DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Examiner Notes
All claims have been reviewed for compliance with 35 U.S.C. §112 and 35 U.S.C. §101 (as set forth in MPEP 2106).
Response to Amendment
Applicant’s amendment filed 15 April 2025 amends claims 1. Claims 2-20 have been added. Applicant’s amendment has been fully considered and entered.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-19 of U.S. Patent No. 12,265,637. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the ‘637 include all the limitations of the instant claims.
Instant Application
U.S. Patent No. 12,265,637
training a neural network model running on one or more computing resources to yield a probability that an outbound electronic message contains sensitive content based on contextual information relating to the outbound electronic message, wherein training the neural network model includes: (Claim 8)
further processing the outbound electronic mail message with a neural network model running on the one or more computing resources and trained to yield a probability that the outbound electronic mail message contains sensitive content based on contextual information relating to the outbound electronic mail message… (Claim 1)
using a training set comprising a set of electronic messages to train the neural network model, the set of electronic messages including messages that exfiltrated at least one item of sensitive content, wherein each of the electronic messages in the set including a non-sensitive content portion that remains and a sensitive content portion that has been removed from the electronic message, wherein the non-sensitive content portion contains patterns indicating the electronic message contained sensitive content; (Claim 8)
wherein: the neural network model is trained, at least in part, using a training set comprising at least one training electronic mail message consisting of non-sensitive text of at least one sensitive mail message that exfiltrated at least one item of sensitive content, the non-sensitive text comprising text of the at least one sensitive mail message with an entirety of the at least one item of sensitive content removed to determine whether the non-sensitive text contains patterns indicative of containing sensitive content; (Claim 1)
wherein the training set includes a specified number of electronic messages that were sent immediately before an exfiltration event. (Claim 8)
and the training set includes a specified number of electronic mail messages that were sent immediately before an exfiltration event; (Claim 1)
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 2, 4-7, 15, 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Borup, U.S. Publication No. 2018/0293400, in view of Bardot, U.S. Publication No. 2022/0215948, and further in view of Jackobsson, U.S. Patent No. 10,880,322. Referring to claim 1, Borup discloses a client program, executing on a computer 101 that includes a processor and memory ([0017] & [0023]: processor reads on the claimed processing circuit), that that analyzes, using machine learning models ([0046]), an outgoing email that includes an attached file to determine the probability that the file violates a rule of a policy ([0019] & [0046]) specific to transmission of sensitive data ([0018]), which meets the limitation of processing an outbound electronic message with a neural network model executed by processing circuit, the outbound electronic message being processed by the neural network model to determine a probability that the outbound electronic message includes sensitive content.
Borup discloses that the machine learning models can be trained using sample sets of data ([0035]) such that the trained machine learning models are published ([0039]) and used to analyze files to be transferred ([0043] & [0046]), which meets the limitation of wherein the neural network model is trained using a training set that includes at least one electronic message having [a non-sensitive portion that contains] patterns indicating that the electronic message contained sensitive content. Borup does not disclose that sensitive information has been removed from sample sets of data.
Bardot discloses training machine learning models ([0292]) using data sets where confidential information has been removed ([0376]), which meets the limitation of using a training set that includes at least one electronic message having a non-sensitive portion that contains patterns indicating that the electronic message contained sensitive content. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have removed any sensitive information from the training data of Borup in order to protect the sensitive data from unauthorized access as suggested by Bardot ([0352]).
Borup discloses that the machine learning models can be used to determine a probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]). Borup does not specify the use of two different thresholds.
Jakobsson discloses analyzing messages and comparing risk scores to a first threshold and a second threshold, such that different remedial actions are performed when the risk score is above the first threshold and second threshold respectively (Col. 19, line 52 – Col. 20, line 16: Threshold T5 = 15, threshold T1 = 50, and threshold T2 = 72. Therefore, different remedial actions are performed when risk score is above one threshold and below another threshold that requires a different remedial action to be performed when the risk score is above that particular threshold), which meets the limitation of executing, by the processing circuit, a first remedial action regarding the outbound electronic message in response to the probability being greater than a first threshold and less than a second threshold, and executing, by the processing circuit, a second remedial action regarding the outbound electronic message in response to the probability being greater than the second threshold. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the analysis of Borup to have utilizes multiple thresholds in order to provide different response types to different levels of identified security risks as suggested by Jakobsson (Col. 29, lines 29-53).
Referring to claim 2, Borup discloses that the machine learning models can be trained using sample sets of data ([0035]), which meets the limitation of identifying a set of electronic messages that each contain [a sensitive content portion]. Borup does not disclose that sensitive information has been removed from sample sets of data.
Bardot discloses training machine learning models ([0292]) using data sets where confidential information has been removed ([0376]), which meets the limitation of each contain a sensitive content portion, removing the sensitive content portion from each electronic message of the set of electronic messages, wherein the set of electronic messages includes the non-sensitive content portion with the sensitive content portion removed. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have removed any sensitive information from the training data of Borup in order to protect the sensitive data from unauthorized access as suggested by Bardot ([0352]).
Referring to claim 4, Borup discloses that the policies detect the transmission of sensitive data from a company/government ([0018]), which meets the limitation of wherein the set of electronic messages includes electronic messages sent that exfiltrated sensitive content from an entity.
Referring to claim 5, Borup discloses that the analysis includes the application of a machine learning model to text from the files in order to determine whether the files include sensitive data ([0051]-[0052]), which meets the limitation of wherein the patterns are selected from an outbound message with certain text patterns.
