Prosecution Insights
Last updated: August 06, 2026
Application No. 17/364,032

AUTOMATED SECURITY ASSESSMENT OF BUSINESS-CRITICAL SYSTEMS AND APPLICATIONS

Non-Final OA §103
Filed
Jun 30, 2021
Priority
Jul 01, 2010 — provisional 61/360,610 +5 more
Examiner
TO, BAOTRAN N
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Onapsis S R L
OA Round
5 (Non-Final)
86%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
574 granted / 667 resolved
+28.1% vs TC avg
Moderate +12% lift
Without
With
+12.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
16 currently pending
Career history
675
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
38.6%
-1.4% vs TC avg
§102
15.9%
-24.1% vs TC avg
§112
12.7%
-27.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 667 resolved cases

Office Action

§103
DETAILED ACTION This Office action is responsive to the Amendment filed on 05/21/2026. Claim 9 has been canceled. Claim 1 has been amended. Claim 24 has been newly added. Claims 12-23 have been withdrawn. Claims 1-8, 10-11, and 24 are presented for examination. Claim Rejections - 35 USC § 103 The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action: (a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-8, 10-11, and 24 are rejected under pre-AIA 35 U.S.C. 103(a) as being unpatentable over Gaa-Frost et al. (US Patent Application Publication No. 2007/0157195 A1) listed in IDS dated 06/31/2021 hereinafter Gaa-Frost in view of Magdych et al. (US Patent No. 7,096,503 B1) hereinafter Magdych and further in view of Hooks et al. (US Patent Application Publication No. 2011/0247071 A1) hereinafter Hooks. Regarding claim 1, Gaa-Frost discloses a method for risk assessment comprising: identifying a target system (fig. 2, system 201) storing a software system (para 0021, The method 100 receives, at 101, configuration parameters characterizing an intended deployment of software and further characterizing a target computing system from which the software is to be deployed); determining a plurality of parameters for the software system of the target system (para 0053, when a specific intended software deployment is specified, the Project Check may analyze system parameters specifically for that deployment); selecting at least one of a testing or probing module for the target system based on the plurality of parameters (para 0041, the software provider 204 may have required the system administrator to run a tool to initially assess deployment risk associated with installing the ERP software 216 in the computing system 201. The tool may have implemented the method 100. For example, a configuration monitor 240 in the computing system may have automatically collected various configuration parameters associated with the computing system 201. The configuration monitor may have transmitted the various configuration parameters to a deployment risk calculator 248 in the second computing system 204 and para 0052, The Project Check UI also provides a control 407 that the user can select to initiate the Project Check. As shown, initiation of the "Automatic Data Collection" with the control 407 will cause the underlying system to collect various system information for use in the Project Check. As was described with reference to FIG. 1A, this information may include various hardware, software and operating system parameters that the Project Check may analyze in assessing initial deployment risk); measuring, using the selected module, the plurality of parameters on a target system on a cloud server (Fig. 2, element 207) (para 0052, The Project Check UI also provides a control 407 that the user can select to initiate the Project Check. As shown, initiation of the "Automatic Data Collection" with the control 407 will cause the underlying system to collect various system information for use in the Project Check. As was described with reference to FIG. 1A, this information may include various hardware, software and operating system parameters that the Project Check may analyze in assessing initial deployment risk, and para 0045, The threshold deployment risk level may have been determined based on data (para 0025 and 0052, configuration parameters) the service provider had previously collected, analyzed and stored (e.g., in the database 255)); storing the measured parameters in a database (para 0045, The threshold deployment risk level may have been determined based on data (para 0025 and 0052, parameters) the service provider had previously collected, analyzed and stored (e.g., in the database 255)), receiving data regarding the target system from the cloud server (para 0021, The method 100 receives, at 101, configuration parameters characterizing an intended deployment of software and further characterizing a target computing system from which the software is to be deployed and para 0034, If the calculated deployment risk level is higher than or equal to a threshold deployment risk level, the method 150 may continue receiving configuration input, at 154, and may continue configuring the enterprise software, at 152. At a later time, data characterizing the configuration state of the enterprise software may again be received, at 160, and the received data may be transmitted, at 163, to the second computing system for recalculation of the deployment risk and comparison, at 166, with the threshold risk level); comparing the measured parameters with the received data (para 0045, The calculated deployment risk level may have been compared to a threshold deployment risk level and para 0034, At a later time, data characterizing the configuration state of the enterprise software may again be received, at 160, and the received data may be transmitted, at 163, to the second computing system for recalculation of the deployment risk and comparison, at 166, with the threshold risk level); and identifying, based on the comparing, a defect as part of the risk assessment (para 0056, the Project Check may identify a faulty piece of hardware (e.g., a network router or a server memory card) that should be replaced prior to beginning to deploy new software. The Project Check may withhold the project key until it confirms that the faulty piece of hardware has been replaced), but does not explicitly disclose, however, Magdych discloses where the at least one testing or probing module is selected from a plurality of modules (claim 4, the risk-assessment modules are selected from the group and col. 4, lines 