DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Applicant filed a response dated April 27, 2026 in which claims 1, 7-10, and 16-19 have been amended. Therefore, claims 1-20 are currently pending in the application.
Priority
Application 19/025,184 was filed on 01/16/2025 and is a CON of 16/552,434 08/27/2019 which is a CON of 14/684,507 04/13/2015 PAT 10,438,207.
Examiner Request
The Applicant is requested to indicate where in the specification there is support for amendments to claims should Applicant amend. The purpose of this is to reduce potential 35 U.S.C. § 112(a) or § 112 1st paragraph issues that can arise when claims are amended without support in the specification. The Examiner thanks the Applicant in advance.
Double Patenting
The terminal disclaimer filed on April 27, 2026 disclaiming the terminal portion of any patent granted on this application which would extend beyond the expiration date has been reviewed and is accepted. The terminal disclaimer has been recorded.
Claim Rejections - 35 USC § 101
35 U.S.C. § 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. § 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. (MPEP 2106). The claims are directed to a method, system, and apparatus which is one of the statutory categories of invention (Step 1: YES). The recitation of the claimed invention is analyzed as follows, in which the abstract elements are boldfaced.
Claim 1 recites the limitations of:
A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising: obtaining data including virtual currency transactions recorded on a distributed ledger and associated with pseudonymous ledger addresses;
de-anonymizing at least a portion of the virtual currency transactions to resolve one or more of the pseudonymous ledger addresses to originating or receiving endpoints;
analyzing the de-anonymized virtual currency transactions to determine a threat index for a subscribed entity, wherein the threat index indicates a likelihood of an APT against the subscribed entity; and
prior to occurrence of the APT, one or more of i) notifying the subscribed entity of the likelihood of the APT or ii) triggering one or more mitigation actions in the network that adjust at least one network operating parameter for the subscribed entity, based on the threat index.
Claim 19 recites the limitations of:
A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity, obtain a threat index for the subscribed entity that is indicative of likelihood of an advanced persistent threat (APT), and
perform, prior to occurrence of the APT, one or more mitigation actions that adjust at least one network operating parameter for the subscribed entity related to the subscribed entity, based on the threat index,
wherein the threat index is determined based on analyzing virtual currency transactions recorded on a distributed ledger and associated with pseudonymous ledger addresses, and
de-anonymizing at least a portion of the virtual currency transactions to resolve one or more of the pseudonymous ledger addresses to originating or receiving endpoints.
The claim as a whole recites a method that, under its broadest reasonable interpretation, covers collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions. This is a fundamental economic practice of a financial transaction; a commercial interaction, such as for business relations; and managing personal behavior or relationships or interactions between people, which are certain methods of organizing human activity.
Thus, the claims recite an abstract idea. (Step 2A, prong 1: YES).
Moreover, the judicial exception is not integrated into a practical application. Other than reciting a “A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising:”, “virtual currency”, “distributed ledger”, and “A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity”, to perform the steps of “obtaining”, “de-anonymizing”, “analyzing”, “notifying”, “triggering”, and “performing”, nothing in the claim elements preclude the steps from practically being a certain method for organizing human activity. The claim as a whole does not integrate the judicial exception into a practical application. The claim merely describes how to generally “apply” the concept of collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions in a computer environment. The additional computer elements recited in the claim limitations are recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception utilizing generic computer components.
For example, the Specification discloses “[0023] Referring to FIG. 1, in an exemplary embodiment, a network diagram illustrates a system 10 for tracking, predicting, and mitigating APTs in a network 12 or collection of networks. The network 12 (or collection of networks) includes various network elements 14, data resources 16, and the like, which can collectively be referred to as service delivery resources. That is, the network 12 provides connectivity for users at various layers, such as Layers 0 (photonic), 1(time-division multiplexing), 2(packet), 3 (Internet Protocol), and/or 4-7 (application). The network elements 14,data resources 16, etc. can include, without limitation, switches, routers, packet/optical switches, storage devices, Wave Division Multiplexing (WDM) equipment, time division multiplexing (TDM) switches, and the like. The network 12 can include any type of wired/wireless network from the access layer to metro, regional, and long haul network layers. The network 12 can include the Internet, Wide Area Networks (WANs), Local Area Networks (LANs), Virtual LANs (VLANs), etc.”
“[0062] Referring to FIG. 8, in an exemplary embodiment, a block diagram illustrates a server 600 such as for the implementing various components of the system 10, the APT prediction and mitigation process 400, and the like. The server 600 can be a digital computer that, in terms of hardware architecture, generally includes a processor 602, input/output (I/O) interfaces 604, a network interface 606, a data store 608, and memory 610. It should be appreciated by those of ordinary skill in the art that FIG. 8 depicts the server 600 in an oversimplified manner, and a practical embodiment may include additional components and suitably configured processing logic to support known or conventional operating features that are not described in detail herein.”
Thus, the specification supports that general purpose computers or computer components are utilized to implement the steps of the abstract idea.
Merely implementing the abstract idea on a generic computer is not a practical application of the abstract idea. The claim as a whole, in viewing the additional elements both individually and in combination, does not integrate the judicial exception into a practical application. Accordingly, these additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. (Step 2A prong two: No)
The claim does not include additional elements, when considered both individually and as an ordered combination, that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using “A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising:”, “virtual currency”, “distributed ledger”, and “A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity”, to perform the steps of “obtaining”, “de-anonymizing”, “analyzing”, “notifying”, “triggering”, and “performing”, amounts to no more than mere instructions to apply the exception using generic computer component. The claim merely describes how to generally “apply” the concept of collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions in a computer environment. Thus, even when viewed as a whole, nothing in the claim adds significantly more (i.e. an inventive concept) to the abstract idea. Such additional elements are determined to not contain an inventive concept according to MPEP 2106.05(f). It should be noted that (1) the “recitation of claim limitations that attempt to cover any solution to an identified problem with no restriction on how the result is accomplished and no description of the mechanism for accomplishing the result, does not provide significantly more because this type of recitation is equivalent to the words “apply it”, and (2) “Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., a fundamental economic practice, commercial interaction, or managing personal behavior or relationships or interactions between people, mental process, or mathematical calculation) does not integrate a judicial exception into a practical application or provide significantly more”.
