DETAILED ACTION
This application has been examined. Claims 1-15 are pending.
In order to facilitate communication with the Examiner and expedite the prosecution of the instant application the Applicant is requested to submit written authorization to authorize the USPTO to communicate via electronic mail. The written authorization must be compliant with the language from MPEP § 502.03.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
This application claims benefits of priority from Foreign Application PT120055 filed February 19, 2025.
The effective date of the claims described in this application is February 19, 2025.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 12/8/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-6,9-12,14-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Khot (USPGPUB 2025/0184341) further in view of Allen (USPGPUB 2026/0156134)
Regarding Claim 1
Khot Paragraph 2 disclosed a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events.
Khot disclosed (re. Claim 1) a computer-implemented method for monitoring a computer system for account and/or session security attacks,( Khot-Paragraph 2,a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events)
wherein the computer system includes a hardware- based computer processor, and a memory configured to store code representing instructions and configured to provide the instructions to the hardware-based computer processor for execution, wherein the computer system provides session logins to a plurality of user devices using a plurality of user accounts, the method comprising:
detecting, using the hardware-based computer processor, a plurality of device characteristic, wherein each device characteristic is encoded as a function of the number of session logins for each device characteristic;(Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual)
and
detecting, using the hardware-based computer processor, a plurality of account characteristics wherein each account characteristic is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts of a plurality of user accounts.(Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.)
While Khot substantially disclosed the claimed invention Khot does not disclose (re. Claim 1) displaying, using the hardware-based computer processor, multidimensional security data from said computer system, said multidimensional security data comprising a plurality of dimensions comprising a time dimension, wherein the time dimension is partitioned in time units;
While Khot substantially disclosed the claimed invention Khot does not disclose (re. Claim 1) displaying heatmaps.
Allen Figure 22A, Paragraph 114 disclosed wherein FIG. 22A shows the unit cell as a hexagon, the user can tilt the gridded data set 2204, and the unit cell will be shown as a cylinder with a hexagon shape with a column height corresponding to the number of network access events. As described above, each unit cell is a colored, 3D visual object that represents a composite score of the anomaly scores associated with zero or more network access events corresponding to the respective network address identifier at the respective time interval.
Allen Paragraph 117 disclosed wherein heatmaps are typically displayed as a grid or a matrix of cells.
Allen disclosed (re. Claim 1) displaying, using the hardware-based computer processor, multidimensional security data from said computer system, said multidimensional security data comprising a plurality of dimensions comprising a time dimension, wherein the time dimension is partitioned in time units; (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.)
Allen disclosed (re. Claim 1) displaying heatmaps. (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights, Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells)
Khot and Allen are analogous art because they present concepts and practices regarding monitoring account security and anomalous events. Before the time of the effective filing date of the claimed invention it would have been obvious to combine Allen into Khot. The motivation for the said combination would have been to enable providing a digital fingerprinting (DFP) workflow for cybersecurity, enabling organizations to deeply analyze every account login across the network.(Allen-Paragraph 31)
Khot-Allen disclosed (re. Claim 1) displaying, using the hardware-based computer processor, a plurality of device heatmaps for each time unit,(Allen-Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells, Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns)
wherein each device heatmap corresponds to a device characteristic of the user devices, (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.) wherein each device heatmap is encoded as a function of the number of session logins for each device characteristic; (Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual) and
displaying, using the hardware-based computer processor, a plurality of account heatmaps for each time unit, (Allen-Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells) wherein each account heatmap corresponds to a characteristic of the user accounts, wherein each account heatmap is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts of a plurality of user accounts. (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.)
Regarding Claim 14
Claim 14 (re. non-transitory computer-readable medium) recites substantially similar limitations as Claim 1. Claim 14 is rejected on the same basis as Claim 1.
Khot-Allen disclosed (re. Claim 14) a user interface for monitoring a computer system for account take-over. (Khot-Paragraph 2,a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events)
Regarding Claim 15
Claim 15 (re. system) recites substantially similar limitations as Claim 1. Claim 15 is rejected on the same basis as Claim 1.
Regarding Claim 2
Khot-Allen disclosed (re. Claim 2) wherein each account heatmap is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.) and also encoded as a function of the one characteristic of the one or more user accounts having been marked as restricted.(Khot-Paragraph 25, In the event the login event is classified as an anomalous event, one or more computer security actions can be taken. For example, the login event can be blocked, the user account can be suspended)
Regarding Claim 3
Khot-Allen disclosed (re. Claim 3) wherein said heatmaps for a same time unit are stacked perpendicularly to the time dimension.(Allen-Paragraph 89, the DFP system 1500 can identify a bucket name, a filename prefix, a start date, an end date, and any filter function on what data is read from the object bucket 1502.Paragraph 116, The hexagon grid represents network events, with anomalous events binned, colored, and sorted by row and time. The grid view can be reformatted in the settings menu. The most recent time stamp starts on the left.)
