DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
EXAMINER’S COMMENT
The conjunction “and/or” in the claims is functionally equivalent to the conjunction “or” under the broadest reasonable interpretation. Therefore, under the broadest reasonable interpretation, a claim reciting a list of possible options joined by the conjunction “and/or” can be taught by prior art fulfilling at least one of the possible options.
Claim Objections
Claim 12 is objected to because of the following informalities:
Claim 12 recites “an user interface” in line 2 of Page 4 of Claims. It is recommended by the Examiner that the limitation read as “a user interface” instead.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 7-8, 12 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 7 recites the limitation "the predetermined security incident monitoring rules" in line 4 of Claim 7. There is insufficient antecedent basis for this limitation in the claim. Claim 7 depends upon Claim 1 which does not recite “predetermined security incident monitoring rules”, instead this limitation first appears in Claim 4. For this reason, it is ambiguous as to what “the predetermined security incident monitoring rules” specifically refers to, rendering the claim indefinite.
Claim 8 is rejected for the same reasons as above by virtue of depending upon Claim 7 and also reciting “the predetermined security incident monitoring rules”.
Claim 12 repeats limitations of Claim 11 in the context of the components introduced. For example, Claim 12 recites “wherein the incident detector is configured to joint analyze first data indicative of first monitoring data from the monitoring of the IT-related data and of second data indicative of second monitoring data from the monitoring of the OT-related data, the joint analyzing based on correlating at least part of the first data with at least part of the second data and/or based on correlating at least part of the second data with at least part of the first data” in lines 14-18 of Claim 12. Due to the limitations being repeated from Claim 11, there is insufficient antecedent basis for these limitations in Claim 12. For example, in the example above, Claim 12 recites “first data”, “second data”, and “joint analyzing”, and then further goes on to recite “the first data”, “the second data”, and “the joint analyzing”. However, Claim 12 depends upon Claim 11 which previously recited “first data”, “second data”, and “joint analyzing” already, meaning that it is ambiguous as to what “the first data”, “the second data”, and “the joint analyzing” specifically refers to, rendering the claim indefinite. This similarly applies to other instances of repeated limitations. It is recommended by the Examiner to amend Claim 12 such that it refers to the previously recited limitations of Claim 11 rather than repeating such limitations again.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-12 are rejected under 35 U.S.C. 103 as being unpatentable over Hassanzadeh et al. (U.S. Pub. No. 2016/0301704 A1) hereinafter referred to as “Hassanzadeh”, and further in view of Khuti et al. (U.S. Pub. No. 2020/0067789 A1) hereinafter referred to as “Khuti”.
Regarding Claim 1:
Hassanzadeh teaches the following limitations:
A method for security incident detection in a (Par. [0016], Par. [0024]). Hassanzadeh teaches threat detection across multiple domains including information technology (IT) and operational technology (OT) for industrial control systems.
monitoring information technology (IT) -related data and operation technology (OT) -related data at a production process (Fig. 1, Fig. 2, Par. [0016]-[0017], Par. [0024]-[0025]). Hassanzadeh teaches monitoring both IT/OT data for industrial systems.
joint analyzing of first data indicative of first monitoring data from the monitoring of the IT-related data and of second data indicative of second monitoring data from the monitoring of the OT-related data, the joint analyzing based on correlating at least part of the first data with at least part of the second data and/or based on correlating at least part of the second data with at least part of the first data (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]). Hassanzadeh teaches aggregating and correlating the IT/OT data to analyze threats.
based on the joint analyzing, detecting a security incident under consideration of predetermined security incident detection rules (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0044]). Hassanzadeh teaches detecting attacks from correlating data.
and based on a result of the detecting, responding on a detected security incident for handling of the detected security incident under consideration of predetermined security incident response rules (Fig. 5A, Par. [0059]-[0062]). Hassanzadeh teaches responding to attacks and threats.
Khuti teaches the following limitations:
in a cloud-native distributed control system (DCS) in industrial process automation (Abstract, Par. [0008]). Khuti teaches that a cloud native distributed system for industrial systems.
and at a containerized DCS associated with the production process (Par. [0071]-[0074], Par. [0336]). Khuti teaches their system using containers.
Hassanzadeh teaches threat detection by correlating IT/OT data, but does not teach the system being a cloud-native distributed system. Khuti however teaches that an industrial system can have a cloud-native distributed control system and that this has the benefit of addressing ingestion of big data (Par. [0002]-[0007]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the threat detection of Hassanzadeh with the system of Khuti in order to gain the predictable result of the control system being a cloud-native distributed system. One of ordinary skill in the art would have recognized that both Hassanzadeh and Khuti are directed towards systems regarding data ingestion for industrial processes, and therefore that the cloud native-distributed control system of Khuti would have been a predictable implementation for data ingestion. One of ordinary skill would have further recognized that such an implementation would have the benefit of handling large amounts of data.
Regarding Claim 2:
Khuti teaches the following limitation:
further comprising performing the monitoring, the joint analyzing, the detecting and the responding by a virtual DCS security operator, wherein the virtual DCS security operator is a software agent running in a container orchestration cluster associated with the DCS and/or wherein the virtual DCS security operator is an autonomously running security operator (Par. [0071]-[0077]). Khuti teaches implementing their system using a container cluster for ingesting and working with data. In combination with the security operator of Hassanzadeh, this teaches the claimed limitation.