Claims 10 is substantially similar to claim 1, thus, it is rejected on similar grounds.
Claim 10 recites the additional elements of “A non-transitory computer-readable medium storing instructions for predicting advanced persistent threats (APTs) in a network, the instructions, when executed, cause one or more processors to perform steps of:”.
For similar reasons as explained above with regard to claim 1, under Step 2A, prong two, these additional elements are merely applying generic computer components to implement the abstract idea. Under Step 2B, when viewing the additional elements individually and in combination, the additional elements do not amount to an inventive concept amounting to significantly more than the judicial exception itself as the claimed computer-related technologies are mere tools for implementing the abstract idea as explained with regard to claim 1.
Dependent claims 2-9, 11-18, and 20 merely limit the abstract idea and do not recite any further additional elements beyond the cited abstract idea and the elements addressed above, thus, they do not amount to significantly more. The dependent claims are abstract for the reasons presented above because there are no additional elements that integrate the abstract idea into a practical application or are sufficient to amount to significantly more than the judicial exception when considered both individually and as an ordered combination. Thus, the dependent claims are directed to an abstract idea. (Step 2B: No)
Therefore, claims 1-20 are not patent-eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. §§ 102 and 103 (or as subject to pre-AIA 35 U.S.C. §§ 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. § 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 5-12, and 14-20 are rejected under 35 U.S.C. 103 as being unpatentable over Stiansen, U.S. Patent Application Publication Number 2016/0044054; in view of Andrade, E.P. Patent Application Publication Number 15161502.
As per claim 1,
Stiansen explicitly teaches:
A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising: obtaining data including virtual currency transactions
(Stiansen US20160044054 at paras. 27-29, 159) ("[0027] In another aspect, described herein, among other things, is a system for reducing the security risk of transactions with a computer over a computer network comprising: a computer network; a first computer on the computer network having a first computer network address and communicating with a second computer on the computer network; a communication between said first computer and said second computer being indicative of a user of the first computer being engaged in a risk activity and including the first computer network address;" [0159] "risk activity is categorized by the technological facets of the IP Address causing suspicious, including but not limited to: open proxies; open relays; brute force attempts; use of bogons; use of botnets; bitcoin and other virtual currency transactions;")
analyzing the de-anonymized virtual currency transactions to determine a threat index for a subscribed entity, wherein the threat index indicates a likelihood of an APT against the subscribed entity; and
(Stiansen US20160044054 at paras. 22, 27-29, 127, 159) ("[0018] The technology described herein can continuously collect and analyze vast amounts of live high-risk Internet traffic to identify compromised hosts, botnets, Advanced Persistent Threats (APTs), and other sources of cyber attack and online fraud. Using Norse's proprietary big data analytics platform, over 1,500 different threat and risk factors are used to deliver a live risk score and deep contextual information providing visibility into the threat profile of any public IP address. Delivered in milliseconds via a global high-speed delivery platform, the technology provides a proprietary IP address risk grading—the IPQ score—and detailed threat context that enable highly effective solutions for online fraud prevention and protection from cyber attacks including zero-day exploits and APTs." "[0027] a monitoring system on the computer network having one or more monitoring agents autonomously obtaining the first computer network address from the communication; one or more algorithms assigning a risk score to transactions over the computer network from the first computer network address, the risk based at least in part on the communication; wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0127] These data sources are used, for example, to identify Martian packets and bogons. Any method is used to collect this third party data (12), including without limitation by subscription, by request, or through the use of automated or semi-automated processes such as collection agents (10). In an embodiment, third party data (12) is stored in a database (14).")
prior to occurrence of the APT, one or more of i) notifying the subscribed entity of the likelihood of the APT or ii) triggering one or more mitigation actions in the network that adjust at least one network operating parameter for the subscribed entity, based on the threat index.
(Stiansen US20160044054 at paras. 27-29, 74, 156-159, 163-165, 237-238) ("[0027] wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0074] When a risky activity is detected, the traffic is blocked or cleaned, and a system administrator is notified." "[0156] Similarly, FIG. 15 and FIG. 16 depict a botnet attack and an embodiment of the present invention from the perspective of a customer or user of the embodiment in the context of counteracting a distributed denial of service attack from a botnet. The customer's interaction with the invention is similar to that depicted in FIG. 14, in that before the customer allows a proposed transaction—in this case merely accepting a network connection from the IP Address at all—the IP Address is sent to a database (28), or other data source, having data concerning IP Addresses posing botnet risk. In the depicted embodiment, the customer has defined his threshold, or “pain tolerance,” for botnet attacks in advance. A large and sophisticated enterprise with advanced load balancers and large bandwidth only wish to turn aside IP Addresses that are almost certain to be botnets. By way of example and not limitation, the customer determines that IP Addresses with a botnet risk score of 75 or higher should be filtered out and connections prohibited. However, a smaller enterprise have less bandwidth and less tolerance for mischief, and determine that an IP Address presenting a botnet risk score of 40 or higher should be filtered out and the connection prohibited. While the latter case is likely to inadvertently prohibit more legitimate connections than the former, the latter case is also likely to prohibit more botnet connections than the former. If an incoming connection's IP Address has a risk in excess of the threshold, the connection is rejected entirely. The customer's ability to define these “pain tolerance” thresholds allows the present invention to be tailored to the business needs of individual customers without having to alter the embodiment itself" "[0237] The deployment of the system/appliance service was as simple as creating an API integration point into the existing customer application where risk assessment of the IP address of a connecting party would enable the application to mitigate risk. These integration points could include: the initial connection, a login page, a payment/checkout page. Where other applications require extensive integration efforts, observed behavior for learning, or payload analysis, the system can score risk based solely on the source IP address. The API integration will also accept additional information related to geofiltering and geo-matching of billing/shipping addresses with the IP geographical location, unique transaction identifiers, and other reference points such as unique merchant ID or other reference number. These additional fields were contained within the API so only one point of integration was necessary. It was up to a client/administrator to determine what data was to be sent along with the IP address and date/time stamp. [0238] The system/appliance comprised an API responding to a request. API response to a risk query was a dataset that provided both the risk value and specific factors and context supporting the risk value returned. The IPQ score, or risk value return, would be a numeric value between 0 (No Risk) and 100 (Extreme Risk). For straight-forward consumption and action, the risk value can be used to determine policy handling and action across a variety of integration points including the business application outward to perimeter devices. The supporting factors and context can be used by the customer to better understand the transactional activities being reviewed for risk, or in advanced scenarios can be used to optimize policies, e.g. IPs involved with any Explicit Content should be prevented from account creation regardless of overall risk score.")
