DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to the applicant’s filing on 05/13/2025. Claims 1-20 are pending. Claims 1, 9, and 15 are independent.
Priority
Priority Acknowledgement is made of applicant’s claiming of priority, as a continuation, to application 17/646,696 filed on 12/31/2021.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 05/13/2025 and 06/05/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12335276. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are anticipated by the claims of Patent No. 12335276. For the mapping of claims, see the table below.
App. 19/206,696
Patent No. 12335276
A method comprising:
updating, through a recursive technique, a numerical aggregate value representing an observed value of a categorical variable, the numerical aggregate value based on (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times historical events over a network and associated with the observed value led to an outcome of interest, wherein a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes;
extracting features from a detected event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable;
applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the detected event; and
based on the score, controlling access to a resource of the network.
1. A method comprising:
detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable;
updating, through a recursive technique, a numerical aggregate value representing the observed value of the categorical variable, the numerical aggregate value based on both (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times the historical events associated with the observed value led to an outcome of interest, wherein the numerical aggregate value is computed as an exponentially decayed event function and a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes;
detecting an event occurring over the network and associated with the observed value of the categorical variable;
extracting features from the event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable; applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the event; and
based on the score, controlling access to a resource of the network.
2. The method of claim 1, further comprising: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable; and detecting an event occurring over the network and associated with the observed value of the categorical variable.
(Claim 1) detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable;
…
detecting an event occurring over the network and associated with the observed value of the categorical variable;
…
3. The method of claim 1, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network, and wherein the method further comprises updating an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
2. The method of claim 1, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network.
3. The method of claim 2, further comprising updating an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
4. The method of claim 3, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
4. The method of claim 3, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
5. The method of claim 3, further comprising computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
5. The method of claim 3, further comprising computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
6. The method of claim 1, further comprising: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
6. The method of claim 1, further comprising: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
7. The method of claim 1, wherein the numerical aggregate value is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function.
7. The method of claim 1, wherein the numerical aggregate value is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function.
8. The method of claim 1, wherein the encoded feature is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function.
8. The method of claim 1, wherein the encoded feature is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function.
9. A system comprising: a processor; and a non-transitory computer-readable medium comprising instructions that are executable by the processor for causing the processor to perform operations comprising: updating, through a recursive technique, a numerical aggregate value representing an observed value of a categorical variable, the numerical aggregate value based on (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times historical events over a network and associated with the observed value led to an outcome of interest, wherein a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes; extracting features from a detected event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable; applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the detected event; and based on the score, controlling access to a resource of the network.
9. A system comprising: a processor; and a non-transitory computer-readable medium comprising instructions that are executable by the processor for causing the processor to perform operations comprising: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable; updating, through a recursive technique, a numerical aggregate value representing the observed value of the categorical variable, on both (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times the historical events associated with the observed value led to an outcome of interest, wherein the numerical aggregate value is computable as an exponentially decayed event function and a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes; detecting an event occurring over the network and associated with the observed value of the categorical variable; extracting features from the event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable; applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the event; and based on the score, controlling access to a resource of the network.
10. The system of claim 9, wherein the operations further comprise: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable; and detecting an event occurring over the network and associated with the observed value of the categorical variable.
(Claim 1) detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable;
…
detecting an event occurring over the network and associated with the observed value of the categorical variable;
…
11. The system of claim 9, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network, and wherein an aggregation subsystem is configured to update an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
10. The system of claim 9, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network.
11. The system of claim 10, wherein an aggregation subsystem is configured to update an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
12. The system of claim 11, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
12. The system of claim 11, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
13. The system of claim 11, wherein the operations further comprise computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
13. The system of claim 11, wherein the operations further comprise: computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
14. The system of claim 9, wherein the operations further comprise: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
14. The system of claim 9, wherein the operations further comprise: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
15. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause the processing device to perform operations comprising: updating, through a recursive technique, a numerical aggregate value representing an observed value of a categorical variable, the numerical aggregate value based on (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times historical events over a network and associated with the observed value led to an outcome of interest, wherein a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes; extracting features from a detected event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable; applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the detected event; and based on the score, controlling access to a resource of the network.
15. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause the processing device to perform operations comprising: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable; updating, through a recursive technique, a numerical aggregate value representing the observed value of the categorical variable, on both (i) an exponentially smoothed prior numerical aggregate value representing prior historical events associated with the observed value and (ii) an exponentially smoothed positive count aggregate representing a number of times the historical events associated with the observed value led to an outcome of interest, wherein the numerical aggregate value is computable as an exponentially decayed event function and a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes; detecting an event occurring over the network and associated with the observed value of the categorical variable; extracting features from the event, wherein the features comprise an encoded feature based on the numerical aggregate value to represent the observed value of the categorical variable; applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the event; and based on the score, controlling access to a resource of the network.
16. The non-transitory computer-readable storage medium of claim 15, wherein the operations further comprise: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable; and detecting an event occurring over the network and associated with the observed value of the categorical variable.
(Claim 1) detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable;
…
detecting an event occurring over the network and associated with the observed value of the categorical variable;
…
17. The non-transitory computer-readable storage medium of claim 15, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network, and wherein the operations further comprise updating an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
16. The non-transitory computer-readable storage medium of claim 15, wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network.
17. The non-transitory computer-readable storage medium of claim 16, the operations further comprising updating an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest.
18. The non-transitory computer-readable storage medium of claim 17, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
18. The non-transitory computer-readable storage medium of claim 17, wherein the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate.
19. The non-transitory computer-readable storage medium of claim 17, the operations further comprising computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
19. The non-transitory computer-readable storage medium of claim 17, the operations further comprising computing the encoded feature, wherein computing the encoded feature comprises: updating the exponentially smoothed total count aggregate based on a time of the event; updating the exponentially smoothed positive count aggregate based on the time of the event; and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate.
20. The non-transitory computer-readable storage medium of claim 15, the operations further comprising: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; and determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
20. The non-transitory computer-readable storage medium of claim 15, the operations further comprising: detecting additional historical events occurring over the network, wherein at least one of the additional historical events is associated with a second observed value of the categorical variable; and determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; and assigning a second numerical aggregate value to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-4, 7-12 15-18 are rejected under 35 U.S.C. 103 as being unpatentable over Sampaio et al. (US PGPub No. 2020/0366699; hereinafter “Sampaio”) in view of Zoldi et al. (US PGPub No. 2015/0195299; hereinafter “Zoldi”) in view of Laptiev et al. (US PGPub No. 2021/0097545; hereinafter “Laptiev”).
As per claim 1: Sampaio discloses a method comprising:
updating, [through a recursive technique], a numerical aggregate value representing an observed value of a categorical variable, the numerical aggregate value based on (i) [an exponentially smoothed] prior numerical aggregate value representing prior historical events associated with the observed value and (ii) [an exponentially smoothed] positive count aggregate representing a number of times historical events over a network and associated with the observed value led to an outcome of interest, wherein [a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes] (event values [¶ 0070]; For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C [¶ 0071, the event value is the observed value, the total count C is the prior numerical aggregate value]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073, the count of items in the identified percentile bin is the positive count aggregate]; The process adjusts one or more counts of data items in one or more of the percentile bins including by applying a suppression factor based on a relative ordering of items… assigning a lower weight to older events [¶ 0074. Fig. 8, exponentially weighted events]; exponentially weighted events, x-axis is index or time, y-axis is weight [Fig. 8]; The process calculates a threshold based at least in part on the percentile distribution (514) [¶ 0077, the threshold refers to an updated numerical aggregate value]; the threshold is