DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
2. The information disclosure statement(s) (IDS) submitted on 07/06/2026, 01/16/2026, 10/13/2025, and 07/18/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) are being considered by the examiner.
Claim Rejections - 35 USC § 112
3. The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
4. Claims are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
5. Claim 2 recites in a limitation “aggregating metadata of the file, wherein the metadata comprises file size, file extension, file type, or the anomaly score of the file” (emphasis added). Another limitation recites “classifying the aggregated metadata of the file into a bucket of a plurality of buckets based on one or more file characteristics selected from the set of file characteristics, wherein the bucket comprises aggregated metadata of another file” Further, last limitation recites “training the machine learning model using at least the aggregated metadata in the bucket”. It is unclear whether the applicant is trying refer to the metadata of the file, metadata of the other file or the metadata of both files to train the model, and therefore, failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 9 and 16 suffer similar deficiencies and rejected using the same rationale.
Claim Rejections - 35 USC § 103
6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
8. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
9. Claims 1-3, 6, 8-10, 13 15-17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Bhave et al. (US 2018/0307839 A1, hereinafter Bhave) [As disclosed in IDS] in view of Kimayong et al. (US 2023/0179607 A1, hereinafter Kimayong) [As disclosed in IDS].
Regarding Claim 1,
Bhave discloses a computer-implemented method for detecting a ransomware incident in a backup data stream (Bhave: ¶ [0054] method of detecting a ransomware on a backup storage through a two-steps approach by the server manager 120, ¶ [0038] statistical behavior analysis is performed to identify a portion of the backup associated with a statistical anomaly, ¶ [0026] retrieve, from a storage machine 130, a backup of a plurality of files
stored by a client device 110…, statistical behavior analysis is performed on the backup of the plurality of files based on the standard pattern to identify a portion of the backup
corresponding to a statistical anomaly different from the standard pattern, ¶¶ [0037, 0055-0056]), the computer-implemented method comprising:
tracking a byte distribution of a file from the backup data stream (Bhave: : ¶ [0021] the entropy detection is performed to check any randomness in the distribution of bits for a given block of file, ¶ [0026] statistical behavior analysis is performed on the backup of the plurality of files…, entropy score represents a randomness of a distribution of bits in a block of a file in the portion of the backup, ¶ [0050] the entropy detection module 330 restores a block (e.g., 1 Kilobytes) of file, and obtains an entropy of the block to determine whether the block may include ransomwares. Entropy represents a randomness of distribution of bits for a given block of file. Ransomware using block cipher algorithms results in uniform distribution of byte octets (0, 255) with a higher entropy compared to general application file formats having a higher density of ASCII and text separators, ¶ [0051] Shannon Entropy can be computed as below according to Equation (1)…., where S is the Shannon Entropy number between [0, 8], and C is the number of occurrence of the byte in length len of data, ¶ [0049]);
calculating an entropy of the byte distribution of the file, wherein the entropy is reflected by an anomaly score for the file (Bhave: ¶ [0021] the entropy detection is performed to check any randomness in the distribution of bits for a given block of file, ¶ [0049] entropy of a file refers to a measurement of randomness in a given set of values (data) in the file, ¶ [0050] Entropy represents a randomness of distribution of bits for a given block of file. Ransomware using block cipher algorithms results in uniform distribution of byte octets (0, 255) with a higher entropy compared to general application file formats having a higher density of ASCII and text separators, ¶ [0059] entropy score computed for an unencrypted file. FIG. 6B is an example entropy score computed for an encrypted file..., an encrypted file or a potential ransomware may be identified by analyzing the entropy score, ¶¶ [0050-0051]);
mapping the file to a confidence threshold of a plurality of confidence thresholds based on a set of file characteristics of the file (Bhave: ¶ [0051] determining whether the backup includes the ransomware comprises determining whether the backup includes the ransomware, responsive to the entropy score of the block of the file exceeding a threshold entropy value, and MIME information for the file changing from an initial value. The entropy detection module 330 compares an entropy of a block of file with a threshold entropy value. The entropy may be larger than a threshold entropy value…, The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.));