Stiansen does not explicitly teach, however, Andrade does teach:
recorded on a distributed ledger and associated with pseudonymous ledger addresses;
(Andrade EP15161502 at pp. 33-35) ("These computing resources are suitable to store and execute software implementing steps of the method according to the present invention. The central approval server (401) processes client registration requests (Fig. 1 ), client cryptocurrency addresses (Fig. 2) client account update requests as well as cryptocurrency transactions (Fig. 3). The central approval server (401) thus cooperates with a client information database (404) (e.g. User X: legal name, date of birthday, home address, contact address, credential, cryptocurrency address, transaction criteria) as well as with a transactions database (413) (e.g. Transaction Y: transaction ID, sender and receiver's cryptocurrency addresses, amount of coins 5 transacted, time of transaction and IP addresses of sender and receiver's client wallets)." "Real personal identities of owners for individual currency addresses are stored in the client information database (Fig. 1, 115). This fulfills the "know-your-customer" regulatory requirement and allows the system to be used as a payment system for 10 commercial activities. However, such information is not accessible to the public, in order to maintain the pseudonymous property of the CBEM and its transaction network." "Because of the pseudonymous or anonymous nature of Bitcoin and alterative cryptocurrencies based on the Bitcoin technology, coin balance of individual coin owners is not traceable by only analyzing the public transaction records stored in the blockchain. Furthermore, by design, when one spends only part of the coins recorded at a specific currency address, the amount of unspent coins is recorded at a newly generated currency address. Through analysis of the blockchain, it is computation intensive for a third party to track where a received sum of coins has been finally transacted to and recorded at what addresses." "With the present invention, an amount of coins owned by a valid registered user is completely traceable and trackable by the central governing body through analyzing the transaction records in the transactions database (413). Besides the capability of linking individual currency addresses to their owners, this unique property of the present system is contributed by recording unspent coins (if there is any) at the currency address from where the coins have just been sent/spent. In other words, the amount of coins recorded at a currency address will become zero only after all of the coins, which were previously sent to that address, have been sent/spent (322). This unique property not only simplifies a third party process for tracing and tracking the ownership transfers of cryptocurrency coins through analyzing the transaction records in the blockchain, but also allows applications of the system to financial and banking activities, particularly those required third-party auditing.")
de-anonymizing at least a portion of the virtual currency transactions to resolve one or more of the pseudonymous ledger addresses to originating or receiving endpoints;
(Andrade EP15161502 at pp. 33-35) ("These computing resources are suitable to store and execute software implementing steps of the method according to the present invention. The central approval server (401) processes client registration requests (Fig. 1 ), client cryptocurrency addresses (Fig. 2) client account update requests as well as cryptocurrency transactions (Fig. 3). The central approval server (401) thus cooperates with a client information database (404) (e.g. User X: legal name, date of birthday, home address, contact address, credential, cryptocurrency address, transaction criteria) as well as with a transactions database (413) (e.g. Transaction Y: transaction ID, sender and receiver's cryptocurrency addresses, amount of coins 5 transacted, time of transaction and IP addresses of sender and receiver's client wallets)." "Real personal identities of owners for individual currency addresses are stored in the client information database (Fig. 1, 115). This fulfills the "know-your-customer" regulatory requirement and allows the system to be used as a payment system for 10 commercial activities. However, such information is not accessible to the public, in order to maintain the pseudonymous property of the CBEM and its transaction network." "Because of the pseudonymous or anonymous nature of Bitcoin and alterative cryptocurrencies based on the Bitcoin technology, coin balance of individual coin owners is not traceable by only analyzing the public transaction records stored in the blockchain. Furthermore, by design, when one spends only part of the coins recorded at a specific currency address, the amount of unspent coins is recorded at a newly generated currency address. Through analysis of the blockchain, it is computation intensive for a third party to track where a received sum of coins has been finally transacted to and recorded at what addresses." "With the present invention, an amount of coins owned by a valid registered user is completely traceable and trackable by the central governing body through analyzing the transaction records in the transactions database (413). Besides the capability of linking individual currency addresses to their owners, this unique property of the present system is contributed by recording unspent coins (if there is any) at the currency address from where the coins have just been sent/spent. In other words, the amount of coins recorded at a currency address will become zero only after all of the coins, which were previously sent to that address, have been sent/spent (322). This unique property not only simplifies a third party process for tracing and tracking the ownership transfers of cryptocurrency coins through analyzing the transaction records in the blockchain, but also allows applications of the system to financial and banking activities, particularly those required third-party auditing.")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen and Andrade, because it would be advantageous to design a personal identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money, that would obviate unauthorized access and malicious attacks. (Andrade at Abstract and pp. 4, 25).
As per claim 2,
Stiansen explicitly teaches:
further comprising updating the threat index after the one or more mitigation actions which reduce an impact of the APT on the subscribed entity.
