DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Remarks
This action is in response to the application received on 3/3/25. Claims 1-20 are pending in the application.
Claims 1-20 are rejected under 35 U.S.C. 112.
Claims 1-20 are rejected under 35 U.S.C. 101.
Claims 1-9 and 11-19 are rejected under 35 U.S.C. 103 as being unpatentable over Martin et al. (US 2024/0154992), and further in view of Suttle et al. (US 2023/0342179).
Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Martin in view of Suttle, and further in view of Sampat et al. (US 2022/0247660).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 9, 11, and 19 recite the limitation "the change feeds." There is insufficient antecedent basis for this limitation in the claim. The recitation of “a change feed” in the “retrieving” limitation does not require multiple change feeds.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 2A, Prong One asks: Is the claim directed to a law of nature, a natural phenomenon (product of nature) or an abstract idea? See MPEP 2106.04 Part I. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. See MPEP 2106.04(a).
With respect to claims 1 and 11, the limitation of “analyzing the change feeds to identify modifications of one or more resources”, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, “analyzing” in the context of this claim encompasses the user thinking about data. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
At step 2a, prong two, this judicial exception is not integrated into a practical application. Claim 11 recites a processor to execute the operations, however, this is recited as a high-level of generality (i.e., as a generic processor performing a generic computer function) such that it amounts to no more than mere instructions to apply the exception using a generic computer component. Additionally, the claim recites “retrieving a change feed,” “updating a data store,” and “providing a customer-specific dashboard.” These elements do not integrate the abstract idea into a practical application because they do not impose a meaningful limit on the judicial exception and provide only insignificant extra solution activity that is mere data gathering in conjunction with the abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements amount to no more than mere instructions to apply an exception using generic computer components. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept.
With respect to “retrieving a change feed”, the courts have found limitations directed towards data gathering to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information).
With respect to “updating a data store”, the courts have found limitations directed towards storing to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Electronic recordkeeping, Alice Corp. Pty. Ltd. v. CLS Bank Int'l, 573 U.S. 208, 225, 110 USPQ2d 1984 (2014) (creating and maintaining "shadow accounts") and “storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015).
With respect to “providing a customer-specific dashboard”, the courts have found limitations directed towards outputting to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Presenting offers and gathering statistics, OIP Techs., 788 F.3d at 1362-63, 115 USPQ2d at 1092-93.
Considering the additional elements individually and in combination and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. The claim is not patent eligible.
With respect to claims 2-4 and 12-14, the limitations further define limitations discussed above without integrating the abstract idea into a practical application.
With respect to claims 5 and 15, the limitations are directed towards creating a connection via an API. An API is a generic computer component and the limitation amounts to no more than mere instructions to apply the exception using a generic computer component.
With respect to claims 6 and 16, the limitations are directed towards “applying filtering logic.” This is a method of organizing human activity that describes managing personal behavior or relationships or interactions between people. See MPEP 2106.04(a)(2) Section II, Part C.
With respect to claims 7 and 17, the limitations are directed towards generating real-time notifications. These elements do not integrate the abstract idea into a practical application because they do not impose a meaningful limit on the judicial exception and provide only insignificant extra solution activity that is mere data gathering in conjunction with the abstract idea. The courts have found limitations directed towards outputting to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Presenting offers and gathering statistics, OIP Techs., 788 F.3d at 1362-63, 115 USPQ2d at 1092-93.
With respect to claims 8 and 18, the limitations are directed towards “performing a full metadata scan” which is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, “performing a full metadata scan” in the context of this claim encompasses the user looking at data.
With respect to claims 9, 10, 19, and 20, the limitations further define above discussed components without integrating the abstract idea into a practical application.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-9 and 11-19 are rejected under 35 U.S.C. 103 as being unpatentable over Martin et al. (US 2024/0154992), and further in view of Suttle et al. (US 2023/0342179).
With respect to claim 1, Martin teaches the method implemented by a cloud-based system, the method comprising steps of:
retrieving a change feed from one or more Cloud Service Providers (CSPs) associated with a customer of the cloud-based system (Martin, pa 0185, Process 1200 begins at step 1201, in which information is obtained about one or more cloud computing events from a cloud computing environment. The information about events may be contained within one or more cloud computing logs, such as logs 115 of FIG. 1);
analyzing the change feeds to identify modifications of one or more resources within network environments associated with the customer (Martin, pa 0186, The information about cloud computing event(s) is analyzed in step 1202 to determine if the one or more events are associated with the allocation of storage to a cloud computing resource.), wherein the network environments are provided by the one or more CSPs (Martin, pa 0186, information related to a single event in which storage is attached to a cloud computing resource, such as an "Attach Volume" event in an AWS cloud computing environment may indicate the particular resource requires collection and analysis.);
updating a data store of the customer with any new or modified resources based on the analyzing (Martin, pa 0111, The cloud collectors 431 may perform one or more operations on the collected cloud computing event information… filtering, grouping, translating, and enriching messages into data structures and/or jobs associated with data structures such as work jobs or work job messages); and
Martin doesn't expressly discuss providing a customer-specific dashboard including analytics for all CSPs associated with the customer of the cloud-based system.
