CTNF 19/002,834 CTNF 101677 Detailed Action The office action is in response to the communication dated on 12/27/2024 . Claims 1-20 are submitted for examination. Claims 1-20 are pending. Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Oath/Declaration Applicant’s oath/declaration filed on 12/27/2024 has been reviewed by the examiner and is found to conform to the requirements prescribed in 37 C.F.R. 1.63. Priority Acknowledgment is made of applicant’s claim for foreign priority under 35 U.S.C. 119 (a)-(d). Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/27/2024 has been reviewed by the examiner and is found to conform to the requirements prescribed in 37 CFR 1.97. Drawings The drawings submitted on 12/27/2024 with the instant application are acceptable for examination purposes. Specification The specification submitted on 12/27/2024 with the instant application are acceptable for examination purposes. Claim Objections 07-29-01 AIA Claim s 1, 2, 4-6, and 19 are objected to because of the following informalities: In line 5 of Claim 1, the limitation “ the event ” lacks proper antecedent basis. It is unclear whether “ the event ” is referring to one of the claimed “ at least two detected events ” or any event in a namespace. Due to this improper antecedent basis: Line 2 in dependent claim 4 inherits the ambiguity regarding what “ the event ” refers to. In line 7 of Claim 1, the limitation “ the events ” lacks proper antecedent basis. It is unclear whether “ the events ” is referring to “ each event in a non-empty set of events ” or “ the at least two detected events ”. Due to this improper antecedent basis: Line 2 in dependent Claim 5 inherits the ambiguity regarding what “ the events ” refers to. Lines 1-2 in dependent Claim 6 inherits the ambiguity regarding what “ the events ” refers to. In line 5 of Claim 2, the limitation “ the at least two events ” lacks proper antecedent basis. The limitation should read “ the at least two detected events ” to provide antecedent basis for the detected events in claim 1. In line 2 of Claim 19, the limitation “ generating a string “/proc/[pid]/ns/pid” in which [pid] is an identifier” contains a typographical error. The limitation should read “ generating a string “/proc/[pid]/ns/pid” in which “[pid]” is an identifier ” . Appropriate correction is required. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-16 and 18-20 are rejected under 35 U.S.C. 101 because the claimed inventions are directed to an abstract idea without significantly more. Claim 1 is rejected under 35 U.S.C. 101 as being directed to an abstract idea. Specifically, claim 1 is directed to a statutory category of a process as it recites a method comprising a series of steps. The recited steps of “ determining a namespace in which the event occurred”, “ascertaining whether the events … occurred in different namespaces”, and “calculating a risk score” are all directed to an abstract idea in the form of mental processes and mathematical calculation as they merely involve the typical processes of observation, evaluation, judgment, opinion, and calculation/computation. Further, the limitations of “ detecting at least two events” and “performing a cybersecurity operation” are mere analysis and security operations recited at a high level of generality, and thus, are considered as insignificantly extra-solution activity. The additional elements, such as “a computing system” and “ a namespace” , are recited at a high level of generality as the claim merely uses the computing system to perform the recited steps of the method and the namespace as an identifier for where an event occurred. In view of the combination, these additional elements do not integrate the recited judicial exception into a practical application. The claim, as a whole, does not amount to significantly more than the recited judicial exception as the aforementioned additional elements, or combination of additional elements, fail to add an inventive concept to the claim. Specifically, the limitations of “ detecting at least two events” and “performing a cybersecurity operation ” are found to be insignificantly extra-solution activity while the additional elements, such as “ a computing system ” and “ a namespace ”, are presented at a high level of generality without providing an inventive concept. In conclusion, Claim 1 is determined to be rejected under 35 U.S.C. 101 because it is directed to an abstract idea and the additional elements, individually and in combination, do not amount to significantly more than the judicial exception. Dependent claims 2 and 4-7 are rejected under 35 U.S.C. 101 because the claimed invention remains directed to an abstract idea in the form of mental processes and mathematical calculation, as they merely involve the typical processes of observation, evaluation, judgment, opinion, and calculation/computation. Furthermore, the additional elements, recited in each of the respective dependent claims as well as discussed with respect to claim 1, remain applicable and, whether considered individually or in combination, do not amount to significantly more than the judicial exception. Dependent claim 3 is rejected under 35 U.S.C. 101 because the limitation relates to the “ detecting at least two events ”, which was previously determined in claim 1 to constitute insignificantly extra-solution activity. Furthermore, the additional elements “ a sensor”, “a driver” , and “a user space probe” are generic computer components and, whether considered individually or in combination, do not add significantly more than the judicial exception. Claim 8 is rejected under 35 U.S.C. 101 because the claim recites the same operations explained in claim 1, but implemented in a computing system, which falls under the statutory category of a machine. Accordingly, the operations performed by the computing system remain directed to an abstract idea and insignificantly extra-solution activity identified in claim 1. The additional elements, such as “ a computing system”, “ digital memory”, “a processor”, “ a map data structure comprising an association of namespace