identifying, by a machine learning model, that the file is encrypted by ransomware based on the anomaly score of the file exceeding the confidence threshold (Bhave: ¶ [0051] determining whether the backup includes the ransomware comprises determining whether the backup includes the ransomware, responsive to the entropy score of the block of the file exceeding a threshold entropy value, and MIME information for the file changing from an initial value. The entropy detection module 330 compares an entropy of a block of file with a threshold entropy value. The entropy may be larger than a threshold entropy value…, If the MIME information of the file has later changed from the initial value, the entropy detection module 330 determines that the file is encrypted and the client device may be infected with a ransomware, ¶ [0056] the server manager 120 restores the portion of the backup, and obtains an entropy for the restored portion of the backup. The server manager 120 compares 450 the entropy with a threshold entropy value. If the entropy is larger than the threshold entropy value, and if there is a change in MIME information for the file, then the entropy detection module 330 determines that the file is (or includes) ransomware, ¶ [0059]); and
creating the ransomware incident based on the identifying that the file is encrypted by the ransomware (Bhave: ¶ [0021] the entropy detection is performed to check any randomness
in the distribution of bits for a given block of file, where a high randomness above a threshold in the distribution indicates a possible a ransomware, ¶ [0026] It is determined
whether the backup includes the ransomware based on the generated entropy score. Information is transmitted describing whether the backup includes the ransomware for display on the client device 110, ¶ [0051] If the MIME information of the file has later changed from the initial value, the entropy detection module determines that the file is encrypted and the client device330 determines that the file is encrypted and the client device may be infected with a ransomware, ¶¶ [0047, 0055-0056]).
Bhave does not explicitly disclose:
identifying, by a machine learning model, that the file is encrypted by ransomware based on the anomaly score of the file exceeding the confidence threshold.
However, Kimayong from the same field of endeavor as the claimed invention discloses that the network device may be configured to identify, based on receiving the file stream, an initial portion of the file. The network device may be configured to process the initial portion of the file to determine one or more features of the file. The network device may be configured to generate, based on the one or more features of the file, a determination as to whether the file is malicious (Kimayong: [Abstract]), the network device may parse, read, and/or analyze the header included in the initial portion of the file to determine the one or more features of the file. The one or more features of the file may include, for example, a respective size of one or more sections (e.g., the header, the code section, a security section, a resource section, and/or one or more other sections) of the file, a respective entropy of the one or more sections, a respective virtual address of the one
or more sections, a respective virtual size of the one or more sections, a respective name of the one or more sections, and/or one or more other features of the file (Kimayong: ¶ [0020]), the network device may train the machine learning model based on historical information that includes sets of features of previously received files and/or additional information, such as determinations of maliciousness respectively associated with the sets of features of the previously received files (Kimayong: ¶ [0022], also see ¶ [0031]), and the trained machine learning model 305 may predict a value of not malicious for the target variable of determination (e.g., of maliciousness) for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label or classification or based on the value satisfying or failing to satisfy a threshold), the machine learning system may provide a recommendation and/or output for determination of a recommendation (Kimayong: ¶ [0045]).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Kimayong in the teachings of Bhave. A person having ordinary skill in the art would have been motivated to do so because the machine learning system may perform an automated action and/or may cause an automated action to be performed (e.g., by instructing another device to perform the automated action), such as automatically allowing or allowing the file stream (Kimayong: ¶ [0045]).
Regarding Claim 2,
Claim 2 is dependent on Claim 1, and the combination of Bhave and Kimayong discloses all the limitations of Claim 1. Bhave further discloses aggregating metadata of the file, wherein the metadata comprises file size, file extension, file type, or the anomaly score of the file (Bhave: ¶ [0049] entropy of a file refers to a measurement of randomness in a given set of values (data) in the file, ¶ [0050] Entropy represents a randomness of distribution of bits for a given block of file, ¶ [0059] entropy score computed for an unencrypted file. FIG. 6B is an example entropy score computed for an encrypted file..., an encrypted file or a potential ransomware may be identified by analyzing the entropy score, ¶ [0051] The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.)); and
classifying the aggregated metadata of the file into a bucket of a plurality of buckets based on one or more file characteristics selected from the set of file characteristics (Bhave: ¶ [0024] data requested to be stored include, but are not limited to, a text file, an image file, a video clip, or any combination thereof, ¶ [0051] The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.) (i.e. different file type categories), ¶¶ [0052-0053]), wherein the bucket comprises aggregated metadata of another file;
Bhave does not explicitly disclose:
classifying the aggregated metadata of the file into a bucket of a plurality of buckets based on one or more file characteristics selected from the set of file characteristics, wherein the bucket comprises aggregated metadata of another file; and
training the machine learning model using at least the aggregated metadata in the bucket.
