Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over McCarthy et al (2024/0305664) in views Sellars et al (WO 2024/145598), Crabtree et al (2023/0370490) and further in views of Liu et al (CN118645248).
For claim 1, McCarthy teaches a computer-implemented method for mitigating cybersecurity threats to a digital system (abstract), the method comprising: receiving multi-modal data representing an access attempt to the digital system (McCarthy teaches of accessing a plurality of network-connected cybersecurity threat protection applications; receiving a plurality of inputs from the cybersecurity threat protection applications, wherein the plurality of inputs is received in response to one or more cybersecurity events as McCarthy teaches in par.7); providing the multi-modal data to a neural network (McCarthy teaches of providing Data to the neural network though inputs such as input 1 510, input 2 512, input 3 514, and input 4 516. While four inputs are shown, other numbers of inputs can also be applied to the neural network. The data can include training data, production data, etc as McCarthy teaches in par.57), wherein layers of the neural network are trained (McCarthy teaches of the neural network for machine learning comprises a plurality of layers, where the layers can include one or more of an input layer, an output layer, a convolutional layer, a bottleneck layer, an activation layer, and the like and a trained neural network as McCarthy teaches in par.29 and 56); receiving, 120 from the cybersecurity threat protection applications, the inputs can include alarms, alerts, notifications, status changes and updates, warnings, etc., the plurality of inputs can be received from one or more network-connected cybersecurity threat protection applications which is to identify potential indicators of compromise or indicators of attack as McCarthy teaches in par.25), in response to receiving the indication that the access attempt to the digital system is unauthorized (McCarthy teaches wherein the plurality of inputs is received in response to one or more cybersecurity events; initiate a cybersecurity mitigation, wherein the initiating is triggered by an analysis of the one or more cybersecurity events, wherein the analysis is performed on a network-connected computer platform as McCarthy teaches in par.78), accessing a machine-learning model trained to generate a corresponding mitigation strategy based on a plurality of features of the multi-modal data (McCarthy teaches of once the SOAR management system receives the alert, further mitigation steps taken by a human administrator or a machine learning model should begin mitigation. In this example, a successful mitigation response from the SOAR system to a malware or virus attack on a user workstation should occur in eight minutes or less after the initial detection of a problem on a workstation. As the event progresses, additional metrics can be collected and compared to metrics in the success metric library as McCarthy teaches in par.48), wherein the machine learning model comprises a decision tree ((McCarthy teaches that cybersecurity threat management and mitigation requires decision-making processes which equivalent as decision tree based on the significance of the threat the scope of the threat impact, and the resources required to deploy and confirm a satisfactory mitigation, including the timing of the mitigation steps, as well as other factors as McCarthy teaches in par.32), the decision tree is updated using a reinforcement learning process based on information on effectiveness of prior responses to other cybersecurity threats (McCarthy teaches that cybersecurity threat management and mitigation requires decision-making processes which equivalent as decision tree based on the significance of the threat The library of cybersecurity mitigation success metrics can be used to validate a cybersecurity mitigation event based on achieving one or more of the cybersecurity mitigation success metrics. For example, success metrics related to a cybersecurity virus attack on a group of users can include the time it takes system administrators to acknowledge and respond to an anti-virus alert, the amount of time required to refresh or rebuild infected workstations, the number of workstations impacted, the version of anti-virus software and signature libraries running on infected workstations, the amount of time required to disconnect infected workstations from the network, and so on. These metrics can be used by the SOAR system to compare cybersecurity events to successful event metrics from previous occasions as McCarthy teaches in par.48); and generating one or more signals configured to implement at least a portion of the corresponding mitigation strategy generated by the machine-learning model (McCarthy teaches that the correct mitigation steps are selected and brought to bear on the threat immediately after the threat is identified; in which the correct mitigation steps are successfully deployed and implemented on all network points under threat; in which prevention steps are clearly identified and put in place to prevent future occurrences; and in which all steps taken from the beginning to the end of the event are clearly logged and documented for network security staff and control systems to review and integrate into future security policies as McCarthy teaches in par.34).
