DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 06/12/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Objections
Claims 26 and 43 are objected to because of the following informalities: The claims recite the acronym “OAuth” without spelling out the acronym at its first occurrence. The Examiner suggest the acronym to be spelled out to recite “Open Authorization” at its first occurrence. Appropriate correction is required.
Claim 18 is objected to because of the following informalities: The claims recite the word “ the” twice in line 6. The examiner suggest amending the claim limitation to recite “the internet” instead of “the the internet”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 11, 14, 17, 19 and 26 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 11, 14, 17, 19 and 26 use the term “and/or”. This term renders the scope of the claim language unclear because it is not clear whether all of the limitations are required or not, in order to fall within the scope of the claim. The use of "and" in the language would require all the limitations to be present in order to fall within the scope of the claim language. The use of "or" in the language would only require one of the limitations to be present in order to fall within the scope of the claim language. The use of "and/or" makes the applicants intended scope unclear because one of ordinary skill in the art would be unable to determine whether or not all of the listed limitations are required or not. Therefore, the claims are rejected for failing to specifically point out and distinctly claim the subject matter which the inventors regard as the invention.
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 28-43 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The claims recite the limitation “a non-transitory, machine-readable medium having stored thereon program code comprising instructions”, however, the specification is void of any medium or program code.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1 and 18 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 8 and 15 of copending Application No. 19/092,316 in view of Chauhan et al. (US Pub No. 2020/0145425). The claims of the copending application teaches each and every claim limitation of the instant application but does not explicitly teach at least one of activity in the first environment and activity of the web browser. However, Chauhan teaches at least one of activity in the first environment and activity of the web browser (Chauhan, page 10, paragraphs 0103-0104 & page 13, paragraph 0124; access policies and manage/monitor network applications). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify the copending application with the teachings of Chauhan to monitor and manage network applications to provide the advantage of preventing potential misuse of resources (Chauhan, page 1, paragraph 0002).
This is a provisional nonstatutory double patenting rejection. Independent claims 1 & 18 of the instant application are mapped to independent claims 1, 8 & 15 of the co-pending application.
Instant Application 19/195,964
Co-Pending Application 19/092,316
1. A method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser;
1. A method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser;
communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser; and
communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser; and
managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser based, at least in part, on the one or more security policies.
monitoring and managing, with at least one of the first environment and the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-7, 10-16, 19, 21-25, 28-32, 34-36, 38 and 40-42 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349).
Regarding independent claim 1, Chauhan teaches a method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser; authentication of the user and client application); communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization the web browser (Chauhan, page 10, paragraphs 0103-0104; client application obtain various policies from network devices/gateway to manage network application); and managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser based, at least in part, on the one or more security policies (Chauhan, page 10, paragraphs 0103-0104; client application access policies and mange/control network application).
Chauhan teaches the client application obtaining policies from the network and authenticating the client application & providing network applications based on the authentication (Chauhan, page 10, paragraphs 0103-0104 and page 13, paragraphs 0120-0121) but does not explicitly teach communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser.
Wilson teaches communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser (Wilson, column 7, lines 40-column 8, line 35; after verification of the credential transmitting browser policy data).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the teachings of Wilson to obtain browser policies after verification to provide the advantage of secure distribution of enterprise policy data (Wilson, column 1, lines 20-52).
Regarding claim 2, Chauhan in view of Wilson teaches the method wherein managing with the web browser comprises managing with an extension associated with the web browser (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057 and page 10, paragraph 0099; embedded browser is extension of client application).
Regarding claim 3, Chauhan in view of Wilson teaches the method wherein managing activity of the web browser comprises enforcing browsing restrictions based, at least partly, on the one or more security policies (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 4, Chauhan in view of Wilson teaches the method wherein enforcing browsing restrictions based, at least in part, on the one or more security policies comprises detecting a restricted uniform resource locator or website and then disallowing at least one of uploading of a file, downloading of a file, copying information, pasting information, printing, taking a screenshot, opening a web browser inspector, executing external program code, installing an extension, and connecting via an external authorization service (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions;).
