Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is a reply to the application filed on 02/13/2025, in which, claim(s) 1-19 are pending. Claim(s) 1, 10 and 11 are independent.
Priority
Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). Receipt is acknowledged of papers submitted under 35 U.S.C. 119(a)-(d), which papers have been placed of record in the file.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/13/2025, has been reviewed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the examiner is considering the information disclosure statement.
Drawings
The drawings filed on 02/13/2025 are accepted by The Examiner.
Claim Objections
Claim 11 is objected to because of the following informalities:
Claim 11 limitation “extracting, by a payload inspection engine… acquiring, by the payload inspection engine…inspecting, by the payload inspection engine” should be “extract, by a payload inspection engine… acquire, by the payload inspection engine…inspect, by the payload inspection engine” to correct the typo.
Appropriate correction is required.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-19 are non-provisionally rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over:
Claims 1-9 of Patent 12,244,565.
Although the conflicting claims are not identical, they are not patentably distinct from each other because claims 1-19 are anticipated by claims 1-9 of Patent 12,244,565.
Instant Application 19/052,382
Patent US 12,244,565 B2
Claim 1. A method for inspecting a high-speed network packet payload by a terminal, the method comprising:
extracting, by a pattern compiler, string patterns to be inspected for each of the containers based on L7 (Layer 7) policy related to the containers;
creating, by the pattern compiler, a deterministic finite automaton (DFA) based on the extracted string patterns;
converting, by the pattern compiler, a state transition table of the DFA into a match-action table and storing the match-action table in an eBPF (extended Berkeley Packet Filter) map,
extracting, by a payload inspection engine, a payload from a packet when the packet is transmitted from a specific container;
acquiring, by the payload inspection engine, a state transition table from an eBPF map related to the specific container; and
inspecting, by the payload inspection engine, whether a pattern related to the acquired state transition table appears in the payload,
wherein the match-action table is a table representing relation among states of the DFA and actions corresponding to the states.
Claim 1. A method for inspecting a high-speed network packet payload by a terminal, the method comprising:
a step of receiving L7 (Layer 7) policy related to containers from a user; a step of extracting string patterns to be inspected for each of the containers on the basis of the L7 policy through a pattern compiler;
a step of creating a deterministic finite automaton (DFA) on the basis of the extracted string patterns through the pattern complier; and
a step of converting a state transition table of the DFA into a match-action table through the pattern compiler and storing the match-action table in an eBPF (extended Berkeley Packet Filter) map for a payload inspection engine,
wherein the match-action table is a table representing relation among states of the DFA and actions corresponding to the states.
5. The method according to claim 2, further comprising:
a step of extracting a payload from a packet through the payload inspection engine when the packet is transmitted from a specific container; and
a step of acquiring a state transition table from an eBPF map related to the specific container and inspecting a pattern of the payload through the payload inspection engine.
Allowable Subject Matter
Claims 1-19 would be allowable if the Applicant overcomes double patenting rejection issued in this office action by filing a valid electronic Terminal Disclaimer.
Independent Claim(s) and their respective dependent claims would be allowable over prior arts since the prior arts taken individually or in combination fails to particular discloses, fairly suggest or render obvious the following italic limitations:
In claims 1, 10 and 11:
“converting, by the pattern compiler, a state transition table of the DFA into a match-action table and storing the match-action table in an eBPF (extended Berkeley Packet Filter) map,
inspecting, by the payload inspection engine, whether a pattern related to the acquired state transition table appears in the payload,
wherein the match-action table is a table representing relation among states of the DFA and actions corresponding to the states” in combination with other limitations recited as specified in the independent claim(s).
The closest prior art made of record are:
Ashish A. Pandya (US 2006/0136570 A1) teaches a runtime adaptable search processor which provides high speed content search capability and provides a unique combination of NFA and DFA based search engines that can process incoming data in parallel to perform the search against the specific rules programmed in the search engines.
Flavel et al. (US 2022/0217120 A1) teaches optimizing the process of minimization a graph so as to produce a minimized version of the graph for a web application firewall in less time than otherwise and consuming fewer resources.
Durand et al. (US 11,943,261 B1) teaches a method for determining whether security assurances are satisfied by security policies that are used to control access to resources used by a mainframe application. The security policies may be evaluated using a satisfiability modulo theories (SMT) solver to determine whether the security policies are equally or less permissive than the reference policy
Hay et al. (US 2017/0208037 A1) teaches a method for inspecting the content of compressed data transferred over computer networks by having DPI deployed as a service including the necessary algorithms and required adaptations.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHENG-FENG HUANG whose telephone number is (571)272-6186. The examiner can normally be reached Monday-Friday: 9 am - 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached on (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHENG-FENG HUANG/Primary Examiner, Art Unit 2497