Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
This action is in response to applicant’s original submittal made on 02/20/2025. Claims 1-20 are pending.
Examiner’s Note:
The examiner notes that applicant’s claim 1 recites that the DPD manager comprises software. The examiner therefore contends that applicant’s claim 1 recites sufficient structure within the claim to carry out the recited DPD manager functions.
Specification (Title)
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Claim Objections
Claims 1-9 are objected to because of the following informalities: The examiner notes that the applicant recites, “cyber security appliance”. The examiner recommends that the applicant consider amending each claim to recite “cyber security device”. Appropriate correction is required.
Claim Interpretation
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: remote desktop activity (RDA) machine learning module is configured… in claims 7-9. The applicant states in par. 0049 that data from the RDA machine learning module can be used to train AI classifiers. As such the examiner considers the structure of the RDA machine learning module to be software.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-6, 10-15 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over ANAND (WO2023056523) in view of Hodgman et al. (US Patent No. 11,507,860 and Hodgman hereinafter).
As to claims 1, 10 and 19, ANAND teaches cyber security appliance to detect a cyber threat, comprising:
a Deep Packet Detection (DPD) manager configured to adaptively parse network traffic with a DPD machine learning (ML) engine (i.e., …teaches in par. 0086 the following: “An FDCP schema 100 formally describes attributes 110, 120, 130, and 140 that can be extracted from a series of packets within a network flow.” …teaches in par. 0098 the following: “an inspection of the signature of a series of packets is used to determine that the HTTP communication protocol is in use.”. …teaches in par. 0104 the following: “deep packet inspection is facilitated by employing a programmable switch (e.g., OpenFlow-based or P4-based) that sits parallel to the operational network,”. …teaches in par. 107 the following: “Machine Learning 390 assistance for making the decisions of what networked devices should be inspected, what packets should be inspected, and even what controller or programmable switch should be chosen as part of the method.”),
and ii) a protocol utilized by the network traffic, under analysis (i.e., …teaches in par. 0013 the following: “the series of packets from the selected networked device may be sent to a protocol analyzer that performs selective inspection of one or more packets.”),
and where instructions implemented in software for the DPD manager and the DPD ML engine are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units (i.e., …teaches in par. 0166 the following: “as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as virtually any combination thereof, and that designing the circuitry and/or writing the code for the software and or firmware would be well within the skill of one of skill in the art in light of this disclosure. In addition, those skilled in the art will appreciate that the mechanisms of the subject matter described herein are capable of being distributed as a program product in a variety of forms, and that an illustrative embodiment of the subject matter described herein applies regardless of the particular type of signal bearing medium used to actually carry out the distribution. Examples of a signal bearing medium include, but are not limited to, the following: a recordable type medium such as a USB drive, a solid state memory device, a hard disk drive, a Compact Disc (CD), a Digital Video Disk (DVD), a digital tape, a computer memory, etc.; and a transmission type medium such as a digital and/or an analog communication medium (e.g., a fiber optic cable, a waveguide, a wired communications link, and a wireless communication link).”).
The system of ANAND does not expressly teach:
based upon determining i) a port configuration setting in a network server in a network,
where the DPD manager is further configured to be capable of detecting 1) a non-standard configuration set up for the network traffic to be processed by a port on the network server, 2) a non-standard protocol utilized by the network traffic, and 3) any combination of both,
and then complete a deep packet inspection upon the network traffic that has 1) the non-standard configuration set up for the network traffic to be processed by the port on the network server, and/or 2) the non- standard protocol utilized by the network traffic.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation element of, “based upon determining i) a port configuration setting in a network server in a network”, Hodgman teaches as part of his claim 7 claim limitation(s) the following: “system is configured to: determine that a port on the server that produced the banner data has a port number that is different from a standard port number associated with the service protocol; and generate an alert indicating that the service protocol is detected on a non-standard port number.”.
With regards to applicant’s claim limitation element of, “where the DPD manager is further configured to be capable of detecting 1) a non-standard configuration set up for the network traffic to be processed by a port on the network server”, Hodgman teaches as part of his claim 7 claim limitation(s) the following: “system is configured to: determine that a port on the server that produced the banner data has a port number that is different from a standard port number associated with the service protocol; and generate an alert indicating that the service protocol is detected on a non-standard port number.”.
