Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-18 of U.S. Patent No. 11,336,669. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of US 11,336,669 anticipate all of the current claims at issue.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,407,712. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of US 12,407,712 anticipate all of the current claims at issue.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 20 is rejected. The term "less repetition" and “greater efficiency” in claim 20 is a relative term which renders the claim indefinite. The terms "less repetition" and “greater efficiency” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Appropriate correction is required.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “module configured to” in claims 11-20.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-7, 9-11, 13-17, 19, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Zhang US 2017/0054745 in view of Jang US 2019/0190945.
As per claims 1, 10, 11. Zhang teaches A method of protecting a system, including but not limited to a network, from a cyber threat, comprising: identifying, with one or more Artificial Intelligence models trained with machine learning on a normal behavior of the system, at least one of i) an abnormal behavior, ii) a suspicious activity, and iii) any combination of both, from one or more entities in the system. Zhang teaches analyzing a collection of system data, including metrics data, to support or refute each of the one or more possible cyber threat hypotheses that could include the identified abnormal behavior and/or suspicious activity data with the one or more AI models trained with machine learning on possible cyber threats; and formatting an output of one or more supported possible cyber threat hypotheses from the possible set of cyber threat hypotheses into a formalized report, from a first template, that is outputted for a human user's consumption in a medium selectable from a group consisting of 1) printable report, 2) presented digitally on a user interface, 3) in a machine readable format for further use in machine-learning reinforcement and refinement, or 4) any combination of the three. [0039][0052][0053][0054][0058] (teaches modeling to detect abnormal behavior or malicious activity using machine learning and analysis, and presenting reports to a user for possible cyber threats)
Jang teaches forming one or more hypotheses on what are a possible set of cyber threats that could include the identified abnormal behavior and/or suspicious activity with one or more AI models trained with machine learning on possible cyber threats; [0007] [0050][0051] [0064] [0074] [0081] (teaches gathering evidence and presenting hypothesis including machine learning)
It would have been obvious to one of ordinary skill in the art to use the hypotheses of Jang because it provides more information about the probability of cyber threat causes for users.As per claims 3, 13 Jang teaches The method of claim 1, further comprising: initiating a collection of data to support or refute each of the one or more possible cyber threat hypotheses that could include this abnormal behavior or suspicious activity by the one or more AI models trained on possible cyber threats, extracting data on each possible hypothetical threat that would include the abnormal behavior or suspicious activity and then filtering that collection of data down to relevant points of data to either 1) support or 2) refute each particular hypothesis of what the cyber threat the suspicious activity and/or abnormal behavior relates to, and sending the filtered down relevant points of data to either 1) support or 2) refute each particular hypothesis to one or more algorithms used by the AI models trained with machine learning on possible cyber threats to make a determination on a probable likelihood of whether that particular hypothesis is supported or refuted. [0007] [0050][0051] [0064] [0074] [0081] (teaches gathering evidence and presenting hypothesis including machine learning)
As per claims 4, 14. Jang teaches The method of claim 3, further comprising: using a plurality of scripts to walk through a step by step process of what to collect to filter down to the relevant data points to make a decision and analyze possible cyber threats and one or more AI models trained with machine learning on a process of human analyzing on possible cyber threats and the relevant data points human analysts examine to support or rebut their analysis of a given cyber threat hypothesis. [0007] [0050][0051] [0064] [0074] [0081] (teaches gathering evidence and presenting hypothesis including machine learning and human review; Examiner interprets “scripts” to be the program that walks through the evidence; Jang teaches finding evidence and scoring evidence in the process of determining and ranking cyber threats)
