Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The IDS file March 21, 2025 has been considered.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 15-16, 19, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Draper et al. (US 10764383, hereinafter referred to as “Draper”) in view of Moore (US 10560432).
Regarding claim 15, Draper teaches an electronic device comprising:
memory (not explicitly disclosed, but in order to carry out the operation, a memory in a device is inherent);
communication circuitry (abstract – network connection); and
one or more processors (col. 2, lines 45-47), the one or more processors are configured to: identify, based on identifying an external electronic device different from a plurality of first external electronic devices executing an agent program using the communication circuitry, a user logged in the external electronic device (abstract - The log record is transmitted to the third server. Col. 2, line 48 to col. 3, line 2: The system includes a software application executing on a first server remote to a plurality of devices. The software application is accessible by devices via a network connection. A tracking software executes on a processor and sends data to a second server. The data received from the tracking software at the second server indicative of a private IP address of one of the plurality of devices which accesses the tracking software. The second server determines a user identifier based on the data and transmits second data to a third server, the second data indicative of the private IP address and further indicative of a second server identifier. A Domain Name System (DNS) server tracks usage of the software application by the one of the plurality of devices on the network to associate a time stamp, a domain and the private IP address with a log record. The log record is transmitted to the third server. The third server queries the log record by the private IP address to match data from the log record with data from the second data such that the log record is associated with the user identifier.).
However, Draper does not teach transmit, based on management information, first information to display a screen including IP addresses associated with the user logged in the external electronic device and a list of the one or more first external electronic devices associated with each of the IP addresses, to the external electronic device; and transmit, based on receiving a signal indicating selection of a first external electronic device in the list of the one or more first external electronic devices from the external electronic device, second information with respect to the first external electronic device selected in the list, to the external electronic device.
Moore teaches transmit, based on management information, first information to display a screen including IP addresses associated with the user logged in the external electronic device and a list of the one or more first external electronic devices associated with each of the IP addresses, to the external electronic device (col. 8, lines 34-47: the user interface may include a window or other GUI display element representing an endpoint device management console 300. The console 300 may display all or part of the endpoint data 135 descriptive of the endpoints 160A-160N and collected by the agents 170A-170N. For example, the console 300 may display a set of endpoint device identifiers 360A-360N that correspond to the endpoint devices 160A-160N. The device identifiers 360A-360N may represent device names, alphanumeric labels, IP addresses, and/or other suitable information that may uniquely identify particular endpoint devices within some context associated with the client organization. Each device identifier may be associated with additional endpoint data in the console 300.); and
transmit, based on receiving a signal indicating selection of a first external electronic device in the list of the one or more first external electronic devices from the external electronic device, second information with respect to the first external electronic device selected in the list, to the external electronic device (col. 8, line 34 to col. 9, line 3: the user interface may include a window or other GUI display element representing an endpoint device management console 300. The console 300 may display all or part of the endpoint data 135 descriptive of the endpoints 160A-160N and collected by the agents 170A-170N. For example, the console 300 may display a set of endpoint device identifiers 360A-360N that correspond to the endpoint devices 160A-160N. The device identifiers 360A-360N may represent device names, alphanumeric labels, IP addresses, and/or other suitable information that may uniquely identify particular endpoint devices within some context associated with the client organization. Each device identifier may be associated with additional endpoint data in the console 300. The device identifiers 360A-360N may be displayed with corresponding security status indicators 361A-361N. The security status indicators 361A-361N may represent firewall information, malware information, antivirus information, and so on, for particular endpoints. For example, the security status indicator for a particular endpoint may represent an “all clear” status if the firewall is operational and no malware or viruses have been detected. The device identifiers 360A-360N may be displayed with corresponding network status indicators 362A-362N. The network status indicators 362A-362N may represent a network health of the corresponding endpoints. The device identifiers 360A-360N may be displayed with corresponding login status indicators 363A-363N. The login status indicators 363A-363N may represent whether the registered user for the endpoint is currently logged in or, if not, how recently the user was logged in. The device identifiers 360A-360N may be displayed with corresponding application status indicators 364A-364N. The application status indicators 364A-364N may represent a status of application use, application installation, application updating, or application deletion. As indicated by the ellipses, the device identifiers 360A-360N may be displayed with other types of endpoint data, as appropriate.).
Before the effective filing date of the invention one of ordinary skill in the art would have been motivated to combine the teaching of Moore with the teaching of Draper by incorporating the management console and endpoint display functionality of Moore into the correlated user/device information system of Draper t provide administrators with an improved mechanism for viewing and managing devices associated with identified users and network addresses. Such a combination would have combined known techniques for the intended purposes, thus improving administration and monitoring network devices.