McCarthy fails to teach wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized; receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized, the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Sellars teaches, similar system, wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized (Sellars teaches that GNN model suspects/ determines that the graph of the current cyber incident has a very high probability of having something bad/ malicious occur, such as unauthorized encryption as Sellars teaches in par.80); receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized (Sellars teaches that identify and understand the events occurring in the ongoing cyber incidents and to check how closely the events relate to confirmed malicious cyber incidents to be classified into the type of cyber incident assigned the score indication of how bad the ongoing cyber incident is as Sellars teaches in par.71). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized as taught and suggested by Sellars for the purpose of analyzing events occurring in ongoing cyber incidents, to cooperate with a scoring classifier, and to turn the analyzed events occurring in the ongoing cyber incidents into actionable information reported by a user interface to a user (Sellars, abstract). McCarthy, as modified by Sellars, do not explicitly teach the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Crabtree teaches, similar system, the machine learning model comprises a decision tree that includes multiple paths (Crabtree teaches the advanced cyber decision platform uses machine learning algorithms to analyze system-wide data to detect threats with randomly selected decision tree commencing from that node's expanded choices may be undertaken, until the simulation or game ends decisively and continually searching and expanding new gameplay paths or simulation choices, with optional weights towards specific node selection as Crabtree teaches in par.158 and 159), each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights (Crabtree teaches This choice may be biased or weighted in certain ways, such as picking leaf nodes of game states that already have favorable win/loss ratios, so as to prioritize the exploration of high-value game states and decisions and to be biased in favor of certain choices for a playout, to attempt to explore “better” choices that may be more likely to end in a favorable result as Crabtree teaches in par.159, 161-164). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include decision tree that includes multiple paths, each path associated with a weight as taught and suggested by Crabtree for the purpose of achieving extremely high performance in the simulated environment or game being analyzed and to try and locate more optimal paths in shorter periods of time than a random or undirected search might reveal (Crabtree, par.167). McCarthy, as modified by Sellars and Crabtree, do not explicitly teach Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths.
Liu teaches, similar system, Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths (Liu teaches of the weight of all decision tree paths in the initialization model is 1, then, the model is iteratively updated by using the marked data, which is specifically as follows: randomly selecting a sample from the mark data, and detecting the sample by a model; if the detection is correct, that is, the detection result is consistent with the label, the next sample is continuously selected; if the detection is wrong, that is, the detection result is not consistent with the label, the weight on the corresponding path is adjusted according to the type of the sample, the weight of the positive type is reduced, and the weight of the negative type is increased; This process continues until the tag data set is empty as Liu teaches in par.112-116 on machine translation). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy, as modified by Sellars and Crabtree, to include in response to selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths as taught and suggested by Liu for the purpose of performing abnormal detection on the psychological sand table sample, which improves the identification accuracy and improves the effect of abnormal psychological sand table detection (Liu, abstract).
For claim 2, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 1, further teaches wherein the information on effectiveness of the prior responses to other cybersecurity threats is stored in a database accessible to the machine-learning model (McCarthy teaches success criteria metric 214 stored in the library 210 can state that the time from initial detection of a suspect file on a user station to a response by a cybersecurity administrator should be eight minutes or less as McCarthy teaches in par.40).
For claim 3, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 2, further teaches wherein the database is configured to store features of the other cybersecurity threats and historical data indicative of corresponding prior responses to the other cybersecurity threats (McCarthy teaches stores instructions; one or more processors attached to the memory wherein the one or more processors, when executing the instructions which are stored, are configured to: access a plurality of network-connected cybersecurity threat protection applications McCarthy in par.8).
For claim 4, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 3, further teaches wherein the database includes information on one or more security policies associated with the other cybersecurity threats (McCarthy teaches that cybersecurity attacks are frequent and continue to change as culprits refine their attempts to interfere with and steal from legitimate computer networks, security systems, policies, and practices must continue to learn and grow to maintain proper functioning of the systems and users they serve as McCarthy teaches in par.34).
For claim 5, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 3, further teaches wherein generating the corresponding mitigation strategy comprises: generating a measure of similarity of the access attempt to other cybersecurity threats based on the features of the multi-modal data and the features of the other cybersecurity threats; and generating the corresponding mitigation strategy based on the measure of similarity (McCarthy teaches that attack involving multiple workstations, the amount of time required to update all related workstations with mitigating software patches can be compared to an optimal time for the same number of workstations, or the time per workstation or network node as recorded in the success library as McCarthy teaches in par.40).
