19075DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to communication/amendment filed on 07/01/2026.
Status of claims in the instant application:
Claims 1-20 are pending.
No claim has been canceled.
No new claim has been added.
Claims 1, 4, 8, 9, 16 and 17 have been amended.
Response to Arguments
Applicant’s arguments, see page [6-8] of the remarks filed on 07/01/2026 with respect to rejections of claims under 35 USC 101, have been fully considered in view of claim amendments and are persuasive. Therefore, the claim rejections have been withdrawn.
Applicant’s arguments, see page [6] of the remarks filed on 07/01/2026 with respect to rejections of claims under non-statutory double patenting, have been fully considered and are persuasive. Therefore, the claim rejections have been withdrawn.
Applicant has filed a terminal disclaimer and it has been approved.
Applicant’s arguments, see page [9-11] of the remarks filed on 07/01/2026 with respect to rejections of claims under 35 USC 103, have been considered in view of claim amendments, but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Furthermore, Applicants claim amendments have rendered new grounds for rejections.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 5, 6, 7, 9, 10, 13, 14, 15, 17 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20180026993 A1 to Parla et al. (hereinafter “Parla”) in view of Pub. No.: US 20200167500 A1 to Malladi et al. (hereinafter “Malladi”), and further in view of Pub. No.: US 20220224711 A1 to SINGH et al. (hereinafter “SINGH”).
Regarding Claim 1. Parla discloses A device (Parla, FIG. 4, Para [0016]: … The comparator 140 may be a network-connected device (with storage and processing capabilities) configured as a comparator to receive and process IP traffic flow reports from the endpoint device 110 and similar reports from one or more network devices 120(1) and 120(2) …) comprising:
a memory that stores instructions (Parla, FIG. 4, Para [0023]: … Processor 405 executes instructions stored in memory 410 …); and
one or more processors configured by the instructions to perform operations (Parla, FIG. 4, Para [0023]: … Processor 405 executes instructions stored in memory 410 … memory 410 may include one or more tangible (non-transitory) computer readable storage media (e.g., a memory device) encoded with software comprising computer executable instructions and, when the software is executed (by processor 405), it is operable to perform the operations …) comprising:
receiving, from a first application, first log entries (Parla, FIG. 1, Para [0019]: … Generally, endpoint device 110 transmits requests to one or more network devices 120(1) or 120(2) for data and/or services from one or more servers 150(1)-150(3), which route the network traffic flows to the one or more servers 150(1)-150(3). According to an embodiment, endpoint device 110 generates and transmits network traffic flows in response to requests from one or more applications resident on endpoint device 110. Endpoint device 110 stores the transmitted network traffic flows and may send reports about the stored network traffic flows to comparator 140 …);
receiving, from a second application, second log entries that originated from the first application (Parla, FIG. 1, Para [0019]: … Each of the one or more network devices 120(1) and 120(2) that route the network traffic flows originating at endpoint device 110 may also store network traffic flows received from endpoint device 110 and send reports about the network traffic flows to comparator 140 …);
[receiving, from the second application, third log entries that originated from the second application]; and
in response to a discrepancy between the first log entries and the second log entries, generating an alert (Parla, FIG. 1, Para [0019]: … Comparator 140 may correlate the reports summarizing (in metadata) network traffic flows originating from endpoint device 110 and stored at endpoint device 110 with the reports summarizing network traffic flows stored at the one or more network devices 120 and compare the correlated reports summarizing the network traffic flows to determine whether they are identical. If comparator 140 determines that the reported network traffic flows stored at the one or more network devices 120 are not identical to the reported network traffic flows stored at endpoint device 110, the comparator 140 may log the network traffic flows as being suspicious and forward the reports summarizing the network traffic flows logged as suspicious to analyzer 160 for further processing to determine whether unauthorized software is resident on endpoint device 110 …).
