DETAILED ACTION
1. This is in reply to an application filed on 05/14/2025. Claims 1-20 are pending examination.
2. The present application, filed on or after March 16, 2013, is being examined under
the first inventor to file provisions of the AIA .
3.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 15-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
The claim recites “to execute on a node of the computing network”. However, there is insufficient antecedent basis for this limitation in the claims. The examiner suggests the Replacement of “to execute on a node of the computing network” with “to execute on a node of a computing network”.
4.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3, 5-10, 12-16 and 18-20 are rejected under 35 U.S.C. 102(a)(1) as being unpatentable over Vasseur et al. US 2017/0279836 (hereinafter Vasseur).
Regarding claim 1 Vasseur teaches a method of detecting an intrusion attack to a computing network, comprising:
initiating, by a node of the computing network, a distributed intrusion detection agent, the distributed intrusion detection agent configured to communicate with a plurality of other distributed intrusion detection agents executing across a plurality of other nodes of the computing network, each of the node and the plurality of other nodes assigned to distinct network segments of the computing network (Vasseur teaches a self learning network (SLN) infrastructure that may be used to detect network anomalies, wherein network devices may be configured to operate as part of the SLN infrastructure to detect, analyze, and/or mitigate network anomalies such as network attacks, wherein the infrastructure may include certain network devices acting as distributed learning agents (DLAs) and one or more supervisory/centralized devices acting as a supervisory and control agent (SCA). A DLA may be operable to monitor network conditions (e.g., router states, traffic flows, etc.), perform anomaly detection on the monitored data using one or more machine learning models, report detected anomalies to the SCA, and/or perform local mitigation actions. Similarly, an SCA may be operable to coordinate the deployment and configuration of the DLAs, wherein by receiving information from the DLAs (e.g., detected anomalies/attacks, compressed data for visualization, etc.), provide information regarding a detected anomaly to a user interface and/or analyze data regarding a detected anomaly using more CPU intensive machine learning processes [0053], fig. 3-4);
monitoring, by the distributed intrusion detection agent, network activity of a network segment assigned to the distributed intrusion detection agent (Vasseur teaches DLA may use any techniques of machine learning such as learning engine to monitor traffic flows associated with the devices of local network [0053], [0059], [0065], fig. 3 and 7C);
generating, by the distributed intrusion detection agent, an initial action vector using one or more reinforcement learning techniques, the initial action vector comprising a first indication of whether an attack was detected (Vasseur teaches DLA may include reinforcement learning (RL) engine that uses reinforcement learning to detect anomalies or assess the operating conditions of the network, wherein the reinforcement learning engine may maintain and use any number of communication models, and wherein the RL engine may enable a feedback loop between the system and the end user [0065-0066] and fig. 4), and a second indication defining a subset of the plurality of other nodes the node requires further information from (Vasseur teaches receive information from the DLAs (e.g., detected anomalies/attacks, compressed data for visualization, etc.), provide information regarding a detected anomaly to a user interface (e.g., by providing a webpage to a display, etc.), and/or analyze data regarding a detected anomaly using more CPU intensive machine learning processes [0053]);
broadcasting, by the distributed intrusion detection agent, the initial action vector across the computing network; receiving, by the distributed intrusion detection agent, the further information from the subset of the plurality of other nodes (Vasseur teaches receive information from the DLAs (e.g., detected anomalies/attacks, compressed data for visualization, etc.), provide information regarding a detected anomaly to a user interface (e.g., by providing a webpage to a display, etc.), and/or analyze data regarding a detected anomaly using more CPU intensive machine learning processes [0053], and wherein RL engine may enable feedback loop between the system and the end user to automatically adapt the system decision to the expectations of the user and raise anomalies that are of interest to the user [0065-0066] and [0095-0098]); and
updating, by the distributed intrusion detection agent, the initial action vector based on the further information to generate an updated action vector comprising an updated first indication of whether an attack was detected (Vasseur teaches wherein the feedback may be used to adjust relevance score for any anomalies that involve the identified device, networks in the feedback [0095-0098], and fig. 7C).