identifiers with corresponding process identifiers” , and “ a namespace” , are recited at a high level of generality and merely employ well-understood, routine, and conventional (WURC) computer components that perform the recited operations. Dependent claims 9-15 are rejected under 35 U.S.C. 101 because the claimed invention remains directed to an abstract idea in the form of mental processes and mathematical calculation, as they merely involve the typical processes of observation, evaluation, judgment, opinion, and calculation/computation. Furthermore, the additional elements discussed with respect to claim 8 remain applicable and, whether considered individually or in combination, do not amount to significantly more than the judicial exception. Claim 16 is rejected under 35 U.S.C. 101 because the claim recites the same operations explained in claim 1, but implemented in a computer-readable storage medium, which falls under the statutory category of article of manufacture. Accordingly, the operations performed by the computer-readable storage medium remain directed to an abstract idea and insignificantly extra-solution activity identified in claim 1. The additional elements, such as “ a computing system” and “ namespace” , are recited at a high level of generality and merely employ well-understood, routine, and conventional (WURC) computer components that perform the recited operations. Dependent claims 18-20 are rejected under 35 U.S.C. 101 because the claimed invention remains directed to an abstract idea in the form of mental processes and mathematical calculation, as they merely involve the typical processes of observation, evaluation, judgment, opinion, and calculation/computation. Furthermore, the additional elements discussed with respect to claim 16 remain applicable and, whether considered individually or in combination, do not amount to significantly more than the judicial exception. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 1-16, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Adamson (US Patent No. 12341797 B1) in view of Chen (WO 2024067479 A1) . Regarding Claim 1: Adamson teaches a cybersecurity method performed by a computing system, the method (Adamson – [Col. 78, lines 43-48]: systems and methods described herein may involve detecting different events that occur within a compute environment and identifying affiliations between such events based on known criteria and characteristics of predefined attack patterns referred to herein as multifaceted security threats) comprising: detecting at least two events in the computing system (Adamson – [Col. 80, lines 63-66]: At operation 504 , data platform 500 … may detect a first event that occurs within the compute environment being monitored; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event that occurs within the compute environment) ; for each event in a non-empty set of events which includes the at least two detected events, determining a namespace in which the event occurred (Adamson – [Col. 86, lines 29-36]: different types of entities may be detected as having initiated the different events 702, including entities such as … a container, a process ; [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ); ascertaining whether the events in the non-empty set of events [occurred in different namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container , etc.). … Accordingly, the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) ; calculating a risk score from at least one of the events in the non-empty set of events (Adamson – [Col. 71, lines 20-26]: detecting, by a data platform monitoring a compute environment, a first event that occurs within the compute environment and is associated with a first alert score ; detecting, by the data platform, a second event that occurs within the compute environment and is associated with a second alert score ) and from at least a result of the ascertaining (Adamson – [Col. 86, lines 51-54]: the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ; [Col. 86, lines 37-39]: some or all of the events 702 that are communicated, analyzed, and ultimately aggregated to form composite event 706 … different events 702 originating from different entities (including from different types of entities) may be aggregated to form composite event 706 ; [Col. 82, lines 1-10]: the composite event may be associated with a third alert score different from the first and second alert scores) ; and performing a cybersecurity operation according to at least the risk score (Adamson – [Col. 81, lines 57-63]: in addition to the first and second events detected at operations 504 and 506 , any number of additional events, each with their own individual alert score s , may also be similarly detected and ultimately merged together into one or more composite events that help form a comprehensive event narrative for the relevant multifaceted security threat; [Col. 82, lines 11-19]: For example, if the first and second alert scores were relatively low alert scores that would be unlikely to instigate special investigational attention for either of the first and/or second events on their own, the third alert score associated with the composite event presented at operation 510 may be a relatively high alert score that is more likely to instigate such investigational attention for the composite even t (e.g., as part of an investigation into the possibility that the multifaceted security threat could be underway)) . Adamson does not teach [ascertaining whether the events in the non-empty set of events] occurred in different namespaces than each other. However, Chen teaches …occurred in different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify Adamson, further incorporating Chen to arrive at the claimed method. One would be motivated to incorporate Chen’s teachings into Adamson’s method to enhance detection of processes escaping from container namespaces into the root namespace, thereby improving security monitoring; see Chen Paragraph [0007]. Regarding Claim 2: The combination of Adamson and Chen teaches the method of claim 1 . Adamson further