Regarding claim 5, Chauhan in view of Wilson teaches the method wherein enforcing browsing restrictions is also based on at least one of type or category of a website being browsed, a user profile, installed applications on the endpoint, and security posture of the endpoint (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 6, Chauhan in view of Wilson teaches the method wherein managing activity comprises at least one of: monitoring for browsing activity corresponding to one or more personal services websites indicated in the one or more security polices; opening a personal services website in a second environment on the endpoint based on detecting attempted access of the personal services website with the web browser in the first environment; and changing focus from an application in the first environment to an application in the second environment based on detecting attempted access of the personal services website with the web browser in the first environment or detecting an event on the personal services website (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0159, 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies).
Regarding claim 7, Chauhan in view of Wilson teaches the method wherein managing activity in the web browser based on the one or more security policies comprises managing at least one of: browsing to websites not known to be safe; browsing to websites with an increased risk level assessment, wherein the increased risk level assessment is based on assessing website assessments from multiple of the backend, third party services, uniform resource locator scanning, and preemptive website scanning; browsing from an insecure location; browsing without authentication to the organization; browsing without authenticating with one of multi-factor authentication, hardware security module, and trusted platform module; browsing from a device assessed as unsafe based on security posture assessment; browsing in websites with indication of anomalous website behavior with respect to normal website behavior; and browsing in an anomalous browsing activity sequence (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 10, Chauhan in view of Wilson teaches the method wherein managing activity in the first environment comprises monitoring browsing by a second web browser, determining that the second web browser instead of the web browser is being used for attempted access of a website or service of the organization, and restricting the attempted access (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 11, Chauhan in view of Wilson teaches the method wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser comprises monitoring website risk levels based on websites viewed with the web browser and modifying permissions in the first environment based on at least one of the website risk levels (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0159, 0161-0162 and page 14, paragraphs 0129-0130; managing/controlling network application based on policies; redirecting request; suspect websites/webpages).
Regarding claim 12, Chauhan in view of Wilson teaches the method further comprising evaluating a website risk level of a website being viewed based on at least one of change to part or all of an uniform resource locator of the website, loading of third party content into the website, and risk level of another website from which content is loaded into the website (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0159, 0161-0162 and page 14, paragraphs 0129-0130; managing/controlling network application based on policies; redirecting request; suspect websites/webpages).
Regarding claim 13, Chauhan in view of Wilson teaches the method wherein modifying permissions in the first environment comprises at least one of logging information sharing between services, blocking information sharing between services, and blocking access to a network of the organization via a virtual private network (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 14, Chauhan in view of Wilson teaches the method wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser comprises isolating and reducing exposure, collection, or access of private employee information while allowing collection or access of company-related activity information and preserving privacy of the private employee information (Chauhan, page 19, paragraphs 0174-0176 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions; mask over content and blanking out screen).
Regarding claim 15, Chauhan in view of Wilson teaches the method wherein identifying collection or access of company related activity information and private employee information comprises whitelisting a set of websites that can be visited with the web browser and applications allowed to be used in the first environment (Chauhan, page 17, paragraph 0159; website/webpage safe or suspect).
Regarding claim 16, Chauhan in view of Wilson teaches the method wherein preserving privacy of the private employee information comprises monitoring for potential exposure of private employee information and, in response to detection of a submission that potentially exposes private employee information, logging the submission, disabling the submission, or deanonymizing information in the submission (Chauhan, page 19, paragraphs 0174-0176 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions; mask over content and blanking out screen).
Regarding claim 19, Chauhan in view of Wilson teaches the method wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser with respect to the one or more security policies comprises protecting the web browser, wherein protecting the web browser comprises one or more of: using an anti-tampering mechanism; securely saving sensitive data; monitoring for malicious links, pop-ups, or websites; analyzing an installed browser extension; analyzing an extension pending install; removing risky functionality provided by browsing and rendering program code; hardening the web browser; monitoring for web application attacks; and rendering a page in an isolated environment to evaluate risk of the page before or while presenting the page to a user (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162, page 19, paragraphs 0174-0176 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions; mask over content and blanking out screen).