With regards to applicant’s claim limitation element of, “2) a non-standard protocol utilized by the network traffic, and 3) any combination of both”, Hodgman teaches in col. 15, lines 30-40 the following: “at operation 850, an alert may be generated if the inferred protocol is detected on a port number that is not standard for that protocol. … a similar alert or notification may be generated if a protocol change is detected on a server port.”.
With regards to applicant’s claim limitation element of: “and then complete a deep packet inspection upon the network traffic that has 1) the non-standard configuration set up for the network traffic to be processed by the port on the network server, and/or 2) the non- standard protocol utilized by the network traffic”, the examiner notes that applicant’s usage of the term “or” places the above limitation(s) in alternative form. As such with regards to applicant’s alternative claim limitation form of, “the non- standard protocol utilized by the network traffic”, Hodgman teaches in col. 8 lines 20-40 the following: “the network scanning service 232 may also implement one or more protocol-specific actions 236. These actions may be directed to a particular port after a particular protocol is discovered on that port…. As another example, the protocol-specific actions 236 may involve running a set of protocol-specific penetration tests on the port. As yet another example, the protocol-specific actions may include a further parsing or analyzing (e.g. using another ML model) of the banner data to extract additional information such as the type of platform of the machine 130 or the service software used by the machine 130. The additional information may also be logged as part of the metadata for that port.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
As to claims 2 and 11, system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND teaches a cyber security appliance of claim 1, where the network traffic under analysis is IT network traffic and the network is an IT network (i.e., …teaches in par. 0095 the following: “monitor network traffic and implement network traffic policies on a programmable switch 130.”),
where the DPD manager is further configured to not have to make assumptions about i) the port configuration setting in the network server in the IT network or ii) the protocol utilized by the IT network traffic, under analysis (i.e., …the examiner notes that applicant’s usage of the term “or” places the above claim limitations in alternative form. As such with regards to applicant’s alternative form of, “… the protocol utilized by the IT network traffic, under analysis”, teaches in par. 0013 the following: “the series of packets from the selected networked device may be sent to a protocol analyzer that performs selective inspection of one or more packets),
but rather have the DPD ML engine learn after being deployed with unsupervised machine learning but over time about which particular ports are servicing the network traffic in this IT network and what protocols are being utilized by the IT network traffic in this IT network (i.e., …teaches in par. 0111 the following: “The Machine Learning 430 may be one or more algorithms to assist in selecting the most appropriate packet for the analysis”),
and wherein the DPD manager is configured to then make a mapping of the particular ports that are servicing the network traffic in this IT network and what protocols are being utilized by the IT network traffic in this IT network (i.e., …teaches in par. 0089 the following: “forms of a list of “port” like TCP/80, TCP/8008, TCP/8O8O, TCP/8888 for HTTP and/or a range from “lower-port” to “upper-port” like UDP/137-139, UDP/445 for SMB.”).
As to claims 3 and 12, system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND teaches a cyber security appliance of claim 1, where the DPD manager is further configured to create a matrix in a memory of the cyber security appliance of all of the ports servicing network traffic in the network and then to analyze for and store in the memory metadata associated with network traffic being processed by each port (i.e., …teaches in par. 0089 the following: “the “metadata” attribute 120 captures information related to the network flow a communication protocol uses for communication. Four fields are dedicated to describe headers of data-link layer (“ether-types”), network layer (“ip-protocols” e.g., TCP, UDP), transport layer (“serverports” and “client-ports”). It can be seen at the top center of Fig. 1 that ports can be in forms of a list of “port” like TCP/80, TCP/8008, TCP/8O8O, TCP/8888 for HTTP and/or a range from “lower-port” to “upper-port” like UDP/137-139, UDP/445 for SMB”).
ANAND does not expressly teach:
which is then fed to the DPD ML engine to deduce and predict what type of network traffic is being process by each port for the network.
In this instance the examiner notes the teachings of prior art reference Hodgman.