For claim 6, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 2, further teaches storing information on the access attempt and the corresponding mitigation strategy in the database (par.78).
For claim 7, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 6, further teaches determining an effectiveness of the corresponding mitigation strategy; and updating the database to store information on the effectiveness of the corresponding mitigation strategy (McCarthey teaches of updating the library of cybersecurity mitigation success metrics. The updating can be based on an additional input from the cybersecurity threat protection applications. The updating can also be based on analysis by the network-connected computer platform. The analysis can include metadata analysis, where metadata can be received from at least one of the group of cybersecurity threat protection applications as McCarthy teaches in par.9).
For claim 8, McCarthy, in view of Sellars, Crabtree and Liu, discloses the method of claim 6, further teaches wherein the updated database is used in the reinforcement learning process to update the decision tree (McCarthey teaches of Cybersecurity threat management and mitigation requires decision-making based on the significance of the threat, the scope of the threat impact, and the resources required to deploy and confirm a satisfactory mitigation, including the timing of the mitigation steps, as well as other factors and updating is based on additional input from the cybersecurity threat protection applications, analyses by the SOAR network-connected computer platform 232, and metadata analysis received from at least one of the plurality of cybersecurity threat protection applications as McCarthy teaches in par.71).
For claim 9, McCarthy teaches A system (abstract) comprising one or more computers and one or more storage devices on which are stored instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations (par.28) comprising : receiving multi-modal data representing an access attempt to the digital system (McCarthy teaches of accessing a plurality of network-connected cybersecurity threat protection applications; receiving a plurality of inputs from the cybersecurity threat protection applications, wherein the plurality of inputs is received in response to one or more cybersecurity events as McCarthy teaches in par.7); providing the multi-modal data to a neural network (McCarthy teaches of providing Data to the neural network though inputs such as input 1 510, input 2 512, input 3 514, and input 4 516. While four inputs are shown, other numbers of inputs can also be applied to the neural network. The data can include training data, production data, etc as McCarthy teaches in par.57), wherein layers of the neural network are trained (McCarthy teaches of he neural network for machine learning comprises a plurality of layers, where the layers can include one or more of an input layer, an output layer, a convolutional layer, a bottleneck layer, an activation layer, and the like and a trained neural network as McCarthy teaches in par.29 and 56); receiving, from the system, an indication that the access attempt to the digital system is unauthorized (McCarthy teaches of receiving a plurality of inputs 120 from the cybersecurity threat protection applications, the inputs can include alarms, alerts, notifications, status changes and updates, warnings, etc., the plurality of inputs can be received from one or more network-connected cybersecurity threat protection applications which is to identify potential indicators of compromise or indicators of attack as McCarthy teaches in par.25), in response to receiving the indication that the access attempt to the digital system is unauthorized (McCarthy teaches wherein the plurality of inputs is received in response to one or more cybersecurity events; initiate a cybersecurity mitigation, wherein the initiating is triggered by an analysis of the one or more cybersecurity events, wherein the analysis is performed on a network-connected computer platform as McCarthy teaches in par.78), accessing a machine-learning model trained to generate a corresponding mitigation strategy based on a plurality of features of the multi-modal data (McCarthy teaches of once the SOAR management system receives the alert, further mitigation steps taken by a human administrator or a machine learning model should begin mitigation. In this example, a successful mitigation response from the SOAR system to a malware or virus attack on a user workstation should occur in eight minutes or less after the initial detection of a problem on a workstation. As the event progresses, additional metrics can be collected and compared to metrics in the success metric library as McCarthy teaches in par.48), wherein the machine learning model comprises a decision tree ((McCarthy teaches that cybersecurity threat management and mitigation requires decision-making processes which equivalent as decision tree based on the significance of the threat the scope of the threat impact, and the resources required to deploy and confirm a satisfactory mitigation, including the timing of the mitigation steps, as well as other factors as McCarthy teaches in par.32), the decision tree is updated using a reinforcement learning process based on information on effectiveness of prior responses to other cybersecurity threats (McCarthy teaches that The library of cybersecurity mitigation success metrics can be used to validate a cybersecurity mitigation event based on achieving one or more of the cybersecurity mitigation success metrics. For example, success metrics related to a cybersecurity virus attack on a group of users can include the time it takes system administrators to acknowledge and respond to an anti-virus alert, the amount of time required to refresh or rebuild infected workstations, the number of workstations impacted, the version of anti-virus software and signature libraries running on infected workstations, the amount of time required to disconnect infected workstations from the network, and so on. These metrics can be used by the SOAR system to compare cybersecurity events to successful event metrics from previous occasions as McCarthy teaches in par.48); and generating one or more signals configured to implement at least a portion of the corresponding mitigation strategy generated by the machine-learning model (McCarthy teaches that the correct mitigation steps are selected and brought to bear on the threat immediately after the threat is identified; in which the correct mitigation steps are successfully deployed and implemented on all network points under threat; in which prevention steps are clearly identified and put in place to prevent future occurrences; and in which all steps taken from the beginning to the end of the event are clearly logged and documented for network security staff and control systems to review and integrate into future security policies as McCarthy teaches in par.34).
