Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1-2, 12-13 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Wuest (US 2025/0200175)
Regarding Claim 1,
Wuest (US 2025/0200175) teaches a method for detecting network incidents, the method comprising:
receiving outputs from a plurality of artificial intelligence (Al) models analyzing a plurality of network operation streams, wherein the plurality of Al models are respectively trained to detect suspicious events corresponding to a potential type of network incident in a respective network operation stream and to output an alert when a suspicious event is detected (Fig. 1, teaches tuned models 122a, 122b, 122c);
determining, from the outputs of the plurality of Al models, a plurality of suspicious events that are associated with an entity (Paragraph [0054] teaches detecting features that are associated with suspicious behavior)(Paragraph [0046] teaches determining potential anomalies)
calculating a probability that two or more of the plurality of suspicious events associated with the entity occurred randomly; and outputting an alert based on the probability (Paragraph [0046] teaches generating an alert if threat risk exceeds a threshold)
Regarding Claim 2,
Wuest teaches the method of claim 1, further comprising creating an ordered list of suspicious events for use in calculating the probability by ordering the plurality of suspicious events associated with the entity based on a time of respective suspicious events (Fig. 2, teaches an ordered list of suspicious events, Application AAA launched…File BBB read…, wherein each event has a time “12:23 PM” “12:25 PM”).
Regarding Claims 12-13,
Claims 12-13 are similar in scope to Claim 1 and are rejected for a similar rationale.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 3, 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wuest in view of Ivanov (US 11,928,243)
Regarding Claim 3,
Wuest teaches the method of claim 2, but does not explicitly teach further comprising filtering the ordered list of suspicious events by: accessing a dictionary of suspicious event pairs; and filtering the ordered list of suspicious events to determine pairs of suspicious events that match suspicious event pairs in the dictionary, wherein the probability is calculated based on the suspicious events that match suspicious event pairs in the dictionary
Ivanov (US 11,928,243) teaches filtering the ordered list of suspicious events by: accessing a dictionary of suspicious event pairs (Col. 11, lines 44-60, teaches an ordered list of suspicious event pairs); and filtering the ordered list of suspicious events to determine pairs of suspicious events that match suspicious event pairs in the dictionary (Col. 11, lines 61-65, teaches identifying scripts containing hacking activity), wherein the probability is calculated based on the suspicious events that match suspicious event pairs in the dictionary (Col. 4, lines 18-23, teaches likelihood script is associated with hacking activities exceeds a threshold)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Wuest with the matching of suspicious events as taught by Ivanov and the results would be predictable (i.e. the suspicious of events in Wuest would be filtered by accessing suspicious event pairs to determine probability malicious activity)
Regarding Claim 14,
Claim 14 is similar in scope to Claim 3 and is rejected for a similar rationale.
Claim(s) 5-7, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wuest in view of Ivanov (US 11,928,243) in view of Sinha (US 2024/0364725)
Regarding Claim 5,
Wuest and Ivanov teaches the method of claim 3, but does not explicitly teach wherein calculating the probability is based on a time of occurrence between a pair of suspicious events.
Sinha (US 2024/0364725) teaches wherein calculating the probability is based on a time of occurrence between a pair of suspicious events (Paragraph [0030[ teaches average time differences between requests, differences in patterns are analyzed to detect attacks)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Wuest and Ivanov to include determining probability is based on time of occurrence between events and the results would be predictable (i.e. probability is based on the time of occurrence between events)
Regarding Claim 6,
Wuest, Ivanov and Sinha teaches the method of claim 5. Sinha teaches wherein a mean time-delta of known network incidents having two event types corresponding to the pair of suspicious events is calculated by accessing a database storing suspicious events and timing information for known incidents, and wherein the probability is calculated based on the time of occurrence between the two suspicious events and the mean time- delta (Paragraph [0030] teaches mean time delta (i.e. average time difference between requests)
Regarding Claim 7,
Wuest, Ivanov and Sinha teaches the method of claim 6, but does not explicitly teach wherein the probability is calculated using an exponential cumulative distribution function.
The Examiner takes Official Notice that exponential cumulative distribution functions are well known in the art and it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the prior art to use an exponential cumulative distributive function and the results would be predictable (i.e. probability would be calculated using the function)
Regarding Claim 15,
Claim 15 is similar in scope to Claim 6 and is rejected for a similar rationale.
Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wuest in view of Guo (US 9,166,997)
Regarding Claim 8,
Wuest teaches the method of claim 1, but does not explicitly teach further comprising calculating a surprise score based on the probability that the two or more of the plurality of suspicious events occurred randomly, and outputting the alert when the surprise score exceeds a threshold value.
Guo (US 9,166,997) teaches calculating a surprise score based on the probability that the two or more of the plurality of suspicious events occurred randomly, and outputting the alert when the surprise score exceeds a threshold value (Col. 2, lines 1-7, teaches calculating that the probability of suspicious events is random (i.e. benign))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Wuest with the scoring method of Guo and the results would be predictable (i.e. the surprise score exceeding a threshold indicates benign events)
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wuest
Regarding Claim 9,
Wuest teaches the method of claim 1, but does not explicitly teach wherein the alert is output when the probability is lower than a threshold value.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Wuest to output an alert with the probability of randomness is lower than a threshold value and the results would be predictable (i.e. the threshold for alarm would be lower)
Claim(s) 10-11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wuest in view of Yuan (US 2025/0156653)
Regarding Claims 10-11,
Wuest teaches the method of claim 1, but does not explicitly teach wherein the plurality of suspicious events associated with the entity is represented as an ordered graph
converting the ordered graph to a textual format;
generating a template based on nodes present in the ordered graph;
customizing a prompt for inputting to a large language model (LLM) to summarize the ordered graph, wherein the prompt is customized based on the template;
and prompting the LLM to generate a summary report of the two or more suspicious events using the textual format of the ordered graph.
Yuan (US 2023/0156653) teaches converting the ordered graph to a textual format;
generating a template based on nodes present in the ordered graph;
customizing a prompt for inputting to a large language model (LLM) to summarize the ordered graph, wherein the prompt is customized based on the template;
and prompting the LLM to generate a summary report (Paragraph [0044-0045] teaches using “graph data-to-text conversion methods to convert the key knowledge subgraph to text, wherein the text can represent key knowledge in a prompt template that the system can provide to the LLM”, wherein LLM provides a response to the query)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the suspicious events of Wuest to be represented as an ordered graph and converted to a text form and prompting an LLM to generate a response to the query and the results would be predictable (i.e. the two or more suspicious events would be converted from graph to text and an LLM would summarize the graph using the textual format of the ordered graph)
Regarding Claim 16,
Claim 16 is similar in scope to Claim 11 and is rejected for a similar rationale.
Allowable Subject Matter
Claim 4 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARRIS C WANG whose telephone number is (571)270-1462. The examiner can normally be reached M-F 9:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HARRIS C WANG/Primary Examiner, Art Unit 2439