Hodgman teaches in col. 11 lines 55-67 and col. 12 lines 1-15 the following: “the ML model 160 in this example produces a model output 510 that includes a set of all possible protocols 520, along with respective confidence indicators 530. In some embodiments, the confidence values may be generated from intermediate results that are produced by the random forest model. The confidence values may be expressed as probability values that sum to one. The confidence values may be analyzed by the model 160 or an external interpretive component to produce the ultimate inferred protocol. For example, the protocol class with the highest confidence value may be selected as the inferred protocol 540. In some embodiments, the model or protocol inference system may be configured so that the inferred protocol 540 must exceed a threshold confidence level (e.g. 90%). If no protocol class has a confidence value greater than the threshold, the model or protocol inference system will produce an indeterminate result as the output, as shown in this example.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
As to claims 4 and 13 , system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND teaches a cyber security appliance of where the network traffic under analysis is IT network traffic and the network is an IT network (i.e., …teaches in par. 0095 the following: “monitor network traffic and implement network traffic policies on a programmable switch 130.”),
and where the DPD manager is further configured to I) cooperate and receive input from network sensors configured to perform deep packet inspection upon the IT network traffic (i.e., …teaches as part of his claim 2 claim elements the following: “wherein the one or more networked devices is one of a security camera, a thermostat, an occupancy sensor, an HVAC system, a lighting system, an access controller, a fire alarm, a physical security system, a camera, a networked appliance, an industrial device, or a robotic device.”).
The system of ANAND does not expressly teach:
in order to detect and determine 1) a standard configuration set up for IT network traffic to be processed by the port on the network server and a standard IT protocol utilized by the IT network traffic
as well as II) cooperate and feed in metadata to the DPD ML engine to determine 1) the non-standard configuration set up for IT network traffic to be processed by the port on the network server, 2) the non-standard IT protocol utilized by the IT network traffic, and 3) any combination of both.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation element of, “in order to detect and determine 1) a standard configuration set up for IT network traffic to be processed by the port on the network server and a standard IT protocol utilized by the IT network traffic ”, teaches in col. 12 lines 50-65 the following: “the next field 626 of the table indicates whether the inferred protocol is located on a standard port. As discussed, many protocols are associated with a standard port number (e.g. the FTP protocol is generally associated with TCP port 21 by standard). When a detected protocol is seen on a non-standard port number, this observation may be explicitly noted in the scan results. For example, the table 620 shows that the HTTPS protocol was detected on port 122, which is different from the standard port number for that protocol (443). In some embodiments, detection of protocols on non-standard ports may cause an alert or notification to be generated (e.g. via email or text) to one or more users responsible for monitoring the client network.”.
With regards to applicant’s claim limitation element of, “as well as II) cooperate and feed in metadata to the DPD ML engine to determine 1) the non-standard configuration set up for IT network traffic to be processed by the port on the network server, 2) the non-standard IT protocol utilized by the IT network traffic, and 3) any combination of both”, teaches in col. 13 lines 1-10 the following: “the next field 628 in the table indicates whether the protocols of individual ports have changed since the last scan of the machine. In some embodiments, the port information for the machine, including their supported protocols, are stored as part of the metadata of the machine (e.g. as part of the machine representation 242 of FIG. 2). Changes in the port configuration or protocol may indicate events that are of interest to the machine assessment service. In some embodiments, such changes may cause an alert or notification to be generated to those monitoring the client network. In some embodiments, a newly detected protocol may cause additional machine data to be collected from the machine, or additional penetration tests to be performed on the machine.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
As to claims 5 and 14, the system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND teaches a cyber security appliance of claim 1, where the DPD manager is configured to use a protocol analyzer to check the non-standard protocol utilized by the network traffic against a library of known protocols for the network traffic (i.e., …teaches in par. 0135 the following: “the series of packets from the selected networked device may be sent to a protocol analyzer that performs selective inspection of one or more packets.”).
The system of ANAND does not expressly teach:
and when no match occurs then to feed metadata and at least partially recognized characteristics of a given known protocol over to the DPD ML engine to deduce and predict what type of protocol is being used by the network traffic.
In this instance the examiner notes the teachings of prior art reference Hodgman.
