Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
The claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because claims 1-19 could be interpreted as pure software and thus are not patentable subject matter.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1,2,3,15 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Cohen US 2020/0322368.
As per claim 1. Cohen teaches A method for network scanning activity detection, comprising: obtaining darknet data from darknet monitoring sensors; [0004] (darknet analyzing network traffic)
Cohen teaches applying the darknet data to a trained machine learning model; [0060]-[0062] [0066](artificial neural network, clustering)
Cohen teaches obtaining one or more labels of honeypot data corresponding to the darknet data based on the trained machine learning model; [0023][0044] (teaches the darknet may be a series of honeypots, and collecting data from honeypots to determine attack patterns, clustering data into results)
Cohen teaches and providing a result of threat behaviors of internet protocols based on the one or more labels. [0011][0071][0073] (alert with result) [0110]-[0115]
As per claim 2. The method of claim 1, wherein Cohen teaches the darknet data comprises network-based information. [0060][0110]-[0115] (darknet traffic (teaches exploit and port scanning, detection of an attack/malware)
As per claim 3. The method of claim 2, Cohen teaches wherein the network-based features comprise at least one of: a volume of scanning, an intensity indication of scanning, a size of exchanged bytes and packets, or scanned sets of ports. [0110]-[0115] (teaches exploit and port scanning, detection of an attack/malware)
As per claim 15. Cohen teaches A system for network scanning activity detection, the system comprising: a darknet monitoring sensor; a trained machine learning model; a processor; a memory having stored thereon a set of instructions which, when executed by the processor, cause the system to:obtain, via the darknet monitoring sensor, darknet data; [0004] (darknet analyzing network traffic)
Cohen teaches apply the darknet data to the trained machine learning model; [0060]-[0062] [0066](artificial neural network, clustering)
Cohen teaches obtain one or more labels of honeypot data corresponding to the darknet data based on the trained machine learning model; [0023][0044] (teaches the darknet may be a series of honeypots, and collecting data from honeypots to determine attack patterns, clustering data into results)
Cohen teaches output a result of threat behaviors of internet protocols based on the one or more labels. [0011][0071][0073] (alert with result) [0110]-[0115]
Claim(s) 4, 5, 16, 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cohen US 2020/0322368 in view of Sharifi Mehr US 2021/0344690
As per claim 4. The method of claim 1, Sharifi Mehr teaches wherein the one or more labels comprises payload-based information. [0038][0041]-[0043] (teaches inclusion of payload based information on detection of threat information and analysis of packets to detect malicious activities)
It would have been obvious to one of ordinary skill in the art at the effective priority date of the current application to use the teaching of Sharifi Mehr with the prior art because it provides more comprehensive threat analysis.
As per claim 5. The method of claim 4, wherein Cohen teaches the payload-based information comprises at least one of: a scan label set, an exploit label set, a malware label set, a brute-force label set, or a tool label set. [0110]-[0115] (teaches exploit and port scanning, detection of an attack/malware)
As per claim 16. The system of claim 15, Sharifi Mehr teaches wherein the one or more labels comprises payload-based information. [0038][0041]-[0043] (teaches inclusion of payload based information on detection of threat information and analysis of packets to detect malicious activities)
As per claim 17. The system of claim 16, Cohen teaches wherein the payload-based information comprises at least one of: a scan label set, an exploit label set, a malware label set, a brute-force label set, or a tool label set. [0110]-[0115] (teaches exploit and port scanning, detection of an attack/malware)
Claim(s) 6, 7, 18, 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cohen US 2020/0322368 in view of Byrne US 2023/0394352
As per claim 6. The method of claim 1, Byrne teaches wherein the trained machine learning model comprises a multi-label classification machine learning model. [0016]-[0019] (teaches multi-label classification by machine learning including, label powerset, binary relevance, and chains)
It would have been obvious to one of ordinary skill in the art at the effective priority date of the current application to use the teaching of Byrne with the prior art because it improves data analysis and solutions. [0002]
As per claim 7. The method of claim 6, Byrne teaches wherein the multi-label classification machine learning model comprises a stacked ensemble of a classifier chains model, a binary relevance classifier model, and a label powerset classifier model. [0016]-[0019] (teaches multi-label classification by machine learning including, label powerset, binary relevance, and chains)
As per claim 18. The system of claim 15, Byrne teaches wherein the trained machine learning model is a multi-label classification machine learning model. [0016]-[0019] (teaches multi-label classification by machine learning including, label powerset, binary relevance, and chains)
As per claim 19. The system of claim 18, Byrne teaches wherein the multi-label classification machine learning model comprises: a stacked ensemble of a classifier chains model; a binary relevance classifier model; and a label powerset classifier model. [0016]-[0019] (teaches multi-label classification by machine learning including, label powerset, binary relevance, and chains)
Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cohen US 2020/0322368 in view of Byrne US 2023/0394352 in view of Salji US 12,634,300
As per claim 8. The method of claim 7, Salji teaches wherein the stacked ensemble is constructed with sparsity regularization. (Column 15 line 55 to Column 16 line 10) (teaches use of sparsity regularization with learning algorithms)
It would have been obvious to one of ordinary skill in the art before the effective priority date of the current application to use the teaching of Salji with the prior art because it improves the ML algorithm.
