DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendments
This communication is in response to the amendments filed on 22 July 2026:
Claims 1, 7, 10 and 15 are amended.
Claim 8 is canceled.
Claim 31 is added.
Claims 1-7 and 9-31 are pending.
Response to Arguments
In response to Applicant’s remarks filed on 22 July 2026:
a. Applicant’s arguments that Nagaraja, Moore and/or Chesla are silent with regard to at least the portion of Applicant’s claim 1 that recites: translating at least some raw anonymized sender IP addresses included in the blocked plurality of data packets into known IP addresses of external network providers corresponding to the raw anonymized sender IP addresses; and identifying, based on the known IP addresses of the external network providers, the one or more external service provider networks from which the blocked plurality of data packets were received has been fully considered but is deemed moot in view of the new grounds of rejection presented in this Office Action.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-4, 9-11, 14-15, 19-20, 26 and 31 are rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja et al. (U.S. PGPub. 2021/0185008), hereinafter Nagaraja, in view of Moore et al. (U.S. Patent 11,438,351), hereinafter Moore, in further view of CHESLA (U.S. PGPub. 2017/0063917), hereinafter Chesla, in further view of Barger et al. (U.S. Patent 10,044,736), hereinafter Barger.
Regarding claim 1, Nagaraja teaches A computer-implemented method for mitigating malicious network traffic, the method comprising:
blocking, by one or more computing devices of a service provider network and by utilizing one or more malicious traffic mitigation techniques, a plurality of data packets received by the service provider network (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…application layer 102-c may be configured to analyze and block data that is malicious based on information represented as input in data included in the at least one packets (e.g., data associated with a PAN, an email address, a phone number, a representation of a user’s fingerprint, a user identifier, and/or the like)…”, which is being read as blocking a plurality of data packets received by a service provider network by utilizing one or more malicious traffic mitigation techniques);
Nagaraja does not teach the following limitation(s) as taught by Moore: detecting, by the one or more computing devices, that one or more external service provider networks communicatively connected to the service provider network have been subjected to at least one vector of one or more cyberattacks based on transformations of anonymized sender Internet Protocol (IP) addresses included in the blocked plurality of data packets (Moore, FIG. 5, see “5-6” and “5-7”, where in 5-6, packets are blocked because of its malicious intent, and in 5-7, the computing device detects and reports that one or more external server provider networks have been subjected to at least one vector attack based on determining the IP address sourcing the attack) (Moore, Column 9, Lines 27 – 32, see “…The packet filtering rules may identify packet matching criteria that correspond to the network addresses and/or identifiers, e.g., IP addresses…of cyber threats that may have been identified by cyber threat intelligence providers (CTIPs)…”) (Moore, Column 41, Lines 42 – 52, see “In Step 5-7…another TIG may provide a GTCS 170 with (additional) characteristic information on the attack, which may include, for example, the key (e.g., The IP address…of the host(s) sourcing the attack), the type of attack…the start time of the attack…the network being attacked…the attack identifier…and/or the like”); and
generating an alert indicating that the one or more external service provider networks have been subjected to the at least one vector of the one or morecyberattacks (Moore, FIG. 5, see “5-8”, which publishes the active attack information to subscribers, indicating that one or more external service provider networks have been subjected to at least one vector attack).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, by implementing techniques of detecting and generating an alert that a network has been subjected to a cyberattack based on an IP address, disclosed of Moore.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of detecting and generating an alert that a network has been subjected to a cyberattack based on an IP address. This allows for better security management by allowing security teams to immediately isolate compromised devices and block attackers at the perimeter based on the identified IP address. Moore is deemed as analogous art due to the art disclosing techniques of detecting and generating an alert that a network has been subjected to a cyberattack based on an IP address (Moore, FIG. 5).
Nagaraja as modified by Moore do not teach the following limitation(s) as taught by Chesla: one or more multi-vector cyberattacks (Chesla, Claim 10, see “…wherein the cyber-attack is a multi-vector attack and each node in the at least one risk-chain is a stage in the cyber-attack”).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, and techniques disclosed of Moore, by implementing techniques of detecting one or more multi-vector cyberattacks, disclosed of Chesla.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of detecting one or more multi-vector cyberattacks. This allows for better security management of a very common and standard tactic for malicious actors to infiltrate systems. Chesla is deemed as analogous art due to the art disclosing techniques of detecting one or more multi-vector cyberattacks (Chesla, Claim 10).
