DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that use the word “means” or “step” but are nonetheless not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph because the claim limitation(s) recite(s) sufficient structure, materials, or acts to entirely perform the recited function. Such claim limitation(s) is/are: “instructions to configure the system to deploy a sensor/receive and event/provision an inspector/inspect the resource” in claim 11; “instructions to configure the system to detect a disk/generate an inspectable disk/inspect the inspectable disk” in claim 12; “instructions to configure the system to clone the detected disk” in claim 13; “instructions to configure the system to initiate a mitigation action” in claim 14; “instructions to configure the system to apply a logical expression/determine that a potential cybersecurity threat is an actual cybersecurity threat” in 15; “instructions to configure the system to send a rule to the sensor/configure the sensor” in claim 17; “instructions to configure the system to configure the sensor” in claim 18; and “instructions to configure the system to send data pertaining to the detected event” in claim 19.
Because this/these claim limitation(s) is/are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are not being interpreted to cover only the corresponding structure, material, or acts described in the specification as performing the claimed function, and equivalents thereof.
If applicant intends to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to remove the structure, materials, or acts that performs the claimed function; or (2) present a sufficient showing that the claim limitation(s) does/do not recite sufficient structure, materials, or acts to perform the claimed function.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-5, 8-16, and 19-21 of U.S. Patent No. 12,278,825. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the ‘825 patent are anticipated by the earlier filed patented ‘825 claims in that the claims of the patent contain all of the limitations on the instant application.
Claim 1 of the instant application corresponds to claim 1 of the ‘825 patent;
Claim 2 of the instant application corresponds to claim 2 of the ‘825 patent;
Claim 3 of the instant application corresponds to claim 3 of the ‘825 patent;
Claim 4 of the instant application corresponds to claim 4 of the ‘825 patent;
Claim 5 of the instant application corresponds to claim 5 of the ‘825 patent;
Claim 6 of the instant application corresponds to claim 8 of the ‘825 patent;
Claim 7 of the instant application corresponds to claim 9 of the ‘825 patent;
Claim 8 of the instant application corresponds to claim 9 of the ‘825 patent;
Claim 9 of the instant application corresponds to claim 10 of the ‘825 patent;
Claim 10 of the instant application corresponds to claim 11 of the ‘825 patent;
Claim 11 of the instant application corresponds to claim 12 of the ‘825 patent;
Claim 12 of the instant application corresponds to claim 13 of the ‘825 patent;
Claim 13 of the instant application corresponds to claim 14 of the ‘825 patent;
Claim 14 of the instant application corresponds to claim 15 of the ‘825 patent;
Claim 15 of the instant application corresponds to claim 16 of the ‘825 patent;
Claim 16 of the instant application corresponds to claim 19 of the ‘825 patent;
Claim 17 of the instant application corresponds to claim 20 of the ‘825 patent;
Claim 18 of the instant application corresponds to claim 20 of the ‘825 patent; and
Claim 19 of the instant application corresponds to claim 21 of the ‘825 patent.
Claims 1-19 of the instant application therefore are not patentably distinct from the earlier filed patented claims, and as such, are unpatentable for obvious-type double patenting.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1, 4, 10, 11, and 14 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Kwon et al, U.S. Patent 12,495,066.