Hodgman teaches in col. 11 lines 55-67 and col. 12 lines 1-15 the following: “the ML model 160 in this example produces a model output 510 that includes a set of all possible protocols 520, along with respective confidence indicators 530. In some embodiments, the confidence values may be generated from intermediate results that are produced by the random forest model. The confidence values may be expressed as probability values that sum to one. The confidence values may be analyzed by the model 160 or an external interpretive component to produce the ultimate inferred protocol. For example, the protocol class with the highest confidence value may be selected as the inferred protocol 540. In some embodiments, the model or protocol inference system may be configured so that the inferred protocol 540 must exceed a threshold confidence level (e.g. 90%). If no protocol class has a confidence value greater than the threshold, the model or protocol inference system will produce an indeterminate result as the output, as shown in this example.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
As to claims 6 and 15, the system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND teaches a cyber security appliance of the cyber security appliance of where the network traffic under analysis is IT network traffic and the network is an IT network (i.e., …teaches in par. 0095 the following: “monitor network traffic and implement network traffic policies on a programmable switch 130.”).
The system of ANAND does not expressly teach:
and where the DPD manager is configured to use a port state component to store a relationship of the non-standard protocol utilized by the IT network traffic, under analysis, to a deduced protocol being used by the IT network traffic by the DPD ML engine and an associated port being used by the IT network traffic using the non- standard IT protocol,
and when a subsequent packet in network traffic is seen on the port, then the DPD manager can subsequently rely upon the port state component to provide the deduced protocol being used by the IT network traffic and the associated port being used by the IT network traffic.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation element of, “and where the DPD manager is configured to use a port state component to store a relationship of the non-standard protocol utilized by the IT network traffic, under analysis, to a deduced protocol being used by the IT network traffic by the DPD ML engine and an associated port being used by the IT network traffic using the non- standard IT protocol”, Hodgman teaches in col. 11 lines 55-67 and col. 12 lines 1-15 the following: “the ML model 160 in this example produces a model output 510 that includes a set of all possible protocols 520, along with respective confidence indicators 530. In some embodiments, the confidence values may be generated from intermediate results that are produced by the random forest model. The confidence values may be expressed as probability values that sum to one. The confidence values may be analyzed by the model 160 or an external interpretive component to produce the ultimate inferred protocol. For example, the protocol class with the highest confidence value may be selected as the inferred protocol 540. In some embodiments, the model or protocol inference system may be configured so that the inferred protocol 540 must exceed a threshold confidence level (e.g. 90%). If no protocol class has a confidence value greater than the threshold, the model or protocol inference system will produce an indeterminate result as the output, as shown in this example.”.
With regards to applicant’s claim limitation element of, “and when a subsequent packet in network traffic is seen on the port, then the DPD manager can subsequently rely upon the port state component to provide the deduced protocol being used by the IT network traffic and the associated port being used by the IT network traffic”, teaches in col. 15 lines 39-55 the following: “based on the inferred protocol, metadata will be stored to associate network traffic to or from a port that is associated with the inferred protocol. For example, in some embodiments, the protocol inference may be performed as part of a passive network traffic monitor (e.g. using a networking device or appliance in the same local network as the server). Once a port on the server is detected to be running a particular protocol, the network traffic monitor may be automatically configured to tag traffic data to or from that port with the detected protocol, before storing the traffic data or forwarding it to a remote network traffic analysis platform. In some embodiments, the metadata may also cause the network traffic monitor to monitor for other types of protocol-specific information about the port traffic, such as client IP addresses that accessed an HTTP port, or files that were uploaded or downloaded via an FTP port, etc.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
Claim(s) 7-9, 16-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over ANAND in view of Hodgman as applied to claims 1, 10 and 19 above and further in view of Lewis (US Patent Publication No. 2022/0046047).
As to claims 7 and 16, the system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND does not expressly teach a cyber security appliance of claim 1, where a remote desktop activity (RDA) machine learning module is configured to work with and supplement the DPD manager to assist in identifying.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation of, “where a remote desktop activity (RDA) machine learning module is configured to work with and supplement the DPD manager to assist in identifying”, Hodgman teaches in col. 5 lines 1-10 the following: “Depending on the embodiment, the protocol inference system 150 may be implemented locally in the same network (e.g. a private network) as the server 130, or remotely in a different network (e.g. in the cloud).”. Teaches in col. 6 lines 35-60 the following: “the ML model 160 may be implemented using a variety of different types of models that can be used for machine learning, including tree-based models (e.g. random forest models), neural network (e.g. recurrent or convolutional neural networks), or other types of models. In some embodiments, the ML model 160 may include an ensemble of multiple models, possibly of different model types. The ML model 160 may be trained via a supervised training process. ”. Teaches in col. 13 lines 25-35 the following: “protocol-specific tests 630 that are run. In some embodiments, the test results may be used to determine the risk score of the machine shown in section 610. In some embodiments, the test results may also indicate remediation actions to reduce detected security vulnerabilities, for example, to apply patches to server software with known vulnerabilities.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
The system of ANAND and Hodgman does not expressly teach:
when the cyber threat is sending the traffic to an external host that is part of an interactive remote desktop session by a shape of i) active connections, ii) data transfer, iii) over time and iv) whether an RDP session would be unusual.