Nagaraja as modified by Moore and further modified by Chesla do not teach the following limitation(s) as taught by Barger: wherein the detecting comprises:
translating at least some raw anonymized sender IP addresses included in the blocked plurality of data packets into known IP addresses of external network providers corresponding to the raw anonymized sender IP addresses (Barger, Column 12, Lines 47 – 51, see “…some examples include network saturation and subsequent latency or the C2 IP address being blocked, forcing the operator of the malicious software campaign to transition to a different C2 IP address to require access to the victim compute device”, which is analogous to utilizing the IP address of the sender included in the blocked plurality of data packets to remedy the malicious behavior by tracking domain name resolutions of the malicious host over time) (Barger, Column 14, Lines 24 – 48, see “…The DNS sensor 202 can collect information that translates (maps, associates) the malicious domain name to an IP address or an IP address to a domain name…the malicious software campaign can dynamically change the infrastructure that hosts the malicious domain name, and thus, the IP address associated with the infrastructure changes over time…the DNS sensor 202 can collect domain name resolution information associated with a malicious domain, such as different IP addresses to which a specific malicious domain resolves over time…the server provider reputation based on prior domain name resolutions, a number of DNS resolutions for that specific location over a period of time, and/or services used by the host…DNS sensor 202 can also collect and/or receive additional contextual information…”, which is analogous to translating at least some anonymized (e.g., due to the IP addresses associated with the infrastructure changing over time) sender IP addresses included in the blocked plurality of data packets into known IP addresses of external network providers corresponding to the malicious anonymized sender IP address); and
identifying, based on the known IP addresses of the external network providers, the one or more external service provider networks from which the blocked plurality of data packets were received (Barger, Column 9, Lines 13 – 21, see “…The malicious infrastructure classification device 101 can subsequently send a signal based on the role of the adversary infrastructure at the first geographic location and/or the role of the adversary infrastructure at the second geographic location such that a remedy response associated with at least one of the set of IP addresses or the malicious domain is initiated…”, which is analogous to identifying based on the known IP addresses, the one or more external service provider networks from which the blocked (malicious) plurality of data packets were received).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, and techniques disclosed of Chesla, by implementing techniques of translating anonymized sender IP addresses included in a blocked plurality of data packets into known IP addresses corresponding to malicious IP addresses, disclosed of Barger.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of translating anonymized sender IP addresses included in a blocked plurality of data packets into known IP addresses corresponding to malicious IP addresses. This allows for better security management and threat intelligence by identifying the attacker and their campaign through translation of the attackers IP addresses and corresponding contextual information. Barger is deemed as analogous art due to the art disclosing techniques of translating anonymized sender IP addresses included in a blocked plurality of data packets into known IP addresses corresponding to malicious IP addresses (Barger, Column 14, Lines 24 – 48).
Regarding claim 2, Nagaraja as modified by Moore and further modified by Chesla and Barger teaches The computer-implemented method of claim 1, wherein:
the blocking includes blocking, at each layer of a plurality of layers via which network traffic is communicated via the service provider network and by utilizing a respective malicious traffic mitigation technique associated with the each layer, a respective portion of the plurality of data packets (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…application layer 102-c may be configured to analyze and block data that is malicious based on information represented as input in data included in the at least one packets (e.g., data associated with a PAN, an email address, a phone number, a representation of a user’s fingerprint, a user identifier, and/or the like)…”, which is being read as blocking a respective portion of a plurality of data packets of the network traffic at each layer of a plurality of layers (OSI model) by utilizing a respective malicious traffic mitigation technique); and
the method further includes causing, by the one or more computing devices and based on respective destination addresses of other data packets received from the one or more external service provider networks, the other data packets to be sent to respective IP destination addresses serviced by the service provider network (Nagaraja, Paragraph [0005], see “…in response to determining that the first probability indicating that the at least one packet is in the first class if greater than the second probability indicating that the at least one packet is in the second class, the at least one processor is programmed or configured to block the at least one packet; and wherein, in response to determining that the first probability indicating that the at least one packet is in the first class is less than the second probability…the at least one processor is programmed or configured to permit the at least one packet to be transmitted to be forwarded”, which is being read as causing the other data packets to be sent to respective IP destination addresses if the packet does not need to be blocked for malicious data).
