Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-20 are pending in this application.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: an incident clustering engine to cluster (claim 1); a cluster criteria manager to determine (claim 1); a retrieval augmented generation pipeline to access (claim 1); an investigation step engine to determine (claim 1); a cluster summarizer to determine (claim 3); an investigation manager to receive/assign/retrieve (claim 4); an investigation interface to present (claim 5); the investigation interface to receive (claim 6); a curation manager to perform (claim 6).
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 as being directed to non- statutory subject matter as being directed to an abstract idea without being integrated into a practical application or significantly more.
Regarding claim 1 and 15, claims 1 and 15 are rejected under U.S.C. 101 because the claimed invention is directed to an abstract idea without significant more. The claim recites "clustering incidents/runbooks by similarity [],” “determining inclusion criteria [],” “retrieving contextual information,” and “determining a suggested investigation step." Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea.
Accordingly, the claims recite an abstract idea. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that utilize “determining a suggested investigation step." It's noted that the claims recite the limitation “wherein the suggested investigation step comprises a natural language description and a programmatic query of a security incident data store." Said steps are not sufficient to consider the abstract idea is being interpreted into a practical application as said steps are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity. As discussed in the specification in paragraph [0019], "In an embodiment, determining the suggested investigation step for the cluster with
the retrieval augmented generation pipeline comprises determining the natural language description with a runbook of the cluster as a retrieval source of the retrieval augmented generation pipeline. In an embodiment, determining the suggested investigation step for the cluster with the retrieval augmented generation pipeline comprises determining the programmatic query with a schema of the security incident data store as a retrieval source of the retrieval augmented generation pipeline,” which is insufficiently considered as "being interpreted the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. It's also noted that the claims recited additional elements (i.e. computing device). However, said additional elements are recited at a high level of generality (i.e. generic computer components performing their conventional functions determining a suggested investigation step for the cluster with the retrieval augmented generation pipeline, wherein the suggested investigation step comprises a natural language description and a programmatic query of a security incident data store) such that it amounts no more than mere instructions to apply the exception or abstract idea using a generic computer component. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic functions (i.e. determining). See US 20240070270 by Mace et al. (See Mace, [0024]-[0027], [0037]-[0049], Figures 2 & 4). As discussed above, the additional elements recited as a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter as being directed to an abstract idea without being integrated into a practical application nor significantly more.
Regarding claims 2-14 and 16-20, claims 2-14 and 16-20 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims recite an abstract idea and the claims do not positively recite any other operations that could be considered as the abstract idea is being integrated into a practical application or significantly more.
It's noted that claim 2 recite the limitation "adds fields representing detected security incidents/anomaly thresholds." Similar to analysis discussed above, the limitation "adds fields representing detected security incidents/anomaly thresholds,” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation "adds fields representing detected security incidents/anomaly thresholds,” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claims 3 and 16 recite the limitation "determine [] a summary." Similar to analysis discussed above, the limitation "determine [] a summary,” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation "determine [] a summary,” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claims 4 and 17 recite the limitation "receive [],” “assign,” and “retrieve []." Similar to analysis discussed above, the limitation "receive [],” “assign,” and “retrieve [],” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation "receive [],” “assign,” and “retrieve [],” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claim 5 recites the limitation "presenting the incident and recommendation []." Similar to analysis discussed above, the limitation "presenting the incident and recommendation [],” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation "presenting the incident and recommendation [],” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claim 6 recites the limitation "receive [],” and “perform reinforcement [].” Similar to analysis discussed above, the limitation "receive [],” and “perform reinforcement [],” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation "receive [],” and “perform reinforcement [],” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claim 7 recites the limitation “investigation similarity comprises similarity metrics and semantic proximity,” Similar to analysis discussed above, the limitation “investigation similarity comprises similarity metrics and semantic proximity,” is recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitation “investigation similarity comprises similarity metrics and semantic proximity,” [],” is also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claims 8 and 18 recites the limitations “generate [],” “identify [],” and “compare [].” Similar to analysis discussed above, the limitations “generate [],” “identify [],” and “compare [],” are recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitations “generate [],” “identify [],” and “compare [],” are also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claims 9 and 19 recites the limitations “determine [],” “generate [],” and “determine [].” Similar to analysis discussed above, the limitations “determine [],” “generate [],” and “determine [],” are recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitations “determine [],” “generate [],” and “determine [],” are also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
It's noted that claims 10 and 20 recites the limitations “determine [],” “train [],” and “determine [].” Similar to analysis discussed above, the limitations “determine [],” “train [],” and “determine [],” are recited at a high level of generality, which is a form of insignificant extra-solution activity; and the limitations “determine [],” “train [],” and “determine [],” are also a mental process which is an abstract idea. Merely adding another abstract idea to the claim does not make the claim less abstract. See RecogniCorp, LLC V. Nintendo Co., 855 F.3d 1322, 1327 (Fed. Cir. 2017) ("Adding one abstract idea to another abstract idea does not render the claim non-abstract.").
