Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed on 03/10/2026 has been accepted and considered on this office action. Claims 1 and 2 have been amended. No claims have been cancelled. No new claims have been added.
Response to Arguments
Applicant’s arguments, see Remarks, filed on 03/10/2026, with respect to the amended limitations of the independent claims have been considered and are persuasive. Therefore, the outstanding 102 rejection has been withdrawn.
However, upon further consideration, a new ground(s) of rejection is made in view of discovery of new prior art Feng (Feng, L., Guan, X., Guo, S., Gao, Y., & Liu, P. (2004). Predicting the intrusion intentions by observing system call sequences. Computers & Security, 23(3)) as set forth below.
With respect to 101 rejection, Applicant’s arguments have been fully considered but are not persuasive except as to the prior characterization of the claims as software per se.
Applicant’s amendment adding “at least one processor configured to execute instructions stored in non-transitory memory” in claim 1 and “at least one processor executing instructions stored in non-transitory memory” in claim 2 is persuasive to the extent that the amended claims are not treated as software per se. Accordingly, the software per se portion of the prior rejection is withdrawn.
Applicant’s arguments are not persuasive with respect to the rejection that the claims are directed to an abstract idea without significantly more. The examiner did not reject the claims merely because the claims contain the words “software,” “agents,” or “reasoning.” Rather, the amended claims continue to recite mental processes and mathematical concepts, including reasoning, analytical reasoning, Boolean logic, conditional probability distributions, evaluating differences in predicted and observed data, and intrusion identification based on the evaluated difference.
Applicant argues that the amended claim is directed to “failure-driven” model reconstruction mechanism. While the applicant has described an “architecture,” the components of that architecture are themselves abstract. As noted in the specification, page 2-3, the “logic cells” (specification referenced as “Cellular Automata Source”) and “sources” are “discrete, abstract” “systems” modeled after abstract Turing machines. An architecture comprised of an abstract computational model is abstract. Furthermore, the improvement cited by the applicant is an improvement to the accuracy of the Bayesian model, not any improvement to the functioning of a computer or any underlying technology.
Applicant argues that the claims are not mental process because the identification of the intrusion event is during real time monitoring. This argument is not persuasive. The office clarifies that the claims are directed to a mental process because the underlying steps (observing, comparing, updating) are those performed by the human mind. The fact that computer can perform these steps faster or in real time does not change the abstract nature of the process.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention, under the broadest reasonable interpretation, is directed to an abstract idea without significantly more.
Step 1: Statutory Category
Independent claim 1 is drawn to a “cognitive Bayesian reasoning system” including at least one processor configured to execute instructions stored. Accordingly,
claim 1 fall under one of the four categories of statutory subject matter (process/method, machines/products/apparatus, manufactures, and compositions of matter).
Step 2A: Prong 1: Judicial Exception
Under the broadest reasonable interpretation (BRI), claim 1 is directed to an abstract idea.
Claim 1 recites:
agents for performing analysis including at least one reasoning selected from the group consisting of inference reasoning, inductive reasoning, abductive reasoning, deductive reasoning, and causal reasoning (Mental process, a human security analyst receives observations/log entries, the analyst applies mental inference/inductive/abductive/deductive reasoning or casual analysis to the observed changes)
a plurality of simple logic cells configured to implement an operation selected from a group consisting of at least one of "OR", "AND", "NAND (not AND)", "NOR (not OR)", and "X-OR (Exclusive OR)" (Mental process/Mathematical concepts, the analyst uses basic Boolean logic (AND/OR/NAND/NOR/XOR) in their head or on paper with truth table to determine whether the pattern suggests an intrusion)
at least one source for a first data and subsequent data indicative of a state of a monitored system (Mental process, the analyst can receive first data and subsequent data from logs, reports, sensor readings etc.)
wherein the agents, executed by the processor and implemented using the simple logic cells dynamically construct a context-specific model from the first data (Mental process, the analyst uses the first data from logs and reports, and can create table or chart for after-hours server access with information like normal after-hours failed logins are 0-5 per hour; normal outbound data transfer is under 100 MB per hour)
update conditional probability distributions of the model using parameter learning (Mental process/Mathematical concepts, initially an analyst estimates probability of intrusion with 50 failed logins/hour is 60%, after observation the analyst can update it to 80%)
identify, during real-time monitoring of the monitored system, the intrusion event based on a detected difference between predicted data generated by the model and observed data derived from the subsequent data (Mental process, an analyst computes the difference between the predicted data from observed data for failed logins/hour attempts and determine if any intrusion based on the result)
and generate, using the detected amount of difference, a new context-specific model (Mental process, the analyst uses can create table or chart for after-hours server access with information like after-hours failed logins above 20/hour indicate a high-risk intrusion.)