(Stiansen US20160044054 at paras. 27-29, 74, 156, 159, 163-165) ("[0163] In some embodiments, the template/darklist is updated regularly or irregularly. In certain embodiments, the template/darklist is updated automatically by a configuration device, wherein the configuration device is on the local computer network or is remote to the computer network. [0164] In additional embodiments, the plurality of the data entries further comprise one or more of the following: one or more Internet protocol addresses, geolocation information, one or more categories, one or more communication protocols used, and one or more risk scores. [0165] In some embodiments, the template/darklist is configured or defined by a user. The list associated with risky activities/addresses is called blacklist; the list associated with non-risky activities/addresses is called white list.")
As per claim 3,
Stiansen explicitly teaches:
wherein the triggering the one or more mitigation actions includes adjusting at least one network operating parameter for the subscribed entity.
(Stiansen US20160044054 at paras. 27-29, 74, 156, 159, 163-165) ("[0027] wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0074] When a risky activity is detected, the traffic is blocked or cleaned, and a system administrator is notified." "[0163] In some embodiments, the template/darklist is updated regularly or irregularly. In certain embodiments, the template/darklist is updated automatically by a configuration device, wherein the configuration device is on the local computer network or is remote to the computer network. [0164] In additional embodiments, the plurality of the data entries further comprise one or more of the following: one or more Internet protocol addresses, geolocation information, one or more categories, one or more communication protocols used, and one or more risk scores. [0165] In some embodiments, the template/darklist is configured or defined by a user. The list associated with risky activities/addresses is called blacklist; the list associated with non-risky activities/addresses is called white list.")
As per claim 5,
Stiansen explicitly teaches:
wherein the adjusting the at least one network operating parameter includes changing a service priority.
(Stiansen US20160044054 at paras. 156, 213-216) ("[0216] The appliance and system were able to provide (a) real-time delivery of fraud and security intelligence data; (b) configurable live scores that enable true risk prioritization; (c) integration through a simple API to let network managers easily configure the security policy; (d) powerful and visualized analytics that provide rich and comprehensive reporting data; (e) geolocation filter scoring and transaction blocking by geographical attributes; (f) flexible risk categories that let network managers configure rules and polices unique to their business." "[0156] By way of example and not limitation, the customer determines that IP Addresses with a botnet risk score of 75 or higher should be filtered out and connections prohibited. However, a smaller enterprise have less bandwidth and less tolerance for mischief, and determine that an IP Address presenting a botnet risk score of 40 or higher should be filtered out and the connection prohibited.")
As per claim 6,
Stiansen explicitly teaches:
wherein the adjusting the at least one network operating parameter includes increasing service monitoring.
(Stiansen US20160044054 at paras. 27-29, 74, 156, 159, 163-165) ("[0027] wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0074] When a risky activity is detected, the traffic is blocked or cleaned, and a system administrator is notified." "[0163] In some embodiments, the template/darklist is updated regularly or irregularly. In certain embodiments, the template/darklist is updated automatically by a configuration device, wherein the configuration device is on the local computer network or is remote to the computer network. [0164] In additional embodiments, the plurality of the data entries further comprise one or more of the following: one or more Internet protocol addresses, geolocation information, one or more categories, one or more communication protocols used, and one or more risk scores. [0165] In some embodiments, the template/darklist is configured or defined by a user. The list associated with risky activities/addresses is called blacklist; the list associated with non-risky activities/addresses is called white list.")
As per claim 7,
Stiansen explicitly teaches:
with sentiment data obtained from one or more of social media, Internet Relay Chat rooms, blogs, and news feeds related to the subscribed entity to refine the threat index.
(Stiansen US20160044054 at paras. 96-99, 159, 205, 213-219) ("[0096] In an embodiment, a collection agent (10) gathers information by examining a file. A “file” is a file stored on physical media, or a stream of related data whether or not stored. For example, a YouTube video is a “file” although the viewer watches the video in a streaming format without storing a copy. In an embodiment, a collection agent (10) gathers information about a file located on or transferred over a network. The mechanism for storage or transfer is any one of the servers, systems, services, or protocols described herein, or any other server, service, system, or protocol suitable for file transfer or storage over the Internet. By way of example and not limitation, these include FTP, P2P, web sites, mobile device applications, instant messaging clients, social networking tools, and future technological developments performing, facilitating, or allowing file transfer and/or storage over a network." "[0099] In an embodiment, a collection agent (10) gathers information about an IP Address by monitoring and/or analyzer natural language communications to or from that IP Address. By way of example and not limitation, a collection agent (10) examines the content of messages on chat servers, instant messaging systems, video game chat channels, text messages, bulletin board systems, web sites, discussion groups, newsgroups, and the like. In an embodiment, a collection agent (10) monitors natural language communications for keywords associated with a risk activity and records the IP Address of connections transmitting or receiving those messages. In an embodiment, a collection agent (10) transmits a message or keyword associated with a risk activity and records the IP Addresses of connections responding to those messages or keywords. The messages and/or communications is public, semi-public, or private." "Example 3 Appliance Coupled with Attack Intelligence Platform [0205] The appliance included attack detection and virtualization-evading malware from the darknet that current security systems are missing. Moreover, it protected an organization from careless users clicking on dangerous links in phishing emails, risky websites, social media or instant messages. Furthermore, the appliance stopped organizational data theft via Tor or anonymous proxy. The appliance was able to filter and correlate torrents of event data from existing security systems to alert network managers to what's truly important." "Example 6 Preventing Malware Infection [0217] An example of preventing malware infection is visualized in FIG. 21. In this example, the subject matter disclosed herein was implemented as an electronics device, named DarkWatch in FIG. 21. The network appliance was deployed behind the firewall where it could see all outgoing traffic. Periodically, the appliance downloaded the latest IP and URL information from another platform in a data center. When a user clicked on a malicious IP or URL within emails, social media sites, web pages, or even instant message windows, the network appliance matched the IP or URL and then was able to block, reroute, or simply report on it. The matching was based on polymorphic matching. Even if the IP and URL were within encrypted traffic, the network appliance matched the destination URL and then blocked the event or reported on the event." "[0219] This example included a system/appliance that comprised a big data analytics platform. Over 1,500 different threat and risk factors were used to deliver a live risk score and deep contextual information providing visibility into the threat profile of any public IP address. Delivered in milliseconds via a global high-speed delivery platform, the system/appliance provided a proprietary IP address risk grading—the IPQ score—and detailed threat context that enable highly effective solutions for online fraud prevention and protection from cyber attacks including zero-day exploits and APTs.")