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884) in view of Yen et al (“Yen,” WO 2023287921) and further in view of Mace et al (“Mace,” US 20240070270).
Regarding claim 1, Forte discloses a computing device for security incident analysis with adaptive incident clustering, the computing device comprising:
an incident clustering engine to cluster a plurality of security incidents and runbooks into a plurality of clusters based on investigation similarity associated with the plurality of security incidents and the runbooks; (Forte, Col. 7, Figures 4-5; Col. 9, Figure 7 describe historical security incidents in a multidimensional feature space, determines incident similarity using a distance metric, retrieves the playbooks associated with the nearest incidents, and describes clusters of identical incidents having associated playbooks)
Forte fails to explicitly disclose a cluster criteria manager to determine one or more criteria for inclusion of a security incident in each cluster of the plurality of clusters, wherein each of the one or more criteria comprises explainable logic for assignment of security incidents to the associated cluster;
However, in an analogous art, Yen discloses a cluster criteria manager to determine one or more criteria for inclusion of a security incident in each cluster of the plurality of clusters, wherein each of the one or more criteria comprises explainable logic for assignment of security incidents to the associated cluster, (Yen, [0109]-[0115]; Figures 13A-13B describe cluster outcome is interpreted using decision trees; cluster assignments serve as labels and features and rules distinguish one cluster from the others; [0114]-[0115] describe deriving the cluster’s internal structure from decision-tree rules)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Yen with Forte to include a cluster criteria manager to determine one or more criteria for inclusion of a security incident in each cluster of the plurality of clusters, wherein each of the one or more criteria comprises explainable logic for assignment of security incidents to the associated cluster. One would have been motivated to use interpretable clustering techniques to identify the need to determine the characteristics to distinguish one security cluster from another and to provide an interpretable representation of cluster structure and to improve transparency and explainability of incident grouping (Yen, [0114]).
Forte and Yen fail to explicitly disclose a retrieval augmented generation pipeline to access one or more retrieval sources for contextual awareness; and
an investigation step engine to determine a suggested investigation step for each cluster of the plurality of clusters with the retrieval augmented generation pipeline, wherein each suggested investigation step comprises a natural language description and a programmatic query of a security incident data store.
However, in an analogous art, Mace discloses a retrieval augmented generation pipeline to access one or more retrieval sources for contextual awareness; and (Mace, [0024]-[0027], [0037]-[0040], Figures 2 & 4 describe an LLM with retrieved or example security-language queries and descriptions called shots, prompt material and query/table information)
an investigation step engine to determine a suggested investigation step for each cluster of the plurality of clusters with the retrieval augmented generation pipeline, (Mace, [0037]-[0049], Figures 2 & 4 describe an LLM based generation of security investigation queries using contextual examples)
wherein each suggested investigation step comprises a natural language description and a programmatic query of a security incident data store, (Mace, [0024]-[0027], [0037]-[0049], Figures 2 & 4 describe pairing natural-language security-hunting descriptions with executable security-language queries (KQL) and uses the paring to generate a query)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Mace with Forte and Yen to include a retrieval augmented generation pipeline to access one or more retrieval sources for contextual awareness; and an investigation step engine to determine a suggested investigation step for each cluster of the plurality of clusters with the retrieval augmented generation pipeline, wherein each suggested investigation step comprises a natural language description and a programmatic query of a security incident data store. One would have been motivated to use an LLM-based security-query generation for using contextual examples and security-query information to prompt an LLM to generate an appropriate executable security-language query, thereby automating part of the analyst’s investigation workflow (Mace, [0042]).
Regarding claim 14, Forte, Yen and Mace disclose the computing device of claim 1.
Mace further discloses wherein to determine the suggested investigation step for the cluster with the retrieval augmented generation pipeline comprises to determine the programmatic query with a schema of the security incident data store as a retrieval source of the retrieval augmented generation pipeline, (Mace, [0042]-[0043], FIG 2 describes submitting a prompt to an LLM 301 and instructs the LLM to generate a KQL-security query based on the input query; [0045], FIG 2 describes the prompt includes table schema data 402. The schema identifies a particular table and particular columns relevant to the KQL query being generated. The data-store schema is supplied as contextual information for query generation; [0106]-[0107], Figures 10 and 12. The LLM prompt is generated using selected shots and query metadata, and includes query metadata in the form of table-schema information as context for the LLM to generate the correct output)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Mace with Forte and Yen to include wherein to determine the suggested investigation step for the cluster with the retrieval augmented generation pipeline comprises to determine the programmatic query with a schema of the security incident data store as a retrieval source of the retrieval augmented generation pipeline. One would have been motivated to supply the security data store schema as contextual input to the LLM for the purpose of identifying the relevant tables and columns enables the LLM to generate an executable security query that correctly addresses the requested investigation (Mace, [0045], [0106], and [0107]).