As per claim 1, it is taught of a method for improved endpoint detection and response (EDR) in a cloud computing environment, comprising:
deploying a sensor on a resource (endpoint agent (i.e., sensor) is installed on an endpoint (i.e., resource), col. 4, lines 56-57), the resource deployed in a cloud computing environment (endpoint (i.e., resource) is deployed on a cloud network (i.e., environment) that communicates via a cloud server, col. 4, lines 34-36 & 56-60), wherein the sensor is configured to detect runtime data on the resource (endpoint agent (i.e., sensor) identifies (i.e., detects) malicious executable files, script location, and control execution methods (i.e., runtime data) on the endpoint (i.e., resource), col. 4, line 66 through col. 5, line 5);
receiving an event from the sensor, the event indicating a cybersecurity threat (the endpoint agent (i.e., sensor) generates metadata for the malware detected (i.e., event indicating a cybersecurity threat) and transmits the generated metadata to a threat analysis server via the cloud server, col. 5, lines 21-24);
provisioning an inspector to inspect the resource for the cybersecurity threat (malware analysis module (i.e. inspector) of the threat analysis server receives the metadata about the malware (i.e., cybersecurity threat) and analyzes (i.e., inspects) the corresponding downloaded malware (i.e., cybersecurity threat), col. 6, lines 6-18); and
inspecting the resource for the cybersecurity threat (a static analyzer of the malware analysis module (i.e. inspector) analyzes the downloaded malware (i.e., cybersecurity threat) by reverse coding through reverse engineering and a dynamic analyzer analyzers the behavior of the corresponding malware (i.e., cybersecurity threat) by execution through a virtual machine (i.e., resource) or a PC (i.e., resource) corresponding to the metadata captured by the endpoint agent (i.e., sensor) of the endpoint (i.e., resource), col. 6, lines 13-18, 28-34, & 41-51).
As per claim 4, it is disclosed of further comprising: initiating a mitigation action in response to detecting the cybersecurity threat based on inspecting the resource (upon detection of the malware (i.e., cybersecurity threat), the malware is blocked (i.e., initiating a mitigation action) based upon the inspection of the endpoint (i.e., resource) and a security policy of a solution is provided, col. 4, lines 61-65 and col. 10, lines 52-57).
As per claim 10, it is disclosed of a non-transitory computer-readable medium storing a set of instructions for improved endpoint detection and response (EDR) in a cloud computing environment, the set of instructions (col. 4, lines 30-41) comprising:
one or more instructions that, when executed by one or more processors of a device (col. 4, lines 30-41), cause the device to:
deploy a sensor on a resource (endpoint agent (i.e., sensor) is installed on an endpoint (i.e., resource), col. 4, lines 56-57), the resource deployed in a cloud computing environment (endpoint (i.e., resource) is deployed on a cloud network (i.e., environment) that communicates via a cloud server, col. 4, lines 34-36 & 56-60), wherein the sensor is configured to detect runtime data on the resource (endpoint agent (i.e., sensor) identifies (i.e., detects) malicious executable files, script location, and control execution methods (i.e., runtime data) on the endpoint (i.e., resource), col. 4, line 66 through col. 5, line 5);
receive an event from the sensor, the event indicating a cybersecurity threat (the endpoint agent (i.e., sensor) generates metadata for the malware detected (i.e., event indicating a cybersecurity threat) and transmits the generated metadata to a threat analysis server via the cloud server, col. 5, lines 21-24);
provision an inspector to inspect the resource for the cybersecurity threat (malware analysis module (i.e. inspector) of the threat analysis server receives the metadata about the malware (i.e., cybersecurity threat) and analyzes (i.e., inspects) the corresponding downloaded malware (i.e., cybersecurity threat), col. 6, lines 6-18); and
inspect the resource for the cybersecurity threat (a static analyzer of the malware analysis module (i.e. inspector) analyzes the downloaded malware (i.e., cybersecurity threat) by reverse coding through reverse engineering and a dynamic analyzer analyzers the behavior of the corresponding malware (i.e., cybersecurity threat) by execution through a virtual machine (i.e., resource) or a PC (i.e., resource) corresponding to the metadata captured by the endpoint agent (i.e., sensor) of the endpoint (i.e., resource), col. 6, lines 13-18, 28-34, & 41-51).