In this instance the examiner notes the teachings of prior art reference Lewis.
Lewis teaches in par. 0033 the following: “monitoring virtual desktops accessed by devices at remote locations using machine-learning models to monitor and mitigate potential cyber-attacks. In some examples, activity data from a virtual desktop accessed by the remote computing device and/or one or more various data in text format (e.g., white papers, input from a user, and the like) may be used to identify one or more factors for an anomalous (or non-anomalous) virtual desktop session accessed by the remote computing device. Upon detecting a potential cyber-threat based on the one or more factors, one or more security response actions may be initiated.”. Teaches in par. 0054 the following: “new activity data may be compared to activity data of previous sessions that were verified as authentic by a user (e.g., an enterprise employee) to identify a potentially suspicious activity or a potential cyber-attack.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND and Hodgman with the teachings of Lewis by having their system comprise a enhance vulnerability detection process. One would have been motivated to do so to provide a simple and effective means to secure virtual network sessions, wherein the enhanced vulnerability detection process helps facilitate robust cyber security threat detection and makes it easier to secure the network.
As to claims 8, 17 and 20, the system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND does not expressly teach a cyber security appliance of claim 1, where an RDA machine learning module is configured to work with and supplement the DPD manager.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation element of, “where an RDA machine learning module is configured to work with and supplement the DPD manager”, Hodgman teaches in col. 5 lines 1-10 the following: “Depending on the embodiment, the protocol inference system 150 may be implemented locally in the same network (e.g. a private network) as the server 130, or remotely in a different network (e.g. in the cloud).”. Teaches in col. 6 lines 35-60 the following: “the ML model 160 may be implemented using a variety of different types of models that can be used for machine learning, including tree-based models (e.g. random forest models), neural network (e.g. recurrent or convolutional neural networks), or other types of models. In some embodiments, the ML model 160 may include an ensemble of multiple models, possibly of different model types. The ML model 160 may be trained via a supervised training process. D”. Teaches in col. 13 lines 25-35 the following: “protocol-specific tests 630 that are run. In some embodiments, the test results may be used to determine the risk score of the machine shown in section 610. In some embodiments, the test results may also indicate remediation actions to reduce detected security vulnerabilities, for example, to apply patches to server software with known vulnerabilities.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
The system of ANAND and Hodgman does not expressly teach:
to assist in identifying when the cyber threat is uploading IT network traffic to a destination hostname that is part of an interactive remote desktop session by a combination of a data shape analysis of the uploaded IT network traffic and a Large Language Model's analysis of the destination hostname where the data is being externally sent.
In this instance the examiner notes the teachings of prior art reference Lewis.
Lewis teaches in par. 0033 the following: “monitoring virtual desktops accessed by devices at remote locations using machine-learning models to monitor and mitigate potential cyber-attacks. In some examples, activity data from a virtual desktop accessed by the remote computing device and/or one or more various data in text format (e.g., white papers, input from a user, and the like) may be used to identify one or more factors for an anomalous (or non-anomalous) virtual desktop session accessed by the remote computing device. Upon detecting a potential cyber-threat based on the one or more factors, one or more security response actions may be initiated.”. Teaches in par. 0054 the following: “new activity data may be compared to activity data of previous sessions that were verified as authentic by a user (e.g., an enterprise employee) to identify a potentially suspicious activity or a potential cyber-attack.”. Teaches in par. 0054 the following: “new activity data may be compared to activity data of previous sessions that were verified as authentic by a user (e.g., an enterprise employee) to identify a potentially suspicious activity or a potential cyber-attack. If there is no indication of a potential cyber-attack in the new activity data, the machine learning model may be updated with the new activity data using machine learning engine 112c and machine learning database 112d, as described in further detail below. If a potential cyber-threat is identified, one or more relevant parameters obtained from the new activity data may be identified for providing with one or more security response actions.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND and Hodgman with the teachings of Lewis by having their system comprise a enhance vulnerability detection process. One would have been motivated to do so to provide a simple and effective means to secure virtual network sessions, wherein the enhanced vulnerability detection process helps facilitate robust cyber security threat detection and makes it easier to secure the network.
