DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continuation
This application is a continuation application of US 17/396,895 (filed on Aug. 9, 2021 – now US Patent No. 12,309,206). The prosecution history and references cited in the above application have been fully considered.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1 and 3 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 2 of US Patent No. 12,309,206 in view of US 2020/0404010 to Costante. Although the claims at issue are not identical, they are not patentably distinct from each other because claims 1 and 3 of the instant application are directed to a system corresponding to the method of the conflicting patent. Furthermore, the current claims further recite features for enforcing the proposed (learned) access control policy, which were not recited in the conflicting claims. However, it would have been obvious to a person having ordinary skill in the art to explicitly apply the proposed access control policies through a gateway, engine, or the like, such as described in Costante. This feature would have been obvious as it is merely putting proposed access control policies into action in a production environment.
For example, refer to the following comparison table between independent claims:
Instant Application (19/066132)
Conflicting Patent (12,309,206)
1. A system comprising a non-transitory computer-readable medium having stored thereon machine-readable instructions executable by a processor for automatically creating access control policies for a network, comprising:
1. A method for automatically creating access control policies for a network, comprising: (the conflicting claim is a method performed by components of the system in claim 1)
(a) an Access Controller embodied on the non-transitory computer-readable medium comprising instructions stored thereon that, when executed on the processor, perform a learning process on user or host entities on the network and propose the access control policies based on said learning process;
(e) performing a learning process, on user or host entities for which no existing access control policies exist; and (f) proposing a respective access control policy for each of said user or host entities based on information gleaned during the learning process.
and (b) an Access Isolator embodied on the non-transitory computer-readable medium comprising instructions stored thereon that, when executed on the processor, enforce the access control policies by allowing or denying network traffic as instructed by said Access Controller, when said Access Isolator is in an enforcement mode;
(from Costante: the IDS applies learned policies for intrusion detection [Costante, ¶0358]; a phase to react if a mismatch with models and constraints is found and an alert is generated [Costante, ¶0364]; blacklist and whitelist policies defining actions to permit or deny traffic [Costante,¶0026-0027; 0366])
wherein said Access Controller includes an Event Listener Engine configured to capture attachment event details when said user or host entities attach to the network;
(a) automatically identifying and recording user or host entities that attach to the network, each of the user or host entities being assigned respective network addresses;
wherein said Access Controller includes a Correlation Engine configured to determine respective network addresses assigned to said user or host entities from said attachment event details, erase any preexisting access control policies for the respective network addresses, and then associate all network traffic flows for the respective network addresses to correlated user or host names;
(d) correlating the respective network addresses with corresponding existing access control policies of said user or host entities based on said allowed network communications; and (c) removing any existing access control policies previously assigned to the network addresses;
and wherein said Access Isolator has a Network Traffic Monitoring mode, wherein in said Network Traffic Monitoring mode said Access Isolator is further configured to perform monitoring on said network traffic and send monitoring data to said Access Controller for said learning process.
(from Costante: an intrusion detection (IDS) system is configured to perform the method in Costante that includes automatically capturing changes in monitored network behavior and automatically creating new policies from the changes, which further include applications for a host monitoring system and a host characterization and classification [Costante, ¶0340-0344])
3. The system of claim 1, wherein said learning process includes at least one of:
2. The method of claim 1, wherein said learning process includes at least one of:
(i) network traffic analysis of network traffic to and from said user or host entities;
(i) performing network traffic analysis on network traffic to and from said user or host entities;
(ii) behavior analysis of said user or host entities;
(ii) performing behavior analysis on said user or host entities;
and (iii) machine learning of activities of said user or host entities.
and (iii) performing machine learning on activities of said user or host entities.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5 are rejected under 35 U.S.C. 103 as being unpatentable over US 2020/0404010 to Costante (hereinafter, “Costante”) in view of US 10,263,868 to Baldi et al. (hereinafter, “Baldi”) and in further view of US 2020/0228404 to Hooda et al. (hereinafter, “Hooda”).
As per claim 1: Costante discloses: A system comprising a non-transitory computer-readable medium having stored thereon machine-readable instructions executable by a processor for automatically creating access control policies for a network (an intrusion detection (IDS) system is configured to perform the method in Costante that includes automatically capturing changes in monitored network behavior and automatically creating new policies from the changes, which further include applications for a host monitoring system and a host characterization and classification [Costante, ¶0340-0344]), comprising: (a) an Access Controller embodied on the non-transitory computer-readable medium comprising instructions stored thereon, that when executed on the processor, perform a learning process on user or host entities on the network and propose the access control policies based on said learning process (the IDS system monitors the network and use the collected data to create initial models, policies, and constraints [Costante, ¶0358-0359]; captured network activity is given as input to a learning module [Costante, ¶0366]); and (b) an Access Isolator embodied on the non-transitory computer-readable medium comprising instructions stored thereon, that when executed on the processor, enforces the access control policies by allowing or denying network traffic as instructed by said Access Controller, when said Access Isolator is in an enforcement mode (the IDS applies learned policies for intrusion detection [Costante, ¶0358]; a phase to react if a mismatch with models and constraints is found and an alert is generated [Costante, ¶0364]; blacklist and whitelist policies defining actions to permit or deny traffic [Costante,¶0026-0027; 0366]); wherein said Access Controller includes an Event Listener Engine configured to capture attachment event details when said user or host entities attach to the network (for every new network activity (i.e., a new host/user connecting to the network), host and link attributes are extracted for analysis and stored in databases [Costante, ¶0366]; for example, the system identifies a new host on the network and its activities are observed [Costante, ¶0327]); (in a learning phase by the IDS [Costante, ¶0358], data traffic is monitored and host/link attributes are derived from the monitored data traffic for generating rules that are translated into an attributed based policy [Costante, ¶0463-0471]; for example, a learning module receives this input [Costante, ¶0366]).