As per claim 11, it is taught of a system for improved endpoint detection and response (EDR) in a cloud computing environment comprising:
a processing circuitry (col. 4, lines 30-41);
a memory, the memory containing instructions that, when executed by the processing circuitry (col. 4, lines 30-41), configure the system to:
deploy a sensor on a resource (endpoint agent (i.e., sensor) is installed on an endpoint (i.e., resource), col. 4, lines 56-57), the resource deployed in a cloud computing environment (endpoint (i.e., resource) is deployed on a cloud network (i.e., environment) that communicates via a cloud server, col. 4, lines 34-36 & 56-60), wherein the sensor is configured to detect runtime data on the resource (endpoint agent (i.e., sensor) identifies (i.e., detects) malicious executable files, script location, and control execution methods (i.e., runtime data) on the endpoint (i.e., resource), col. 4, line 66 through col. 5, line 5);
receive an event from the sensor, the event indicating a cybersecurity threat (the endpoint agent (i.e., sensor) generates metadata for the malware detected (i.e., event indicating a cybersecurity threat) and transmits the generated metadata to a threat analysis server via the cloud server, col. 5, lines 21-24);
provision an inspector to inspect the resource for the cybersecurity threat (malware analysis module (i.e. inspector) of the threat analysis server receives the metadata about the malware (i.e., cybersecurity threat) and analyzes the corresponding downloaded malware (i.e., cybersecurity threat), col. 6, lines 6-18); and
inspect the resource for the cybersecurity threat (a static analyzer of the malware analysis module (i.e. inspector) analyzes the downloaded malware (i.e., cybersecurity threat) by reverse coding through reverse engineering and a dynamic analyzer analyzers the behavior of the corresponding malware (i.e., cybersecurity threat) by execution through a virtual machine (i.e., resource) or a PC (i.e., resource) corresponding to the metadata captured by the endpoint agent (i.e., sensor) of the endpoint (i.e., resource), col. 6, lines 13-18, 28-34, & 41-51).
As per claim 14, it is disclosed wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
initiate a mitigation action in response to detecting the cybersecurity threat based on inspecting the resource (upon detection of the malware (i.e., cybersecurity threat), the malware is blocked (i.e., initiating a mitigation action) based upon the inspection of the endpoint (i.e., resource) and a security policy of a solution is provided, col. 4, lines 61-65 and col. 10, lines 52-57).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2, 3, 12, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Kwon et al, U.S. Patent 12,495,066 in view of Loureiro et al, U.S. Patent 10,412,109.
As per claims 2 and 12, Kwon fails to disclose: detecting a disk associated with the resource; generating an inspectable disk based on the detected disk; and inspecting the inspectable disk for a cybersecurity object indicating the cybersecurity threat, in response to receiving the event.
Loureiro et al discloses:
detecting a disk associated with the resource (e.g., system connects to a virtual or cloud computing system (“resource”), col. 2, lines 22-25; the “detected” virtual or cloud computing system is presented for cloning/copying, col. 4, lines 39-44);
generating an inspectable disk based on the detected disk (e.g., clone or disk copy of the virtual production server or cloud computing system (“resource”) is created, col. 2, lines 22-25; col. 4, lines 56-62); and
inspecting the inspectable disk for a cybersecurity object indicating the cybersecurity threat, in response to receiving the event (e.g., the clone or disk copy is analyzed for vulnerabilities (“cybersecurity object”), col. 2, lines 26-30)(e.g., vulnerabilities include presence of viruses, presence of malware, hacking of the server, presence of intrusions, etc. (“cybersecurity objects”), col. 2, lines 56-65).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have been motivated to clone a copy of a virtual or cloud computing system (i.e., “inspectable disk”) for the security of a virtual or cloud computing system to detect vulnerabilities that may not be exhaustive, and lead to identification of false positives, as is known in the prior art (Loureiro et al, col. 1, line 66 through col. 2, line 3). Loureiro et al offers motivation for the cloning by disclosing that it is isolated from the cloud computing system that avoids side effects that could be caused by running the test of searching for vulnerabilities, col. 5, lines 13-16.
The teachings of Kwon et al are disclose of applying remediations, col. 4, lines 61-65 and col. 10, lines 52-57, and the teachings of Loureiro et al offer an approach that isolates the resource that is analyzed for cybersecurity objects by cloning the resource in a manner whereby side effects are avoided, that does not adversely affect the regular performance of the system.