teaches …the at least two events (Adamson – [Col. 80, lines 33-34]: process 502 may include a plurality of operations 504 , 506 ; [Col. 80, lines 63-65]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event ; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event ) …and the detecting comprises receiving the at least two events (Adamson – [Col. 80, lines 63-65]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event ; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event ) Chen further teaches wherein: namespaces in the computing system are arranged in a namespace hierarchy which comprises a root namespace and at least one non-root namespace (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, with one parent namespace deriving two child namespaces. The parent namespace has a level of 0, and the child namespaces have a level of 1); occurred outside the root namespace (Chen – Paragraph [0137]: The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … in Figure 1, the six processes of the two child namespaces in level 1; Examiner’s Note : the six processes of the two child namespaces occurring outside of the root namespace ); and …in the root namespace (Chen – Paragraph [0137]: due to the hierarchical nature of namespaces, the parent namespace is aware of the existence of the child namespaces , and…the six processes of the two child namespaces in level 1 are mapped to PID numbers 5 to 10 of their parent namespaces , respectively). The motivation to combine the arts is the same as that of claim 1. Regarding Claim 3: The combination of Adamson and Chen teaches the method of claim 1 . Adamson further teaches wherein the detecting comprises at least one of: receiving a filesystem activity event through a fanotify listener; receiving a filesystem activity event through an inotify listener; receiving an event from a Berkeley Packet Filter sensor; receiving an event from a sensor; receiving an event from a driver; or receiving an event from a user space probe which is in a container (Adamson – [Col. 69, lines 7-21]: agents, sensor s , or similar mechanisms may be deployed on or near managed endpoints…In such an example, the endpoint protection platform may provide functionality such as: …The ability to detect and prevent threats using behavioral analysis of device activity, application activity, user activity, and/or other data) . The motivation to combine the arts is the same as that of claim 1. Regarding Claim 4: The combination of Adamson and Chen teaches the method of claim 1 . Adamson further teaches wherein determining the namespace in which the event occurred (Adamson – [Col. 86, lines 29-36]: different types of entities may be detected as having initiated the different events 702, including entities such as … a container, a process ; [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ) comprises: identifying an event process in which the event occurred (Adamson – [Col. 80, lines 33-35]: process 502 may include a plurality of operations 504 , 506 , 508 , and 510 each of which may be performed; [Col. 80, lines 63-66]: At operation 504 , data platform 500 … may detect a first event that occurs within the compute environment being monitored) ; Chen further teaches finding a namespace creation process which created the namespace in which the event occurred (Chen – Paragraph [0134]: When creating a child process using the clone or fork function, you can specify whether to create a new namespce ; Paragraph [0023]: The host machine obtains the process's data structure; the data structure includes an identifier of the namespace where the process resides) the namespace creation process being either the event process or an ancestor of the event process (Chen – Paragraph [0134]: When creating a child process using the clone or fork function, you can specify whether to create a new namespce ) in a process hierarchy in the computing system (Chen – Paragraph [0137]: due to the hierarchical nature of namespaces, the parent namespace is aware of the existence of the child namespaces, and…the six processes of the two child namespaces in level 1 are mapped to PID numbers 5 to 10 of their parent namespaces , respectively); and determining the namespace from at least the namespace creation process (Chen – Paragraph [0023]: The host machine obtains the process's data structure; the data structure includes an identifier of the namespace where the process resides) . The motivation to combine the arts is the same as that of claim 1. Regarding Claim 5: The combination of Adamson and Chen teaches the method of claim 1 . Adamson further teaches wherein the ascertaining ascertains that the events [occurred in different namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container , etc.). … the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) , and wherein the calculating calculates the risk score by at least one of: assessing a risk due to the events as though the events occurred in the same namespace as each other; assessing a risk due to the events as though the events were instigated by a same threat actor as each other; assessing a risk due to the events as though the events were coordinated with each other; or assessing a risk due to the events as though the events belong to a same attack as each other (Adamson – [Col. 81, lines 57-63]: the first and second events detected at operations 504 and 506 …may… ultimately merged together into one or more composite events that help form a comprehensive event narrative for the relevant multifaceted security threat, [Col. 78, lines 52-56]: when such events are associated or correlated with one another based on known patterns of predefined multifaceted security threats, the events in the aggregate may be determined to be indicative of an attack) . Chen further teaches … occurred in different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively). The motivation to combine the arts is the same as that of claim 1. Regarding Claim 6: The combination of Adamson and Chen teaches the method of claim 5 . Adamson further teaches wherein the ascertaining ascertains that the events occurred [in different container namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container, etc.). … the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) . Chen further teaches …in different container namespaces than each other (Chen – Paragraph [0211]: Containers: are used to provide a relatively independent and isolated running environment for processes. For example, a container contains an independent file system, namespace) , and wherein each container namespace corresponds to a respective container (Chen – Paragraph [0128]: Resources are placed in different containers (different namespaces), and each container is isolated from the others) , each container comprising an application program and any code the application program is configured to invoke upon execution of the application program (Chen – Paragraph [0003]: Container technology is a technology that packages applications into separate containers ; Paragraph [0004]: Users can create and run containers based on container images in a host machine) . The motivation to combine the arts is the same as that of claim 5. Regarding Claim 7: The combination of Adamson and Chen teaches the method of claim 1 . Chen further teaches wherein namespaces in the computing system are arranged in a namespace hierarchy (Chen – Paragraph [0137]: one parent namespace derives two child namespaces) , and the ascertaining comprises locating a shared ancestor of the namespaces in the namespace hierarchy (Chen – Paragraph [0230]: The host machine checks whether the address of the cache to which the process belongs is equal to the address in the namespace where the process is located; Paragraph [0137]: The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace, and the child namespace must be mapped to the parent namespace. Therefore, the six processes of the two child namespaces in level 1 in Figure 1 are mapped to PID numbers 5 to 10 of their parent namespaces respectively) , the shared ancestor being a container namespace which corresponds to a container (Chen – Paragraph [0137]: one parent namespace derives two child namespaces … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace; Paragraph [0128]: Resources are placed in different containers (different namespaces), and each container is isolated from the others) , the container comprising an application program and any code the application program is configured to invoke upon execution of the application program (Chen – Paragraph [0003]: Container technology is a technology that packages applications into separate containers; Paragraph [0004]: Users can create and run containers based on container images in a host machine) . The motivation to combine the arts is the same as that of claim 1. Regarding Claim 8: Adamson teaches a computing system, comprising: a digital memory; a processor in operable communication with the digital memory (Adamson – [Col. 73, lines 55-57]: A system comprising: a memory storing instructions; and one or more processor s communicatively coupled to the memory) ; a set of instructions which is not empty, the set of instructions representing a sequence of cybersecurity steps which upon execution by the processor (Adamson – [Col. 73, lines 55-58]: A system comprising: a memory storing instructions; and one or more processor s communicatively coupled to the memory and configured to execute the instructions to perform a process) : detect at least two events in the computing system (Adamson – [Col. 80, lines 63-66]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event that occurs within the compute environment being monitored; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event that occurs within the compute environment) , … identify for each event in a non-empty set of events a respective event process in which the event occurred (Adamson – [Col. 80, lines 33-34]: process 502 may include a plurality of operations 504 , 506 ; [Col. 80, lines 63-65]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event ; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event ; [Col. 11, lines 53-57]: agent 112 may collect information about the process and provide associated information to data aggregator 114 . In various embodiments, the agent may always collect/report information about certain events) , … ascertain whether the events in the non-empty set of events [occurred in different namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container , etc.). … the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) , calculate a risk score from at least the at least two events (Adamson – [Col. 71, lines 20-26]: detecting, by a data platform monitoring a compute environment, a first event that occurs within the compute environment and is associated with a first alert score ; detecting, by the data platform, a second event that occurs within the compute environment and is associated with a second alert score ) and from at least a result of the ascertaining (Adamson – [Col. 86, lines 51-54]: the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ; [Col. 86, lines 37-39]: some or all of the events 702 that are communicated, analyzed, and ultimately aggregated to form composite event 706 … different events 702 originating from different entities (including from different types of entities) may be aggregated to form composite event 706 ; [Col. 82, lines 1-10]: the composite event may be associated with a third alert score different from the first and second alert scores) , and perform a cybersecurity operation according to at least the risk score (Adamson – [Col. 81, lines 57-63]: in addition to the first and second events detected at operations 504 and 506 , any number of additional events, each with their own individual alert score s , may also be similarly detected and ultimately merged together into one or more composite events that help form a comprehensive event narrative for the relevant multifaceted security threat; [Col. 82, lines 11-19]: For example, if the first and second alert score s were relatively low alert score s that would be unlikely to instigate special investigational attention for either of the first and/or second