Regarding claim 3, Nagaraja as modified by Moore and further modified by Chesla and Barger teaches The computer-implemented method of claim 2, wherein the blocking, at the each layer of the plurality of layers, of the respective portion of the plurality of data packets includes at least one of:
utilizing a different malicious traffic mitigation technique for each layer of at least two layers of the plurality of layers;
blocking at the each layer of the plurality of layers sequentially ;
determining the respective portion of the plurality of data packets by utilizing a different data filter associated with the each layer of the plurality of layers;
blocking at each layer of three or more layers (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…”, where the blocking at each layer is achieved at each layer of three or more layers (e.g., malicious at layers three through seven)).;
blocking at each layer of a plurality of Open Systems Interconnection (OSI) layers (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…”).; or
blocking the respective portion of the plurality of data packets based on at least two of: a prohibited source address, a communication request threshold, a data or information rate threshold, an access control list, a packet size threshold, a restricted content type, a prohibited protocol, or a prohibited port number
Regarding claim 4, Nagaraja as modified by Moore and further modified by Chesla and Barger teaches The computer-implemented method of claim 2, wherein the utilizing of the respective malicious traffic mitigation technique associated with the each layer includes at least one of:
utilizing a particular malicious traffic mitigation technique at a first layer of the plurality of layers and utilizing the particular malicious traffic mitigation technique at a second layer of the plurality of layers (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…”, where “first firewall” and “second firewall” are being read as utilizing a particular malicious traffic mitigation technique (traffic control and/or metric monitoring) at a first layer (layers three and/or four) and at a second layer (layers three through seven) of the plurality of layers).;
utilizing both a first malicious traffic mitigation technique and a second malicious traffic mitigation technique at a particular layer of the plurality of layers; or
utilizing at least two of: ingress filtering, source-based rate limiting, access control, network rate limiting, deep pack analysis, traffic control, or metric monitoring
Regarding claim 9, Nagaraja as further modified by Chesla and Barger do not teach the following limitation(s) as taught by Moore: The computer-implemented method of claim 1, wherein the detecting includes detecting that the one or more external service provider networks host the anonymized IP sender addresses of the blocked plurality of data packets (Moore, Column 41, Lines 42 – 52, see “…the TIG 120, for example TIG120a, may provide a GTCS 170 with characteristic information on the attack, which may include…the key (e.g., the IP address 22.22.22.22 or subnet address range 22.22.22.00/24 of the host(s) sourcing the attack)…the type of attack…the network being attacked (e.g., identified by the subnet address prefix 11.11.11.00/24 of network 102)…and/or the like…”, which is analogous to detecting that one or more service provider networks host the IP sender address that is blocked or flagged as malicious).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of detecting that the one or more networks host the IP address of the blocked/malicious packets, disclosed of Moore.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of detecting that the one or more networks host the IP address of the blocked/malicious packets. This allows for better security management by allowing organizations to instantly identify attack sources, quarantine compromised internal devices and automate defenses. Moore is deemed as analogous art due to the art disclosing techniques of detecting that the one or more networks host the IP address of the blocked/malicious packets (Moore, Column 41, Lines 42 – 52).
Regarding claim 10, Nagaraja as modified by Moore and further modified by Chesla do not teach the following limitation(s) as taught by Barger: The computer-implemented method of claim 1, wherein determining that the one or more external service provider networks have been subjected to the at least one vector of the one or more multi-vector cyberattacks is further based on at least one of types of the blocking or locations within the service provider network at which at least some of the plurality of data packets were blocked (Barger, Column 14, Lines 24 – 42, see “…The DNS sensor 202 can collect information that translates (maps, associates) the malicious domain name to an IP address or an IP address to a domain name…the DNS sensor 202 can collect domain name resolution information associated with a malicious domain…the geographic location associated with each IP address to which the malicious domain resolves…”, which is analogous to determining the one or more external service provider networks that have been subjected to the cyberattack based on locations within the service provider network at which the malicious data packets were received and flagged as malicious).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, and techniques disclosed of Chesla, by implementing techniques of determining that the one or more networks that have been subjected to the cyberattack is based on locations within the network at which some of the plurality of data packets were flagged as malicious, disclosed of Barger.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of determining that the one or more networks that have been subjected to the cyberattack is based on locations within the network at which some of the plurality of data packets were flagged as malicious. This allows for better security management and resource optimization by identifying a geolocation associated with the malicious IP address in order to isolate the threat quickly by blocking the network segments in the vicinity of the geolocation. Barger is deemed as analogous art due to the art disclosing techniques of determining that the one or more networks that have been subjected to the cyberattack is based on locations within the network at which some of the plurality of data packets were flagged as malicious (Barger, Column 14, Lines 24 – 42).
