DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 7/30/2026 have been fully considered
35 USC § 102 & 35 USC § 103:
Regarding Applicant’s Argument (pages:7-11): Examiner’s response:- Applicant’s arguments with respect to the rejection(s) of under 35 USC § 102/103 have been fully considered, upon further consideration a new ground(s) of rejection is made in view of US 20230262081 A1; Malamut; Mark et al. (hereinafter Malamut). The examiner recommends further elaborating on "alert cluster engagement component" in the independent claims. The examiner believes amendments directed towards parameters/factors involved in the alert cluster engagement component will help push over the current prior art and push the application towards allowance. If the applicant would like further guidance for overcoming the prior art(s), please call the examiner at 571-272-5212.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-5,8-14, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over US 20240340314 A1; Radon; Aungon Nag et al. (hereinafter Radon) in view of US 20210279603 A1; Teran Matus; Jose Adalberto et al. (hereinafter Teran) and US 20230262081 A1; Malamut; Mark et al. (hereinafter Malamut)
Regarding claim 1, Radon teaches An alert cluster generation apparatus comprising one or more processors and one or more memories storing instructions that are operable, when executed by the one or more processors, to cause the alert cluster generation apparatus to: (Radon [FIG.3 in conjunction with FIG.12] show corresponding system comprising one or more processors and one or more memories storing instructions that are operable, when executed by the one or more processors, to cause the system to performing corresponding steps [0023] models to facilitate determination of whether the identifier associated with the resource is suspicious based on a type of the identifier, based on a type of the resource, based on an identity of the user, based on features extracted from the identifier, or a combination thereof ...) access an alert set associated with one or more service events; apply a feature extraction model that is configured to extract alert features from the alert set; (Radon [FIG.3] shows sets of data associated with events and a model which extract features from said sets of data [0022] a machine learning model to facilitate determination of whether the identifier associated with the resource is suspicious. In certain embodiments, the system can be configured to load identifier features extracted from the identifier associated with the resource attempting to be accessed. In certain embodiments, the system can be configured to determine whether the identifier associated with the resource attempting to be accessed is suspicious based on execution of the machine learning model using the plurality of first features. In certain embodiments, the identifier can be configured to be determined to be suspicious if training features of the machine learning model are determined to have a similarity with the identifier features of the identifier [0086] the feature extractor 406, which can extract features (e.g., identifier features) from the identifier, such as, but not limited to, an address, URL, FQDN, and/or other access mechanism associated with the request. [71-76 &134-135] elaborate on the matter) compare alert features for selected alerts of the alert set to a tag presence threshold; (Radon [0041] the optimal machine learning model can have an optimal model parameter combination (e.g., combination of weights, biases, etc.) that is learned via the training process using the optimal hyperparameter combination. In certain embodiments, the optimal machine learning model having the optimal model parameter combination can have a highest performance for suspiciousness determination according to a specified performance metric associated with an evaluation measure(s) when compared to other trained machine learning models of the plurality of trained machine learning models. [131] trainable machine learning models (or algorithms) can have combinations of hyperparameters specified for them, such as by a user, the system 100, or a combination thereof. For example, hyperparameters can include, but are not limited to, a machine learning model...updates model parameters of the trained machine learning model. In certain embodiments, an optimal combination of hyperparameters can be determined by conducting tuning on the hyperparameters to determine which combination of hyperparameters results in learning the optimal model parameters of the generated trained machine learning model that provide a highest performance according to a performance metric (e.g., evaluation measure) for determining suspiciousness of digital identifiers when compared to other generated trained machine learning models. In certain embodiments, the training can be performed and/or facilitated by utilizing the server 140, the server 145, the server 150, the server 160, the communications network 135, the PCP classifier 202 [72-75 & 154-155] elaborate on the matter [FIG.3] shows corresponding visual) in a circumstance in which the alert features for the selected alerts satisfy the tag presence threshold, apply a tag based clustering algorithm to the selected alerts to group the selected alerts into one or more alert clusters; (Radon [0075] a threshold level...the developed machine learning model can be persisted in a model registry 212 along with useful metadata about the model. In certain embodiments, the metadata can be utilized to describe the features and/or functionality of the model, the types of algorithms that the model utilizes, the types of determinations that the model is capable of making, the types of features that the model can process, the types of training data utilized to train the model, the datasets utilized to train the model ...algorithms that can be utilized by the system 100 can include, but are not limited to, classification algorithms, logistic regression algorithms, support vector machine algorithms, Naive Bayes algorithms, decision trees, ensemble techniques, deep learning algorithms, and/or any other types of algorithms. [120] the categorized balanced labeled samples have been correctly categorized ... the trainable machine learning model(s) using the categorized balanced labeled samples. In certain embodiments, the training and/or developing can include training the trainable machine learning model(s) to perform determinations relating to the suspiciousness of digital identifiers....