events on their own, the third alert score associated with the composite event presented at operation 510 may be a relatively high alert score that is more likely to instigate such investigational attention for the composite even t (e.g., as part of an investigation into the possibility that the multifaceted security threat could be underway)). Adamson does not teach a map data structure residing in the digital memory, the map data structure comprising an association of namespace identifiers with corresponding process identifiers; … determine for [each event in the non-empty set of events] through use of at least the map data structure a namespace [in which the event occurred], [ascertain whether the events in the non-empty set of events] occurred in different namespaces than each other. However, Chen teaches a map data structure residing in the digital memory (Chen – Paragraph [0404]: The computer software product is stored in a memory and includes several instructions to cause a computer device … to execute all or part of the steps of the methods described in the various embodiments of this application) , the map data structure comprising an association of namespace identifiers with corresponding process identifiers (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1)…due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace, and the child namespace must be mapped to the parent namespace. Therefore, the six processes of the two child namespaces in level 1 in Figure 1 are mapped to PID numbers 5 to 10 of their parent namespaces respectively) , determine for [each event in the non-empty set of events] through use of at least the map data structure a namespace [in which the event occurred] (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1)…due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace, and the child namespace must be map ped to the parent namespace. Therefore, the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively) , [ascertain whether the events in the non-empty set of events] occurred in different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify Adamson, further incorporating Chen to arrive at the claimed system. One would be motivated to incorporate Chen’s teachings into Adamson’s system to enhance detection of processes escaping from container namespaces into the root namespace, thereby improving security monitoring; see Chen Paragraph [0007]. Regarding Claim 9: The combination of Adamson and Chen teaches the system of claim 8 . Chen further teaches wherein a process identifier in the map data structure identifies a namespace creation process which created the namespace (Chen – Paragraph [0276]: the host machine can obtain the address space pid_cachep of the process; Paragraph [0134]: When creating a child process using the clone or fork function, you can specify whether to create a new namespace) identified by the associated namespace identifier (Chen – Paragraph [0023]: The host machine obtains the process's data structure; the data structure includes an identifier of the namespace where the process resides) , the sequence of cybersecurity steps comprises matching the event process to the namespace creation process (Chen – Paragraph [0230]: The host machine checks whether the address of the cache to which the process belongs is equal to the address in the namespace where the process is located) , and the namespace creation process is either the event process or an ancestor of the event process in a process hierarchy in the computing system (Chen – Paragraph [0134]: When creating a child process using the clone or fork function, you can specify whether to create a new namespace ). The motivation to combine the arts is the same as that of Claim 8. Regarding Claim 10: The combination of Adamson and Chen teaches the system of claim 9 . Chen further teaches wherein the process hierarchy has a single global root which is an ancestor of all processes in the computing system (Chen – Paragraph [0195]: `init_nsproxy` defines the initial global namespace , which stores pointers to the initial namespace objects of each subsystem and has high privileges) , and the namespace creation process is positioned in the process hierarchy below the global root of the process hierarchy (Chen – Paragraph [0201]: When cloning or forking a child process , you can specify whether to create a new namespace ) . The motivation to combine the arts is the same as that of Claim 9. Regarding Claim 11: The combination of Adamson and Chen teaches the system of claim 8 . Adamson further teaches comprising an attack pattern discriminator (Adamson – [Col. 80, lines 29-33]: platform 500 configured to perform an illustrative process 502 for creating and presenting composite events indicative of multifaceted security threats within a compute environment monitored by the data platform; [Col. 78, lines 44-48]: detecting different events that occur within a compute environment and identifying affiliations between such events based on known criteria and characteristics of predefined attack patterns referred to herein as multifaceted security threats) , wherein the computing system ascertains that [the events occurred in different namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container , etc.). … the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) , and the computing system submits the events together to the attack pattern discriminator (Adamson – [Col. 81, lines 57-63]: the first and second events detected at operations 504 and 506 …may … ultimately merged together into one or more composite events that help form a comprehensive event narrative for the relevant multifaceted security threat; [Col. 82, lines 11-19]: the composite event presented at operation 510 may be a relatively high alert score that is more likely to instigate such investigational attention for the composite even t (e.g., as part of an investigation into the possibility that the multifaceted security threat could be underway)) . Chen further teaches … the events occurred in different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively). The motivation