Kimayong further discloses that the network device may be configured to process the initial portion of the file to determine one or more features of the file. The network device may be configured to generate, based on the one or more features of the file, a determination as to whether the file is malicious (Kimayong: [Abstract]), and the network device may process the one or more features of the file using a machine learning model to generate the determination…, the network device may process at least one of the one or more features of the file to identify a structure
of the file…, the network device may select, based on the structure of the file, a machine learning model (e.g., a machine learning model that has been trained on features of files associated with the same structure) and may process, using the machine learning model, the one or more features of the file to generate the determination (Kimayong: ¶ [0021], ¶¶ [0022, 0039], Fig. 2).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Kimayong in the teachings of Bhave. A person having ordinary skill in the art would have been motivated to do so because the machine learning system may perform an automated action and/or may cause an automated action to be performed (e.g., by instructing another device to perform the automated action), such as automatically allowing or allowing the file stream (Kimayong: ¶ [0045]).
Regarding Claim 3,
Claim 3 is dependent on Claim 1, and the combination of Bhave and Kimayong discloses all the limitations of Claim 1. Bhave further discloses wherein the identifying comprises: evaluating the file for a particular ransomware attack of a set of ransomware attacks (Bhave: ¶ [0050] Entropy represents a randomness of distribution of bits for a given block of file, ¶ [0059] entropy score computed for an unencrypted file. FIG. 6B is an example entropy score computed for an encrypted file..., an encrypted file or a potential ransomware may be identified by analyzing the entropy score, ¶ [0051] The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.)), wherein the set of ransomware attacks comprises in-place encryption ransomware or delete-and-replace ransomware (Bhave: ¶ [0051] the entropy detection module 330 determines that the file is encrypted and the client device may be infected with a ransomware, ¶ [0036] The backup log module 215 is communicatively coupled to the ransomware detection module 230 and stores file activities comprising addition, deletion, and modification of the plurality of files, ¶ [0020]).
Regarding Claim 6,
Claim 6 is dependent on Claim 1, and the combination of Bhave and Kimayong discloses all the limitations of Claim 1. Bhave further discloses wherein the mapping comprises: correlating the file to a resource type using the set of file characteristics, wherein the set of file characteristics comprises file type, file size, file age, file extension, or file usage (Bhave: ¶ [0050] performs a journal walk (i.e., restoring one or more backup cycles) to identify files updated or added in the given restore point. For each file object found, the entropy detection module 330 restores a block (e.g., 1 Kilobytes) of file, and obtains an entropy of the block to determine whether the block may include ransomwares, ¶ [0051] determining whether the backup includes the ransomware, responsive to the entropy score of the block of the file exceeding a threshold entropy value, and MIME information for the file changing from an initial value. The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.), ¶ [0052] the MIME information for a file may include any or all of the following: MIME-Version: 1.0; ContentType: multipart/mixed; boundary ="XXXXboundary text"; This is a multipart message in MIME format. –XXXXboundary text; Content-Type: text/plain, ¶ [0053] determine that MIME information for the file has changed from an initial value); and extracting the confidence threshold corresponding to the resource type (Bhave: ¶ [0051] The threshold value may be predetermined, and may be varied according to a type of the file (text document, image file, etc.)).
