DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
The instant application is a continuation of US S.N. 18/452,539 filed 20 August 2023 and US S.N. 16/019,368 filed 26 June 2018. Therefore, the effective filing date of the claims will be 26 June 2018.
Information Disclosure Statement
The Information Disclosure Statement filed on 05 May 2025 complies with all applicable rules and regulations. Therefore, the information referred to therein has been considered.
Oath/Declaration
A proper Oath/Declaration was filed on 04 March 2025.
Drawings
No issues have been found with the drawings filed 19 February 2025.
Specification
No issues have been found with the specification filed 19 February 2025.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-7, 9-13 and 16-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-9, 11-12, and 18-20 of U.S. Patent No. 11,792,216 B2.
Although the claims at issue are not identical, they are not patentably distinct from each other because they are different definitions or descriptions of the same subject matter varying in breadth.
For example, note the following relationship between the instant application claims and the patented claims:
Application claim 1 corresponds to the patent claim 1:
US S.N. 19/057,894
US Patent No. 11,792,216 B2
1. A method, comprising:
1. A method, comprising:
accessing, by an intercept container of a container system, unobfuscated content of a file that corresponds to network activity using an encryption key accessed from an application container using a single kernel, wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container;
obtaining, by the intercept container using the kernel to access the application container, an encryption key from a process monitor of the intercept container which retrieves the encryption key by a scan inspection of a memory of the application container, and wherein the encryption key is used to access an unobfuscated content of the file that corresponds to the network activity prior to the file being obfuscated and transmitted out of the application container;
applying, by the intercept container, one or more expressions representing patterns of sensitive personal data to the unobfuscated content using the single kernel to determine whether the one or more expressions match the unobfuscated content;
wherein inspecting the content of the file comprises: retrieving a template corresponding to a policy that controls transmission of sensitive personal data, the template comprising one or more regular expressions that represent patterns of the sensitive personal data;
applying, by the intercept container, the one or more regular expressions to the unobfuscated content of the file that is obtained using the kernel to find whether one or more regular expression matches exist in the content of the file;
in response to the determining that the one or more expressions match the unobfuscated content, determining, by the intercept container, that the network activity is an attempt to transmit sensitive personal data out of the application container; and
determining, in response to one or more regular expression matches are found, that the network activity attempting to transmit the file to the network destination involves an attempt to transmit the sensitive personal data out of the application container; and
in response to the attempt to transmit the sensitive personal data out of the application container, triggering, by the intercept container, an action specified in a policy of the container system.
triggering an action specified in the policy in response to determining that the network activity involves the attempt to transmit the sensitive personal data out of the application container.
Claim 2 corresponds to claim 2.
Claim 3 corresponds to claim 18.
Claim 4 corresponds to claim 1.
Claim 5 corresponds to claim 3.
Claim 6 corresponds to claim 4.
Claim 7 corresponds to claim 5.
Claim 9 corresponds to claim 6.
Claim 10 corresponds to claim 7.
Claim 11 corresponds to claim 6.
Claim 12 corresponds to claim 8.
Claim 13 corresponds to claim 9.
Claim 16 corresponds to claim 19.
Claim 17 corresponds to claim 11.
Claim 18 corresponds to claim 12.
Claim 19 corresponds to claim 11.
Claim 20 corresponds to claim 20.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-19 and 20 of U.S. Patent No. 12,244,625 B2.
Although the claims at issue are not identical, they are not patentably distinct from each other because they are different definitions or descriptions of the same subject matter varying in breadth.
For example, note the following relationship between the instant application claims and the patented claims:
Application claim 1 corresponds to the patent claim 1:
US S.N. 19/057,894
US Patent No. 12,244,625 B2
1. A method, comprising:
1. A method, comprising:
accessing, by an intercept container of a container system, unobfuscated content of a file that corresponds to network activity using an encryption key accessed from an application container using a single kernel, wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container;
accessing by the intercept container unobfuscated content of the file that corresponds to the network activity using an encryption key accessed from the application container using the single kernel, wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container;
applying, by the intercept container, one or more expressions representing patterns of sensitive personal data to the unobfuscated content using the single kernel to determine whether the one or more expressions match the unobfuscated content;
applying by the intercept container one or more regular expressions representing patterns of sensitive personal data to the unobfuscated content using the single kernel to determine whether the one or more regular expressions match the unobfuscated content;
in response to the determining that the one or more expressions match the unobfuscated content, determining, by the intercept container, that the network activity is an attempt to transmit sensitive personal data out of the application container; and
in response to the determining that the one or more regular expressions match the unobfuscated content, determining by the intercept container that the network activity is an attempt to transmit sensitive personal data out of the application container; and
in response to the attempt to transmit the sensitive personal data out of the application container, triggering, by the intercept container, an action specified in a policy of the container system.