Regarding claim 15, Forte discloses a method for security incident analysis with adaptive incident clustering, the method comprising:
clustering, by a computing device, a plurality of security incidents and runbooks into a plurality of clusters based on investigation similarity associated with the plurality of security incidents and the runbooks; and for each cluster in the plurality of clusters: (Forte, Col. 7, Figures 4-5; Col. 9, Figure 7 describe historical security incidents in a multidimensional feature space, determines incident similarity using a distance metric, retrieves the playbooks associated with the nearest incidents, and describes clusters of identical incidents having associated playbooks)
Forte fails to explicitly disclose clustering, by a computing device, a plurality of security incidents and runbooks into a plurality of clusters based on investigation similarity associated with the plurality of security incidents and the runbooks; and for each cluster in the plurality of clusters:
However, in an analogous art, Yen discloses clustering, by a computing device, a plurality of security incidents and runbooks into a plurality of clusters based on investigation similarity associated with the plurality of security incidents and the runbooks; and for each cluster in the plurality of clusters: (Yen, [0061], describes a clustering operation, applying K-means or another clustering method to learned low-dimensional representations)
determining, by the computing device, one or more criteria for inclusion of a security incident in the cluster, wherein each of the one or more criteria comprises explainable logic for assigning security incidents to the associated cluster; (Yen, [0115] describes defining an internal structure S sub I for cluster C sub I such that data satisfying S sub I is more likely to belong to C sub I than another cluster. The criteria is expressed as conjunctive decision-tree conditions with multiple paths combined into DNF rules characterizing the cluster)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Yen with Forte to include clustering, by a computing device, a plurality of security incidents and runbooks into a plurality of clusters based on investigation similarity associated with the plurality of security incidents and the runbooks; and for each cluster in the plurality of clusters. One would have been motivated to use a decision-tree-derived cluster criteria to expose the distinguishing features and logical conditions defining cluster membership, making otherwise unsupervised clustering results interpretable to a security analyst (Yen, [0109], [0114]-[0115]).
Forte and Yen fail to explicitly disclose accessing, by the computing device, one or more retrieval sources for contextual awareness with a retrieval augmented generation pipeline of the computing device; and determining, by the computing device, a suggested investigation step for the cluster with the retrieval augmented generation pipeline, wherein the suggested investigation step comprises a natural language description and a programmatic query of a security incident data store.
However, in an analogous art, Mace discloses accessing, by the computing device, one or more retrieval sources for contextual awareness with a retrieval augmented generation pipeline of the computing device; and (Mace, [0027] describes constructing an LLM prompt using selected example shots plus query metadata, that includes table schemas and relevant tables. A trained model selects this contextual material and supplies it to the LLM)
determining, by the computing device, a suggested investigation step for the cluster with the retrieval augmented generation pipeline, (Mace, [0027] describes the retrieval and/or context-augmented LLM mechanism used to generate security-query output)
wherein the suggested investigation step comprises a natural language description and a programmatic query of a security incident data store, (Mace, [0024], describes converting natural-language input into a structured code-like security query, such as KQL; [0027] augments the prompt with selected examples and schema and/or query metadata and returns a corresponding security-language query)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Mace with Forte and Yen to include accessing, by the computing device, one or more retrieval sources for contextual awareness with a retrieval augmented generation pipeline of the computing device; and determining, by the computing device, a suggested investigation step for the cluster with the retrieval augmented generation pipeline, wherein the suggested investigation step comprises a natural language description and a programmatic query of a security incident data store. One would have been motivated to retrieve relevant security-query examples and schema metadata and provide them as context to the LLM such that contextual augmentation improves the accuracy of the generated programmatic security query and its correspondence to the intended security investigation (Mace, [0027]).
Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Coulter et al (“Coulter,” US 20230252140).
Regarding claim 2, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein each security incident of the plurality of security incidents comprises a record including a plurality of fields that are indicative of a detected computer security incident or a detected network security incident characterized by anomaly detection thresholds.