However, Parla does not explicitly teach, but Malladi from same or similar field of endeavor teaches:
“receiving, from a second application (Malladi, Para [0041-0047]: … When the data access performed by one or more entities associated with Action 3, above, is detected by the management server 265 as pertaining to private data, the management server 265 can generate an event and provide it to the verification server 303 using queue service (Actions 4 and 5). The event information provided from the queue to the verification server 303 (Action 5) can be temporarily stored in a buffer element that is illustrated in FIG. 3 as event log data 310. The event log data 310 can include for example, one or more items such as: a listing of one or more private applications … The event log data 310 can separately be stored in a database 315 that is part of, or accessible to, the verification server 303. The event log data 310 can be stored in its original form or it can be stored as a hashed value (the same hashed value provided to the blockchain application 320). … The auditor module 325 can carry out an audit operation (Action 12) in order to verify the integrity of the data stored in the blockchain application 320 and the database 315 …; Note: the block chain application is interpreted as the second application) and;
generating an alert (Malladi, Para [0047]: … If the auditor module 325 determines that the hashes do not match, and that the data in the database 315 has therefore been tampered with, the verification server 303 can take various actions. In one example, an alert message is sent out to personnel such as the administrator 330 or a supervisor of the administrator 330 …)”
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Malladi into the teachings of Parla, because it discloses that, “The alerted personnel can then use the data stored in the blockchain application 320 to carry out an investigation. The investigation can be directed at determining one or more details pertaining to the tampered event. For example, the investigation can be directed at identifying the person who carried out the tampering, the time at which the tampering occurred, and the content that was modified or deleted. Some or all of the results of the investigation can be conveyed to at least one of: the user 305, the administrator 330 (when the administrator 330 is not the perpetrator of the tampering), and a supervisor of the administrator 330 (when the administrator 330 is the perpetrator of the tampering) … (Malladi, Para [0047])”.
However, the combination of Parla-Malladi does not explicitly teach, but Malladi from same or similar field of endeavor teaches:
“receiving, from the second application, third log entries that originated from the second application (US 20220224711 A1 - SINGH; MANJIT GOMBRA et al., Abstract, Para [0005, 0010, 0015, 0020]: … Methods for observing and/or monitoring a computer network that may include a plurality of nodes may be performed by, for example, a computer monitoring and/or observing system that detects a data flow between two or more nodes of the computer network. The data flow may be associated with a user of the computer network. Exemplary users include, but are not limited to, individuals, groups of users, businesses, governmental entities, enterprises, software applications, and Web crawlers … In some embodiments, a software application transaction log for the computer network may be recorded and/or received … a software application transaction log may be received from, for example, a software application (e.g., a data tracing program) running on, within, and/or outside the computer network. A data source transaction log may be received from a data source communicatively coupled to the computer network and the software application transaction log and the data source transaction log may be compared with one another to, for example, identify differences therebetween such as a data source transaction that does not have a corresponding software application transaction log entry, and/or a software application transaction log entry that does not have a corresponding data source transaction log entry … observing and/or monitoring a computer network including a plurality of nodes may include receiving a set (e.g., 2-10,000) of software application transaction logs directly and/or indirectly from, for example, one or more software applications running on and/or within the computer network. In some cases, each software transaction log may be received from a separate software application. In other cases, multiple software transaction logs may be received from a single software application. In addition, a set of data source transaction logs may be received directly and/or indirectly from one or more data source(s) associated with the computer network. In some cases, each data source transaction log may be received from a separate data source application. In other cases, multiple data source transaction logs may be received from a data source …)”.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of SINGH into the combined teachings of Parla-Malladi, because it discloses that, “The set of software application transaction logs and the set of data source transaction logs may be compared with one another to determine differences therebetween. Any data source transaction log entry that does not have a corresponding software application transaction log entry and/or any software application transaction log entry that does not have a corresponding data source transaction log entry may be flagged or otherwise associated with an alert condition. An indication of a flagged data source transaction log entry, software transaction log entry, and/or alert condition may then be communicated to an operator via, for example, a message and/or an icon displayed on a GUI or map of nodes included in the computer network (SINGH, Para [0021])”.
Regarding Claim 2. The combination of Parla-Malladi-SINGH discloses the device of claim 1, Malladi further discloses, “wherein the operations further comprise:
detecting an unauthorized modification to the first log entries by comparing cryptographic hashes of the first log entries with cryptographic hashes of the second log entries (Malladi, Para [0045-0047]: … The auditor module 325 can carry out an audit operation (Action 12) in order to verify the integrity of the data stored in the blockchain application 320 and the database 315. For example, the auditor module 325 can hash the event log data 310 stored in the database 315 and compare the resulting hash to the hash stored in the blockchain application 320 that corresponds to the appropriate entity ID. If the data stored in the database 315 is the same as the original event data log 310 that was stored in the blockchain application 320, the two hashed values should provide an exact match. If, on the other hand, the data stored in the database 315 has been altered in any way, the hashes will not match … If the auditor module 325 determines that the hashes do not match, and that the data in the database 315 has therefore been tampered with, the verification server 303 can take various actions …).”
