DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The claim set of claims 1-20, filed on 3/4/2025, is acknowledged and considered.
Claims 1-20 are pending. Claims 1, 8, and 15 are independent claims.
Priority
3. The present application has relationship to:
PRO 62015436, filing date 6/22/2014
CON 14745637, filing date 6/22/2015
DIV 16868669, filing date 5/7/2020
CON 17692901, filing date 3/11/2022
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
4. Claims 1, 8, and 15 recites the limitation "the related online elements". There is insufficient antecedent basis for this limitation in the claim.
Claim 1 (line 20-22), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation.
Claim 8 (line 24-25), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation.
Claim 15 (line 22-23), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(d):
(d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers.
The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph:
Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers.
5. Claims 11, 14 and 18 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claims 11 and 14 recites “the system of claim 8, further comprising: determining”, where the claim is directed to a method step. Thus, is directed towards two different statutory classes. The claim may be amended to recite ‘the system of claim 8, wherein the method further comprising’. Claim 18 recites “the computer program product of claim 15, further comprising: determining” where the claim is a method step, which is directed towards two different statutory classes. This claim may be amend to recite ‘the set of operations further comprising’. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements.
Claim Objections
6. Claims 1, 8, and 15 are objected to because of the following informalities:
Claim 1 (line), recite “portion of of”, where there is a repetitive term “of”.
Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
7. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over CP, et al [US 20150121449] in view of Kailash, et al. [US 20150163199].
As per claim 1: CP, et al. teaches a method for predicting and mitigating network threats, comprising:
receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node]
identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity]
querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers]
receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host]
when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems]
querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data referenced by the reputation and relationship tracking server; [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score]
determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score]
generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations]
generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector]
sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host]
CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”.
Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses.
Claim 2: CP: para 0034 (i.e. IP address); discussing the method of claim 1, the network activity item comprises at least one of an IP address, a file, a software application, or a URL.
Claim 3: CP: para 0020 (File reputation scores can be obtained by querying threat intelligence servers, locally or globally (e.g., in the cloud)); discussing the method of claim 1, wherein the querying to identify the related network activity having the known relationship comprises at least one of traversing a graph database, querying a relational database, or applying natural language processing techniques to textual data.
Claim 4: CP: para 0020, 0045; discussing the method of claim 1, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees.
Claim 5: CP: para 0031; discussing the method of claim 1, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors.
Claim 6: CP: para 0030, 0096 (interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the method of claim 1, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call.
Claim 7: CP: para 0020; discussing the method of claim 1, further comprising: determining if the initial reputation is known, and if the initial reputation is unknown, determining the initial reputation.
As per claim 8: CP, et al. teaches a system comprising:
at least one processor; and [CP: para Fig.9]
memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, performs a method comprising: [CP: para Fig. 9, 0030]
receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node]
identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity]
querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers]
receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host]
when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems]
querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score]
determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score]
generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations]
generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector]
sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host]
CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”.
Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses.
Claim 9: CP: para 0034 (i.e. IP address); discussing the system of claim 8, the network activity item comprises at least one of an IP address, a file, a software application, or a URL.
Claim 10: CP: para 0020 (File reputation scores can be obtained by querying threat intelligence servers, locally or globally (e.g., in the cloud)); discussing the system of claim 8, wherein the querying to identify the related online elements having the known relationship comprises at least one of traversing a graph database, querying a relational database, or applying natural language processing techniques to textual data.
Claim 11: CP: para 0020, 0045; discussing the system of claim 8, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees.
Claim 12: CP: para 0031; discussing the system of claim 8, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors.
Claim 13: CP: para 0030, 0096 (computing devices include interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the system of claim 8, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call.
Claim 14: CP: para 0020; discussing the system of claim 8, further comprising: determining if the initial reputation is known, and if the initial reputation is unknown, determining the initial reputation.
As per claim 15: CP, et al. teaches a computer program product comprising a non-transitory computer readable medium storing instructions executable by a processor to perform a set of operations for network threat prediction and blocking, the set of operations comprising:
receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node]
identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity]
querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers]
receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host]
when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems]
querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system]
determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score]
determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score]
generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations]
generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector]
sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host]
CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”.
Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses.
Claim 16: CP: para 0034 (i.e. IP address); discussing the computer program product of claim 15, the network activity item comprises at least one of an IP address, a file, a software application, or a URL.
Claim 17: CP: para 0023 (query a threat intelligence server to obtain a file reputation score); discussing the computer program product of claim 15, wherein the known relationship is based on the related network activity being hosted on the same server infrastructure.
Claim 18: CP: para 0020, 0045; discussing the computer program product of claim 15, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees.
Claim 19: CP: para 0031; discussing the computer program product of claim 15, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors.
Claim 20: CP: para 0030, 0096 (computing devices include interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the computer program product of claim 15, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Leynna Truvan whose telephone number is (571)272-3851. The examiner can normally be reached Monday-Friday 9:00AM-5:00PM, EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Leynna Truvan
Examiner
Art Unit 2435
/L.TT/Examiner, Art Unit 2435
/EDWARD ZEE/Primary Examiner, Art Unit 2435