However, in an analogous art, Coulter discloses wherein each security incident of the plurality of security incidents comprises a record including a plurality of fields that are indicative of a detected computer security incident or a detected network security incident characterized by anomaly detection thresholds, (Coulter, [0028]-[0029] describes computer-event data stored in a ledger/database as data-frame records containing multiple data fields, including fields such as usernames, hostnames, MAC addresses, process descriptions, file data, and other event information. Those fields originate from monitoring computer and/or network events and provide the information used to characterize and compare the events for security analysis; [0070]-[0071], FIG 4, Step 416 describes the system identifies an event as anomalous when its calculated distance exceeds a predetermined threshold. The security event represented by the multi-field record is characterized as anomalous using a threshold criterion)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Coulter with Forte, Yen and Mace to include wherein each security incident of the plurality of security incidents comprises a record including a plurality of fields that are indicative of a detected computer security incident or a detected network security incident characterized by anomaly detection thresholds. One would have been motivated to identify anomalous computer events from detailed event data and distinguish unusual events from normal event cohorts using measurable distance criteria (Coulter, [0028]-[0029], [0070]-[0071])
Claims 3 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Davraev et al (“Davraev,” US 20250088517).
Regarding claim 3, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose further comprising a cluster summarizer to determine, with a large language model, a summary of each cluster in the plurality of clusters based on the security incidents of the cluster.
However, in an analogous art, Davraev discloses further comprising a cluster summarizer to determine, with a large language model, a summary of each cluster in the plurality of clusters based on the security incidents of the cluster, (Davraev, [0075]-[0076] the system forms a security incident alerts group from related security alerts and identifies the attack-type bucket(s) associated with those grouped alerts; [0083], the security alert generative language model 310 receives the grouped security alerts and attack-type information and generates the resulting security incident report. The generative language model is an LLM. The generated security incident report includes a plain language description/narrative based on the security alerts contained in the security-incident group and the associated attack-type information; FIG 6 directly depicts security incident alerts group 416 to a generative language model 310 to a security incident report 604).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Davraev with Forte, Yen and Mace to include further comprising a cluster summarizer to determine, with a large language model, a summary of each cluster in the plurality of clusters based on the security incidents of the cluster. One would have been motivated to summarize a group of related security alerts using the disclosed generative language model to provide a concise, contextual, plain language description of the underlying security incident, thereby improving an analysts ability to understand and respond to the grouped security activity (Davraev, [0018], [0020], [0083]).
Regarding claim 16, claim 16 is directed to the method of claim 15. Claim 16 is similar in scope to claim 3 and is therefore rejected under the same rationale.
Claims 4-5 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Forte et al (“Forte ‘001,” US 20210398001).
Regarding claim 4, Forte, Yen and Mace disclose the computing device of claim 1.
Mace further discloses wherein the first suggested investigation step was determined by the retrieval augmented generation pipeline for the first cluster, (Mace, [0041]-[0045], Figures 2 & 4 describe contextual material to an LLM including example natural language/KQL query pairs and security-data/table information and uses that augmented prompt to generate the executable security query. The system automatically clusterizes stored incidents and identifies prior incidents most similar to the current incident based on their fields/features)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Mace with Forte and Yen to include wherein the first suggested investigation step was determined by the retrieval augmented generation pipeline for the first cluster. One would have been motivated to use a context-augmented LLM query generation so that information associated with a group of similar security incidents could be used to automatically generate an executable query for investigating the newly assigned incident thereby reducing manual query formulation and making the incident recommendation more directly actionable (Mace, [0041]-[0045]).
Forte, Yen and Mace fail to explicitly disclose further comprising an investigation manager to: receive a first security incident, wherein the security incident comprises a plurality of fields indicative of a potential security detection at a monitored computer system or network; assign the first security incident to a first cluster of the plurality of clusters based on the one or more criteria for inclusion of the security incident in each cluster of the plurality of clusters; and retrieve a first suggested investigation step for the first cluster, wherein the first suggested investigation step was determined by the retrieval augmented generation pipeline for the first cluster.