[131]... updates model parameters of the trained machine learning model. In certain embodiments, an optimal combination of hyperparameters can be determined by conducting tuning on the hyperparameters to determine which combination of hyperparameters results in learning the optimal model parameters of the generated trained machine learning model that provide a highest performance according to a performance metric (e.g., evaluation measure) for determining suspiciousness of digital identifiers when compared to other generated trained machine learning models. In certain embodiments, the training can be performed and/or facilitated by utilizing the server 140, the server 145, the server 150, the server 160, the communications network 135, the PCP classifier 202 [135] the PCP classifier 202, the inference pipeline service 208...use any type of auto-machine learning technique to generate, determine, and/or identify the optimal machine learning model to process a request by utilizing the feature matrices of the training and validation samples obtained from the feature store 312. In certain embodiments, the learner 308 can be configured to determine or identify the optimal machine learning model for processing a request based on the optimal machine learning model having a highest performance based on a defined performance metric (or evaluation measure) in comparison to other trained machine learning models. In certain embodiments, the optimal machine learning model (or algorithm) can have an optimal hyperparameter combination, which can be utilized by during the training process to estimate and learn the optimal model parameters (e.g., the weights, coefficients, biases, thresholds, leaf values, intercepts, support vectors, multipliers, etc. for variables learned during the training process) for the optimal machine learning model. [131-135] elaborate on the matter [FIG.3] shows corresponding visual) ...apply a machine learning clustering model to the one or more alerts of the selected alerts to group the one or more alerts of the selected alerts into one or more alert clusters; (Radon [36] the method can include generating categorized labeled samples from the balanced labeled dataset. In certain embodiments, the method can include training, by utilizing the categorized labeled samples from the balanced labeled dataset, the trainable machine learning model to generate a trained machine learning model for identifying whether identifiers [68] classify and/or label requests and/or identifiers as being suspicious based on the determinations (or indications) from the automated suspicious URL/FQDN detection system 206 and persist (or store) the classifications and/or labels in a PCP database 204, which can be database 155 or a different database. [0111] the categorized samples are generated based on the constraint(s), the method 1000 can include developing and/or training the trainable machine learning model using features extracted from the categorized labeled samples. [116] cluster sampling ... the sampling strategy can be changed automatically based on time intervals, types of data present in new labeled datasets, and/or at will [120] the categorized balanced labeled samples have been correctly categorized ... the trainable machine learning model(s) using the categorized balanced labeled samples. In certain embodiments, the training and/or developing can include training the trainable machine learning model(s) to perform determinations relating to the suspiciousness of digital identifiers.... [131-135 & 148-151] elaborate on the matter [FIG.3] shows corresponding visual) and cause rendering of an alert cluster list interface to a user device display, wherein the alert cluster list interface comprises an alert cluster engagement component associated with at least one of the one or more alert clusters. (Radon [26] outputting an alert to the device associated with the user [0065] alerts outputted by the system 100 [106] provide the response including the indication to the PCP classifier 202. [89] The rankings can be provided via a notification ...a list of rankings [130-132] elaborate on the matter [FIG.1 in conjunction with FIG.3] shows rendering data to the users) Radon lacks explicitly and orderly teaching in a circumstance in which the tag based clustering algorithm is unable to group one or more alerts of the selected alerts into one or more alert clusters... However Teran teaches in a circumstance in which the tag based clustering algorithm is unable to group one or more alerts of the selected alerts into one or more alert clusters apply a machine learning clustering model to the one or more alerts of the selected alerts to group the one or more alerts of the selected alerts into one or more alert clusters (Teran [0042]Convolutional neural networks may be used to analyze photos images and video by security cameras, images uploaded to social media, etc. Machine learning models that may be used in conjunction with the present disclosure include, but are not limited to, reinforcement learning models, natural language processing models, trained classifiers, regression models, clustering models, anomaly detectors, etc. Based on the output of the various models being executed by the system, alerts may be issued and certain resources may be automatically be deployed, relocated to a different area, etc. [0058] The event classification data indicates a type of event, a severity of the event, a confidence value, or a combination thereof. In some instances, the event classifiers 326 may be unable to assign event classification data with sufficient confidence (e.g., greater than a threshold value) to a particular cluster. In such instances, the cluster can be re-evaluated, alone or with other data, by the clustering instructions 324 to determine whether the cluster is actually associated with two or more distinct events. In some implementations, the cluster can be re-evaluated by the clustering instructions 324 after a delay to allow additional related data to be gathered from the data sources 302. [FIG.1 in conjunction with FIG.3] shows corresponding visual for dealing with circumstance in which the tag based clustering algorithm is unable to group one or more alerts of the selected alerts into one or more alert clusters...) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of Teran in order to efficiently improve the system output via additional methods on handling situations in which the tag based clustering algorithm is unable to group one or more alerts of the selected alerts into one or more alert clusters (Teran [0014] According to particular aspects, public safety systems can be improved by using artificial intelligence (AI) to analyze various types and modes of input data in a holistic fashion. For example, video camera output can be analyzed using AI models to identify suspicious objects left unattended in places (e.g., airports), people or objects in a “wrong” or prohibited place or time, etc. Accomplishments in deep learning and improved computing capabilities enable some systems to go a step further [0038] efficacy of its recommended actions and generate training data that can be used to train subsequent generation(s) of models so that future event detections/classifications, risk index predictions, and suggested actions are more accurate and effective. [0062] the clustering instructions 324, the event classifiers 326, or the event response models 328. For example, based on data that is received from the data sources 302 well after the event (such as via updated news stories or social media posts), the computing device(s) 306 or a user may determine that the event classification data wrongly indicated that a bank robbery was a kidnapping. In this example, the digest data used to generate the initial event classification data can be used as labeled data by tagging the digest data as corresponding to a bank robbery and retraining one or more of the event classifiers based on the labeled data. As another example, the actual response actions taken and the resulting outcomes can be used with a reinforcement learning technique to update the event response models to improve future response recommendations.) the combination lack explicitly and orderly teaching all of wherein the alert set is generated by an alert management system configured to monitor a software application framework, and wherein each alert of the alert set is indicative of an operating functionality of a component of the software application framework However Malamut teaches wherein the alert set is generated by an alert management system configured to monitor a software application framework, and wherein each alert of the alert set is indicative of an operating functionality of a component of the software application framework (Malamut [0035] Such embodiments use knowledge about the software running on a machine (typically databases such as SQL server, Oracle) and monitors the activity performed on a machine based on the application(s) running on the machine. This extended knowledge allows a finer level of activity (e.g. DB create, delete, size changes) to be monitored to create alerts, and leverages the specific knowledge of the applications and their particular attributes. Additional applications can also be covered, and could include a web server or a content management system, so that the system could monitor number of web pages or files streamed, and so on. [0041] The embodiment of FIG. 1 extends the system to monitor attributes specific to the running applications on the machines (e.g., server or client computer) in the system through a. customized alert notification rules process 121. This process uses knowledge about the software running on a machine (typically databases such as SQL server.Oracle) and monitors the activity performed on a machine based on the application(s) running on the backup server 102 or machine. This extended knowledge allows a finer level of activity (e.g. DB create, delete, size changes) to be monitored to create alerts, and leverages the specific knowledge of the applications and their particular attributes. [0109] The system will record and analyze operation/asset type combinations in a database. Every operation against any known asset will cause the system to evaluate the contents of the database to determine if a new severity event (an operation/asset type over a timeframe that exceeded a metric) has occurred. When a new severity event occurs, the system will use the above rules to determine which users/systems are to be notified and how the notification is to be delivered. This system of alerts and notification rules helps users take advantage of the KPI information collected by the activity monitor 120, by allowing them to take action in real time and saving them from having to sift through the data to determine the importance of each alert individually. [110-119] elaborate on the matter [FIG.1 in conjunction with FIG.20] shows wherein the alert set is generated by an alert management system configured to monitor a software application framework, and wherein each alert of the alert set is indicative of an operating functionality of a component of the software application framework) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of Malamut in order to efficiently improve the overall performance of the system (Malamut [AB.] Embodiments for generating user customized alert notifications for application operations and activities based on monitored performance metrics. Key performance indicators for the application and user behavior are defined, and a monitor process collects behavior statistics of the application for each user with respect to data assets for each of the key performance indicators. Anomaly detection policies are provided to define anomalous behavior of the users with respect to data assets of the computer network. An anomaly detection process detects anomalous user behavior and an alert notification is sent to administrative or security personnel upon each detected instance of abnormal user behavior. The alert notification rules are defined by the user based on operation severity, asset type, operation, and defined metrics to tailor and minimize the number of alerts sent to the user.[0005] What is needed is a notification system that allows users to set customized notification rules to monitor key operations and send alerts only when any of these operations occurs so to minimize the volume of notifications generated in the system.[0059] In step 508, a KPI data event is created and sent to the anomaly detection service 424. The anomaly detection service receives the KPI data event information and runs 510 the required anomaly detection policies. These policies are defined and generated as described in greater detail below. The policies are used to analyze the KPI data event information to provide a detection of any abnormal or substandard performance of the application, 512. After analysis of the data, if an anomaly event is detected, an anomaly alert or notification will be created and saved in the database 418. In addition, the detected anomaly alert events will be sent out 514 to the user via the notification service 426 and the UI service 428.[FIG.1 in conjunction with FIG.20] shows the corresponding improvements)
Corresponding method claim 12 is rejected similarly as claim 1 above.
