The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office action is in response to communications filed on 4/11/2025.
Claims 1-17 are pending.
DETAILED ACTION
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 13, 15, and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bowers et al. (US 8813234 B1, hereinafter Bowers) in view of Christian (US 20200204574 A1).
Regarding claim 13, Bowers discloses a method for data protection in a distributed network (col. 2, lines 50-59, "an information processing system 100 configured with functionality for graph-based deterrence of persistent security threats in an illustrative embodiment of the invention. The system 100 in this embodiment comprises target information technology (IT) infrastructure 102 that is coupled to an additional processing device 104, which may comprise a separate computer or server. The IT infrastructure 102 of system 100 is the target of an APT or other persistent security threat from an attacker associated with one or more attacker devices 106"), the method comprising:
initiating a network flow analysis (col. 8, lines 6-9, "a minimum cut of the graph is computed. This computation can be performed using any of a number of different known minimum cut algorithms, such as the Edmonds-Karp algorithm"; col. 4, lines 14-21, "a graph generation module 126 which forms a graph that is representative of a particular persistent security threat, a minimum cut computation module 128 which computes a minimum cut of the graph, and a defensive strategy selection module 130 that determines an appropriate defensive strategy for protecting the IT infrastructure 102 against the persistent security threat based on a computed minimum cut"), wherein the network flow analysis comprises the steps of:
assigning specialized access nodes of a network diagram comprising nodes predetermined to have specialized access (col. 8, lines 33-40, "implementation of the various defenses that were associated with the defensive costs assigned to the respective edges that are removed from the graph by the minimum cut. More particularly, we have determined that an optimal defensive strategy for the enterprise in certain embodiments of the invention is to deploy the defenses along the minimum cut of the graph within the constrained budget"; col. 7, lines 15-17, "The log analysis defense 322 may involve an analysis of event logs to determine correlation among certain events and thereby facilitate attack detection");
executing a first cut, wherein the first cut removes predetermined nodes at edges to isolate first specialized access nodes (col. 4, lines 14-18, "a graph generation module 126 which forms a graph that is representative of a particular persistent security threat, a minimum cut computation module 128 which computes a minimum cut of the graph"; col. 5, lines 64-66, "deploy the appropriate defenses along particular edges in the graph, with each such defense removing one or more edges"; col. 8, lines 6-9, "a minimum cut of the graph is computed. This computation can be performed using any of a number of different known minimum cut algorithms, such as the Edmonds-Karp algorithm"; col. 8, lines 25-28, "The computation of the minimum cut in step 204 will identify those edges of the graph that if removed will prevent the attacker from advancing to the target node at the lowest defensive costs"; col. 8, lines 33-40, "implementation of the various defenses that were associated with the defensive costs assigned to the respective edges that are removed from the graph by the minimum cut. More particularly, we have determined that an optimal defensive strategy for the enterprise in certain embodiments of the invention is to deploy the defenses along the minimum cut of the graph within the constrained budget" - that is, the defenses are isolated because they are placed in the network segment that removed the identified edges);
Bowers does not disclose that the data protection is via reconstruction and analysis of data segments; assigning indicators to specialized access nodes; capturing a first plurality of electronic communications at the first specialized access nodes, wherein each of the first plurality of electronic communications comprises a corresponding discrete data segment; and storing the corresponding discrete data segments for each of the first plurality of electronic communications in a first storage device; constructing a first arrangement of a selected group of the corresponding discrete data segments; determining a presence of sensitive information based on the first arrangement using a sensitive information detection engine; storing in a second storage device, for a predetermined length of time, a suspect electronic communication when the sensitive information detection engine determines the presence of sensitive information; and executing, subsequent the predetermined length of time, one selected from the group consisting of: (i) returning the suspect electronic communication to a source and (ii) completing a transfer of the suspect electronic communication to a destination.
