DETAILED ACTION
Introduction
This office action is in response to applicant’s claims filed 2/25/2025. Claims 1-20 are currently pending and have been examined. There is no claim to foreign priority.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3, 4, 6, 8, 9, 11, 12, 14, 15, 17, 18 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cora et al. (US 2018/0052936) in view of Nguyen et al. (Nguyen, US 2016/0065597).
A computer-implemented method for evaluating a domain to identify a potential security threat, the method comprising:
accessing, for a domain, a set of domain attribute features (paragraph [0052]-as his domain features, domain name, etc.);
accessing, for the domain, a set of domain profile features (paragraphs [0047-0053]-his domain features including usage events, and corresponding frequency/statistics);
[generating a first set of feature vectors based on the set of domain attribute features for the domain;
generating a second set of feature vectors based on the set of domain profile features for the domain;
generating a third set of feature vectors of predicted domain profile feature data using a first machine learning model based on the first set of feature vectors and the second set of feature vectors; and
generating a domain reputation score, wherein the generating the domain reputation score comprises:
processing, by a second machine learning model, the third set of feature vectors and observed domain profile feature data;
analyzing, using the second machine learning model, the third set of feature vectors and the observed domain profile feature data to determine a probability of the domain having malicious content; and
generating, based on the probability of the domain having malicious content, the domain reputation score.”
Cora lacks explicitly teaching that which Nguyen teaches, generating a first set of feature vectors based on the set of domain attribute features for the domain (Nguyen, paragraphs [0007, 0007-0012]-as his attribute feature vectors, and profile vectors used in generating a domain reputation score);
generating a second set of feature vectors based on the set of domain profile features for the domain (ibid);
generating a third set of feature vectors of predicted domain profile feature data using a first machine learning model based on the first set of feature vectors and the second set of feature vectors (ibid-paragraph [0026]-his domain attribute/profile feature vectors provided to the predictive model and corresponding predicted model result as a third set of feature vectors, including predicted profile feature data (ibid-paragraph [0059, 0064, 0077]-his produced feature vector based on the plurality of feature vectors, based on similarity vector calculation, of profile features); and
generating a domain reputation score, wherein the generating the domain reputation score comprises (Figs. 2 item 240, Fig. 3 item 335):
processing, by a second machine learning model, the third set of feature vectors and observed domain profile feature data (ibid, Fig. 2 item 225, Fig. 3 item 300-his predictive model, as the second machine learning model, receiving the third set of vectors, input from domain of interest as the observed domain profile feature data, feature extraction and vectors entered into the predictive model, along with the input data, feature extraction and vectors entered into the predictive model, from input data 205 through the supervised training pipeline to the predictive model, with corresponding vectors);
analyzing, using the second machine learning model, the third set of feature vectors and the observed domain profile feature data to determine a probability of the domain having malicious content (ibid-paragraph [0007, 0026-0027, 0033], Figs. 2 and 3, his reputation score, predictive model including clustering, graph analysis, of all feature vectors including the third set of feature vectors, and corresponding likelihood that the domain is associated with malicious content); and
generating, based on the probability of the domain having malicious content, the domain reputation score (ibid-his reputation “score”, as a “likelihood”, thus probability, of the domain having “malicious” content).
Thus, it would have been obvious to one of ordinary skill in the communications and/or linguistics art, before the effective filing date of the
invention, as all the claimed elements were known in the prior art and one skilled in the art could have combined the elements as claimed by known methods (computer implemented techniques and algorithms combining processes and steps in natural language processing or communications), in view of the teachings of Cora and Nguyen to combine the prior art element of using domain profile features as taught by Cora with having vectorized features of a domain as taught by Nguyen as each element performs the same function as it does separately, as the combination would yield predictable results, KSR International Co. V. Teleflex Inc., 550 US. -- 82 USPQ2nd 1385 (2007), wherein the predictable result would be determining domain reputation using relevant domain related features (ibid- Nguyen, paragraphs [0011-0014], abstract).
As per claims 3, 11 and 17, Cora with Nguyen make obvious the method of claim 1, wherein the second set of feature vectors comprises a set of probabilistic values representing domain profile features (Nguyen, paragraphs [0007, 0007-0012, paragraphs [0062-0064]]-as his attribute feature vectors, and corresponding likelihood of the extracted domain profile features, used in generating a domain reputation score, as similarly combined and motivated).
As per claims 4, 12 and 18, Cora with Nguyen make obvious the method of claim 1, wherein the observed domain profile feature data comprises a set of probabilistic values, wherein the probabilistic values are generated based on:
statistics of prior observations on the domain, responses from active probing of content, and [security-related aspects of the domain] (ibid-see above, Cora, domain event statistics, usage and log discussion, his features used in content items and corresponding extraction of the features therein, as his comments, etc. as his response data).
