Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
1. The office action is in response to the communication filed 04/28/2025.
Information Disclosure Statement
2. The information disclosure statements (IDS) submitted on 4/28/2025 & 4/24/2026 were filed after the mailing date of the instant application. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Interpretation
3. The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
4. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f):
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f). The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f). The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) except as otherwise indicated in an Office action.
5. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f), because the claim limitations use a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: “first engines configured to” and “second engine is configured to” in claims 4, 9, 13, and 19.
Because these claim limitations are being interpreted under 35 U.S.C. 112(f), they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have these limitations interpreted under 35 U.S.C. 112(f), applicant may: (1) amend the claim limitations to avoid them being interpreted under 35 U.S.C. 112(f) (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitations recite sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f).
Claim Rejections – 35 USC 103
6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office Action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7. Claims 1-20 are rejected under 35 USC 103 as being unpatentable over Luo et al (CN 111,614,627 A) in view of Manjunath et al (US 2025/0139250).
Regarding claim 1, Luo et al teaches a method implemented by nodes of a network, comprising:
receiving, by a first engine of a node, event data associated with security events from one or more other nodes in the network (Abstract, which discloses a data plane receiving a notification of a monitored detected abnormal flow caused by a DDOS attack);
determining, by the first engine, a subset of data of the event data that meets one or more criteria (pg. 3, lines 4-8, which discloses data parameters indicating the abnormal flow caused by the DDOS attack);
generating, by the first engine, a security signal associated with the subset of data (pg. 3, lines 9-10, which discloses an alarm being generated regarding the detected abnormal flow); and
receiving, by a second engine of the node and from the first engine, the security signal as input (pg. 3, lines 9-15, which discloses the data plane transmitting the alarm to a control plane).
Luo et al does not explicitly teach determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal; and outputting, by the second engine and to a second node within the network, instructions to perform the action.
However, Manjunath et al further teaches determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal (par [0018], lines 10-15, “remediation action”); and
outputting, by the second engine and to a second node within the network, instructions to perform the action (par [0018], lines 10-15, “initiate the remediation action”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al in order to improve resolving detected security events among network nodes by implementing the security feature recommendation engine (as disclosed in fig. 1 of Manjunath et al) because this feature would allow for faster remediation of security events when pre-stored mitigation of matching threats are issued upon a security event with a previously matching pattern being detected.
Regarding claim 2, Luo et al does not explicitly teach wherein the node is included as part of a first level within a swarm system of the network, further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function; and outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data.
However, Manjunath et al further teaches wherein the node is included as part of a first level within a swarm system of the network (par [0010], lines 18-19), further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function (par [0061-00062], “classified the container environment as being critical”); and
outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data (par [0060], lines 7-9).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 1.
Regarding claim 3, Luo et al and Manjunath et al teach the limitations of claim 1.
Luo et al further teaches wherein the specialized type of function comprises one of a pattern matching function, a machine learning function (Abstract, “DDOS machine learning”), heuristic function, a Bayesian function, a neural network function.
Regarding claim 4, Luo et al does not explicitly teach wherein: first nodes within the first level of the swarm system comprise one or more first engines configured to execute a first type of specialized function, and one or more second nodes within the second level of the swarm system comprise one or more first engines configured to execute a second type of specialized function that is different from the first type.
However, Manjunath et al further teaches wherein:
first nodes within the first level of the swarm system comprise one or more first engines configured to execute a first type of specialized function (fig. 2 par [0003], “security feature”), and
one or more second nodes within the second level of the swarm system comprise one or more first engines configured to execute a second type of specialized function that is different from the first type (par [0060], lines 7-9, “different levels of security alerting”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 1.
Regarding claim 5, Luo et al does not explicitly teach wherein the second engine comprises a control plane engine that is configured to execute a level specific computation graph that is selected by an administrator of the network and loaded into the second engine at runtime.
