DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA and is in response to communications filed on 6/11/2026 in which claims 1-20 are presented for examination.
Priority
Acknowledgment is made of parent Application No. 17/733155, filed on 4/29/2022.
Drawings
Drawings have been acknowledged and are acceptable for examination purposes.
Specification
Specification has been acknowledged and is acceptable for examination purposes.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. U.S. 20190109868 (hereinafter referred to as “Muddu”) in view of Muddu.
As per claim 1, Muddu teaches:
A computerized system comprising:
one or more computer processors; and
computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations comprising:
…,
wherein the query-authoring interface comprises interface portions for inputting the parameters of the observation stream query to query (Muddu, [0323] – Query)
a plurality of security data sources and perform dynamic tracking of a security incident (Muddu, [0702], [0638]), and
wherein the observation stream query is executable (Muddu, [0174] – The SQL store 378 that stores information accessible by scripted query language (SQL), a time series database. See also [0203]. [0248] – Late binding schema) and
comprises the parameters that collectively define data retrieval operations across a plurality of security data sources (Muddu, [0195] – Various data connectors 802 can be employed by the security platform (e.g., at the data intake stage) to support various data sources. Embodiments of the data connectors 802 can provide support for accessing/receiving indexed data, unindexed data (e.g., data directly from a machine at which an event occurs), data from a third-party provider (e.g., threat feeds such as Norse™, or messages from AWS™ CloudTrail™), or data from a distributed file system (e.g., HDFS™)– The data generated by such data sources can include, for example, server log files, activity log files, configuration files, ..., etc. See also [0143] – The security platform …, from multiple data sources. [0167] – Configurable properties… (i) parse events, (ii) correlate between users and IP address, and/or (iii) correlate between one attribute with another attribute in the event data or an external attribute);
communicating the observation stream query to an observation stream engine to cause generation of observation stream data (Muddu, [0149]),
the observation stream data provides an observation stream timeline (Muddu, [0453])
associated with dynamic tracking of the security incident based on the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data (Muddu, [0671] fig. 57, 58);
receiving the observation stream data comprising security incidents with corresponding timestamps and user-defined interpretation data (Muddu, [0671] fig. 57, 58); and
causing display, via a view interface, of the observation stream data (Muddu, Fig. 2).
Muddu does explicitly teach receiving, via a query-authoring interface, parameters of an observation stream query, wherein the query-authoring interface comprises interface portions for inputting the parameters.
receiving, via a query-authoring interface (Muddu, [0206] – The security platform can prompt (e.g., through a user interface) the administrator to specify the data format), parameters of an observation stream query (Muddu, [0646] [0654] – Parameters)
It would have been obvious to a person having ordinary skill in the art at the time the invention was made to have modified Muddu by the teaching of Muddu to include receiving, via a query-authoring interface parameters of an observation stream query wherein the query-authoring interface comprises interface portions for inputting the parameters with the motivation to provide better monitoring as taught by Muddu ([0006]).
As per claim 2, Muddu as modified teaches:
The system of claim 1, the operations further comprising:
accessing, at the observation stream engine, the observation stream query, wherein the observation stream query is a user-generated observation stream query;
causing execution of the observation stream query against the plurality of data security sources based on the parameters (parameters. [0646] [0654][0657] fig.73);
generating the observation stream data associated with the observation stream query (generating the observation stream data associated with the observation stream query,[0646] [0654][0657] fig.73),
the observation stream data comprising security incidents ([0702][0638])
with corresponding timestamps and user-defined interpretation data ([0671] fig. 57, 58),
wherein the user-defined interpretation data is generated based on a parameter from the observation stream query, wherein generating the user-defined interpretation data comprises extracting a portion of raw observation stream data associated with monitoring the security incident across a plurality of computing resources ([0646] [0654][0657] fig.73); and
communicating the observation stream data to cause display of the observation stream data on an observation stream interface comprising graphical interface elements associated with the observation stream data (fig. 2 and ([0671] fig. 57, 58).
As per claim 3, Muddu as modified teaches:
The system of claim 2, wherein causing execution of the observation stream query comprises: causing execution of a first query portion that is a real-time query to receive a first set of event data;
causing execution of a second query portion that is a query-on-timer query to receive a second set of event data ([0147]);
generating the raw observation stream data based on the first set of event data and the second set of event data ([0147]).