Stiansen does not explicitly teach, however, Andrade does teach:
further comprising correlating the de-anonymized virtual currency transactions
(Andrade EP15161502 at pp. 33-35) ("These computing resources are suitable to store and execute software implementing steps of the method according to the present invention. The central approval server (401) processes client registration requests (Fig. 1 ), client cryptocurrency addresses (Fig. 2) client account update requests as well as cryptocurrency transactions (Fig. 3). The central approval server (401) thus cooperates with a client information database (404) (e.g. User X: legal name, date of birthday, home address, contact address, credential, cryptocurrency address, transaction criteria) as well as with a transactions database (413) (e.g. Transaction Y: transaction ID, sender and receiver's cryptocurrency addresses, amount of coins 5 transacted, time of transaction and IP addresses of sender and receiver's client wallets)." "Real personal identities of owners for individual currency addresses are stored in the client information database (Fig. 1, 115). This fulfills the "know-your-customer" regulatory requirement and allows the system to be used as a payment system for 10 commercial activities. However, such information is not accessible to the public, in order to maintain the pseudonymous property of the CBEM and its transaction network." "Because of the pseudonymous or anonymous nature of Bitcoin and alterative cryptocurrencies based on the Bitcoin technology, coin balance of individual coin owners is not traceable by only analyzing the public transaction records stored in the blockchain. Furthermore, by design, when one spends only part of the coins recorded at a specific currency address, the amount of unspent coins is recorded at a newly generated currency address. Through analysis of the blockchain, it is computation intensive for a third party to track where a received sum of coins has been finally transacted to and recorded at what addresses." "With the present invention, an amount of coins owned by a valid registered user is completely traceable and trackable by the central governing body through analyzing the transaction records in the transactions database (413). Besides the capability of linking individual currency addresses to their owners, this unique property of the present system is contributed by recording unspent coins (if there is any) at the currency address from where the coins have just been sent/spent. In other words, the amount of coins recorded at a currency address will become zero only after all of the coins, which were previously sent to that address, have been sent/spent (322). This unique property not only simplifies a third party process for tracing and tracking the ownership transfers of cryptocurrency coins through analyzing the transaction records in the blockchain, but also allows applications of the system to financial and banking activities, particularly those required third-party auditing.")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen and Andrade, because it would be advantageous to design a personal identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money, that would obviate unauthorized access and malicious attacks. (Andrade at Abstract and pp. 4, 25).
As per claim 8,
Stiansen explicitly teaches:
wherein the threat index is computed as a weighted average of trigger events
(Stiansen US20160044054 at paras. 137-145, 159) ("[0141] In an embodiment, the rating system (18) operates in real time. In an embodiment, the rating engine weighs and compares different factors to arrive at a numerical assessment of the severity of risk presented by a given IP Address, as well as the risk categories for that risk activity. Because the present systems and methods are designed to be “learning” systems, a complete examination of the weighing and balancing of these factors is impossible, but some illustrative, but not limiting, examples are provided herein, such as in FIG. 2.")
the sentiment data, and
(Stiansen US20160044054 at paras. 96-99, 159, 205, 213-219) ("[0096] In an embodiment, a collection agent (10) gathers information by examining a file. A “file” is a file stored on physical media, or a stream of related data whether or not stored. For example, a YouTube video is a “file” although the viewer watches the video in a streaming format without storing a copy. In an embodiment, a collection agent (10) gathers information about a file located on or transferred over a network. The mechanism for storage or transfer is any one of the servers, systems, services, or protocols described herein, or any other server, service, system, or protocol suitable for file transfer or storage over the Internet. By way of example and not limitation, these include FTP, P2P, web sites, mobile device applications, instant messaging clients, social networking tools, and future technological developments performing, facilitating, or allowing file transfer and/or storage over a network." "[0099] In an embodiment, a collection agent (10) gathers information about an IP Address by monitoring and/or analyzer natural language communications to or from that IP Address. By way of example and not limitation, a collection agent (10) examines the content of messages on chat servers, instant messaging systems, video game chat channels, text messages, bulletin board systems, web sites, discussion groups, newsgroups, and the like. In an embodiment, a collection agent (10) monitors natural language communications for keywords associated with a risk activity and records the IP Address of connections transmitting or receiving those messages. In an embodiment, a collection agent (10) transmits a message or keyword associated with a risk activity and records the IP Addresses of connections responding to those messages or keywords. The messages and/or communications is public, semi-public, or private.")
wherein the threat index is updated in real time as additional trigger events are detected.
(Stiansen US20160044054 at paras. 137-145, 159) ("[0141] In an embodiment, the rating system (18) operates in real time. In an embodiment, the rating engine weighs and compares different factors to arrive at a numerical assessment of the severity of risk presented by a given IP Address, as well as the risk categories for that risk activity. Because the present systems and methods are designed to be “learning” systems, a complete examination of the weighing and balancing of these factors is impossible, but some illustrative, but not limiting, examples are provided herein, such as in FIG. 2.")
