Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Currently pending claims are 1 – 22.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the exclaimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 – 3, 7 & 13 – 20 are rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of in view of Xu et al. (U.S. Patent 11,483,324).
As per claim 1 & 14, Sade teaches a non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for securing stored functions, the operations comprising:
identifying a session between a network identity and a network resource, the session being established using a native client associated with the network identity, the network resource being associated with one or more stored functions, wherein the native client is associated with a native communication protocol;
(Sade: Figure 2B / E-2000 & Col. 2 Line 9 – 12, Col. 7 Line 24 – 27, Col. 3 Line 60 – 67, Col. 5 Line 20 – 23, Col. 2 Line 51 – 58, Col. 4 Line 45 – 57 and Col. 11 Line 21 – 25:
(a) a user / client (networking identity) sends a request to access a network resource of target service (Sade: Figure 2B / E-2000 & Col. 2 Line 9 – 12 and Col. 7 Line 24 – 27);
(b) a proxy entity of CMS (Credential Management System) authenticates the user / client (network identity) based on an authentication credential sent in the request (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23), wherein
(b-1) the CMS proxy entity can be an endpoint device located on which the user / client resides, which constitutes a native client (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23),
(b-2) a request from the client to access a target service running (executing) on a target network node – i.e. an access request to a network resource being associated with one or more stored functions (target services) running (executing) on a target network node (Sade: Col. 2 Line 56 – 58),
(b-3) the authentication credential can be sent in the request via (e.g.) a Kerberos protocol (i.e. a native communication protocol) (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23) and
(b-4) the CMS proxy entity (i.e. native client) communicates with an authentication service and operates transparently with the target service (i.e. network resource) (Sade: Figure 2B / E-2000).
monitoring the session to identify a request to perform at least one action associated with at least one function of the one or more stored functions (Sade: see above & Col. 2 Line 56 – 58 and Col. 14 Line 61 – 65: (a) monitoring a privileged access permission in order to access the stored functions (target services) running (executing) on a target network node, (b) monitoring and controlling the behavior of the client according to a limitation of client access to the target service based on a usage data associated with a boundary definition, and (c) in summary – use a requested access function to act for the user as a result of the request).
However, Sade does not disclose expressly generating, based on the request, a signature representation of the at least one function.
Xu (& Sade) teaches generating, based on the request, a signature representation of the at least one function (Sade: see above & Col. 14 Line 61 – 65: monitoring and controlling the behavior of the client according to a limitation of client access to the target service based on a usage data associated with a boundary definition) ||
(Xu: Abstract & Col. 19 Line 46 – 50, Col. 20 Line 16 – 18, and Col. 3 Line 27 – 34:
(a) monitoring the behavior of the client such as a rate limiting factor including at least a rate limiting on browser fingerprint which can be construed as one type of signature representing a user activity on a corresponding requested browser function (Xu: Col. 19 Line 46 – 50 & Col. 20 Line 16 – 18),
(b) a security organization can aggregate data received across many clients and many domains, wherein the data that characterizes various clients when requesting a service function can also be construed as one type of signatures, which was determined to be legitimated or automated (i.e. historical signatures) to enable using (historical) aggregated information to generate effective countermeasures (Xu: Col. 3 Line 27 – 34),
(c) generating a risk score that represents a likelihood that the client request could be an malicious automated request and
(d) in summary – use a requested access function to act for the user and generate a signature representation as a result of the request);
comparing the generated signature representation of the at least one function with at least one stored signature representation of the at least one function (Xu: Abstract & Col. 19 Line 46 – 50 and Col. 20 Line 16 – 18: see above); and
determining whether to allow the at least one action based on the comparison (Xu: Abstract & Col. 2 Line 64 – 6).
As per claim 3, (& claim 2) and claim 20, Sade as modified teaches wherein the signature representation of the at least one function is based on a combination of the signature representations for the one or more components (Xu: see above & Col. 3 Line 27 – 34, Col. 19 Line 46 – 50 & Col. 20 Line 16 – 18: (a) a security organization can aggregate data received across many clients and many domains, wherein the data that characterizes various clients when requesting a service function can also be construed as one type of signatures, which was determined to be legitimated or automated (i.e. historical signatures) to enable using (historical) aggregated information to generate effective countermeasures (Xu: Col. 3 Line 27 – 34), wherein (b) monitoring the behavior of the client such as a rate limiting factor including at least a rate limiting on browser fingerprint which can be construed as one type of signature representing a user activity on a corresponding requested browser function (Xu: Col. 19 Line 46 – 50 & Col. 20 Line 16 – 18)).
As per claim 7, the instant claim is directed to a claimed content having functionality corresponding to the Claim 1, and are rejected by a similar rationale.
As per claim 13, Sade as modified teaches wherein generating the signature representation of the at least one function includes applying at least one trained model (Sade: se above) || (Xu: see above & Col. 3 Line 1 – 12 / Line 27 – 31: providing a network security system for anomaly detection by utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that characterizes a client device of a plurality of client devices (i.e. as a particular type of client device) (Xu: Col. 3 Line 1 – 12 / Line 27 – 31).
As per claim 15, Sade as modified teaches wherein the at least one action includes a manipulation of the at least one function to generate at least one manipulated function and wherein the signature representation is generated based on the at least one manipulated function (Sade: see above) || (Xu: see above & Col. 19 Line 34 – 35 / Line 46 – 50: a manipulation of an access request function to generate one manipulated function such as web browser function to check the browser fingerprint rate limiting).
