Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is responsive to: an original application filed on 5 March 2025.
2. Claims 1-21 are currently pending and rejected.
Information Disclosure Statement
3. The information disclosure statement (IDS) submitted The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Priority
4. Claimed Priority date has been considered.
Drawings
5. The drawings filed on 5 March 2025 are accepted by the examiner.
Double Patenting
6. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents /process/ file/efs/guidance /eTD-info-I.jsp.
Claims 1-21 are rejected under the grounds of non-statutory obviousness-type double patenting, as they are deemed unpatentable over claims 1-20 of US Patent application No. 18/400,720. 17/664,508.
Although the conflicting claims are not identical, they are considered not patentably distinct from one another, as they convey the same inventive concept. Specifically, both sets of claims disclose a method for disk inspection by cloning original disk. Furthermore, it would have been obvious to one of ordinary skill in the art, at the time of the invention’s filing, to employ this approach to prevent and protect data, malware in a network, thereby rendering the claims unpatentable.
Claim Rejections - 35 USC § 101
7. 35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 11 and 12 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e. an abstract idea) without significantly more.
Following the decision in the claims are analyzed where the abstract idea judicial exception to the categories of statutory subject matter is at issue using the following two-part analysis set forth in Mayo: 1) Determine whether the claim is directed to an abstract idea; and 2) if an abstract idea is present in the claim, determine whether any element, or combination of elements, in the claim is sufficient to ensure that the claim amounts to significantly more than the abstract idea itself. See Alice Corp. Pty. Ltd. v. CLS Bank Int’l, 134 S.Ct. at 2350.
Claims 1, 11 and 12 are directed to the abstract idea of detecting sensitive data by reciting steps of generating, inspecting determining, initiating information found to be an abstract idea by the courts (Cyberfone: see Section IV.B.5).
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the limitations are merely instructions to implement the abstract idea on a computer and require no more than a generic computer to perform generic computer functions that are well-understood, routine and conventional activities previously known to the industry.
Above limitations are generic computing operation that does not enhance the functionality of the computer. Further, the claim does not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or meaningful limitations beyond generally linking the use of an abstract idea to a particular technological environment.
Therefore, claims 1, 11 and 12 are directed to non-statutory subject matter. The dependent claims fail to obviate such rejections and are themselves rejected under this title for they are also abstract ideas and fall outside the plainly expressed scope of this title.
Please see the Interim Guidance on Patent Subject Matter Eligibility (December 2014) - http://www.gpo.gov/fdsys/pkg/FR-2014-12-16/pdf/2014-29414.pdf
Claim Rejections - 35 USC § 102
8. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-21 are rejected 35 U.S.C §102 (a)(2) as being anticipated by Ithal et al. (US Publication No. 20230087093), hereinafter Ithal.
Regarding claim 1:
generating a cloned disk directly from an original disk of a resource deployed in a cloud computing environment (Ithal, abstract), wherein, The method includes identifying a snapshot of the database, wherein the snapshot includes a second authentication requirement that is different than the first authentication requirement. The method includes accessing the snapshot using the second authentication requirement, generating a representation of the database using the snapshot, and generating a data posture analysis result indicative of a data posture of the database based on scanning the representation of the database.
inspecting the cloned disk for a cybersecurity object, the cybersecurity object indicating a sensitive data (Ithal, ¶99), wherein T The system can discover sensitive data among the cloud storage resources and discover access patterns to the sensitive data. The results can be used to identify security vulnerabilities to understand the data security posture, detect and remediate the security vulnerabilities, and to prevent future breaches to sensitive data. The system provides real-time visibility and control on the control data infrastructure by discovering resources, sensitive data, and access paths, and tracking resource configuration, deep context and trust relationships in real-time as a graph or other visualization.
detecting the cybersecurity object, wherein the cybersecurity object further includes a data schema (Ithal, ¶128, ¶136), wherein btained by metadata ingestion component 216, sensitive data profiles 254, detected data schema records 255, and can store other items 256 as well. Examples of sensitive data profiles 254 are discussed in further detail below. Briefly, however, sensitive data profiles 254 can identify target data patterns that are to be categorized as sensitive or conforming to a predefined pattern of interest. Sensitive data profiles 254 can be used as training data for data classification performed by data schema detection component 229. Examples of data classification are discussed in further detail below. For instance, however, pattern matching can be performed based on the target data profiles.