obtained by further processing the outlier definition using delayed exponential weighting on previous estimates to obtain a final threshold [¶ 0078]; giving greater weight to more recent transactions [¶ 0078]; a higher importance is given to more recent monitoring events [¶ 0097-0098]; exponential moving average smoothing [¶ 0102]; Gateway 1210 receives transaction data from one or more transaction devices 1202-1206, routes the transaction data to network 1220 [¶ 0139, Fig. 12]; the input dataset includes events/data records in a stream of data [¶ 0038]; the R window contains events in a reference period prior to the target window T, prior events are historical events [¶ 0040]; the reference window R also moves to contain the four events immediately preceding window T [¶ 0051]; For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C, the event value is the observed value [¶ 0071]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073]);
extracting features from a detected event, [wherein the features comprise an encoded feature] based on the numerical aggregate value to represent the observed value of the categorical variable (the set of features can contain a subset containing raw fields of the data record and/or transformations of the raw fields, taking the features from the data record [¶ 0111]; identify one of the set of percentile bins corresponding to the new data item [Fig. 5, element 504]; For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C [¶ 0071, the event value is the observed value]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073]; The process adjusts one or more counts of data items in one or more of the percentile bins including by applying a suppression factor based on a relative ordering of items [¶ 0074]);
applying a predictive model, the predictive model having been trained on at least the numerical aggregate value, to the features to determine a score representing likelihood of an outcome for the detected event (the explanation is determined by training a machine learning model to find a pattern that distinguishes events in a target window T from the events in a reference window R. The output score and the feature importance of that machine learning model is then used to summarize the characteristics of the alarm [¶ 0035]; trains a second machine learning model to learn how to differentiate between two groups … the second machine learning model is a classification model that differentiates between groups based on the features and/or model score present in each of the data records [¶ 0111]; the process (optionally) proceeds by comparing the monitoring value(s) to a threshold and providing an indication that the monitoring value(s) meets/exceeds a threshold [¶ 0043]); and
based on the score, controlling access to a resource of the network (the process determines monitoring values (204). Each monitoring value is associated with a measure of similarity between model scores for those data records of the input dataset, the monitoring values are based on the score [¶ 0040]; When a monitoring value exceeds the threshold, a number of responses are possible. … As another example, the process blocks the attack (e.g. bot attack) and reports the attack to an administrator, blocking the attack is controlling access to the resource [¶ 0044]).
Sampaio discloses the claimed subject matter as discussed above but does not explicitly disclose through a recursive technique; an exponentially smoothed; a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes. However, Zoldi teaches through a recursive technique (process streaming transactions by maintaining real-time entity profiles, which include real-time recursively updated variables, and to utilize real-time updated calibration profiles to scale individual variables as well as transform this multitude of attributes into a single score … [Zoldi ¶ 0033]; transaction profiling technology, on the other hand, does not require explicit storage of a transaction history, and instead utilizes recursive formulas to decay and adjust variable estimates smoothly over events or physical timescales [Zoldi ¶ 0043, ¶ 0044-0049]); an exponentially smoothed (adjust variables smoothly over events or physical timescales [Zoldi ¶ 0043]); a decay parameter controls a rate at which contribution of historical events to the numerical aggregate value decays as time passes (transaction profiling technology, on the other hand, does not require explicit storage of a transaction history, and instead utilizes recursive formulas to decay and adjust variable estimates smoothly over events or physical timescales [¶ 0043, Examiner’s Note: see formula]; The above recursive variable example allows a current estimated value pv, to be based on the past estimate pv t-1 and on a function of the current transaction being processed. Transaction profiles are computationally efficient and provide real-time predictive scores for low-latency decisions such as fraud decisions on credit card authorizations [¶ 0049]). Sampaio and Zoldi are analogous art because they are from the same field of endeavor of computer network security. Therefore, based on Sampaio in view of Zoldi, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Zoldi to the system of Sampaio in order to improve updating scores through computationally efficient profiles allowing for real-time predictive scores where current estimates are based on past estimates (¶ 0049, ¶ 0033, ¶ 0043-0048). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Sampaio in view of Zoldi discloses the claimed subject matter as discussed above but does not explicitly disclose wherein the features comprise an encoded feature. However, Laptiev teaches wherein the features comprise an encoded feature (is configured to perform feature encoding on one or more categorical variables in a first matrix to generate one or more feature encoded categorical variables [¶ 0007; Fig. 5, element 506]). Sampaio in view of Zoldi and Laptiev are analogous art because they are from the same field of endeavor of fraud prevention. Therefore, based on Sampaio in view of Zoldi in view of Laptiev, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Laptiev to the system of Sampaio in view of Zoldi in order to achieve a higher capture of nefarious actors through behavioral analysis, and improve the efficiency of computer resources used by a client server (behavioral biometrics provide a more reliable means of loss prevention by analyzing reliable behavior signals and detecting fraud at application-time, prior to possible loss [¶ 0005]; One advantage to the OAO service over conventional methods is a higher capture rate of nefarious actors by utilizing behavioral analysis. Another advantage is more efficient use of computer resources by a client server [¶ 0006]; the use of feature encoding increases the efficiency in the OAO model [¶ 0034]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
As per claim 2: Sampaio in view of Zoldi further in view of Laptiev teach all limitations of claim 1. Furthermore, Sampaio discloses further comprising: detecting historical events occurring over a network, wherein at least one of the historical events is associated with an observed value of a categorical variable (Gateway 1210 receives transaction data from one or more transaction devices 1202-1206, routes the transaction data to network 1220 [¶ 0139, Fig. 12]; the input dataset includes events/data records in a stream of data [¶ 0038]; the R window contains events in a reference period prior to the target window T, prior events are historical events [¶ 0040]; the reference window R also moves to contain the four events immediately preceding window T [¶ 0051]; For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C, the event value is the observed value [¶ 0071]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073]); and detecting an event occurring over the network and associated with the observed value of the categorical variable (receiving an input dataset (200). In various embodiments, the input dataset includes events/data records in a stream of data. The input data may be received and processed in real time or near real time [¶ 0038]; The process identifies one of the set of percentile bins corresponding to the new data item (504). The incoming data record can be classified into one of the bins [¶ 0072; Fig. 5, element 502 and 504]; For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C [¶ 0071]).
As per claim 3: Sampaio in view of Zoldi further in view of Laptiev teach all limitations of claim 1. Furthermore, Sampaio, Zoldi, and Laptiev teach wherein the numerical aggregate value is an exponentially smoothed total count aggregate representing a count of the observed value in certain events occurring over the network, and wherein the method further comprises updating an exponentially smoothed positive count aggregate representing an additional count of the observed value in events of the certain events that led to the outcome of interest (For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C, the event value is the observed value [Sampaio ¶ 0071]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [Sampaio ¶ 0073]; The process adjusts one or more counts of data items in one or more of the percentile bins including by applying a suppression factor based on a relative ordering of items [Sampaio ¶ 0074]; The process calculates a threshold based at least in part on the percentile distribution (514), the threshold refers to an updated numerical aggregate value [Sampaio ¶ 0077]; In some embodiments, gateway 1210 groups one or more transactions together and sends the batch of transactions to issuer 1230 via network 1220, the events are occurring over the network [Sampaio ¶ 0139]; adjust variables smoothly over events or physical timescales [Zoldi ¶ 0043]; the fraud prevention server 135 determines the average feature value (e.g. average input words per minute) for each country categorical variable value [Laptiev ¶ 0037; See Equation 2 below ¶ 0041]; adjust variables smoothly over events or physical timescales [Zoldi ¶ 0043]; the fraud prevention server 135 determines the number of times each country categorical variable value (e.g. each country) was recorded in a training dataset, a retaining dataset, or other trusted data source, the total count of the categorical variable value [Laptiev ¶ 0037]).
As per claim 4: Sampaio in view of Zoldi further in view of Laptiev teach all limitations of claim 3. Furthermore, Laptiev teaches the encoded feature is a function of the exponentially smoothed total count aggregate and the exponentially smoothed positive count aggregate (the fraud prevention server 135 applies the updated smoothing value to adjust the country categorical variable value as defined by Equation 2 below, the “count of times categorical variable is recorded” is used in calculating the smoothing in Equation 1, the average_feature_value_for_categorical_variable_value is used in Equation 2 [Laptiev ¶ 0041; See Equation 1 below ¶ 0040; See Equation 2 below ¶ 0041]).