to combine the arts is the same as that of Claim 8. Regarding Claim 12: The combination of Adamson and Chen teaches the system of claim 8 . Chen further teaches wherein each event process is in a process hierarchy in the computing system which includes a process tree of process nodes which represent processes (Chen – Paragraph [0137]: As shown in Figure 1 … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively) , each namespace is in a namespace hierarchy in the computing system which includes a namespace tree of namespace nodes which represent namespaces (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1)) , the namespace tree corresponds to a proper subtree of the process tree (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1)…due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace, and the child namespace must be map ped to the parent namespace. Therefore, the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively) , and the sequence of cybersecurity steps matches two process nodes to a same namespace node which corresponds to a shared ancestor of the two process nodes (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively; Paragraph [0256]: the host machine can obtain the process's address space pid_cachep … it then checks whether it is the same as the pid_cache of the current namespace … it checks whether it is the same as the slab_cache of the process's namespace). The motivation to combine the arts is the same as that of Claim 8. Regarding Claim 13: The combination of Adamson and Chen teaches the system of claim 12 . Adamson further teaches wherein each namespace in which a detected event occurred (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container; [Col. 80, lines 33-34]: process 502 may include a plurality of operations 504 ; [Col. 80, lines 63-65]: At operation 504 , data platform 500 … may detect a first event ) is identified by an inode number (Adamson – [Col. 12, lines 13-19]: One way an agent can obtain a mapping between a given inode and a process identifier is to scan within the /proc/pid directory … If a file descriptor is a match for the inode, the agent can determine that the process associated with the file descriptor owns the inode) . The motivation to combine the arts is the same as that of Claim 12. Regarding Claim 14: The combination of Adamson and Chen teaches the system of claim 12 . Adamson further teaches wherein the detected events (Adamson – [Col. 80, lines 63-66]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event that occurs within the compute environment being monitored; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event that occurs within the compute environment) Chen further teaches …occurred in different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively) , and each namespace in which a detected event occurred comprises a respective container namespace which corresponds to a respective container (Chen – Paragraph [0128]: Resources are placed in different containers (different namespaces), and each container is isolated from the others) . The motivation to combine the arts is the same as that of Claim 12. Regarding Claim 15: The combination of Adamson and Chen teaches the system of claim 8 . Chen further teaches wherein the namespace in which the event occurred comprises at least one of: a process namespace, a mount namespace, a network namespace, an inter-process communication namespace, a time sharing namespace, a user namespace, a control group namespace, a time namespace, or a journal namespace (Chen – Paragraph [0128]: Currently, six different namespaces have been implemented: mount namespace, UTS namespace, inter-process communication (IPC) namespace, user namespace, process identifier (PID) namespace, and network namespace…Resources in each namespace are isolated from each other, and resources in each namespace are accessed by different processes) . The motivation to combine the arts is the same as that of claim 8. Regarding Claim 16: Adamson teaches a computer-readable storage medium configured with data and instructions which upon execution by a processor of a computing system perform a cybersecurity method (Adamson – [Col. 7, lines 44-50]: a non-transitory computer-readable medium storing computer-readable instructions may be provided in accordance with the principles described herein. The instructions, when executed by a processor of a computing device, may direct the processor and/or computing device to perform one or more operations, including one or more of the operations described herein; [Col. 78, lines 15-23]: the following description addresses how a data platform may determine… a multifaceted security threat…and what severity or importance such an issue may pose (…a full-blown attack requiring immediate investigational attention and/or mitigation/remedial action ..)) , the method comprising: detecting a first event in the computing system (Adamson – [Col. 71, lines 20-22]: A method comprising: detecting, by a data platform monitoring a compute environment, a first event that occurs within the compute environment) ; detecting a second event in the computing system, the second event different than the first event (Adamson – [Col. 71, lines 23-25]: detecting, by the data platform, a second event that occurs within the compute environment; [Col. 86, lines 46-50]: the first event may be initiated within compute environment 602 by a first entity …while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity ) ; determining [a first namespace] in which the first event occurred (Adamson – [Col. 86, lines 29-36]: different types of entities may be detected as having initiated the different events 702, including entities such as … a container, a process ; [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ) ; determining [a second namespace] in which the second event occurred (Adamson – [Col. 86, lines 29-36]: different types of entities may be detected as having initiated the different events 702, including entities such as … a container, a process ; [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ) ; ascertaining that [the