Regarding claim 21, Chauhan in view of Wilson teaches the method wherein the sensitive data comprises at least one of configuration files, cached data, cookies, and binaries and wherein securely saving the sensitive data comprises one or more of: locally encrypting the sensitive data with key accessible after user authentication or browser authentication and prevented from being cached locally or is locally saved with hardware security module or trusted platform module; storing the sensitive data on a remote server of the organization and requiring secure authentication for accessing and preventing local storing; obfuscating the sensitive data if locally stored; and storing the sensitive data on a remote filesystem that requires secure authentication for accessing (Chauhan, page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 22, Chauhan in view of Wilson teaches the method wherein analyzing an installed browser extension comprises monitoring behavior of the installed browser extension to determine whether the installed browser extension attempts to interact with a resource of the organization (Chauhan, page 10, paragraphs 0099-0100, page 13, paragraph 0124, page 17, paragraph 0159 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 23, Chauhan in view of Wilson teaches the method wherein removing risky functionality provided by browsing and rendering program code comprises removing or disabling corresponding program code (Chauhan, page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 24, Chauhan in view of Wilson teaches the method wherein hardening the web browser comprises one or more of: hardening default browser policies; requiring stronger authentication for auto-filling passwords or payment information ;blocking pop-ups unless specifically allowed; disabling downloads unless specifically allowed; and removing one or more application programming interfaces specified in the one or more security policies of the organization (Chauhan, page 10, paragraph 0104 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 25, Chauhan in view of Wilson teaches the method wherein rendering a page in an isolated environment to evaluate risk of the page before or while presenting the page to a user comprises :rendering the page with one or more of a local sandboxed emulator, a remote service via an application programming interface, a local or remote container, and a local or remote virtual machine; and injecting user events to identify potential malicious behavior in the isolated environment (Chauhan, pages 14-15, paragraphs 0133-0136 and page 17, paragraph 0159).
Regarding independent claim 28, Chauhan teaches a non-transitory, machine-readable medium having stored thereon program code comprising instructions to: authenticate a web browser with a backend of an organization, on an endpoint that hosts a first environment that comprises the web browser (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser; authentication of the user and client application); obtain from the backend one or more security policies of the organization the web browser (Chauhan, page 10, paragraphs 0103-0104; client application obtain various policies from network devices/gateway to manage network application); and managing, with the web browser, activity of the web browser based, at least in part, on the one or more security policies (Chauhan, page 10, paragraphs 0103-0104; client application access policies and mange/control network application).
Chauhan teaches the client application obtaining policies from the network and authenticating the client application & providing network applications based on the authentication (Chauhan, page 10, paragraphs 0103-0104 and page 13, paragraphs 0120-0121) but does not explicitly teach obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser.
Wilson teaches obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser (Wilson, column 7, lines 40-column 8, line 35; after verification of the credential transmitting browser policy data).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the teachings of Wilson to obtain browser policies after verification to provide the advantage of secure distribution of enterprise policy data (Wilson, column 1, lines 20-52).
Regarding claim 29, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the web browser or an extension to the web browser comprises program code (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057 and page 10, paragraph 0099; embedded browser is extension of client application).
Regarding claim 30, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to manage activity of the web browser comprise instructions to enforce browsing restrictions based, at least partly, on the one or more security policies, wherein the instructions to enforce browsing restrictions comprise at least one of, instructions to detect a restricted uniform resource locator or website and then disallow at least one of uploading of a file, downloading of a file, copying information, pasting information, printing, taking a screenshot, opening a web browser inspector, executing external program code, installing an extension, and connecting via an external authorization service; and instructions to enforce browsing restrictions also based on at least one of type or category of a website being browsed, a user profile, installed applications on the endpoint, and security posture of the endpoint (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 31, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to manage activity of the web browser comprises at least one of: instructions to monitor for browsing activity corresponding to one or more personal services websites indicated in the one or more security polices; instructions to open a personal services website in a second environment on an endpoint based on detecting attempted access of the personal services website with the web browser in a first environment that hosts the web browser; and instructions to change focus from an application in the first environment to an application in the second environment based on detecting attempted access of the personal services website with the web browser in the first environment or detecting an event on the personal services website (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0159, 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies).
