DETAILED ACTION
This communication is in response to application filed on 05/28/2025 in which claims 1-20 is/are pending and presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
This application discloses and claims only subject matter disclosed in prior Application No. 18/166,432, filed 02-08-2023, and names the inventor or at least one joint inventor named in the prior application. Accordingly, this application may constitute a continuation or divisional. Should applicant desire to claim the benefit of the filing date of the prior application, attention is directed to 35 U.S.C. 120, 37 CFR 1.78, and MPEP § 211 et seq. The presentation of a benefit claim may result in an additional fee under 37 CFR 1.17(w)(1) or (2) being required, if the earliest filing date for which benefit is claimed under 35 U.S.C. 120, 121, 365(c), or 386(c) and 1.78(d) in the application is more than six years before the actual filing date of the application.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claim(s) 1-20 of the instant application are rejected on the ground of nonstatutory double patenting as being unpatentable over claim(s) 1-20 of parent U.S. Patent No. 18/166,432. Although the claims at issue are not identical, they are not patentably distinct from each other because:
Instant Application
Parent/Co-Application
A system for account restriction using user group definitions based on user actions, the system comprising: one or more processors; and a non-transitory, computer-readable storage medium storing instructions, which when executed by the one or more processors, cause the one or more processors to perform operations comprising: obtaining a first plurality of time-ordered sequences of actions common to a first subset of a plurality of users associated with a malicious label, and a second plurality of time-ordered sequences of actions common to a second subset of the plurality of users associated with a benign label; identifying one or more time-ordered sequences within the first plurality of time- ordered sequences that do not match the second plurality of time-ordered sequences by: determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences, determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences, and based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences; assigning the one or more time-ordered sequences to the malicious label; generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user; determining whether the one or more time-ordered sequences associated with the malicious label are found within the time-ordered dataset; and disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset.
A system for account restriction using user group definitions based on user actions, the system comprising: one or more processors; and a non-transitory, computer-readable storage medium storing instructions, which when executed by the one or more processors, cause the one or more processors to perform operations comprising: receiving a dataset comprising (1) a plurality of actions performed by a plurality of users, and (2) a plurality of timestamps corresponding to the plurality of actions, wherein a first subset of the plurality of users is associated with a malicious label and a second subset of the plurality of users is associated with a benign label; determining, for each action of the plurality of actions, a corresponding action type of a plurality of action types, wherein a first set of action types comprises a first plurality of subsets of actions, and wherein a second set of action types comprises a second plurality of subsets of actions; inputting, into a sequence determination function for the first subset, the first set of action types and a first set of corresponding timestamps, to obtain a first plurality of time-ordered sequences of actions common to the first subset, wherein the sequence determination function determines the first plurality of time-ordered sequences of actions by: determining a number of users within the first subset that are associated with a first time-ordered sequence of the first plurality of time-ordered sequences, and determining, based on the number of users within the first subset that are associated with the first time-ordered sequence, whether to add the first time- ordered sequence to the first plurality of time-ordered sequences; inputting, into the sequence determination function for the second subset, the second set of action types and a second set of corresponding timestamps, to obtain a second plurality of time-ordered sequences of actions common to the second subset; identifying one or more time-ordered sequences within the first subset plurality of time-ordered sequences that do not match the second subset plurality of time-ordered sequences; assigning the one or more time-ordered sequences to the malicious label; determining, using the one or more time-ordered sequences assigned to the malicious label, that a set of actions performed by a user is associated with the malicious label; and disabling a user account associated with the user based on determining that the set of actions is associated with the malicious label.
5. A method comprising: obtaining a first plurality of time-ordered sequences of actions common to a first subset of a plurality of users associated with a malicious label, and a second plurality of time-ordered sequences of actions common to a second subset of the plurality of users associated with a benign label;identifying one or more time-ordered sequences within the first plurality of time-ordered sequences that do not match the second plurality of time-ordered sequences based on a first percentage of users in the first subset associated with a first sequence of the first plurality of time- ordered sequences and a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences;generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user;determining whether the one or more time-ordered sequences are found within the time- ordered dataset; anddisabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset.
8. The method of claim 5, wherein identifying the one or more time- ordered sequences within the first plurality of time-ordered sequences that do not match the second plurality of time-ordered sequences further comprises:
determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences;
determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; and
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences.