Regarding Claim 8,
Bhave discloses a system for detecting a ransomware incident in a backup data stream (Bhave: ¶ [0018] Disclosed embodiments herein are related to a system, a method, and a non-transitory computer readable medium for detecting ransomware through a multistep
approach, e.g., a two-step approach. The system includes a server manager for detecting ransomware, including a server interface to retrieve, from a storage device, a backup of a
plurality of files stored by a client device, ¶ [0054] detecting a ransomware on a backup storage through a two-steps approach by the server manager 120, ¶ [0038] statistical behavior analysis is performed to identify a portion of the backup associated with a statistical anomaly, ¶ [0026] retrieve, from a storage machine 130, a backup of a plurality of files stored by a client device 110…, statistical behavior analysis is performed on the backup of the plurality of files based on the standard pattern to identify a portion of the backup
corresponding to a statistical anomaly different from the standard pattern, ¶¶ [0037, 0055-0056, 0060, 0062]), the system comprising: one or more memories (Bhave: ¶ [0025] the server manager 120 may be a PC, a tablet PC, an STB, a smartphone, an internet of things (IoT) appliance, or any machine capable of executing instructions that specify actions to be taken by that machine. Parts of the server manager 120 may include one or more processing units (e.g., a CPU, a GPU, a DSP, a controller, a state machine, one or more ASICs, one or more RFICs, or any combination of these) and a memory, ¶ [0062]);
at least one processor each coupled to at least one of the memories and configured to perform operations comprising (Bhave: ¶ [0025] the server manager 120 may be a PC, a tablet PC, an STB, a smartphone, an internet of things (IoT) appliance, or any machine capable of executing instructions that specify actions to be taken by that machine. Parts of the server manager 120 may include one or more processing units (e.g., a CPU, a GPU, a DSP, a controller, a state machine, one or more ASICs, one or more RFICs, or any combination of these) and a memory, ¶[0062]): and discloses, in combination with Kimayong, all the limitations of Claim 8 as discussed in Claim 1. Therefore, Claim 8 is rejected using the same rationales as discussed in Claim 1.
Regarding Claim 9,
Claim 9 is dependent on Claim 8, and the combination of Bhave and Kimayong discloses all the limitations of Claim 8. The combination of Bhave and Kimayong discloses all the limitations of Claim 9 as discussed in Claim 2. Therefore, Claim 9 is rejected using the same rationales as discussed in Claim 2.
Regarding Claim 10,
Claim 10 is dependent on Claim 8, and the combination of Bhave and Kimayong discloses all the limitations of Claim 8. The combination of Bhave and Kimayong discloses all the limitations of Claim 10 as discussed in Claim 3. Therefore, Claim 10 is rejected using the same rationales as discussed in Claim 3.
Regarding Claim 13,
Claim 13 is dependent on Claim 8, and the combination of Bhave and Kimayong discloses all the limitations of Claim 8. The combination of Bhave and Kimayong discloses all the limitations of Claim 13 as discussed in Claim 6. Therefore, Claim 13 is rejected using the same rationales as discussed in Claim 6.
Regarding Claim 15,
Bhave discloses a non-transitory computer-readable device having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations for detecting a ransomware incident in a backup data stream (Bhave: ¶ [0018] Disclosed embodiments herein are related to a system, a method, and a non-transitory computer readable medium for detecting ransomware through a multistep
approach, e.g., a two-step approach. The system includes a server manager for detecting ransomware, including a server interface to retrieve, from a storage device, a backup of a
plurality of files stored by a client device, ¶ [0054] detecting a ransomware on a backup storage through a two-steps approach by the server manager 120, ¶ [0038] statistical behavior analysis is performed to identify a portion of the backup associated with a statistical anomaly, ¶ [0026] retrieve, from a storage machine 130, a backup of a plurality of files stored by a client device 110…, statistical behavior analysis is performed on the backup of the plurality of files based on the standard pattern to identify a portion of the backup
corresponding to a statistical anomaly different from the standard pattern, ¶¶ [0037, 0055-0056, 0060, 0062]), the operations comprising: and discloses, in combination with Kimayong, all the limitations of Claim 15 as discussed in Claim 1. Therefore, Claim 15 is rejected using the same rationales as discussed in Claim 1.
Regarding Claim 16,
Claim 16 is dependent on Claim 15, and the combination of Bhave and Kimayong discloses all the limitations of Claim 15. The combination of Bhave and Kimayong discloses all the limitations of Claim 16 as discussed in Claim 2. Therefore, Claim 16 is rejected using the same rationales as discussed in Claim 2.
Regarding Claim 17,
Claim 17 is dependent on Claim 15, and the combination of Bhave and Kimayong discloses all the limitations of Claim 15. The combination of Bhave and Kimayong discloses all the limitations of Claim 17 as discussed in Claim 3. Therefore, Claim 17 is rejected using the same rationales as discussed in Claim 3.