Corresponding product claim 20 is rejected similarly as claim 1 above. Additional Limitations: computer readable medium capable of reading and executing instructions (Radon [0140] The systems and methods of the present disclosure may take the form of or include a computer program product on a computer-readable storage medium or device having computer-readable program code (e.g., instructions) embodied or stored in the storage medium or device. Any suitable computer-readable storage medium or device may be utilized, including hard disks, CD-ROM, optical storage devices, magnetic storage devices, and/or other storage media. As used herein, a “computer-readable storage medium” or “computer-readable storage device” is not a signal [FIG.3 in conjunction with FIG.12] computer readable medium capable of reading and executing instructions)
Regarding claim 2, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 1, wherein the alert cluster list interface comprises an alert cluster bulk action component associated with at least one of the one or more alert clusters. (Radon [0052] As shown in FIGS. 1-7, a system 100 for providing automated detection of suspicious identifiers (e.g., digital identifiers) utilizing machine learning is provided. Notably, the system 100 can be configured to support, but is not limited to supporting, cybersecurity systems and services, monitoring and surveillance systems and services, phishing and content protection classification systems and services, ranking systems and services, SASE systems and services, cloud computing systems and services, privacy systems and services, firewall systems and services, data analytics systems and services, data collation and processing systems and services, artificial intelligence services and systems, machine learning services and systems, neural network services, autonomous vehicle applications and services, mobile applications and services, alert systems and services, content delivery services, satellite services, telephone services, voice-over-internet protocol services (VoIP), software as a service (SaaS) applications, platform as a service (PaaS) applications, gaming applications and services, social media applications and services, operations management applications and services, productivity applications and services, and/or any other computing applications and services. Notably, the system 100 can include a first user 101, who can utilize a first user device 102 to access data, content, and services, or to perform a variety of other tasks and functions. As an example, the first user 101 can utilize first user device 102 to transmit signals to access various online services and content, such as those available on an internet, on other devices, and/or on various computing systems. In certain embodiments, the first user 101 can utilize the first user device 102 to access services, applications, and/or content, such as by interacting with uniform resource locators (URLs), fully qualified domain names (FQDNs), links, and/or other mechanisms for accessing services, applications, and/or content. As another example, the first user device 102 can be utilized to access an application, devices, and/or components of the system 100 that provide any or all of the operative functions of the system 100. [0065] store alerts outputted by the system 100, store features utilized by the machine learning models to make determinations, store data shared by devices in the networks, store configuration information for the networks and/or devices of the system 100, store user profiles associated with the first and second users 101, 121, store device profiles associated with any device in the system 100, store communications traversing the system 100, store user preferences, store information associated with any device or signal in the system 100, store information relating to patterns of usage relating to the user devices, store any information obtained from any of the networks in the system 100, store historical data associated with the first and second users 101, 121, store device characteristics, store information relating to any devices associated with the first and second users 101, 121, store information associated with the communications network 135, store any information generated and/or processed by the system 100... [FIG.1 in conjunction with FIG.2] shows corresponding visual)
Corresponding method claim 13 is rejected similarly as claim 2 above.
Regarding claim 3, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 2, further comprising a bulk action assistant module configured to cause rendering of the alert cluster bulk action component to the user device display in association with the one or more alert clusters. (Radon [0052] As shown in FIGS. 1-7, a system 100 for providing automated detection of suspicious identifiers (e.g., digital identifiers) utilizing machine learning is provided. Notably, the system 100 can be configured to support, but is not limited to supporting, cybersecurity systems and services, monitoring and surveillance systems and services, phishing and content protection classification systems and services, ranking systems and services, SASE systems and services, cloud computing systems and services, privacy systems and services, firewall systems and services, data analytics systems and services, data collation and processing systems and services, artificial intelligence services and systems, machine learning services and systems, neural network services, autonomous vehicle applications and services, mobile applications and services, alert systems and services, content delivery services, satellite services, telephone services, voice-over-internet protocol services (VoIP), software as a service (SaaS) applications, platform as a service (PaaS) applications, gaming applications and services, social media applications and services, operations management applications and services, productivity applications and services, and/or any other computing applications and services.[0054] The first user device 102 can also include an interface 105 (e.g., screen, monitor, graphical user interface, etc.) that can enable the first user 101 to interact with various applications executing on the first user device 102 and to interact with the system 100. In certain embodiments, the first user device 102 can be and/or can include a computer, any type of sensor, a laptop, a set-top-box, a tablet device, a phablet, a server, a mobile device, a smartphone, a smart watch, a voice-controlled-personal assistant, a physical security monitoring device (e.g., camera, glass-break detector, motion sensor, etc.), an internet of things device (IoT), appliances, an autonomous vehicle, and/or any other type of computing device. Illustratively, the first user device 102 is shown as a computer in FIG. 1. In certain embodiments, the first user device 102 can be utilized by the first user 101 to control, access, and/or provide some or all of the operative functionality of the system 100 [FIG.1 in conjunction with FIG.2] shows corresponding visual)
Corresponding method claim 14 is rejected similarly as claim 3 above.