As per claim 16 – 17, Sade as modified teaches wherein the determination whether to allow the at least one action is based on a difference between the at least one function and the at least one manipulated function indicated by the comparison (Sade: see above) || (Xu: see above & Col. 19 Line 34 – 35 / Line 46 – 50 and Col. 20 Line 11 – 18: (a) based on the comparison between the limiting threshold (versus a normal / regular behavior function) so as to determine whether the request was initiated by an automated process and (b) generating (i.e. storing) a likelihood score (i.e. one type of signature) that the request was initiated by an automated process).
As per claim 18, Sade as modified teaches wherein determining whether to allow the at least one action is further based on application of at least one rule (Sade: see above) || (Xu: see above & Col. 19 Line 34 – 35 / Line 46 – 50 and Col. 20 Line 11 – 18: based on application of at least one rule such as the browser fingerprint rate limiting to determine whether the request was initiated by an automated process).
As per claim 19, Sade as modified teaches wherein the at least one rule defines a maximum exposure level and wherein the determining whether to allow the at least one action is based on a change in exposure level indicated by the comparison (Sade: see above) || (Xu: see above & Col. 19 Line 34 – 35 / Line 46 – 50 and Col. 20 Line 11 – 18: (a) based on the comparison between the limiting threshold (versus a normal / regular behavior function) so as to determine whether the request was initiated by an automated process and (b) generating (i.e. storing) a likelihood score that represents a change in exposure level indicated by the comparison so as to determine whether the request was initiated by an automated process).
Claims 4 – 6, 8 – 10, 12 & 21 are rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Priess et al. (U.S. Patent 10,290,053).
As per claim 4 – 5 & 21, Priess (& Sade) as modified teaches wherein at least one of the one or more components is a SQL statement; and calculating at least one exposure risk associated with the at least one function (Sade: see above) || (Priess: Col. 5 Line 55 – 67, Col. 53 Line 46 – 59, Col. 74 Line 19 – 22 & Col. 75 Line 30 – 40 / Col. 79 Line 2 – 8: managing the fraud detecting of database activity of a user online banking system that involves SQL statements such as SQL Intersect, Union and Minus operations and generating risk data score accordingly).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of analyzing the at least one first data element to identify a characteristic of the native client because Priess teaches to alternatively, effectively and securely manage the fraud detecting of database activity of a user online banking system that involves SQL statements such as SQL Intersect, Union and Minus operations and generating risk data score accordingly (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities (see above).
As per claim 6, 8, 10 & 12, Priess (& Sade) as modified teaches wherein the signature representation of the at least one function is at least partially based on a determination whether the at least one function includes a write operation (Sade: see above) || (Priess: see above & Col. 101 Line 14 – 25: for example, a write operation to transfer from an account routing number to another account using a user online banking system, that requires access to a sensitive resource to manipulate at least one function).
As per claim 9, Priess (& Sade) as modified teaches determination whether the at least one function includes an operation requiring access to a resource external to the database (Sade: see above) || (Priess: see above & Col. 109 Line 61 – 63 and Col. 110 Line 46 – 50: modeling a risk function that makes money transfer to an external account using three different IP addresses in a short amount of time).
Claim 11 is rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Guha et al. (U.S. Patent 11,455,588).
As per claim 11, Guha (& Sade) teaches wherein the signature representation of the at least one function is at least partially based on a number of rows affected by the at least one function (Sade: see above) || (Guha: Abstract, Col. 4 Line 27 – 30, Col. 18 Line 62 – 65 & Col. 33 Line 22 – 24: provide a secured system for data security operations to verify data within a semantic network including relational databases (SQL) and (b) monitoring a sequence of DB transformation function when importing data via SQL statements to change the number of rows and/or columns).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of analyzing the at least one first data element to identify a characteristic of the native client because Guha teaches to alternatively, effectively and securely provide a secured system for data security operations to verify data within a semantic network including relational databases (SQL) and (b) monitoring a sequence of DB transformation function when importing data via SQL statements to change the number of rows and/or columns (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities (see above).
Claim 22 is rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Gargaro et al. (U.S. Patent 11,206,262).
As per claim 22, Gargaro (& Sade teaches) teaches identifying a change to the at least one rule; and generating the at least one stored signature representation of the at least one function based on the identified change (Sade: see above) || (Gargaro: Abstract, Col. 10 Line 61 – Col. 11 Line 4 and Col. 5 Line 9 – 11: identifying / determining changes to the rules / policies of access control information (ACL) such as adding roles/rules, updating users assigned to roles, updating rules, adding/deleting attributes, and so on and accordingly a trigger manager saves / stores these updates (i.e. signatures) into the corresponding entry of the historical database such that a respective score is also assigned corresponding to their effectiveness in triggering the revision (change) of the access control information (ACL rules)).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of analyzing the at least one first data element to identify a characteristic of the native client because Gargaro teaches to alternatively, effectively and securely identify / determine changes to the rules / policies of access control information (ACL) such as adding roles/rules, updating users assigned to roles, updating rules, adding/deleting attributes, and so on and accordingly a trigger manager saves / stores these updates (i.e. signatures) into the corresponding entry of the historical database such that a respective score is also assigned corresponding to their effectiveness in triggering the revision (change) of the access control information (ACL rules) (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential based on the corresponding access control information (ACL) rules / policies to access the network resource of target service and detecting anomaly / malicious activities (see above).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
---------------------------------------------------
/Longbit Chai/
Longbit Chai E.E. Ph.D.
Primary Examiner, Art Unit 2431
No. #2622 – 2026 ---------------------------------------------------