Such reasoning over data to recognize a pattern (intrusion vs. no intrusion) is a mental process and mathematical concepts. See MPEP 2106.04 (a).
With respect to step 2A, prong 2, the additional elements fail to integrate the abstract idea into a practical application. The claim is directed to, or limited to, a technical solution solving a technical problem. They fail to provide an improvement to a technology or the functioning of a computer. See MPEP 2106.04 (d)(1). Instead, the additional elements merely recite, at high level of generality, general purpose computing structure that are used as tools for implementing the abstract idea. The field of uses high-level reasoning, logical operations and unspecified data sources to apply the abstract idea in a particular environment. Thus, the examiner finds the additional elements are mere instructions to implement the judicial exception. See MPEP 2106.05 (a) (e) (f). As, such the examiner must conclude the invention is not integrated into a practical application.
With respect to step 2B, the claim fails to recite significantly more than the abstract idea itself. Similar to the analysis for step 2A, prong 2, the claims fail to provide improvement to a technology of the functioning of a computer. The additional elements, considered individually and as an ordered combination, amounts to no more than: obtaining first data and subsequent data; constructing a model from data; updating probability distribution; comparing predicted data to observed data; identifying an intrusion based on the difference; generating a new model. These are generic computer/mathematical processing steps recited at a high level of generality.
Therefore, the examiner concludes claim 1 is directed to an abstract idea without significantly more.
Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention, under the broadest reasonable interpretation, is directed to an abstract idea without significantly more.
Step 1: Statutory Category
Independent claim 2 is drawn to a “system having self-learning behaviors.” Accordingly,
claim 2 falls under one of the four categories of statutory subject matter (process/method, machines/products/apparatus, manufactures, and compositions of matter).
Step 2A: Prong 1: Judicial Exception
Under the broadest reasonable interpretation (BRI), claim 2 is directed to an abstract idea.
Claim 2 recites:
one or more sensors for obtaining a first data and subsequent data indicative of an intrusion event (Mental process, a human security analyst receives first and subsequent observations/log entries)
a cognitive reasoning system comprising: a plurality of simple logic cells configured for mapping truth, selected from a group consisting of at least one of "OR", "AND", "NAND (not AND)", "NOR (not OR)", and "X-OR (exclusive OR)"; (Mental process/Mathematical concepts, the analyst uses basic Boolean logic (AND/OR/NAND/NOR/XOR) and probabilistic/Bayesian rules in their head or on paper to classify events)
dynamically construct and update an analytical model from the first data (Mental process, the analyst uses the first data from logs and reports, and can create a model that normal outbound traffic is 100MB/hour; After additional observations, the analyst updates the model to account for 150MB/hour during backup period)
perform analytical reasoning comprising at least one of inductive, abductive, deductive, and casual reasoning using the analytical model (Mental process, a human security analyst uses the created table and applies mental inference/inductive/abductive/deductive reasoning or casual analysis to the observed changes)
detect a difference between predicted data and observed data (Mental process, an analyst computes and detect a difference between the predicted data from observed data for failed logins/hour attempts)
generate from the difference between predicted data and observed data a context-specific replacement model (Mental process, the analyst uses can create table or chart for after-hours server access with information like after-hours failed logins above 20/hour indicate a high-risk intrusion.)
wherein upon identifying the intrusion event based on the difference between predicted data and observed data (Mental process, an analyst computes the difference between the predicted data from observed data for failed logins/hour attempts and determine if any intrusion based on the result)
the system publishes a message indicative of the intrusion event (Organizing human activity, an analyst communicates an alert message about intrusion verbally or in writing.)
With respect to step 2A, prong 2, the additional elements fail to integrate the abstract idea into a practical application. The claim is directed to, or limited to, a technical solution solving a technical problem. They fail to provide an improvement to a technology or the functioning of a computer. See MPEP 2106.04 (d)(1). Instead, the additional elements merely recite, at high level of generality, general purpose computing structure that are used as tools for implementing the abstract idea. The field of uses high-level reasoning, logical operations and unspecified data sources to apply the abstract idea in a particular environment. Thus, the examiner finds the additional elements are mere instructions to implement the judicial exception. See MPEP 2106.05 (a) (e) (f). As, such the examiner must conclude the invention is not integrated into a practical application.
