DETAILED ACTION
This Non-Final Office Action is in response to Application filed on 08/28/2025.
Claims 1-20 filed on 08/28/2025 are being considered on the merits.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings filed on 08/28/2025 are accepted.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 08/28/2025 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly an initialed and dated copy of Applicant's IDS form 1449 filed 08/28/2025 are attached to the instant Office action.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, and 8-20 are rejected under 35 U.S.C. 103 as being unpatentable over Levy et al. (US 20190319987 A1 and hereafter referred as Levy et al.) in view of Shenefiel et al. (US 20200159947 A1 and hereafter referred as Shenefiel et al.), Mandagere et al. (US 20110296237 A1 and hereafter referred as Mandagere et al.), and Jaiswal (US 20120303558 A1 and hereafter referred as Jaiswal).
As for claim 1, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal discloses a method for implementing data loss prevention (DLP), the method comprising: (Levy et al. teaches of a method for data loss prevention to classify data and use the classifications for analytics and response [Section [0098]])
obtaining file system metadata for an asset in a client; (Levy et al. teaches gathered documents on users’ local computers and a recognition model labeling the files based on file metadata [Sections [0105], [0135]])
analyzing the file system metadata to generate an asset lineage map; (Levy et al. teaches of a ledger (i.e. asset lineage map) created through file metadata that contains the tracking of file custody and file content [Sections [0144], [0145]])
identifying, based on the asset lineage map, an input feature linked to the asset, a type of the asset, and a plurality of activities linked to the asset; (Levy et al. teaches evaluating a trustworthiness of the file based chain of custody (i.e. plurality of activates) from the ledger (i.e. asset lineage map), analysis of the amount and type of changes to the file (version of the file/ i.e. input feature), and the type of file including classifications (i.e. type of the asset) [Section [0154]])
obtaining, based on the plurality of activities, a malicious score and a data loss score for the asset; (Levy et al. teaches ranking intermediate threats (i.e. plurality of activities) based an objective score of riskiness (i.e. malicious score) from an integrative model [Sections [0118], [0119]])
determining a user level of a user; (Levy et al. teaches levels of privileges for one or more users [Section [0202]])
tagging, based on the user level of the user, the user as a high-risk user; (Levy et al. teaches an identity provider provides user identity information (i.e. user level) and an identity management facility determines a risk score for a user, if the use is risky (i.e. high-risk user) the identity provider assesses the user [Section [0037]])
making a second determination that the plurality of activities are malicious; (Levy et al. teaches calculating a second risk score by a threat management facility based on a second event vector for detection of malicious activity [Section [0183]])
The combination of Levy et al., Mandagere et al., and Jaiswal do not disclose:
obtaining, based on the type of the asset, a coefficient for the input feature;
executing, based on the input feature and the coefficient, a model to obtain an asset sensitivity score for the asset;
based on the asset sensitivity score
making a determination, based on the asset risk score, that the asset is a sensitive asset;
However, Shenefiel et al. does disclose:
obtaining, based on the type of the asset, a coefficient for the input feature; (Shenefiel et al. teaches assigning coefficients of a linear classifier trainer (i.e. input feature) based on file metadata (type of asset) [Section [0099]])
executing, based on the input feature and the coefficient, a model to obtain an asset sensitivity score for the asset; (Shenefiel et al. teaches a sensitivity score of a file (i.e. asset) about the type of endpoint (i.e. input feature) and correlated by traffic analysis service employed by a machine learning model [Sections [0062], [0037]])
based on the asset sensitivity score (Shenefiel et al. teaches sensitivity score based on a file on metadata [Section [0081]])
making a determination, based on the asset risk score, that the asset is a sensitive asset; (Shenefiel et al. teaches a sensitivity score based on weights applied to words found within file path associated with a file (i.e. asset), which correlates to an asset risk score [Section [0116]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Mandagere et al., and Jaiswal with the teachings of Shenefiel et al. for coefficient for input feature, sensitivity score, and an asset risk score to increase security for asset authentication.
The combination of Levy et al., Shenefiel et al., and Jaiswal do not disclose:
determining, the malicious score, and the data loss score
However, Mandagere et al. does disclose:
determining, the malicious score, and the data loss score (Mandagere et al. teaches a data restore point based on a data loss percentage (i.e. data loss score) and a combination of signature match scores (i.e. malicious score). Signature match comprises information for a event log [Sections [0039], [0007]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Jaiswal with the teachings of Mandagere et al. for determining a malicious and data loss score to increase efficiency with identifying threats for asset protection.
The combination of Levy et al., Shenefiel et al., and Mandagere et al. do not disclose:
implementing, based on the second determination, a medium-level DLP policy to deter the user.