in response to the attempt to transmit the sensitive personal data out of the application container, triggering by the intercept container an action specified in a policy of the container system.
Claims 2-20 correspond to claims 2, 8, 3-7, 9-19, and 23, respectively.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 4, 9, 11, 17, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Bernstein et al. (US 2018/0278639 A1) in view of Smelov et al. (US 2019/0342315 A1) and further in view of Moore et al. (US 10,079,810 B1).
Regarding claim 1, Bernstein teaches accessing, by an intercept container, e.g., detector container 315 (Fig. 3, el. 315), of a container system, e.g., host device 310 (Fig. 3, el. 310), unobfuscated content of a file that corresponds to network activity using an encryption key accessed from an application container, e.g., app containers 110-1 through 110-n/311-1 (Fig. 1, el. 110-1 to 110-n; Fig. 3, el. 311-1), using a single kernel, wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a…inspection of a memory of the application container, e.g., at S630, traffic redirected to the detector container is inspected, by the detector container, to detect any malicious activity, where the monitored traffic can be encrypted traffic, and the detector container interfaces with the protected APP container and server's operating system at runtime to securely retrieve keys from the protected APP container, and using the retrieved keys, the detector container can terminate the encrypted connection and decrypt the traffic for inspection (Fig. 6, el. S630; Para. 79);
the intercepted communications may include system calls, access to a filesystem, access to a virtual machine hosting the APP container, access to a communication port, inbound and outbound network traffic, and so on (Para. 42);
a software container is an instance of a user-space running an application within the operating system (OS) of a host device (e.g., a server), where software containers enable operating-system-level virtualization in which the OS kernel allows the existence of multiple isolated software containers (Para. 6);
a number of software containers (i.e., the app containers 110-1 through 110-n, hereinafter referred to individually as a container 110, merely for simplicity purposes) can access and share the same OS kernel 120 (Fig. 1, el. 120; Para. 9);
applying, by the intercept container, one or more expressions representing patterns of…data to the unobfuscated content using the single kernel to determine whether the one or more expressions match the unobfuscated content, e.g., the detector container 315 may utilize predetermined attack signatures of common attacks for different types of applications to detect malicious activity related to the protected APP container 311-1 (Para. 49);
the container relies on the kernel's functionality and uses hardware resources (CPU, memory, I/O, network, etc.) and separate namespaces to isolate the application's view of the operating system, where a software container can access the OS kernel's virtualization features either directly or indirectly (Para. 8);
in response to the determining that the one or more expressions match the unobfuscated content, determining, by the intercept container, that the network activity is an attempt to transmit…data out of the application container, e.g., at S620, one or more routing rules are generated, where the routing rules are for redirecting traffic from the protected APP container to a detector container, and the redirected traffic is originally directed to the protected APP container or is sent from the protected APP container (Fig. 6, el. S620; Para. 78);
at S630, traffic redirected to the detector container is inspected, by the detector container, to detect any malicious activity (Para. 79);
the malicious activity may be detected when one or more abnormalities in execution of the protected APP container is detected based on the inspected traffic, where the abnormalities may be detected as deviations above a threshold from a baseline, for example, a baseline of a machine learning model trained as described herein above (Para. 80);
the traffic inspection may include input validation using automatically inferred input types, API method validation, communication state monitoring, data leak prevention, malware detection, a combination thereof, and the like (Para. 53); and
in response to the attempt to transmit the…data out of the application container, triggering, by the intercept container, an action specified in a policy of the container system, e.g., at S640, when malicious activity has been detected at S630, such activity is blocked or otherwise mitigated using one or more filtering rules design to block or present certain type of threats (Fig. 6, el. S640; Para. 81).