Costante does not explicitly disclose, but Baldi discloses: wherein said Access Controller includes a Correlation Engine configured to determine respective network addresses assigned to said user or host entities from said attachment event details…and then associate all network traffic flows for respective network addresses to correlated user or host names (a mapping table containing a correspondence between each IP address associated to a user device and the unique user identifier (host/link attributes from Costante) [Baldi, col. 12, lines 12-20]; block delineation group flows into blocks belonging to the same user [Baldi, col. 11, lines 46-65]).
Thus, it would have been obvious to person having ordinary skill in the art before the effective filing date of the claimed invention to implement a mapping table of device IP addresses to a unique user identifier in Costante to enable identification of users. In an environment where a user may use multiple devices on a network, it would have been advantageous to maintain mappings between IP addresses of devices and the user’s unique identifier. Therefore, policies would have been tied to the users themselves, rather than just for each device, which would have reduced the number of redundant policies in a network where users own multiple devices or use multiple devices.
Costante and Mentze do not explicitly disclose, but Hooda discloses: erase any preexisting access control policies for the respective network addresses (when a host leaves the enterprise fabric, the previously assigned IP address is released back and associated policies are deleted to enable the old IP address to be reused for the next joining host [Hooda, ¶0049]).
Thus, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to remove policies of assigned IP addresses of a network. One would have been motived to remove policies assigned to IP addresses, such that devices are allowed to join/leave a network while maintaining a device-specific enforcement for access control.
As per claim 2: Costante in view of Baldi and Hooda disclose all limitations of claim 1. Furthermore, Costante discloses: wherein said monitoring includes at least one of: deep packet inspection and extracting metadata from network packets (extraction of hosts and links attributes from the captured network traffic [Costante, ¶0368]).
As per claim 3: Costante in view of Baldi and Hooda disclose all limitations of claim 1. Furthermore, Costante discloses: wherein said learning process includes at least one of: (i) network traffic analysis of network traffic to and from said user or host entities (the attributes used in machine learning algorithms for generating policies include host and link attributes, which include host identification and direction communications between a source and a destination host [Costante, ¶0397-0400]); (ii) behavior analysis of said user or host entities (analyzing behavior frequency as means for detecting legitimate activities [Costante, ¶0266]); and (iii) machine learning of activities of said user or host entities (generating rules by machine learning algorithms on attributes of network traffic [Costante, ¶0225, 0234]).
As per claim 4: Costante in view of Baldi and Hooda disclose all limitations of claim 1. Furthermore, Costante discloses: wherein said Access Controller includes an Enrichment Engine configured to add contextual information to information collected during said learning process (deriving implicit attributes from extracted explicit attributes in the captured network traffic to be used in part of learning [Costante, ¶0368-0369, 0389]; enforcing policies based on explicit and implicit hosts/links attributes.).
As per claim 5: Costante in view of Baldi and Hooda disclose all limitations of claim 1. Furthermore, Costante discloses: wherein said Access Controller includes an Analytics Engine configured to perform analytical calculations on information collected during said learning process (generating rules by machine learning algorithms on attributes of network traffic [Costante, ¶0241-0244; 0369]).
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Costante in view of Baldi and Hooda and in further view of US 2021/0243604 to Lepp et al. (hereinafter, “Lepp”).
As per claim 6: Costante in view of Baldi and Hooda disclose all limitations of claim 1. Costante, Baldi, and Hooda do not disclose the features of claim 6. However, Lepp discloses: wherein said Access Controller includes a User Host Name System Engine adapted to dynamically add and remove said user or host names and said network addresses to and from a database whenever an attachment or detachment event occurs on the network (an identifier (username, group name) of a computing device is provided to an enterprise server to create a virtual network, wherein an address resolution protocol (ARP) table stores an IP address and MAC address of the computing device [Lepp, ¶0020, 0072-0074]; when the computing device leaves the virtual network, the computing device is removed from the ARP table [Lepp, ¶0080]).
Thus, it would have been obvious to a person having ordinary skill in the art before the filing date of the claimed invention to segment the hosts in Costante into virtual networks to be enable management and tracking of current devices on a particular network. Furthermore, devices would have been segmented according to different trust levels.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 2015/0220837: A network analysis tool can learn common attributes in a network to allows a user to create new rule objects. See ¶0022.
US 2021/0306354: When a new device couples to a network, a cluster for that device is determines and used to determine anomalies and policies. See ¶0095 & 0109.
US 2012/0167168: Policies are generated during a learning mode. Newly detected communication events are analyzed against the policies. See ¶0040, 0080.
Samak, T. and Al-Shaer, E., 2010, October. Synthetic security policy generation via network traffic clustering. In Proceedings of the 3rd ACM Workshop on Artificial Intelligence and Security (pp. 45-53). (Discloses generating a security policy using online clustering mechanisms on network traffic. See Abstract, Section 3 on pg. 47.)
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ROBERT B LEUNG whose telephone number is (571)270-1453. The examiner can normally be reached Mon - Thurs: 10am-7pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JUNG KIM can be reached on 571-272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ROBERT B LEUNG/Primary Examiner, Art Unit 2494