5. A method for account restriction using user group definitions based on user actions, comprising:
inputting, into a sequence determination function for a first subset of a plurality of users associated with a malicious label, a first set of action types, that comprises a first plurality of subsets of actions, and a first set of corresponding timestamps, to obtain a first plurality of time- ordered sequences of actions common to the first subset, wherein the sequence determination function determines the first plurality of time-ordered sequences of actions by:
determining a number of users within the first subset that are associated with a first time-ordered sequence of the first plurality of time-ordered sequences, and
determining, based on the number of users within the first subset that are associated with the first time-ordered sequence, whether to add the first time-ordered sequence to the first plurality of time-ordered sequences;
inputting, into the sequence determination function for a second subset of the plurality of users associated with a benign label, a second set of action types, that comprises a second plurality of subsets of actions, and a second set of corresponding timestamps, to obtain a second plurality of time-ordered sequences of actions common to the second subset;
identifying one or more time-ordered sequences within the first subsetplurality of time- ordered sequences that do not match the second subset plurality of time-ordered sequences;
assigning the one or more time-ordered sequences to the malicious label;
receiving (1) a set of actions performed by a user, and (2) a set of timestamps corresponding to the set of actions;
determining, for each action of the set of actions, a corresponding action type of a plurality of action types;
generating a time-ordered dataset comprising a set of action types corresponding to the set of actions, wherein the set of action types is ordered based on the set of timestamps;
determining whether one or more time-ordered sequences of the plurality of time-ordered sequences associated with the malicious label are found within the time-ordered dataset; and
disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset.
8. The method of claim 5, wherein identifying the one or more time- ordered sequences within the first plurality of time-ordered sequences that do not match the second plurality of time-ordered sequences further comprises:
determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences;
determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; and
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences.
13. A non-transitory, computer-readable medium storing instructions that, when executed by one or more processors cause the one or more processors to perform operations comprising:inputting, into a sequence determination function for a first subset of a plurality of users associated with a first group label, a first set of action types, that comprises a first plurality of subsets of actions, and a first set of corresponding timestamps, to obtain a first plurality of time- ordered sequences of actions common to the first subset, wherein the sequence determination function determines the first plurality of time-ordered sequences of actions by:determining a number of users within the first subset that are associated with a first time-ordered sequence of the first plurality of time-ordered sequences, and determining, based on the number of users within the first subset that are associated with the first time-ordered sequence, whether to add the first time-ordered sequence to the first plurality of time-ordered sequences; inputting, into the sequence determination function for a second subset of the plurality of users associated with a second group label, a second set of action types, that comprises a second plurality of subsets of actions, and a second set of corresponding timestamps, to obtain a second plurality of time-ordered sequences of actions common to the second subset; identifying one or more time-ordered sequences within the first subsetplurality of time- ordered sequences that do not match the second subsetpluralityof time-ordered sequences; assigning the one or more time-ordered sequences to the first group label; receiving (1) a set of actions performed by a user, and (2) a set of timestamps corresponding to the set of actions; determining, for each action of the set of actions, a corresponding action type of a plurality of action types; generating a time-ordered dataset comprising a set of action types corresponding to the set of actions, wherein the set of action types is ordered based on the set of timestamps; determining whether one or more time-ordered sequences of the plurality of time-ordered sequences associated with the first group label are found within the time-ordered dataset; based on determining that the plurality of time-ordered sequences associated with the first group label are found within the time-ordered dataset, labelling the user with the first group label; and disabling a user account associated with the user based on the user being associated with the first group label.
13. One or more non-transitory, computer-readable media storing instructions that, when executed by one or more processors cause the one or more processors to perform operations comprising:
identifying one or more time-ordered sequences within a first plurality of time-ordered sequences of actions common to a first subset of a plurality of users associated with a malicious label that do not match a second plurality of time-ordered sequences of actions common to a second subset of the plurality of users associated with a benign label;
generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user;
determining whether the one or more time-ordered sequences are found within the time- ordered dataset; and
disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset.
16. (Currently Amended) The non-transitory, computer-readable medium of claim 13, wherein the instructions for identifying the one or more time-ordered sequences within the first plurality of time-ordered sequences that do not match the second plurality of time- ordered sequences further cause the one or more processors to perform operations comprising:
determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences;
determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; and
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences.
The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above.
The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection are rejected similarly over corresponding claims in the parent application.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 5-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to judicial exception (an abstract idea) without significantly more. The following is Examiner’s analysis of the claimed invention.
Step 1 Is the claim to a process, machine, manufacture, or composition of matter?, Claim 5 (and dependent claims 6-12) recites a method (process), and claim 13 (and dependent claims 14-20) recites a non-transitory computer medium (manufacture).
Step 2A Prong one: Does the claim recite an abstract idea, law of nature, or natural phenomenon? The claim recites the steps of, “obtaining a first plurality of time-ordered sequences…. identifying one or more time-ordered sequences within the first plurality…. generating a time-ordered dataset…. determining whether the one or more time-ordered sequences are found…. disabling a user account associated with the user” Which fall with the “Mental Processes” grouping as concepts performed in the human mind (including observation, evaluation, judgment, and opinion). Each of these steps of obtaining time-ordered sequences, identifying one or more time-ordered sequences, generating a dataset, determining if a sequence is found, and disabling a user account is a mental process that can practically be performed in the human mind; therefore, the claimed limitations fall within the mental processes grouping, and the claims recite an abstract idea.