Regarding Claim 20,
Claim 20 is dependent on Claim 15, and the combination of Bhave and Kimayong discloses all the limitations of Claim 15. The combination of Bhave and Kimayong discloses all the limitations of Claim 20 as discussed in Claim 6. Therefore, Claim 20 is rejected using the same rationales as discussed in Claim 6.
10. Claims 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Bhave et al. (US 2018/0307839 A1, hereinafter Bhave) [As disclosed in IDS] in view of Kimayong et al. (US 2023/0179607 A1, hereinafter Kimayong) [As disclosed in IDS], and further in view of Kommula et al. (US 2024/0179158 A1, hereinafter Kommula).
Regarding Claim 4,
Claim 4 is dependent on Claim 1, and the combination of Bhave and Kimayong discloses all the limitations of Claim 1. The combination of Bhave and Kimayong does not explicitly disclose wherein the machine learning model comprises a random cut forest model.
However, Kommula from the same field of endeavor as the claimed invention discloses that the instructions cause the network system to obtain second traffic session metrics data and determine an anomaly in traffic based on a comparison of the traffic prediction and the second traffic session metrics data (Kommula: [Abstract]), and Anomaly detection service 632 may be configured to detect any anomalies in the received timeseries telemetry data from multiple layers in the stack. Anomaly detection service 632 may use, for example, an unsupervised learning-based random cut forest (RCF) approach (Kommula: ¶ [0109], also see ¶ [0133]).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Kommula in the teachings of Bhave. A person having ordinary skill in the art would have been motivated to do so because the machine learning system with random cut forest (RCF) can automatically detect any deviation from expected behavior in detecting anomalies in the received timeseries telemetry data (See Kommula: ¶ [0109]).
Regarding Claim 11,
Claim 11 is dependent on Claim 8, and the combination of Bhave and Kimayong discloses all the limitations of Claim 8. The combination of Bhave, Kimayong and Kommula discloses all the limitations of Claim 11 as discussed in Claim 4. Therefore, Claim 11 is rejected using the same rationales as discussed in Claim 4.
Regarding Claim 18,
Claim 18 is dependent on Claim 15, and the combination of Bhave and Kimayong discloses all the limitations of Claim 15. The combination of Bhave, Kimayong and Kommula discloses all the limitations of Claim 18 as discussed in Claim 4. Therefore, Claim 18 is rejected using the same rationales as discussed in Claim 4.
11. Claims 5, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Bhave et al. (US 2018/0307839 A1, hereinafter Bhave) [As disclosed in IDS] in view of Kimayong et al. (US 2023/0179607 A1, hereinafter Kimayong) [As disclosed in IDS], and further in view of Mehta et al. (US 2022/0350886 A1, hereinafter Mehta) [As disclosed in IDS].
Regarding Claim 5,
Claim 5 is dependent on Claim 1, and the combination of Bhave and Kimayong discloses all the limitations of Claim 1. Bhave further discloses wherein the calculating comprises: applying a chi square entropy scoring equation on the byte distribution (Bhave: ¶ [0051] determining whether the backup includes the ransomware comprises determining whether the backup includes the ransomware, responsive to the entropy score of the block of the file exceeding a threshold entropy value, and MIME information for the file changing from an initial value. The entropy detection module 330 compares an entropy of a block of file with a threshold entropy value. The entropy may be larger than a threshold entropy value…, If the MIME information of the file has later changed from the initial value, the entropy detection module 330 determines that the file is encrypted and the client device may be infected with a ransomware).
The combination of Bhave and Kimayong does not explicitly disclose wherein the calculating comprises: applying a chi square entropy scoring equation on the byte distribution.
However, Mehta from the same field of endeavor as the claimed invention discloses that the system may use stealth file reading capabilities to read some portions of the file ( e.g., a few bytes from the start of file, a few bytes from the end of the file, and a few bytes randomly selected from within the file). These small portions can be provided to an artefacts extractor, which computes some mathematical parameters such as (for example), entropy, entropy, Monte Carlo pi, Monte
Carlo pi approximation error, serial correlation coefficient, arithmetic mean, chi square distribution (Mehta: ¶ [0038]), and Chi Square Distribution: If this value is greater than a threshold (usually in the range of 255 to 300) with a lower value of Pi error, this is an indication that the file may be encrypted (Mehta: ¶ [0058], also see ¶¶ [0053, 0059]).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Mehta in the teachings of Bhave. A person having ordinary skill in the art would have been motivated to do so to provide another statistical means for confirming that the detected randomness of the byte distribution is indicative of ransomware.
