DETAILED ACTION
In response to the communication filed on 03/13/2025, responded in following.
On this Office Action, claims 1-11, consisting of independent claims 1, 10 and 11.
Claims 1-11 are pending.
Claims 1-11 are rejected under the 35 USC § 101.
Claims 1-9 are rejected under 35 U.S.C. 112.
Claims 1-11 are rejected under the 35 USC § 103.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/13/2025 and 07/15/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
The drawings were received on 03/13/2025. These drawings are accepted.
Priority
Acknowledgment is made of applicant’s claim for foreign priority under 35 U.S.C. 119 (a)-(d). The certified copy has been filed in parent Application No. JP2024-046765, filed on 03/22/2022.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: a log collecting unit, an unauthorized-access detecting unit, a function-to-be-restricted specifying unit and a function restricting unit in claim 1; a tampering-detection unit in claim 4.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-9 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the applicant regards as the invention.
Claim limitation, a log collecting unit, an unauthorized-access detecting unit, a function-to-be-restricted specifying unit and a function restricting unit in claim 1; and a tampering-detection unit in claim 4, has been evaluated under the three-prong test set forth in MPEP § 2181, subsection I, but the result is inconclusive. Thus, it is unclear whether this limitation should be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The boundaries of this claim limitation are ambiguous; therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. The dependent claims inherit the deficiencies of the independent claims upon which they are based and thus rejected as well.
For example, claim limitation “a log collecting unit, an unauthorized-access detecting unit, a function-to-be-restricted specifying unit and a function restricting unit in claim 1; and a tampering-detection unit in claim 4” invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function.
Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph.
Applicant may:
(a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph;
(b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or
(c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)).
If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either:
(a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or
(b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-9 are rejected under 35 USC § 101 because claim 1 is directed to an apparatus comprising software only. For example, claim 1 recites several units, but, after review of the specification, there is no section that defines any of them as hardware. Therefore the claim is directed to software per se. The examiner suggests including a hardware component such as a memory or a hardware processor in the claim to overcome this rejection. The dependent claims inherit the deficiencies of the claim upon which they ultimately depend and are rejected as well.
Claims 10 and 11 are rejected under 35 U.S.C. 101 because the claimed invention is directed to judicial exception (an abstract idea) without significantly more. The following is Examiner’s analysis of the claimed invention under the 2019 Revised Patent Subject Matter Eligibility Guidance (PEG).
2019 Revised Patent Eligibility Guidance (hereinafter “2019 PEG”): Step 1: Is the claim to a Process, Machine, Manufacture or Composition of matter?
Independent claims 10-11 are directed to a method and a non-transitory computer-readable medium with computer executable instructions by a computing device. Accordingly, they fall within at least one of the four statutory categories of 35 U.S.C. § 101.
2019 PEG: Step 2A - Prong One: Does the Claim Recite an Abstract Idea, Law of Nature, or Natural Phenomenon?
Under Prong One of Step 2A, the claim limitations are evaluated to determine whether “recite” a judicial exception.
Independent claims 10 and 11 recite, for example:
Collecting information to detect unauthorized access.
Making a decision regarding which function should be restricted.
Taking action based on the determination.
These limitations, under their broadest reasonable interpretation, constitute steps of:
Collecting information.
Analyzing the information.
Making a security decision based on the information.
Such steps amount to collecting, analyzing information, including making a determination based on the analyzed information, which can be practically performed in the human mind or with pen and paper. Accordingly, the claim recites a mental process, which is one of enumerated groupings of abstract ideas under the 2019 PEG.
Thus, the claims recites an abstract idea under Step 2A, Prong One.
2019 PEG: Step 2A - Prong Two: Does the Claim Recite Additional Elements That Integrate the Judicial Exception into a Practical Application?
Under Prong Two, it is determined whether the claim as a whole integrates the abstract idea into a practical application.
The claim does not recite any additional elements that meaningfully limit the abstract idea. Instead, the claim merely implements the abstract idea using a generic computer environment, as evidence by the recitation of a “computerized method” without any specific technical details. The step is a well-understood, routine, and conventional computer function, and does not impose any meaningful limit on the abstract idea.
Furthermore, the claim does not:
Improve the functioning of a computer or another technology,
Effect a transformation of a particular article, or
Apply the abstract idea in any meaningful way beyond generally linking it to a computer.
Accordingly, the claims do not integrate the abstract idea into a practical application.
2019 PEG: Step 2B: Does the Claim Recite Additional Elements That Amount to Significantly More Than the Judicial Exception?
Under Step 2B of the 2019 PEG, the additional elements must amount to “Significantly More” than abstract idea. Therefore, the claims fail to amount to “Significantly More” than the abstract idea.