The motivation to further combine Malladi remains same as in claim 1.
Regarding Claim 5. The combination of Parla-Malladi-SINGH discloses the device of claim 1, Parla further discloses, “wherein the alert comprises information about the first application (Parla, Para [0018-0019, 0030]: … If comparator 140 determines that the correlated network traffic flows are not identical, it may log the network traffic flows as suspicious and forward the reports summarizing the correlated network traffic flows to analyzer 160 for further processing to determine whether endpoint device 110 is compromised with malicious software. According to an embodiment, the malicious software may include a rootkit that has been hooked out into one or more authorized applications resident on endpoint device 110 …).”
Regarding Claim 6. The combination of Parla-Malladi-SINGH discloses the device of claim 1, Malladi further discloses, “wherein the operations further comprise:
selecting the second application from a set of available applications (Malladi, Para [0013]: … With reference first to FIG. 1, there is depicted a block diagram of a network environment 100 in which a differential analysis of network traffic flows is employed to detect malware on a host endpoint device. Network access environment 100 includes a host endpoint device 110, one or more network devices, e.g., network devices 120(1) and 120(2), which are in communication over network 130 with a comparator device 140, one or more server/controllers, e.g., servers 150(1)-150(3), and an analyzer device 160. Endpoint host device 110 may be any wired or wireless communication device configured to generate and transmit data/packet flows to the one or more servers requesting data and/or services from the one or more servers, wherein the generated network traffic flows through at least one network device 120(1) or 120(2) …); and
prior to receiving the second log entries from the second application, providing an identifier of the second application to the first application (Malladi, Para [0016]: … According to a further embodiment, the set of attributes identifying a specific data flow may be indicated in an IP flow information export (“IPFIX”) data packet reported by endpoint device 110 and/or a network device 120(1) or 120(2). The comparator 140 may be a network-connected device (with storage and processing capabilities) configured as a comparator to receive and process IP traffic flow reports from the endpoint device 110 and similar reports from one or more network devices 120(1) and 120(2) …).”
The motivation to further combine Malladi remains same as in claim 1.
Regarding Claim 7. The combination of Parla-Malladi-SINGH discloses the device of claim 6, Parla further discloses, “wherein the set of available applications excludes applications associated with customers other than a customer associated with the first application (Parla, Para [0014]: … Network 130 may include one or more wide area networks (WANs), such as the Internet, and one or more local area networks (LANs). The one or more network devices, e.g., 120(1) and 120(2), are configured to route one or more network traffic flows requesting data and/or services transmitted from endpoint device 110 over network 130 to the one or more servers 150(1)-150(3) …); *** Note: As described in Parla here and shown in FIG. 1, network devices, e.g., 120(1) and/or 120(2) stores data from only the Endpoint Host Device 101, and are not in communication with any other data/log/report source(s). network devices 120(1) and/or 120(2) are interpreted to host second application that forwards data originated from application in Endpoint Host Device 101.”
Regarding Claim 9. This claim contains all the same or similar limitations as claim 1, and hence similarly rejected as claim 1.
Regarding Claim 10. This claim contains all the same or similar limitations as claim 2, and hence similarly rejected as claim 2.
Regarding Claim 13. This claim contains all the same or similar limitations as claim 5, and hence similarly rejected as claim 5.
Regarding Claim 14. This claim contains all the same or similar limitations as claim 6, and hence similarly rejected as claim 6.
Regarding Claim 15. This claim contains all the same or similar limitations as claim 7, and hence similarly rejected as claim 7.
Regarding Claim 17. This claim contains all the same or similar limitations as claim 1, and hence similarly rejected as claim 1.
*** Note: Parla also discloses “A non-transitory computer-readable medium that stores instructions that, when executed by one or more processors of a device (Parla: Para [0024])”
Regarding Claim 18. This claim contains all the same or similar limitations as claim 2, and hence similarly rejected as claim 2.
Claims 3, 11 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20180026993 A1 to Parla et al. (hereinafter “Parla”) in view of Pub. No.: US 20200167500 A1 to Malladi et al. (hereinafter “Malladi”) and Pub. No.: US 20220224711 A1 to SINGH et al. (hereinafter “SINGH”), as applied to claim 1 above, and further in view of Pat. No.: US 10075425 B1 to Waugh et al. (hereinafter “Waugh”).
