DETAILED ACTION
This communication is responsive to the application # 19/096,234 filed on March 31, 2025. Claims 1-20 are pending and are directed toward PROGRESSIVE AUGMENTATION OF THREAT TIMELINE VISUALIZATION.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Drawings
Figures 1-12 should be designated by a legend such as --Prior Art-- because only that which is old is illustrated. Compare with FIG. 1-7, 11-15 of US 2021/0397738. See MPEP § 608.02(g). Corrected drawings in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. The replacement sheet(s) should be labeled “Replacement Sheet” in the page header (as per 37 CFR 1.84(c)) so as not to obstruct any portion of the drawing figures. If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
The drawings FIG. 13 and 15 are objected to because of poor quality. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being unpatentable over Samosseiko et al. (US 2023/0247048, Pub. Date: Aug. 3, 2023), hereinafter referred to as Samosseiko.
As per claim 1, Samosseiko teaches a computer program product for visualizing threat data (1412-DISPLAY TIMELINE, Samosseiko, FIG.14), the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:
storing event data from an enterprise network in a data lake for long term storage (An event stream of events and related data in the stream service 1104 may be organized using schemas that are stored in a schema registry 1112 or similar resource available to various entities interacting with the stream service 1104 and/or data lake 1108. Samosseiko, [0153]), the data lake organized into a plurality of temporal partitions (While indicated as directly coupled to the threat management facility 1310, the one or more data lakes 1308 may be remotely or locally managed resources configured to store telemetry queries collected from endpoints and servers. Samosseiko, [0182]), and the data lake optimized for long term storage of unstructured data (The transformer 1106 may also or instead transmit transformed event data to the data lake 1108 for long-term storage ( e.g., one week, one month, one year, etc.). Samosseiko, [0156]);
storing a plurality of lineages in a data store for the enterprise network, each of the plurality of lineages associated with a security event detected on an endpoint of the enterprise network (In general, the stream service 1104 may include any suitable event stream processing storage or technology, or any similar hardware and/or software layer suitable for storing, managing, processing, and querying streams of events as contemplated herein, or otherwise supporting event-driven information. Samosseiko, [0155]), wherein the data store is optimized for query performance and short term storage and wherein the data store has a lower query latency than the data lake (In general, the transformer 1106 may transmit transformed event data back to the stream service 1104 for short-term usage (e.g., one hour, one day, seven days, etc.) by the listeners 1110 or high-speed access by the query engine 1114. Samosseiko, [0156]), each lineage including:
an identifier for a process associated with a corresponding one of the security events (For example, the system 300 may usefully implement globally unique device identifiers, user identifiers, application identifiers, data identifiers, Samosseiko, [0080]),
a time stamp for the process (The event vectors 810 may be time stamped or otherwise labeled by the threat management facility 812 to record chronology, Samosseiko, [0114]), and
process data for a plurality of additional processes causally related to the process (The filter 322 may also or instead be configured to report causal information that causally relates collections of events to one another. Samosseiko, [0078]);
receiving an input from a user of a selected lineage from the plurality of lineages (The threat management facility 308 may generally include an application programming interface 310 to third party services 320, a user interface 312 for access to threat management and network administration functions, and a number of threat detection tools 314. Samosseiko, [0071]);
displaying a graphical representation of the selected lineage to the user as a threat timeline visualization (the computer program product may include code that causes the one or more computing devices to perform the step of displaying a timeline of a plurality of indicators of breach from the first and second sets of indicators of breach in a user interface interactively coupled to information about the plurality of indicators of breach. Samosseiko, [0006]); and
progressively updating the threat timeline visualization with data from the data lake (The user interface 1500 may include a timeline 1506 showing a temporal distribution of the indicators of breach. The timeline may show timestamps of the indicators of breach along a selected time frame. The timestamp may be shown to the nearest minute, hour, day, month, or any other suitable unit of time. Samosseiko, [0209]).
As per claim 2, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes periodically querying the data lake for supplemental information related to the selected lineage (Samosseiko, [0057]).
As per claim 3, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes selecting one of the plurality of temporal partitions based on the identifier and the time stamp for the selected lineage and querying the one of the plurality of temporal partitions based on the identifier for the selected lineage (Samosseiko, [0058]).
As per claim 4, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes receiving a user selection of one of the plurality of additional processes in the selected lineage and querying the data lake for supplemental data relating to the one or more of the plurality of additional processes (Samosseiko, [0070]).
As per claim 5, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes progressively updating the threat timeline visualization to include supplemental event data for at least a predetermined time window around a time of the time stamp for the selected lineage (Samosseiko, [0153]).
As per claim 6, Samosseiko teaches the computer program product of claim 1, wherein each lineage in the data store is associated with a corresponding endpoint in the enterprise network, and wherein progressively updating the threat timeline visualization includes progressively updating the threat timeline visualization for the selected lineage with event data from the data lake for one or more other endpoints associated with the enterprise network (Samosseiko, [0152]).
As per claim 7, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of updating the threat timeline visualization with reputation data for at least one of the process and one or more of the plurality of additional processes (Samosseiko, [0048]).
As per claim 8, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of updating the threat timeline visualization with a natural language description of a relationship between the process and one or more of the plurality of additional processes (Samosseiko, [0172]).
As per claim 9, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the steps of: receiving a detection of a threat associated with the selected lineage; generating a natural language explanation of the detection; and updating the threat timeline visualization with the natural language explanation of the detection (Samosseiko, [0172]).
As per claim 10, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of supplementing the threat timeline visualization with one or more low severity detections within a temporal window around a corresponding security event associated with the selected lineage (scoring the plurality of malicious breaches to provide a ranking of severity; and selecting one of the customers for notification based on based on the ranking of severity. Samosseiko, [0009]).
As per claim 11, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of supplementing the threat timeline visualization with a predetermined number of unique events detected on a corresponding one of the endpoints associated with the selected lineage (Samosseiko, FIG. 15).
Claims 12-20 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of anticipation as used above.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims 1-20 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of copending Application No. 19/096,196. Although the conflicting claims are not identical, they are not patentably distinct from each other because all elements of claims 1-20 of the instant application correspond to elements of claims 1-20 of Application No. 19/096, 196. The above claims of the present application would have been obvious over claims 1-20 of Application No. 19/096, 196 because each element of the claims of the present application is anticipated by the claims of the Application No. 19/096, 196 and as such are unpatentable for obviousness-type double patenting (In re Goodman (CAFC) 29 USPQ2D 2010 (12/3/1993)).
Claims 1-20 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of copending Application No. 19/096,152. Although the conflicting claims are not identical, they are not patentably distinct from each other because all elements of claims 1-20 of the instant application correspond to elements of claims 1-20 of Application No. 19/096,152. The above claims of the present application would have been obvious over claims 1-20 of Application No. 19/096,152 because each element of the claims of the present application is anticipated by the claims of the Application No. 19/096,152 and as such are unpatentable for obviousness-type double patenting (In re Goodman (CAFC) 29 USPQ2D 2010 (12/3/1993)).
This is a provisional nonstatutory double patenting rejection.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLEG KORSAK whose telephone number is (571)270-1938. The examiner can normally be reached on 5:00 AM- 4:00 PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/OLEG KORSAK/
Primary Examiner, Art Unit 2492