generating a classification of the data schema (Ithal, ¶22), wherein, wherein generating the data posture analysis result comprises: [0023] obtaining metadata representing a structure of schema objects in the database; and [0024] based on the metadata, executing a content-based data classifier to classify data items in the schema objects.
detecting in the cloned disk a plurality of data files, each data file generated based on the data schema (Ithal, ¶200), wherein Data store accessing component 902 is configured to access data stores to be analyzed. Context-based classifier 904 includes a schema detector 920, a metadata generator 922, and can include other items 924 as well. Schema detector 920 is configured to detect a schema used by the data store, and includes a schema parsing component 926, which includes a schema object detector 928. For sake of illustration, but not by limitation, in an example structured database.
determining that the data schema corresponds to sensitive data based on the generated classification (Ithal, ¶180), wherein the first subset of storage resources identified at block 572, are based on determining that the storage resources satisfy a risk signature of containing private and/or sensitive content.
determining that the original disk includes a cybersecurity risk (Ithal, ¶103), wherein a cloud security posture analysis system 122 configured to access cloud services 108 to identify and analyze cloud security posture data. Examples of system 122 are discussed in further detail below. Briefly, however, system 122 is configured to access cloud services 108 and identify connected resources, entities, actors, etc. within those cloud services, and to identify risks and violations against access to sensitive information.
and initiating a mitigation action for each data file based on the cybersecurity risk(Ithal, ¶241, ¶219), perform remedial actions, etc. At block 1088, security issue detection can be performed to detect security issues based on the scan results. In one example, security issue prioritization is performed at block 1090. Examples of security issue detection and prioritization are discussed above. Remedial actions are illustrated at block 1092. Of course, other actions can be performed at block 1094 and discover sensitive data among the cloud storage resources and as well as access patterns to the sensitive data, using local scanners that reduce or eliminate need to send the cloud data outside the cloud environment. This improves data security. Further, the technology facilitates the discover of security vulnerabilities to understand the data security posture, detect, and remediate the security vulnerabilities, and to prevent future breaches to sensitive data.
Regarding claim 2:
further comprising: detecting the cybersecurity risk based on the cybersecurity object (Ithal, ¶22).
Regarding claim 3:
further comprising: determining a severity of the cybersecurity risk based on the detected sensitive data (Ithal, ¶156).
Regarding claim 4:
further comprising: initiating the mitigation action on the resource of the original disk (Ithal, ¶99).
Regarding claim 5:
further comprising: generating in a security database: a representation of the resource, a representation of the data schema, and a representation of each data file; connecting the representation of the resource with the representation of the data schema in response to detecting the plurality of data files in the cloned disk; and rendering a visual representation of the cloud computing environment including a representation of the data schema (Ithal, ¶16).
Regarding claim 6:
further comprising: releasing the cloned disk in response to determining that inspection is complete (Ithal, ¶50).
Regarding claim 7:
further comprising: generating the classification further based on any one of: metadata of a data file, the data schema, a content of a data file, and a combination thereof (Ithal, ¶22).
Regarding claim 8:
further comprising: extracting from a first data file of the plurality of data files a file header, and a plurality of data blocks (Ithal, ¶177).
Regarding claim 9:
wherein the first data file is a file associated with a distributed database (Ithal, abstract).
Regarding claim 10:
further comprising: classifying sensitive data further as any one of: personal identifiable information (PII), personal health information (PHI), payment card industry (PCI), and any combination thereof (Ithal, ¶136).
Regarding claim 11:
A non-transitory computer-readable medium storing a set of instructions for agentless detection of sensitive data in a cloud computing environment, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to (Ithal, ¶31):
generate a cloned disk directly from an original disk of a resource deployed in a cloud computing environment (Ithal, abstract), wherein, The method includes identifying a snapshot of the database, wherein the snapshot includes a second authentication requirement that is different than the first authentication requirement. The method includes accessing the snapshot using the second authentication requirement, generating a representation of the database using the snapshot, and generating a data posture analysis result indicative of a data posture of the database based on scanning the representation of the database.