Regarding Claim 3. The combination of Parla-Malladi-SINGH discloses the device of claim 1, However, it does not explicitly teach, but Waugh from same or similar field of endeavor teaches:
“wherein the operations further comprise:
decrypting the first log entries using a private key of a public/private key pair (Waugh, col.15,ln.4-12;col.20.ln.3-47: … The first log entry 1102 includes a first log data 1110. The second log entry 1104 includes a second log data 1112. The third log entry 1106 includes a third log data 1114. The next log entry 1108 includes a next log data 1116 … data objects such as log entries with associated hash values may be cryptographically verifiable. In one example, cryptographically verifiable data objects are created to be cryptographically verifiable by the system to which the data object is to be provided or another system that operates in conjunction with the system to which the data object is to be provided. For example, the data object may be encrypted so as to be decryptable by the system that will cryptographically verify the data object, where the ability to decrypt the data object serves as cryptographic verification of the data object … The key used to encrypt and/or digitally sign the data object may vary in accordance with various embodiments and the same key is not necessarily used for both encryption and digital signing, where applicable. In some embodiments, a key used to encrypt the data object is a public key of a public/private key pair where the private key of the key pair is maintained securely by the system to which the data object is to be provided, thereby enabling the system to decrypt the data object using the private key of the key pair …); and
decrypting the second log entries using the private key (Waugh, col.20.ln.3-47; col.15,ln.4-12: … a key used to encrypt the data object is a public key of a public/private key pair where the private key of the key pair is maintained securely by the system to which the data object is to be provided, thereby enabling the system to decrypt the data object using the private key of the key pair …)”.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Waugh into the combined teachings of Parla-Malladi-SINGH, because it discloses that, “The client computer system 1002 verifies a batch of log entries by retrieving the log entries from the logging service, recalculating the hash value based at least in part on the received log entries, and comparing the recalculated hash value to the stored hash value in the audit history database 1020. If a commutative function is used to combine the hash values of the individual log entry records at the logging-service load balancer 1006, the corresponding log entry hash values may be combined in any order by the logging-service load balancer 1006, potentially improving performance of the logging system (Waugh, col.14, ln.43-53)”.
Regarding Claim 11. This claim contains all the same or similar limitations as claim 3, and hence similarly rejected as claim 3.
Regarding Claim 19. This claim contains all the same or similar limitations as claim 3, and hence similarly rejected as claim 3.
Claims 4, 12 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20180026993 A1 to Parla et al. (hereinafter “Parla”) in view of Pub. No.: US 20200167500 A1 to Malladi et al. (hereinafter “Malladi”) and Pub. No.: US 20220224711 A1 to SINGH et al. (hereinafter “SINGH”), as applied to claim 1 above, and further in view of Pub. No.: US 20170091463 A1 to Lindteigen et al. (hereinafter “Lindteigen”) and Pub. No.: US 12192183 B1 to Kerr et al. (hereinafter “Kerr”).
Regarding Claim 4. The combination of Parla-Malladi-SINGH discloses the device of claim 1, however it does not explicitly teach, but Kerr from same or similar field of endeavor teaches, “wherein:
the first application has access to a symmetric key (Kerr, col.13, ln.3-25: … At block 150, the client device application operating on wireless client device 122 transmits the local authentication credentials and the illustrative one-time password to the remote network component 126 along a broadband communication channel that may include a cellular network. The broadband communication channel between the client device 122 and remote network component 126 may be authenticated or initialized through an initial transmission of a client device identifier (i.e., factory identifier, media access control (MAC) address, etc.) from the client device to the remote network component 126. Additionally, the wireless client device 122 requests key material comprising an exclusive local key from the remote network component 126 at block 152 along the broadband communication channel. Each exclusive local key is specific to a particular wireless client device 122. In some embodiments, the exclusive local key may be a hash, an initialization vector, a symmetric key, or public cryptographic material. In the illustrative embodiment, the exclusive local key is a token that can include a cryptoperiod and standard 128 bit or 256 bit encryption. In other embodiments, the token may simply comprise an autogenerated random number …);
the second application does not have access to the symmetric key (Kerr, col.3, ln.44-52): … The client device application, having the exclusive local key, requests a cryptographic material from the remote network component, and the client device application receives the cryptographic material from the remote network component. The client device application encrypts and decrypts communications to the remote network component with a shared secret that includes the exclusive local key received from the gateway component and the cryptographic material received from the network component …); and
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kerr into the teachings of Parla-Malladi-SINGH, because it discloses that, “The client device application, having the exclusive local key, requests and receives cryptographic material from the remote network component. The client device application secures communications to the remote network component … (Kerr: Abstract)”.