However, Jaiswal does disclose:
implementing, based on the second determination, a medium-level DLP policy to deter the user. (Jaiswal teaches implementing a DLP system and a DLP policy that limits data exiting a client device and locks down the device (i.e. deter the user) [Sections [0077], [0078]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Mandagere et al. with the teachings of Jaiswal for implementing a DLP policy to increase efficiency in preventing threats for asset security.
Independent claims 3 and 17 recite substantially similar subject matter to claim 1 and are therefore rejected for similar reasons as applied to claim 1 above. Dependent claims 4, 8, 11, 18 recite substantially similar subject matter to claim 1 and are therefore rejected for similar reasons as applied to claim 1 above.
As for claim 2, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal discloses the method of claim 1, further comprising: making a third determination, that a second plurality of activities has a higher level of risk; (Levy et al. teaches calculating a second risk score by a threat management facility based on a second event vector for detection of malicious activity [Section [0183]]) and implementing, based on the third determination, policy to disrupt the user. (Levy et al. teaches an implemented policy restricting messaging activity, prevent access to data or network access [Sections [0051], [0053]])
The combination of Levy et al., Shenefiel et al., and Mandagere et al. do not disclose:
implementing the medium-level DLP policy
a high-level DLP policy
However, Jaiswal does disclose:
implementing the medium-level DLP policy (Jaiswal teaches an implemented DLP policy determining the sensitivity of identified data [Section [0072]])
a high-level DLP policy (Jaiswal teaches implementing a DLP system and a DLP policy that limits data exiting a client device and locks down the device (i.e. deter the user) [Sections [0077], [0078]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Mandagere et al. with the teachings of Jaiswal for implementing different levels of DLP policies for enhanced security prevention tactics for asset security.
As for claim 5, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal discloses the method of claim 4, wherein initiating implementing an intrusive monitoring on the user by recording a display screen of the user. (Levy et al. teaches an entity type such as a laptop that is monitored for the events associated with the entity. An entity model creates observing activity as recorded by an entity. [Sections [0166], [0167]]).
The combination of Levy et al., Shenefiel et al., and Mandagere et al. do not disclose:
implementation of the second DLP policy comprises implementing an intrusive monitoring
However, Jaiswal does disclose:
implementation of the second DLP policy comprises implementing an intrusive monitoring (Jaiswal teaches a DLP policy monitoring messages, displayed data, store documents, and actions performed when sensitive data is detected [Section [0072]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Mandagere et al. with the teachings of Jaiswal for implementing a DLP policy for monitoring to increase security at the user level.
Dependent claim 19 recites substantially similar subject matter to claim 5 and is therefore rejected for similar reasons as applied to claim 5 above.
As for claim 6, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal discloses the method of claim 4, further comprising: after implementing the second DLP policy, obtaining a third plurality of activities linked to the asset; (Levy et al. teaches a third model to identify computer objects based on life behavior, file path, or features suitable for assessing suspiciousness (i.e. plurality of activities) [Section [0113]) making a third determination, after implementing the second DLP policy, that the third plurality of activities has a higher level of risk; (Levy et al. teaches calculating a second risk score by a threat management facility based on a second event vector for detection of malicious activity [Section [0183]]) and initiating, based on the third determination, implementation of a third DLP policy for the user, wherein initiating implementation of the third DLP policy comprises removing the user's network access. (Levy et al. teaches a threat management facility restricts users’ access to networks, servers and more [Section [0060]])
The combination of Levy et al., Shenefiel et al., and Mandagere et al. do not disclose:
implementation of DLP policies
However, Jaiswal does disclose:
Implementation of DLP policies (Jaiswal teaches a DPL management server that generates and/or modifies DLP policies and then implements the policies to a DLP detection server and/or client device [Section [0038]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Mandagere et al with the teachings of Jaiswal for implementing DLP policies to enhance security for scores in generating an asset risk score.
Dependent claim 20 recites substantially similar subject matter to claim 6 and is therefore rejected for similar reasons as applied to claim 6 above.
As for claim 9, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 3, wherein the asset lineage map specifies historical file system activities linked to the asset. (Levy et al. teaches a ledger containing the history of custody and modifications of files [Section [0142]])
As for claim 10, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 3, further comprising: obtaining, based on the type of the asset, a coefficient for the input feature, wherein the coefficient is fitted from training data for the asset type. (Levy et al. teaches types of potential threats (i.e. asset) suitable for assessing suspiciousness and training set (i.e. coefficient) of known safe and known unsafe threat samples (i.e. input features) for machine learning models [Section [0113]])
As for claim 12, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 3, wherein the sensitivity score is obtained by implementing a multiple linear regression model. (Levy et al. teaches identifying high business value files such as sensitive information by regression valuation models. The valuation model generates a score of business value (i.e. sensitivity score) [Sections [0110], [0111], [0116]])
As for claim 13, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 3, wherein initiating implementation of the first DLP policy for the user based on the user level, the malicious score, the data loss score, and the sensitivity score comprises: mapping the malicious score into the predetermined range to obtain a scaled malicious score; (Levy et al. teaches identifying threats outside a predetermined confidence level (i.e. malicious score) of malicious code [Section [0115]]) mapping the data loss score into the predetermined range to obtain a scaled data loss score; (Levy et al. teaches generating a score for the business value impact (i.e. data loss score) of intermediate threats in estimated dollar value [Section [0116]).