However, in an analogous art, Forte ‘001 discloses further comprising an investigation manager to: receive a first security incident, wherein the security incident comprises a plurality of fields indicative of a potential security detection at a monitored computer system or network; (Forte ‘001, [0019] the system receives details to a cybersecurity incident with those details corresponding to a set of features of the incident. Those features are then used to represent and compare the incident in feature space)
assign the first security incident to a first cluster of the plurality of clusters based on the one or more criteria for inclusion of the security incident in each cluster of the plurality of clusters; (Forte ‘001, [0044], The machine learning system automatically clusterizes the stored incident-details space and identifies prior incidents that are most similar to the incident being managed based on field/feature values. The incident is associated with a similarity-defined region/group based on its features)
and retrieve a first suggested investigation step for the first cluster, (Forte ‘001, [0143], for a given incident, the system searches for the most similar incidents and uses their associated playbooks to synthesize a custom tailored playbook. Those playbooks contain actions and/or prescriptive procedures for incident response and investigation)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Forte ‘001 with Forte, Yen and Mace to include further comprising an investigation manager to: receive a first security incident, wherein the security incident comprises a plurality of fields indicative of a potential security detection at a monitored computer system or network; assign the first security incident to a first cluster of the plurality of clusters based on the one or more criteria for inclusion of the security incident in each cluster of the plurality of clusters; and retrieve a first suggested investigation step for the first cluster, wherein the first suggested investigation step was determined by the retrieval augmented generation pipeline for the first cluster. One would have been motivated to assign a new cybersecurity incident to a similarity-based incident grouping and retrieve associated investigation actions because do so reduces repetitive incident handling and permits proven procedures from similar historical incidents to be reused in generating an incident-specific response (Forte ‘001, [0016], [0019] and [0044]).
Regarding claim 5, Forte, Yen, Mace and Forte ‘001 disclose the computing device of claim 4.
Forte further discloses further comprising an investigation interface to present the first security incident and the first suggested investigation step to a first user, (Forte describes in Col. 11, Lines 7-16 & 49-55; Figure 8 the user interacts with the cybersecurity incident-response platform through a web interface and the playbook generation system returns its results through that platform to the user. During playbook recommendation, the user is expressly presented with recommend actions together with the relevant incidents from which those actions were derived. Thus, the interface presents both the security-incident information and the suggested response/investigation actions to the user; Figures 9-11; Col. 13, Lines 1-14 describe FIG 9 shows the incident interface; Figures 10-11 show proposed playbooks containing prescriptive response procedures displayed to the user).
Regarding claim 17, claim 17 is directed to the method of claim 15. Claim 17 is similar in scope to claim 4 and is therefore rejected under the same rationale
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921), Mace et al (“Mace,” US 20240070270) in view of Forte et al (“Forte ‘001,” US 20210398001) and further in view of Givental et al (“Givental,” US 20250300995).
Regarding claim 6, Forte, Yen, Mace and Forte ‘001 disclose the computing device of claim 5.
Forte, Yen, Mace, Forte ‘001 fail to explicitly disclose wherein the investigation interface is further to receive a security incident resolution from the first user, the computing device further comprising a curation manager to perform reinforcement learning with human feedback based on the security incident resolution.
However, in an analogous art, Givental discloses wherein the investigation interface is further to receive a security incident resolution from the first user, the computing device further comprising a curation manager to perform reinforcement learning with human feedback based on the security incident resolution, (Givental, [0015] describes the analyst uses tools to triage and determine a disposition to security threats. Once reinforcement learning is allowed, the machine learning model can improve its recommendations based on analyst interaction; [0047],describes that the machine-learning model is trained through reinforcement learning based on validating whether the provided recommendation is appropriate; [0048] further states that the system performs a follow up action base don input from the cybersecurity analyst, including closing the investigation; further [0047]-[0048] describe the reinforcement learning signal is the analyst’s validation of the recommended action and the resulting analyst input drives the follow up disposition, including closing or escalating the investigation; also see FIG 3)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Givental with Forte, Yen, Mace, Forte ‘001 to include wherein the investigation interface is further to receive a security incident resolution from the first user, the computing device further comprising a curation manager to perform reinforcement learning with human feedback based on the security incident resolution. One would have been motivated to use the analyst’s incident disposition as reinforcement-learning feedback to make the system learn from human validation of recommended actions and improve the accuracy of future cybersecurity investigation and response recommendations (Givental, [0015], [0047]-[0048]).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Hercock et al (“Hercock,” US 20240045962).
Regarding claim 7, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein investigation similarity comprises vector similarity metrics and semantic proximity.
However, in an analogous art, Hercock discloses wherein investigation similarity comprises vector similarity metrics and semantic proximity, (Hercock, [0021]-[0022], FIG 2 describes the system generates vector embeddings for security-event data fields, evaluates the distance of those embeddings from a reference vector, and identifies similar records based on the degree of similarity of those distances; [0020] describes the vector embedded uses a neural network to generate embeddings that represent the semantic meaning of the data fields. Closeness and/or distance between those embeddings represents semantic proximity; [0028] & FIG 4 describe the technique is applied to security-event records, where similar records are identified and systems are clustered based on a common security occurrence)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Hercock with Forte, Yen and Mace to include wherein investigation similarity comprises vector similarity metrics and semantic proximity. One would have been motivated to use vector-distance metrics over semantic embeddings because doing so enables security-event records to be compared according to semantic similarity and grouped based on common security characteristics (Hercock, [0005], [0020], [0022]).
