Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is responsive to: an original application filed on 2 March 2025.
2. Claims 1-20 are currently pending and claims 1, 9 and 18 are independent claims.
Information Disclosure Statement
3. The information disclosure statement (IDS) submitted on 4 December 2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Priority
4. Foreign Priority claimed acknowledged.
Drawings
5. The drawings filed on 2 March 2025 are accepted by the examiner.
Claim Rejections - 35 USC § 102
6. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-20 are rejected 35 U.S.C §102 (a)(2) as being anticipated by Davis Perez (US Publication No. 20250254199), hereinafter Perez.
Regarding claim 1:
A computer program product for detecting threats in a cloud computing environment managed by a threat management facility, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of: (Perez, abstract).
receiving, at the threat management facility, a log of a plurality of modifications to cloud resources published by the cloud computing environment, wherein the log is incrementally transmitted to the threat management facility on an intermittent schedule (Perez, ¶17), wherein, the risk detection and prevention component 116 detects a risk in a configuration input prior to submission and implementation of that input for a given cloud asset. Upon receiving the input via a user interface, the risk detection and prevention component 116 modifies the user interface to prevent the submission of the input. As a result, the risk detection and prevention component 116 blocks the implementation of a detected misconfiguration or potential vulnerability (referred to herein collectively as “misconfiguration”.
filtering the log to identify one of the plurality of modifications associated with a potential misconfiguration of the cloud resources (Perez, ¶30), wherein, processing device determines if the input identified as a security misconfiguration has been modified. For example, the processing device monitors the user interface to detect if the user changes the input to replace a value, update a range of values, etc. If the input has been modified, the method 200 returns to operation 215 to evaluate if the modified input still satisfies the security misconfiguration threshold (and, if not, update the user interface to permit submission of the input). If the input has not been modified, the method 200 proceeds to operation 230.
extracting identity information for an entity that initiated the one of the plurality of modifications (Perez, ¶23), wherein, processing device optionally identifies a cloud service providing the user interface and/or managing the cloud asset. For example, in a web browser plugin embodiment, the accessing of the source markup language can include identifying the provider of the user interface and/or the provider of the cloud asset being managed. Different cloud services can use different terminology, implement rules differently, or present other factors that impact the detection of a misconfiguration risk. As such, embodiments can use the identification of the cloud service to interpret the input for risk evaluation. For example, the processing device can use a lookup table or other data structure to map an input parameter and/or asset in one cloud environment to another cloud environment, to neutral terminology, etc. Additionally or alternatively, the processing device can use the cloud service identity as an indicator of whether the input presents a risk. Other embodiments are configured to operate within or for a specific cloud service and, as a result, bypass operation 210.
in response to detecting the potential misconfiguration, fetching resource configuration data related to the potential misconfiguration from the cloud computing environment to the threat management facility using an application programming interface for the cloud computing environment, wherein fetching the resource configuration data includes fetching the resource configuration information before a next incrementally transmitted log update is published by the cloud computing environment, thereby providing an update to the resource configuration data for use in threat analysis (Perez, ¶30, ¶32, ¶17), wherein, the risk detection and prevention component 116 detects a risk in a configuration input prior to submission and implementation of that input for a given cloud asset. Upon receiving the input via a user interface, the risk detection and prevention component 116 modifies the user interface to prevent the submission of the input. As a result, the risk detection and prevention component 116 blocks the implementation of a detected misconfiguration or potential vulnerability (referred to herein collectively as “misconfiguration”). Additionally, the risk detection and prevention component 116 can display an alert to describe to a user why the submission was prevented. The risk detection and prevention component 116 can also reside, completely or at least partially, within the processing device 102 during execution thereof by the computer system 100.
and issuing a threat detection when the identity information and the resource configuration data including the update indicate a malicious misconfiguration of the cloud resources in the cloud computing environment (Perez, ¶23, ¶30), wherein, mplement rules differently, or present other factors that impact the detection of a misconfiguration risk. As such, embodiments can use the identification of the cloud service to interpret the input for risk evaluation. For example, the processing device can use a lookup table or other data structure to map an input parameter and/or asset in one cloud environment to another cloud environment, to neutral terminology, etc.
Regarding claim 2:
wherein the resource configuration data includes one or more security settings for the cloud computing environment (Perez, ¶9).