Bernstein does not clearly teach wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container;
applying, by the intercept container, one or more expressions representing patterns of sensitive personal data to the unobfuscated content using the single kernel to determine whether the one or more expressions match the unobfuscated content;
in response to the determining that the one or more expressions match the unobfuscated content, determining, by the intercept container, that the network activity is an attempt to transmit sensitive personal data out of the application container; and
in response to the attempt to transmit the sensitive personal data out of the application container, triggering, by the intercept container, an action specified in a policy of the container system.
Smelov teaches applying…one or more expressions representing patterns of sensitive personal data to the unobfuscated content…to determine whether the one or more expressions match the unobfuscated content, e.g., the data controller engine 1145 may control the network traffic from the client running the client application 404 to the one or more servers hosting the application 1110, where the data controller engine 1145 may apply a policy to each packet from the embedded browser 410 to the application 1110 to determine whether transmission of the packet is permitted, where the policy may specify a set of predefined data types labeled as potentially sensitive information (e.g., personally identifiable information (PII), health records, and financial records), where the policy may include a format or a regular expression for each data type labeled as potentially sensitive information, where in applying the policy, the data controller engine 1145 may intercept all packets sent via the embedded browser 410 (Fig. 11, el. 404, 1110, 1145; Para. 173);
the application inspector may determine whether to restrict data (1420), where the restriction of data by the embedded browser may be in accordance with an administrative policy, where the administrative policy may specify packets containing potentially sensitive data are not to leave the client device via the embedded browser, where the potentially sensitive data may be defined using regular expressions or formats (Fig. 14, el. 1420; Para. 186);
in response to the determining that the one or more expressions match the unobfuscated content, determining…that the network activity is an attempt to transmit sensitive personal data out of the application container, e.g., the data controller engine 1145 may apply a policy to each packet from the embedded browser 410 to the application 1110 to determine whether transmission of the packet is permitted, where the policy may specify a set of predefined data types labeled as potentially sensitive information (e.g., personally identifiable information (PII), health records, and financial records), where the policy may include a format or a regular expression for each data type labeled as potentially sensitive information, where in applying the policy, the data controller engine 1145 may intercept all packets sent via the embedded browser 410, and if the packet to be transmitted contains information matching one of the predefined data types, the data controller engine 1145 may restrict the transmission of the packet to the application 1110 (Para. 173);
the application inspector may determine whether to restrict data (1420), where the restriction of data by the embedded browser may be in accordance with an administrative policy, where the administrative policy may specify packets containing potentially sensitive data are not to leave the client device via the embedded browser, where the potentially sensitive data may be defined using regular expressions or formats (Para. 186);
the client application or CEB can include or be associated with a secure container 418, where a secure container can include a logical or virtual delineation of one or more types of resources accessible within the client device and/or accessible by the client device (Para. 103); and
in response to the attempt to transmit the sensitive personal data out of the application container, triggering…an action specified in a policy of the container system, e.g., if the packet to be transmitted contains information matching one of the predefined data types, the data controller engine 1145 may restrict the transmission of the packet to the application 1110 (Para. 173);
the application inspector may determine whether to restrict data (1420), where the restriction of data by the embedded browser may be in accordance with an administrative policy, where the administrative policy may specify packets containing potentially sensitive data are not to leave the client device via the embedded browser, where the potentially sensitive data may be defined using regular expressions or formats (Para. 186).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein to include applying, by the intercept container, one or more expressions representing patterns of sensitive personal data to the unobfuscated content using the single kernel to determine whether the one or more expressions match the unobfuscated content; in response to the determining that the one or more expressions match the unobfuscated content, determining, by the intercept container, that the network activity is an attempt to transmit sensitive personal data out of the application container; and in response to the attempt to transmit the sensitive personal data out of the application container, triggering, by the intercept container, an action specified in a policy of the container system, using the known method of determining whether to restrict data using an administrative policy, wherein the policy may specify packets containing potentially sensitive data are not to leave the client device via the embedded browser, and the potentially sensitive data may be defined using regular expressions, as taught by Smelov, in combination with the app container activity interception, inspection, and restriction system of Bernstein, for the purpose of improving the security of sensitive files and aiding in the Data Loss Prevention of the files.