Regarding claim 32, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to manage activity of the web browser comprise instructions to manage at least one of: browsing to websites not known to be safe; browsing to websites with an increased risk level assessment, wherein the increased risk level assessment is based on assessing website assessments from multiple of the backend, third party services, uniform resource locator scanning, and preemptive website scanning; browsing from an insecure location; browsing without authentication to the organization; browsing without authenticating with one of multi-factor authentication, hardware security module, and trusted platform module; browsing from a device assessed as unsafe based on security posture assessment; browsing in websites with indication of anomalous website behavior with respect to normal website behavior; and browsing in an anomalous browsing activity sequence (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 34, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the program code further comprises instructions to monitor browsing by a second web browser, determine that the second web browser instead of the web browser is being used for attempted access of a website or service of the organization, and restrict the attempted access. (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162 and page 19, paragraphs 0174-0176; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 35, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to manage activity of the web browser comprise instructions to monitor website risk levels based on websites viewed with the web browser and modify permissions in a first environment based on at least one of the website risk levels, wherein the instructions to evaluate a website risk level of a website being viewed comprises the instruction to evaluate based on at least one of change to part or all of an uniform resource locator of the website, loading of third party content into the website, and risk level of another website from which content is loaded into the website, wherein the instructions to modify permissions in the first environment comprise instructions to, at least one of, log information sharing between services, block information sharing between services, and block access to a network of the organization via a virtual private network, wherein the first environment hosts the web browser (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0159, 0161-0162 and page 14, paragraphs 0129-0130; managing/controlling network application based on policies; redirecting request; suspect websites/webpages).
Regarding claim 36, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the program code further comprises instructions to isolate and reduce exposure, collection, or access of private employee information while allowing collection or access of company-related activity information and to preserve privacy of the private employee information, wherein the instructions to identify collection or access of company related activity information and private employee information comprise instructions to whitelist a set of websites that can be visited with the web browser and applications allowed to be used in the first environment, wherein the instructions to preserve privacy of the private employee information comprise instructions to monitor for potential exposure of private employee information and, in response to detection of a submission that potentially exposes private employee information, log the submission, disable the submission, or deanonymize the information in the submission (Chauhan, page 17, paragraph 0159, page 19, paragraphs 0174-0176 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions; mask over content and blanking out screen).
Regarding claim 38, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the program code further comprises instructions to protect the web browser, wherein the instructions to protect the web browser comprise at least one of: instructions to use an anti-tampering mechanism; instructions to securely save sensitive data; instructions to monitor for malicious links, pop-ups, or websites; instructions to monitor behavior of an installed browser extension to determine whether the installed browser extension attempts to interact with a resource of the organization; instructions to analyze an extension pending install; instructions to remove risky functionality provided by browsing and rendering program code; instructions to harden the web browser; instructions to monitor for web application attacks; and instructions to render a page in an isolated environment to evaluate risk of the page before or while presenting the page to a user (Chauhan, page 10, paragraph 0104, page 17, paragraphs 0161-0162, page 19, paragraphs 0174-0176 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions; mask over content and blanking out screen).