Cora lacks explicitly teaching that which Nguyen teaches the security-related aspects of the domain (paragraph [0011]-his security information associated with the domain).
Thus, it would have been obvious to one of ordinary skill in the communications and/or linguistics art, before the effective filing date of the
invention, as all the claimed elements were known in the prior art and one skilled
in the art could have combined the elements as claimed by known methods (computer-implemented techniques and algorithms combining processes and
steps in natural language processing or communications), in view of the teachings
of Cora and Nguyen to combine the prior art element of using domain profile features as taught by Cora with having probabilistic values based on security-related aspects of a domain a feature as taught by Nguyen as each element performs the same function as it does separately, as the combination would yield predictable results, KSR International Co. V. Teleflex Inc., 550 US. -- 82 USPQ2nd 1385 (2007), wherein the predictable result would be determining domain reputation using relevant domain related features (ibid-Nguyen, paragraphs [0011-0014], abstract).
As per claims 6, 14 and 20, Cora with Nguyen make obvious the method of claim 1, wherein the domain attribute features comprise at least one of a domain registration attribute, a certificate attribute, or a network attribute (ibid, Cora, see paragraphs [0039-0040, 0052] and his Table 1, “WHOIS” data features, as domain registration, Nameservers, Domain name, etc. and his other network attributes).
As per claim 8, Cora with Nguyen make obvious the method of claim 1, wherein the second machine learning model further comprises a filtering application, wherein the filtering application performs one or more of:
blocking traffic to the domain (ibid, Cora paragraphs [0024, 0007]-see his blocking content and allowing traffic to the domains with high scores, based on domain information/reputation); allowing traffic to the domain (ibid); generating a low-risk message for the domain (ibid-paragraph [0045, 0046]-his whitelist, as a generated message for domains); or generating a warning status (ibid-paragraph [0045, 0046]-his blacklist as generated messages for domains).
As per claim 9, claim 9 sets forth limitations similar to claim 1 and is thus rejected under similar reasons and rationale, wherein the system is deemed to embody the method, such that Cora with Nguyen make obvious a computer system comprising:
a processor (Cora, paragraphs [0057, 0058]-his system, storage medium, processor and instructions); and
a memory storing instructions that, when executed by the processor, cause the computer system to perform a set of operations, the set of operations comprising (ibid):
accessing, for a domain, a set of domain attribute features (ibid-see claim 1, corresponding and similar limitation);
accessing, for the domain, a set of domain profile features (ibid);
generating a first set of feature vectors based on the set of domain attribute features for the domain (ibid);
generating a second set of feature vectors based on the set of domain profile features for the domain (ibid);
generating a third set of feature vectors of predicted domain profile feature data using a first machine learning model based on the first set of feature vectors and the second set of feature vectors (ibid); and
generating a domain reputation score, wherein the generating the domain reputation score comprises (ibid):
processing, by a second machine learning model, the third set of feature vectors and observed domain profile feature data (ibid);
analyzing, using the second machine learning model, the third set of feature vectors and the observed domain profile feature data to determine a probability of the domain having malicious content (ibid); and
generating, based on the probability of the domain having malicious content, the domain reputation score (ibid).
As per claim 15, claim 15 sets forth limitations similar to claim 1 and is thus rejected under similar reasons and rationale, wherein the computer program product comprising a non-transitory computer readable medium is deemed to embody the method, such that Cora with Nguyen make obvious a computer program product comprising a non-transitory computer readable medium having embodied thereon instructions executable by a processor for causing a computer to perform a set of operations, the set of operations comprising (paragraphs [0057, 0058]):
accessing, for a domain, a set of domain attribute features (ibid-see claim 1, corresponding and similar limitation);
accessing, for the domain, a set of domain profile features (ibid);
generating a first set of feature vectors based on the set of domain attribute features for the domain (ibid);
generating a second set of feature vectors based on the set of domain profile features for the domain (ibid);
generating a third set of feature vectors of predicted domain profile feature data using a first machine learning model based on the first set of feature vectors and the second set of feature vectors (ibid); and
generating a domain reputation score, wherein the generating the domain reputation score comprises (ibid):
processing, by a second machine learning model, the third set of feature vectors and observed domain profile feature data (ibid);
analyzing, using the second machine learning model, the third set of feature vectors and the observed domain profile feature data to determine a probability of the domain having malicious content (ibid); and
generating, based on the probability of the domain having malicious content, the domain reputation score (ibid).
Claim(s) 2, 5, 7, 10, 13, 16 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cora et al. (US 2018/0052936) in view of Nguyen et al. (Nguyen, US 2016/0065597), as applied to claim 1, and further in view of Xu et al. (Xu, US 2019/0166141).
As per claims 2, 10 and 16, Cora with Nguyen make obvious the method of claim 1, but lack teaching that which Xu teaches, wherein generating the first set of feature vectors comprises encoding at least one variable-length domain attribute feature using a sequence autoencoder (paragraph [0019, 0151]-his input sequences of any length encoded into a set of feature vectors, using his sequence autoencoder).