Bernstein in view of Smelov does not clearly teach wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container.
Moore teaches wherein the encryption key is obtained from a process monitor of the intercept…, e.g., packet capture system 105 (Fig. 1, el. 105),…retrieves the encryption key by a scan inspection of a memory of the application…, e.g., in step 202, the key capture agent collects key material associated with a session key utilized to encrypt packets sent by the first endpoint device to a second endpoint device over a network in a corresponding session, where the key material can comprise the session key itself (Fig. 2, el. 202; Col. 9, lines 62-66);
a mode that intercepts at least a portion of the key material utilizing memory scanning and pattern matching performed on the first endpoint device 102-1 (Col. 6, lines 16-18);
in step 204, the key material and an identifier of the corresponding session are transmitted to a decoder that is not part of the first and second endpoint devices so as to permit the decoder to be configured to decrypt the encrypted packets in intercepted network traffic (Fig. 2, el. 204; Col. 10, lines 4-8).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov to include wherein the encryption key is obtained from a process monitor of the intercept container, which retrieves the encryption key by a scan inspection of a memory of the application container, using the known method of utilizing memory scanning and pattern matching to collect a key from an endpoint device, as taught by Moore, in combination with the app container activity interception, inspection, and restriction system of Bernstein in view of Smelov, for the purpose of locating and retrieving a key when the specific storage address is not known.
Regarding claim 4, Bernstein in view of Smelov in view of Moore teaches the method of claim 1, wherein the single kernel enables a plurality of containers sharing the single kernel, the plurality of containers includes the application container and the intercept container, e.g., the container relies on the kernel's functionality and uses hardware resources (CPU, memory, I/O, network, etc.) and separate namespaces to isolate the application's view of the operating system, where a software container can access the OS kernel's virtualization features either directly or indirectly (Bernstein-Para. 8);
a number of software containers (i.e., the app containers 110-1 through 110-n, hereinafter referred to individually as a container 110, merely for simplicity purposes) can access and share the same OS kernel 120 (Bernstein-Fig. 1, el. 120; Para. 9);
detector container 315 (Bernstein-Fig. 3, el. 315).
Regarding claim 9, the claim is analyzed with respect to claim 1. Bernstein in view of Smelov in view of Moore further teaches a container system, e.g., host device 310 (Bernstein-Fig. 3, el. 310), comprising: a processor that, when executing instructions stored in any associated memory, e.g., the host device requires an underlying hardware layer to execute the OS, VMs, and software containers, where the hardware layer 400 includes a processing circuitry 410 and a memory 415 (Bernstein-Fig. 4, el. 400, 410, 415; Para. 62), is configured to: perform the steps.
Regarding claim 11, the claim is analyzed with respect to claim 4.
Regarding claim 17, the claim is analyzed with respect to claim 1. Bernstein in view of Smelov in view of Moore further teaches a non-transitory computer-readable storage medium configured to store instructions that, when executed by a processor of a container system, e.g., the host device requires an underlying hardware layer to execute the OS, VMs, and software containers, where the hardware layer 400 includes a processing circuitry 410 and a memory 415 (Bernstein-Fig. 4, el. 400, 410, 415; Para. 62), cause the processor to: perform the steps.
Regarding claim 19, the claim is analyzed with respect to claim 4.
Claims 2, 10, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Bernstein in view of Smelov in view of Moore and further in view of Duan (US 2017/0093923 A1).
Regarding claim 2, Bernstein in view of Smelov in view of Moore teaches the method of claim 1.
Bernstein in view of Smelov in view of Moore does not clearly teach wherein the network activity is associated with providing network data from the application container to a virtual switch of the container system.
Duan teaches wherein the network activity is associated with providing network data from the application container, e.g., App container 120A-120D (Fig. 1, el. 120A-120D), to a virtual switch, e.g., a virtual switch (Fig. 1, el. 135A, 135B), of the container system, e.g., container system 105 (Fig. 1, el. 105);
intercepting connections between the app containers and the virtual switch (Para. 46, 49, 52);
inserting the security container within the flow of the connection between the app container and the virtual switch (Para. 59).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include wherein the network activity is associated with providing network data from the application container to a virtual switch of the container system, using the known method of intercepting connections between the app containers and the virtual switch using a security container, as taught by Duan, in combination with the app container activity interception, inspection, and restriction system of Bernstein in view of Smelov in view of Moore, for the purpose of utilizing a switch that allows for virtual networks to be quickly created, configured, and deleted without modifying the physical infrastructure.