Regarding Claim 12,
Claim 12 is dependent on Claim 8, and the combination of Bhave and Kimayong discloses all the limitations of Claim 8. The combination of Bhave, Kimayong and Mehta discloses all the limitations of Claim 12 as discussed in Claim 5. Therefore, Claim 12 is rejected using the same rationales as discussed in Claim 5.
Regarding Claim 19,
Claim 19 is dependent on Claim 15, and the combination of Bhave and Kimayong discloses all the limitations of Claim 15. The combination of Bhave, Kimayong and Mehta discloses all the limitations of Claim 19 as discussed in Claim 5. Therefore, Claim 19 is rejected using the same rationales as discussed in Claim 5.
12. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Bhave et al. (US 2018/0307839 A1, hereinafter Bhave) [As disclosed in IDS] in view of Kimayong et al. (US 2023/0179607 A1, hereinafter Kimayong) [As disclosed in IDS], and further in view of Shintre et al. (US 10,015,182 B1, hereinafter Shintre).
Regarding Claim 7,
Claim 7 is dependent on Claim 6, and the combination of Bhave and Kimayong discloses all the limitations of Claim 6. Bhave further discloses calculating an average anomaly score for one or more files correlated to the resource type over a number of previous days (Bhave: ¶ [0042] statistical filtering module 320 may be configured to detect a standard pattern of file activities for a certain time period, ¶ [0055] threshold value may be determined based on the standard pattern, ¶¶ [0043-0047, 0051]).
The combination of Bhave and Kimayong does not explicitly disclose wherein the extracting comprises:
calculating an average anomaly score for one or more files correlated to the resource type over a number of previous days; and
defining the confidence threshold to be within a number of standard deviations from the average anomaly score.
However, Shintre from the same field of endeavor as the claimed invention discloses that protecting computing resources may include (i) computing a degree of commonality between pairs of users within a file sharing system based on which files the users accessed over a period of time, (ii) building a social graph that indicates at least one edge between members of an instance of the pairs of users, (iii) computing an anomaly score for a user within the instance of the pairs of users, (iv) detecting that the anomaly score deviates, according to a statistical measurement, from historical anomaly scores computed for the same user, and (v) performing, in response to detecting that the
anomaly score deviates from the historical anomaly scores (Shintre: [Abstract]), and the mean and
standard deviation have been calculated for both user A and user B. In this example, the sample
standard deviation (as opposed to the population standard deviation, which is another option) has
been calculated on the five measurements, including the Friday value…, and standard deviation calculations and the previous day's calculations (e.g., the mean and standard deviation for the Monday-Thursday values) may be used for comparing against the current value…, “#Stan.Dev.,” indicates the number of standard deviations that the measured value is from the mean (i.e., #Stan.Dev.=Diff. from Mean/Standard Deviation)…, use a threshold value that is defined in terms of 1, 2, 3, or any decimal value N multiplied by the mean, the standard deviation, and/or any other statistical value (according to any suitable algebraic or business logic) (Shintre: [Col. 11 Lines: 20-65], also see Fig. 6).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Shintre in the teachings of Bhave. A person having ordinary skill in the art would have been motivated to do so as an average anomaly score provides a historical baseline against in which a current anomaly score can be compared, thereby providing a more meaningful measurement of deviation from the expected historical behavior.
Regarding Claim 14,
Claim 14 is dependent on Claim 13, and the combination of Bhave and Kimayong discloses all the limitations of Claim 13. The combination of Bhave, Kimayong and Shintre discloses all the limitations of Claim 14 as discussed in Claim 7. Therefore, Claim 14 is rejected using the same rationales as discussed in Claim 7.
Conclusion
13. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US-20200244672-A1
US-20190332769-A1
US-20190235973-A1
US-12657299-B2
US-20210334374-A1
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMEERA WICKRAMASURIYA whose telephone number is (571)272-1507. The examiner can normally be reached on MON-FRI 8AM-4:30PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JUNG W. KIM can be reached on (571)272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAMEERA WICKRAMASURIYA/
Examiner, Art Unit 2494
/JUNG W KIM/Supervisory Patent Examiner, Art Unit 2494