McCarthy fails to teach wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized; receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized and the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Sellars teaches, similar system, wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized (Sellars teaches that GNN model suspects/ determines that the graph of the current cyber incident has a very high probability of having something bad/ malicious occur, such as unauthorized encryption as Sellars teaches in par.80); receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized (Sellars teaches that identify and understand the events occurring in the ongoing cyber incidents and to check how closely the events relate to confirmed malicious cyber incidents to be classified into the type of cyber incident assigned the score indication of how bad the ongoing cyber incident is as Sellars teaches in par.71). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized as taught and suggested by Sellars for the purpose of analyzing events occurring in ongoing cyber incidents, to cooperate with a scoring classifier, and to turn the analyzed events occurring in the ongoing cyber incidents into actionable information reported by a user interface to a user (Sellars, abstract). McCarthy, as modified by Sellars, do not explicitly teach the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Crabtree teaches, similar system, the machine learning model comprises a decision tree that includes multiple paths (Crabtree teaches the advanced cyber decision platform uses machine learning algorithms to analyze system-wide data to detect threats with randomly selected decision tree commencing from that node's expanded choices may be undertaken, until the simulation or game ends decisively and continually searching and expanding new gameplay paths or simulation choices, with optional weights towards specific node selection as Crabtree teaches in par.158 and 159), each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights (Crabtree teaches This choice may be biased or weighted in certain ways, such as picking leaf nodes of game states that already have favorable win/loss ratios, so as to prioritize the exploration of high-value game states and decisions and to be biased in favor of certain choices for a playout, to attempt to explore “better” choices that may be more likely to end in a favorable result as Crabtree teaches in par.159, 161-164). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include decision tree that includes multiple paths, each path associated with a weight as taught and suggested by Crabtree for the purpose of achieving extremely high performance in the simulated environment or game being analyzed and to try and locate more optimal paths in shorter periods of time than a random or undirected search might reveal (Crabtree, par.167). McCarthy, as modified by Sellars and Crabtree, do not explicitly teach Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths.
Liu teaches, similar system, Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths (Liu teaches of the weight of all decision tree paths in the initialization model is 1, then, the model is iteratively updated by using the marked data, which is specifically as follows: randomly selecting a sample from the mark data, and detecting the sample by a model; if the detection is correct, that is, the detection result is consistent with the label, the next sample is continuously selected; if the detection is wrong, that is, the detection result is not consistent with the label, the weight on the corresponding path is adjusted according to the type of the sample, the weight of the positive type is reduced, and the weight of the negative type is increased; This process continues until the tag data set is empty as Liu teaches in par.112-116 on machine translation). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy, as modified by Sellars and Crabtree, to include in response to selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths as taught and suggested by Liu for the purpose of performing abnormal detection on the psychological sand table sample, which improves the identification accuracy and improves the effect of abnormal psychological sand table detection (Liu, abstract).