Regarding claim 10, the claim is analyzed with respect to claim 2.
Regarding claim 18, the claim is analyzed with respect to claim 2.
Claims 3, 16, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Bernstein in view of Smelov in view of Moore and further in view of Ahuja et al. (US 2014/0194094 A1).
Regarding claim 3, Bernstein in view of Smelov in view of Moore teaches the method of claim 1.
Bernstein in view of Smelov in view of Moore does not clearly teach wherein the sensitive personal data comprises credit card information, a social security number, or a combination thereof.
Ahuja teaches wherein the sensitive personal data comprises credit card information, a social security number, or a combination thereof, e.g., sensitive information may be credit card numbers, social security numbers, or PIN numbers (Para. 41).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include wherein the sensitive personal data comprises credit card information, a social security number, or a combination thereof, using the known method of including credit card numbers and social security numbers in the sensitive information, as taught by Ahuja, in combination with the app container activity interception, inspection, and restriction system of Bernstein in view of Smelov in view of Moore, for the purpose of providing a flexible policy framework and preserving configurations of applications and subsystems (Ahuja-Para. 13). Another benefit of the combination would be to enhance the security of the user by preventing sensitive credit card and social security information from being leaked.
Regarding claim 16, the claim is analyzed with respect to claim 3.
Regarding claim 20, the claim is analyzed with respect to claim 3.
Claims 5, 6, 8, 12, 13, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Bernstein in view of Smelov in view of Moore and further in view of Khanduja (US 10,146,936 B1).
Regarding claim 5, Bernstein in view of Smelov in view of Moore teaches the method of claim 1.
Bernstein in view of Smelov in view of Moore further teaches further comprising: intercepting file system activity from the application container; and capturing data…from a…storage of the container system from the file system activity that has been intercepted, e.g., at S630, traffic redirected to the detector container is inspected, by the detector container, to detect any malicious activity, where the monitored traffic can be encrypted traffic, and the detector container interfaces with the protected APP container and server's operating system at runtime to securely retrieve keys from the protected APP container, and using the retrieved keys, the detector container can terminate the encrypted connection and decrypt the traffic for inspection (Bernstein-Fig. 6, el. S630; Para. 79);
the intercepted communications may include system calls, access to a filesystem, access to a virtual machine hosting the APP container, access to a communication port, inbound and outbound network traffic, and so on (Bernstein-Para. 42).
Bernstein in view of Smelov in view of Moore does not clearly teach capturing data written to and read from a virtual storage of the container system from the file system activity that has been intercepted.
Khanduja teaches capturing data written to and read from a virtual storage of the container system, e.g., system 100 comprises a plurality of containers 102 that are assumed to be implemented by at least one container host device (Fig. 1, el. 100, 102), from the file system activity that has been intercepted, e.g., the kernel module of the storage intrusion detector 125 is illustratively configured to intercept system calls involving reading from or writing to the storage volume 106 of a given one of the containers 102 (Fig. 1, el. 106, 125; Col. 6, lines 22-25);
the storage disks 106 are examples of what are more generally referred to herein as “storage volumes”, where the storage disks may comprise respective virtual disks (Col. 2, lines 55-58).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include capturing data written to and read from a virtual storage of the container system from the file system activity that has been intercepted, using the known method of intercepting system calls involving reading from and writing to virtual disks, as taught by Khanduja, in combination with the app container activity interception, inspection, and restriction system of Bernstein in view of Smelov in view of Moore, for the purpose of facilitating the use of containers in multi-tenant environments by providing a mechanism through which each tenant can receive alerts when an unauthorized process attempts to access its provisioned storage volume, where such an arrangement can alleviate some of the difficulties associated with isolation of shared storage resources between multiple tenants, leading to improved security and performance in an information processing system comprising a multi-tenant storage environment (Khanduja-Col. 1, line 66-Col. 2, line 7).