As per claim 7: Sampaio in view of Zoldi further in view of Laptiev disclose all limitations of claim 1. Furthermore, Sampaio teaches wherein the numerical aggregate value is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function (in this claim a first event having a greater weight is interpreted as giving less emphasis to that event; the process calculates a threshold based at least in part on the percentile distribution (514), the threshold refers to an updated numerical aggregate value [¶ 0077]; the threshold is obtained by further processing the outlier definition using delayed exponential weighting on previous estimates to obtain a final threshold, the previous estimates represent prior numerical aggregate values [¶ 0078]; The suppression factor can be thought of as a forgetting factor ( e.g., assigning a lower weight to older events) that makes an estimation of percentiles adaptive [¶ 0074]; prior to adding a new event value to a bin (506), all bins are suppressed (e.g., multiply all values by 0.99). This gives higher weight to counts in bins that have recently received an instance [¶ 0097]).
As per claim 8: Sampaio in view of Zoldi further in view of Laptiev disclose all limitations of claim 1. Furthermore, Sampaio and Laptiev teach wherein the encoded feature is computed as a function of appearance of the observed value in past events, wherein a first weight given to a first event occurring after a second event is greater than a second weight given to the second event in the function (in this claim a first event having a greater weight is interpreted as giving less emphasis to that event; the fraud prevention server 135 determines the average feature value across the entire population of records (e.g., in the last n days) scored by the OAO model [Laptiev ¶ 0037]; The fraud prevention server 135 calculates an updated smoothing value based on the number of observations [Laptiev ¶ 0040, See Equation 1 below ¶ 0040]; The fraud prevention server 135 applies the updated smoothing value to adjust the country categorical variable value as defined by Equation 2 below [Laptiev ¶ 0041, See Equation 2 below ¶ 0041]; The suppression factor can be thought of as a forgetting factor ( e.g., assigning a lower weight to older events) that makes an estimation of percentiles adaptive [Sampaio ¶ 0074, Fig. 8]).
As per claim 9: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 1 above. Furthermore, Sampaio discloses a system comprising: a processor; and a non-transitory computer-readable medium comprising instructions that are executable by the processor for causing the processor to perform operations comprising (a computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for [Page 13, claim 20]; a computer program product embodied on a computer readable storage medium; and/or a processor, such as a processor configured to execute instructions stored on and/or provided by a memory coupled to the processor [Sampaio ¶ 0024]): The limitations of claim 9 are substantially similar to claim 1 above, and therefore the claim is likewise rejected.
As per claim 10: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 9. The limitations of claim 10 are substantially similar to claim 2 above, and therefore the claim is likewise rejected.
As per claim 11: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 9. The limitations of claim 11 are substantially similar to claim 3 above, therefore the claim is likewise rejected.
As per claim 12: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 11. The limitations of claim 12 are substantially similar to claim 4 above, therefore the claim is likewise rejected.
As per claim 15: Sampaio in view of Zoldi further in view of Laptiev teach all the limitations of claim 1 above. Sampaio further discloses a non-transitory computer-readable storage medium having program code that is executable by a processor device to cause the processing device to perform operations comprising (a computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for [Page 13, claim 20]; a computer program product embodied on a computer readable storage medium; and/or a processor, such as a processor configured to execute instructions stored on and/or provided by a memory coupled to the processor [Sampaio ¶ 0024]): The limitations of claim 15 are substantially similar to claim 1 above, and therefore the claim is likewise rejected.
As per claim 16: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 15. The limitations of claim 16 are substantially similar to claim 2 above, and therefore the claim is likewise rejected.
As per claim 17: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 15. The limitations of claim 17 are substantially similar to claim 3 above, and therefore the claim is likewise rejected.