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921), Mace et al (“Mace,” US 20240070270) in view of Hercock et al (“Hercock,” US 20240045962) and further in view of Stuempfle et al (“Stuempfle,” US 20140250125).
Regarding claim 8, Forte, Yen, Mace and Hercock disclose the computing device of claim 7.
Forte, Yen, Mace and Hercock fail to explicitly disclose wherein to cluster the plurality of security incidents and runbooks comprises to: generate a vector embedding for each security incident of the plurality of security incidents and for each runbook; identify the vector embedding associated with each runbook as a centroid of a corresponding cluster; and compare the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity.
However, in an analogous art, Steumpfle discloses wherein to cluster the plurality of security incidents and runbooks comprises to: generate a vector embedding for each security incident of the plurality of security incidents and for each runbook; identify the vector embedding associated with each runbook as a centroid of a corresponding cluster; and compare the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity, (Steumpfle, [0033], [0035] describe each incident is represented as a vector. Each incident-addressing step is also represented/positioned using vector attributes. The incident-addressing steps are the operative contents of the autonomous runbook; [0031]-[0032] describes a reference item is represented as a d-dimensional vector and that vector expressly defines the centroid of a corresponding cluster; [0032]-[0036] describes a vector distance and/or nearest-neighbor relationships are used among incidents, clusters, applications, and incident addressing steps to identify the appropriate incident-addressing step for the current incident)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Steumpfle with Forte, Yen, Mace and Hercock to include wherein to cluster the plurality of security incidents and runbooks comprises to: generate a vector embedding for each security incident of the plurality of security incidents and for each runbook; identify the vector embedding associated with each runbook as a centroid of a corresponding cluster; and compare the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity. One would have been motivated to use vector representations and centroid-based clustering for incident-response selection for providing geometric similarity between an incident and clustered reference information to be used efficiently to identify an appropriate incident-addressing step for the incident (Steumpfle, [0031]-[0036]).
Claims 9 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Bulut et al (“Bulut,” US 20240427879).
Regarding claim 9, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein to cluster the plurality of security incidents and runbooks comprises to: determine a natural language description of investigation steps for each security incident with a large language model; generate an embedding for the natural language description of investigation steps for each security incident of the plurality of security incidents; and determine investigation similarity based on the embedding associated with the natural language description of each security incident.
However, in an analogous art, Bulut discloses wherein to cluster the plurality of security incidents and runbooks comprises to: determine a natural language description of investigation steps for each security incident with a large language model; generate an embedding for the natural language description of investigation steps for each security incident of the plurality of security incidents; and determine investigation similarity based on the embedding associated with the natural language description of each security incident, (Bulut, [0036]-[0038], FIG 1B describes the system uses a natural language generation process to generate natural language descriptions corresponding to security log lines which are used to train/fine tune the security embedding LLM 132; FIG 1B describes security logs and alerts to natural language describes to fine tuning to security embedding generation LLM; [0098]-[0100], FIG 4A describes the system generates a natural language description corresponding to each security log line and then generates a log-line embedding using that natural-language description; FIG 4A, steps 408-410 describe generate natural language descriptions and generate embeddings using those descriptions; [0101]-[0102], FIG 4A describe the system determines embedding distances between a search query embedding and security log embeddings and identifies relevant security information based on those distances)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Bulut with Forte, Yen and Mace to include wherein to cluster the plurality of security incidents and runbooks comprises to: determine a natural language description of investigation steps for each security incident with a large language model; generate an embedding for the natural language description of investigation steps for each security incident of the plurality of security incidents; and determine investigation similarity based on the embedding associated with the natural language description of each security incident. One would have been motivated to represent natural-language security descriptions as embeddings and compare those embeddings to enable semantically relevant security information to be identified and used to generate more accurate and contextually relevant investigation responses (Bulut, [0022], [0098]-[0102]).
Regarding claim 19, claim 19 is directed to the method of claim 15. Claim 19 is similar in scope to claim 9 and is therefore rejected under the same rationale.
Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921), Mace et al (“Mace,” US 20240070270) in view of Zhao et al (“Zhao,” “Malware Detection Method Based on the Control-Flow Construct Feature of Software,” 2014, Pages 18-24) and further in view of Ntoutsi et al (“Ntoutsi,” “A General Framework for Estimating Similarity of Datasets and Decision Trees: Exploring Similarity of Decision Trees, SDM, 2008, Pages 1-12).
Regarding claim 10, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein to cluster the plurality of security incidents and runbooks comprises to: determine a label for each security incident of the plurality of security incidents, wherein the label comprises a benign label or a malicious label; train a plurality of classification models on the labels associated with each of the plurality of security incidents; and determine investigation similarity based on similarity of classification model.