Because independent claims 10 and 11 recite an abstract idea and do not include additional elements that integrate the exception into a practical application or amount to significantly more, the claims are not patent-eligible under 35 USC § 101.
The respective dependent claims depend from the rejected independent claims and therefore are rejected as well.
Accordingly, claims 10 and 11 are not patent-eligible under 35 USC § 101.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1 and 6-11 are rejected under 35 U.S.C. 103 as being unpatentable over Asai et al.(US 20250036760 A1, hereinafter “Asai”) in view of Chien (US 20230198997 A1, hereinafter “Chien”).
Regarding claim 1, Asai discloses an information processing apparatus comprising:
a log collecting unit configured to collect a log of operations of a system or a program in the information processing apparatus (Asai: [0065] The past case collection unit 231 also collects the attack log 43 for in-house systems. The attack log 43 is a log of cyberattacks on the systems operated and managed in-house; [0112] The past case collection unit 231 collects logs of cyberattacks against the analysis target system);
an unauthorized-access detecting unit configured to detect unauthorized access on a basis of the operation log and an attack scenario (Asai: [0052] The scenario analysis unit 22 refers to the threat DB 31 (See the table, including M-1 unauthorized access) to identify threats that are expected to occur in the target constituent element. As indicated in FIG. 4, types of constituent elements in which a threat is expected to occur is set for each threat in the threat DB 31; [0056] the scenario analysis unit 22 sets each threat for each constituent element as a target threat. The scenario analysis unit 22 refers to the attack DB 32 to identify an attack scenario for the target threat), the operation log being collected by the log collecting unit, the attack scenario being defined with a combination of operations which are not performed typically by the information processing apparatus (Asai: [0067] the past case analysis unit 232 sets each collected attack case as a target attack case. The past case analysis unit 232 presents the target attack case and also information from the attack DB 32 to the user. Then, the past case analysis unit 232 has the user specify attack activities in the attack DB 32 respectively for attacks in the target attack case; [0070] The likelihood calculation unit 233 calculates a similarity between the target attack scenario and each past scenario identified in step S42. Then, the likelihood calculation unit 233 calculates a likelihood of occurrence of the target threat based on the calculated similarity); and
a function-to-be-restricted specifying unit configured to specify a function that is to be restricted, on a basis of the attack scenario used in detection of the unauthorized access (Asai: [0052] The scenario analysis unit 22 refers to the threat DB 31 (See the table, including M-1 unauthorized access) to identify threats that are expected to occur in the target constituent element. … [0080] the risk value calculation unit 24 generates the analysis result 44 (“specify a function that is to be restricted”) indicating the information assets, each threat, the likelihood of occurrence of each threat, and the risk value).
However, Asai does not discloses, Chien, in a same field of endeavor, teaches the information processing apparatus, wherein a function restricting unit configured to restrict the function specified by the function-to-be-restricted specifying unit (Chien: [0006] Some embodiments provide a computer security module (“CSM”) that is configured to control (e.g., suppress, restrict, monitor) the execution of malicious software on a computing system).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Chien to restrict the function specified by the function-to-be-restricted specifying unit. One of ordinary skill in the art would have been motivated to make this modification because this technique stops any hacker from accessing, modifying, or executing folders or other resources (para. 0021).
Regarding claim 6, the combination of Asai and Chien discloses all elements of the current invention as stated above. Asai disclose the information processing apparatus according to claim 1, wherein the attack scenario is defined with a plurality of functions which are not performed typically by the information processing apparatus (Asai: [0111] The evaluation value combining unit 239 combines the likelihood of occurrence calculated by the different method and the likelihood of occurrence calculated based on the similarity, depending on the collection status of past cases (“attack scenario is defined with a plurality of functions which are not performed typically”)), and
wherein, in accordance with a count of detections of unauthorized access, the function restricting unit is configured to restrict functions step by step starting from a latest function among the functions of the attack scenario (Asai: [0066] The past case analysis unit 232 identifies a past scenario indicating a chronological sequence of attack methods for each attack case collected in step S41 (“restrict functions step by step starting from a latest function”). It is assumed that past scenarios are in the same format as the attack scenarios identified in step S3; [0109] If a likelihood of occurrence is set based on a similarity before a sufficient number of past cases have been collected (“a count of detections of unauthorized access”), an unreasonably low value may be output).
Regarding claim 7, the combination of Asai and Chien discloses all elements of the current invention as stated above. Asai discloses the information processing apparatus according to claim 6, wherein, when a different function among the plurality of functions included in the attack scenario is detected, the different function being different from the function which has been restricted, the unauthorized-access detecting unit is configured to determine that unauthorized access occurs (Asai: [0052] The scenario analysis unit 22 refers to the threat DB 31 to identify threats that are expected to occur in the target constituent element. As indicated in FIG. 4 (See the table, such as unauthorized access), types of constituent elements in which a threat is expected to occur is set for each threat in the threat DB 31; [0056] the scenario analysis unit 22 sets each threat for each constituent element as a target threat. The scenario analysis unit 22 refers to the attack DB 32 to identify an attack scenario for the target threat).