Regarding claim 40, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the sensitive data comprises at least one of configuration files, cached data, cookies, and binaries and wherein the instructions to securely save the sensitive data comprise one or more of: instructions to locally encrypt the sensitive data with key accessible after user authentication or browser authentication and prevented from being cached locally or is locally saved with hardware security module or trusted platform module; instructions to store the sensitive data on a remote server of the organization and requiring secure authentication for accessing and preventing local storing; instructions to obfuscate the sensitive data if locally stored; and instructions to store the sensitive data on a remote filesystem that requires secure authentication for accessing (Chauhan, page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 41, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to harden the web browser comprises one or more of: instructions to harden default browser policies; instructions to require stronger authentication for auto-filling passwords or payment information; instructions to block pop-ups unless specifically allowed; instructions to disable downloads unless specifically allowed; and instructions to remove one or more application programming interfaces specified in the one or more security policies of the organization (Chauhan, page 10, paragraph 0104 and page 20, paragraphs 0181-0182; managing/controlling network application based on policies and performance of revoking actions).
Regarding claim 42, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to render a page in an isolated environment to evaluate risk of the page before or while presenting the page to a user comprise instructions to: render the page with one or more of a local sandboxed emulator, a remote service via an application programming interface, a local or remote container, and a local or remote virtual machine; and inject user events to identify potential malicious behavior in the isolated environment (Chauhan, pages 14-15, paragraphs 0133-0136 and page 17, paragraph 0159).
Claim(s) 8-9, 17-18, 33 and 37 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1-7, 10-16, 19, 21-25, 28-32, 34-36, 38 and 40-42 above, and further in view of Boyer et al. (US Pub No. 2021/0273957).
Regarding claim 8, Chauhan in view of Wilson teaches each and every claim limitation of claim 7.
Chauhan in view of Wilson does not explicitly teach the method wherein managing browsing in websites with indication of anomalous website behavior with respect to normal website behavior comprises calculating a risk score based on one or more parameters and enforcing one or more browsing restrictions if the risk score exceeds a threshold.
Boyer teaches wherein managing browsing in websites with indication of anomalous website behavior with respect to normal website behavior comprises calculating a risk score based on one or more parameters and enforcing one or more browsing restrictions if the risk score exceeds a threshold (Boyer, page 3, paragraph 0044, page 5, paragraph 0061, page 7, paragraph 0077, page 9, paragraph 0104 and page 12, paragraph 0139; threat or breach state based on threat risk parameter).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to detect malicious behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Regarding claim 9, Chauhan in view of Wilson and in further view of Boyer teaches each and every limitation of claim 8, however Wilson teaches the method wherein the one or more parameters comprise at least one of a uniform resource locator, website content, metadata of the website, script of a website page, a certificate being used, user behavior, domains related to the website page, websites that link to a page being viewed, a server network address and derived information from the network address, and risk scores of other websites associated with the server being accessed (Boyer, page 4, paragraph 0059, page 7, paragraph 0077, and page 10, paragraph 0113).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to detect malicious behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Regarding claim 17, Chauhan in view of Wilson teaches each and every claim limitation of claim 1.
Chauhan in view of Wilson does not explicitly teach the method wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser based on the one or more security policies comprises: collecting data on employee activity to a backend of the organization; aggregating collected data; and analyzing individual employee activity data and aggregated employee activity data.
Boyer teaches wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser based on the one or more security policies comprises: collecting data on employee activity to a backend of the organization; aggregating collected data; and analyzing individual employee activity data and aggregated employee activity data (Boyer, page 4, paragraphs 0054-0057, and page 17, paragraphs 0178 & 0182-0185; analyze activity of specific user).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyze behavior of a user to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Regarding claim 18, Chauhan in view of Wilson and in further view of Boyer teaches each and every limitation of claim 17, however Wilson teaches the method wherein the collected data comprises at least one of time a tab was open, lengthy of user activity in a service, actions taken within a service, user events for applications running in the first environment, how much information was transferred between each application running within the first environment and the organization, how much information was transferred between each application running within the first environment and the the internet, and what type of information was transferred (Boyer, page 4, paragraphs 0054-0057, and page 17, paragraphs 0178 & 0182-0185).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyze behavior of a user to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Regarding claim 33, Chauhan in view of Wilson teaches each and every claim limitation of claim 32.
Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to manage browsing in websites with indication of anomalous website behavior with respect to normal website behavior comprise instructions to calculate a risk score based on one or more parameters and to enforce one or more browsing restrictions if the risk score exceeds a threshold, wherein the one or more parameters comprise at least one of a uniform resource locator, website content, metadata of the website, script of a website page, a certificate being used, user behavior, domains related to the website page, websites that link to a page being viewed, a server network address and derived information from the network address, and risk scores of other websites associated with the server being accessed.
Boyer teaches wherein the instructions to manage browsing in websites with indication of anomalous website behavior with respect to normal website behavior comprise instructions to calculate a risk score based on one or more parameters and to enforce one or more browsing restrictions if the risk score exceeds a threshold, wherein the one or more parameters comprise at least one of a uniform resource locator, website content, metadata of the website, script of a website page, a certificate being used, user behavior, domains related to the website page, websites that link to a page being viewed, a server network address and derived information from the network address, and risk scores of other websites associated with the server being accessed (Boyer, page 3, paragraph 0044, page 5, paragraph 0061, page 7, paragraph 0077, page 9, paragraph 0104 and page 12, paragraph 0139; threat or breach state based on threat risk parameter).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to detect malicious behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Regarding claim 37, Chauhan in view of Wilson teaches each and every claim limitation of claim 28.
Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the program code further comprises instructions to manage activity in a first environment that hosts the web browser, wherein the instructions to manage activity in the first environment and to manage activity of the web browser comprise instructions to: collect data on employee activity to a backend of the organization, wherein the collected data comprises at least one of time a tab was open, lengthy of user activity in a service, actions taken within a service, user events for applications running in the first environment, how much information was transferred between each application running within the first environment and the organization, how much information was transferred between each application running within the first environment and the internet, and what type of information was transferred; aggregate collected data; and analyze individual employee activity data and aggregated employee activity data.
Boyer teaches wherein the program code further comprises instructions to manage activity in a first environment that hosts the web browser, wherein the instructions to manage activity in the first environment and to manage activity of the web browser comprise instructions to: collect data on employee activity to a backend of the organization, wherein the collected data comprises at least one of time a tab was open, lengthy of user activity in a service, actions taken within a service, user events for applications running in the first environment, how much information was transferred between each application running within the first environment and the organization, how much information was transferred between each application running within the first environment and the internet, and what type of information was transferred; aggregate collected data; and analyze individual employee activity data and aggregated employee activity data (Boyer, page 4, paragraphs 0054-0057, and page 17, paragraphs 0178 & 0182-0185; analyze activity of specific user).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyze behavior of a user to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005).
Claim(s) 20 and 39 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1-7, 10-16, 19, 21-25, 28-32, 34-36, 38 and 40-42 above, and further in view of Warman et al. (US Patent No. 9,635,041).
Regarding claim 20, Chauhan in view of Wilson teaches each and every claim limitation of claim 19.
Chauhan in view of Wilson does not explicitly teach the method wherein using the anti-tampering mechanism comprises at least one of: generating a hash on one or more components of the web browser and providing the hash to a server of the organization for validation; confirming with an operating system of the endpoint that the web browser or components of the web browser are digitally signed; and digitally signing different parts of the program code of the web browser with an encryption algorithm, a trusted platform module, or a hardware security module of the endpoint and verifying the digital signatures.
Warman teaches wherein using the anti-tampering mechanism comprises at least one of: generating a hash on one or more components of the web browser and providing the hash to a server of the organization for validation; confirming with an operating system of the endpoint that the web browser or components of the web browser are digitally signed; and digitally signing different parts of the program code of the web browser with an encryption algorithm, a trusted platform module, or a hardware security module of the endpoint and verifying the digital signatures (Warman, column 15, lines 5-31; match hash value or signature).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Warman to verify websites to provide the advantage of preventing or reducing the chance of malware infecting enterprise nodes (Warman, column 2, lines 3-14).