inspect the cloned disk for a cybersecurity object, the cybersecurity object indicating a sensitive data (Ithal, ¶99), wherein T The system can discover sensitive data among the cloud storage resources and discover access patterns to the sensitive data. The results can be used to identify security vulnerabilities to understand the data security posture, detect and remediate the security vulnerabilities, and to prevent future breaches to sensitive data. The system provides real-time visibility and control on the control data infrastructure by discovering resources, sensitive data, and access paths, and tracking resource configuration, deep context and trust relationships in real-time as a graph or other visualization.
detect the cybersecurity object, wherein the cybersecurity object further includes a data schema (Ithal, ¶128, ¶136), wherein btained by metadata ingestion component 216, sensitive data profiles 254, detected data schema records 255, and can store other items 256 as well. Examples of sensitive data profiles 254 are discussed in further detail below. Briefly, however, sensitive data profiles 254 can identify target data patterns that are to be categorized as sensitive or conforming to a predefined pattern of interest. Sensitive data profiles 254 can be used as training data for data classification performed by data schema detection component 229. Examples of data classification are discussed in further detail below. For instance, however, pattern matching can be performed based on the target data profiles.
generate a classification of the data schema (Ithal, ¶22), wherein, wherein generating the data posture analysis result comprises: [0023] obtaining metadata representing a structure of schema objects in the database; and [0024] based on the metadata, executing a content-based data classifier to classify data items in the schema objects.
detect in the cloned disk a plurality of data files, each data file generated based on the data schema (Ithal, ¶200), wherein Data store accessing component 902 is configured to access data stores to be analyzed. Context-based classifier 904 includes a schema detector 920, a metadata generator 922, and can include other items 924 as well. Schema detector 920 is configured to detect a schema used by the data store, and includes a schema parsing component 926, which includes a schema object detector 928. For sake of illustration, but not by limitation, in an example structured database.
determine that the data schema corresponds to sensitive data based on the generated classification (Ithal, ¶180), wherein the first subset of storage resources identified at block 572, are based on determining that the storage resources satisfy a risk signature of containing private and/or sensitive content.
determine that the original disk includes a cybersecurity risk (Ithal, ¶103), wherein a cloud security posture analysis system 122 configured to access cloud services 108 to identify and analyze cloud security posture data. Examples of system 122 are discussed in further detail below. Briefly, however, system 122 is configured to access cloud services 108 and identify connected resources, entities, actors, etc. within those cloud services, and to identify risks and violations against access to sensitive information.
and initiate a mitigation action for each data file based on the cybersecurity risk(Ithal, ¶241, ¶219), perform remedial actions, etc. At block 1088, security issue detection can be performed to detect security issues based on the scan results. In one example, security issue prioritization is performed at block 1090. Examples of security issue detection and prioritization are discussed above. Remedial actions are illustrated at block 1092. Of course, other actions can be performed at block 1094 and discover sensitive data among the cloud storage resources and as well as access patterns to the sensitive data, using local scanners that reduce or eliminate need to send the cloud data outside the cloud environment. This improves data security. Further, the technology facilitates the discover of security vulnerabilities to understand the data security posture, detect, and remediate the security vulnerabilities, and to prevent future breaches to sensitive data.
Regarding claim 12:
a processing circuitry; a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: (Ithal, ¶243, ¶259).
generate a cloned disk directly from an original disk of a resource deployed in a cloud computing environment (Ithal, abstract), wherein, The method includes identifying a snapshot of the database, wherein the snapshot includes a second authentication requirement that is different than the first authentication requirement. The method includes accessing the snapshot using the second authentication requirement, generating a representation of the database using the snapshot, and generating a data posture analysis result indicative of a data posture of the database based on scanning the representation of the database.
inspect the cloned disk for a cybersecurity object, the cybersecurity object indicating a sensitive data (Ithal, ¶99), wherein The system can discover sensitive data among the cloud storage resources and discover access patterns to the sensitive data. The results can be used to identify security vulnerabilities to understand the data security posture, detect and remediate the security vulnerabilities, and to prevent future breaches to sensitive data. The system provides real-time visibility and control on the control data infrastructure by discovering resources, sensitive data, and access paths, and tracking resource configuration, deep context and trust relationships in real-time as a graph or other visualization.