However, in an analogous art, Zhao discloses wherein to cluster the plurality of security incidents and runbooks comprises to: determine a label for each security incident of the plurality of security incidents, wherein the label comprises a benign label or a malicious label; (Zhao, Section 3.3, Page 21, FIG 3 describes that during training, executable are labeled benign or malicious, and that each executable’s features include a label indicating benign or malicious)
train a plurality of classification models on the labels associated with each of the plurality of security incidents; (Zhao, Section 3.3, Page 21, Figures 3-4 describe that multiple classifiers are trained to classify an executable as benign or malicious; FIG 3 shows the training architecture and FIG 4 shows the classification rules for a J48 classifer)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Zhao with Forte,Yen and Mace to include wherein to cluster the plurality of security incidents and runbooks comprises to: determine a label for each security incident of the plurality of security incidents, wherein the label comprises a benign label or a malicious label; train a plurality of classification models on the labels associated with each of the plurality of security incidents; and determine investigation similarity based on similarity of classification model. One would have been motivated to train multiple benign or malicious classifiers to improve automated detection and classification of malicious software from learned security features (Zhao, Section 3.3, Page 21, Figure 3)
Forte, Yen, Mace and Zhao fail to explicitly disclose and determine investigation similarity based on similarity of classification model.
However, in an analogous art, Ntoutsi discloses and determine investigation similarity based on similarity of classification model, (Ntoutsi, Section 4.3, Page 5; Eq. 4.9 describes a semantic similarity measure between decision-tree classification models, based on the extent to which the models agree in their predictions; Page 1, Introduction; Page 12 Conclusion describes that the similarity measures can be used to perform mining tasks on classification models rather than raw data, including clustering models into groups of similar behavior. Decision trees can be clustered using semantic similarity and a representative tree selected for each cluster).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Ntoutsi with Forte, Yen, Mace and Zhao to include wherein to cluster the plurality of security incidents and runbooks comprises to: determine a label for each security incident of the plurality of security incidents, wherein the label comprises a benign label or a malicious label; train a plurality of classification models on the labels associated with each of the plurality of security incidents; and determine investigation similarity based on similarity of classification model. One would have been motivated to measure similarity between classification models to determine whether trained models exhibit semantically similar decision behavior and to enable clustering or other analysis based on that model similarity (Ntoutsi, Page 1, Introduction; Section 4.3, Page 5, Conclusion, Page 12).
Regarding claim 20, claim 20 is directed to the method of claim 15. Claim 20 is similar in scope to claim 10 and is therefore rejected under the same rationale.
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921), Mace et al (“Mace,” US 20240070270) in view of Singla et al (“Singla,” US 20150135263) and further in view of Walthers et al (“Walthers,” US 20180322508).
Regarding claim 11, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: identify a high granularity field of the plurality of security incidents; and match against values of the high granularity field for the plurality of security incidents in the cluster.
However, in an analogous art, Singla discloses wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: identify a high granularity field of the plurality of security incidents; and match against values of the high granularity field for the plurality of security incidents in the cluster, (Singla, [0029], [0036], Figures 2-3 describes cardinality is determined for event-data fields, where cardinality is the number of unique values, and selects high-cardinality fields; [0031]-[0032] describes the pattern identifier compares event records against criteria in a patten discovery profile and identifies events whole field values satisfy those criteria)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Singla with Forte, Yen and Mace to include wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: identify a high granularity field of the plurality of security incidents; and match against values of the high granularity field for the plurality of security incidents in the cluster. One would have been motivated to select high-cardinality security-event fields because such fields provide discriminating event values useful for automated pattern discovery and detection of suspicious network activity (Singla, [0012], [0029] and [0036]).
Forte, Yen, Mace and Singla fail to explicitly disclose and match against values of the high granularity field for the plurality of security incidents in the cluster.
However, in an analogous art, Walthers discloses and match against values of the high granularity field for the plurality of security incidents in the cluster, (Walthers, [0040]-[0042], Fig 3 describes clusters incident reports and evaluates whether the incidents within a particular cluster have the same attribute values for an evaluation field; [0040] checks whether each incident in a cluster has the same assignment-field value; [0042] describes evaluating each group based on whether the grouped incidents share the same field values)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Walthers with Forte, Yen, Mace and Singla to include and match against values of the high granularity field for the plurality of security incidents in the cluster. One would have been motivated to match field values across incidents in a cluster because common field values provide an objective criterion for confirming that the grouped incidents represent the same or closely related items (Walthers, [0040]-[0042]).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Anderson et al (“Anderson,” US 20170099304).