As per claims 3 and 13, it is taught by Loureiro et al of further comprising: cloning the detected disk into the inspectable disk (e.g., clone or disk copy of the virtual production server or cloud computing system is created, col. 2, lines 22-25; col. 4, lines 56-62). Please refer above for the motivational benefits of the cloning of the disk as is recited above in the preceding independent claim, when applying Loureiro et al with the teachings of Kwon et al.
Claims 5, 7-9, 15, and 17-19 are rejected under 35 U.S.C. 103 as being unpatentable over Kwon et al, U.S. Patent 12,495,066 in view of Woodford et al, U.S. Patent 11,546,360.
As per claims 5 and 15, Kwon et al discloses of events detected by the sensor and determining that potential malware (i.e., cybersecurity threat) is actual malware (i.e., cybersecurity threat)(col. 3, lines 15-35), but fail to disclose: applying a logical expression of a definition to a detected event; and determining that a potential cybersecurity threat is an actual cybersecurity threat in response to a binary outcome of the applied logical expression having a predetermined value.
Woodford et al discloses:
applying a logical expression of a definition to a detected event; and determining that a potential cybersecurity threat is an actual cybersecurity threat in response to a binary outcome of the applied logical expression having a predetermined value (watching for specific threats…for which the threat detection system is being used, heuristics are applied that use complex chains of weight logical expressions manifested as regular expressions with atomic objects that are detected at runtime, and a policy dictates what action may be taken, e.g. providing alerts, etc, col. 26, lines 21-45).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have been motivated to apply logical expressions for detecting certain types of threats. The teachings of Woodford et al disclose of using heuristics using complex chains of weighted logical expressions that are stored in libraries, and parsed in real-time against outputs, to determine what kind of particular threat exists, and what action to take, such as alerting an administrator if a certain condition is detected and triggered, col. 26, lines 25-41. The teachings of Kwon et al would have found the teachings of Woodford et al to be a more comprehensive addition of detecting and reporting malicious conditions on top of the current methods used by Kwon et al whereby endpoint agents (i.e., sensors) and additional remote analysis is conducted to determine maliciousness (i.e., cybersecurity threats).
As per claims 7, 8, 17, and 18, Kwon et al fails to disclose: sending a rule to the sensor, the rule including a logical expression and an action; configuring the sensor to apply the rule on a detected runtime event; and configuring the sensor to perform the action in response to applying the rule on the detected event and receiving a predetermined result.
Woodford et al discloses of sending a rule to the sensor, the rule including a logical expression and an action; configuring the sensor to apply the rule on a detected runtime event; and configuring the sensor to perform the action in response to applying the rule on the detected event and receiving a predetermined result (watching for specific threats…for which the threat detection system is being used, heuristics are applied that use complex chains of weight logical expressions manifested as regular expressions with atomic objects that are detected at runtime, and a policy dictates what action may be taken, e.g. providing alerts, etc, col. 26, lines 21-45).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have been motivated to apply logical expressions for detecting certain types of threats. The teachings of Woodford et al disclose of using heuristics using complex chains of weighted logical expressions that are stored in libraries, and parsed in real-time against outputs, to determine what kind of particular threat exists, and what action to take, such as alerting an administrator if a certain condition is detected and triggered, col. 26, lines 25-41. The teachings of Kwon et al would have found the teachings of Woodford et al to be a more comprehensive addition of detecting and reporting malicious conditions on top of the current methods used by Kwon et al whereby endpoint agents (i.e., sensors) and additional remote analysis is conducted to determine maliciousness (i.e., cybersecurity threats).