As per claims 5, 15 Jang teaches The method of claim 1, further comprising: assigning either i) a probability or ii) a confidence level, of a given cyber threat hypothesis that is supported and a threat level posed by that cyber threat hypothesis, which includes this abnormal behavior or suspicious activity, with the one or more AI models trained on possible cyber threats. [0074] (ranks hypothesis by severity and likelihood to report to personnel)As per claims 6, 16 Zhang teaches The method of claim 5, further comprising: generating a textual write up of an incident report in the formalized report for a wide range of breaches of normal behavior, used by the AI models trained with machine learning on the normal behavior of the system, based on analyzing previous reports with one or more models trained with machine learning on assessing and populating relevant data into the incident report corresponding to each possible cyber threat. [0054][0055][0058] (presents reports based in part on models with machine learning and historical data)As per claims 7, 17. Jang teaches The method of claim 1, further comprising: generating a threat incident report in the formalized report from a multitude of dynamic human-supplied and/or machine created templates corresponding to different types of cyber threats, each template, including the first template, corresponding to different types of cyber threats that vary in format, style, and standard fields in the multitude of templates, populating a given template with relevant data, graphs, or other information as appropriate in various specified fields, along with a ranking of a likelihood of whether that hypothesis cyber threat is supported and its threat severity level for each of the supported cyber threat hypotheses, and then outputting the formatted threat incident report with the ranking of each supported cyber threat hypothesis, which is presented digitally on the user interface and/or printed as the printable report. [0007] [0050][0051] (Jang teaches reports based on threats with ranking by threat and likelihood) (Zhang teaches a more comprehensive formalized report [0058]As per claim 9, 19 Jang teaches The method of claim 1, further comprising: ranking supported candidate cyber threat hypotheses by combination of a likelihood that this candidate cyber threat hypothesis is supported as well as severity threat level of this incident type, where these factors are combined to create a total ordering possible cyber threat hypotheses presented in the formalized report on the user interface, where a filtering out of refuted cyber threat hypotheses and putting higher supported and more severe threat level possible cyber threat hypotheses higher in the total ordering of possible cyber threat hypotheses allows cyber personnel to better focus on interesting cyber threats that could include the identified abnormal behavior and/or suspicious activity data. [0074] (ranks hypothesis by severity and likelihood to report to personnel)
As per claim 15, Jang teaches The apparatus of claim 11, further comprising: an assessment module configured to assign a probability of a given cyber threat hypothesis that is supported and a threat level posed by that cyber threat hypothesis, which includes this abnormal behavior or suspicious activity, with the one or more AI models trained on possible cyber threats. [0074] (ranks hypothesis by severity and likelihood to report to personnel)
As per claim 20. Jang teaches The apparatus of claim 11, further comprising: wherein the trigger module, analyzer module and formatting module cooperate to improve the analysis and formalized report generation with less repetition to consume CPU cycles with greater efficiency than humans repetitively going through these steps and re-duplicating steps to filter and rank the one or more supported possible cyber threat hypotheses from the possible set of cyber threat hypotheses. [0074]- [0077] (more efficient than standard human analysis)
Claims 2, 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Zhang US 2017/0054745 in view of Jang US 2019/0190945 in view of Yadav 2016/0359695
As per claims 2, 12 Yadav teaches The method of claim 1, further comprising: wherein the AI models trained with machine learning on possible cyber threats are at least one or more supervised machine learning models, and using both 1) the one or more supervised machine learning models trained on agnostic examples of past history of detection of a multitude of possible types of cyber threat hypotheses previously analyzed by human cyber threat analysis, and 2) one or more unsupervised machine learning models trained to perform anomaly detection verses a normal pattern of life to determine whether the abnormal behavior and/or suspicious activity is malicious or benign when the cyber threat is previously unknown. [0017] [0084]- [0090] (Yadav teaches both supervised and unsupervised learning methods for detecting cyber threats)
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the learning methods of Yadav with the prior combination because both machine learning methods improve efficiency.
Claims 8, 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Zhang US 2017/0054745 in view of Jang US 2019/0190945 in view of Altman US 2014/0359761
As per claims 8, 18 Altman teaches The method of claim 1, further comprising: utilizing repetitive feedback, as time goes on, for the AI models trained with machine learning on possible cyber threats via reviewing a subsequent resulting analysis of the supported possible cyber threat hypotheses and supply that information to the training of the AI models trained with machine learning on possible cyber threats in order to reinforce the model's finding were correct or inaccurate. [0055]- [0057] (analyst uses repetitive feedback to improve models)
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the feedback of Altman with the prior art combination because it improves accuracy.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439