first namespace and the second namespace are different namespaces than each other] (Adamson – [Col. 15, lines 13-14]: agents may use namespaces to determine whether a process is associated with a container ; [Col. 86, lines 46-60]: the first event may be initiated within compute environment 602 by a first entity … , while the second event may be initiated within compute environment 602 by a second entity distinct from the first entity (e.g., a particular container , etc.). … the identifying (at operation 508 ) of the affiliation between the first event and the second event may be based on an additional affiliation detected between the first entity and the second entity ) ; calculating a risk score from at least the first event and the second event (Adamson – [Col. 86, lines 37-39]: some or all of the events 702 that are communicated, analyzed, and ultimately aggregated to form composite event 706 … different events 702 originating from different entities (including from different types of entities) may be aggregated to form composite event 706 ; [Col. 82, lines 1-10]: the composite event may be associated with a third alert score different from the first and second alert scores) ; and performing a cybersecurity operation according to at least the risk score ((Adamson – [Col. 82, lines 11-19]: For example, if the first and second alert scores were relatively low alert scores that would be unlikely to instigate special investigational attention for either of the first and/or second events on their own, the third alert score associated with the composite event presented at operation 510 may be a relatively high alert score that is more likely to instigate such investigational attention for the composite even t (e.g., as part of an investigation into the possibility that the multifaceted security threat could be underway)) . Adamson does not teach … a first namespace … ; … a second namespace … ; [ascertaining that] the first namespace and the second namespace are different namespaces than each other. However, Chen teaches … a first namespace (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, with one parent namespace deriving two child namespaces) ; … a second namespace … (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, with one parent namespace deriving two child namespace s); … the first namespace and the second namespace are different namespaces than each other (Chen – Paragraph [0137]: one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1) … due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace … the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespaces respectively). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify Adamson, further incorporating Chen to arrive at the claimed system. One would be motivated to incorporate Chen’s teachings into Adamson’s system to enhance detection of processes escaping from container namespaces into the root namespace, thereby improving security monitoring; see Chen Paragraph [0007]. Regarding Claim 18: The combination of Adamson and Chen teaches the computer-readable storage medium of claim 16 . Adamson further teaches …in which at least one of the first event or the second event occurred (Adamson – [Col. 80, lines 63-66]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event that occurs within the compute environment being monitored; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event that occurs within the compute environment) . Chen further teaches wherein the method comprises mapping a process identifier to a namespace identifier which identifies the namespace (Chen – Paragraph [0137]: As shown in Figure 1, there are four namespaces, one parent namespace derives two child namespaces. The parent namespace has a level 0 (i.e., level 0); the child namespace has a level 1 (i.e., level 1)…due to the hierarchical nature of the namespace, the parent namespace knows the existence of the child namespace, and the child namespace must be map ped to the parent namespace. Therefore, the six processes of the two child namespaces in level 1 in Figure 1 are map ped to PID numbers 5 to 10 of their parent namespace respectively). The motivation to combine the arts is the same as that of claim 16 . 07-21-aia AIA Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Adamson (US Patent No. 12341797 B1) in view of Chen (WO 2024067479 A1) , and further in view of Zhong (CN 115630391 A) . Regarding Claim 17 The combination of Adamson and Chen teaches the computer-readable medium of claim 16 . Adamson further teaches … and wherein the detecting comprises detecting at least one of the first event or the second event [via the handle] (Adamson – [Col. 80, lines 63-66]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event that occurs within the compute environment being monitored; [Col. 81, lines 11-12]: Similarly, at operation 506 , data platform 500 may detect a second event that occurs within the compute environment) . The combination of Adamson and Chen do not expressly teach wherein the method further comprises injecting a thread which is configured to upon execution acquire a handle, …via the handle. However, Zhong teaches wherein the method further comprises injecting a thread which is configured to upon execution acquire a handle, …via the handle (Zhong – Paragraph [0011]: In the remote thread , the dynamic link library file in the dynamic link library path is injected into the memory space of the browser process; Paragraph [0025]: Trigger the dynamic link library file to obtain the browser window handle ). It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify the combination of Adamson and Chen with Zhong to arrive at the claimed invention. One would be motivated to incorporate Zhong’s teachings into the combination of Adamson and Chen’s invention to enhance user privacy across operating system’s processes using a browser anti-screenshot method; see Zhong Paragraph [0007] . 