Christian discloses that the data protection is via reconstruction and analysis of data segments (¶[0033], "a user session may be reconstructed from its corresponding packets, for the purpose of analysis");
assigning indicators to specialized access nodes (¶[0091], "data surveillance system 100 of FIG. 1 first establishes a baseline 120 of data 130 against which it compares subsequent portions or the entirety of data 130 as it flows in and out computer network 108"; ¶[0173], "Once the master has established the baseline, it then communicates the baseline to all the agents on the network"; ¶[0174], "Once the agents have received the updated baseline, they then score the network packets against the baseline and issue any alerts or notifications as needed"; ¶[0229], "system determines what is “normal” for packets of data on network 514 for systems 504A, 504B, . . . . It stores its baseline data corresponding to conceptual hypercubes 180A, 180B, . . . for baselines 120A, 120B"; ¶[0230], "if a file belonging to partner A from database 506A has a close enough hash/signature to a data packet on network 514 that originated from a user of partner A not authorized to access the file, then this is flagged as a security event in ledger 526 per above teachings");
capturing a first plurality of electronic communications at the first specialized access nodes, wherein each of the first plurality of electronic communications comprises a corresponding discrete data segment (¶[0116], "data analysis module 112 (see FIG. 1), detects that a user 1020 has a sudden spike in the number of received video data packets"; ¶[0136], "packet data being captured and monitored by the system" - packets are known in the art and they comprise discrete data segments); and
storing the corresponding discrete data segments for each of the first plurality of electronic communications in a first storage device (¶[0181], "the master receives all incoming packets from the agents and builds/establishes the rolling baseline"; ¶[0107], "each packet is thus analyzed and clustered");
constructing a first arrangement of a selected group of the corresponding discrete data segments (¶[0107], "Over time, the packets are thus clustered form various populations or clusters of packets. After a sufficient number of packets have been clustered, the cluster with the highest density of clustered packets is determined to be the centroid of a conceptual n-dimensional “hypercube” of data 130");
determining a presence of sensitive information based on the first arrangement using a sensitive information detection engine (¶[0174], "Once the agents have received the updated baseline, they then score the network packets against the baseline and issue any alerts or notifications as needed"; ¶[0230], "if a file belonging to partner A from database 506A has a close enough hash/signature to a data packet on network 514 that originated from a user of partner A not authorized to access the file, then this is flagged as a security event in ledger 526 per above teachings"; ¶[0174], "Once the agents have received the updated baseline, they then score the network packets against the baseline and issue any alerts or notifications as needed. The reader is referred to Eq. (1) above and related teachings for the scoring or distance calculation, including CTPH distance/similarity calculation, of the packets against the baseline. More specifically, each agent scores the network packets sent/received by the device against the centroid of the latest baseline received from the master. If the distance of a packet from the centroid is large enough, or differently stated, an anomaly is detected by the agent based on the score/distance of the packet, an appropriate alert is generated by the agent per prior teachings"; ¶[0152], "CTPH edit distance/similarity between packets is used to identify and prevent exfiltration of sensitive data");
storing in a second storage device, for a predetermined length of time, a suspect electronic communication when the sensitive information detection engine determines the presence of sensitive information; and executing, subsequent the predetermined length of time, one selected from the group consisting of: (i) returning the suspect electronic communication to a source and (ii) completing a transfer of the suspect electronic communication to a destination (alternate limitations that can be met by the combination when presence of sensitive information is not determined).
Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Bowers and Christian to arrive at a system in which the data protection is via reconstruction and analysis of data segments; assigning indicators to specialized access nodes; capturing a first plurality of electronic communications at the first specialized access nodes, wherein each of the first plurality of electronic communications comprises a corresponding discrete data segment; and storing the corresponding discrete data segments for each of the first plurality of electronic communications in a first storage device; constructing a first arrangement of a selected group of the corresponding discrete data segments; determining a presence of sensitive information based on the first arrangement using a sensitive information detection engine; storing in a second storage device, for a predetermined length of time, a suspect electronic communication when the sensitive information detection engine determines the presence of sensitive information; and executing, subsequent the predetermined length of time, one selected from the group consisting of: (i) returning the suspect electronic communication to a source and (ii) completing a transfer of the suspect electronic communication to a destination.
One of ordinary skill in the art would have been motivated because it would enable detection of "a large variety of security issues, including data intrusions, data exfiltration/theft, data loss/leak, steganographic attempts, etc." (Christian, ¶[0040]).
Regarding claim 15, the combined teachings of Bowers and Christian disclose the invention substantially as applied to claim 13, above, wherein the method further comprises: constructing a second arrangement of the selected group of the discrete data segments (Christian, ¶[0111], "“rolling” or “evolving” of baseline 120 allows the instant technology to automatically learn from data and calibrate itself. It does this by adapting to what is now considered normal and what types of data packets to raise a security or performance alert on"; ¶[0112], "The evolution of the baseline is also sometimes referred to as “centroid drift” because of the movement of the centroid of the data. In an interesting scenario, a hypercube may have a split centroid, with two or more almost equally dense populations of data. In such a situation, data analysis module 112 of FIG. 1 will choose any one of the centroid for baseline 120. Furthermore, such a situation is most often resolved as packets continue to get analyzed and clustered and one of the populations takes over in density to assume the role of the centroid"); and
determining the presence of sensitive information based on the second arrangement using the sensitive information detection engine (Christian, ¶[0179], "a master component/software running on master device 402 and transmitting/communicating rolling baseline 406 along with its centroid of normal population of the above teachings to devices 404A, 404B, . . . , 404N and more specifically to respective agents Agent-1, Agent-2, . . . , Agent-N running on these devices"; ¶[0113], "Employing the dynamic or rolling baseline technology of the instant technology taught herein, a system may continuously and automatically evolve or calibrate its definitions of a threat and normal data. This is crucial in the highly dynamic threat environment of today's networks that are constantly exposed to external as well as internal threats from potentially rogue admins or employees. Knowledge from these updated “learned data-sets” allows a computer network of the present techniques to automatically stay up-to-date with respect to various security threats, particularly of data theft/exfiltration types"; ¶[0181], "the agents score their packets against the baseline received from the master"; ¶[0189], "the new master “re-syncs” with the agents by communicating them the newly established rolling baseline").