The reasons for motivation/combination of references remain the same as in Claim 1.
Regarding Claim 3:
Hassanzadeh teaches the following limitation:
wherein the first monitoring data represents the monitored IT-related data comprising monitored system diagnostics data, and wherein the second monitoring data represents the monitored OT-related data comprising monitored process data; and/or wherein the correlating comprises correlating at least part of the first monitoring data with at least part of the second monitoring data and/or correlating at least part of the second monitoring data with at least part of the first monitoring data (Fig. 2, Fig. 5A, Par. [0020]-[0021], Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]). As argued in the Examiner’s comment above, the claim is directed towards a list of options joined by the conjunction “and/or”, meaning that only one option needs to be taught. Previously, it was argued that Hassanzadeh taught correlating first/second data. Furthermore, this first/second data can also be IT system diagnostics data and OT process data, as Hassanzadeh teaches monitoring for system alerts for both domains, which can be considered to be both system diagnostics data and process data under the broadest reasonable interpretation.
Regarding Claim 4:
Hassanzadeh teaches the following limitation:
wherein the monitoring of the IT-related data and of the OT-related data comprises monitoring the IT-related data and the OT-related under consideration of predetermined security incident monitoring rules; and/or wherein the monitoring of the IT-related data and of the OT-related data comprises monitoring data coining from a Kubernetes Application Programming Interface, API, server and from an Open Platform Communications Unified Architecture, OPC UA, server; and/or wherein the method further comprises accessing the Kubernetes API server; and performing the responding based on adjusting parameters available in the Kubernetes API server (Fig. 2, Fig. 3, Par. [0025]-[0030]). Hassanzadeh teaches monitoring and filtering data according to rules.
Regarding Claim 5:
Hassanzadeh teaches the following limitation:
wherein the joint analyzing comprises detecting a security incident in one of the first data and the second data and analyzing the other one of the first data and the second data for an event associated with the detected security incident (Par. [0026], Par. [0034]-[0035]). Hassanzadeh teaches identifying an alert and checking the other domain in order to group similar alerts.
Regarding Claim 6:
Hassanzadeh teaches the following limitation:
wherein the production process and the containerized DCS correspond to a certain domain and wherein the predetermined security incident detection rules and the predetermined security incident response rules are specific for the certain domain (Fig. 1, Fig. 2, Par. [0016]-[0017], Par. [0024]-[0025]). The claim recites a “certain domain”, but a domain is not defined within the Applicant’s specification. Therefore, under the broadest reasonable interpretation, the entire industrial control system of Hassanzadeh/Khuti can be considered to be a domain (with the IT/OT domains being sub-domains of this domain), and the system’s rules would therefore be specific to the domain.
Regarding Claim 7:
Hassanzadeh teaches the following limitation:
wherein the method further comprises using virtual DCS security custom resources that comprise at least part of the predetermined security incident detection rules, of the predetermined security incident response rules, and of the predetermined security incident monitoring rules (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]). The claim recites a “custom resources”, but “custom resources” are not defined within the Applicant’s specification. Therefore, the system data of Hassanzadeh/Khuti can be considered to be custom resources under the broadest reasonable interpretation and therefore comprise the mentioned rules.
Regarding Claim 8:
Hassanzadeh teaches the following limitations:
further comprising modifying the virtual DCS security custom resources for at least one of the predetermined security incident detection rules, the predetermined security incident response rules, and the predetermined security incident monitoring rules (Par. [0028], Par. [0043], Par. [0056], Par. [0073]). Hassanzadeh teaches configuration management such as a tunable threshold parameter for determining/responding to security incidents.
wherein the modifying is performed manually by a user, automatically by a reasoning system associated with the DCS and without involving the user, or semi-automatically where the user provides guidance to the reasoning system (Par. [0028], Par. [0043], Par. [0056], Par. [0073]). This modification can be manually done by an operator.
Regarding Claim 9:
Hassanzadeh teaches the following limitation:
wherein the responding comprises at least one of: notifying a user about the detected security incident, applying a command received by a user regarding the detected security incident, autonomously applying of a predetermined security incident response rule from the predetermined security incident response rules regarding the detected security incident, and simulating a response on the detected security incident before performing the response, and performing the responding further based on a result of the simulating (Par. [0023], Par. [0062], Par. [0063]). Hassanzadeh teaches reporting and providing visualization data of the attack to an operator.
Regarding Claim 10:
Hassanzadeh teaches the following limitations:
wherein the method further comprises exchanging third data with a security information and event management (SIEM) system (Par. [0020]). Hassanzadeh teaches activity data being additionally sourced from a SIEM system.
and performing at least one of the monitoring, the joint analyzing, the detecting, and the responding further based on the third data (Fig. 2, Fig. 5A, Par. [0020], Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]). This activity data is used for monitoring/analyzing/detection.
wherein the third data is indicative of at least one of: recorded events occurred at the production process and/or the containerized DCS, performed responses, additional, removed and/or updated security incident monitoring rules, additional, removed and/or updated security incident detection rules, and additional, removed and/or updated security incident response rules (Par. [0020]). The activity data of Hassanzadeh being recorded event data.