However, the combination of Parla-Malladi-SINGH-Kerr does not explicitly teach, but Lindteigen from same or similar field of endeavor teaches:
“the operations further comprise:
decrypting the first log entries using the symmetric key (Lindteigen , Para [0018-0020]: … The secure audit manager 2300 is further enabled to upload the encrypted audit log 2200 to a secure audit server 2500. The secure audit server 2500 is enabled to receive the encrypted audit log 2400 from the secure audit manager 2300. Finally a secure audit log consumer 2600 is enabled to request the audit log 2200 from the secure audit log manager 2300 to review the secure audit log 2200 … The secure audit client 2100, secure audit manager 2300, secure audit server 2500, and secure audit consumer 2600 may include internal hardware such as a processor, memory, and communication features. The secure audit client 2100, secure audit manager 2300, secure audit server 2500, and secure audit consumer 2600 may include software applications enabled to encrypt and decrypt data before sending the data through the network. The data encryption may be accomplished using any data encryption method such as Advanced Encryption Standard (“AES”) …; Note: AES is a symmetric encryption algorithm …); and
decrypting the second log entries using the symmetric key (Lindteigen , Para [0018-0020]: … The secure audit manager 2300 is further enabled to upload the encrypted audit log 2200 to a secure audit server 2500. The secure audit server 2500 is enabled to receive the encrypted audit log 2400 from the secure audit manager 2300. Finally a secure audit log consumer 2600 is enabled to request the audit log 2200 from the secure audit log manager 2300 to review the secure audit log 2200 … The secure audit client 2100, secure audit manager 2300, secure audit server 2500, and secure audit consumer 2600 may include internal hardware such as a processor, memory, and communication features. The secure audit client 2100, secure audit manager 2300, secure audit server 2500, and secure audit consumer 2600 may include software applications enabled to encrypt and decrypt data before sending the data through the network. The data encryption may be accomplished using any data encryption method such as Advanced Encryption Standard (“AES”) …; Note: AES is a symmetric encryption algorithm …)”.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Lindteigen into the teachings of Parla-Malladi-SINGH-Kerr, because it discloses that, “the second device decrypts the encrypted audit log with a compatible encryption key to produce the audit log (see step 1500). The second device then uses the secured audit log to perform a forensic root cause analysis. For example, the encryption of the audit log is performed such that the chain of title for the audit log is sufficient to withstand the scrutiny of a legal proceeding (Lindteigen, Para [0014])”.
Regarding Claim 12. This claim contains all the same or similar limitations as claim 4, and hence similarly rejected as claim 4.
Regarding Claim 20. This claim contains all the same or similar limitations as claim 4, and hence similarly rejected as claim 4.
Claims 8 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Pub. No.: US 20180026993 A1 to Parla et al. (hereinafter “Parla”) in view of Pub. No.: US 20200167500 A1 to Malladi et al. (hereinafter “Malladi”) and Pub. No.: US 20220224711 A1 to SINGH et al. (hereinafter “SINGH”), as applied to claim 1 above, and further in view of Pub. No.: US 20210374021 A1 to Santhakumar et al. (hereinafter “Santhakumar”).
Regarding Claim 8. The combination of Parla-Malladi-SINGH discloses the device of claim 1, however it does not explicitly teach, but Santhakumar from same or similar field of endeavor teaches “wherein the operations further comprise:
providing, to the first application, an identifier of a third application to which log entries should be provided if an audit-log service is unavailable (Santhakumar, Para [0012, 0030, 0063], FIIG. 1C: … the storage manager can determine the health of an alternate media agent based on the number of pending, failed, and/or long-running jobs. If an alternate media agent is healthy and available to take over for a soon-to-be-disabled media agent, the storage manager can maintain the states of media agents that have a new state equal to a current state and can change the states of media agents that have a new state not equal to a current state to the corresponding new state … Another aspect of the disclosure provides a networked information management system comprising a first secondary storage computing device. The networked information management system further comprises one or more computing devices in communication with the secondary storage computing device, where the one or more computing devices are configured with computer-executable instructions that, when executed, cause the one or more computing devices to: determine that the first secondary storage computing device has computing resources allocated to a current job; identify a new state for the first secondary storage computing device based at least in part on the current job, where the new state is a disabled state; determine that at least one alternate secondary storage computing device associated with the first secondary storage computing device is healthy; and disable the first secondary storage computing device …); and
receiving, from the third application, fourth log entries that originated from the first application (Santhakumar, Para [0281], FIG. 1C-D: … The target media agent 144A receives the data-agent-processed data from client computing device 102, and at step 4 generates and conveys backup copy 116A to disk library 108A to be stored as backup copy 116A, again at the direction of storage manager 140 and according to backup copy rule set 160 …).”