Thus, it would have been obvious to one of ordinary skill in the communications and/or linguistics art, before the effective filing date of the
invention, as all the claimed elements were known in the prior art and one skilled in the art could have combined the elements as claimed by known methods (computer implemented techniques and algorithms combining processes and steps in natural language processing or communications), in view of the teachings of Cora and Nguyen to combine the prior art element of using domain profile features as taught by Cora with having vectorized features of a domain as taught by Nguyen and generating feature vectors using a variable length sequence autoencoder as taught by Xu as each element performs the same function as it does separately, as the combination would yield predictable results, KSR International Co. V. Teleflex Inc., 550 US. -- 82 USPQ2nd 1385 (2007), wherein the predictable result would be using relevant encoding input sequences of varying length, as input data is not typically one particular length, into a fixed-length vector, using a sequence autoencoder, in order to determine similarities with other input data to assess malicious content or attacks and anomalies, and blocking a domain if deemed necessary (ibid- Nguyen, paragraphs [0011-0014], abstract, ibid Xu paragraph [0057, 0006, 0007]).
As per claims 5, 13 and 19, Cora with Nguyen make obvious the method of claim 1, but lack that which Xu teaches, wherein the first machine learning model is a recurrent neural network (paragraph [0077, 0152]-his deep learning architecture as the learning model, and RNN for each input data).
Thus, it would have been obvious to one of ordinary skill in the communications and/or linguistics art, before the effective filing date of the
invention, as all the claimed elements were known in the prior art and one skilled in the art could have combined the elements as claimed by known methods (computer implemented techniques and algorithms combining processes and steps in natural language processing or communications), in view of the teachings of Cora and Nguyen to combine the prior art element of using domain profile features as taught by Cora with having vectorized features of a domain as taught by Nguyen and generating feature vectors using an RNN deep learning model which processes sequential information as taught by Xu as each element performs the same function as it does separately, as the combination would yield predictable results, KSR International Co. V. Teleflex Inc., 550 US. -- 82 USPQ2nd 1385 (2007), wherein the predictable result would be using relevant encoding input sequences using a sequential neural model, RNN, in order to determine similarities with other input data to assess malicious content or attacks and anomalies, and blocking a domain if deemed necessary (ibid- Nguyen, paragraphs [0011-0014], abstract, ibid Xu paragraph [0057, 0006, 0007, 0152]).
As per claim 7, Cora with Nguyen make obvious the method of claim 1, but lack that which Xu teaches, wherein at least one domain attribute feature of the one or more domain attribute features is variable length, wherein the first machine learning model comprises a sequence auto-encoder architecture, wherein the sequence auto-encoder architecture comprises a nested autoencoder architecture (ibid-see claim 2, corresponding and similar limitation, Xu, (paragraph [0019, 0150-0151]-his input sequences of any length encoded into a set of feature vectors, using his stacked, as the nested, sequence autoencoder).
Thus, it would have been obvious to one of ordinary skill in the communications and/or linguistics art, before the effective filing date of the
invention, as all the claimed elements were known in the prior art and one skilled in the art could have combined the elements as claimed by known methods (computer implemented techniques and algorithms combining processes and steps in natural language processing or communications), in view of the teachings of Cora and Nguyen to combine the prior art element of using domain profile features as taught by Cora with having vectorized features of a domain as taught by Nguyen and generating feature vectors using a stacked, variable length sequence autoencoder as taught by Xu as each element performs the same function as it does separately, as the combination would yield predictable results, KSR International Co. V. Teleflex Inc., 550 US. -- 82 USPQ2nd 1385 (2007), wherein the predictable result would be using relevant encoding input sequences of varying length, as input data is not typically one particular length, into a fixed-length vector, using a sequence autoencoder, in order to determine similarities with other input data to assess malicious content or attacks and anomalies, and blocking a domain if deemed necessary (ibid- Nguyen, paragraphs [0011-0014], abstract, ibid Xu paragraph [0057, 0006, 0007]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (See PTO-892).
Mirza et al., Computer Network Intrusion Detection Using Sequential LSTM Neural Networks Autoencoders, (2018) teaches anomaly detection, using a sequential autoencoder, in order to determine and predict beforehand whether a domain contains malicious content.
Lison et al., Neural reputation models learned from passive DNS data (2017).
Jakobsson (US 2018/0091453) teaches blocking access/traffic, providing a “warning” and “risk” assessment message to a user, based on reputation evaluation.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LAMONT M SPOONER whose telephone number is (571)272-7613. The examiner can normally be reached 8:00 AM -5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Daniel Washburn can be reached at (571)272-5551. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LAMONT M SPOONER/Primary Examiner, Art Unit 2657
8/7/2026