Regarding claim 11, Nagaraja as further modified by Chesla and Barger do not teach the following limitation(s) as taught by Moore: The computer-implemented method of claim 1, wherein the detecting includes detecting that a particular external service provider network of the one or more external service provider networks hosts more than one anonymized IP sender address of the blocked plurality of data packets (Moore, Column 41, Lines 42 – 52, see “…the TIG 120, for example TIG120a, may provide a GTCS 170 with characteristic information on the attack, which may include…the key (e.g., the IP address 22.22.22.22 or subnet address range 22.22.22.00/24 of the host(s) sourcing the attack)…the type of attack…the network being attacked (e.g., identified by the subnet address prefix 11.11.11.00/24 of network 102)…and/or the like…”, which is analogous to detecting that one or more service provider networks hosts more than one IP sender address (i.e., subnet address range of the host(s) sourcing the attack) that are blocked or flagged as malicious).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of detecting that the one or more networks host the IP addresses of the blocked/malicious packets, disclosed of Moore.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of detecting that the one or more networks host the IP addresses of the blocked/malicious packets. This allows for better security management by allowing organizations to instantly identify attack sources, quarantine compromised internal devices and automate defenses. Moore is deemed as analogous art due to the art disclosing techniques of detecting that the one or more networks host the IP address of the blocked/malicious packets (Moore, Column 41, Lines 42 – 52).
Regarding claim 14, Nagaraja as further modified by Chesla and Barger do not teach the following limitation(s) as taught by Moore: The computer-implemented method of claim 1, wherein the generating of the alert includes transmitting the alert to respective computing devices associated with the one or more external service provider networks (Moore, FIG. 5, see “5-8”, which generates the alert and transmits the alert to respective computer devices (subscribers)).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of transmitting an alert to respective computing devices associated with the one or more networks compromised, disclosed of Moore.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of transmitting an alert to respective computing devices associated with the one or more networks compromised. This allows for better security management by alerting respective computing devices associated with the one or more compromised networks in order to enable rapid response to contain breaches. Moore is deemed as analogous art due to the art disclosing techniques of transmitting an alert to respective computing devices associated with the one or more networks compromised (Moore, FIG. 5).
Regarding claims 15 and 31, the claims are rejected under the same reasoning as claim 1.
Regarding claim 19, the claim is rejected under the same reasoning as claim 9.
Regarding claim 20, the claim is rejected under the same reasoning as claim 11.
Regarding claim 26, the claim is rejected under the same reasoning as claim 2.
Claims 5 and 27-28 are rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Lim (U.S. PGPub. 2016/0277436).
Regarding claim 5, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Lim: The computer-implemented method of claim 2, wherein the blocking of the respective portion of the plurality of data packets includes at least one of:
sending a control message to a network routing device of the service provider network via which the plurality of data packets was received;
sending data rate limiting instructions to a first one or more network devices of the service provider network;
sending an access control list to a second one or more network devices of the service provide network; or
sending instructions to a third one or more network devices of the service provider network to block packets based on at least one of: a prohibited source address, a communication request threshold, a data or information rate threshold, a packet size threshold, a restricted content type, a prohibited protocol, or a prohibited port number (Lim, Paragraph [0044], see “…receive the instructions and add the IP address of the source that initiated the information security attack to an access control list of gateway 118 thereby effectively blocking all data transmissions from the source of the attack to network 100”, which is analogous to sending instructions to a network device to block packets based on at least a prohibited source address (IP address of the source that initiated the information security attack)).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of sending instructions to a network device to block packets based on a prohibited source address, disclosed of Lim.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of sending instructions to a network device to block packets based on a prohibited source address. This allows for better security management by filtering and/or blacklisting a known prohibited source address from sending further messages. Lim is deemed as analogous art due to the art disclosing techniques of sending instructions to a network device to block packets based on a prohibited source address (Lim, Paragraph [0044]).