Regarding claim 4, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 2, wherein the one or more processors and one or more memories storing instructions are further operable, when executed by the one or more processors, to cause the alert cluster generation apparatus to: cause common action to each alert of the one or more alert clusters in response to user engagement with the alert cluster bulk action component. (Teran [FIG.1] shows overall flow which includes a common action to alerts/notifications in response to user actions with clusters of data [0022] The system may also automatically send reports or notifications regarding such events to users configured to receive such notifications. The system may generate recommendations regarding response actions and resource allocations/deployments. In some examples, the system can provide post-event information that can assist an investigation, searching the internet for relevant data related to an event that occurred within the monitored geographical or virtual area, etc. [0116] The user can configure aspects of the genetic algorithm 810 via input to graphical user interfaces (GUIs). For example, the user may provide input to limit a number of epochs that will be executed by the genetic algorithm 810. ...[107-116] further elaborate)
Regarding claim 5, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 1, wherein the one or more processors and one or more memories storing instructions are further operable, when executed by the one or more processors, to cause the alert cluster generation apparatus to: cause rendering of an alert cluster detail interface associated with the at least one of the one or more alert clusters upon receiving a user engagement indication associated the alert cluster engagement component. (Teran [0020] generate output reporting based on whether a match was found. If a match was not found, the detected face (or other identification) may optionally be stored in an alternate database, for example so that the stored information can be used to try identify the person using existing infrastructure. [0022] The system may also automatically send reports or notifications regarding such events to users configured to receive such notifications. The system may generate recommendations regarding response actions and resource allocations/deployments. In some examples, the system can provide post-event information that can assist an investigation, searching the internet for relevant data related to an event that occurred within the monitored geographical or virtual area, etc.[0117] The genetic algorithm 810 represents a recursive search process. Consequently, each iteration of the search process (also called an epoch or generation of the genetic algorithm 810) has an input set 820 of models (also referred to herein as an input population) and an output set 830 of models (also referred to herein as an output population). The input set 820 and the output set 830 may each include a plurality of models, [107-116] further elaborate [FIG.1 in conjunction with FIG.2] show rendering upon user engagement)
Regarding claim 8, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 1, wherein the tag based clustering algorithm comprises a pattern mining algorithm. (Radon [0065] store algorithms supporting the functionality of the machine learning models, store verifications of indications that an identifier, such as, but not limited to, a link, URL, FQDN, and/or interactable mechanism is suspicious or not, store alerts outputted by the system 100, store features utilized by the machine learning models to make determinations, store data shared by devices in the networks, store configuration information for the networks and/or devices of the system 100, store user profiles associated with the first and second users 101, 121, store device profiles associated with any device in the system 100, store communications traversing the system 100, store user preferences, store information associated with any device or signal in the system 100, store information relating to patterns of usage relating to the user devices, store any information obtained from any of the networks in the system 100, store historical data associated with the first and second users 101, 121, store device characteristics, store information relating to any devices associated with the first and second users 101, 121, store information associated with the communications network 135, store any information generated and/or processed by the system 100, store any of the information disclosed for any of the operations and functions disclosed for the system 100 herewith, store any information traversing the system 100, or any combination thereof. Furthermore, the database 155 can be configured to process queries sent to it by any device in the system 100.[0130] In certain embodiments, the obtaining of the labeled dataset can be enabled based on a signal transmitted via the training orchestrator 302 of the training pipeline service 210, which can be utilized request the labeled dataset from the PCP database 204. At 1104, the method 1100 can include training a plurality of trainable machine learning models based on the labeled dataset to generate trained machine learning models to perform suspiciousness determinations. In certain embodiments, the trainable machine learning models can be a computing process, procedure, program and/or algorithm (e.g., untrained) having a computing structure to combine a given input (e.g., labeled dataset) with a set of adjustable and/or trainable parameters to generate an output that is responsive to the given input. In certain embodiments, the trainable machine learning models can be computer procedures that are run on labeled or other datasets to recognize patterns and rules that can be trained to generate trained machine learning models. In certain embodiments, a trained machine learning model can be a trained trainable machine learning model that can be a computing process, algorithm, program, having a computing structure to combine a given input with a previously trained set of parameters to generate an output in response to a given input. In certain embodiments, the trained machine learning models can be the output resulting from training the trainable machine learning models and the trained machine learning models can be utilized to make predictions, such as predictions regarding the suspiciousness of an identifier associated with a request.)
Corresponding method claim 16 is rejected similarly as claim 8 above.
Regarding claim 9, Radon, Teran and Malamut teach The alert cluster generation apparatus of claim 1, wherein the tag based clustering algorithm is a deterministic rule-based process and wherein the machine learning clustering model comprises an unsupervised clustering machine learning model that is applied to a residual subset of the selected alerts, (Teran [0041] Public safety is a problem in places where crime has reached levels that are affecting daily citizen life. Even though budgets assigned to control this problem are substantial, existing solutions are not designed to anticipate reallocation of resources to maximize efficiencies. Currently solutions to these problems are provided manually by humans, but this does not scale and it is impossible to react in timely fashion due to the large quantity of inputs and the time it takes to process them, as well as due to the constant change in the modus operandi of organized crime. Thus, the techniques of the present disclosure do not merely automate an activity previously performed manually or in the human mind. Rather, the described techniques solve specific computing challenges. Using models that are trained using training data and supervised learning, and/or trained using unsupervised learning techniques, the system can quickly process the high volume and varied types of available input signals. The models may identify signals that are most highly correlated with successful detection/prediction, and based on those signals, generate output that can be used for security purposes.[0042] Different techniques may be used on different combinations of signals. Recurrent, convolutional, and/or LSTM neural networks may be used to process video and detect events based on a sequence of multiple frames. Audio data may be processed using deep learning techniques to perform audio fingerprinting, matching, feature extraction/comparison, etc. Internet data, emergency call data, etc. may be analyzed using natural language processing algorithms Convolutional neural networks may be used to analyze photos images and video by security cameras, images uploaded to social media, etc. Machine learning models that may be used in conjunction with the present disclosure include, but are not limited to, reinforcement learning models, natural language processing models, trained classifiers, regression models, clustering models, anomaly detectors, etc. Based on the output of the various models being executed by the system, alerts may be issued and certain resources may be automatically be deployed, relocated to a different area, etc.[52-57] further elaborate [FIG.1 in conjunction with FIG.3] shows corresponding visual) the residual subset comprising those of the one or more alerts of the selected alerts that the tag based clustering algorithm was unable to group into the one or more alert clusters (Teran [0042]Convolutional neural networks may be used to analyze photos images and video by security cameras, images uploaded to social media, etc. Machine learning models that may be used in conjunction with the present disclosure include, but are not limited to, reinforcement learning models, natural language processing models, trained classifiers, regression models, clustering models, anomaly detectors, etc. Based on the output of the various models being executed by the system, alerts may be issued and certain resources may be automatically be deployed, relocated to a different area, etc. [0058] The event classification data indicates a type of event, a severity of the event, a confidence value, or a combination thereof. In some instances, the event classifiers 326 may be unable to assign event classification data with sufficient confidence (e.g., greater than a threshold value) to a particular cluster. In such instances, the cluster can be re-evaluated, alone or with other data, by the clustering instructions 324 to determine whether the cluster is actually associated with two or more distinct events. In some implementations, the cluster can be re-evaluated by the clustering instructions 324 after a delay to allow additional related data to be gathered from the data sources 302. [FIG.1 in conjunction with FIG.3] shows corresponding visual for dealing with circumstance in which the tag based clustering algorithm is unable to group one or more alerts of the selected alerts into one or more alert clusters...)
