Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This non-final office action is responsive to the U.S. patent application no. 19/203,042 filed on May 8, 2025.
Claims 1-20 are pending.
Claims 1-20 are rejected.
Priority
The application claims priority under 35 U.S.C. 120 to U.S. non-provisional application No. 18/536,794 filed on December 12th, 2023, which claims priority under 35 U.S.C. 120 to U.S. non-provisional application No. 17/327,098 filed on May 21st, 2021, which claims priority under 35 U.S.C. 120 to U.S. non-provisional application No. 16/051,247 filed on July 31st, 2018.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on May 8th, 2025 is compliant with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 8 and 15 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 13 and 22 of U.S. Patent No. 11,038,915. Although the claims at issue are not identical, they are not patentably distinct from each other as shown below.
Instant application no. 19/203,042
Patent No. 11,038,915
1. A method, comprising:
causing, by an incident service, display of a first version of a course of action, the first version of the course of action comprising one or more actions for responding to an occurrence of an incident in an information technology (IT) environment;
receiving, by the incident service, input identifying a suggested action for inclusion in the first version of the course of action, the suggested action identified based at least in part on one or more attributes associated with the incident;
causing, by the incident service, display of a second version of the course of action, the second version of the course of action comprising the one or more actions and the suggested action, and the second version of the course of action identifying a sequence for executing the one or more actions and the suggested action; and
causing, by the incident service, the second version of the course of action to be executed, wherein the causing comprises executing the one or more actions and the suggested action according to the identified sequence.
1. A method comprising:
causing display of a first version of a course of action comprising a plurality of actions used to respond to occurrences of incidents in an information technology (IT) environment, wherein the IT environment comprises a plurality of computing devices and the course of action defines an operational flow of the plurality of actions;
obtaining input requesting addition of a new action in the course of action, wherein the new action is linked to at least one of the plurality of actions;
determining suggested actions based at least in part on the plurality of actions, wherein determining the suggested actions includes determining a relevance of each of the suggested actions to the plurality of actions of the course of action;
causing display of the suggested actions;
obtaining input selecting a particular action from the suggested actions; and
causing display of a second version of the course of action, wherein the second version of the course of action includes the plurality of actions of the first version of the course of action and the particular action.
Claims 1, 8 and 15 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 15 and 18 of U.S. Patent No. 11,863,583. Although the claims at issue are not identical, they are not patentably distinct from each other.
Claims 1, 8 and 15 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 7 and 13 of U.S. Patent No. 12,363,158. Although the claims at issue are not identical, they are not patentably distinct from each other as shown below.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(2) as being unpatentable over Thomas et al. (U.S. 2017/0063920).
Regarding claim 1, Thomas disclosed a method, comprising:
causing, by an incident service, display of a first version of a course of action, the first version of the course of action comprising one or more actions for responding to an occurrence of an incident in an information technology (IT) environment (Thomas, Fig. 15A and [0123], “ a sequencing diagram 1501 that shows several actions 1552 being associated with certain network elements 1556.” And [0124], “The sequencing diagram 1501 may display the various network security actions 1552 in the order in which they are to be executed in responding to the cyber-security threat.” Please see paragraphs [0128, 0129] for additional disclosure about the GUI displaying pre-planned actions);
receiving, by the incident service, input identifying a suggested action for inclusion in the first version of the course of action, the suggested action identified based at least in part on one or more attributes associated with the incident (Thomas, Fig. 15C and [0125], “a user may correlate an action with a network security element by dragging and dropping an action item 1548 and a network element icon 1524, 1528 to the correlation area 1560”);
causing, by the incident service, display of a second version of the course of action, the second version of the course of action comprising the one or more actions and the suggested action, and the second version of the course of action identifying a sequence for executing the one or more actions and the suggested action (Thomas, [0130, 0131], “The reporting component 112 may also display one or more custom network security actions in the graphical user interface. … the correlation between the network security action and the network security element may be made by network security personal “on-the-fly,” or as the cyber-security attack is on-going”); and
causing, by the incident service, the second version of the course of action to be executed, wherein the causing comprises executing the one or more actions and the suggested action according to the identified sequence (Thomas, [0131], “the activation component 116 may respond to the cyber-security attack by executing custom network security actions where the correlation between and the action and network security element is provided by user input as the attack is on-going”).