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cohen US 2020/0322368 in view of Ranjan US 8,762,298
As per claim 9. Cohen teaches A method for network scanning activity detection training, comprising: obtaining training darknet data from darknet monitoring sensors; [0004] (darknet analyzing network traffic; darknet including honeypots) [0060]-[0062] [0066](artificial neural network, clustering)
Ranjan teaches obtaining ground-truth honeypot data; integrating the training darknet data with labels of the ground-truth honeypot data; (Column 4 line 57 to Column 5 line 15) (teaches supervised machine learning, and training data including honeypot ground truth)
Ranjan teaches and training a machine learning model based on the training darknet data and the labels of the ground-truth honeypot data, the labels corresponding to the training darknet data. (Column 4 line 57 to Column 5 line 15) (Column 15 lines 4-35) (training a machine learning model using supervised machine learning)
It would have been obvious to one of ordinary skill in the art before the effective priority date of the current application to use the teaching of Ranjan with the prior art because it improves the ML algorithm.
Claim(s) 10-14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cohen US 2020/0322368 in view of Ranjan US 8,762,298 in view of Chen US 2019/0132343
As per claim 10. The method of claim 9, further comprising: Chen teaches generating synthetic darknet data for a subset of the labels, a subset of training darknet data corresponding to the subset of the labels being less than another subset of training darknet data corresponding to another subset of the labels, wherein training the machine learning model is further based on the synthetic darknet data. [0041] [0020]-[0028] (teaches generating synthetic data based on labeled data collected in order to train a machine learning model)
As per claim 11. The method of claim 10, Chen teaches wherein the synthetic darknet data is generated based on interpolation between neighboring instances in the subset of the training darknet data. [0063]-[0065] (teaches the synthetic data is generated based on instances of the subsets of local and global data)
Cohen teaches obtaining training darknet data from darknet monitoring sensors; [0004] (darknet analyzing network traffic; darknet including honeypots) [0060]-[0062] [0066](artificial neural network, clustering)
As per claim 12. The method of claim 9, further comprising: Chen teaches obtaining a plurality of annotations corresponding to a portion of the darknet data, wherein the labels are integrated based on the plurality of annotations. [0014]-[0017] (analyst feedback in supervised machine learning)
As per claim 13. The method of claim 12, Chen teaches wherein the plurality of annotations corresponds to privileged information. [0014]-[0017] (analyst feedback in supervised machine learning) (the specification provides that “privileged information” is merely experienced user feedback)
As per claim 14. The method of claim 13, Chen teaches wherein the privileged information was obtained after the training darknet data was obtained from the darknet monitoring sensors. [0014]-[0017] (analyst feedback in supervised machine learning) (the specification provides that “privileged information” is merely experienced user feedback)
Cohen teaches obtaining training darknet data from darknet monitoring sensors; [0004] (darknet analyzing network traffic; darknet including honeypots) [0060]-[0062] [0066](artificial neural network, clustering)
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439