multi-cloud architecture 100 against flood DDoS attacks is performed by means of the defense platform 140. In an embodiment, the defense platform 140 is a cloud computing platform managed by a cloud security vendor (or managed security service provider) that is not one of the service providers of the cloud computing platforms 110-1 through 110-N.”)
DEVARAJAN further teaches “… and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider. ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls … providing a software-based cloud solution, such as a Virtualized Network Function (VNF) in the cloud. The firewall systems and methods support application awareness to identify application regardless of port, protocol, evasive tactic, or Secure Sockets Layer (SSL)”) ([DEVARAJAN, para. 0084] “the cloud system 500 can be multi-tenant in that it operates with multiple different customers (enterprises), each possibly including different policies and rules. One advantage of the multi-tenancy and a large volume of users is the zero-day/zero-hour protection in that a new vulnerability can be detected and then instantly remediated across the entire cloud system 500.”)
The same motivation to modify DORON with DEVARAJAN as in the rejection of claim 1 applies.
Regarding claim 14, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON2 further teaches “wherein the one or more mitigation policies includes a timeout indicating a point in time at which to revert a mitigation policy of the one or more mitigation policies to a previous state. ([DORON2, 0079] “S340 may include, for example, selecting a workflow to mitigate a predicted attack and comparing the selected workflow to a workflow that is currently being utilized.”) ([DORON2, 0080] “S340 may include modifying a workflow scheme, configuring a new security service with a mitigation resource, or both. For example, if the scheme in an inline mitigation resource cannot handle a L7 attack due to lack of HTTP mitigation policy, then the mitigation resource will be configured with that policy”) ([DORON2, 0081] “upon receiving an indication that the attack has been mitigated or ended, the configuration of the selected mitigation resources can be reverted to a peace mode configuration. The peace mode configuration may be a default configuration of each mitigation resource.”).
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW with DORON2 as in the rejection of claim 1 applies.
Regarding claim 15, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DEVARAJAN further teaches “wherein the plurality of application-layer web application firewalls are arranged in a plurality of different cloud computing architectures, ([DEVARAJAN , para. 0046] “Also, the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls.”) ([DEVARAJAN , para. 0057] “The enterprise 200 may, for example, include a firewall (FW) 202 protecting an internal network that may include one or more enterprise servers 216, a lightweight directory access protocol (LDAP) server 212, and other data or data stores 214. Another firewall 203 may protect an enterprise subnet that can include user computers 206 and 208”) wherein the orchestration engine is further configured to transmit control signals to the plurality of application-layer web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. ([DEVARAJAN , para. 0095] “The firewall 602 also can provide basic stateful firewall functionality for common Layer 3 (L3) applications, allowing for the configuration of any one of these applications to traverse through the firewall 602. The user will now be capable of managing and controlling which protocols and applications are allowed through the firewall 602 and which ones are dropped.”) ([DEVARAJAN , para. 0126] “The policy engine 694 is configured to enforce Web and firewall policies and to send the traffic 680 to the Internet 504.”) ([DEVARAJAN , para. 0165] “As described herein, the cloud firewall 602 is implemented by the cloud system 500 and/or the distributed security system 100, via the cloud node 502 or the processing node 110. The cloud firewall 602 provides a proxy-based firewall architecture, and FIG. 28 illustrates functional modules for supporting such architecture.”)
The same motivation to modify DORON with DEVARAJAN as in the rejection of claim 1 applies.
Regarding claim 16, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches “wherein the one or more mitigation policies includes a network layer rule or a transport layer rule preventing a subsequent application-layer request message from a source from reaching the one or more components of the computing services environment. ([DORON, para. 0059] “The mitigation resource 250 is configured to clean the traffic by executing one or more mitigation actions, and to send the clean traffic directly to the servers 165 for use by the protected application 160. Alternatively, the clean traffic is provided to the ADC 270, which directs such traffic to servers 165 for use by the protected application 160.”) ([DORON, para. 0101] “the mitigation resource cleans the traffic by removing malicious traffic and sends the clean traffic to at least one server hosting the protected application. In another embodiment, the mitigation action includes automatic configuration of ACLs in the cloud computing platform to prevent direct access to the protected application.”)