Corresponding method claim 17 is rejected similarly as claim 9 above.
Regarding claim 10, Radon, Teran, and Malamut teach The alert cluster generation apparatus of claim 1, wherein the one or more processors and one or more memories storing instructions are further operable, when executed by the one or more processors, to cause the alert cluster generation apparatus to: cause calculation of one or more confidence metrics associated with the one or more alert clusters grouped by the tag based clustering algorithm or the machine learning clustering model; (Teran [0020] Machine learning strategies employed by the system can include deep learning for video analytics (e.g., object recognition or tracking), natural language processing, neural networks, genetic algorithms, etc. The system may, based on execution of one or more trained models, analyze the data to identify data related to common events, identify the type or severity of an event, and recommend one or more response actions for an event. [0045] Machine learning algorithms and models 122 perform holistic analysis of the input signals 102 to detect, identify, and respond to events. Video may be analyzed to identify events, behaviors, objects, faces, etc. using models (e.g., video analysis models 112) trained on TELs. A face recognition model 114 can compare faces detected in the video with law enforcement databases (e.g., a criminals database 108) and, optionally, alternate databases 116 that supplement law enforcement databases (e.g., if law enforcement databases do not reveal a face match, images posted to various social media sites 118 may be searched for a face match). The system 100 optionally may create the alternate database 116 where it will store the faces or other means of identification of people involved directly or indirectly in a crime or relevant event and that probably are or are not stored in the criminal databases 108 in order to identify and locate these people later. Other data sources 120, including sensors 110, ambient environment characteristics, social media posts, structured data, legacy system databases, and Internet data 118, etc. may be used as further inputs to refine event detection (e.g., influence a confidence value output by the model for the detected event). New TELs 124 may also be created (or existing TELs may be augmented) based on some or all of the input signals 102. In some cases, other adjustments may be received from different instances of the system, TELs, etc. [71-75 & 116-120] elaborate on the mater [FIG.1 in conjunction with FIG. 8] show cause calculation of one or more confidence metrics associated with the one or more alert clusters grouped by the tag based clustering algorithm or the machine learning clustering model;and tune the tag based clustering algorithm or retrain the machine learning clustering model based on the one or more confidence metrics) and tune the tag based clustering algorithm or retrain the machine learning clustering model based on the one or more confidence metrics. (Teran [0045] Machine learning algorithms and models 122 perform holistic analysis of the input signals 102 to detect, identify, and respond to events. Video may be analyzed to identify events, behaviors, objects, faces, etc. using models (e.g., video analysis models 112) trained on TELs. A face recognition model 114 can compare faces detected in the video with law enforcement databases (e.g., a criminals database 108) and, optionally, alternate databases 116 that supplement law enforcement databases (e.g., if law enforcement databases do not reveal a face match, images posted to various social media sites 118 may be searched for a face match). The system 100 optionally may create the alternate database 116 where it will store the faces or other means of identification of people involved directly or indirectly in a crime or relevant event and that probably are or are not stored in the criminal databases 108 in order to identify and locate these people later. Other data sources 120, including sensors 110, ambient environment characteristics, social media posts, structured data, legacy system databases, and Internet data 118, etc. may be used as further inputs to refine event detection (e.g., influence a confidence value output by the model for the detected event). New TELs 124 may also be created (or existing TELs may be augmented) based on some or all of the input signals 102. In some cases, other adjustments may be received from different instances of the system, TELs, etc.[0062] retrain or update one or more of the speech recognition instructions 320, the data reduction models 322, the clustering instructions 324, the event classifiers 326, or the event response models 328. For example, based on data that is received from the data sources 302 well after the event (such as via updated news stories or social media posts), the computing device(s) 306 or a user may determine that the event classification data wrongly indicated that a bank robbery was a kidnapping. In this example, the digest data used to generate the initial event classification data can be used as labeled data by tagging the digest data as corresponding to a bank robbery and retraining one or more of the event classifiers based on the labeled data. As another example, the actual response actions taken and the resulting outcomes can be used with a reinforcement learning technique to update the event response models to improve future response recommendations.[71-75 & 116-120] elaborate on the mater [FIG.1 in conjunction with FIG. 8] show cause calculation of one or more confidence metrics associated with the one or more alert clusters grouped by the tag based clustering algorithm or the machine learning clustering model;and tune the tag based clustering algorithm or retrain the machine learning clustering model based on the one or more confidence metrics)
Corresponding method claim 18 is rejected similarly as claim 10 above.