Regarding claim 3:
wherein the resource configuration data includes one or more properties of one of the cloud resources (Perez, ¶23).
Regarding claim 4:
wherein the cloud computing environment hosts resources for an enterprise network managed by the threat management facility (Perez, ¶23).
Regarding claim 5:
wherein extracting identity information includes storing an activity map of resources, entities, and resource modifications at the threat management facility based on a stream of log data from the cloud computing environment (Perez, ¶23).
Regarding claim 6:
wherein extracting identity information includes looking up one or more identities associated with the potential misconfiguration in the activity map (Perez, ¶23).
Regarding claim 7:
wherein the activity map stores at least one of an email address, a user name, or a unique cloud identifier for each entity (Perez, ¶32).
Regarding claim 8:
wherein the cloud computing environment generates an incremental update to the log at least once per minute (Perez, ¶30).
Regarding claim 9:
A method for detecting threats in a cloud computing environment managed by a threat management facility, the method comprising: receiving, at the threat management facility, a log of a plurality of modifications to cloud resources published by the cloud computing environment (Perez, Abstract).
filtering the log to identify one of the plurality of modifications associated with a potential misconfiguration of the cloud resources (Perez, ¶30), wherein, processing device determines if the input identified as a security misconfiguration has been modified. For example, the processing device monitors the user interface to detect if the user changes the input to replace a value, update a range of values, etc. If the input has been modified, the method 200 returns to operation 215 to evaluate if the modified input still satisfies the security misconfiguration threshold (and, if not, update the user interface to permit submission of the input). If the input has not been modified, the method 200 proceeds to operation 230.
extracting identity information for an entity that initiated the one of the plurality of modifications (Perez, ¶23), wherein, processing device optionally identifies a cloud service providing the user interface and/or managing the cloud asset. For example, in a web browser plugin embodiment, the accessing of the source markup language can include identifying the provider of the user interface and/or the provider of the cloud asset being managed. Different cloud services can use different terminology, implement rules differently, or present other factors that impact the detection of a misconfiguration risk. As such, embodiments can use the identification of the cloud service to interpret the input for risk evaluation. For example, the processing device can use a lookup table or other data structure to map an input parameter and/or asset in one cloud environment to another cloud environment, to neutral terminology, etc. Additionally or alternatively, the processing device can use the cloud service identity as an indicator of whether the input presents a risk. Other embodiments are configured to operate within or for a specific cloud service and, as a result, bypass operation 210.
fetching resource configuration data related to the potential misconfiguration from the cloud computing environment to the threat management facility using an application programming interface for the cloud computing environment (Perez, ¶9-10, ¶18), wherein, application running on top of or otherwise interpreting the markup language of a web browser (collectively referred to herein as a plugin for the case of providing examples). For example, the computer system 100 accesses a user interface to configure one or more cloud services via a web browser. As a plugin, the risk detection and prevention component 116 can detect and prevent the submission of a cloud asset misconfiguration for multiple cloud services. The software may further be transmitted or received over a network 108 via a network interface 106. For example, the machine-readable medium 114 and risk detection and prevention component 116 are implemented within one or more of the cloud service devices 110. In some embodiments, the risk detection and prevention component 116 is a component of the cloud service configuration service, CNAPP service, or other cloud service presenting the configuration user interface and receiving cloud asset configuration input.
and issuing a threat detection when the identity information and the resource configuration data indicate a malicious misconfiguration of the cloud resources in the cloud computing environment (Perez, ¶23, ¶30), wherein, implement rules differently, or present other factors that impact the detection of a misconfiguration risk. As such, embodiments can use the identification of the cloud service to interpret the input for risk evaluation. For example, the processing device can use a lookup table or other data structure to map an input parameter and/or asset in one cloud environment to another cloud environment, to neutral terminology, etc.
Regarding claim 10:
wherein the resource configuration data includes one or more security settings for the cloud computing environment (Perez, ¶9).
Regarding claim 11:
wherein the resource configuration data includes one or more properties of one of the cloud resources (Perez, ¶23).
Regarding claim 12:
wherein the cloud computing environment hosts resources for an enterprise network managed by the threat management facility (Perez, ¶23).