Step 2A Prong two: Does the claim recite additional elements that integrate the judicial exception into a practical application? The claimed preamble, “a method comprising” generally links the use of the judicial exception to a particular technological environment, therefore the claim as a whole is no more than a drafting effort designed to monopolize the exception. Claim 6-9 and 11-12 and “receiving a dataset…. determining, for each action of the plurality of actions”, “retrieving a first action identifier”, “retrieving the plurality of action types…determining, whether the first action identifier…based on determining, that the first action identifier”, “determining a number of users within the first subset that are associated”, “determining a restriction level associated with the malicious label”, “determining a restriction level associated with the malicious label…determining a ratio of a first set of time-ordered sequences” is so broad as to cover insignificant extra-solution activity.
Step 2B Does the claim recite additional elements that amount to significantly more than the judicial exception? The elements recited in claims 6-8, 9-10, 11, 12 and 14-20 recite further determinations about the time-ordered sequences and the information they contain and determinations what user are associated with certain sequences which amounts to no more than mental processes. Claim 13 using a non-transitory computer readable medium which amounts to no more than mere instructions to apply the exception using a generic computer component. See Two-Way Media Ltd. V. Comcast Cable Communications, LLC, 2017 U.S. App. LEXIS 21706 at 14 (Fed. Cir. Nov. 1, 2017) finding “simply implementing an abstract concept on a computer without meaningful limitations to that concept, does not transform a patent-ineligible claim into a patent-eligible one.” Accenture Global Service v. Guidewire Software, Inc., 728 F.3d 1336 (Fed. Cir. 2013) at 1345; see also the prohibition against patenting an abstract principle by attempting to limit the use of the [principle] to a particular technological environment; Classen an example case identifying a mental process. Specifically, “[c]oncepts relating to data comparisons that can be performed mentally or are analogous to human mental work.” See MPEP 2106.04(a)(2), sections III and III A. Therefore, additionally recited limitations individually or in combination as a whole in Claims 1-20 fail to amount to significantly more than the abstract idea.
The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 5-6, 13-14 is/are rejected under 35 U.S.C. 103 as being unpatentable over in view of Amit (US 10,686,829 B2), hereinafter Amit in view of Vijayvargiya (US 12,197,418 B1), hereinafter Vij in further view of Moore (US 2023/0129466 A1), hereinafter Moore.
Regarding Claim(s) 5 Amit teaches:
A method comprising: (Amit Col. 4 Ln. 8-11 teaches, provide methods and systems for detecting a change in use of a user's credentials that indicates that the user's credentials were compromised.)
obtaining a first plurality of time-ordered sequences of actions common to a first subset of a plurality of users associated with a malicious label, and a second plurality of time-ordered
sequences of actions common to a second subset of the plurality of users associated with a benign label; (Amit Col. 2 Ln. 5-50 teaches, from initial data transmitted on a data network including a set of resources accessed by a set of training users, a plurality of events, each of the events including a given training user accessing a given resource, creating first and second sets of records, each given record in the first set including a sub-group of the extracted events of a single training user, each given record in the second set including a sub-group of the events of a plurality of the training users during respective sub-periods of a training period, assigning safe labels to the records in the first set and suspicious labels to the records in the second set. Amit Col. 9 Ln. 60-64 teaches, Model generation application receives a list of events, such as Alice accessing resource A at time T1, accessing resource B at time T2, etc. (i.e. time-ordered))
generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user; (Amit Col. 9 Ln. 7-12 teaches, if records comprise a paired dataset (as described in Appendix 1 hereinbelow), then processor fits model to the paired dataset. As described supra, model 86 receives a sequence of events 90 (and respective features) as an input, and labels (i.e., the concept to predict) for each sequence of events as either safe or suspicious.)
determining whether the one or more time-ordered sequences are found within the time- ordered dataset; and (Amit Col. 9 Ln. 19-28 teaches, use the model to filter subsequent data (also known as production data) transmitted on network (e.g., data packets or data in logs) to identify (i.e., in the filtered data) sequences of events that the model classifies as suspicious. The filtered data comprises events where production users access resources. If the model classifies a given sequence of events as suspicious, processor can generate an alert (e.g., on user interface device) for the production user associated with the given sequence of events.)