As per claim 4, Muddu as modified teaches:
The system of claim 2, wherein generating observation stream data associated with the observation stream query further comprises one of:
based on the parameters of the observation stream query, classifying an event in the observation stream data with a classification type, wherein the classification type is associated with interface highlighting element ([0477]);
tagging the event with the interface highlight element to cause presentation of the event based on the interface highlight element ([0477]); and
identifying a presentation setting parameter associated with the user-defined interpretation data and mapping the presentation setting parameter with the user-defined parameter to cause presentation of the user-defined interpretation data based on the presentation setting parameter ([0517] and [0477]).
As per claim 5, Muddu as modified teaches:
The system of claim 1, wherein the observation stream query is associated with an observation stream query-type of a plurality of observation stream query-types, wherein observation stream query-types are selectable predefined security sensors comprising parameters for retrieving raw observation stream data and generating user-defined interpretation data ([0638[0517] [0477]).
As per claim 6, Muddu as modified teaches:
The system of claim 1, wherein the plurality of security data sources include a first data source that is configured for real-time queries and a second data source that is configured for query-on-timer queries, the first data source is associated with a first schema for storing event data and the second data source is associated with a second schema for storing event data ([0638[0517] [0477]); and
wherein the observation stream query comprises a first query portion having a real-time query for the first data source and a second query portion having a query-on-time query for the second data source ([0638[0517] [0477]).
As per claim 7, Muddu as modified teaches:
The system of claim 1, wherein the view interface comprises interface portions for presenting timestamps, an observation type corresponding to an observation stream query-type and details comprising the user-defined interpretation data ([0638[0517] [0477]).
As to claims 8-20, the limitations of these claims have been noted in the rejection above. They are therefore rejected as set forth above.
Response to Arguments
Based on the Terminal Disclaimer filed by Applicant on 6/11/2026, the double patenting rejection is withdrawn.
Applicant’s arguments, see Remarks, filed 6/11/2026, with respect to the 103 rejection have been fully considered but they aren’t persuasive.
Further search and consideration of Muddu shows that the amendments made to the claims are also taught in paragraphs [0174] – The SQL store 378 that stores information accessible by scripted query language (SQL), a time series database. See also [0203]. [0248] – Late binding schema. See also, [0195] – Various data connectors 802 can be employed by the security platform (e.g., at the data intake stage) to support various data sources. Embodiments of the data connectors 802 can provide support for accessing/receiving indexed data, unindexed data (e.g., data directly from a machine at which an event occurs), data from a third-party provider (e.g., threat feeds such as Norse™, or messages from AWS™ CloudTrail™), or data from a distributed file system (e.g., HDFS™)– The data generated by such data sources can include, for example, server log files, activity log files, configuration files, ..., etc. See also [0143] – The security platform …, from multiple data sources. [0167] – Configurable properties… (i) parse events, (ii) correlate between users and IP address, and/or (iii) correlate between one attribute with another attribute in the event data or an external attribute.
To specifically address Applicant’s point about the application having an authored interface, the GUI in [0440]-[0442] is interpreted as more precisely teaching this type of interface because it allows users to filter out data which is an authored query by a user.
To specifically address Applicant’s point about the claims being directed to dynamic display of security threats and stream data, Muddu teaches in [0322] – The event processing engine in the real-time path operates in a real-time mode to process unbounded, streaming data that enters the security platform.
In conclusion, the prior art of record teaches the claimed limitations.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Al-Fuqaha et al. 2015, “Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications”
Makaremi et al. US 20190236210 A1 teaches a query building component may elicit search criteria via the user interface using a natural language interface, construct a proper query therefrom (Abstract).
Rathod et al. US 20110276396 A1 teaches dynamically monitoring, tracking, storing, processing & presenting physical or digital activities, actions, locations, behavior & status with dynamically attached active links (Abstract).
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to the current examiner working on this case, name: Matthew Ellis, telephone number: (571)270-3443, email: matthew.ellis@uspto.gov, normal business hours Monday-Friday 8AM-5PM EST.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kavita Stanley can be reached on (571) 272-8352. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
September 16, 2026
/MATTHEW J ELLIS/Primary Examiner, Art Unit 2153