Suttle teaches providing a customer-specific dashboard including analytics for all CSPs associated with the customer of the cloud-based system (Suttle, Fig. 2, AGENT dashboard with data from AWS and Azure & pa 0016, The system may also allow for fast access to compliance information for a company's cloud environment via robust dashboarding capability).
It would have been obvious at the effective filing date of the invention to a person having ordinary skill in the art to which said subject matter pertains to have modified Martin with the teachings of Suttle because fast access to compliance information for a company's cloud environment (Suttle, pa 0016).
With respect to claim 2, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Google Cloud Platform (GCP), and wherein the retrieving includes accessing the customers' GCP Audit Logs (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment… For example, in a Google Cloud Platform (GCP) Cloud the cloud computing log(s) may be a "Cloud Asset Inventory (CAI) Event Stream".).
With respect to claim 3, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Amazon Web Services (AWS), and wherein the retrieving includes accessing the customers' AWS CloudTrail Events (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment. For example, in an Amazon Web Services (A WS) Cloud the cloud computing log(s) may be an AWS "CloudTrail" log.).
With respect to claim 4, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Microsoft Azure, and wherein the retrieving includes accessing the customers' Azure Activity Logs (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment.… For example, in an Azure cloud, the one or more log(s) may be an "Azure Security Logging and Auditing log" and/or an "Azure platform activity log".).
With respect to claim 5, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise creating a connection to the one or more CSPs via Application Programing Interfaces (APIs) associated therewith, and wherein the retrieving is performed via the APIs.
With respect to claim 6, Martin in view of Suttle teaches the method of claim 1, wherein the analyzing includes applying filtering logic to identify changes for specific resources in the network environments (Martin, pa 0108, One or more event subscriptions 317 allow information related to cloud computing events to be obtained from the logs 319A and 319B… event subscriptions 317 may be associated with specific event types, and therefore individual event subscriptions obtain certain events from logs 319Aand 319B. For example, event subscriptions 317 may only obtain information about cloud computing events which may or are likely to introduce security risks into the cloud computing environment 310).
With respect to claim 7, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise generating real-time notifications based on the analyzing (Martin, pa 0159, display the determined security actions on a user interface of the information security system for an administrator of the system to analyze).
With respect to claim 8, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise performing a full metadata scan of a resource based on the analyzing (Martin, pa 0158, Process 900 then proceeds to step 903 in which it is determined whether a security action is to be taken at least in part by analyzing the data and the supplemental data. & Suttle, pa 0007, identifying, by a processor, at least one of a creation of a cloud resource or a change to a configuration of the cloud resource (step 105); scanning, by the processor and in real-time, the configuration of the cloud resource, in response to the identifying (step 110); & pa 0022, “AGENT Scanner” may add additional capability in enriching the resource information by collecting resource metadata beyond what is provided by AWS by default as a service offering. For example, the resource state, annotations, tags, resource properties, etc. This data may allow the AGENT to take actions which are not by-default available in AWS services including, for example, triggering an auto remediation workflow, generating ServiceNow ITSM or checking if the non-compliant resource has an associated security exception.).
With respect to claim 9, Martin in view of Suttle teaches the method of claim 8, wherein the full metadata scan is performed in response to one or more specific events identified in the change feeds (Martin, pa 0119, cloud worker 433B may determine additional analysis of the cloud computing event may be needed and therefore the event information is passed to security processing module 436.).
With respect to claims 11-19, the limitations are essentially the same as claims 1-9, and are rejected for the same reasons.
Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Martin in view of Suttle, and further in view of Sampat et al. (US 2022/0247660).
With respect to claim 10, Martin in view of Suttle teaches the method of claim 8, as discussed above.
Sampat teaches identifying malicious activity in response to a number of resources being altered surpassing a threshold (Sampat, pa 0066, the number of times a process restarted, changed, or crashed may be determined. A process that has been restarted more than a threshold number of times within the aggregation interval may indicate malicious activity associated with the process.).
It would have been obvious at the effective filing date of the invention to a person having ordinary skill in the art to which said subject matter pertains to have modified Martin in view of Suttle with the teachings of Sampat because it indicates computing units that may be have malicious activity (pa 0019 & 0066).
With respect to claim 20, the limitations are essentially the same as claim 10, and are rejected for the same reasons.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Pandurangi et al. (US 2022/0046059) teaches a cloud security posture management system for analyzing misconfigurations in cloud systems.
Sobrier et al. (US 12,425,428) teaches activity monitoring of a cloud compute environment for security issues.
Jim, Md Majadul Islam. "Cloud security posture management automating risk identification and response in cloud infrastructures." Academic Journal on Science, Technology, Engineering & Mathematics Education 4.3 (2024): 10-69593. This reference discusses a cloud security posture management system for automating risk identification and response in cloud infrastructures.
Gujjala, Praveen Kumar Reddy. "Scalable and Intelligent Centralized Alerting Frameworks for Multi-Region Cloud Environments." International Journal of Scientific Research in Computer Science, Engineering and Information Technology (2024). This reference discusses a centralized alerting framework for enterprise cloud environments.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRITTANY N ALLEN whose telephone number is (571)270-3566. The examiner can normally be reached M-F 9 am - 5:00 pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Sherief Badawi can be reached at 571-272-9782. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BRITTANY N ALLEN/ Primary Examiner, Art Unit 2169