With respect to step 2B, the claim fails to recite significantly more than the abstract idea itself. Similar to the analysis for step 2A, prong 2, the claims fail to provide improvement to a technology of the functioning of a computer. The additional elements, considered individually and as an ordered combination, amounts to no more than: collecting data using sensors; applying Boolean logics; constructing/updating a model; reasoning using the model; comparing predicted data to observed data; generating a replacement model; publishing an alert message. These are generic computer/mathematical processing steps recited at a high level of generality.
Therefore, the examiner concludes claim 2 is directed to an abstract idea without significantly more.
Specification
Applicant is reminded of the proper language and format for an abstract of the disclosure.
The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details.
The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 and 2 are rejected under 35 U.S.C. 103 as being unpatentable over Majumdar (US 20200004752 A1) in view of Feng (Feng, L., Guan, X., Guo, S., Gao, Y., & Liu, P. (2004). Predicting the intrusion intentions by observing system call sequences. Computers & Security, 23(3).)
Regarding Claim 1, Majumdar teaches:
A cognitive Bayesian reasoning system to identify an intrusion event comprising (Majumdar, para 104, discloses that agents operate using belief networks which are well known in the art as Bayesian probabilistic models; para 118, 126, 127, Majumdar discloses these agents perform abductive, deductive and inductive reasoning cycles to interpret data and generate hypotheses and prediction. The coordinated multi-agent reasoning process constitute a cognitive reasoning system under Broadest reasonable interpretation; para 125, Majumdar discloses the system being used to identify illicit or harmful behaviors, e.g., identifying rogue traders.);
agents for performing analysis including at least one reasoning selected from the group consisting of inference reasoning, inductive reasoning, abductive reasoning, deductive reasoning, and causal reasoning (Majumdar, para 104 discloses agents are equipped with a reasoning paradigm (belief network, decision tree etc.) or preference function); Majumdar discloses the system utilizes abductive reasoning (para 126) to formulate a working hypothesis based on perceived data, deductive reasoning (para 127) to aggregate and test these hypothesis into a predictive theory; para 118, Fig 9, Majumdar discloses queries can be answered at the lowest layer using inductive, deductive, and abductive reasoning; para 125, Majumdar discloses the causal analysis of identifying rogue traders, the agents are designed to select specific pieces of evidence/evidence signals that are relevant to the user’s requirement of identifying rogue traders. Under the Broadest reasonable interpretation, this process of selecting relevant cause-effect data is fundamental to causal reasoning);
a plurality of simple logic cells configured to implement an operation selected from a group consisting of at least one of "OR", "AND", "NAND (not AND)", "NOR (not OR)", and "X-OR (Exclusive OR)" (Majumdar, para 166 discloses the agents/manager use logical
operators like "OR" and "AND" as part of their percept and similarity computation; para 134, Majumdar discloses (pattern vector) PV can be understood as representing percepts from the point of view of the agent relative to the positions of other agents.);
at least one processor configured to execute instructions stored in non-transitory memory;
and at least one source for a first data and subsequent data indicative of a state of a monitored system (Majumdar, para 112 discloses agents receive information through respective sensors 1020(1)-(3); agents receive data streams 1020(4) - (N) from other agents; para 125, Majumdar discloses the system starts receiving inputs from sources connected to the data sources (e.g., sensors and data streams));
Majumdar does not explicitly teach; However, Feng teaches:
dynamically construct a context-specific model from the first data (Feng, Section 1 discloses first phase of collecting traces of normal behavior and creates a database to characterize normal patterns; Section 2, Feng discloses the network expands with its nodes, which inherently means the model is not static, it is built and grown as data arrives);
update conditional probability distributions of the model using parameter learning (Feng, Section 2.2 discloses the conditional probability distribution (CPDs) are calculated through recursive process every time a new system call is observed (Eq. 6); Examiner interprets, adjusting the CPDs based on observed evidence is the parameter learning, in context of Bayesian networks (abstract));
identify, during real-time monitoring of the monitored system, the intrusion event based on a detected difference between predicted data generated by the model and observed data derived from the subsequent data (Feng, Section 1 discloses identifying an intrusion or anomaly when there is a significant deviation between the monitored activities and the model);
and generate, using the detected amount of difference, a new context-specific model (Feng, Section 2.2 discloses every time the recursive equation (6) is executed, the probability state of the network changes; Section 2, Feng discloses the network expands with its nodes, which inherently means the model is not static, it is built and grown as data arrives; Examiner interprets, the system us effectively generating a new version model at every step.)
It would have been obvious to a person of ordinary skill in the art at the time of invention to modify the system of Majumdar by incorporating Feng’s system to include updating a probabilistic model, detecting deviations between monitored activity and observed activity and detecting intrusion based on such deviations. One would have been motivated to make such modifications on Majumdar’s system to improve prediction accuracy and decision making, enable intrusion detection via deviation analysis in more concrete and measurable way.