Regarding claim 11, Radon, Teran, and Malamut teach The alert cluster generation apparatus of claim 5, wherein user engagement with the alert cluster detail interface generates alert clustering feedback, and wherein the alert clustering feedback is used to tune or train at least one of the tag based clustering algorithm or the machine learning clustering model. (Teran [0045] Machine learning algorithms and models 122 perform holistic analysis of the input signals 102 to detect, identify, and respond to events. Video may be analyzed to identify events, behaviors, objects, faces, etc. using models (e.g., video analysis models 112) trained on TELs. A face recognition model 114 can compare faces detected in the video with law enforcement databases (e.g., a criminals database 108) and, optionally, alternate databases 116 that supplement law enforcement databases (e.g., if law enforcement databases do not reveal a face match, images posted to various social media sites 118 may be searched for a face match). The system 100 optionally may create the alternate database 116 where it will store the faces or other means of identification of people involved directly or indirectly in a crime or relevant event and that probably are or are not stored in the criminal databases 108 in order to identify and locate these people later. Other data sources 120, including sensors 110, ambient environment characteristics, social media posts, structured data, legacy system databases, and Internet data 118, etc. may be used as further inputs to refine event detection (e.g., influence a confidence value output by the model for the detected event). New TELs 124 may also be created (or existing TELs may be augmented) based on some or all of the input signals 102. In some cases, other adjustments may be received from different instances of the system, TELs, etc.[0062] retrain or update one or more of the speech recognition instructions 320, the data reduction models 322, the clustering instructions 324, the event classifiers 326, or the event response models 328. For example, based on data that is received from the data sources 302 well after the event (such as via updated news stories or social media posts), the computing device(s) 306 or a user may determine that the event classification data wrongly indicated that a bank robbery was a kidnapping. In this example, the digest data used to generate the initial event classification data can be used as labeled data by tagging the digest data as corresponding to a bank robbery and retraining one or more of the event classifiers based on the labeled data. As another example, the actual response actions taken and the resulting outcomes can be used with a reinforcement learning technique to update the event response models to improve future response recommendations. [0031] Risk events may be classified through multiple relevance parameters, for example accidents and type of accident, violations and type of violation, crime and type of crime, weapons in scene (e.g., presence of weapons, types of weapons, number of weapons), criminals recognized in scene, etc. The system may “learn” what is relevant based on initial training of machine learning models and further based on feedback [71-75 & 116-120] elaborate on the mater [FIG.1 in conjunction with FIG. 8] wherein user engagement with the alert cluster detail interface generates alert clustering feedback, and wherein the alert clustering feedback is used to tune or train at least one of the tag based clustering algorithm or the machine learning clustering model)
Corresponding method claim 19 is rejected similarly as claim 11 above.
Claims 6 is rejected under 35 U.S.C. 103 as being unpatentable over Radon in view of Teran, Malamut and US 20210406041 A1; Saraiya; Urvish et al. (hereinafter Saraiya)
Regarding claim 6, Radon, Teran, and Malamut teach The alert cluster generation apparatus of claim 5 Radon and Teran lack explicitly and orderly teaching wherein the alert cluster detail interface comprises an alert cluster pattern interface component that is configured to visually depict alert analytics associated with the at least one of the one or more alert clusters. However Saraiya teaches wherein the alert cluster detail interface comprises an alert cluster pattern interface component that is configured to visually depict alert analytics associated with the at least one of the one or more alert clusters. (Saraiya [0004] the present disclosure is directed to a method of displaying information to assist a user with critical-event management. The method being performed by a computing system includes retrieving, from a datastore in memory of the computing system, data contained in an analytics table comprising values for a plurality of attributes of each of a plurality of stored critical events; executing at least one pattern-recognition algorithm that operates on the data in the analytics table so as to identify one or more patterns within the plurality of attributes among the plurality of stored critical events; executing a visualization algorithm to generate a visualization depicting the one or more patterns; and displaying, via a graphical user interface (GUI) of the computing system, the visualization to the user. [0027] identifying patterns or other groupings in historical critical event data, providing one or more Analytics Dashboards graphical user interfaces (GUIs) that allow one or more users to view and assess such patterns/groupings and implement changes that may result from such assessments, providing Dashboard Analytics GUIs that allow one or more users to augment data associated with each historical or otherwise closed critical event, generating models of critical events that enable a CEM software system to make predictions about newly arriving critical events and/or recommendations for resolving newly arriving critical events, and providing one or more Dashboard Analytics GUIs [0034] The output of pattern-recognition algorithm(s) 104 may be used by a visualization GUI, such as visualization GUI 116 of FIG. 1, that allows a user to view representations of the output of the pattern-recognition algorithm(s). Visualization GUI 116 may be configured to display any one or more of a variety of charts, graphs, tables, and/or other data-visualization graphics that allow a user to view the output of pattern-recognition algorithm(s) 104 and/or representations of such output... cause visualization GUI 116 to display a popup window or dialog box (not shown, but examples shown