Regarding claim 12, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: determine fields of the plurality of security incidents having a high divergence between first security incidents in the cluster and second security incidents outside of the cluster; and match against values of the fields having the high divergence.
However, in an analogous art, Anderson discloses wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: determine fields of the plurality of security incidents having a high divergence between first security incidents in the cluster and second security incidents outside of the cluster; (Anderson, [0020], [0028], FIG 3 describes distinguishing cluster data from non-cluster data then compares the cluster centroid vector to samples outside the cluster. Each matrix row is based on the absolute difference between the cluster. Each matrix row is based on the absolute difference between the cluster centroid and non-cluster sample, and the resulting optimization identifies the minimal set of features that uniquely differentiates the cluster)
and match against values of the fields having the high divergence, (Anderson, [0033], [0037]-[0038], FIG 4B describes the selected discriminatory features are converted into a cluster description and/or malware signature or machine-readable rule such as IP-range, registry-access and file-access conditions. Those rules are then used as indicators for identifying matching malware and/or security activity)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Anderson with Forte, Yen and Mace to include wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to: determine fields of the plurality of security incidents having a high divergence between first security incidents in the cluster and second security incidents outside of the cluster; and match against values of the fields having the high divergence. One would have been motivated to select fields that most strongly distinguish in-cluster from out-of-cluster security data to yield a compact, machine-readable cluster definition with improved fidelity and fewer false positives (Anderson, [0013]-[0014] and [0020]).
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Baker et al (“Baker,” US 20200320371).
Regarding claim 13, Forte, Yen and Mace disclose the computing device of claim 1.
Forte, Yen and Mace fail to explicitly disclose wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to train a machine learning classifier to classify between first security incidents in the cluster and second security incidents outside of the cluster.
However, in an analogous art, Baker discloses wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to train a machine learning classifier to classify between first security incidents in the cluster and second security incidents outside of the cluster, (Baker, [0373], [0375], FIG 13 describes that the clustering method uses a classifier to do the clustering and given an existing clustering, the system trains a classifier to recognize the cluster-assignment values. The existing cluster assignment is used as the supervised-training target; [0376]-[0377], FIG 13 describes each data example is classified according to its cluster assignment. The classifier can have one output node for each cluster, so the output corresponding to the assigned cluster distinguishes membership in that cluster from assignment to the other clusters. Once trained, the classifier is used to classify existing or new data)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Baker with Forte, Yen and Mace to include wherein to determine the one or more criteria for inclusion of a security incident in the cluster comprises to train a machine learning classifier to classify between first security incidents in the cluster and second security incidents outside of the cluster. One would have been motivated to train a classifier using existing cluster memberships because doing so allows the learned classifier to automatically distinguish cluster members from non-members and assign new data to the appropriate cluster (Baker, [0373], [0375] and [0377]).
Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Forte et al (“Forte,” US 10,439,884), Yen et al (“Yen,” WO 2023287921) in view of Mace et al (“Mace,” US 20240070270) and further in view of Stuempfle et al (“Stuempfle,” US 20140250125).
Regarding claim 18, Forte, Yen and Mace disclose the method of claim 15.
Forte, Yen and Mace fail to explicitly disclose generating a vector embedding for each security incident of the plurality of security incidents and for each runbook; identifying the vector embedding associated with each runbook as a centroid of a corresponding cluster; and comparing the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity.
However, in an analogous art, Steumpfle discloses generating a vector embedding for each security incident of the plurality of security incidents and for each runbook; identifying the vector embedding associated with each runbook as a centroid of a corresponding cluster; and comparing the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity, (Steumpfle, [0033], [0035] describe each incident is represented as a vector. Each incident-addressing step is also represented/positioned using vector attributes. The incident-addressing steps are the operative contents of the autonomous runbook; [0031]-[0032] describes a reference item is represented as a d-dimensional vector and that vector expressly defines the centroid of a corresponding cluster; [0032]-[0036] describes a vector distance and/or nearest-neighbor relationships are used among incidents, clusters, applications, and incident addressing steps to identify the appropriate incident-addressing step for the current incident)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Steumpfle with Forte, Yen and Mace to include generating a vector embedding for each security incident of the plurality of security incidents and for each runbook; identifying the vector embedding associated with each runbook as a centroid of a corresponding cluster; and comparing the vector embedding associated with each security incident to each of the centroids to determine an associated investigation similarity. One would have been motivated to use vector representations and centroid-based clustering for incident-response selection for providing geometric similarity between an incident and clustered reference information to be used efficiently to identify an appropriate incident-addressing step for the incident (Steumpfle, [0031]-[0036]).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-3774. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES J WILCOX/Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439