Regarding claim 27, Nagaraja as modified by Moore and further modified by Chesla and Barger teaches The system of claim 26, wherein at least one of: the plurality of layers includes three or more layers, or the plurality of layers is a plurality of Open Systems Interconnection (OSI) layers (Nagaraja, Paragraph [0059], see “…first firewall 102-a may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three and/or four of the open systems interconnection (OSI) model…second firewall 102-b may be configured to analyze and block data (e.g., at least one messages, packets, and/or the like) that are malicious at layers three through seven of the OSI model…”);
Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Lim: the blocking, at the each layer of the plurality of layers, of the respective portion of the plurality of data packets includes at least one of:
a utilization of a different malicious traffic mitigation technique for each layer of at least two layers of the plurality of layers;
a sequential, layer-based blocking of the plurality of layers;
a utilization of a different data filter associated with the each layer of the plurality of layers to determine the respective portion of the plurality of data packets; or
a blocking of the respective portion of the plurality of data packets based on at least two of: a prohibited source address, a communication request threshold, a data or information rate threshold, an access control list, a packet size threshold, a restricted content type, a prohibited protocol, or a prohibited port number (Lim, Paragraph [0044], see “…receive the instructions and add the IP address of the source that initiated the information security attack to an access control list of gateway 118 thereby effectively blocking all data transmissions from the source of the attack to network 100”, which is being read as the blocking the plurality of data packets being based at least on two including a prohibited source address and an access control list).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of blocking the respective portion of the plurality of data packets based on a prohibited source address and an access control list, disclosed of Lim.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of blocking the respective portion of the plurality of data packets based on a prohibited source address and an access control list. This allows for better security management by tracking and blocking respective data packets based on a prohibited source address and an access control list, which improves network performance by filtering out unnecessary or malicious traffic and protecting against DDoS and spoofing. Lim is deemed as analogous art due to the art disclosing techniques of blocking the respective portion of the plurality of data packets based on a prohibited source address and an access control list (Lim, Paragraph [0044]).
Regarding claim 28, the claim is rejected under the same reasoning as claim 5.
Claims 6-7 and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Baker (U.S. PGPub. 2015/0156213), in further view of Steele et al. (U.S. PGPub. 2020/0120129), hereinafter Steele.
Regarding claim 6, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Baker: The computer-implemented method of claim 1, further comprising:
sorting, by the one or more computing devices, the anonymized IP sender addresses based on a measure corresponding to a respective number of cyberattacks associated with each anonymized IP sender address (Baker, Paragraph [0248], see “…It defines that the datatype is source to identify all attacks. A start time stand and an end time stamp is provided, with a time range. This request returns all Source IP addresses grouped by the number of attacks made…”, where the IP sender addresses are sorted based on a measure corresponding to a respective number of cyberattacks associated with each source IP address (i.e., number of attacks made));
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of sorting the IP addresses based on a respective number of cyberattacks associated with each IP address, disclosed of Baker.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of sorting the IP addresses based on a respective number of cyberattacks associated with each IP address. This allows for better security management by enabling rapid, risk-based prioritization for security mitigation, whilst improving threat detection and reducing false positives. Baker is deemed as analogous art due to the art disclosing techniques of sorting the IP addresses based on a respective number of cyberattacks associated with each IP address (Baker, Paragraph [0248]).
Nagaraja as modified by Moore and further modified by Chesla, Barger and Baker do not teach the following limitation(s) as taught by Steele: the detecting of the one or more external service provider networks includes identifying each of the one or more external service provider networks based on a threshold corresponding to the measure (Steele, Paragraph [0032], see “…Once an aggregate threat level of the security breach crosses a certain threshold, the system may generate an alert containing the security threat levels for each service and send the alert to the user”).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, techniques disclosed of Barger and techniques disclosed of Baker, by implementing techniques of identifying each network that has experienced a cyberattack based on a threshold corresponding to a measurement, disclosed of Steele.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of identifying each network that has experienced a cyberattack based on a threshold corresponding to a measurement. This allows for proactive, automated and precise security management by transforming chaotic security monitoring into a structured, risk-based operation. Steele is deemed as analogous art due to the art disclosing techniques of identifying each network that has experienced a cyberattack based on a threshold corresponding to a measurement (Steele, Paragraph [0032]).