As per claim 18: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 17. The limitations of claim 18 are substantially similar to claim 4 above, and therefore the claim is likewise rejected.
Claims 5, 13, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Sampaio in view of Zoldi further in view of Laptiev, and further in view of Kim et al. (U.S. PGPub 2019/0065738; hereinafter "Kim").
As per claim 5: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 3. Furthermore, Sampaio, Zoldi, and Laptiev disclose further comprising computing the encoded feature, wherein computing the encoded feature comprises (is configured to perform feature encoding on one or more categorical variables in a first matrix to generate one or more feature encoded categorical variables [Laptiev ¶ 0007; Fig. 5, element 506]): updating the exponentially smoothed total count aggregate based on a time of the event (the process adjusts one or more counts of data items in one or more of the percentile bins including by applying a suppression factor based on a relative ordering of items [Sampaio ¶ 0074]; The process calculates a threshold based at least in part on the percentile distribution (514) [Sampaio ¶ 0077]; the fraud prevention server 135 determines the number of times each country categorical variable value (e.g. each country) was recorded in a training dataset, a retaining dataset, or other trusted data source, the total count of the categorical variable value [Laptiev ¶ 0037]; exponential moving average smoothing is applied on the calculated threshold to obtain a new threshold as described above [Sampaio ¶ 0102]; The suppression factor can be time-based, if it is proportional to the time lag since the previous event, or index-based, if it is constant [Sampaio ¶ 0103]; adjust variables smoothly over events or physical timescales [Zoldi ¶ 0043]); updating the exponentially smoothed positive count aggregate [based on the time of the event] (the fraud prevention server 135 determines the average feature value (e.g. average input words per minute) for each country categorical variable value [Laptiev ¶ 0037; See Equation 2 below ¶ 0041]; Compute the average feature value for each categorical variable value averages [Laptiev, Page 5, See code]; adjust variables smoothly over events or physical timescales [Zoldi ¶ 0043]); and computing the encoded feature as a function of the updated exponentially smoothed total count aggregate and the updated exponentially smoothed positive count aggregate (these new encoded features may also be updated periodically or in real-time (with each transaction), [Laptiev ¶ 0043, See Equation 1 below ¶ 0040, See Equation 2 below ¶ 0041]).
Sampaio in view of Zoldi further in view of Laptiev discloses the claimed subject matter as discussed above but does not explicitly disclose based on the time of the event. However, Kim teaches based on the time of the event (event data aggregation 204 can be performed every X time interval, where X can be a specified value. The event data aggregation 204 can be performed by the preprocessing engine 108 (FIG. 1). From the streamed event data 202, the event data aggregation 204 produces aggregated event data 206. Aggregation of event data can refer to combining event data records, such as by summing or averaging or calculating some other aggregate of respective attributes in the event data records [Kim ¶ 0051, Fig. 2, Fig. 4]). Sampaio in view of Zoldi further in view of Laptiev and Kim are analogous art because they are from the same field of endeavor of event risk detection. Therefore, based on Sampaio in view of Zoldi further in view of Laptiev in view of Kim, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kim to the system of Sampaio in view of Zoldi further in view of Laptiev in order to provide a scalable framework that allows for timely online analysis of event data for detecting anomalous entities, and for enhance flexibility and accuracy in detecting anomalous entities (in accordance with some implementations of the present disclosure, techniques or systems provide a scalable framework that allows for timely online analysis of event data for detecting anomalous entities. Event data can be aggregated in respective time intervals to reduce the amount of event data that has to be processed to extract features for training machine-learning models to assist in detecting anomalous entities. for enhanced flexibility and accuracy in detecting anomalous entities, different types of analytics modules can be used, where each respective analytics module can be associated with an ensemble of machine-learning models [¶ 0016]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
As per claim 13: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 11. The limitations of claim 13 are substantially similar to claim 5 above, and therefore the claim is likewise rejected.
As per claim 19: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 17. The limitations of claim 19 are substantially similar to claim 5 above, and therefore the claim is likewise rejected.