Amit does not appear to explicitly teach but in related art:
identifying one or more time-ordered sequences within the first plurality of time-ordered sequences that do not match the second plurality of time-ordered sequences based on a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences and a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; (Vij Col. 16 Ln. 8-20 teaches, an instrumented anomaly generated by instrumented anomaly generator can encompass a magnitude parameter and a timestamp parameter. The magnitude parameter can be a numerical value that specifies a percentage increase or percentage decrease or an absolute value increase or absolute value decrease relative to a baseline value of instrumented time series. Vij Col. 16 Ln. 25-32 teaches, Based on the timestamps of instrumented anomalies generated by anomaly generator, time series generator can replace or substitute corresponding baseline values with instrumented anomalies to produce instrumented time series with set of instrumented anomalies.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit with Vij, to modify the method for identifying changes in user credentials of Amit with the percentages identification of series of Vij. The motivation to do so, Vij Col. 11 Ln. 12-13, to detect anomalies in instrumented time series.
Amit in view of Vij does not appear to explicitly teach but in related art:
disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset. (Moore ¶ 5 teaches, The remediation may include disabling an account of the user, disabling access by the user device, and requiring the user to change a password.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit in view of Vij with Moore, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the disabling of an account of Moore. The motivation to do so, Moore ¶ 21, deliver full threat protection against malicious content.
Regarding Claim(s) 13 Amit-Vij-Moore teaches:
One or more non-transitory, computer-readable media storing instructions that, when executed by one or more processors cause the one or more processors to perform operations comprising: (Amit Col. 7 Ln. 37-47 teaches, Processor comprises a general-purpose central processing unit (CPU) or special-purpose embedded processors, which are programmed in software or firmware to carry out the functions described herein. This software may be downloaded to the computer in electronic form, over a network, for example. Additionally or alternatively, the software may be stored on tangible, non-transitory computer-readable media, such as optical, magnetic, or electronic memory media. Further additionally or alternatively, at least some of the functions of processor 70 may be carried out by hard-wired or programmable digital logic circuits.)
plurality of users associated with a malicious label….plurality of users associated with a benign label (Amit Col. 2 Ln. 5-50 teaches, from initial data transmitted on a data network including a set of resources accessed by a set of training users, a plurality of events, each of the events including a given training user accessing a given resource, creating first and second sets of records, each given record in the first set including a sub-group of the extracted events of a single training user, each given record in the second set including a sub-group of the events of a plurality of the training users during respective sub-periods of a training period, assigning safe labels to the records in the first set and suspicious labels to the records in the second set. Amit Col. 9 Ln. 60-64 teaches, Model generation application receives a list of events, such as Alice accessing resource A at time T1, accessing resource B at time T2, etc. (i.e. time-ordered))
generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user; (Amit Col. 9 Ln. 7-12 teaches, if records comprise a paired dataset (as described in Appendix 1 hereinbelow), then processor fits model to the paired dataset. As described supra, model 86 receives a sequence of events 90 (and respective features) as an input, and labels (i.e., the concept to predict) for each sequence of events as either safe or suspicious.)
determining whether the one or more time-ordered sequences are found within the time- ordered dataset; and (Amit Col. 9 Ln. 19-28 teaches, use the model to filter subsequent data (also known as production data) transmitted on network (e.g., data packets or data in logs) to identify (i.e., in the filtered data) sequences of events that the model classifies as suspicious. The filtered data comprises events where production users access resources. If the model classifies a given sequence of events as suspicious, processor can generate an alert (e.g., on user interface device) for the production user associated with the given sequence of events.)
Amit does not appear to explicitly teach but in related art:
identifying one or more time-ordered sequences within a first plurality of time-ordered sequences of actions common to a first subset of a […] that do not match a second plurality of time-ordered sequences of actions common to a second subset of the […]; (Vij Col. 16 Ln. 8-20 teaches, an instrumented anomaly generated by instrumented anomaly generator can encompass a magnitude parameter and a timestamp parameter. The magnitude parameter can be a numerical value that specifies a percentage increase or percentage decrease or an absolute value increase or absolute value decrease relative to a baseline value of instrumented time series.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit with Vij, to modify the method for identifying changes in user credentials of Amit with the percentages identification of series of Vij. The motivation to do so, Vij Col. 11 Ln. 12-13, to detect anomalies in instrumented time series.
Amit in view of Vij does not appear to explicitly teach but in related art:
disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset. (Moore ¶ 5 teaches, The remediation may include disabling an account of the user, disabling access by the user device, and requiring the user to change a password.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit in view of Vij with Moore, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the disabling of an account of Moore. The motivation to do so, Moore ¶ 21, deliver full threat protection against malicious content.