The combination of Levy et al., Mandagere et al. and Jaiswal do not disclose:
mapping the sensitivity score into a predetermined range to obtain a scaled sensitivity score;
predetermined range to obtain a scaled malicious score
generating an asset risk score using the scaled sensitivity score
However, Shenefiel et al. does disclose:
mapping the sensitivity score into a predetermined range to obtain a scaled sensitivity score; (Shenefiel et al. teaches an adjustment to any sensitivity score in a range from a base score [Section [0111])
predetermined range to obtain a scaled malicious score (Shenefiel et al. teaches malware detection metadata accounted via a score multiplier or added to a base score [Section [0111]])
generating an asset risk score using the scaled sensitivity score (Shenefiel et al. teaches a ranged sensitivity score is determined on a file in the file metadata (asset risk score) [Sections [0116], [0111]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Mandagere et al. and Jaiswal with the teachings of Shenefiel et al. for a scaled sensitivity score, scaled malicious score, and an asset risk score to increase scalability efficiency for scoring that generates an asset risk score.
The combination of Levy et al., Shenefiel et al., and Mandagere et al. do not disclose:
and the user level are used to identify the first DLP policy
However, Jaiswal does disclose:
and the user level are used to identify the first DLP policy (Jaiswal teaches at least one DLP action can be performed upon detecting data exfiltration from a client device from a DLP policy defined by an administrator [Section 0078]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., and Mandagere et al. with the teachings of Jaiswal for identifying a DLP policy through a user level to increase security at the user level for threat detection.
As for claim 14, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 3, wherein the plurality of activities comprises a malicious activity and a data loss activity. (Levy et al. teaches malicious activities such as detection of a threat, policy violation, code or activity that might compromise security. Also, Levy et al. teaches data loss activities such as inappropriate use or exfiltration of sensitive information [Sections [0067], [0156]]).
As for claim 15, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 14, wherein the malicious activity is a data exfiltration event that occurred when the user attempted to transfer the asset to an unauthorized removable storage media. (Levy et al. teaches increasing monitoring from terminated employees to protect again data exfiltration to prevent the risk of exposing sensitive information and a configuration policy to disallow the use of USB disks [Sections [0223], [0053]])
As for claim 16, the combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal the method of claim 14, wherein the data loss activity is a data loss event that occurred. (Levy et al. teaches a security management facility providing web security and control for reporting on suspect compute instances where the compute instances are assets within an enterprise network [Sections [0044], [0029]]).
The combination of Levy et al., Mandagere et al. and Jaiswal do not disclose:
when the user attempted to upload the asset to an unauthorized file sharing website
However, Shenefiel et al. does disclose:
when the user attempted to upload the asset to an unauthorized file sharing website (Shenefiel et al. teaches a policy violation of uploading Personal Identifiable Information (PII) to a public folder [Section [0044]])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Mandagere et al. and Jaiswal with the teachings of Shenefiel et al. for a user uploading unauthorized assets on a website to increase efficiency in threat detection in data exfiltration.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal as applied to claim 1-6, and 8-20 above, and further in view of Sadeh-Koniecpol et at. (US 2014/0199664 A1 and hereafter referred as Sadeh-Koniecpol et al.).
As for claim 7, the combination of Levy et al., Shenefiel et al., Mandagere et al., Jaiswal and Sadeh-Koniecpol et al. discloses the method of claim 3, wherein initiating implementation of the first DLP policy comprises enrolling the user in a security awareness training.
The combination of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal do not disclose:
enrolling the user in a security awareness training
However, Sadeh-Koniecpol et al. does disclose:
enrolling the user in a security awareness training (Sadeh-Koniecpol et al. teaches enrolling a user to a more in-depth training if they fail a mock malicious attack)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined invention of Levy et al., Shenefiel et al., Mandagere et al. and Jaiswal with the teachings of Sadeh-Koniecpol et al. for enrolling a user in security awareness training to increase user awareness in threat detection.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Vasudeva (US 20240111870 A1) discloses detecting malware attacks and mitigating data loss.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BASSAM A NOAMAN whose telephone number is (571)272-2705. The examiner can normally be reached Monday-Friday 8:30 AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BASSAM A NOAMAN/Primary Examiner, Art Unit 2497