Regarding claim 16, Draper teaches the electronic device of claim 15, wherein the one or more processors are configured to: obtain, based on log information in which the IP addresses of second external electronic devices accessing each of the plurality of first external electronic devices are included, the list (col. 2, line 48 to col. 3, line 2: The system includes a software application executing on a first server remote to a plurality of devices. The software application is accessible by devices via a network connection. A tracking software executes on a processor and sends data to a second server. The data received from the tracking software at the second server indicative of a private IP address of one of the plurality of devices which accesses the tracking software. The second server determines a user identifier based on the data and transmits second data to a third server, the second data indicative of the private IP address and further indicative of a second server identifier. A Domain Name System (DNS) server tracks usage of the software application by the one of the plurality of devices on the network to associate a time stamp, a domain and the private IP address with a log record. The log record is transmitted to the third server. The third server queries the log record by the private IP address to match data from the log record with data from the second data such that the log record is associated with the user identifier.).
Regarding claim 19, Draper does not teach the electronic device of claim 15, wherein the one or more processors are configured to: receive, from a third external electronic device, issue information with respect to at least one of the plurality of first external electronic devices; and transmit the first information including the issue information to the external electronic device. Moore teaches wherein the one or more processors are configured to: receive, from a third external electronic device, issue information with respect to at least one of the plurality of first external electronic devices; and transmit the first information including the issue information to the external electronic device (col. 8, lines 34-47: the user interface may include a window or other GUI display element representing an endpoint device management console 300. The console 300 may display all or part of the endpoint data 135 descriptive of the endpoints 160A-160N and collected by the agents 170A-170N. For example, the console 300 may display a set of endpoint device identifiers 360A-360N that correspond to the endpoint devices 160A-160N. The device identifiers 360A-360N may represent device names, alphanumeric labels, IP addresses, and/or other suitable information that may uniquely identify particular endpoint devices within some context associated with the client organization. Each device identifier may be associated with additional endpoint data in the console 300.). The motivation to combine is the same as claim 15.
Regarding claim 20, Draper does not teach the electronic device of claim 19, wherein the one or more processors are configured to: transmit, based on receiving the issue information, third information for notifying the issue information to the external electronic device. More teaches wherein the one or more processors are configured to: transmit, based on receiving the issue information, third information for notifying the issue information to the external electronic device (col. 8, lines 34-47: the user interface may include a window or other GUI display element representing an endpoint device management console 300. The console 300 may display all or part of the endpoint data 135 descriptive of the endpoints 160A-160N and collected by the agents 170A-170N. For example, the console 300 may display a set of endpoint device identifiers 360A-360N that correspond to the endpoint devices 160A-160N. The device identifiers 360A-360N may represent device names, alphanumeric labels, IP addresses, and/or other suitable information that may uniquely identify particular endpoint devices within some context associated with the client organization. Each device identifier may be associated with additional endpoint data in the console 300.). The motivation to combine is the same as claim 15.
Allowable Subject Matter
Claims 1-14 are allowed.
The closest prior art of record: Draper (US 10764383) teaches distributed agent log collection, IP correlation, user association and centralized processing; Nappier (US 20110185055) teaches identity/network correlation, relationships among users, IP addresses, network resources, and event correlation; and Moore (US 10560432) teaches centralized endpoint management system to provide management interface for remotely managing endpoint devices, such as displaying information associated with managed devices, network information such as IP address, and device status, and receiving user input selecting a managed endpoint from a displayed list and providing additional information regarding the selected endpoint.
While the combination of these references teach most of claims 1, the specific limitation of “determine a mapping of respective first external electronic devices with the one or more second external electronic devices… based on a grouping… based on a second IP addresses” is not taught in any of the prior art of record. Accordingly, claim 1 is allowed.
Claims 2-7 are allowed for their dependencies of allowed claim.
Claims 8-14 are similar to claims 1-7, respectively, therefore are allowed for the same rationale.
Claims 17 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Regarding claim 17, the prior art of record does not teach the electronic device of claim 16, wherein the one or more processors are configured to: obtain, based on identifying at least one first external electronic device associated with each of the IP addresses, the list by grouping the log information based on the IP addresses of the second external electronic devices.
Claim 18 depends on objected claim 17, therefore is objected to for its dependency.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Villella, US 20110314148 - obtaining useful information from processed log messages generated by a variety of network platforms, and one or more "event managers" may analyze the events to determine whether alarms should be generated therefrom.
Brandwine et al., US 10178119 - customers may implement security applications and/or devices using the one or more computing resources provided by the computing resource service provider. Operational information from customer operated computing resources may be correlated with operational information from computing resources operated by the computing resource service provider or other entities and correlated threat information may be generated.
Vo et al., US 20190286671 - associating an entity to an IP address of a non-logged-in user.
Malboubi et al. US 20190394080 - A framework to handle monitoring and automatic fault manifestation in cloud networks. Multiple techniques correlate the logs of different cloud services or generate independent capsules for each component, VM, storage, or transaction.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALINA N BOUTAH whose telephone number is (571)272-3908. The examiner can normally be reached M-F 7:00 AM - 3:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at (571) 270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
ALINA BOUTAH
Primary Examiner
Art Unit 2458
/ALINA A BOUTAH/Primary Examiner, Art Unit 2458