detect the cybersecurity object, wherein the cybersecurity object further includes a data schema (Ithal, ¶128, ¶136), wherein btained by metadata ingestion component 216, sensitive data profiles 254, detected data schema records 255, and can store other items 256 as well. Examples of sensitive data profiles 254 are discussed in further detail below. Briefly, however, sensitive data profiles 254 can identify target data patterns that are to be categorized as sensitive or conforming to a predefined pattern of interest. Sensitive data profiles 254 can be used as training data for data classification performed by data schema detection component 229. Examples of data classification are discussed in further detail below. For instance, however, pattern matching can be performed based on the target data profiles.
generate a classification of the data schema (Ithal, ¶22), wherein, wherein generating the data posture analysis result comprises: [0023] obtaining metadata representing a structure of schema objects in the database; and [0024] based on the metadata, executing a content-based data classifier to classify data items in the schema objects.
detect in the cloned disk a plurality of data files, each data file generated based on the data schema (Ithal, ¶200), wherein Data store accessing component 902 is configured to access data stores to be analyzed. Context-based classifier 904 includes a schema detector 920, a metadata generator 922, and can include other items 924 as well. Schema detector 920 is configured to detect a schema used by the data store, and includes a schema parsing component 926, which includes a schema object detector 928. For sake of illustration, but not by limitation, in an example structured database.
determine that the data schema corresponds to sensitive data based on the generated classification (Ithal, ¶180), wherein the first subset of storage resources identified at block 572, are based on determining that the storage resources satisfy a risk signature of containing private and/or sensitive content.
determine that the original disk includes a cybersecurity risk (Ithal, ¶103), wherein a cloud security posture analysis system 122 configured to access cloud services 108 to identify and analyze cloud security posture data. Examples of system 122 are discussed in further detail below. Briefly, however, system 122 is configured to access cloud services 108 and identify connected resources, entities, actors, etc. within those cloud services, and to identify risks and violations against access to sensitive information.
and initiate a mitigation action for each data file based on the cybersecurity risk(Ithal, ¶241, ¶219), perform remedial actions, etc. At block 1088, security issue detection can be performed to detect security issues based on the scan results. In one example, security issue prioritization is performed at block 1090. Examples of security issue detection and prioritization are discussed above. Remedial actions are illustrated at block 1092. Of course, other actions can be performed at block 1094 and discover sensitive data among the cloud storage resources and as well as access patterns to the sensitive data, using local scanners that reduce or eliminate need to send the cloud data outside the cloud environment. This improves data security. Further, the technology facilitates the discover of security vulnerabilities to understand the data security posture, detect, and remediate the security vulnerabilities, and to prevent future breaches to sensitive data.
Regarding claim 13:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: detect the cybersecurity risk based on the cybersecurity object (Ithal, ¶22).
Regarding claim 14:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: determine a severity of the cybersecurity risk based on the detected sensitive data (Ithal, ¶156).
Regarding claim 15:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: initiate the mitigation action on the resource of the original disk (Ithal, ¶99).
Regarding claim 16:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: generate in a security database: a representation of the resource, a representation of the data schema, and a representation of each data file; connect the representation of the resource with the representation of the data schema in response to detecting the plurality of data files in the cloned disk; and render a visual representation of the cloud computing environment including a representation of the data schema (Ithal, ¶16).
Regarding claim 17:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: release the cloned disk in response to determining that inspection is complete (Ithal, ¶50).
Regarding claim 18:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: generate the classification further based on any one of: metadata of a data file, the data schema, a content of a data file, and a combination thereof (Ithal, ¶22).
Regarding claim 19:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: extract from a first data file of the plurality of data files a file header, and a plurality of data blocks (Ithal, ¶177).
Regarding claim 20:
wherein the first data file is a file associated with a distributed database (Ithal, abstract).
Regarding claim 21:
wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to: classify sensitive data further as any one of: personal identifiable information (PII), personal health information (PHI), payment card industry (PCI), and any combination thereof (Ithal, ¶136).
Conclusion
9. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Monjour Rahim whose telephone number is (571)270-3890.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (in USA or CANANDA) or 571-272-1000.
/Monjur Rahim/
Patent Examiner
United States Patent and Trademark Office
Art Unit: 2436; Phone: 571.270.3890
E-mail: monjur.rahim@uspto.gov
Fax: 571.270.4890