Claim 8 lists substantially the same elements as claim 1, but in computer readable medium form rather than method form. Therefore, the rejection rationale for claim 1 applies equally as well to claim 8.
Claim 15 lists substantially the same elements as claim 1, but in apparatus form rather than method form. Therefore, the rejection rationale for claim 1 applies equally as well to claim 15.
Regarding claims 2, 9 and 16, Thomas disclosed the subject matter of claims 1, 8 and 15, respectively. Thomas further disclosed wherein the suggested action is a first suggested action, wherein the IT environment includes a plurality of types of services (Thomas, Fig. 15A-15E and [0131]) and wherein the method further comprises:
determining a second suggested action based at least in part on a type of service from the plurality of types of services (Thomas, [0126], “Once expanded the security analyst can very quickly see with elements and element types that are in the zone needing protection. … the visible security elements can be dragged onto correlation area 1560 or other assembly stage, grouped with common-English action names” Thomas shows here that the security analyst select the action based on the type of the security element); and
causing display of a ranked set of suggested actions, wherein the ranked set of suggested actions prioritizes the first suggested action over the second suggested action (Thomas, [0123], “When action sets for the interactive sequencing diagram 1501 are created, those that are to run in parallel or otherwise as a group can be displayed in the sequencing map of FIG. 15A as a grouping. The various groups can be displayed in an order in which they to run. For example, the grouping that runs first can be displayed on the far left, the subsequent group just to the right of first group, …”).
Regarding claims 3, 10 and 17, Thomas disclosed the subject matter of claims 1, 8 and 15, respectively. Thomas further disclosed wherein the suggested action is a first suggested action, wherein the IT environment further includes a plurality of types of computing devices (Thomas, Fig. 7), and wherein the method further comprises:
determining a second suggested action based at least in part on a type of computing device from the plurality of types of computing device (Thomas, [0126] and see the rejection rationale for claim 2 above); and causing display of a ranked set of suggested actions, wherein the ranked set of suggested actions prioritizes the first suggested action over the second suggested action (Thomas, [0123] and the rejection rationale for claim 2 above. The computing device in the claim corresponds to the network security elements in Thomas).
Regarding claims 4, 11 and 18, Thomas disclosed the subject matter of claims 1, 8 and 15, respectively. Thomas further disclosed wherein the one or more attributes associated with the incident comprises at least one of a domain name or an Internet Protocol (IP) address (Thomas, Figs. 15A-E and [0128], “As shown in FIGS. 15D-E, the data enrichment GUI 1580 may display cyber-security threat information that is detected or is being monitored as coming from a particular web address or IP address”).
Regarding claims 5, 12 and 19, Thomas disclosed the subject matter of claims 1, 8 and 15, respectively. Thomas further disclosed wherein the one or more actions and the suggested action are represented in a visual representation in the second version of the course of action using one or more blocks, wherein the one or more blocks includes at least a first action block corresponding to the suggested action (Thomas, Figs. 15C-E and [0131, 0135]).
Regarding claims 6, 13 and 20, Thomas disclosed the subject matter of claims 1, 8 and 15, respectively. Thomas further disclosed wherein execution of the suggested action involves using a format of a score or value returned as part of a preexisting action of the course of action (Thomas, [0065, 0066], “Real-time trigger event feeds of actionable items can be directly accepted by the activation component 116 in various formats to initiate pre-configured workflows.”).
Regarding claims 7 and 14, Thomas disclosed the subject matter of claims 1 and 8, respectively. Thomas further disclosed identifying one or more trends in action sequences associated with other courses of action; and wherein the suggested action is further determined based on the identified one or more trends (Thomas, [0075, 0079, 0090], “Data information may be delivered to data repositories as indicated in operation 610 for additional analysis and insight to review patterns and modify/create new response actions”).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIRLEY X ZHANG whose telephone number is (571)270-5012. The examiner can normally be reached 8:30am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon H Hwang can be reached at 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHIRLEY X ZHANG/Primary Examiner, Art Unit 2447