However, Manjunath et al further teaches wherein the second engine comprises a control plane engine that is configured to execute a level specific computation graph that is selected by an administrator of the network and loaded into the second engine at runtime (par [0029], lines 7-14 and par [0070], lines 6-16, which disclose the administrator providing SLA parameters via a remote dashboard/GUI).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al in order to improve resolving detected security events among network nodes by implementing the security feature recommendation engine (as disclosed in fig. 1 of Manjunath et al) because this feature would allow for faster remediation of security events when pre-stored mitigation of matching threats are issued upon a security event with a previously matching pattern being detected.
Regarding claim 6, Luo et al and Manjunath et al teach the limitations of claim 1.
Luo et al further teaches wherein the second engine comprises a control plane engine (Abstract, lines 5-6) and is configured to:
receive one or more inputs via one or more pathways of the network, the one or more inputs including security events (pg. 7, lines 35-39, “feature of DDOS attack”);
perform processing, classification, or filtering of the security events to generate an output (pg. 11, lines 5-10, “classification and detection”);
determine an event type associated with the output (pg. 11, lines 25-33, “characteristics of DDOS attack flow”); and
route the output to a particular first engine within the network based on the event type (pg. 6, lines 12-33, “Unloading the pre-detection function to the data plane”).
Regarding claim 7, Luo et al does not explicitly teach wherein the action comprises one or more of: informing peer nodes or other nodes of the security event; performing a remediation or enforcement action based on a configured policy determined for the security event; accumulating security signals associated with the security event, wherein subsequent security signals received in association with the security event may trigger action at a subsequent time; informing upper layer nodes of the security event; or informing an upper layer controller.
However, Manjunath et al further teaches wherein the action comprises one or more of:
informing peer nodes or other nodes of the security event;
performing a remediation or enforcement action based on a configured policy determined for the security event (par [0018], lines 1-5, “remediation policy”);
accumulating security signals associated with the security event, wherein subsequent security signals received in association with the security event may trigger action at a subsequent time;
informing upper layer nodes of the security event; or
informing an upper layer controller (par [0060], lines 7-9, “different levels of security alerting”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 5.
Regarding claim 8, Luo et al does not explicitly teach wherein the second engine determines the action further based on one or more of: first inputs associated with additional security events from one or more peer nodes; second inputs from one or more nodes associated with a different level within the network; or third inputs from an administrator of the network.
However, Manjunath et al further teaches wherein the second engine determines the action further based one or more of:
first inputs associated with additional security events from one or more peer nodes;
second inputs from one or more nodes associated with a different level within the network (par [0060], lines 6-9, “recommend different levels of security alerting”); or
third inputs from an administrator of the network.
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 5.
Regarding claim 9, Luo et al and Manjunath et al teach the limitations of claim 1.
Luo et al further teaches wherein the second engine is configured to instantiate the first engine at runtime (pg. 2, lines 1-5, “”cross-plane cooperative”).
Regarding claim 10, Luo et al teaches a system comprising:
receiving, by a first engine of a node, event data associated with security events from one or more other nodes in the network (Abstract, which discloses a data plane receiving a notification of a monitored detected abnormal flow caused by a DDOS attack);
determining, by the first engine, a subset of data of the event data that meets one or more criteria (pg. 3, lines 4-8, which discloses data parameters indicating the abnormal flow caused by the DDOS attack);
generating, by the first engine, a security signal associated with the subset of data (pg. 3, lines 9-10, which discloses an alarm being generated regarding the detected abnormal flow); and
receiving, by a second engine of the node and from the first engine, the security signal as input (pg. 3, lines 9-15, which discloses the data plane transmitting the alarm to a control plane).
Luo et al does not explicitly teach one or more processors; and one or more non-transitory computer-readable media that, when executed by the one or more processors, cause the one or more processors to perform operations; determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal; and outputting, by the second engine and to a second node within the network, instructions to perform the action.