Regarding claim 8, the combination of Asai and Chien discloses all elements of the current invention as stated above. Asai discloses the information processing apparatus according to claim 6, wherein, when activation of a function corresponding to a plurality of attack scenarios is detected, the unauthorized-access detecting unit is configured to determine that unauthorized access corresponding to the attack scenario having the most count of unauthorized access occurs (Asai: [0031] The scenario analysis unit 22 refers to the threat DB 31 (See the table, including M-1 unauthorized access) to identify threats that are expected to occur in the target constituent element; [0070] The likelihood calculation unit 233 calculates a similarity between the target attack scenario and each past scenario identified in step S42. Then, the likelihood calculation unit 233 calculates a likelihood of occurrence of the target threat based on the calculated similarity; [0120] The security analysis device 10 according to Embodiment 2 updates a likelihood of occurrence based on a log scenario generated from a log of cyberattacks against the analysis target system. This makes it possible to calculate a likelihood of occurrence of a threat more appropriately (“most count of unauthorized access occurs”)).
Regarding claim 9, the combination of Asai and Chien discloses all elements of the current invention as stated above. Asai discloses the information processing apparatus according to claim 1,
wherein the attack scenario is defined with execution of a plurality of functions which are not performed typically by the information processing apparatus, and an attack scenario defined with similar execution of functions is used as a related attack scenario (Asai: [0067] the past case analysis unit 232 sets each collected attack case as a target attack case. The past case analysis unit 232 presents the target attack case and also information from the attack DB 32 to the user. Then, the past case analysis unit 232 has the user specify attack activities in the attack DB 32 respectively for attacks in the target attack case; [0070] The likelihood calculation unit 233 calculates a similarity between the target attack scenario and each past scenario identified in step S42. Then, the likelihood calculation unit 233 calculates a likelihood of occurrence of the target threat based on the calculated similarity).
Chien discloses the information processing apparatus, wherein the function restricting unit is configured to also restrict a function of the related attack scenario (Chien: [0003] The malicious software (e.g., viruses, Trojan horses, worms, etc. (“attack scenario”)) can be used by the hacker to damage, control, gain access, or otherwise compromise the computing system; [0006] Some embodiments provide a computer security module (“CSM”) that is configured to control (e.g., suppress, restrict, monitor) the execution of malicious software on a computing system).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Chien to restrict a function of the related attack scenario. One of ordinary skill in the art would have been motivated to make this modification because this technique stops any hacker from accessing, modifying, or executing folders or other resources (para. 0021).
Regarding independent claim 10 and 11, they are a method and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 1. Asai further discloses A non-transitory storage medium storing a program (Asai: [0035] The security analysis device 10 includes hardware of a processor 11, a memory 12, a storage 13, and a communication interface 14). Therefore, the claims are rejected for at least the same reasons of claim 1.
Claims 2 and 3 are rejected under 35 U.S.C. 103 as being unpatentable over Asai et al.(US 20250036760 A1, hereinafter “Asai”) in view of Chien (US 20230198997 A1, hereinafter “Chien”) as applied to claim above, and further in view of Swartz et al. (US 20070180509 A1, hereinafter “Swartz”).
Regarding claim 2, the combination of Asai and Chien discloses all elements of the current invention as stated above. However, the combination does not disclose, Swartz, in is a same field of endeavor, teaches the information processing apparatus according to claim 1, further comprising:
an image formation function (Swartz: [0148-0149] Third, a scanner that scans the system for signatures in the blacklist database. A scanner may inspect files, running processes and various system records (for example, the Microsoft Windows registry) for evidence of malicious software. The objective of the scanner is to detect the presence of malicious programs on the system after they have already been executed, so that they can be removed from the system).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Swartz to include an image formation function. One of ordinary skill in the art would have been motivated to make this modification because an anti-malware program may have both monitor and scanner elements, or either without the other (para. 0150).
Regarding claim 3, the combination of Asai and Chien discloses all elements of the current invention as stated above. However, the combination does not disclose, Swartz, in is a same field of endeavor, teaches the information processing apparatus according to claim 1, wherein, when the function-to-be-restricted specifying unit determines that reboot is to be performed, the information processing apparatus is configured to be rebooted (Swartz: [0408] The autorun element 0505 may be used, for example, to run smart reboot software that instructs the computer's local operating system to preserve the state of running applications (i.e., hibernation mode) before rebooting the computer 0102 from the security device 0101).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Swartz to reboot the system when the function-to-be-restricted specifying unit determines that reboot is to be performed. One of ordinary skill in the art would have been motivated to make this modification because this may provide increased convenience by allowing the user to switch from the local operating system installed on his computer's internal storage devices to the independent secure operating system environment provided by the security device (para. 0408).