Regarding claim 6, Bernstein in view of Smelov in view of Moore in view of Khanduja teaches the method of claim 5, wherein the intercepting file system activity further comprises: intercepting system call requests from the application container, e.g., the intercepted communications may include system calls, access to a filesystem, access to a virtual machine hosting the APP container, access to a communication port, inbound and outbound network traffic, and so on (Bernstein-Para. 42);
the kernel module of the storage intrusion detector 125 is illustratively configured to intercept system calls involving reading from or writing to the storage volume 106 of a given one of the containers 102 (Khanduja-Col. 6, lines 22-25).
Regarding claim 8, Bernstein in view of Smelov in view of Moore teaches the method of claim 1.
Bernstein in view of Smelov in view of Moore further teaches further comprising: intercepting file system calls made by the application container to a…storage associated with the application container, e.g., at S630, traffic redirected to the detector container is inspected, by the detector container, to detect any malicious activity, where the monitored traffic can be encrypted traffic, and the detector container interfaces with the protected APP container and server's operating system at runtime to securely retrieve keys from the protected APP container, and using the retrieved keys, the detector container can terminate the encrypted connection and decrypt the traffic for inspection (Bernstein-Fig. 6, el. S630; Para. 79);
the intercepted communications may include system calls, access to a filesystem, access to a virtual machine hosting the APP container, access to a communication port, inbound and outbound network traffic, and so on (Bernstein-Para. 42).
Bernstein in view of Smelov in view of Moore does not clearly teach intercepting file system calls made by the application container to a virtual storage associated with the application container.
Khanduja teaches intercepting file system calls made by the application container to a virtual storage associated with the application container, e.g., the kernel module of the storage intrusion detector 125 is illustratively configured to intercept system calls involving reading from or writing to the storage volume 106 of a given one of the containers 102 (Fig. 1, el. 102, 106, 125; Col. 6, lines 22-25);
each of the containers 102 comprises a corresponding application 104 that runs in that container, a storage disk 106, and an associated file system (FS) 108, where the storage disks 106 are examples of what are more generally referred to herein as “storage volumes”, where the storage disks in some embodiments may comprise respective virtual disks (Col. 2, lines 53-58).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include intercepting file system calls made by the application container to a virtual storage associated with the application container, using the known method of intercepting system calls involving reading from and writing to virtual disks, as taught by Khanduja, in combination with the app container activity interception, inspection, and restriction system of Bernstein in view of Smelov in view of Moore, for the purpose of facilitating the use of containers in multi-tenant environments by providing a mechanism through which each tenant can receive alerts when an unauthorized process attempts to access its provisioned storage volume, where such an arrangement can alleviate some of the difficulties associated with isolation of shared storage resources between multiple tenants, leading to improved security and performance in an information processing system comprising a multi-tenant storage environment (Khanduja-Col. 1, line 66-Col. 2, line 7).
Regarding claim 12, the claim is analyzed with respect to claim 5.
Regarding claim 13, the claim is analyzed with respect to claim 6.
Regarding claim 15, the claim is analyzed with respect to claim 8.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Bernstein in view of Smelov in view of Moore and further in view of Cravo de Almeida et al. (US 2002/0169871 A1).
Regarding claim 7, Bernstein in view of Smelov in view of Moore teaches the method of claim 1.
Bernstein does not clearly teach transmitting a report that is a graphical interface presented on a web page by a web server, the report discussing the network activity.
Smelov further teaches transmitting a report…, the report discussing the network activity, e.g., in operation (4), the security operator 1310 may be alerted as to the attempt to transfer the document file from the company application server 1305A to an authorized location (Para. 179);
in operation (2), the security operator 1310 may be alerted as to the attempted to transfer of the document file from the company application server 1305A to an authorized location (Para. 180).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein to include transmitting a report, the report discussing the network activity, using the known method of alerting a security operator as to the attempted transfer of the document file, as taught by Smelov, in combination with the app container activity interception, inspection, and restriction system of Bernstein, using the same motivation as in claim 1.
Bernstein in view of Smelov in view of Moore does not clearly teach transmitting a report that is a graphical interface presented on a web page by a web server, the report discussing the network activity.