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Santhakumar into the teachings of Parla-Malladi-SINGH, because it discloses that, “By routing future jobs to an alternate component (e.g., an alternate media agent), the information management system performance may not be degraded by a poorly performing component. Rather, the job success rate of the information management system may be increased and/or the job failure rate of the information management system may decrease (Santhakumar, Para [0013])”.
*** Note: SINGH also discloses multiple logs for multiple applications – thus the combination making the third, fourth, … logs obvious.
Regarding Claim 16. This claim contains all the same or similar limitations as claim 8, and hence similarly rejected as claim 8.
Pertinent Prior Arts
The following prior arts made of record and not relied upon are considered pertinent to applicant's disclosure.
US10015015; Lazar, Gregory W.: Lazar discloses techniques for verifying the integrity of an encryption key log file generated on a data storage system. Encryption key activity events associated with a storage system's back-end storage drives are identified. A unique signature is generated for each encryption key activity event. Each encryption key activity event and its corresponding signature are stored in an audit log file. An audit log hash file is generated using the contents of the audit log file. At an external location, the audit log file and the audit log hash file are retrieved from the storage system. The integrity of the retrieved audit log file is verified by generating a local audit log hash file and comparing the local audit log hash file to the retrieved audit log hash file and determining if the local audit log hash file matches the retrieved audit log hash file.
US 20180322312 A1; Olrog; Christian: Olrog discloses mechanisms for verifying a log entry in a communications system. A method is performed by a host server. The method comprises obtaining a log entry of a service access tracker. The log entry indicates access to a service during a client session, the service being tracked by the service 5 access tracker. The method comprises providing the log entry to a trusted third party for digital signing thereof using a digital trusted timestamping scheme. The method comprises verifying that the log entry has been digitally signed by the trusted third party. The method comprises providing a new aggregate comprising the digitally signed log entry and a previous aggregate 10 of previously digitally signed and aggregated log entries to the trusted third party for digital signing thereof using the digital trusted timestamping scheme. The method comprises verifying that the new aggregate has been digitally signed by the trusted third party.
US 20190347339 A1; Becker et al.: Becker discloses Systems and methods for monitoring and logging all activity occurring in a system. The logged activity may include keystroke entries input into the system, user and/or application interactions with the system, access restriction conflicts, and the like. The logged activity may be stored in at least two datastores, at least one of which is an immutable, append-only datastore. Storage of the logged activity in the immutable, append-only datastore is performed using hash algorithms. Attempts at manipulating or at hiding malicious or unauthorized activity can be recognized due to all activity being captured in the immutable, append-only datastore.
US 20230137235 A1; CHEN; Hsiulan: CHEN discloses Methods, computer program products, and systems where the methods include, for instance: A plurality of log messages generated while an application processes two or more workloads are collected. The application is microservice-based and each of the microservices generates respective log messages. A time domain analysis is performed to lay out respective iteration counts of the microservices of the application. Keyword patterns in the log messages are compiled and stored in a keywords database. A frequency domain analysis on the keyword patterns for respective numbers of appearances in the log messages and stored in a frequency domain analysis database. Logs generated from a new workload are automatically monitored for abnormality by comparing the logs by the new workload to the statistical pattern of keywords as established by previous workloads. For a deviation greater than a threshold, an alert is generated with issue location and delivered to preselected recipients.
US 20120054841A1; Paul T. Schultz: Schultz discloses A system that includes a memory to store registration information for a particular application hosted by a particular user device, where the registration information includes context information regarding the particular user device and an integrity code based on credentials associated with the particular application. The system also includes a first server to receive, from a second server, a request to receive a service on behalf of a user device that hosts an application, the request including other credentials associated with the application; generate, using a data integrity algorithm, another integrity code based on the other credentials; determine that the application is trusted when the integrity code matches the other integrity code; compare other context information associated with the user device with the context information when the application is trusted; and send an instruction to the user device to re-register the application when the context information does not match the other context information.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHABUB S AHMED whose telephone number is (571)272-0364. The examiner can normally be reached on 9AM-5PM EST M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached on 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MAHABUB S AHMED/Examiner, Art Unit 2434
/TESHOME HAILU/Primary Examiner, Art Unit 2434