Referring to claim 6, Borup discloses that the machine learning models can be used to determine the probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]: Examiner notes that what the alarm “indicates” would be considered to be non-functional descriptive material that is not given patentable weight since the alarm, nor its’ contents, are functionally utilized in the claims. See MPEP 2111.04-2111.05), which meets the limitation of wherein the first remedial action includes triggering an alarm to indicate that the outbound electronic message is being sent.
Referring to claim 7, Borup discloses that the machine learning models can be used to determine a probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]). Borup does not specify the use of two different thresholds.
Jakobsson discloses analyzing messages and comparing risk scores to a first threshold and a second threshold, such that different remedial actions are performed when the risk score is above the first threshold and second threshold respectively (Col. 19, line 52 – Col. 20, line 16) such that one of the remedial actions could be sending the message to a unit that “scrubs” the message (Col. 19, lines 55-59), which meets the limitation of wherein the second remedial action includes removing sensitive content from the outbound electronic message. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the analysis of Borup to have utilizes multiple thresholds in order to provide different response types to different levels of identified security risks as suggested by Jakobsson (Col. 29, lines 29-53).
Referring to claim 15, Borup discloses a client program, executing on a computer 101 that includes a processor and memory ([0017] & [0023]: processor reads on the claimed processing circuit), that that analyzes, using machine learning models ([0046]), an outgoing email that includes an attached file to determine the probability that the file violates a rule of a policy ([0019] & [0046]) specific to transmission of sensitive data ([0018]), which meets the limitation of a computing device comprising a processing circuit, and a memory having executable instructions stored thereon, which when executed by the processing circuit, cause the processing circuit to process an outbound electronic message with a neural network model executed by processing circuit, the outbound electronic message being processed by the neural network model to determine a probability that the outbound electronic message includes sensitive content.
Borup discloses that the machine learning models can be trained using sample sets of data ([0035]) such that the trained machine learning models are published ([0039]) and used to analyze files to be transferred ([0043] & [0046]), which meets the limitation of wherein the neural network model is trained using a training set that includes at least one electronic message having [a non-sensitive portion that contains] patterns indicating that the electronic message contained sensitive content. Borup does not disclose that sensitive information has been removed from sample sets of data.
Bardot discloses training machine learning models ([0292]) using data sets where confidential information has been removed ([0376]), which meets the limitation of using a training set that includes at least one electronic message having a non-sensitive portion that contains patterns indicating that the electronic message contained sensitive content. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have removed any sensitive information from the training data of Borup in order to protect the sensitive data from unauthorized access as suggested by Bardot ([0352]).
Borup discloses that the machine learning models can be used to determine a probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]). Borup does not specify the use of two different thresholds.
Jakobsson discloses analyzing messages and comparing risk scores to a first threshold and a second threshold, such that different remedial actions are performed when the risk score is above the first threshold and second threshold respectively (Col. 19, line 52 – Col. 20, line 16: Threshold T5 = 15, threshold T1 = 50, and threshold T2 = 72. Therefore, different remedial actions are performed when risk score is above one threshold and below another threshold that requires a different remedial action to be performed when the risk score is above that particular threshold), which meets the limitation of execute a first remedial action regarding the outbound electronic message in response to the probability being greater than a first threshold and less than a second threshold, and execute a second remedial action regarding the outbound electronic message in response to the probability being greater than the second threshold and less than a third threshold. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the analysis of Borup to have utilizes multiple thresholds in order to provide different response types to different levels of identified security risks as suggested by Jakobsson (Col. 29, lines 29-53).
Referring to claim 18, Borup discloses that the analysis includes the application of a machine learning model to text from the files in order to determine whether the files include sensitive data ([0051]-[0052]), which meets the limitation of wherein the patterns are selected from an outbound message with certain text patterns.
Referring to claim 19, Borup discloses that the machine learning models can be used to determine the probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]: Examiner notes that what the alarm “indicates” would be considered to be non-functional descriptive material that is not given patentable weight since the alarm, nor its’ contents, are functionally utilized in the claims. See MPEP 2111.04-2111.05), which meets the limitation of wherein the first remedial action includes triggering an alarm to indicate that the outbound electronic message is being sent.
Referring to claim 20, Borup discloses that the machine learning models can be used to determine a probability that the file is likely to violate policy rules such that if the probability exceeds a pre-defined threshold, transfer of the file is not permitted ([0046]) and a message can be sent to a user ([0022] & [0043]). Borup does not specify the use of two different thresholds.
Jakobsson discloses analyzing messages and comparing risk scores to a first threshold and a second threshold, such that different remedial actions are performed when the risk score is above the first threshold and second threshold respectively (Col. 19, line 52 – Col. 20, line 16) such that one of the remedial actions could be sending the message to a unit that “scrubs” the message (Col. 19, lines 55-59), which meets the limitation of wherein the second remedial action includes removing sensitive content from the outbound electronic message. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the analysis of Borup to have utilizes multiple thresholds in order to provide different response types to different levels of identified security risks as suggested by Jakobsson (Col. 29, lines 29-53).
Allowable Subject Matter
Claims 8-14 are allowed.
Claims 3, 16, 17 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Subramanian, U.S. Patent No. 10,523,609, discloses that analysis of email messages for suspicious objects.
Rogynskyy, U.S. Publication No. 2019/0361918, discloses the analysis of email message to determine the probability of activities.
Black, U.S. Publication No. 2006/0075228, discloses that real time protection of sensitive information in documents.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN E LANIER whose telephone number is (571)272-3805. The examiner can normally be reached M-Th: 5:30-4:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BENJAMIN E LANIER/ Primary Examiner, Art Unit 2437