Regarding Claim(s) 6 Amit-Vij-Moore teaches:
The method of claim 5, further comprising: (Amit-Vij-Moore teaches the parent claim above.)
receiving a dataset comprising a plurality of actions performed by the plurality of users; (Amit Col. 9 Ln. 7-12 teaches, if records comprise a paired dataset (as described in Appendix 1 hereinbelow), then processor fits model to the paired dataset. As described supra, model 86 receives a sequence of events 90 (and respective features) as an input, and labels (i.e., the concept to predict) for each sequence of events as either safe or suspicious.) and determining, for each action of the plurality of actions, a corresponding action type of a plurality of action types. (Amit Col. 4 Ln. 10-15 teaches, accesses to a set of resources (e.g., servers and workstations) on a data network by a set of training users are recorded as events during a training period. Amit Col. 5 Ln. 35-45 teaches, each server maintains a server log of actions performed by and on the server, such as logins, commands received and executed (e.g., for a given user logged into a given workstation), (i.e., action types) and access to various hardware/software modules and data (e.g., files) on or via the server. Workstations may maintain similar logs (which are omitted from the figure for the sake of simplicity).)
Regarding Claim(s) 14 Amit-Vij-Moore teaches:
The one or more non-transitory, computer-readable media of claim 13, wherein the instructions further cause the one or more processors to perform operations comprising: (Amit-Vij-Moore teaches the parent claim above.)
receiving a dataset comprising a plurality of actions performed by the plurality of users, wherein each action of the plurality of actions is associated with a timestamp; (Amit Col. 9 Ln. 7-12 teaches, if records comprise a paired dataset (as described in Appendix 1 hereinbelow), then processor fits model to the paired dataset. As described supra, model 86 receives a sequence of events 90 (and respective features) as an input, and labels (i.e., the concept to predict) for each sequence of events as either safe or suspicious.)
determining, for each action of the plurality of actions, a corresponding action type of a plurality of action types; (Amit Col. 4 Ln. 10-15 teaches, accesses to a set of resources (e.g., servers and workstations) on a data network by a set of training users are recorded as events during a training period. Amit Col. 5 Ln. 35-45 teaches, each server maintains a server log of actions performed by and on the server, such as logins, commands received and executed (e.g., for a given user logged into a given workstation), (i.e., action types) and access to various hardware/software modules and data (e.g., files) on or via the server. Workstations may maintain similar logs (which are omitted from the figure for the sake of simplicity).)
inputting, into a sequence determination function for the first subset, a first set of action types and a first set of corresponding timestamps, to obtain a first plurality of time-ordered sequences of actions common to the first subset, wherein the sequence determination function
detects time-ordered sequences of actions within datasets of action types and corresponding timestamps; and (Amit Col. 8 Ln. 39-46 teaches, in a first creation step, processor creates, from the respective pluralities of events, first set of records, each of the records in the first set comprising a given training user, a given sub-group of events comprising the respective plurality of the events for the given training user, and features for each of the events in the given sub-group. In a first classification step, processor labels all the records in first set as safe.)
inputting, into the sequence determination function for the second subset, a second set of action types and a second set of corresponding timestamps, to obtain a second plurality of time- ordered sequences of actions common to the second subset. (Amit Col. 8 Ln. 47-56 teaches, In a second creation step, processor creates, from the respective pluralities of events, second set of the records, each of the records in the second set comprising multiple training users, and for each of the multiple training users, respective sub-groups during respective sub-periods. In a second classification step, processor labels all the records in second set as suspicious.)
Claim(s) 7-8 and 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Amit-Vij-Moore as applied to claim 5 above, and further in view of Ross (US 12,130,908 B2), hereinafter Ross.
Regarding Claim(s) 7 and 19 Amit-Vij-Moore teaches:
The method of claim 6, wherein determining, for each action of the plurality of actions, the corresponding action type of the plurality of action types further comprises: (Amit-Vij-Moore teaches the parent claim above.)
Amit-Vij-Moore does not appear to explicitly teach but in related art:
retrieving a first action identifier and one or more action parameters for a first action in the set of actions; (Ross Col. 43 Ln. 4-29 teaches, temporal events which include uploading, transferring, downloading data. The temporal events including metadata which includes entity identifier types or classifications.)
retrieving the plurality of action types, wherein each action type of the plurality of action types comprises a corresponding set of action type parameters; (Ross Col. 43 Ln. 4-29 teaches, temporal events which include uploading, transferring, downloading data. The temporal events including metadata which includes entity identifier types or classifications.)
determining, whether the first action identifier and the one or more action parameters match a first action type of the plurality of action types and the corresponding set of action type parameters; and (Ross Col. 44 Ln. a security related abstraction operation where rather than providing details associated with “Windows:4624” event, its details are abstracted to “User Login to Device” security related activity.)
based on determining, that the first action identifier and the one or more action parameters match the first action type of the plurality of action types and the corresponding set of action type parameters, adding the first action type to the time-ordered dataset. (Ross Col. 44 Ln. 20-40 teaches, the session information associated with events i, i+1, i+n or their corresponding observables or their corresponding security related activities.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit-Vij-Moore with Ross, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the disabling of an account of Moore with the security event data of Ross. The motivation to do so, Ross Col. 13 Ln. 64, to generate enriched entity behavior information.