Stiansen does not explicitly teach, however, Andrade does teach:
including the de-anonymized virtual currency transactions and
(Andrade EP15161502 at pp. 33-35) ("These computing resources are suitable to store and execute software implementing steps of the method according to the present invention. The central approval server (401) processes client registration requests (Fig. 1 ), client cryptocurrency addresses (Fig. 2) client account update requests as well as cryptocurrency transactions (Fig. 3). The central approval server (401) thus cooperates with a client information database (404) (e.g. User X: legal name, date of birthday, home address, contact address, credential, cryptocurrency address, transaction criteria) as well as with a transactions database (413) (e.g. Transaction Y: transaction ID, sender and receiver's cryptocurrency addresses, amount of coins 5 transacted, time of transaction and IP addresses of sender and receiver's client wallets)." "Real personal identities of owners for individual currency addresses are stored in the client information database (Fig. 1, 115). This fulfills the "know-your-customer" regulatory requirement and allows the system to be used as a payment system for 10 commercial activities. However, such information is not accessible to the public, in order to maintain the pseudonymous property of the CBEM and its transaction network." "Because of the pseudonymous or anonymous nature of Bitcoin and alterative cryptocurrencies based on the Bitcoin technology, coin balance of individual coin owners is not traceable by only analyzing the public transaction records stored in the blockchain. Furthermore, by design, when one spends only part of the coins recorded at a specific currency address, the amount of unspent coins is recorded at a newly generated currency address. Through analysis of the blockchain, it is computation intensive for a third party to track where a received sum of coins has been finally transacted to and recorded at what addresses." "With the present invention, an amount of coins owned by a valid registered user is completely traceable and trackable by the central governing body through analyzing the transaction records in the transactions database (413). Besides the capability of linking individual currency addresses to their owners, this unique property of the present system is contributed by recording unspent coins (if there is any) at the currency address from where the coins have just been sent/spent. In other words, the amount of coins recorded at a currency address will become zero only after all of the coins, which were previously sent to that address, have been sent/spent (322). This unique property not only simplifies a third party process for tracing and tracking the ownership transfers of cryptocurrency coins through analyzing the transaction records in the blockchain, but also allows applications of the system to financial and banking activities, particularly those required third-party auditing.")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen and Andrade, because it would be advantageous to design a personal identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money, that would obviate unauthorized access and malicious attacks. (Andrade at Abstract and pp. 4, 25).
As per claim 9,
Stiansen explicitly teaches:
wherein the obtaining the data includes receiving virtual currency transaction information from a monitoring gateway configured to detect patterns indicative of short-burst, suspicious transaction activity
(Stiansen US20160044054 at paras. 12-14, 226-228, 159) ("[0013] In addition to obscuring the true source of the malicious behavior, bots also allow malefactors to carry out attacks not otherwise possible on the shoestring budget of a cybercriminal. For example, governments and large corporations usually have substantial bandwidth available to handle Internet traffic and use sophisticated load balancers to route incoming traffic to idle resources which promptly services the connection. No one individual computer on commodity hardware has the horsepower to take down this kind of corporate network. However, in some embodiments the wrongdoer utilizes a “bot herder” program to organize millions of zombies into a “botnet” and coordinate a simultaneous distributed attack on a single system. The botnet floods the victim network with traffic that appears innocent but quickly brings the system to its knees, causing legitimate users to receive a “timeout” message stating that the web site is too busy to serve them. This type of attack is known as Distributed Denial of Service (“DDoS”) attack." "[0227] Emulating many different types of network infrastructure, protocols, and services, the system/appliance created 6-7 million concurrent transactions at any given time.")
Stiansen does not explicitly teach, however, Andrade does teach:
comprising a transaction pattern between an originating ledger address and a destination ledger address temporally correlated with an attack event.
(Andrade EP15161502 at pp. 19-20) ("2.19. storing the transaction information (including but not limited to transaction ID, sender and receiver's cryptocurrency addresses, amount of money transacted, time 5 of transaction and IP addresses of sender and receiver's client wallets) in a transaction database;" "2.21. tracing personal identities of the sender and receiver by mapping their 10 currency addresses in the transaction database and the client information database when needed." "Preferably, individual transactions can be monitored with a defined rules to identify, record and report suspicious transactions that is likely to be involved in illegal activities, such as money laundering. Preferably, real personal identities of owners of individual currency addresses are stored in the client information database. For those transactions suspected of illegal activities, identities of their associated senders and receivers will be extracted from the client information database by tracing with the currency addresses of the senders and receivers. Subsequently, the suspicious activities and the associated client information will be reported to government agencies with respect to the regulations and laws in the associated countries.")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen and Andrade, because it would be advantageous to design a personal identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money, that would obviate unauthorized access and malicious attacks. (Andrade at Abstract and pp. 4, 25).
As per claim 19,
Stiansen explicitly teaches:
A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity, obtain a threat index for the subscribed entity that is indicative of likelihood of an advanced persistent threat (APT), and
(Stiansen US20160044054 at paras. 22, 27-29, 127, 159) ("[0027] a monitoring system on the computer network having one or more monitoring agents autonomously obtaining the first computer network address from the communication; one or more algorithms assigning a risk score to transactions over the computer network from the first computer network address, the risk based at least in part on the communication; wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0127] These data sources are used, for example, to identify Martian packets and bogons. Any method is used to collect this third party data (12), including without limitation by subscription, by request, or through the use of automated or semi-automated processes such as collection agents (10). In an embodiment, third party data (12) is stored in a database (14).")