Regarding claim 17, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches “wherein the input data includes information selected from the group consisting of: backend metric data, threat service data, computing services environment component performance data, traffic level data, text-based data, and the historical data. ([DORON, para. 0050] “the detector 260 in the defense platform 140 is configured to receive or collect one or more of: telemetries, alerts, and logs, that are related at least to traffic between the cloud computing platform 110 and the protected applications 160, from any reliable source regardless of its deployment.”) ([DORON, para. 0051] “The telemetries may be received continuously, at regular intervals (e.g., once per minute), and the like. The telemetries may be related to, but are not limited to, CPU utilization, latency, TCP connections count (new and current connections), a TCP connections size, a HTTP sessions size, layer-7 HTTP methods or verbs count, other request counts, transaction volume, error rate, memory usage, combinations thereof, and the like. The telemetries may be predefined by one or more operators or owners of the cloud computing platform 110.”) [Examiner’s note: Examiner is interpreting para. 0051 of DORON to teach input data consisting of traffic level data.]
Claims 2, 3, 5-8, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over DORON-DEVARAJAN-TULCZYJEW-DORON2 in view of BOYER (US-20240045990-A1), hereinafter DORON-DEVARAJAN-TULCZYJEW-DORON2-BOYER.
Regarding claim 2, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. However DORON-DEVARAJAN-TULCZYJEW-DORON2 does not teach “wherein the autonomous agent is instantiated and executed upon receipt of an instruction from a human agent”.
In analogous teaching BOYER teaches “wherein the autonomous agent is instantiated and executed upon receipt of an instruction from a human agent.” ([BOYER, para. 0060] “an external endpoint identified as likely malicious by a cyber security appliance can then be reported to the cyber security hub. This can be analyzed by a human cyber threat analyst and if it is determined that this end point is indeed likely malicious, the other cyber security appliances can then be informed. The cyber threat detection engines of other cyber security appliances can then monitor for traffic to the identified malicious endpoint on their networks.”) ([BOYER, para. 00156] “A user interface for the response module can program the autonomous response engine i) to merely make a suggested response to take to counter the cyber threat that will be presented on a display screen and/or sent by a notice to an administrator for explicit authorization when the cyber threat is detected”) ([BOYER, para. 00188] “The autonomous response engine can also reference its artificial intelligence trained to perform mitigation actions. … The cyber professional can also indicate what types of mitigation actions can be performed for different users and parts of the system as well as what actions need the cyber professional to approve.”).
Thus, given the teaching of BOYER, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of receipt of an instruction from a human agent by BOYER into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON- DEVARAJAN. One of ordinary skill in the art would have been motivated to do so because BOYER recognizes the need to improve cyber threat detection ([BOYER, para. 0037] “the cyber threat analyst module 120 cooperating with the AI model(s) 160 trained with machine learning on how to form cyber threat hypotheses and how to conduct investigations for a cyber threat hypothesis in the AI-based cyber security appliance 100 provides an advantage as it reduces the time taken for human led or cyber security investigations, provides an alternative to manpower for small organizations and improves detection (and remediation) capabilities within the cyber security appliance 100.”)
Regarding claim 3, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. However DORON-DEVARAJAN-TULCZYJEW-DORON2 does not teach “wherein the autonomous agent is instantiated and executed upon determining that a traffic metric associated with the portion of the computing services environment exceeds a designated threshold.”
In analogous teaching BOYER teaches “wherein the autonomous agent is instantiated and executed upon determining that a traffic metric associated with the portion of the computing services environment exceeds a designated threshold. ([BOYER, para. 0029] “the analyzer module 115 and AI model(s) 160 can rapidly detect and then the autonomous response module 140 will autonomously respond to overt and obvious cyberattacks. However, thousands to millions of low level anomalies occur in a domain under analysis all of the time; and thus, most other systems need to set the threshold of trying to detect a cyberattack by a cyber threat at level higher than the low level anomalies examined by the cyber threat analyst module 120 just to not have too many false positive indications of a cyberattack when one is not actually occurring”) ([BOYER, para. 0078] “The autonomous response engine, rather than the human taking the action, is configured to autonomously cause the one or more mitigation actions to be taken to contain the cyber threat when a threat risk parameter from an assessment module in the detection engine is equal to or above an actionable threshold.”)
