DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Amendment
The preliminary amendment to the claims filed 08/18/25 has been entered and is the current claim set being examined.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 6-7, 12, 17-18 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Ivershen (US 2011/0145391).
As to claims 1, 12, Ivershen discloses an apparatus (108), and corresponding data flow identification method, comprising:
a processor (paragraph 25); and
a memory coupled to the at least one processor to store instructions (paragraph 25), which when executed by the processor, cause the apparatus to:
obtain a fingerprint feature (paragraph 10, 28, 42) and setup time of a first data flow (timestamp of first packet; paragraph 10, 29, 45); and
determine, based on the fingerprint feature and the setup time of the first data flow, at least one data flow network address translation (NAT) associated with the first data flow (determining the second data flow, which passed through NAT, associated with the first data flow; paragraph 27-29, 44-46).
As to claim 6, 17, Ivershen discloses wherein the instructions further cause the apparatus to:
determine a second data flow based on the fingerprint feature of the first data flow, wherein a fingerprint feature of the second data flow is the same as the fingerprint feature of the first data flow (paragraph 44-46); and
determine, when an absolute value of a time difference between setup time of the second data flow and the setup time of the first data flow is less than a threshold, that the first data flow is NAT-associated with the second data flow (within a time window that is close to or similar to the timestamp; see paragraph 45-46).
As to claim 7, 18, Ivershen discloses wherein the fingerprint feature comprises at least one of following features: an internet protocol identifier (IPID) of a first data packet (paragraph 28, 42), a payload of the first data packet (paragraph 28, 42), a hash value of the payload of the first data packet (paragraph 28, 42), an IPID of an synchronize sequence number (SYN) packet in a transmission control protocol (TCP) three-way handshake process (paragraph 28, 37, 42-43), an initial sequence number (ISN) of the SYN packet in the TCP three-way handshake process (paragraph 28, 42), or an ISN of an SYN-ACK packet in the TCP three-way handshake process (paragraph 28, 37, 42-43).
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Ahn et al. (Ahn) (US 2016/0234083).
As to claims 1 and 12, Ahn discloses an apparatus (Fig. 1, 128), and corresponding data flow identification method, comprising:
a processor (132; paragraph 15); and
a memory coupled to the at least one processor to store instructions (130, paragraph 15), which when executed by the processor, cause the apparatus to:
obtain a fingerprint feature and setup time of a first data flow (Fig. 3, paragraph 16-18, 40-42, 53); and
determine, based on the fingerprint feature and the setup time of the first data flow, at least one data flow network address translation (NAT) (paragraph 21, 31-32, 43-44) associated with the first data flow (comparing records and timestamps for received packets to transmitted packets to identify matches; paragraph 48-50, 53).
As to claim 2, 13, Ahn discloses wherein the instructions further cause the apparatus to:
send a first query request to a first network node, wherein the first query request comprises a first flow identifier of the first data flow (rules for which packets to monitor and log; paragraph 15-17, 25, 28, 38-40); and
receive a first query response sent by the first network node, wherein the first query response comprises the fingerprint feature and the setup time of the first data flow (received log data from the tap; Fig. 3, paragraph 17-18, 41-42, 53).
As to claim 3, 14, Ahn discloses wherein the instructions further cause the apparatus to:
send a second query request to a second network node (rules for which packets to monitor and log; paragraph 15-17, 25, 28, 38-40) comprising the fingerprint feature of the first data flow (such as network-layer information contained in their headers indicating an address; paragraph 16, 25, 33, 40);
receive a second query response sent by the second network node, wherein the second query response comprises a first flow identifier and setup time of a second data flow having a same fingerprint feature as the first data flow (taps returning log data matching rules criteria; Fig. 3, paragraph 16-18, 40-42, 53); and
determine, when an absolute value of a time difference between the setup time of the second data flow and the setup time of the first data flow is less than a threshold, that the first data flow is NAT-associated with the second data flow (timestamp difference within a threshold value; see paragraph 49).
As to claim 4, 15, Ahn discloses wherein the first query response further comprises a first flow identifier and setup time of a second data flow having a same fingerprint feature as the first data flow (taps returning log data and timestamps matching rules criteria; Fig. 3, paragraph 16-18, 40-42, 53); and the instructions further cause the apparatus to:
determine, when an absolute value of a time difference between setup time of the second data flow and the setup time of the first data flow is less than a threshold, that the first data flow is NAT- associated with the second data flow (timestamp difference within a threshold value; see paragraph 49).