Regarding Claim(s) 8 and 20 Amit-Vij-Moore-Ross teaches:
The method of claim 7, further comprising: (Amit-Vij-Moore-Ross teaches the parent claim above.)
retrieving a timestamp associated with the first action in the set of actions; and (Ross Col. 42 Ln. 59-67 teaches, the entity identifier information may include temporal information e.g., a timestamp. The temporal information may be associated with an event associated with a particular point in time.)
determining, based on the timestamp and a set of timestamps associated with the set of actions within the time-ordered dataset, a position within the time-ordered dataset for the first action, wherein adding the first action type to the time-ordered dataset comprises adding the first action type according to the position. (Vij Col.19-20 Ln. 65-67 and 1-5 teaches, Time series generator can continually add new time series data points to instrumented time series on the time series generation interval. These time series data points that time series generator adds to instrumented time series can contain instrumented anomalies among baseline data points and is referred to as “continuous” time series data points.)
Claim(s) 1-4, 9-12, and 15-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Amit-Vij-Moore as applied to claim 5 above, and further in view of Abbasi (US 2017/0083703 A1), hereinafter Abbasi.
Regarding Claim(s) 1 Amit teaches:
A system for account restriction using user group definitions based on user actions, the system comprising: (Amit Col. 4 Ln. 8-11 teaches, provide methods and systems for detecting a change in use of a user's credentials that indicates that the user's credentials were compromised.)
one or more processors; and
a non-transitory, computer-readable storage medium storing instructions, which when executed by the one or more processors, cause the one or more processors to perform operations comprising: (Amit Col. 7 Ln. 37-47 teaches, Processor comprises a general-purpose central processing unit (CPU) or special-purpose embedded processors, which are programmed in software or firmware to carry out the functions described herein. This software may be downloaded to the computer in electronic form, over a network, for example. Additionally or alternatively, the software may be stored on tangible, non-transitory computer-readable media, such as optical, magnetic, or electronic memory media. Further additionally or alternatively, at least some of the functions of processor 70 may be carried out by hard-wired or programmable digital logic circuits.)
obtaining a first plurality of time-ordered sequences of actions common to a first subset of a plurality of users associated with a malicious label, and a second plurality of time-ordered sequences of actions common to a second subset of the plurality of users associated with a benign label; (Amit Col. 2 Ln. 5-50 teaches, from initial data transmitted on a data network including a set of resources accessed by a set of training users, a plurality of events, each of the events including a given training user accessing a given resource, creating first and second sets of records, each given record in the first set including a sub-group of the extracted events of a single training user, each given record in the second set including a sub-group of the events of a plurality of the training users during respective sub-periods of a training period, assigning safe labels to the records in the first set and suspicious labels to the records in the second set. Amit Col. 9 Ln. 60-64 teaches, Model generation application receives a list of events, such as Alice accessing resource A at time T1, accessing resource B at time T2, etc. (i.e. time-ordered))
generating a time-ordered dataset comprising a set of action types corresponding to a set of actions performed by a user; (Amit Col. 9 Ln. 7-12 teaches, if records comprise a paired dataset (as described in Appendix 1 hereinbelow), then processor fits model to the paired dataset. As described supra, model 86 receives a sequence of events 90 (and respective features) as an input, and labels (i.e., the concept to predict) for each sequence of events as either safe or suspicious.)
determining whether the one or more time-ordered sequences associated with the malicious label are found within the time-ordered dataset; and (Amit Col. 9 Ln. 19-28 teaches, use the model to filter subsequent data (also known as production data) transmitted on network (e.g., data packets or data in logs) to identify (i.e., in the filtered data) sequences of events that the model classifies as suspicious. The filtered data comprises events where production users access resources. If the model classifies a given sequence of events as suspicious, processor can generate an alert (e.g., on user interface device) for the production user associated with the given sequence of events.)
Amit does not appear to explicitly teach but in related art:
identifying one or more time-ordered sequences within the first plurality of time- ordered sequences that do not match the second plurality of time-ordered sequences by: (Vij Col. 16 Ln. 8-20 teaches, an instrumented anomaly generated by instrumented anomaly generator can encompass a magnitude parameter and a timestamp parameter. The magnitude parameter can be a numerical value that specifies a percentage increase or percentage decrease or an absolute value increase or absolute value decrease relative to a baseline value of instrumented time series.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit with Vij, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij. The motivation to do so, Vij Col. 11 Ln. 12-13, to detect anomalies in instrumented time series.
Amit in view of Vij does not appear to explicitly teach but in related art:
disabling a user account associated with the user based on determining that the one or more time-ordered sequences are found within the time-ordered dataset. (Moore ¶ 5 teaches, The remediation may include disabling an account of the user, disabling access by the user device, and requiring the user to change a password.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit in view of Vij with Moore, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the disabling of an account of Moore. The motivation to do so, Moore ¶ 21, deliver full threat protection against malicious content.