perform, prior to occurrence of the APT, one or more mitigation actions that adjust at least one network operating parameter for the subscribed entity related to the subscribed entity, based on the threat index,
(Stiansen US20160044054 at paras. 27-29, 74, 156-159, 163-165, 237-238) ("[0027] wherein the monitoring system utilizes the risk score to inhibit a communication between the first computer and a third computer." "[0074] When a risky activity is detected, the traffic is blocked or cleaned, and a system administrator is notified." "[0156] Similarly, FIG. 15 and FIG. 16 depict a botnet attack and an embodiment of the present invention from the perspective of a customer or user of the embodiment in the context of counteracting a distributed denial of service attack from a botnet. The customer's interaction with the invention is similar to that depicted in FIG. 14, in that before the customer allows a proposed transaction—in this case merely accepting a network connection from the IP Address at all—the IP Address is sent to a database (28), or other data source, having data concerning IP Addresses posing botnet risk. In the depicted embodiment, the customer has defined his threshold, or “pain tolerance,” for botnet attacks in advance. A large and sophisticated enterprise with advanced load balancers and large bandwidth only wish to turn aside IP Addresses that are almost certain to be botnets. By way of example and not limitation, the customer determines that IP Addresses with a botnet risk score of 75 or higher should be filtered out and connections prohibited. However, a smaller enterprise have less bandwidth and less tolerance for mischief, and determine that an IP Address presenting a botnet risk score of 40 or higher should be filtered out and the connection prohibited. While the latter case is likely to inadvertently prohibit more legitimate connections than the former, the latter case is also likely to prohibit more botnet connections than the former. If an incoming connection's IP Address has a risk in excess of the threshold, the connection is rejected entirely. The customer's ability to define these “pain tolerance” thresholds allows the present invention to be tailored to the business needs of individual customers without having to alter the embodiment itself" "[0237] The deployment of the system/appliance service was as simple as creating an API integration point into the existing customer application where risk assessment of the IP address of a connecting party would enable the application to mitigate risk. These integration points could include: the initial connection, a login page, a payment/checkout page. Where other applications require extensive integration efforts, observed behavior for learning, or payload analysis, the system can score risk based solely on the source IP address. The API integration will also accept additional information related to geofiltering and geo-matching of billing/shipping addresses with the IP geographical location, unique transaction identifiers, and other reference points such as unique merchant ID or other reference number. These additional fields were contained within the API so only one point of integration was necessary. It was up to a client/administrator to determine what data was to be sent along with the IP address and date/time stamp. [0238] The system/appliance comprised an API responding to a request. API response to a risk query was a dataset that provided both the risk value and specific factors and context supporting the risk value returned. The IPQ score, or risk value return, would be a numeric value between 0 (No Risk) and 100 (Extreme Risk). For straight-forward consumption and action, the risk value can be used to determine policy handling and action across a variety of integration points including the business application outward to perimeter devices. The supporting factors and context can be used by the customer to better understand the transactional activities being reviewed for risk, or in advanced scenarios can be used to optimize policies, e.g. IPs involved with any Explicit Content should be prevented from account creation regardless of overall risk score.")
wherein the threat index is determined based on analyzing virtual currency transactions
(Stiansen US20160044054 at paras. 27-29, 159) ("[0027] In another aspect, described herein, among other things, is a system for reducing the security risk of transactions with a computer over a computer network comprising: a computer network; a first computer on the computer network having a first computer network address and communicating with a second computer on the computer network; a communication between said first computer and said second computer being indicative of a user of the first computer being engaged in a risk activity and including the first computer network address;" [0159] "risk activity is categorized by the technological facets of the IP Address causing suspicious, including but not limited to: open proxies; open relays; brute force attempts; use of bogons; use of botnets; bitcoin and other virtual currency transactions;")
Stiansen does not explicitly teach, however, Andrade does teach:
further comprising correlating the de-anonymized virtual currency transactions
(Andrade EP15161502 at pp. 33-35) ("These computing resources are suitable to store and execute software implementing steps of the method according to the present invention. The central approval server (401) processes client registration requests (Fig. 1 ), client cryptocurrency addresses (Fig. 2) client account update requests as well as cryptocurrency transactions (Fig. 3). The central approval server (401) thus cooperates with a client information database (404) (e.g. User X: legal name, date of birthday, home address, contact address, credential, cryptocurrency address, transaction criteria) as well as with a transactions database (413) (e.g. Transaction Y: transaction ID, sender and receiver's cryptocurrency addresses, amount of coins 5 transacted, time of transaction and IP addresses of sender and receiver's client wallets)." "Real personal identities of owners for individual currency addresses are stored in the client information database (Fig. 1, 115). This fulfills the "know-your-customer" regulatory requirement and allows the system to be used as a payment system for 10 commercial activities. However, such information is not accessible to the public, in order to maintain the pseudonymous property of the CBEM and its transaction network." "Because of the pseudonymous or anonymous nature of Bitcoin and alterative cryptocurrencies based on the Bitcoin technology, coin balance of individual coin owners is not traceable by only analyzing the public transaction records stored in the blockchain. Furthermore, by design, when one spends only part of the coins recorded at a specific currency address, the amount of unspent coins is recorded at a newly generated currency address. Through analysis of the blockchain, it is computation intensive for a third party to track where a received sum of coins has been finally transacted to and recorded at what addresses." "With the present invention, an amount of coins owned by a valid registered user is completely traceable and trackable by the central governing body through analyzing the transaction records in the transactions database (413). Besides the capability of linking individual currency addresses to their owners, this unique property of the present system is contributed by recording unspent coins (if there is any) at the currency address from where the coins have just been sent/spent. In other words, the amount of coins recorded at a currency address will become zero only after all of the coins, which were previously sent to that address, have been sent/spent (322). This unique property not only simplifies a third party process for tracing and tracking the ownership transfers of cryptocurrency coins through analyzing the transaction records in the blockchain, but also allows applications of the system to financial and banking activities, particularly those required third-party auditing.")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen and Andrade, because it would be advantageous to design a personal identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money, that would obviate unauthorized access and malicious attacks. (Andrade at Abstract and pp. 4, 25).
As per claim 20,
Stiansen explicitly teaches:
wherein the one or more mitigation actions include one or more of increasing network bandwidth, changing a service priority, or increasing service monitoring.
(Stiansen US20160044054 at paras. 27-29, 74, 156, 159, 163-165, 213-216) ("[0216] The appliance and system were able to provide (a) real-time delivery of fraud and security intelligence data; (b) configurable live scores that enable true risk prioritization; (c) integration through a simple API to let network managers easily configure the security policy; (d) powerful and visualized analytics that provide rich and comprehensive reporting data; (e) geolocation filter scoring and transaction blocking by geographical attributes; (f) flexible risk categories that let network managers configure rules and polices unique to their business." "[0156] By way of example and not limitation, the customer determines that IP Addresses with a botnet risk score of 75 or higher should be filtered out and connections prohibited. However, a smaller enterprise have less bandwidth and less tolerance for mischief, and determine that an IP Address presenting a botnet risk score of 40 or higher should be filtered out and the connection prohibited.")