For claim 10, McCarthy, in view of Sellars, Crabtree and Liu, discloses the system of claim 9, further teaches wherein the information on effectiveness of the prior responses to other cybersecurity threats is stored in a database accessible to the machine-learning model (McCarthy teaches success criteria metric 214 stored in the library 210 can state that the time from initial detection of a suspect file on a user station to a response by a cybersecurity administrator should be eight minutes or less as McCarthy teaches in par.40).
For claim 11, McCarthy, in view of Sellars, Crabtree and Liu, discloses the system of claim 10, further teaches wherein the database is configured to store features of the other cybersecurity threats and historical data indicative of corresponding prior responses to the other cybersecurity threats and information on one or more security policies associated with the other cybersecurity threats (McCarthy teaches stores instructions; one or more processors attached to the memory wherein the one or more processors, when executing the instructions which are stored, are configured to: access a plurality of network-connected cybersecurity threat protection applications McCarthy in par 8 and 34).
For claim 12, McCarthy, in view of Sellars, Crabtree and LIu, discloses the system of claim 11, further teaches wherein generating the corresponding mitigation strategy comprises:
generating a measure of similarity of the access attempt to other cybersecurity threats based on the features of the multi-modal data and the features of the other cybersecurity threats; and generating the corresponding mitigation strategy based on the measure of similarity (McCarthy teaches that attack involving multiple workstations, the amount of time required to update all related workstations with mitigating software patches can be compared to an optimal time for the same number of workstations, or the time per workstation or network node as recorded in the success library as McCarthy teaches in par.40).
For claim 13, McCarthy, in view of Sellars, Crabtree and Liu, discloses the system of claim 10, further teaches wherein the operations performed by the one or more computers further comprise storing information on the access attempt and the corresponding mitigation strategy in the database (par.78).
For claim 14, McCarthy, in view of Sellars, Crabtree and Liu, discloses the system of claim 13, further teaches wherein: the operations performed by the one or more computers further comprise: determining an effectiveness of the corresponding mitigation strategy; and updating the database to store information on the effectiveness of the corresponding mitigation strategy; and
the updated database is used in the reinforcement learning process to update the decision tree (McCarthey teaches of Cybersecurity threat management and mitigation requires decision-making based on the significance of the threat, the scope of the threat impact, and the resources required to deploy and confirm a satisfactory mitigation, including the timing of the mitigation steps, as well as other factors and updating is based on additional input from the cybersecurity threat protection applications, analyses by the SOAR network-connected computer platform 232, and metadata analysis received from at least one of the plurality of cybersecurity threat protection applications as McCarthy teaches in par.9 and 71).
For claim 15, McCarthy teaches One or more non-transitory computer storage media encoded with computer program instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:
(par.7) comprising : receiving multi-modal data representing an access attempt to the digital system (McCarthy teaches of accessing a plurality of network-connected cybersecurity threat protection applications; receiving a plurality of inputs from the cybersecurity threat protection applications, wherein the plurality of inputs is received in response to one or more cybersecurity events as McCarthy teaches in par.7); providing the multi-modal data to a neural network (McCarthy teaches of providing Data to the neural network though inputs such as input 1 510, input 2 512, input 3 514, and input 4 516. While four inputs are shown, other numbers of inputs can also be applied to the neural network. The data can include training data, production data, etc as McCarthy teaches in par.57), wherein layers of the neural network are trained (McCarthy teaches of he neural network for machine learning comprises a plurality of layers, where the layers can include one or more of an input layer, an output layer, a convolutional layer, a bottleneck layer, an activation layer, and the like and a trained neural network as McCarthy teaches in par.29 and 56); receiving, from the system, an indication that the access attempt to the digital system is unauthorized (McCarthy teaches of receiving a plurality of inputs 120 from the cybersecurity threat protection applications, the inputs can include alarms, alerts, notifications, status changes and updates, warnings, etc., the plurality of inputs can be received from one or more network-connected cybersecurity threat protection applications which is to identify potential indicators of compromise or indicators of attack as McCarthy teaches in par.25), in response to receiving the indication that the access attempt to the digital system is unauthorized (McCarthy teaches wherein the plurality of inputs is received in response to one or more cybersecurity events; initiate a cybersecurity mitigation, wherein the initiating is triggered by an analysis of the one or more cybersecurity events, wherein the analysis is performed on a network-connected computer platform as McCarthy teaches in par.78), accessing a machine-learning model trained to generate a corresponding mitigation strategy based on a plurality of features of the multi-modal