Cravo de Almeida teaches transmitting a report that is a graphical interface presented on a web page by a web server…, e.g., generating a web page corresponding to a report and providing the web page to a web server, wherein the web server may provide the report as the web page (Para. 46).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include transmitting a report that is a graphical interface presented on a web page by a web server, the report discussing the network activity, using the known method of generating a web page corresponding to a report and providing the web page to a web server, wherein the web server may provide the report as the web page, as taught by Cravo de Almeida, in combination with the app container activity interception, inspection, and reporting system of Bernstein in view of Smelov in view of Moore, for the purpose of enabling an administrator to log onto the web server from a remote computer and view the report as a web page (Cravo de Almeida-Para. 46).
Regarding claim 14, Bernstein in view of Smelov in view of Moore teaches the container system of claim 9.
Bernstein does not clearly teach wherein the intercept container is further configured to: transmit a report regarding the network activity to a graphical interface of a user device.
Smelov further teaches wherein the intercept container is further configured to: transmit a report regarding the network activity to…, e.g., in operation (4), the security operator 1310 may be alerted as to the attempt to transfer the document file from the company application server 1305A to an authorized location (Para. 179);
in operation (2), the security operator 1310 may be alerted as to the attempted to transfer of the document file from the company application server 1305A to an authorized location (Para. 180).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein to include wherein the intercept container is further configured to: transmit a report regarding the network activity, using the known method of alerting a security operator as to the attempted transfer of the document file, as taught by Smelov, in combination with the app container activity interception, inspection, and restriction system of Bernstein, using the same motivation as in claim 1.
Bernstein in view of Smelov in view of Moore does not clearly teach wherein the intercept container is further configured to: transmit a report regarding the network activity to a graphical interface of a user device.
Cravo de Almeida teaches to: transmit a report…to a graphical interface of a user device, e.g., the report generator 116 uses the SMTP server 86 to send the report to the email address, wherein report generator 116 also generates a web page corresponding to the report and provides the web page to web server 91, wherein the administrator of the local server 12 may retrieve the email message from any computer, such as laptop computer 22, wherein the laptop computer 22 retrieves the performance report email from an email server associated with the administrator, wherein the administrator can then view the report on a display associated with laptop computer 22, wherein alternatively, the administrator can log onto web server 91 from a remote computer and view the report as a web page, (Fig. 1, el. 12, 22, 86, 91, 116; Para. 46),
wherein the report 602 has details 616 which are divided into sections corresponding to the paragraphs in the executive summary 608, wherein the details 616 include a network section 618d, wherein each of the sections contains usage information 620 that includes a graphic, such as a traffic light indicating whether the performance of the component, natural language text describing the performance of the component in words, and a graph showing a plot of the data of the component (Fig. 6, el. 602, 616, 618d, 620; Para. 58).
Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify Bernstein in view of Smelov in view of Moore to include wherein the intercept container is further configured to: transmit a report regarding the network activity to a graphical interface of a user device, using the known method of sending the report to the email address, wherein the report generator also generates a web page corresponding to the report and provides the web page to web server 91, wherein the administrator of the local server may retrieve the email message from any computer, as taught by Cravo de Almeida, in combination with the app container activity interception, inspection, and reporting system of Bernstein in view of Smelov in view of Moore, for the purpose of improving the user’s overall experience with the system by providing the user with knowledge of any issues with the network usage.
Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Evans et al. (US 10,447,720 B1)-- Evans discloses an external application that performs security inspections of data being transferred to or from a computing device (Col. 8, lines 14-20). A request may be directed to a function library that includes a custom version of the function that facilitates transferring, between the application container and the external data source, an encrypted version of the data that is unintelligible to an external application running outside the application container and providing an unencrypted version of the data to the external application to enable the external application to inspect the data (Col. 7, lines 14-34; Col. 8, lines 43-65), wherein the function library may reside within the application container (Col. 9, lines 29-34).
Barton et al. (US 2015/0143120 A1) – Barton discloses data stored in a secure container may be encrypted according to a policy and retrieving a key required to encrypt/decrypt the data stored in the secure containers (Abstract).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEREMY DUFFIELD whose telephone number is (571)270-1643. The examiner can normally be reached Monday - Friday, 7:00 AM - 3:00 PM (ET).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at (571) 272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
28 July 2026
/Jeremy S Duffield/Primary Examiner, Art Unit 2498