26-28, unique set of risk-assessment modules 404 may be selected based on specifications, platform, etc. of the particular local computer 212), that each is configured to evaluate a different information security risk affecting the software system, (col. 4, lines 15-25, these risk-assessment modules 404 refer to different functions that work in conjunction to perform a risk-assessment scan. In use, such risk-assessment modules 404 are capable of performing a specific function upon being executed by a command. Moreover, the risk-assessment modules 404 serve to perform a specific function on parameters that are specified by the command). Therefore, it would have been obvious to a person having ordinary skill in the art to modify the teachings of Gaa-Frost to include each is configured to evaluate a different information security risk affecting the software system as taught by Magdych in order to detect vulnerabilities on a local computer (Magdych, abstract), but does not explicitly disclose, however, Hooks discloses where the parameters comprise settings or snapshots of a state of the software of the software system (fig. 2-4, abstract, para 0072-0075). Accordingly, it would have been obvious to a person having ordinary skill in the art to modify the teachings of Gaa-Frost to include the parameters comprise settings or snapshots of a state of the software of the software system as taught by Hooks in order to detect malware in a selected computer (Hooks, abstract). Regarding claim 2, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, wherein the risk assessment is performed on at least one central server different from the cloud server storing the target system (Gaa-Frost fig. 2, element 204, para 0038-0039). Regarding claim 3, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, wherein the module performing the measuring comprising a measurement input interface including a test input interface for receiving the data (Gaa-Frost para 0052-0054). Regarding claim 4, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 3, wherein the data comprises test data from the test input interface (Gaa-Frost para 0052-0054). Regarding claim 5, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, further comprising: generating correction instructions for correcting the parameters when the defect is identified (Gaa-Frost para 0028 and 0056). Regarding claim 6, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, wherein the defect comprises a software risk in software of the target system (Gaa-Frost para 0056). Regarding claim 7, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 6, wherein the software of the target system comprises at least one of Customer Relationship Management (CRM), Supplier Relationship Management (SRM), Supply Chain Management (SCM), Product Life-cycle Management (PLM), HumanCapital Management (HCM), Integration Platforms, Business Warehouse (BW), Business Intelligence (BI), or enterprise resource planning (ERP) (Gaa-Frost para 0038). Regarding claim 8, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 7, wherein the software comprises at least one of SAP software, Oracle software, Microsoft software, Siebel software, JD Edwards software, Salesforce, Workday, or PeopleSoft software (Gaa-Frost para 0033 and 0053). Regarding claim 10, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, wherein the comparing and the identifying is performed on a second cloud server different from the cloud server (Gaa-Frost fig. 2, element 231, para 0062). Regarding claim 11, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, wherein the comparing and the identifying is performed on-premises (Gaa-Frost para 0053 and 0056). Regarding claim 24, the combination of Gaa-Frost, Magdych, and Hooks discloses the method of claim 1, further comprising: identifying a second target system storing a second software system (Gaa-Frost para 0021); determining second parameters for the second software system of the identified second target system (Gaa-Frost para 0053); selecting at least one testing or probing module for the identified second target system based on the determined second parameters (Gaa-Frost para 0041); receiving, at the cloud server, second data from an execution of the selected at least one testing or probing module for the identified second target system (Hooks, fig. 2-4, para 0072-0075); and analyzing, at the cloud server, the received second data for the risk assessment of the second software system (Hooks, fig. 2-4, para 0072-0075). Response to Arguments Applicant’s arguments (regarding amended limitation “where the parameters comprise settings or snapshots of a state of the software of the software system” as recited in independent claim 1) with respect to claims 1-8, 10-11, and 24 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-892). Any inquiry concerning this communication or earlier communications from the examiner should be directed to BAOTRAN N TO whose telephone number is (571)272-8156. The examiner can normally be reached M-F: 8-5. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached on 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BAOTRAN N TO/ Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Show 4 earlier events
May 19, 2025
Request for Continued Examination
May 25, 2025
Response after Non-Final Action
Jun 02, 2025
Non-Final Rejection mailed — §103
Aug 27, 2025
Response Filed
Nov 25, 2025
Final Rejection mailed — §103
May 21, 2026
Request for Continued Examination
Jun 01, 2026
Response after Non-Final Action
Jun 29, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12700995
MULTI-USER QUANTUM KEY DISTRIBUTION APPARATUS
2y 9m to grant Granted Aug 04, 2026
Patent 12683693
AN OPTICAL TRANSMITTER, A QUANTUM COMMUNICATION SYSTEM AND A METHOD OF OPERATING AN OPTICAL TRANSMITTER
2y 5m to grant Granted Jul 14, 2026
Patent 12676865
PLATFORM ACCESS REQUEST MANAGEMENT
2y 2m to grant Granted Jul 07, 2026
Patent 12664323
TAMPER DETECTOR BASED ON POWER NETWORK ELECTRICAL CHARACTERISTIC
2y 7m to grant Granted Jun 23, 2026
Patent 12659142
INFORMATION PROCESSING DEVICE, QUANTUM CRYPTOGRAPHIC COMMUNICATION SYSTEM, KEY MANAGEMENT DEVICE, INFORMATION PROCESSING METHOD, AND COMPUTER PROGRAM PRODUCT
1y 11m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
86%
Grant Probability
98%
With Interview (+12.4%)
2y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 667 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month