Claim 10 is substantially similar to claim 1, thus, it is rejected on similar grounds.
Claims 11-18 are substantially similar to claims 2-19, thus, they are rejected on similar grounds.
Claims 4 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Stiansen, U.S. Patent Application Publication Number 2016/0044054; in view of Andrade, E.P. Patent Application Publication Number 15161502; in view of Joll, U.S. Patent Application Publication Number 2014/0157405.
As per claim 4,
Stiansen and Andrade do not explicitly teach, however, Joll does teach:
wherein the adjusting the at least one network operating parameter includes increasing network bandwidth.
(Joll US20140157405 at paras. 148-150) ("[0149] As indicated earlier, the invention relies primarily on observing network traffic and developing baselines of expected flows and inventories of host characteristics. Desirably, the invention is configured to automatically update its baselines on an ongoing basis. As a result, there is not significant tuning or customization to be performed, other than updating firewall rule set-like policies that are offered by most products. Also, administrators may wish to adjust thresholds periodically (e.g., how much additional bandwidth usage should trigger an alert) to take into account changes to the environment. Thresholds can often be set on a per-host basis or for administrator-defined groups of hosts. The invention offers whitelist and blacklist capabilities for hosts and service and is customizable for each alert (e.g., specifying which prevention option it should trigger).")
Therefore, it would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Stiansen, Andrade, and Joll, because it allows for an improved scalable cyber-security system and architecture for the identification of malware and malicious behavior in a computer network. (Joll at Abstract and paras. 2-36).
Claim 13 is substantially similar to claim 4, thus, it is rejected on similar grounds.
Response to Arguments
Applicant’s arguments filed on April 27, 2026 have been fully considered but are not persuasive for the following reasons:
With respect to Applicant’s arguments as to the § 101 rejections for now pending claims 1-20, Examiner notes the following:
Applicant argues that the claims are not directed to an abstract idea.
Examiner disagrees, however, and notes that the claim as a whole recites a method that, under its broadest reasonable interpretation, covers collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions. This is a fundamental economic practice of a financial transaction; a commercial interaction, such as for business relations; and managing personal behavior or relationships or interactions between people, which are certain methods of organizing human activity.
Thus, the claims recite an abstract idea.
Regarding the applicant's argument that the amended features would integrate the abstract idea into a practical application, the examiner respectfully disagrees.
Examiner disagrees and notes that the additional elements of the computer system - a “A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising:”, “virtual currency”, “distributed ledger”, and “A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity”, to perform the steps of “obtaining”, “de-anonymizing”, “analyzing”, “notifying”, “triggering”, and “performing”, in all steps is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer component. The claims at issue covers a system for collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions. The claims invoke the “A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising:”, “virtual currency”, “distributed ledger”, and “A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity”, to perform the steps of “obtaining”, “de-anonymizing”, “analyzing”, “notifying”, “triggering”, and “performing” merely as tools to execute the abstract idea. Use of a computer or other machinery in its ordinary capacity for economic or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., a certain method of organizing human activity or mental process or mathematical calculation) does not integrate a judicial exception into a practical application. (MPEP 2106.05 (f))
Examiner notes that, the stated problems of predicting an APT attack is not a technical problem, and the claimed solution is not a technical solution. In the claim, the solution of obtaining financial transaction data, de-anonymizing data, analyzing data, computing a threat index, and providing notification and mitigation is part of the abstract idea, as it is merely involves collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions. Furthermore, the data manipulation and analysis could be completed mentally or manually by paper or pen.
Finally, the Applicant argues that the claims are directed to significantly more than the abstract idea.
Examiner disagrees, however, and notes that, as explained above in the instant rejection under 35 U.S.C. § 101, that the additional elements do not amount to an inventive concept. The additional elements of the computer system - “A computer-implemented method for predicting advanced persistent threats (APTs) in a network, the method comprising:”, “virtual currency”, “distributed ledger”, and “A network element in a network, the network element comprising circuitry configured to provide network services to a subscribed entity”, to perform the steps of “obtaining”, “de-anonymizing”, “analyzing”, “notifying”, “triggering”, and “performing” are merely generic computer components performing their well-known basic functions of collecting, analyzing, and transmitting data to facilitate tracking, predicting, and mitigating threats in financial transactions. Per the specification, the recited computer elements are described only at a high level of generality, (see Spec. at paras. [0023], [0062]). In view of the specification, the application of the computer elements is merely being applied to the abstract idea.
The other limitations which are simply supporting the abstract idea correspond to insignificant extra-solution activity which do not transform the abstract idea into a patent eligible subject matter. Also, the functionality here is already present in the recited hardware, which is merely routine and conventional. Collecting, analyzing, and transmitting data is routine and conventional. There is no technological problem or solution identified. This is merely a business solution to transfer data between devices. (MPEP 2106.05 (f))
With respect to Applicant’s arguments as to the Double Patenting rejections for now pending claims 1-20, Examiner notes that the rejections are withdrawn.
With respect to Applicant’s arguments as to the § 102 rejections for now pending claims 1-20, Examiner notes that the rejections are withdrawn.
With respect to Applicant’s arguments as to the § 103 rejections for now pending claims 1-20, Examiner notes that the arguments are moot in light of the new grounds for rejection.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure and is available for review on Form PTO-892 Notice of References Cited.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MERRITT J HASBROUCK whose telephone number is (571)272-3109. The examiner can normally be reached M-F 9:00-5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Christine Tran can be reached on 571-272-8103. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MERRITT J HASBROUCK/Examiner, Art Unit 3695
/CHRISTINE M Tran/Supervisory Patent Examiner, Art Unit 3695