Regarding claim 13:
wherein extracting identity information includes storing an activity map of resources, entities, and resource modifications at the threat management facility based on a stream of log data from the cloud computing environment (Perez, ¶23).
Regarding claim 14:
wherein extracting identity information includes looking up one or more identities associated with the potential misconfiguration in the activity map (Perez, ¶23).
Regarding claim 15:
wherein the activity map stores at least one of an email address, a user name, or a unique cloud identifier for each entity (Perez, ¶32).
Regarding claim 16:
wherein the cloud computing environment streams the log to the threat management facility as a plurality of incremental updates (Perez, ¶10).
Regarding claim 17:
wherein the cloud computing environment generates an incremental update to the log at least once per minute (Perez, ¶30).
Regarding claim 18:
A system comprising: a cloud computing environment hosting resources for an enterprise network, the cloud computing environment configured to publish a log of a plurality of modifications to cloud resources on a predetermined schedule (Perez, ¶17, abstract).
and a threat management facility providing security services to the enterprise network, the threat management facility configured by computer executable code to perform the steps of: receiving the log from the cloud computing environment (Perez, ¶17), wherein, The risk detection and prevention component 116 detects a risk in a configuration input prior to submission and implementation of that input for a given cloud asset. Upon receiving the input via a user interface, the risk detection and prevention component 116 modifies the user interface to prevent the submission of the input.
filtering the log to identify one of the plurality of modifications associated with a potential misconfiguration of the cloud resources (Perez, ¶30), wherein, processing device determines if the input identified as a security misconfiguration has been modified. For example, the processing device monitors the user interface to detect if the user changes the input to replace a value, update a range of values, etc. If the input has been modified, the method 200 returns to operation 215 to evaluate if the modified input still satisfies the security misconfiguration threshold (and, if not, update the user interface to permit submission of the input). If the input has not been modified, the method 200 proceeds to operation 230.
extracting identity information for an entity that initiated the one of the plurality of modifications (Perez, ¶23), wherein, processing device optionally identifies a cloud service providing the user interface and/or managing the cloud asset. For example, in a web browser plugin embodiment, the accessing of the source markup language can include identifying the provider of the user interface and/or the provider of the cloud asset being managed. Different cloud services can use different terminology, implement rules differently, or present other factors that impact the detection of a misconfiguration risk. As such, embodiments can use the identification of the cloud service to interpret the input for risk evaluation. For example, the processing device can use a lookup table or other data structure to map an input parameter and/or asset in one cloud environment to another cloud environment, to neutral terminology, etc. Additionally or alternatively, the processing device can use the cloud service identity as an indicator of whether the input presents a risk. Other embodiments are configured to operate within or for a specific cloud service and, as a result, bypass operation 210.
and in response to the potential misconfiguration, fetching resource configuration data related to the potential misconfiguration from the cloud computing environment using an application programming interface for the cloud computing environment (Perez, ¶30, ¶32, ¶17), wherein, the risk detection and prevention component 116 detects a risk in a configuration input prior to submission and implementation of that input for a given cloud asset. Upon receiving the input via a user interface, the risk detection and prevention component 116 modifies the user interface to prevent the submission of the input. As a result, the risk detection and prevention component 116 blocks the implementation of a detected misconfiguration or potential vulnerability (referred to herein collectively as “misconfiguration”). Additionally, the risk detection and prevention component 116 can display an alert to describe to a user why the submission was prevented. The risk detection and prevention component 116 can also reside, completely or at least partially, within the processing device 102 during execution thereof by the computer system 100.
Regarding claim 19:
wherein the threat management facility is further configured to perform the step of issuing a threat detection when the identity information and the resource configuration data indicate a malicious misconfiguration of the cloud resources in the cloud computing environment (Perez, ¶9-10).
Regarding claim 20:
wherein extracting identity information includes looking up one or more identities associated with the potential misconfiguration in an activity map stored by the threat management facility (Perez, ¶23).
Conclusion
7. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Monjour Rahim whose telephone number is (571)270-3890.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (in USA or CANANDA) or 571-272-1000.
/Monjur Rahim/
Patent Examiner
United States Patent and Trademark Office
Art Unit: 2436; Phone: 571.270.3890
E-mail: monjur.rahim@uspto.gov
Fax: 571.270.4890