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW-DORON2 with BOYER as in the rejection of claim 2 applies.
Regarding claim 5, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches of “application-layer distributed denial of service attack” as can be seen in the rejection of claim 1. Therefore, the same rejection applies. However, DORON-DEVARAJAN-TULCZYJEW-DORON2 does not teach “wherein the autonomous agent is configured to determine novel thought text characterizing a virtual thought explaining why the network traffic is indicative of the … attack”.
In analogous teaching BOYER teaches “wherein the autonomous agent is configured to determine novel thought text characterizing a virtual thought explaining why the network traffic is indicative of the … attack. ([BOYER, para. 0063] “The natural language input is then analyzed by the interactive cyber security user interface 710 to generate one or more queries in order to enable the interactive cyber security interface 710 to provide a response to the human cyber security operative.”) ([BOYER, para. 0064] “Based on the contextual information and the content of the natural language input received by the interactive cyber security user interface 710, the LLM module determines one or more components of the cyber security system to query. … Therefore, the LLM module may determine that the cyber security user interface 710 should query the response engine 140 to obtain information regarding any ongoing threats (in response to the context of informing about any “active threats”) as well determining to query the prediction engine 105 to obtain information about potential threats (in response to the context of informing about any “future risks”).”) ([BOYER, para. 0068] “In order that all of the information within each of these responses is presented in a concise and helpful manner for a human cyber security operative, the interactive cyber security user interface 710 may process the responses received from each of the queried components of the cyber security system using the LLM module to collate and/or summarize the information received in the responses. In fact, the LLM module may process a single response received from just one component of the cyber security system in this manner, to convert it into an appropriate output for the human cyber security operator.”) ([BOYER, para. 0161] “The detection engine monitoring the example network being protected detects a potential cyber threat. The detection engine informs all the other engines of the new detection and details (e.g. the symptoms detected and any devices possibly compromised). The detection engine also sends a report to the human security team to review.”) ([BOYER, para. 0181] “the detection engine can use historic IaaS data on virtual resource usage to understand when a client is undergoing some kind of DDOS and the autonomous response engine acts to do scaling to handle the load until the overload is over.”) ([BOYER, para. 0118] “The cyber security appliance 100 works with network probes to monitor network traffic and store and record the data and metadata associated with the network traffic in the data store.”)
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW-DORON2 with BOYER as in the rejection of claim 2 applies.
Regarding claim 6, DORON-DEVARAJAN-TULCZYJEW-DORON2-BOYER teach all limitations of claim 5. DORON further teaches of “application-layer distributed denial of service attack” as can be seen in the rejection of claim 1. Therefore, the same rejection applies.
BOYER teaches “wherein the novel thought text includes a textual indicator indicating that the autonomous agent has identified the … attack. ([BOYER, para. 0064] “Based on the contextual information and the content of the natural language input received by the interactive cyber security user interface 710, the LLM module determines one or more components of the cyber security system to query. … Therefore, the LLM module may determine that the cyber security user interface 710 should query the response engine 140 to obtain information regarding any ongoing threats (in response to the context of informing about any “active threats”) as well determining to query the prediction engine 105 to obtain information about potential threats (in response to the context of informing about any “future risks”).”) ([BOYER, para. 0068] “In order that all of the information within each of these responses is presented in a concise and helpful manner for a human cyber security operative, the interactive cyber security user interface 710 may process the responses received from each of the queried components of the cyber security system using the LLM module to collate and/or summarize the information received in the responses. In fact, the LLM module may process a single response received from just one component of the cyber security system in this manner, to convert it into an appropriate output for the human cyber security operator.”)
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW-DORON2 with BOYER as in the rejection of claim 2 applies.
Regarding claim 7, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. However, DORON-DEVARAJAN-TULCZYJEW-DORON2 does not teach “wherein the autonomous agent is configured to determine novel action text describing a recommended course of action determined by the autonomous agent.”