Regarding Claim 11:
Hassanzadeh teaches the following limitations:
A data processing apparatus for security incident detection in (Par. [0016], Par. [0024], Par. [0076], Par. [0084]).
the method comprising: monitoring information technology (IT) -related data and operation technology (OT) - related data at a production process (Fig. 1, Fig. 2, Par. [0016]-[0017], Par. [0024]-[0025]).
joint analyzing of first data indicative of first monitoring data from the monitoring of the IT-related data and of second data indicative of second monitoring data from the monitoring of the OT-related data, the joint analyzing based on correlating at least part of the first data with at least part of the second data and/or based on correlating at least part of the second data with at least part of the first data (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]).
based on the joint analyzing, detecting a security incident under consideration of predetermined security incident detection rules (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0044]).
and based on a result of the detecting, responding on a detected security incident for handling of the detected security incident under consideration of predetermined security incident response rules (Fig. 5A, Par. [0059]-[0062]).
Khuti teaches the following limitations:
in a cloud-native distributed control system (DCS) in industrial process automation (Abstract, Par. [0008]).
and at a containerized DCS associated with the production process (Par. [0071]-[0074], Par. [0336]).
Hassanzadeh teaches threat detection by correlating IT/OT data, but does not teach the system being a cloud-native distributed system. Khuti however teaches that an industrial system can have a cloud-native distributed control system and that this has the benefit of addressing ingestion of big data (Par. [0002]-[0007]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the threat detection of Hassanzadeh with the system of Khuti in order to gain the predictable result of the control system being a cloud-native distributed system. One of ordinary skill in the art would have recognized that both Hassanzadeh and Khuti are directed towards systems regarding data ingestion for industrial processes, and therefore that the cloud native-distributed control system of Khuti would have been a predictable implementation for data ingestion. One of ordinary skill would have further recognized that such an implementation would have the benefit of handling large amounts of data.
Regarding Claim 12:
Hassanzadeh teaches the following limitations:
comprising (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0044], Par. [0059]-[0062]). Hassanzadeh teaches detecting incidents through collecting alerts, responding to incidents by determining a course of action, and a user interface for presenting visualized threat data.
(taught by Khuti below)
the incident detector is communicatively connected with the user interface and the incident responder, and the incident responder is communicatively connected with the user interface and the incident detector (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0044], Par. [0059]-[0062]). These components of Hassanzadeh are communicatively connected.
wherein a containerized DCS associated with the production process (Fig. 1, Fig. 2, Par. [0016]-[0017], Par. [0024]-[0025]).
wherein the incident detector is configured to joint analyze first data indicative of first monitoring data from the monitoring of the IT-related data and of second data indicative of second monitoring data from the monitoring of the OT-related data, the joint analyzing based on correlating at least part of the first data with at least part of the second data and/or based on correlating at least part of the second data with at least part of the first data (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0041]).
and based on the joint analyzing, detecting a security incident under consideration of predetermined security incident detection rules (Fig. 2, Fig. 5A, Par. [0025]-[0027], Par. [0035], Par. [0039]-[0044]).
and wherein the incident responder is configured to respond on a detected security incident for handling of the detected security incident under consideration of predetermined security incident response rules based on a result of the detecting (Fig. 5A, Par. [0059]-[0062]).
Khuti teaches the following limitations:
a Kubernetes client, an OPC UA client (Fig. 1A, Par. [0073]-[0074], Par. [0088], Par. [0336]). The cloud system of Khuti includes a Kubernetes and OPC UA client, and these clients act as part of data ingestion/monitoring.
wherein the Kubernetes client is communicatively connected with the incident detector and the incident responder, the OPC UA client is communicatively connected with the incident detector and the incident responder (Fig. 1A, Par. [0071]-[0074], Par. [0088], Par. [0336]). The cloud system of Khuti includes a Kubernetes and OPC UA client which are communicatively connected to other services within the cloud-in-a-box system. Previously, Khuti was combined with Hassanzadeh such that Hassanzadeh leveraged the structure of Khuti. This suggests that the Kubernetes/OPC UA clients are communicatively connected to the components of Hassanzadeh.
The reasons for motivation/combination of references remain the same as in Claim 11.
Related Art
The following prior art made of record and cited on PTO-892, but not relied upon, is considered pertinent to applicant’s disclosure:
Hassanzadeh et al. (U.S. Pub. No. 2017/0230410 A1) – Includes methods regarding event anomaly detection
dos Santos et al. (U.S. Pub. No. 2021/0203673 A1) – Includes methods regarding event investigation
Chiu et al. (U.S. Pub. No. 2016/0359895 A1) – Includes methods regarding cybersecurity for operational/information technologies
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ETHAN V VO whose telephone number is (571)272-2505. The examiner can normally be reached M-F 8am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/E.V.V./Examiner, Art Unit 2431 /LYNN D FEILD/Supervisory Patent Examiner, Art Unit 2431