DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is a Non-Final Office Action in response to the communication filed on February 03, 2025.
Claims 1-20 have been examined.
Drawings
The drawings filed on February 03, 2025 are acceptable for examination proceedings.
Priority
Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). The certified copy has been filed in parent Application No. 19/169569, filed on February 03, 2025.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on February 03, 2025 was filed after the mailing date of the application 19/169569, filed on February 03, 2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Liu et al. (Chinese Patent Application Publication No.: CN 105471882 A / or “Liu” hereinafter).
Regarding claim 1, Liu discloses “A method for eliminating duplicate correlation chains of events during detection of information security incidents, comprising” (Abstract: method and device of network attack detection based on the behavior characteristics of the network attack; and Page 4: lines 34-35):
“receiving information from a plurality of computers in the network” (Abstract: collecting original security information from various safety device);
“generating an event based on the received information, wherein each generated event contains attributes” (Page 4: lines 38-40, producing from the original security information security event i.e., a “event”; and see also Abstract);
“identifying at least one correlation chain [i.e., “a correlation chain is constructed contain at least an IP address/MAC address identifying the computer 110 from which the event originated, the event type, and a timestamp” (see, Applicant’s specification, Para 0049: last few lines)] in a database, wherein, for the first event of each identified correlation chain, attributes are set based on a corresponding correlation rule” (Page 4: lines 38-40, the original security information is converted into a unified format i.e., a “correlation chain” where at least one field i.e., “attributes” contains time field, type field, IP address field etc. and Page 4: lines 44-48: where the security events are associated with rule base i.e., a “corresponding correlation rule”);
“comparing the generated event with the first event from each identified correlation chain, including determining the similarity of attributes, and further comprising: merging an event with a correlation chain if the generated event is a duplicate event for the first event in the correlation chain” (Page 5: lines 20-21, the security event is merged with a cluster if similar security event is detected),
“and creating a new correlation chain if the attributes of the generated event are not similar to the attributes of the first event in the correlation chain” (Page 5: lines 21-22, the security event is a new security event a new cluster i.e., a “new correlation chain” is created).
Regarding claim 2, in view of claim 1, Liu discloses “wherein if the attributes of the generated event are not similar to the first event from at least one correlation chain, then comparing the generated event with subsequent events from each identified correlation chain using other correlation rules” (Page 7: lines 11-21, “Sorting the different types of security events that have the same source IP address and destination IP address and occurred within a monitoring period according to the order of the event generation time to obtain the security event combination; find out whether there are the same security events in the security event association rule base combination, if there is, it is considered that the host corresponding to the destination IP address has been attacked and an alarm will be issued. If not, store these security events in the association rule mining database”).
Regarding claim 3 in view of claim 2, Liu discloses “wherein, if the generated event corresponds to the next event from at least one correlation chain, according to the correlation rule, then adding the generated event to the corresponding correlation chain” (Page 5: lines 20-21, the security event is merged with a cluster if similar security event is detected).
Regarding claim 4 in view of claim 3, Liu discloses “wherein, if the correlation chain corresponds with the correlation rule, an information security incident is identified” (Page 7: lines 23-27, “For example, it is found that during a monitoring period for the same source IP address and the same destination IP address, Type A security events, Type B security events, and Type C security events occurred sequentially; and there is such an association rule in the association rule base: rule1→rule2 →rule3. If the received type A security event matches rule1 in the rule, type B security event matches rule2, and type C security event matches rule3, it is determined that the host corresponding to the target IP address has suffered a combination of attacks and an alarm is issued”).
Regarding claim 5, in view of claim 1, Liu discloses “wherein the information from the computers in the network includes at least information about an unauthorized network connection, registration of a new device on the network, disconnection of the sensor or controller, and/or unauthorized access to the computer” (Page 4: lines 19-25, the behavior data i.e., the “information” may include honey pot technology, intrusion detection technology etc.).
Regarding claim 6, in view of claim 1, Liu discloses “wherein the similarity of the event attributes is determined according to the correlation rule during a timeout” (Page 4: lines 44-48, monitoring period for security events are utilized).
Regarding claim 7, in view of claim 1, Liu discloses “wherein the attributes of the event comprise at least a source of the event, a type of event, and/or a timestamp” (Page 4: lines 38-40, the original security information is converted into a unified format i.e., a “correlation chain” where at least one field i.e., “attributes” contains time field, type field, IP address field etc.).
Regarding claim 8, in view of claim 7, Liu discloses “wherein the sources of the event includes the security features installed on the computers and/or the security software” (Page 5: lines 50-56, the source of the events could be “…firewall, an intrusion detection system, a vulnerability library, antivirus software, and a host monitoring system”).
Regarding claim 9, claim 9 is directed to a system corresponding to the method recited in claim 1. Claim 9 is similar in scope to claim 1, and is therefore, rejected under similar rationale.
Regarding claim 10, claim 10 is directed to a system corresponding to the method recited in claim 2. Claim 10 is similar in scope to claim 2, and is therefore, rejected under similar rationale.
Regarding claim 11, claim 11 is directed to a system corresponding to the method recited in claim 3. Claim 11 is similar in scope to claim 3, and is therefore, rejected under similar rationale.
Regarding claim 12, claim 12 is directed to a system corresponding to the method recited in claim 4. Claim 1 2is similar in scope to claim 4, and is therefore, rejected under similar rationale.
Regarding claim 13, claim 13 is directed to a system corresponding to the method recited in claim 5. Claim 13 is similar in scope to claim 5, and is therefore, rejected under similar rationale.
Regarding claim 14, claim 14 is directed to a system corresponding to the method recited in claim 6. Claim 14 is similar in scope to claim 6, and is therefore, rejected under similar rationale.
Regarding claim 15, claim 15 is directed to a system corresponding to the method recited in claim 7. Claim 15 is similar in scope to claim 7, and is therefore, rejected under similar rationale.
Regarding claim 16, claim 16 is directed to a system corresponding to the method recited in claim 8. Claim 16 is similar in scope to claim 8, and is therefore, rejected under similar rationale.
Regarding claim 17, claim 17 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 1. Claim 17 is similar in scope to claim 1, and is therefore, rejected under similar rationale.
Regarding claim 18, claim 18 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 2. Claim 18 is similar in scope to claim 2, and is therefore, rejected under similar rationale.
Regarding claim 19, claim 19 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 3. Claim 19 is similar in scope to claim 3, and is therefore, rejected under similar rationale.
Regarding claim 20, claim 20 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 4. Claim 20 is similar in scope to claim 4, and is therefore, rejected under similar rationale.
Relevant Prior Arts
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Freitas et al. (US 20260006048 A1) discloses “… alerts are correlated based on shared attributes, such as an IP address, username, or session identifier. Correlations may be filtered based on domain knowledge and threat intelligence. The remaining correlations are used to construct a graph that represents an incident. Alerts are represented in the graph as vertices while correlations are represented as edges. The graph is pruned of redundant correlations, resulting in a streamlined representation of the incident”. (Abstract).
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULLAH ALMAMUN whose telephone number is (571) 270-3392. The examiner can normally be reached on 8 AM - 5 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ABDULLAH ALMAMUN/Examiner, Art Unit 2431
/JEREMIAH L AVERY/Primary Examiner, Art Unit 2431