Regarding claim 39, Chauhan in view of Wilson teaches each and every claim limitation of claim 38.
Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to use the anti-tampering mechanism comprise at least one of: instructions to generate a hash on one or more components of the web browser and provide the hash to a server of the organization for validation; instructions to confirm with an operating system of an endpoint hosting the web browser that the web browser or components of the web browser are digitally signed; and instructions to digitally sign different parts of the program code of the web browser with an encryption algorithm, a trusted platform module, or a hardware security module of the endpoint and verify the digital signatures.
Warman teaches wherein the instructions to use the anti-tampering mechanism comprise at least one of: instructions to generate a hash on one or more components of the web browser and provide the hash to a server of the organization for validation; instructions to confirm with an operating system of an endpoint hosting the web browser that the web browser or components of the web browser are digitally signed; and instructions to digitally sign different parts of the program code of the web browser with an encryption algorithm, a trusted platform module, or a hardware security module of the endpoint and verify the digital signatures (Warman, column 15, lines 5-31; match hash value or signature).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Warman to verify websites to provide the advantage of preventing or reducing the chance of malware infecting enterprise nodes (Warman, column 2, lines 3-14).
Claim(s) 26-27 and 43 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1-7, 10-16, 19, 21-25, 28-32, 34-36, 38 and 40-42 above, and further in view of Cohen et al. (US Pub No. 2015/0135302).
Regarding claim 26, Chauhan in view of Wilson teaches each and every claim limitation of claim 1.
Chauhan in view of Wilson does not explicitly teach the method wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser comprises monitoring for an OAuth login sequence and, based on detection of an OAuth login sequence, interrupting the detected OAuth login sequence to protect an application or service corresponding to the detected OAuth login sequence.
Cohen teaches wherein managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser comprises monitoring for an OAuth login sequence and, based on detection of an OAuth login sequence, interrupting the detected OAuth login sequence to protect an application or service corresponding to the detected OAuth login sequence (Cohen, page 2, paragraph 0039, page 3, paragraph 0047, and page 4, paragraph 0077; track request for OAuth token to enforce redirection or enforcements).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003).
Regarding claim 27, Chauhan in view of Wilson and in further view of Boyer teaches each and every limitation of claim 26, however Wilson teaches the method wherein interrupting the detected OAuth login sequence is based on an approval-list or blocking-list of services or based on a requested permission scope of the detected OAuth login sequence (Cohen, page 4, paragraphs 0077-0079 and page 9, paragraphs 0206, 0211 & 0227-0228).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003).
Regarding claim 43, Chauhan in view of Wilson teaches each and every claim limitation of claim 28.
Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the program code further comprises instructions to monitor for an OAuth login sequence and, based on detection of an OAuth login sequence, interrupt the detected OAuth login sequence to protect an application or service corresponding to the detected OAuth login sequence, wherein the instructions to interrupt the detected OAuth login sequence comprise instructions to interrupt the detected OAuth login sequence based on an approval-list or blocking-list of services or based on a requested permission scope of the detected OAuth login sequence.
Cohen teaches wherein the program code further comprises instructions to monitor for an OAuth login sequence and, based on detection of an OAuth login sequence, interrupt the detected OAuth login sequence to protect an application or service corresponding to the detected OAuth login sequence, wherein the instructions to interrupt the detected OAuth login sequence comprise instructions to interrupt the detected OAuth login sequence based on an approval-list or blocking-list of services or based on a requested permission scope of the detected OAuth login sequence (Cohen, page 2, paragraph 0039, page 3, paragraph 0047, and page 4, paragraph 0077; track request for OAuth token to enforce redirection or enforcement; page 4, paragraphs 0077-0079 and page 9, paragraphs 0206, 0211 & 0227-0228).
It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003).
Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Magazine et al. (US Pub No. 2020/0334698).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAQUEAL D WADE whose telephone number is (571)270-0357. The examiner can normally be reached M-F 8:00-5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHAQUEAL D WADE-WRIGHT/Primary Examiner, Art Unit 2407