Regarding claim 2 Vasseur teaches the method of claim 1, wherein generating, by the distributed intrusion detection agent, the initial action vector comprises:
generating, via a recurrent neural network, a hidden state based on the network activity of the network segment assigned to the distributed intrusion detection agent, the hidden state representing a current understanding of the network activity based on previous observed states (Vasseur teaches a learning machine may construct a model of normal network behavior, to detect data points that deviate from this model, wherein the model may be used to generate and report anomaly scores to another device [0049], [0065] and fig. 8). Note the hidden state in a neural network is an internal vector that stores past inputs.
Regarding claim 3 Vasseur teaches the method of claim 2, further comprising: receiving a plurality of other hidden states from the plurality of other distributed intrusion detection agents in the computing network (Vasseur teaches a computer network may comprise a plurality of nodes, wherein a node may user a machine learning-based anomaly detection to report detected network anomaly to a supervisor device [0015-0016], fig. 1B and 3, wherein a learning machine may construct a model of normal network behavior, to detect data points that deviate from this model, wherein the model may be used to generate and report anomaly scores to another device [0049], [0065] and fig. 8).
Regarding claim 5 Vasseur teaches the method of claim 1, wherein generating, by the distributed intrusion detection agent, the initial action vector comprises: determining a probability of whether an attack was detected based on the network activity [0040].
Regarding claim 6 Vasseur teaches the method of claim 1, further comprising: receiving, by the distributed intrusion detection agent, a plurality of other updated action vectors from the plurality of other distributed intrusion detection agents [0062].
Regarding claim 7 Vasseur teaches the method of claim 6, further comprising: updating and refining, by the distributed intrusion detection agent, the one or more reinforcement learning techniques based on the plurality of other updated action vectors (Vasseur teaches DLA may include reinforcement learning (RL) engine that uses reinforcement learning to detect anomalies or assess the operating conditions of the network, wherein the reinforcement learning engine may maintain and use any number of communication models, and wherein the RL engine may enable a feedback loop between the system and the end user [0065-0066] and fig. 4).
In response to Claim 8: Rejected for the same reason as claim 1
In response to Claim 9: Rejected for the same reason as claim 2
In response to Claim 10: Rejected for the same reason as claim 3
In response to Claim 12: Rejected for the same reason as claim 5
In response to Claim 13: Rejected for the same reason as claim 6
In response to Claim 14: Rejected for the same reason as claim 7
In response to Claim 15: Rejected for the same reason as claim 1
In response to Claim 16: Rejected for the same reason as claim 2
In response to Claim 18: Rejected for the same reason as claim 5
In response to Claim 19: Rejected for the same reason as claim 6
In response to Claim 20: Rejected for the same reason as claim 7
5.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4, 11 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Vasseur as mentioned above, and further in view of Friedrich et al. US 2021/0357588 (hereinafter Friedrich).
Regarding claim 4 Vasseur teaches the method of claim 3, wherein the plurality of hidden states are from a plurality distributed intrusion detection agents (Vasseur teaches a learning machine may construct a model of normal network behavior, to detect data points that deviate from this model, wherein the model may be used to generate and report anomaly scores to another device [0049], [0065] and fig. 8). Vasseur does not teach leveraging an attention mechanism comprising a Softmax layer to focus on a plurality of hidden wherein the attention mechanism generates a weighted combination of the plurality of hidden states. Friedrich substantially teaches an attention layer of an artificial neural network including a BiLSTM structure may calculate a sentence representation as a weighted representation of the BiLSTM hidden states, and a Softmax layer may classify information [0077].
been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Henry such that the invention further includes leveraging an attention mechanism comprising a Softmax layer to focus on a plurality of hidden wherein the attention mechanism generates a weighted combination of the plurality of hidden states. One would have been motivated to do so to identify and mitigate attacks.
In response to Claim 11: Rejected for the same reason as claim 4
In response to Claim 17: Rejected for the same reason as claim 4
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AYOUB ALATA whose telephone number is (313)446-6541. The examiner can normally be reached on Monday - Friday 7:30 - 5:00 Est.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung (Jay) Kim can be reached on (571)272-3804. The fax phone number for the organization where this application or proceeding is assigned is (571)273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AYOUB ALATA/Primary Examiner, Art Unit 2494