Regarding Claim 4
Khot-Allen disclosed (re. Claim 4) displaying a time window selector, receiving user interaction from said time window selector, (Allen-Paragraph 120, the number of events can vary depending on “Time Bin Per Hexagon” values set in default settings or a settings menu 2212 ) and updating displayed heatmaps with the selected time window, wherein the time window selector includes an adjustable time dimension granularity, including an automatically adjustable time dimension granularity as a function of the selected time window, wherein the automatically adjustable time dimension granularity is a function of the selected time window duration.
Regarding Claim 5
Khot-Allen disclosed (re. Claim 5) displaying a horizontal bar chart aligned with time dimension, and displaying a session amount per time dimension unit.( Allen-Paragraph 89, the DFP system 1500 can identify a bucket name, a filename prefix, a start date, an end date, and any filter function on what data is read from the object bucket 1502.
Regarding Claim 6
Khot-Allen disclosed (re. Claim 6) displaying said plurality of device heatmaps arranged parallel to the time dimension, (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.) wherein each device heatmap is aligned with a time dimension unit, and displaying number of logins for all the user devices. (Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual)
Regarding Claim 9
Khot-Allen disclosed (re. Claim 9) an aggregated device heatmap, wherein the aggregated device heatmap is encoded as a function of the number of session logins for a plurality of device characteristics, wherein the plurality of device characteristics is an aggregation of each device characteristic for each of the plurality of device heatmaps.(Allen-Paragraph 113, The GUI dashboard 2200 includes an area chart 2202 showing the total network traffic volume. An area chart, also known as an area graph, is a type of data visualization used to display the magnitude or proportion of different data series over time or along a continuous axis. It is commonly used to illustrate the cumulative effect or trend of multiple variables.)
Regarding Claim 10
Khot-Allen disclosed (re. Claim 10) an aggregated account heatmap, wherein the aggregated account heatmap is encoded as a function of an aggregation of characteristics of the user accounts, wherein the aggregated account heatmap is encoded as a function of a change occurring, or not, to one or more characteristics of the user accounts. (Allen-Paragraph 113, The GUI dashboard 2200 includes an area chart 2202 showing the total network traffic volume. An area chart, also known as an area graph, is a type of data visualization used to display the magnitude or proportion of different data series over time or along a continuous axis. It is commonly used to illustrate the cumulative effect or trend of multiple variables.)
Regarding Claim 11
Khot-Allen disclosed (re. Claim 11) displaying an indicator representing an added device, (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device) wherein the indicator is placed perpendicularly to the time dimension and adjacent to the device heatmap for a time unit where the device has been added.
Regarding Claim 12
Khot-Allen disclosed (re. Claim 12) detecting a user input at one time unit of one heatmap and, if detected, highlighting the heatmaps of the corresponding time unit. (Allen-Paragraph 116,Clicking on a hexagon can open the details menu 2206.)
Claim(s) 7-8,13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Khot (USPGPUB 2025/0184341) further in view of Allen (USPGPUB 20260156134) further in view of OToole (USPGPUB 2021/0216928)
Regarding Claim 7
Allen Paragraph 116 disclosed wherein clicking on a hexagon can open the details menu 2206.
While Khot-Allen substantially disclosed the claimed invention Khot-Allen does not disclose (re. Claim 7) detecting a user hover point over any part of a time unit partition and high-lighting the hovered time unit partition.
OToole Paragraph 118 disclosed a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.
OToole disclosed (re. Claim 7) detecting a user hover point over any part of a time unit partition and high-lighting the hovered time unit partition. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.)
Khot,Allen and OToole are analogous art because they present concepts and practices regarding monitoring account security and anomalous events. Before the time of the effective filing date of the claimed invention it would have been obvious to combine OToole into Khot. The motivation for the said combination would have been to enable a threat summary panel 401 giving a user more information about the key events that contributed to the risk score of the asset at that point in time. (OToole-Paragraph 118)
Regarding Claim 8
Khot-Allen-OToole disclosed (re. Claim 8) detecting a user hover point over any part of a time unit partition, and displaying a hovering pop-up comprising data about the hovered time unit partition. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.)
Regarding Claim 13
Khot-Allen-OToole disclosed (re. Claim 13) detecting a user hover point over any of the highlighted time unit heatmaps (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.)
and, if detected, displaying a hovering pop- up comprising data about the hovered time unit; including detecting a user hover point over any of the highlighted time unit heatmaps of a device characteristic heatmap and, if detected, displaying a hovering pop-up comprising a labelled value for the corresponding hovered device characteristic. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.)
Conclusion
Examiner’s Note: In the case of amending the claimed invention, Applicant is respectfully requested to indicate the portion(s) of the specification which dictate(s) the structure relied on for proper interpretation and also to verify and ascertain the metes and bounds of the claimed invention.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GREG C BENGZON whose telephone number is (571)272-3944. The examiner can normally be reached on Monday - Friday 8 AM - 4:30 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John Follansbee can be reached on (571) 272-3964. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GREG C BENGZON/ Primary Examiner, Art Unit 2444