As per claims 9 and 19, it is taught by Kwon et al of:
sending data pertaining to the detected event to a sensor backend server (the endpoint agent (i.e., sensor) generates metadata for the malware detected (i.e., event indicating a cybersecurity threat) and transmits the generated metadata to a threat analysis server (i.e., sensor backend server) via the cloud server, col. 5, lines 21-24), wherein the sensor backend server is configured to initiate inspection of the resource (malware analysis module of the threat analysis server (i.e., sensor backend server) receives the metadata about the malware (i.e., cybersecurity threat) and analyzes (i.e., inspects) the corresponding downloaded malware (i.e., cybersecurity threat), col. 6, lines 6-18).
Claims 6 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Kwon et al, U.S. Patent 12,495,066 in view of Siddiqui et al, U.S. Patent 10,791,138.
As per claims 6 and 16, Kwon et al fails to disclose wherein the resource is a software container, further comprising: configuring a container cluster of the software container to deploy a daemonset, the daemonset including a plurality of nodes, each node including a daemonset pod, wherein the daemonset pod is the deployed sensor.
Siddiqui et al discloses wherein the resource is a software container (a subscriber site, which is running as a software application on the subscriber’s device, col. 6, lines 61-63, wherein the object evaluation service (i.e. containers) includes one or more clusters (referred to as “clusters”) for use in analyzing objects provided by one or more sensors for malware and a cluster management system that monitors the operations of each cluster and controls its configuration, col. 2, lines 62-66), further comprising:
configuring a container cluster of the software container to deploy a daemonset, the daemonset including a plurality of nodes, each node including a daemonset pod, wherein the daemonset pod is the deployed sensor (e.g., cloud broker for the analysis selection service establishes communications sessions between a sensor and cluster, that involves selection of a particular compute node (i.e., daemonset pod) within that cluster to handle analyses of suspicious objects detected by a specific sensor, col. 5, lines 17-31).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to have been motivated to apply container clusters to aid in detecting cybersecurity threats. Siddiqui et al discloses of motivation to allow for evaluation of objects in a more detailed manner. Siddiqui et al discloses of motivational reasons by reciting of an object evaluation service includes one or more clusters for use in analyzing objects provided by one or more sensors for malware and a cluster management system that monitors the operations of each cluster and controls its configuration, col. 2, lines 62-66. The teachings of Kwon et al would have found this improvement introduced by Siddiqui et al as a means to use an object evaluation service to monitor operations provided by sensors for cybersecurity threats as a more comprehensive way of performing cybersecurity analysis.
Conclusion
The relevant art made of record and not relied upon is considered pertinent to applicant's disclosure.
Rao et al, US 2022/0036208 is relied upon for disclosing of a malware analysis service can comprise an additional workflow to execute files on a virtual machine to analyze malicious effects, apply additional machine learning models or algorithms, perform domain expert analysis on the files, etc. and can implement the supplemental model with the tuned activation range in a pipeline with the incumbent model already running natively. The security products are depicted as Palo Alto Networks® enterprise firewall PA-5020, M-700 appliance, and enterprise firewall PA-7080 respectively but can be any security product running natively on any remote device, across a cloud or network, see paragraph 0026.
Vijayvargiya et al, US 2021/0286877 is relied upon for disclosing of next generation antivirus (NGAV) security solution in a virtualized computing environment includes a security sensor at a virtual machine that runs on a host and a security engine remote from the host. The integrity of the NGAV security solution is increased, by providing a verification as to whether a verdict issued by the security engine has been successfully enforced by the security sensor to prevent execution of malicious code at the virtual machine, see abstract.
Lee et al, US 2022/0094713 is relied upon for disclosing of a system including a security classifier executing on a threat management resource of an enterprise network, the security classifier performing a classification task. The threat management resource may, for example, include a local security agent executing on an endpoint in the enterprise network, a local or remote (e.g., cloud-based) threat management facility for the enterprise network, a firewall or gateway for the enterprise network, a communications platform for the network (e.g., an email server, instant messaging server, and so forth), or any other resource, see paragraph 0099.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER REVAK whose telephone number is (571)272-3794. The examiner can normally be reached 5:30am - 3:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER A REVAK/Primary Examiner, Art Unit 2407