data (McCarthy teaches of once the SOAR management system receives the alert, further mitigation steps taken by a human administrator or a machine learning model should begin mitigation. In this example, a successful mitigation response from the SOAR system to a malware or virus attack on a user workstation should occur in eight minutes or less after the initial detection of a problem on a workstation. As the event progresses, additional metrics can be collected and compared to metrics in the success metric library as McCarthy teaches in par.48), wherein the machine learning model comprises a decision tree, the decision tree is updated using a reinforcement learning process based on information on effectiveness of prior responses to other cybersecurity threats (McCarthy teaches that The library of cybersecurity mitigation success metrics can be used to validate a cybersecurity mitigation event based on achieving one or more of the cybersecurity mitigation success metrics. For example, success metrics related to a cybersecurity virus attack on a group of users can include the time it takes system administrators to acknowledge and respond to an anti-virus alert, the amount of time required to refresh or rebuild infected workstations, the number of workstations impacted, the version of anti-virus software and signature libraries running on infected workstations, the amount of time required to disconnect infected workstations from the network, and so on. These metrics can be used by the SOAR system to compare cybersecurity events to successful event metrics from previous occasions as McCarthy teaches in par.48); and generating one or more signals configured to implement at least a portion of the mitigation strategy generated by the machine-learning model (McCarthy teaches that the correct mitigation steps are selected and brought to bear on the threat immediately after the threat is identified; in which the correct mitigation steps are successfully deployed and implemented on all network points under threat; in which prevention steps are clearly identified and put in place to prevent future occurrences; and in which all steps taken from the beginning to the end of the event are clearly logged and documented for network security staff and control systems to review and integrate into future security policies as McCarthy teaches in par.34).
McCarthy fails to teach wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized; receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized, the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Sellars teaches, similar system, wherein layers of the neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized (Sellars teaches that GNN model suspects/ determines that the graph of the current cyber incident has a very high probability of having something bad/ malicious occur, such as unauthorized encryption as Sellars teaches in par.80); receiving, from the neural network, an indication that the access attempt to the digital system is unauthorized (Sellars teaches that identify and understand the events occurring in the ongoing cyber incidents and to check how closely the events relate to confirmed malicious cyber incidents to be classified into the type of cyber incident assigned the score indication of how bad the ongoing cyber incident is as Sellars teaches in par.71). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include neural network are trained to generate an indication whether or not multi-modal attempts to access the digital system are unauthorized as taught and suggested by Sellars for the purpose of analyzing events occurring in ongoing cyber incidents, to cooperate with a scoring classifier, and to turn the analyzed events occurring in the ongoing cyber incidents into actionable information reported by a user interface to a user (Sellars, abstract). McCarthy, as modified by Sellars, do not explicitly teach the machine learning model comprises a decision tree that includes multiple paths, each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights.
Crabtree teaches, similar system, the machine learning model comprises a decision tree that includes multiple paths (Crabtree teaches the advanced cyber decision platform uses machine learning algorithms to analyze system-wide data to detect threats with randomly selected decision tree commencing from that node's expanded choices may be undertaken, until the simulation or game ends decisively and continually searching and expanding new gameplay paths or simulation choices, with optional weights towards specific node selection as Crabtree teaches in par.158 and 159), each path associated with a weight corresponding to a historical effectiveness of a mitigation strategy represented by the path; and generating the corresponding mitigation strategy comprises selecting a path of the decision tree based on the associated weights (Crabtree teaches This choice may be biased or weighted in certain ways, such as picking leaf nodes of game states that already have favorable win/loss ratios, so as to prioritize the exploration of high-value game states and decisions and to be biased in favor of certain choices for a playout, to attempt to explore “better” choices that may be more likely to end in a favorable result as Crabtree teaches in par.159, 161-164). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy to include decision tree that includes multiple paths, each path associated with a weight as taught and suggested by Crabtree for the purpose of achieving extremely high performance in the simulated environment or game being analyzed and to try and locate more optimal paths in shorter periods of time than a random or undirected search might reveal (Crabtree, par.167). McCarthy, as modified by Sellars and Crabtree, do not explicitly teach Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths.