However, Manjunath et al further teaches one or more processors (fig. 1, ‘100); and
one or more non-transitory computer-readable media (par [0089]) that, when executed by the one or more processors, cause the one or more processors to perform operations;
determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal (par [0018], lines 10-15, “remediation action”); and
outputting, by the second engine and to a second node within the network, instructions to perform the action (par [0018], lines 10-15, “initiate the remediation action”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al in order to improve resolving detected security events among network nodes by implementing the security feature recommendation engine (as disclosed in fig. 1 of Manjunath et al) because this feature would allow for faster remediation of security events when pre-stored mitigation of matching threats are issued upon a security event with a previously matching pattern being detected.
Regarding claim 11, Luo et al does not explicitly teach wherein the node is included as part of a first level within a swarm system of the network, further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function; and outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data.
However, Manjunath et al further teaches wherein the node is included as part of a first level within a swarm system of the network (par [0010], lines 18-19), further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function (par [0061-00062], “classified the container environment as being critical”); and
outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data (par [0060], lines 7-9).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 10.
Regarding claim 12, Luo et al and Manjunath et al teach the limitations of claim 10.
Luo et al further teaches wherein the specialized type of function comprises one of a pattern matching function, a machine learning function (Abstract, “DDOS machine learning”), heuristic function, a Bayesian function, a neural network function.
Regarding claim 13, Luo et al does not explicitly teach wherein: first nodes within the first level of the swarm system comprise one or more first engines configured to execute a first type of specialized function, and one or more second nodes within the second level of the swarm system comprise one or more first engines configured to execute a second type of specialized function that is different from the first type.
However, Manjunath et al further teaches wherein:
first nodes within the first level of the swarm system comprise one or more first engines configured to execute a first type of specialized function (fig. 2 par [0003], “security feature”), and
one or more second nodes within the second level of the swarm system comprise one or more first engines configured to execute a second type of specialized function that is different from the first type (par [0060], lines 7-9, “different levels of security alerting”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 11.
Regarding claim 14, Luo et al does not explicitly teach wherein the second engine comprises a control plane engine that is configured to execute a level specific computation graph that is selected by an administrator of the network and loaded into the second engine at runtime.
However, Manjunath et al further teaches wherein the second engine comprises a control plane engine that is configured to execute a level specific computation graph that is selected by an administrator of the network and loaded into the second engine at runtime (par [0029], lines 7-14 and par [0070], lines 6-16, which disclose the administrator providing SLA parameters via a remote dashboard/GUI).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al in order to improve resolving detected security events among network nodes by implementing the security feature recommendation engine (as disclosed in fig. 1 of Manjunath et al) because this feature would allow for faster remediation of security events when pre-stored mitigation of matching threats are issued upon a security event with a previously matching pattern being detected.
Regarding claim 15, Luo et al and Manjunath et al teach the limitations of claim 10.
Luo et al further teaches wherein the second engine comprises a control plane engine (Abstract, lines 5-6) and is configured to:
receive one or more inputs via one or more pathways of the network, the one or more inputs including security events (pg. 7, lines 35-39, “feature of DDOS attack”);
perform processing, classification, or filtering of the security events to generate an output (pg. 11, lines 5-10, “classification and detection”);
determine an event type associated with the output (pg. 11, lines 25-33, “characteristics of DDOS attack flow”); and
route the output to a particular first engine within the network based on the event type (pg. 6, lines 12-33, “Unloading the pre-detection function to the data plane”).
Regarding claim 16, Luo et al does not explicitly teach wherein the action comprises one or more of: informing peer nodes or other nodes of the security event; performing a remediation or enforcement action based on a configured policy determined for the security event; accumulating security signals associated with the security event, wherein subsequent security signals received in association with the security event may trigger action at a subsequent time; informing upper layer nodes of the security event; or informing an upper layer controller.