Regarding claim 7, Nagaraja as modified by Moore and further modified by Chesla, Barger and Steele do not teach the following limitation(s) as taught by Baker: The computer-implemented method of claim 6, wherein the measure is indicative of at least one of a raw number of cyberattack hits or a bandwidth degradation (Baker, Paragraph [0248], see “…It defines that the datatype is source to identify all attacks. A start time stand and an end time stamp is provided, with a time range. This request returns all Source IP addresses grouped by the number of attacks made…”, where “number of attacks made” is analogous to the measure being indicative of a raw number of cyberattack hits).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, techniques disclosed of Barger and techniques disclosed of Steele, by implementing techniques of the measurement indicating a raw number of cyberattack hits, disclosed of Baker.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of the measurement indicating a raw number of cyberattack hits. This allows for better security management by allowing organizations to track trends over time, justify security investments and assess the volume of threats blocked. Baker is deemed as analogous art due to the art disclosing techniques of the measurement indicating a raw number of cyberattack hits (Baker, Paragraph [0248]).
Regarding claim 16, the claim is rejected under the same reasoning as claim 6.
Regarding claim 17, the claim is rejected under the same reasoning as claim 7.
Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Baker, in further view of Steele, in further view of Ginter et al. (U.S. PGPub. 2009/0271504), hereinafter Ginter.
Regarding claim 18, Nagaraja as modified by Moore and further modified by Chesla, Barger, Baker and Steele do not teach the following limitation(s) as taught by Ginter: The system of claim 16, wherein the measure is indicative of a bandwidth degradation (Ginter, Paragraph [0211], see “…the agents described herein are designed to transmit small fixed-size messages at fixed intervals, thus consuming a bounded portion of available communication resources, even under denial-of-service attack conditions…The reports may include…network bandwidth utilization…”, where “network bandwidth utilization” is analogous to indicating an amount of potential bandwidth degradation based on the report).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, techniques disclosed of Barger, techniques disclosed of Baker, and techniques disclosed of Steele, by implementing techniques of the measurement indicating a bandwidth degradation, disclosed of Ginter.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of the measurement indicating a bandwidth degradation. This allows for better security management by offering critical insights for maintaining network performance and indicating whether a denial-of-service attack might be active. Ginter is deemed as analogous art due to the art disclosing techniques of the measurement indicating a bandwidth degradation (Ginter, Paragraph [0211]).
Claims 12 and 21-22 are rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of BOBAK et al. (U.S. PGPub. 2022/0385678), hereinafter Bobak.
Regarding claim 12, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Bobak: The computer-implemented method of claim 1, further comprising detecting, based on the transformations of the anonymized IP sender addresses, that a particular infrastructure element of a particular external service provider network has been subjected to the at least one cyberattack vector, and wherein the alert is indicative of the particular infrastructure element (Bobak, FIG. 2, see “240”, which detects that a particular infrastructure element has been subjected to at least one cyberattack and see “250”, which generates a warning about a potential cyberattack on the particular infrastructure element).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of detecting that a particular infrastructure element of a network has been cyber attacked and generating an alert for it, disclosed of Bobak.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of detecting that a particular infrastructure element of a network has been cyber attacked and generating an alert for it. This allows for better security management by enabling rapid containment, minimizing downtime and reducing data loss. Bobak is deemed as analogous art due to the art disclosing techniques of detecting that a particular infrastructure element of a network has been cyber attacked and generating an alert for it (Bobak, FIG. 2).
Regarding claim 21, the claim is rejected under the same reasoning as claim 12.
Regarding claim 22, the claim is rejected under the same reasoning as claim 12. Also, Applicant’s attention is further directed to Bobak, FIG. 3A, which depicts multiple different infrastructure elements associated with at least two different external service provider networks and Paragraph [0122], see “…The infrastructure detection module is configured to search for and identify infrastructure elements (also referred to herein as “checkpoints”) of the network infrastructure 180 defining a cyberattack surface of the network infrastructure…”, which is analogous to identifying cyberattacks on multiple different network infrastructure elements).
Claims 13 and 25 are rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Ginter.
Regarding claim 13, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Ginter: The computer-implemented method of claim 1, wherein the alert is indicative of at least one of: a respective count of cyberattacks to which each external service provider network has been subjected, or a respective amount of bandwidth loss caused by the cyberattacks to which the each external service provider network has been subjected (Ginter, Paragraph [0211], see “…the agents described herein are designed to transmit small fixed-size messages at fixed intervals, thus consuming a bounded portion of available communication resources, even under denial-of-service attack conditions…The reports may include…network bandwidth utilization…”, where “The reports may include…network bandwidth utilization” is analogous to comprising an alert indicating an amount of potential bandwidth loss caused by the cyberattacks (denial of service attack) based on the report).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of the measurement indicating a bandwidth degradation, disclosed of Ginter.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of the measurement indicating a bandwidth degradation. This allows for better security management by offering critical insights for maintaining network performance and indicating whether a denial-of-service attack might be active. Ginter is deemed as analogous art due to the art disclosing techniques of the measurement indicating a bandwidth degradation (Ginter, Paragraph [0211]).