Amit-Vij-Moore does not appear to explicitly teach but in related art:
determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences, (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), )
determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences, and(Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), )
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences; (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), )
assigning the one or more time-ordered sequences to the malicious label; (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit-Vij-Moore with Abbasi, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the degrees of relatedness for sequences of Abbasi. The motivation to do so, Abbasi ¶ 29, to detect and classify malware.
Regarding Claim(s) 2 Amit-Vij-Moore- Abbasi teaches:
The system of claim 1, wherein the instructions for determining whether the one or more time-ordered sequences associated with the malicious label are found within the time-ordered dataset further cause the one or more processors to perform operations comprising: (Amit-Vij-Moore- Abbasi teaches the parent claim above.)
receiving (1) the set of actions performed by the user, and (2) a set of timestamps corresponding to the set of actions; (Amit Col. 8 Ln. 7-14 teaches, feature comprises a property for one or more given event (i.e., a feature may comprise a number of events). Examples of features include, but are not limited to, an identity of a given server that is accessed, a date of the access, a time of the access, a security level of the given server, and a file and/or directory accessed on the given server.)
determining, for each action of the set of actions, a corresponding action type of a plurality of action types; (Amit Col. 4 Ln. 10-15 teaches, accesses to a set of resources (e.g., servers and workstations) on a data network by a set of training users are recorded as events during a training period. Amit Col. 5 Ln. 35-45 teaches, each server maintains a server log of actions performed by and on the server, such as logins, commands received and executed (e.g., for a given user logged into a given workstation), (i.e., action types) and access to various hardware/software modules and data (e.g., files) on or via the server. Workstations may maintain similar logs (which are omitted from the figure for the sake of simplicity).)
generating the time-ordered dataset comprising the set of action types corresponding to the set of actions, wherein the set of action types is ordered based on the set of timestamps; (Amit Col. 11 Ln. 13-15 teaches, The input to the pairs dataset algorithm comprises: A dataset of sequences of events per training user. Amit Col. 11 Ln. 45-55 teaches, given the following dataset S: (62) TABLE-US-00001 User 26 Time Resource 30 Alice 8:00 Marketing1 Bob 8:10 Accounting3 Alice 8:30 Marketing4 Alice 9:00 Marketing2 Carol 9:15 Marketing1 Bob 9:15 Accounting1 Carol 10:00 Marketing2 Alice 10:10 Marketing2 Bob 10:30 Accounting2)
determining, whether the one or more time-ordered sequences associated with the malicious label match time-ordered sequences within the time-ordered dataset; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
based on determining that the one or more time-ordered sequences associated with the malicious label match the time-ordered sequences within the time-ordered dataset, assigning the malicious label to the user. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
The motive given in Claim 1 is equally applicable to the above claim.
Regarding Claim(s) 3 and 17 Amit-Vij-Moore- Abbasi teaches the parent claim above:
The system of claim 1, wherein the instructions further cause the one or more processors to perform operations comprising: (Amit-Vij-Moore- Abbasi teaches the parent claim above.)
determining a restriction level associated with the malicious label; and (Vij Col. 19 Ln. 48-52 teaches, when service finds an anomaly in instrumented time series, it can output a severity score. The severity score can indicate how unexpected the detected anomaly is based on detector understanding of instrumented time series.)
applying the restriction level associated to the user account. (Moore ¶ 63 teaches, such remediation may include disabling an account of the user, disabling access by the user, (i.e., maximum restriction) requiring the user to change a password, and other security measures of the like.)
The motive given in Claim 1 is equally applicable to the above claim.
Regarding Claim(s) 4 Amit-Vij-Moore- Abbasi teaches:
The system of claim 1, wherein the instructions for determining whether the one or more time-ordered sequences associated with the malicious label are found within the time-ordered dataset further cause the one or more processors to perform operations comprising: (Amit-Vij-Moore- Abbasi teaches the parent claim above.)
determining a percentage of time-ordered sequences associated with the malicious label that match the time-ordered sequences within the time-ordered dataset; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
determining whether the one or more time-ordered sequences associated with the malicious label match the time-ordered sequences within the time-ordered dataset based on the percentage meeting a threshold. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
The motive given in Claim 1 is equally applicable to the above claim.
Regarding Claim(s) 9 Amit-Vij-Moore- Abbasi teaches:
The method of claim 5, further comprising: (Amit-Vij-Moore teaches the parent claim above.)