However, Manjunath et al further teaches wherein the action comprises one or more of:
informing peer nodes or other nodes of the security event;
performing a remediation or enforcement action based on a configured policy determined for the security event (par [0018], lines 1-5, “remediation policy”);
accumulating security signals associated with the security event, wherein subsequent security signals received in association with the security event may trigger action at a subsequent time;
informing upper layer nodes of the security event; or
informing an upper layer controller (par [0060], lines 7-9, “different levels of security alerting”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 14.
Regarding claim 17, Luo et al does not explicitly teach wherein the second engine determines the action further based on one or more of: first inputs associated with additional security events from one or more peer nodes; second inputs from one or more nodes associated with a different level within the network; or third inputs from an administrator of the network.
However, Manjunath et al further teaches wherein the second engine determines the action further based one or more of:
first inputs associated with additional security events from one or more peer nodes;
second inputs from one or more nodes associated with a different level within the network (par [0060], lines 6-9, “recommend different levels of security alerting”); or
third inputs from an administrator of the network.
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 14.
Regarding claim 18, Luo et al and Manjunath et al teach the limitations of claim 10.
Luo et al further teaches wherein the second engine is configured to instantiate the first engine at runtime (pg. 2, lines 1-5, “”cross-plane cooperative”).
Regarding claim 19, Luo et al teaches receiving, by a first engine of a node, event data associated with security events from one or more other nodes in the network (Abstract, which discloses a data plane receiving a notification of a monitored detected abnormal flow caused by a DDOS attack);
determining, by the first engine, a subset of data of the event data that meets one or more criteria (pg. 3, lines 4-8, which discloses data parameters indicating the abnormal flow caused by the DDOS attack);
generating, by the first engine, a security signal associated with the subset of data (pg. 3, lines 9-10, which discloses an alarm being generated regarding the detected abnormal flow); and
receiving, by a second engine of the node and from the first engine, the security signal as input (pg. 3, lines 9-15, which discloses the data plane transmitting the alarm to a control plane).
Luo et al does not explicitly teach a non-transitory computer-readable media storing instructions executable by one or more processors of a node, wherein the instructions, when executed, cause the one or more processors to perform operations; determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal; and outputting, by the second engine and to a second node within the network, instructions to perform the action.
However, Manjunath et al further teaches a non-transitory computer-readable media (par [0089]) storing instructions executable by one or more processors of a node, wherein the instructions, when executed, cause the one or more processors to perform operations;
determining, by the second engine and based in part on the security signal, to perform an action with regard to a security event associated the security signal (par [0018], lines 10-15, “remediation action”); and
outputting, by the second engine and to a second node within the network, instructions to perform the action (par [0018], lines 10-15, “initiate the remediation action”).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al in order to improve resolving detected security events among network nodes by implementing the security feature recommendation engine (as disclosed in fig. 1 of Manjunath et al) because this feature would allow for faster remediation of security events when pre-stored mitigation of matching threats are issued upon a security event with a previously matching pattern being detected.
Regarding claim 20, Luo et al does not explicitly teach wherein the node is included as part of a first level within a swarm system of the network, further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function; and outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data.
However, Manjunath et al further teaches wherein the node is included as part of a first level within a swarm system of the network (par [0010], lines 18-19), further comprising:
generating, by the first engine and based on executing a specialized type of function using the event data as input, transformed event data associated with a portion of the security events that comprise a particular identifier or classifier defined by the specialized type of function (par [0061-00062], “classified the container environment as being critical”); and
outputting, by the first engine and to one or more nodes at a second level within the network, the transformed event data (par [0060], lines 7-9).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Manjunath et al within the teachings of Luo et al according to the motivation disclosed regarding claim 19.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Randy A. Scott whose telephone number is (571) 272-3797. The examiner can normally be reached on Monday-Thursday 7:30 am-5:00 pm, second Fridays 7:30 am-4pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RANDY A SCOTT/Primary Examiner, Art Unit 2439
20260716