Liu teaches, similar system, Wherein updating the decision tree comprises: after selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths (Liu teaches of the weight of all decision tree paths in the initialization model is 1, then, the model is iteratively updated by using the marked data, which is specifically as follows: randomly selecting a sample from the mark data, and detecting the sample by a model; if the detection is correct, that is, the detection result is consistent with the label, the next sample is continuously selected; if the detection is wrong, that is, the detection result is not consistent with the label, the weight on the corresponding path is adjusted according to the type of the sample, the weight of the positive type is reduced, and the weight of the negative type is increased; This process continues until the tag data set is empty as Liu teaches in par.112-116 on machine translation). It would have been obvious to one ordinary skill in the art before effective filling date to modify McCarthy, as modified by Sellars and Crabtree, to include in response to selection of a path with an associated weight, dynamically updating a subset of remaining weights, the subset of the remaining weights including weights associated with non-selected paths as taught and suggested by Liu for the purpose of performing abnormal detection on the psychological sand table sample, which improves the identification accuracy and improves the effect of abnormal psychological sand table detection (Liu, abstract).
For claim 16, McCarthy, in view of Sellars, Crabtree and Liu, discloses the one or more non-transitory computer storage media of claim 15, further teaches wherein the information on effectiveness of the prior responses to other cybersecurity threats is stored in a database accessible to the machine-learning model.
For claim 17, McCarthy, in view of Sellars, Crabtree and Liu, discloses the one or more non-transitory computer storage media of claim 16, further teaches wherein the database is configured to store features of the other cybersecurity threats and historical data indicative of corresponding prior responses to the other cybersecurity threats and information on one or more security policies associated with the other cybersecurity threats (McCarthy teaches stores instructions; one or more processors attached to the memory wherein the one or more processors, when executing the instructions which are stored, are configured to: access a plurality of network-connected cybersecurity threat protection applications McCarthy in par 8 and 34).
For claim 18, McCarthy, in view of Sellars, Crabtree and Liu, discloses the one or more non-transitory computer storage media of claim 17, further teaches wherein generating the corresponding mitigation strategy comprises: generating a measure of similarity of the access attempt to other cybersecurity threats based on the features of the multi-modal data and the features of the other cybersecurity threats; and generating the corresponding mitigation strategy based on the measure of similarity (McCarthy teaches that attack involving multiple workstations, the amount of time required to update all related workstations with mitigating software patches can be compared to an optimal time for the same number of workstations, or the time per workstation or network node as recorded in the success library as McCarthy teaches in par.40).
For claim 19, McCarthy, in view of Sellars, Crabtree and Liu, discloses the one or more non-transitory computer storage media of claim 16, further teaches wherein the operations performed by the one or more computers further comprise storing information on the access attempt and the corresponding mitigation strategy in the database (par.9 and 78).
For claim 20, McCarthy, in view of Sellars, Crabtree and Liu, discloses the one or more non-transitory computer storage media of claim 19, further teaches wherein: the operations performed by the one or more computers further comprise: determining an effectiveness of the mitigation strategy; and updating the database to store information on the effectiveness of the mitigation strategy; and the updated database is used in the reinforcement learning process to update the decision tree (McCarthey teaches of Cybersecurity threat management and mitigation requires decision-making based on the significance of the threat, the scope of the threat impact, and the resources required to deploy and confirm a satisfactory mitigation, including the timing of the mitigation steps, as well as other factors and updating is based on additional input from the cybersecurity threat protection applications, analyses by the SOAR network-connected computer platform 232, and metadata analysis received from at least one of the plurality of cybersecurity threat protection applications as McCarthy teaches in par.9 and 71).
Response to Amendments/Arguments
Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
The applicant’s arguments regarding the amendment limitation in claims 1, 9 and 15, has been considered but is moot, because the examiner applied new art, Liu et al (CN118645248), that covers newly claimed limitation.
Regarding dependent claims arguments, said arguments are moot because the applied references are not considered to have alleged differences, and therefore are considered to properly show that for which they were cited.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AYUB A MAYE whose telephone number is (571)270-5037. The examiner can normally be reached Monday-Friday 9AM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AYUB A MAYE/Examiner, Art Unit 2436
/SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436