Regarding claim 25, the claim is rejected under the same reasoning as claim 13.
Claim 23 is rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Coleman et al. (U.S. Patent 10,027,705), hereinafter Coleman.
Regarding claim 23, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Coleman: The system of claim 15, wherein the anonymized IP sender addresses exclude any collaboration IP addresses associated with multiple external service provider networks (Coleman, FIG. 4B, see “421”, which receives an indicator of a risk (threat), see “430”, which determines whether the IP address is on an exclusion list, and if it is, it ignores the active threat, which is analogous to excluding any IP addresses associated with multiple networks).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of excluding any shared IP addresses associated with multiple networks, disclosed of Coleman.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of excluding any shared IP addresses associated with multiple networks. This allows for better security management by allowing administrators to add specific IP addresses to an exclusion list, preventing them from being processed as anonymous traffic to help distinguish between legitimate corporate traffic (collaboration). Coleman is deemed as analogous art due to the art disclosing techniques of excluding any shared IP addresses associated with multiple networks (Coleman, FIG. 4B).
Claim 24 is rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Baker.
Regarding claim 24, the claim is rejected under the same reasoning as claim 7.
Claim 29 is rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of Matityahu et al. (U.S. PGPub. 2011/0211473), hereinafter Matit.
Regarding claim 29, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Matit: The system of claim 15, wherein the one or more malicious traffic mitigation techniques include at least one of: ingress filtering, source-based rate limiting, access control, network rate limiting, deep packet analysis, traffic control, or metric monitoring (Matityahu, Paragraph [0035], see “…filtering component 220 may be configured to perform at least one of ingress filtering, egress filtering and/or deep pack inspection (DPI)”).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of utilizing ingress filtering and deep pack analysis for the respective malicious traffic mitigation techniques, disclosed of Matityahu.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of utilizing ingress filtering and deep pack analysis for the respective malicious traffic mitigation techniques. This allows for better security management by utilizing ingress filtering and deep pack analysis to prevent IP spoofing, mitigating DoS attacks and enhancing traffic traceability. Matityahu is deemed as analogous art due to the art disclosing techniques of utilizing ingress filtering and deep pack analysis for the respective malicious traffic mitigation techniques (Matityahu, Paragraph [0035]).
Claim 30 is rejected under 35 U.S.C. 103 as being unpatentable over Nagaraja, in view of Moore, in further view of Chesla, in further view of Barger, in further view of BE’ERY et al. (U.S. PGPub. 2019/0349395), hereinafter Be’ery.
Regarding claim 30, Nagaraja as modified by Moore and further modified by Chesla and Barger do not teach the following limitation(s) as taught by Be’ery: The system of claim 15, wherein the one or more multi-vector cyberattacks include one or more of: a volumetric attack, a protocol attack, an exhaustion attack, an application layer-attack, or a multi-vector attack (Be’ery, Paragraph [0004], see “…Some volumetric DoS attacks create problems outside the LAN of the target device that the target may not even be aware of…A few types of volumetric attacks include Internet Control Message Protocol (ICMP) floods, User Datagram Protocol (UDP) floods, and Transmission Control Protocol (TCP) state exhaustion attacks such as TCP SYN floods and idle session attacks”, where the network traffic includes malicious network traffic corresponding to at least two of a volumetric attack, a protocol attack and/or an exhaustion attack).
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Nagaraja, techniques disclosed of Moore, techniques disclosed of Chesla, and techniques disclosed of Barger, by implementing techniques of the network traffic including malicious network traffic corresponding to a volumetric attack, a protocol attack and/or an exhaustion attack, disclosed of Be’ery.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for mitigating malicious network traffic, comprising of the network traffic including malicious network traffic corresponding to a volumetric attack, a protocol attack and/or an exhaustion attack. This allows for better security management by mitigating malicious network traffic that comprises volumetric and exhaustion attacks, due to these attacks being common and types of attacks that overwhelm a network with an enormous flood of malicious traffic. Be’ery is deemed as analogous art due to the art disclosing techniques of the network traffic including malicious network traffic corresponding to a volumetric attack, a protocol attack and/or an exhaustion attack (Be’ery, Paragraph [0004]).
Conclusion
Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office Action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499