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Asai et al.(US 20250036760 A1, hereinafter “Asai”) in view of Chien (US 20230198997 A1, hereinafter “Chien”) in view of Swartz et al. (US 20070180509 A1, hereinafter “Swartz”) as applied to claims above, and further in view of Ndu et al. (US 20240119155 A1, hereinafter “”Ndu).
Regarding claim 4, the combination of Asai, Chien and Swartz discloses all elements of the current invention as stated above. Swartz discloses teaches the information processing apparatus according to claim 3, wherein, when the function-to-be-restricted specifying unit determines that reboot is to be performed, the information processing apparatus is configured to be rebooted (Swartz: [0408] The autorun element 0505 may be used, for example, to run smart reboot software that instructs the computer's local operating system to preserve the state of running applications (i.e., hibernation mode) before rebooting the computer 0102 from the security device 0101).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Swartz to reboot the system when the function-to-be-restricted specifying unit determines that reboot is to be performed. One of ordinary skill in the art would have been motivated to make this modification because this may provide increased convenience by allowing the user to switch from the local operating system installed on his computer's internal storage devices to the independent secure operating system environment provided by the security device (para. 0408).
However, the combination does not disclose, Ndu, in is a same field of endeavor, teaches the information processing apparatus, wherein the information processing apparatus further includes a tampering-detection unit for detecting tampering with the information processing apparatus is performed, and, when tampering is detected, the information processing apparatus is configured to perform restoration from a golden copy stored in advance (Ndu: [0059] sending an alert notification 250 to a local or remote operator; shutting down the computer platform; resetting the computer platform; taking one or multiple recovery actions (e.g., restoring a kernel image from a golden copy).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Ndu to perform restoration from a golden copy stored in advance when tampering is detected. One of ordinary skill in the art would have been motivated to make this modification because, instead of spending hours attempting to disinfect files or locate every trace of malware, this may completely wipe the compromised system and restore it to a known-good state in minutes.
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Asai et al.(US 20250036760 A1, hereinafter “Asai”) in view of Chien (US 20230198997 A1, hereinafter “Chien”) as applied to claim above, and further in view of Ndu et al. (US 20240119155 A1, hereinafter “”Ndu) in view of Ignatius (US 20240056482 A1).
Regarding claim 5, the combination of Asai and Chien discloses all elements of the current invention as stated above. However, the combination does not disclose, Ndu, in is a same field of endeavor, teaches the information processing apparatus according to claim 1, wherein, when the function is restricted, the function restricting unit is configured to notify a manager (Ndu: [0064] logging information about the unexpected kernel module and sending an alert to a system administrator or security analyst; [0094] A computer platform alert may be communicated for purposes of being handled by a SIEM security analyst, a system administrator or other person, in accordance with example implementations. In accordance with example implementations, the kernel integrity scanning engine 608 may generate a computer platform alert in response to an alert that is provided by the hardware processor(s) 604 determining that a kernel module is unexpected), and
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Ndu to notify a manager when the function is restricted. One of ordinary skill in the art would have been motivated to make this modification because, generating alerts for unexpected kernel modules may be beneficial as a control measure for a wide variety of reasons, such as detecting security attacks in a timely manner and preventing erroneous operations of the computer platform (para.0017).
However, the combination does not discloses, Ignatius, in a same field of endeavor, teaches the information processing apparatus, wherein cancel the restriction in response to an operation of the manager (Ignatius: [0071]At block 802, data storage management system 1102 (e.g., storage manager 340) stops, suspends, or cancels pending storage operations that are currently being conducted by the at-risk component).
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the elements disclosed by Asai with the teachings of Ignatius to cancel the restriction in response to an operation of the manager. One of ordinary skill in the art would have been motivated to make this modification because this allows for critical, time-sensitive operations (e.g., a massive purchase order or an urgent software release) to proceed without waiting for preventing business delays.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
MULLIGAN et al. (US20240354404A1): [0020] the migration entity 112 can be a container management daemon process that can relocate containers to a different location; [0021] Responsive to detecting the trigger that indicates the potential attack, method 200 includes initiating (206) an attack countermeasure by migrating the process 108 to execute in a second computing location isolated from the first computing location. This mitigation breaks access to data at the first computing location.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANDREW SUH whose telephone number is (571)270-5524. The examiner can normally be reached 9:00 AM- 5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ANDREW SUH/Primary Examiner, Art Unit 2493