In analogous teaching BOYER teaches “wherein the autonomous agent is configured to determine novel action text describing a recommended course of action determined by the autonomous agent. ([BOYER, para. 0046] “The communication module can cooperate with the cyber security restoration engine to communicate with the other Artificial Intelligence-based engines of the cyber security system. Again, the machine-learned tasks of the other Artificial Intelligence-based engines can include i) identifying the cyber threat itself and ii) taking one or more mitigation actions to mitigate the cyber threat during a cyberattack by the cyber threat. … In addition, the cyber security restoration engine can send a request to the human cyber security team to take similar actions where it has no direct capability to do so itself but can recommend the remediation and recovery steps.”) ([BOYER, para. 0174] “The human cyber security team reviews the updated report from the detection engine. The human team is active and occasionally needs to confirm recommendations or make decisions, but a large part of the overall incident response is assisted by the AI engines working together without human input.”)
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW-DORON2 with BOYER as in the rejection of claim 2 applies.
Regarding claim 8, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 1. DORON further teaches of “application-layer distributed denial of service attack” as can be seen in the rejection of claim 1. Therefore, the same rejection applies. However, DORON-DEVARAJAN-TULCZYJEW-DORON2 does not teach “wherein identification of the … attack depends in part upon text-based instructions provided by a human agent via a chat interface”.
In analogous teaching BOYER teaches “wherein identification of the application-layer distributed denial of service attack depends in part upon text-based instructions provided by a human agent via a chat interface. ([BOYER, para. 0169, fig. 11] “The restoration engine sends another report after its analysis to the human cyber security team. The report communicates that it cannot be sure whether an initially compromised device can be trusted now and it recommends rebuilding from an effective date prior to the initial indications of the cyberattack. This a major operation and the device and its user will lose some data. The cyber-security restoration engine checks with the human team to obtain approval to perform this restoration action. … The restoration engine enables human security teams to make quick and confident decisions with the goal of keeping the business up and running. The report can identify assets affected by a cyberattack, their condition, and how best to restore them during and after an attack.”) ([BOYER, para. 0171, fig. 12] “The human security team confirms the recommended device rebuild. The restoration engine communicates back to the detection engine and the human cyber security team after it has automatically recovered an affected account. The detection engine reviews the information from the restoration engine and can choose to enhance the monitoring of this account temporarily, since its recent attack makes it more likely to be attacked again or for new activity to reveal the restoration did not fully resolve the problem.”) ([BOYER, para. 0082] “The interactive cyber security user interface 710 (e.g. a form a chatbot) receives supplied input from a user, whether it be via written or voice input from supplied from the user from a number of different input sources, such as the UI of the local cyber security appliance 100”) [Examiner’s note: Figure 9-14 show a human security team working alongside AI detection engines to overcome cyber threats using text based instructions.]
The same motivation to modify DORON-DEVARAJAN-TULCZYJEW-DORON2 with BOYER as in the rejection of claim 2 applies.
Regarding claim 19, DORON-DEVARAJAN-TULCZYJEW-DORON2 teach all limitations of claim 18. Furthermore, this claim recites of features similar to that of claims 5 and 6. Therefore, claim 19 is rejected in a similar manner as in the rejection of claims 5 and 6.
Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s
disclosure.
O'Hara (US-20210360023-A1): This prior art teaches of system and method for detecting a Denial of Service (DoS) attack. A number of evaluator elements (M) is determined for DoS analysis for network connection requests wherein each evaluator element is preferably associated with a component of the analyzed connection request. A DoS evaluator element score is determined for an evaluator element of the connection request by analyzing the evaluator element. DoS mitigation actions may be performed on the connection request if the determined evaluator element score is indicative of a DoS attack. An evaluator consolidated score (which may be weighted) is then calculated preferably consisting of one or more of the respective DoS evaluator element scores. Next, a determination is made as to whether each evaluator element of the M evaluator elements has been analyzed for determining a respective DoS evaluator element score. If no, a DoS evaluator element score for a succeeding evaluator element to be analyzed is then determined. And if yes, a determination is then made as to whether the value of the evaluator consolidated score is indicative of a DoS attack by the subject analyzed network connection request.
Reddy (US-10728280-B2): This prior art teaches of a device in a network receives an attack mitigation request regarding traffic in the network. The device causes an assessment of the traffic, in response to the attack mitigation request. The device determines that an attack detector associated with the attack mitigation request incorrectly assessed the traffic, based on the assessment of the traffic. The device causes an update to an attack detection model of the attack detector, in response to determining that the attack detector incorrectly assessed the traffic.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.A./
09/03/2026
/AFAQ ALI/Examiner, Art Unit 2434
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434