Regarding claim 17, the combined teachings of Bowers and Christian disclose the invention substantially as applied to claim 13, above.
Bowers does not disclose that the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device.
Christian discloses the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device (¶[0115], "The data surveillance system 100 of the instant design is thus a hybrid system for detecting exfiltration attacks as well as other security/performance issues in computer network 108, comprising both unsupervised and supervised machine learning components"; ¶[0151], "both supervised and unsupervised machine learning may be used to learn the behavior of the environment and evolve the baseline. Initially, the unsupervised learning using techniques such as k-means clustering of Eq. (1) above may be used to find the location of the centroid. Then human inputs or labels may be provided to adjust the scores of the packets or to assign scores to completely new unknowns, thus forming the supervised component of machine learning."; ¶[0143], "An embodiment of the design uses trained datasets of known anomalous behavior and security/data attacks for packet/session analysis, utilizing prebuilt datasets or signatures for known anomalies of data, especially protocols and packet contents. In an analogous fashion, another embodiment preferably uses traffic trace patterns or datasets and respective known signatures, while still preferably, any combination of both the above datasets may be used"; ¶[0172], "The master device receives the packets from all the agents in the network. It then develops a rolling baseline").
Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bowers in view of Christian so that the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device.
One of ordinary skill in the art would have been motivated because it "allows the system to stay operational while requiring minimal input from a human user/admin" (Christian, ¶[0113]).
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-2, 4, 7-8, 10, 13-14, and 16 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 3-4, 9, 10, and 15-16 of U.S. Patent No. 12,363,176 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because, for example:
PNG
media_image1.png
200
400
media_image1.png
Greyscale
Claims 2, 4, 7-8, 10, 13-14, and 16 are similarly disclosed by claims 3-4, 9, 10, and 15-16 of U.S. Patent No. 12,363,176 B2.
Claims 3, 6, 9, 12, 15, and 17 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 3, 9, and 15 of U.S. Patent No. 12,363,176 B2 in view of Christian (US 20200204574 A1).
Regarding claim 3, U.S. Patent No. 12,363,176 B2 discloses the system of claim 1 (Claim 3).
Claim 3 of U.S. Patent No. 12,363,176 B2 does not disclose constructing a second arrangement of the selected group of the discrete data segments; and determining the presence of sensitive information based on the second arrangement using the sensitive information detection engine.
Christian discloses constructing a second arrangement of the selected group of the discrete data segments; and determining the presence of sensitive information based on the second arrangement using the sensitive information detection engine (¶[0111], "“rolling” or “evolving” of baseline 120 allows the instant technology to automatically learn from data and calibrate itself. It does this by adapting to what is now considered normal and what types of data packets to raise a security or performance alert on"; ¶[0112], "The evolution of the baseline is also sometimes referred to as “centroid drift” because of the movement of the centroid of the data. In an interesting scenario, a hypercube may have a split centroid, with two or more almost equally dense populations of data. In such a situation, data analysis module 112 of FIG. 1 will choose any one of the centroid for baseline 120. Furthermore, such a situation is most often resolved as packets continue to get analyzed and clustered and one of the populations takes over in density to assume the role of the centroid").
Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Claim 3 of U.S. Patent No. 12,363,176 B2 and Christian to arrive at a system for constructing a second arrangement of the selected group of the discrete data segments; and determining the presence of sensitive information based on the second arrangement using the sensitive information detection engine.
One of ordinary skill in the art would have been motivated because it would enable detection of "a large variety of security issues, including data intrusions, data exfiltration/theft, data loss/leak, steganographic attempts, etc." (Christian, ¶[0040]).
Regarding claim 6, U.S. Patent No. 12,363,176 B2 discloses the system of claim 1 (Claim 3).
Claim 3 of U.S. Patent No. 12,363,176 B2 does not disclose wherein the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device.