Claims 6, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Sampaio in view of Zoldi further in view of Laptiev, and further in view of Jain et al. (U.S. PGPub 2017/0250953; hereinafter "Jain").
As per claim 6: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 1. Furthermore, Sampaio discloses further comprising: detecting additional historical events occurring over the network (Gateway 1210 receives transaction data from one or more transaction devices 1202-1206, routes the transaction data to network 1220 [¶ 0139, Fig. 12]; the input dataset includes events/data records in a stream of data [¶ 0038]; the R window contains events in a reference period prior to the target window T, prior events are historical events [¶ 0040]), wherein at least one of the additional historical events is associated with a second observed value of the categorical variable (For each incoming event the percentile position estimates in global list P are updated taking into account the incoming event value and the current total count C [¶ 0071, the event value is the observed value]; the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073]; Histogram 702 contains 10 bins where each bin is a percentile bin meaning that its wall (or boundary) represents an estimated percentile position of the events in the bin. The height of the bin represents how many events fall into that bin [¶ 0086]); [determining that the second observed value is not yet represented in a data store]; [adding, to the data store, a categorical key corresponding to the second observed value]; and assigning [a second numerical aggregate value] to represent the second observed value of the categorical variable based on a count of the historical events associated with the second observed value (the process increments a count of items in the identified percentile bin (506). This accounts for classifying the incoming data record as belonging to the identified percentile bin [¶ 0073]; Histogram 702 contains 10 bins where each bin is a percentile bin meaning that its wall (or boundary) represents an estimated percentile position of the events in the bin. The height of the bin represents how many events fall into that bin [¶ 0086]).
Sampaio in view of Zoldi further in view of Laptiev discloses the claimed subject matter as discussed above but does not explicitly disclose determining that the second observed value is not yet represented in a data store; adding, to the data store, a categorical key corresponding to the second observed value; a second numerical aggregate value. However, Jain teaches determining that the second observed value is not yet represented in a data store (for an incoming key-statistic pair, if the key is not in the global table/view, then the key and its statistics are inserted [¶ 0052]); adding, to the data store, a categorical key corresponding to the second observed value (A corresponding local key-value table is updated to add new keys and to update statistics (e.g., counts) for existing keys [¶ 0042]; the payload 106B is mapped to key2 in the hash table 192A/194A. Similarly, the header 106A is mapped to a key representing an IP address (e.g. source address IP2). With key2 331 as an index, a row for key2 is updated 332 [¶ 0058]); a second numerical aggregate value (Fig. 9; Fig. 10; Fig. 11, element 202; Traits of an identified packet feature can be determined in many ways, for instance by payload contents, protocols or ports, known addresses, historical statistics of the packet feature, or leveraging external information such as blacklists of IP addresses known to have sent malicious traffic [¶ 0066]). Sampaio in view of Zoldi further in view of Laptiev and Jain are analogous art because they are from the same field of endeavor of anomaly detection. Therefore, based on Sampaio in view of Zoldi further in view of Laptiev in view of Jain, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Jain to the system of Sampaio in view of Zoldi further in view of Laptiev in order to efficiently and automatically detect and mitigate network anomalies on busy networks, without relying on prior definitions or indications of the attack (embodiments discussed below address one or more needs such as efficiently and automatically detecting and mitigating network attacks or anomalies, in near real time, on potentially extensive and busy networks, in a distributed scalable manner, without relying on a priori definitions or indicia of particular attacks [¶ 0006]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
As per claim 14: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 9. The limitations of claim 14 are substantially similar to claim 6 above, therefore the claim is likewise rejected.
As per claim 20: Sampaio in view of Zoldi further in view of Laptiev disclose all the limitations of claim 15. The limitations of claim 20 are substantially similar to claim 6 above, therefore the claim is likewise rejected.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES P MOLES whose telephone number is (703)756-1043. The examiner can normally be reached M-F 8:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES P MOLES/Examiner, Art Unit 2494
/JUNG W KIM/Supervisory Patent Examiner, Art Unit 2494