DETAILED ACTION
Claims 1-10 are pending in this action.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 6/5/2025, 10/1/2025 and 5/14/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-6 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over Devost (US PGPUB No. 2013/0254885) in view of Touboul et al. (US PGPUB No. 2016/0359905) [hereinafter “Touboul”].
As per claim 1, Devost teaches a intrusion detection and protection system comprising: a database, the database storing: a plurality of profiles of legitimate users ([0012], storing a reference data map defines normal patterns of user and system behaviors); a plurality of profiles relating to known attackers ([0062], determining patterns of potentially malicious activity and storing patterns as signatures see [0065]); attacker classification data ([0065], deviation report used to classify attackers); and attack prevention data comprising honeypot configuration parameters ([0059], placing a host under attack into a honeypot network to reduce damage for system or increase costs for attackers); and a data manager configured to communicate with the database and a plurality of users via a network, the data manager providing services comprising: receiving, processing and logging network traffic data received at the data manager from the plurality of users of the intrusion detection and protection system ([0060], system manages host and attack data using a digital hidrosis monitor and digital hidrosis engine), and updating the database with network traffic data to form a single data resource sourced from the users' traffic data ([0062], updating reference data maps of normal behavior using patterns of network behavior by users).
Devost does not explicitly teach determining protection parameters in the form of a honeypot configuration appropriate for a particular attackers; and providing legitimate users with access to shared information on the database, enabling the users to identify attackers and implement the honeypot configuration. Touboul teaches determining protection parameters in the form of a honeypot configuration appropriate for a particular attackers (Abstract, decoy policy is customized for a attackers targeting specific groups of resources using specific attack vectors); and providing legitimate users with access to shared information on the database, enabling the users to identify attackers and implement the honeypot configuration ([0050], policy database stored decoy policies with specific decoy attack vectors for attackers targeting specific resources – decoy policies can be used by “legitimate users” like administrators to defend against attacks and bait attackers see [0026]).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Devost with the teachings of Touboul, determining protection parameters in the form of a honeypot configuration appropriate for a particular attackers; and providing legitimate users with access to shared information on the database, enabling the users to identify attackers and implement the honeypot configuration, to distribute threat profile information to save time and resources and to implement a consistent threat defense.
As per claim 2, the combination of Devost and Toubul teaches the intrusion detection and protection system of claim 1, wherein the data manager is a single computing device or a computing network that includes multiple computing devices or processors to allow for distributed computing, grid computing or cloud computing (Devost; Fig. 1 and [0019], hidrosis monitor at a single or multiple hosts works with a hidrosis engine at a single or multiple servers to analyze network data for threats/attacks).
As per claim 3, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 1, wherein the database is part of the data manager (Touboul; [0042], database of attack vectors and policy database works with management server to monitor and analyze network data for attacks).
As per claim 4, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 1, wherein the data manager determines whether a request from an authorized user relates to a request for traffic profile data (Devost; [0064], reference data maps regarding network behavior can be shared with other organizations, i.e. authorized users – including attack signatures see [0065]), or whether the purpose of the request is to provide traffic data for processing and logging (Devost; [0060], administrators can set up hidrosis monitors to obtain traffic data for processing and logging to later form data maps – the administrators are interpreted to be an authorized user requesting traffic data from the host systems).
As per claim 5, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 1, wherein raw traffic data is received by the data manager, wherein the raw traffic data is processed in order to classify the traffic as relating to normal user traffic or attacker traffic (Devost; [0064]-[0065], data can be mapped into reference data maps that reflect normal behavior or into attack signatures).
As per claim 6, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 5, wherein determining the classification comprises supervised learning pattern recognition (Devost; [0029], classifying anomaly and normal behavior using machine learning and pattern recognition).
As per claim 8, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 1, further comprising a system protection system arranged to determine whether an incoming request originates from a legitimate user or an attacker (Devost; [0064] and [0065], determining whether network behavior is normal behavior or a potential attacker this includes unauthorized access requests).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Devost and Touboul in further view of Gallo (US Patent No. 6,016,384).
As per claim 7, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 6.
The combination of Devost and Touboul does not explicitly teach the intrusion detection and protection system of claim 6, wherein the supervised learning pattern recognition comprises using multi-layer perceptrons. Gallo teaches the intrusion detection and protection system of claim 6, wherein the supervised learning pattern recognition comprises using multi-layer perceptrons (Abstract, using multi-layered perceptrons to determine and learn patterns in a neural network).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Devost and Touboul with the teachings of Gallo, the intrusion detection and protection system of claim 6, wherein the supervised learning pattern recognition comprises using multi-layer perceptrons, to distribute threat profile information to save time and resources and to implement a consistent threat defense.
Claims 9 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Devost and Touboul in further view of Stading (US PGPUB No. 2004/0255155).
As per claim 9, the combination of Devost and Touboul teaches the intrusion detection and protection system of claim 8.
The combination of Devost and Touboul does not explicitly teach wherein if a request is determined to be from an attacker, generating a virtual honeypot and/or honeynet and a false database. Stading teaches wherein if a request is determined to be from an attacker, generating a virtual honeypot and/or honeynet and a false database ([0039], in response to a detected attacker, generating on honeypot and connecting attacker to that honeypot).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Devost and Touboul with the teachings of Stading, wherein if a request is determined to be from an attacker, generating a virtual honeypot and/or honeynet and a false database, to distribute threat profile information to save time and resources and to implement a consistent threat defense.
As per claim 10, the combination of Devost, Touboul and Stading teaches the intrusion detection and protection system of claim 9, wherein the false database contains data which is not commercially or confidentially sensitive data and/or comprises randomised data (Stading; [0039], honeypots do not contain any sensitive system data for attackers to obtain see [0057], not real system).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Oliver et al. (US PGPUB No. 2007/0133537), Adams et al. (US PGPUB No. 2011/0214182), Hannis et al. (US PGPUB No. 2015/0047032), Leckie et al. ("Metadata for anomaly-based security protocol attack deduction," in IEEE Transactions on Knowledge and Data Engineering, vol. 16, no. 9, pp. 1157-1168, Sept. 2004, doi: 10.1109/TKDE.2004.43), Nkosi et al. ("Insider threat detection model for the cloud," 2013 Information Security for South Africa, Johannesburg, South Africa, 2013, pp. 1-8, doi: 10.1109/ISSA.2013.6641040), Ponaganti et al. ("Adaptive AI Algorithms for Cyber Defense: Predictive Behavioral Analysis to Mitigate Zero-Day Attacks," 2025 5th (ICERECT), MANDYA, India, 2025, pp. 1-6, doi: 10.1109/ICERECT65215.2025.11377505) and Gong et al. ("Detection of Multi-Stage Attacks Through Attack Pattern Segmentation," in IEEE Access, vol. 13, pp. 204155-204167, 2025, doi: 10.1109/ACCESS.2025.3635053) all disclose various aspects of the claimed invention including threat and attacker profiles stored by a manager or in a central repository.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PETER C SHAW whose telephone number is (571)270-7179. The examiner can normally be reached Max Flex.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/PETER C SHAW/Primary Examiner, Art Unit 2493 July 14, 2026