Christian discloses wherein the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device (¶[0115], "The data surveillance system 100 of the instant design is thus a hybrid system for detecting exfiltration attacks as well as other security/performance issues in computer network 108, comprising both unsupervised and supervised machine learning components"; ¶[0151], "both supervised and unsupervised machine learning may be used to learn the behavior of the environment and evolve the baseline. Initially, the unsupervised learning using techniques such as k-means clustering of Eq. (1) above may be used to find the location of the centroid. Then human inputs or labels may be provided to adjust the scores of the packets or to assign scores to completely new unknowns, thus forming the supervised component of machine learning."; ¶[0143], "An embodiment of the design uses trained datasets of known anomalous behavior and security/data attacks for packet/session analysis, utilizing prebuilt datasets or signatures for known anomalies of data, especially protocols and packet contents. In an analogous fashion, another embodiment preferably uses traffic trace patterns or datasets and respective known signatures, while still preferably, any combination of both the above datasets may be used"; ¶[0172], "The master device receives the packets from all the agents in the network. It then develops a rolling baseline").
Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Claim 3 of U.S. Patent No. 12,363,176 B2 and Christian to arrive at a system wherein the sensitive information detection engine comprises a machine learning engine, wherein the machine learning engine is trained using suspect electronic communications in a third storage device.
One of ordinary skill in the art would have been motivated because it "allows the system to stay operational while requiring minimal input from a human user/admin" (Christian, ¶[0113]).
Regarding claim 9, U.S. Patent No. 12,363,176 B2 discloses the computer program product of claim 7 (Claim 9).
The remaining limitations of claim 9 are similar in scope to those of claim 3. Therefore, claim 9 is rejected for the same reasons as set forth in the rejection of claim 3, above.
Regarding claim 12, U.S. Patent No. 12,363,176 B2 discloses the computer program product of claim 7 (Claim 9).
The remaining limitations of claim 12 are similar in scope to those of claim 3. Therefore, claim 12 is rejected for the same reasons as set forth in the rejection of claim 3, above.
Regarding claim 15, U.S. Patent No. 12,363,176 B2 discloses the method of claim 13 (Claim 15).
The remaining limitations of claim 15 are similar in scope to those of claim 3. Therefore, claim 15 is rejected for the same reasons as set forth in the rejection of claim 3, above.
Regarding claim 17, U.S. Patent No. 12,363,176 B2 discloses the method of claim 13 (Claim 15).
The remaining limitations of claim 17 are similar in scope to those of claim 6. Therefore, claim 17 is rejected for the same reasons as set forth in the rejection of claim 6, above.
Claims 5 and 11 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 3 and 9 of U.S. Patent No. 12,363,176 B2 in view of Nenov (US 9692784 B1).
Regarding claim 5, U.S. Patent No. 12,363,176 B2 discloses the system of claim 1 (Claim 3).
Claim 3 of U.S. Patent No. 12,363,176 B2 does not disclose that the specialized access comprises an ability for the specialized access nodes to transfer electronic communication to devices in unrelated computer networks.
Nenov discloses that specialized access comprises an ability for the specialized access nodes to transfer electronic communication to devices in unrelated computer networks (col. 12, lines 36-44, "At step 302, a packet may be received by the security device. The packet may be received via a local network interface (e.g. to a LAN, including a WiFi interface to a wireless LAN) or via an external network interface (e.g. to a WAN, such as the Internet) [...] the security device may determine if the packet is part of an attack attempt or represents an attack attempt"; col. 13, lines 14-17, "the security device may transmit a notification to a computing device of an administrator on the local or external network (e.g. a smart phone, a desktop computer, a management service, etc.)").
Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Claim 3 of U.S. Patent No. 12,363,176 B2 and Nenov to arrive at a system in which the specialized access comprises an ability for the specialized access nodes to transfer electronic communication to devices in unrelated computer networks.
One of ordinary skill in the art would have been motivated because it would enable a human administrator to take actions in order to resolve a potential security problem.
Regarding claim 11, U.S. Patent No. 12,363,176 B2 discloses the computer program product of claim 7 (Claim 9).
The remaining limitations of claim 11 are similar in scope to those of claim 5. Therefore, claim 11 is rejected for the same reasons as set forth in the rejection of claim 5, above.
Allowable Subject Matter
Claims 1-12 would be allowable by overcoming all double patenting rejections set forth above.
Claims 14 and 16 would be allowable by overcoming all double patenting rejections set forth above if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BORIS D GRIJALVA LOBOS whose telephone number is (571)272-0767. The examiner can normally be reached M-F 10:30AM to 6:30PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BORIS D GRIJALVA LOBOS/ Primary Patent Examiner, Art Unit 2496