DETAILED ACTION
Claims 1-20 are pending in this action.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 3/27/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 4-6 and 8-9, 11-12, 14, 17-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (US PGPUB No. 2019/0260778) [hereinafter “Chen ‘778”] in view of Miller et al. (US PGPUB No. 2019/0188212) [hereinafter “Miller”].
As per claim 1, Chen ‘778 teaches a method comprising: generating a first plurality of vectors representing corresponding ones of a plurality of traffic log entries generated by a firewall for a network, wherein generating the first plurality of vectors (Examiner Note: first plurality of vectors are interpreted to be equivalent to the “spoofing attack detector” see Abstract and [0053]) comprises, determining a plurality of unique values recorded in the plurality of traffic log entries (Abstract, extracting features from traffic log data); generating a second plurality of vectors representing corresponding ones of the plurality of unique values, wherein each of the second plurality of vectors corresponds to one of the plurality of unique values (Abstract, training and testing vectors are generated based on extracted features); for each traffic log entry of the plurality of traffic log entries, determining a subset of the second plurality of vectors that correspond to those of the plurality of unique values recorded in the traffic log entry (Abstract, training and testing spoofing attack detector by comparing traffic log data with second set of vectors) and aggregating the subset of vectors to generate a corresponding one of the first plurality of vectors ([0036], aggregating learned parameters which make up the parameters for an anomaly, i.e. what is detected by a spoofing attack detector see also [0053]).
Chen ‘778 does not explicitly teach clustering the first plurality of vectors into a plurality of clusters; and analyzing network traffic detected for the network based on the plurality of clusters. Miller teaches clustering the first plurality of vectors into a plurality of clusters ([0006], grouping anomalous samples into clusters); and analyzing network traffic detected for the network based on the plurality of clusters ([0007], using the clusters to analyze data traffic flows for anomalies).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 with the teachings of Miller, clustering the first plurality of vectors into a plurality of clusters; and analyzing network traffic detected for the network based on the plurality of clusters, to provide further insight and context into the determination of anomaly and malicious attack in traffic data.
As per claim 4, the combination of Chen ‘778 and Miller teaches the method of claim 1, wherein clustering the first plurality of vectors into the plurality of clusters comprises clustering the first plurality of vectors with k-means clustering (Miller; [0076], clustering anomalous features using a k-means clustering technique).
As per claim 5, the combination of Chen ‘778 and Miller teaches the method of claim 1, further comprising, based on analyzing the plurality of clusters, determining that one or more of the first plurality of vectors represent potentially anomalous network traffic of the network (Miller; [0007], labeling individual anomalous samples in a cluster as potentially anomalous based on detecting the cluster).
As per claim 6, the combination of Chen ‘778 and Miller teaches the method of claim 5, wherein determining that the one or more vectors represent potentially anomalous network traffic of the network comprises, for each vector of the one or more vectors, determining that a distance between the vector and a centroid of a respective one of the plurality of clusters exceeds a threshold (Miller; [0076[, determining distance from a centroid in K-mean clustering).
As per claim 8, the combination of Chen ‘778 and Miller teaches the method of claim 1, wherein aggregating the subset of vectors comprises averaging or summing the subset of vectors (Miller; [0011], averaging the features values which are represented by feature vectors see [0030]).
As per claim 9, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale.
As per claim 11, the substance of the claimed invention is identical or substantially similar to that of claim 5. Accordingly, this claim is rejected under the same rationale.
As per claim 12, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale.
As per claim 14, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale.
As per claim 17, the substance of the claimed invention is identical or substantially similar to that of claims 5 and 6. Accordingly, this claim is rejected under the same rationale.
As per claim 18, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale.
As per claim 20, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale
Claims 2-3, 10 and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Chen ‘778 and Miller in view of Sjogren et al. (WO-2020049087-A1) [hereinafter “Sjogren”].
As per claim 2, the combination of Chen ‘778 and Miller teaches the method of claim 1.
The combination of Chen ‘778 and Miller does not explicitly teach extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values, wherein the weight matrix comprises the second plurality of vectors. Sjogren teaches extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values (Page 42, para. 1, weight matrices used to combine intermediary observational data with target input data), wherein the weight matrix comprises the second plurality of vectors (See id., weight matrices are combined with intermediary values to create intermediary representation).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 and Miller with the teachings of Sjogren, extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values, wherein the weight matrix comprises the second plurality of vectors, to provide further insight and context into the determination of anomaly and malicious attack in traffic data.
As per claim 3, the combination of Chen ‘778, Miller and Sjorgen teaches the method of claim 2 wherein determining the subset of the second plurality of vectors that correspond to those of the plurality of unique values recorded in the traffic log entry (Sjorgen; Page 3, para. 2, applying anomaly detection to network traffic anomalies) comprises determining a set of vectors corresponding to rows of the weight matrix that represent those of the plurality of unique values recorded in the traffic log entry (Sjorgen; Page 42, para. 2, x is a n-dimensional row vector, i.e. a set of n row vectors which can represent image data or traffic data see Page 3 applying this anomaly detection to network traffic anomalies), wherein aggregating the subset of vectors comprises aggregating the set of vectors corresponding to the rows of the weight matrix (Sjorgen; Page 42, para. 2, aggregating the set of vectors into an intermediary representation based on the weight matrix).
As per claim 10, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 15, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 16, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale.
Claims 7, 13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Chen ‘778 and Miller in view of Chen et al. (US PGPUB No. 2018/0329932) [hereinafter “Chen ‘932”].
As per claim 7, the combination of Chen ‘778 and Miller teaches the method of claim 1.
The combination of Chen ‘778 and Miller teaches determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values. Chen ‘932 teaches determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values ([0082], deduplicating anomaly features from network traffic used to generate alerts see also claim 22).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 and Miller with the teachings of Chen ‘932, determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values, to provide further insight and context into the determination of anomaly and malicious attack in traffic data.
As per claim 13, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale.
As per claim 19, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Lin et al. (US PGPUB No. 2012/0278021), Addepalli et al. (US PGPUB No. 2017/0257388), Vasseur et al. (US PGPUB No. 2017/0310691), Kimura et al. (US PGPUB No. 2022/0156529), Sampath et al. ("Adaptive Firewall System with Dynamic Rules Generation for Network Security," 2026 4th (ICSCSS), Coimbatore, India, 2026, pp. 1200-1208, doi: 10.1109/ICSCSS69635.2026.11646076), Chentoufi et al. ("An Approach for intrusion detection using machine learning algorithms," 2023 10th International Conference on Wireless Networks and Mobile Communications (WINCOM), Istanbul, Turkiye, 2023, pp. 1-6, doi: 10.1109/WINCOM59760.2023.10322882), Qiu et al. ("Anomaly detection using data clustering and neural networks," 2008 IEEE International Joint Conference on Neural Networks (IEEE World Congress on Computational Intelligence), Hong Kong, China, 2008, pp. 3627-3633, doi: 10.1109/IJCNN.2008.4634317) and Ismail et al. ("A Novel Method for Unsupervised Anomaly Detection Using Unlabelled Data," 2008 International Conference on Computational Sciences and Its Applications, Perugia, Italy, 2008, pp. 252-260, doi: 10.1109/ICCSA.2008.70) all disclose various aspects of the claimed invention including clustering anomaly vectors and detectors for increasing context accuracies in anomaly detection.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PETER C SHAW whose telephone number is (571)270-7179. The examiner can normally be reached Max Flex.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/PETER C SHAW/Primary Examiner, Art Unit 2493 September 17, 2026