in FIGS. 3 and 6D) that lists specific information about that critical event, such as type, identifier, date, resources used, and/or any other attributes from critical-event data 108 and/or information from the output of pattern-recognition algorithm(s) [FIG.6-7] show corresponding visual) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to take all prior methods and make the addition of Saraiya's visualization and analytics in order to efficiently create a more enhanced output with better user experience (Saraiya [0003] For a wide variety of organizations, properly managing critical events, such as information-technology (IT) incidents, severe-weather and other force-of-nature events, active-shooter events, fire events, terrorist events, etc., is important to minimize the impact (e.g., disruption to usual operations and cost) of the critical events on the organizations. Many organizations manage at least some of their critical events using critical event management (CEM) software systems available from a variety of providers, such as Everbridge Inc., Burlington, Mass. Some CEM software systems provide users with a wide range of functionality, from providing graphical user interfaces (GUIs) that allow critical-event managers to view statuses of current critical event and interface with responders and response teams working to resolve critical events. Centralization of CEM afforded by contemporary CEM software systems has led to improvements in CEM that have correspondingly led to efficiencies and improved response performance. However, advancements in CEM software systems that lead to further efficiencies and performance improvements are desired [0063] analytics GUI 600 to display another popup window 674 or other graphical device that contains user-selectable actions in the form of a “Quarantine” selector 674(1), among others. Both of these actions are prescriptive actions that the CEM software system suggests based on the classification and/or regression performed using one or more predictive models as discussed above. For example, the CEM software may recommend these actions based on historical data that shows that they are the two most effective actions to minimize TTR and/or cost impact, perhaps among other criteria. Prescriptive-analytics GUI 600 may display these suggested actions in order of performance (e.g., lowest TTR, lowest cost, etc., or combination of such factors), for example, with the best (better) performing action at the top of the list. [0134] CRM subsystem 800 displays the discovered patterns 804A to a knowledgeable user via Analytics Dashboard 804. By viewing patterns 804A uncovered during pattern discovery on Analytics Dashboard 804, a knowledgeable user can gain knowledge about historical critical events and their attributes and use that knowledge to drive improvements to the organization's management of future critical events as well as to inform the organization about its CEM strategy and implementation success. Analytics Dashboard 804 is partly driven by various algorithms, including, but not limited to static and interactive charting algorithms for charting and displaying discovered patterns to the user and/or allowing a user to interact with the charts.[0201] As seen in FIG. 9, UI 904 includes six tabs 912 that provide various functionalities. In screenshot 900, a use has selected the Patterns tab 912(1), correspondingly, UI 904 displays a set of charts 916(1) to 916(3) that present various patterns to the user. In this example, chart 916(1) shows response efficiency)
Claims 7 and 15 is rejected under 35 U.S.C. 103 as being unpatentable over Radon in view of Teran, Malamut and US 20230137235 A1; CHEN; Hsiulan (hereinafter Chen)
Regarding claim 7, Radon, Teran, and Malamut teach The alert cluster generation apparatus of claim 1 the combination lack explicitly and orderly teaching wherein the alert features comprise alert tags extracted through tag extraction, alert text extracted through text extraction, or vector embeddings extracted through vectorization. However Chen teaches wherein the alert features comprise alert tags extracted through tag extraction, alert text extracted through text extraction, or vector embeddings extracted through vectorization. (Chen [0018] The log collector 130 of the automated service alert system 120 collects the log messages 105 from various sources where the microservices including the microservice N 103 write system logs during operation such as system log directory, log storage area for the workload 101 and/or the respective microservices, memory dump or storage area set aside for logs by the application, based on the respective log configurations of the microservices. An operating system of a computing platform running the microservice-based service architecture, the microservice-based service architecture, the application running on the microservice-based service architecture, or the individual microservices themselves can configure where the log messages 105 would be recorded. The log collector 130 then transforms the log messages 105 into time domain analysis (TDA) graph data and prepares the log messages 105 for the log analyzer 140 by, for example, extracting clean text from the log messages 105. [0022] The log analyzer 140 extracts keyword patterns and stores the keyword patterns in a keywords DB 170 based on the clean texts of the log messages 105 as prepared by the log collector 130 and the TDA graph data stored in the TDA DB 160. The log analyzer 140 performs a frequency domain analysis on the keyword patterns in the keywords DB 170 and stores the result in a frequency domain analysis (FDA) DB 180. Upon receiving a notification from the application health monitor 150 to update a certain statistically deviating keyword patterns and iterations within the threshold, the log analyzer 140 updates the keywords DB 170 and the FDA DB 180 with the logs generated by the currently monitored workload. [44-50] elaborate on the matter [FIG.1&4] show the corresponding visual)
Corresponding method claim 15 is rejected similarly as claim 7 above.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARYAN D TOUGHIRY whose telephone number is (571)272-5212. The examiner can normally be reached Monday - Friday, 9 am - 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aleksandr Kerzhner can be reached at (571) 270-1760. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ARYAN D TOUGHIRY/Examiner, Art Unit 2165
/ALEKSANDR KERZHNER/Supervisory Patent Examiner, Art Unit 2165