As to claims 9 and 18, the system of ANAND and Hodgman as applied to claim 1 above teaches cyber security, specifically ANAND does not expressly teaches a cyber security appliance of claim 1, where an RDA machine learning module is configured to work with and supplement the DPD manager.
In this instance the examiner notes the teachings of prior art reference Hodgman.
With regards to applicant’s claim limitation element of, “where an RDA machine learning module is configured to work with and supplement the DPD manager”, Hodgman teaches in col. 5 lines 1-10 the following: “Depending on the embodiment, the protocol inference system 150 may be implemented locally in the same network (e.g. a private network) as the server 130, or remotely in a different network (e.g. in the cloud).”. Teaches in col. 6 lines 35-60 the following: “the ML model 160 may be implemented using a variety of different types of models that can be used for machine learning, including tree-based models (e.g. random forest models), neural network (e.g. recurrent or convolutional neural networks), or other types of models. In some embodiments, the ML model 160 may include an ensemble of multiple models, possibly of different model types. The ML model 160 may be trained via a supervised training process. D”. Teaches in col. 13 lines 25-35 the following: “protocol-specific tests 630 that are run. In some embodiments, the test results may be used to determine the risk score of the machine shown in section 610. In some embodiments, the test results may also indicate remediation actions to reduce detected security vulnerabilities, for example, to apply patches to server software with known vulnerabilities.”. Teaches as part of his claim 13 claim element(s) the following: “determining one or more subsequences of characters in text sequence that matches a name associated with a particular service protocol”. Teaches in col. 15 lines 5-25 the following: “At operation 840, output of the ML model is provided. The output may be provided in a variety of ways, for example, via a GUI (or some other interactive interface) of the protocol inference system (e.g., as part of a scan report of the ports on a server). In some embodiments, the output may be provided via a programmatic interface such an API or a web service interface. In some embodiments, the determined protocol may be logged or stored in a database, for example, as part of the machine representation 242 of FIG. 2. In some embodiments, the output may indicate inferred protocol and also a confidence value for the inferred protocol, which may be determined during the execution of the model. In some embodiments, the output may include a list of possible protocols and their respective confidence values. In some embodiments, the protocol(s) indicated in the output may be required to be above a specified confidence threshold, which may be a configurable value.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND with the teachings of Hodgman by having their system comprise a enhance configuration analysis process. One would have been motivated to do so to provide a simple and effective means to control network access, wherein the enhance configuration analysis process helps facilitate better security within the network and makes it easier to determine network configuration settings.
The system of ANAND and Hodgman does not expressly teach:
to assist in identifying when the cyber threat is using an interactive remote desktop session and a match is not found in a library of services that legitimately provide a type of remote desktop control functionality.
In this instance the examiner notes the teachings of prior art reference Lewis.
Lewis teaches in par. 0033 the following: “monitoring virtual desktops accessed by devices at remote locations using machine-learning models to monitor and mitigate potential cyber-attacks. In some examples, activity data from a virtual desktop accessed by the remote computing device and/or one or more various data in text format (e.g., white papers, input from a user, and the like) may be used to identify one or more factors for an anomalous (or non-anomalous) virtual desktop session accessed by the remote computing device. Upon detecting a potential cyber-threat based on the one or more factors, one or more security response actions may be initiated.”. Teaches in par. 0054 the following: “new activity data may be compared to activity data of previous sessions that were verified as authentic by a user (e.g., an enterprise employee) to identify a potentially suspicious activity or a potential cyber-attack.”.
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of ANAND and Hodgman with the teachings of Lewis by having their system comprise a enhance vulnerability detection process. One would have been motivated to do so to provide a simple and effective means to secure virtual network sessions, wherein the enhanced vulnerability detection process helps facilitate robust cyber security threat detection and makes it easier to secure the network.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRYAN F WRIGHT whose telephone number is (571)270-3826.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRYAN F WRIGHT/ Examiner, Art Unit 2497