Amit-Vij-Moore does not appear to explicitly teach but in related art:
determining a number of users within the first subset that are associated with a first time- ordered sequence of the first plurality of time-ordered sequences; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (e.g., certain percentage of rules that are part of the rule aggregation sequence (i.e., to determine a percentage there must be known numerical values of that sequence) having the same ordering as the rules that are part of a reference rule sequence,)
determining, based on the number of users within the first subset that are associated with the first time-ordered sequence, whether to add the first time-ordered sequence to the first plurality of time-ordered sequences. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
It would have been obvious to one with ordinary skill the art, prior to the applicant's earliest effective filing date, to combine the teachings of Amit-Vij-Moore with Abbasi, to modify the method for identifying changes in user credentials of Amit with the percentage’s identification of series of Vij with the degrees of relatedness for sequences of Abbasi. The motivation to do so, Abbasi ¶ 29, to detect and classify malware.
Regarding Claim(s) 10 Amit-Vij-Moore- Abbasi teaches:
The method of claim 5, wherein identifying the one or more time-ordered sequences comprises: (Amit-Vij-Moore teaches the parent claim above.)
determining the first percentage of users in the first subset associated with the first sequence of the first plurality of time-ordered sequences; (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
determining the second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
The motive given in Claim 9 is equally applicable to the above claim.
Regarding Claim(s) 11 Amit-Vij-Moore- Abbasi teaches:
The method of claim 5, further comprising: (Amit-Vij-Moore teaches the parent claim above.)
determining a restriction level associated with the malicious label; and (Vij Col. 19 Ln. 48-52 teaches, when service finds an anomaly in instrumented time series, it can output a severity score. The severity score can indicate how unexpected the detected anomaly is based on detector understanding of instrumented time series.)
applying the restriction level associated to the user account. (Moore ¶ 63 teaches, such remediation may include disabling an account of the user, disabling access by the user, (i.e., maximum restriction) requiring the user to change a password, and other security measures of the like.)
Regarding Claim(s) 12 and 18 Amit-Vij-Moore teaches:
The method of claim 5, wherein determining whether the one or more time-ordered sequences are found within the time-ordered dataset further comprises: (Amit-Vij-Moore teaches the parent claim above.)
determining a number of time-ordered sequences associated with the malicious label that match the time-ordered dataset; (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
determining a ratio of a first set of time-ordered sequences that match to a second set of time-ordered sequences that do not match; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
determining a match based on the ratio meeting a threshold. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (i.e., a ratio) ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
The motive given in Claim 9 is equally applicable to the above claim.
Regarding Claim(s) 15 Amit-Vij-Moore- Abbasi teaches:
The one or more non-transitory, computer-readable media of claim 14, wherein the sequence determination function determines the first plurality of time-ordered sequences of actions by: (Amit-Vij-Moore teaches the parent claim above.)
determining a number of users within the first subset that are associated with a first time- ordered sequence of the first plurality of time-ordered sequences; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (e.g., certain percentage of rules that are part of the rule aggregation sequence (i.e., to determine a percentage there must be known numerical values of that sequence) having the same ordering as the rules that are part of a reference rule sequence,)
determining, based on the number of users within the first subset that are associated with the first time-ordered sequence, whether to add the first time-ordered sequence to the first plurality of time-ordered sequences. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), the malware sample may be assigned a particular malware class (family) that is identified in accordance with a labeling scheme that is dependent on whether or not the sample is already labeled.)
The motive given in Claim 1 is equally applicable to the above claim.
Regarding Claim(s) 16 Amit-Vij-Moore- Abbasi teaches:
The one or more non-transitory, computer-readable media of claim 14, wherein the instructions for identifying the one or more time-ordered sequences further cause the one or more processors to perform operations comprising: (Amit-Vij-Moore teaches the parent claim above.)
determining a first percentage of users in the first subset associated with a first sequence of the first plurality of time-ordered sequences; (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), ) determining a second percentage of users in the second subset associated with the first sequence of the first plurality of time-ordered sequences; and (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold ( e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.), )
based on a ratio of the first percentage and the second percentage meeting a threshold, adding the first sequence to the one or more time-ordered sequences. (Abbasi ¶ 40-41 teaches, When the degree of relatedness exceeds a threshold (e.g., certain percentage of rules that are part of the rule aggregation sequence having the same ordering as the rules that are part of a reference rule sequence, meeting or exceeding a prescribed number of these chronologically ordered rules of the rule aggregation sequence having the same ordering as the rules associated with the reference rule sequence, etc.),)
The motive given in Claim 1 is equally applicable to the above claim.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 2014/0129273 A1 – System and Method for Visual Role Engineering
US 2020/0145824 A1 – Localized Multi-Factor Network Authentication
US 2022/0229906 A1 – High-Confidence Malware Severity Classification of Reference File
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JACOB BENEDICT KNACKSTEDT whose telephone number is (703)756-5608. The examiner can normally be reached Monday-Friday 8:00 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/J.B.K./Examiner, Art Unit 2408
/LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408