07-21-aia AIA Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Adamson (US Patent No. 12341797 B1) in view of Chen (WO 2024067479 A1) , and in further view of Michael Kerrisk “Namespaces in operation, Part 3: PID Namespaces,” published on January 16, 2013 hereby regarded to as Kerrisk . Regarding Claim 19: The combination of Adamson and Chen teaches the computer-readable medium of claim 16 . Adamson further teaches …a process in which at least one of the first event or the second event occurred (Adamson – [Col. 80, lines 33-34]: process 502 may include a plurality of operations 504 ; [Col. 80, lines 63-66]: At operation 504 , data platform 500 (e.g., computing resources operating on the data platform) may detect a first event that occurs within the compute environment being monitored) . The combination of Adamson and Chen do not expressly teach wherein the method comprises generating a string “/proc/[pid]/ns/pid” in which [pid] is an identifier of [a process in which at least one of the first event or the second event occurred], and utilizing the string to determine the namespace [in which said event occurred]. However, Kerrisk teaches wherein the method comprises generating a string “/proc/[pid]/ns/pid” in which [pid] is an identifier of a process…and utilizing the string to determine the namespace (Kerrisk – [Page 4]: By using the readlink command to display the (differing) contents of the /proc/ PID /ns/pid symbolic links…we can see that the two processes are in separate PID namespaces: # readlink /proc/27655/ns/pid pid: [4026531836] # readlink /proc/27656/ns/pid pid: [4026532412]) . It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify the combination of Adamson and Chen with Kerrisk to arrive at the claimed invention. One would be motivated to incorporate Kerrisk’s teachings into the combination of Adamson and Chen’s invention to improve monitoring and analysis of events across namespaces by identifying the pid of an event; see Kerrisk Paragraph [0007] . 07-21-aia AIA Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Adamson (US Patent No. 12341797 B1) in view of Chen (WO 2024067479 A1) , and further in view of Abhinav Shreyash “Nested Containers: Launching a Docker Container within a Docker Container,” published on August 2, 2023 hereby regarded to as Shreyash . Regarding Claim 20: The combination of Adamson and Chen teaches the computer-readable medium of claim 16 . Chen further teaches wherein each of the different namespaces is the namespace of a respective container (Chen – Paragraph [0128]: Resources are placed in different containers (different namespaces), and each container is isolated from the others) . The combination of Adamson and Chen do not expressly teach …and wherein at least one of: the respective containers are each nested within a third container; or one of the respective containers is nested within another of the respective containers. However, Shreyash teaches …and wherein at least one of: the respective containers are each nested within a third container; or one of the respective containers is nested within another of the respective containers (Shreyash – [Page 4, Section: Understanding Running Docker Containers in Docker]: Running Docker inside Docker allows you to create a nested container environment ) . It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to modify Shreyash with the combination of Adamson and Chen to arrive at the claimed invention. One would be motivated to incorporate Shreyash’s teachings into the combination of Adamson and Chen’s invention to have nested container configurations to allow for events to be detected and analyzed across different namespace levels; see Shreyash [Page 2] . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure : Liang (CN 202211603759 A) teaches a safety detection method and system in container environments. Chen (CN 119865326 A) teaches a method for detecting abnormal behaviors between systems and determining if it’s an attack. Belair (US 20230195884 A1) teaches a security management system for monitoring processes and doing a system call for determining a namespace a process. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NATHANIEL C SKIRVIN whose telephone number is (571)272-9798. The examiner can normally be reached Monday-Friday 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin Chin Shaw can be reached at (571) 272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NATHANIEL CHRISTIAN SKIRVIN/Examiner, Art Unit 2498 /YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498 Application/Control Number: 19/002,834 Page 2 Art Unit: 2498 Application/Control Number: 19/002,834 Page 3 Art Unit: 2498 Application/Control Number: 19/002,834 Page 4 Art Unit: 2498 Application/Control Number: 19/002,834 Page 5 Art Unit: 2498 Application/Control Number: 19/002,834 Page 6 Art Unit: 2498 Application/Control Number: 19/002,834 Page 7 Art Unit: 2498 Application/Control Number: 19/002,834 Page 8 Art Unit: 2498 Application/Control Number: 19/002,834 Page 9 Art Unit: 2498 Application/Control Number: 19/002,834 Page 10 Art Unit: 2498 Application/Control Number: 19/002,834 Page 11 Art Unit: 2498 Application/Control Number: 19/002,834 Page 12 Art Unit: 2498 Application/Control Number: 19/002,834 Page 13 Art Unit: 2498 Application/Control Number: 19/002,834 Page 14 Art Unit: 2498 Application/Control Number: 19/002,834 Page 15 Art Unit: 2498 Application/Control Number: 19/002,834 Page 16 Art Unit: 2498 Application/Control Number: 19/002,834 Page 17 Art Unit: 2498 Application/Control Number: 19/002,834 Page 18 Art Unit: 2498 Application/Control Number: 19/002,834 Page 19 Art Unit: 2498 Application/Control Number: 19/002,834 Page 20 Art Unit: 2498 Application/Control Number: 19/002,834 Page 21 Art Unit: 2498 Application/Control Number: 19/002,834 Page 22 Art Unit: 2498 Application/Control Number: 19/002,834 Page 23 Art Unit: 2498 Application/Control Number: 19/002,834 Page 24 Art Unit: 2498 Application/Control Number: 19/002,834 Page 25 Art Unit: 2498 Application/Control Number: 19/002,834 Page 26 Art Unit: 2498 Application/Control Number: 19/002,834 Page 27 Art Unit: 2498 Application/Control Number: 19/002,834 Page 28 Art Unit: 2498 Application/Control Number: 19/002,834 Page 30 Art Unit: 2498 Application/Control Number: 19/002,834 Page 31 Art Unit: 2498