Regarding Claim 2, Majumdar teaches:
A system having self-learning behaviors for protection against security intrusions comprising: (Majumdar, para 125 discloses that its agents continually learn evidential signal schemata “learned earlier from a training period”; Majumdar discloses the system being used to identify illicit or harmful behaviors, e.g., identifying rogue traders);
one or more sensors for obtaining a first data and subsequent data indicative of intrusion event (Majumdar, para 112 discloses sensors 1020(1)-(3) and associated data streams 1020(4) - (N) that continuously capture environmental and cybersecurity-related data (para 84, 200), which the agent network uses as evidential input to detect and reason about anomalous/attack behavior);
a cognitive reasoning system comprising (Majumdar, para 104, discloses that agents operate using belief networks which are well known in the art as Bayesian probabilistic models; para 118, 126, 127, Majumdar discloses these agents perform abductive, deductive and inductive reasoning cycles to interpret data and generate hypotheses and prediction. The coordinated multi-agent reasoning process constitute a cognitive reasoning system under Broadest reasonable interpretation);
a plurality of simple logic cells configured for mapping truth, selected from a group consisting of at least one of "OR", "AND", "NAND (not AND)", "NOR (not OR)", and "X-OR (exclusive OR)" (Majumdar, para 166 discloses the agents/manager use logical operators like "OR" and "AND" as part of their percept and similarity computation; para 134, Majumdar discloses (pattern vector) PV can be understood as representing percepts from the point of view of the agent relative to the positions of other agents.);
perform analytical reasoning comprising at least one of inductive, abductive, deductive, and causal reasoning using the analytical model (Majumdar, para 104 discloses agents are equipped with a reasoning paradigm (belief network, decision tree etc.) or preference function); Majumdar discloses the system utilizes abductive reasoning (para 126) to formulate a working hypothesis based on perceived data, deductive reasoning (para 127) to aggregate and test these hypothesis into a predictive theory; para 118, Fig 9, Majumdar discloses queries can be answered at the lowest layer using inductive, deductive, and abductive reasoning; para 125, Majumdar discloses the causal analysis of identifying rogue traders, the agents are designed to select specific pieces of evidence/evidence signals that are relevant to the user’s requirement of identifying rogue traders. Under the Broadest reasonable interpretation, this process of selecting relevant cause-effect data is fundamental to causal reasoning);
Majumdar, para 126 discloses agents acts on perceptions in an abductive process to generate hypothesis, and these hypotheses are revised and aggregated into a deductive theory used to form a prediction (para 127); Majumdar, para 126-129, discloses the agents continuously receive new data and revise hypothesis based on these data changes; para 126, Majumdar discloses agent's task such as "identifying rogue traders" and the response is output as a report to the analyst (para 127)
Majumdar does not explicitly teach; However, Feng teaches:
at least one processor executing instructions stored in non-transitory memory; agents implemented as executable instructions configured to: dynamically construct and update an analytical model from the first data (Feng, Section 1 discloses first phase of collecting traces of normal behavior and creates a database to characterize normal patterns; Section 2, Feng discloses the network expands with its nodes, which inherently means the model is not static, it is built and grown as data arrives);
detect a difference between predicted data and observed data (Feng, Section 1 discloses identifying an intrusion or anomaly when there is a significant deviation between the monitored activities and the model);
and generate from the difference between predicted data and observed data a context-specific replacement model (Feng, Section 2.2 discloses every time the recursive equation (6) is executed, the probability state of the network changes; Section 2, Feng discloses the network expands with its nodes, which inherently means the model is not static, it is built and grown as data arrives; Examiner interprets, the system us effectively generating a new version model at every step.)
wherein, upon identifying the intrusion event based on the difference between predicted data and observed data, the system publishes a message indicative of the intrusion event (Feng, Section 1 discloses identifying an intrusion or anomaly when there is a significant deviation between the monitored activities and the model; Feng, Section 4 discloses issuing a short-term early warning with direct evidence)
It would have been obvious to a person of ordinary skill in the art at the time of invention to modify the system of Majumdar by incorporating Feng’s system to include updating a probabilistic model, detecting deviations between monitored activity and observed activity and detecting intrusion based on such deviations. One would have been motivated to make such modifications on Majumdar’s system to improve prediction accuracy and decision making, enable intrusion detection via deviation analysis in more concrete and measurable way.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIT KHADKA whose telephone number is (703)756-1440. The examiner can normally be reached Monday - Friday, 8:00 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L. Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AMIT KHADKA/Examiner, Art Unit 2432
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432