As to claim 5, 16, Ahn discloses wherein the instructions further cause the apparatus to:
receive a first query request comprising a first flow identifier of the first data flow (paragraph 15-18, 25, 28, 39-42); and
determine the fingerprint feature and the setup time of the first data flow based on the first flow identifier of the first data flow (received and analyzed log data from the tap; Fig. 3, paragraph 17-18, 41-42, 53).
As to claim 6, 17, Ahn discloses wherein the instructions further cause the apparatus to:
determine a second data flow based on the fingerprint feature of the first data flow, wherein a fingerprint feature of the second data flow is the same as the fingerprint feature of the first data flow (Fig. 3, paragraph 48-49); and
determine, when an absolute value of a time difference between setup time of the second data flow and the setup time of the first data flow is less than a threshold, that the first data flow is NAT-associated with the second data flow (timestamp difference within a threshold value; see paragraph 49).
As to claim 7, 18, Ahn discloses wherein the fingerprint feature comprises at least one of following features: an internet protocol identifier (IPID) of a first data packet (paragraph 18), a payload of the first data packet (paragraph 18), a hash value of the payload of the first data packet (checksum; paragraph 18), an IPID of an synchronize sequence number (SYN) packet in a transmission control protocol (TCP) three-way handshake process, an initial sequence number (ISN) of the SYN packet in the TCP three-way handshake process, or an ISN of an SYN-ACK packet in the TCP three-way handshake process.
As to claim 8, 19, Ahn discloses wherein the instructions further cause the apparatus to:
determine, when the absolute value of the time difference between the setup time of the second data flow and the setup time of the first data flow is less than the threshold (timestamp difference within a threshold value; see paragraph 38, 49) and a fingerprint conflict does not exist between the first data flow and the second data flow (comparing data entries within the log to determine a correlation score between the log data; paragraph 36-37), that the first data flow is NAT- associated with the second data flow, wherein the fingerprint conflict means that fingerprint features of non-NAT-associated data flows are the same (compared data to determine multiple potential correlating entries, with the greatest match indicating they correspond to the same flow; paragraph 36-37).
As to claim 9, 20, Ahn discloses wherein the instructions further cause the apparatus to:
determine at least one third data flow having a same second flow identifier as the second data flow (paragraph 36-37);
determine at least one fourth data flow having a same fingerprint feature as each third data flow (paragraph 36-37); and
determine, when an absolute value of a time difference between setup time of one fourth data flow in the at least one fourth data flow and setup time of a corresponding third data flow is less than a threshold (timestamp difference within a threshold value; see paragraph 38, 49) and a second flow identifier of the fourth data flow is the same as a second flow identifier of the first data flow, that a fingerprint conflict does not exist between the first data flow and the second data flow (lower correlated entries determined to have some values in common but not be the same flow; paragraph 36-37).
As to claim 10, Ahn discloses an apparatus (Fig. 1, 124, 126), comprising:
a processor (paragraph 15); and
a memory coupled to the at least one processor to store instructions (paragraph 15), which when executed by the processor, cause the apparatus to:
receive a query request, wherein the query request comprises comprising a first flow identifier of a first data flow (rules for which packets to monitor and log; paragraph 15-17, 25, 28, 38-40); and
send a query response, wherein the query response comprises comprising a fingerprint feature and setup time of the first data flow (Fig. 3, paragraph 16-18, 40-42, 53), and the fingerprint feature and the setup time of the first data flow are used to determine at least one data flow NAT-associated with the first data flow (it is noted that this limitation is directed to actions performed outside the apparatus, and thus is not required, as it does not alter its functionality and instead describes functions potentially performed by a different device) (Ahn further discloses comparing records and timestamps for received packets to transmitted packets to identify matches; paragraph 48-50, 53).
As to claim 11, Ahn discloses wherein the query response further comprises a first flow identifier and setup time of a second data flow having a same fingerprint feature as the first data flow (taps returning log data matching rules criteria and timestamps; Fig. 3, paragraph 16-18, 40-42, 53).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Shay et al. (US 2003/0223367) disclosing correlating a first data flow and a network address translated second data flow based upon a fingerprint feature and time of the data flows.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Sheleheda whose telephone number is (571)272-7357. The examiner can normally be reached M-F 8 am-5 pm CST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Benjamin Bruckart can be reached at (571) 272-3982. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/James R Sheleheda/Primary Examiner, Art Unit 2424