DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
This is a final office action in response to the amendment filed 06 July 2026. Claims 1 and 11 have been amended. Claims 1-20 remain pending and have been examined.
Response to Amendment
Applicant’s amendment to claims 1 and 11 has been entered.
Applicant’s amendment is sufficient to overcome the claim objection. The claim objection is respectfully withdrawn.
Applicant’s amendment is insufficient to overcome the pending 35 U.S.C. 101 rejection. The rejection remains pending.
Response to Arguments
Applicant’s arguments regarding the 35 U.S.C. 101 rejection have been fully considered, but are not persuasive. Applicant asserts that Examiner’s characterization of the claimed invention improperly oversimplifies the claims and fails to account for the recited specific technical requirements that comprise multiple interoperating modules that perform automated cyber-attack modeling and targeted training simulations that is not an abstract concept and cannot practically be performed in the human mind or with pencil and paper because “a human mind cannot practically generate graphs from multi-domain network data , conduct analytics across potentially thousands of network nodes, model cyber-attacks using a simulator, and direct simulations to targeted user groups based on common susceptibility patterns.” Examiner respectfully disagrees.
The Specification at paragraph [0089] states: “… feeding of the details of the detected incident into multiple hypothetical simulations of that incident will be performed by the importance node module in order to predict and/or control the autonomous response to the detected incident as well as subsequently improve the detection of the cyber threat causing that ongoing attack … running parallel simulations of the actual attack about what might happen in terms of what the cyber threat may do in response to the autonomous response and an impact on the network being protected.” The Specification at paragraph [151] states: “… modules may cooperate to improve the analysis of the how vulnerable the organization is based on any of the observed (or trained/simulated/pentested) unusual events are to that specific organization and thus improve the formalized report generation.” Therefore, the claimed limitations analyze known data using models to output a prediction/simulation result related to a potential cyberattack incident for a specific group of users. The claimed limitations improve the process of how the data is analyzed using data processing modules. When applying the broadest reasonable interpretation of the claim language in view of the Specification, the claimed invention falls within the mental processes grouping of abstract concepts because a human could analyze data and mentally determine or deduce whether the network or other enterprise technology would be at risk or vulnerable to a potential cyber-attack, and could mentally determine which preventative or corrective actions should be taken to mitigate the risks. The underlying technology used as tools to implement the abstract data analysis and output concepts is broadly and generically claimed. Merely automating a process is not enough. See Customedia, 951 F.3d at 1365 (generic speed or efficiency increases that result from applying a computer to a task do not improve computer functioning); OIP Techs., Inc. v. Amazon.com, Inc., 788 F.3d 1359, 1363 (Fed. Cir. 2015) (“But relying on a computer to perform routine tasks more quickly or more accurately is insufficient to render a claim patent eligible.”); Cellspin Soft, Inc. v. Fitbit, Inc., 927 F.3d 1306, 1316 (Fed. Cir. 2019) (“But the need to perform tasks automatically is not a unique technical problem.”); Credit Acceptance Corp. v. Westlake Servs., 859 F.3d 1044, 1055 (Fed. Cir. 2017) (automating processes using generic computers does not improve computer technology); Bancorp Servs., L.L.C. v. Sun Life Assur. Co. of Can. (U.S.), 687 F.3d 1266, 1279 (Fed. Cir. 2012) (“Using a computer to accelerate an ineligible mental process does not make that process patent-eligible.” Therefore, the claimed limitations recite an abstract idea.
The Examiner has a duty to give Applicant a fair opportunity to respond to a rejection, which is violated only when a rejection is so uninformative that it prevents Applicant from recognizing and seeking to counter the grounds for rejection. "[A]Il that is required of the office to meet its prima facie burden of production is to set forth the statutory basis of the rejection in a sufficiently articulate and informative manner" so as to "notify the applicant,' "stating the reasons for such rejection,' 'together with such information as may be useful in judging the propriety of continuing prosecution of his application." In re Jung, 637 F.3d 1356, 1363 (Fed. Cir. 2011) (citing 35 U.S.C. § 132). Per the MPEP evidentiary requirements in making a § 101 rejection: “When performing the analysis at Step 2A Prong One, it is sufficient for the examiner to provide a reasoned rationale that identifies the judicial exception recited in the claim and explains why it is considered a judicial exception (e.g., that the claim limitation(s) falls within one of the abstract idea groupings).
Applicant further asserts that the claims integrate any alleged abstract idea into a practical application by providing an improvement to network security technology, in a manner that is analogous to the claims found eligible in Finjan Inc. v. Blue coat Systems, 879 F.3d 1299 (Fed. Cir. 2018) because the present claims generate importance metrics and attack path models that identify vulnerable network nodes and key pathways that potential cyber-attacks could exploit. Applicant further asserts that the claimed limitations are analogous to those found eligible in BASCOM Global Internet v. AT&T Mobility LLC, 827 F.3d 1341 (Fed. Cir. 2016). Examiner respectfully disagrees.
Unlike the eligible claims of Finjan, the independent claims herein present information without improving the functioning of computers and are therefore not analogous to the eligible claims of Finjan. The court in BASCOM determined that an inventive concept may be found in a non-conventional and non-generic arrangement of components that are individually well-known and conventional. Bascom, 828 F.3d at 1350. The arrangement involved the placement of a filtering element for filtering Internet content at a specific location in a system. Here, Applicant does not identify any non-conventional and non-generic arrangement of physical components. Accordingly, BASCOM does not support Applicant’s position. Examiner notes, “to be directed to a patent-eligible improvement to computer functionality, the claims must be directed to an improvement to the functionality of the computer or network platform itself.” Customedia Techs., LLC v. Dish Network Corp., 951 F.3d 1359, 1365 (Fed. Cir. 2020); Interval Licensing, 896 F.3d at 1344 (software can make non-abstract improvements but software-based inventions that did not pass § 101 muster failed when “they did not recite any inventive technology for improving computers as tools or because the elements of the asserted invention were so result-based that they amounted to patenting the ineligible concept itself). The claims herein do not implement a functional change to the underlying technologies in a manner that transforms the recited abstract idea into a practical application. While cyberattack security is the technological field, the data analyzed is not used in a meaningful way that goes beyond presentation of an output or results based claiming to a specific group of users that are classified as “vulnerable” to cyber-attacks. Therefor the claims are properly rejected under Step 2A, Prong Two.
Applicant lastly asserts that even if the claims were found to be directed to an abstract idea that is not integrated into a practical application, the claims recite an inventive concept that amounts to significantly more than the alleged abstract idea – noting Examiner’s withdrawal of the 35 U.S.C. 103 prior art rejection. Examiner respectfully disagrees. The patent eligibility analysis is not an evaluation of the either the novelty or non-obviousness of the claim limitations. There is no indication in the Specification that Applicant has achieved an advancement or improvement in computer processing technology. See generally Spec. All of the data processing, memory, and input-output devices, as well as their interconnections, are described at a high level of generality that presumes familiarity on the part of the reader. The recited claim limitations merely tell a computer to “apply” the abstract idea of Step 2A, Prong 1. A claim for a new abstract idea is still an abstract idea. The 35 U.S.C. 101 rejection is proper and maintained.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1 -20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea, without significantly more. Independent claim 1 recites a device, independent claim 11 recites a process, and independent claim 20 recites a product for automated cyber security training. Claims 1, 11, and 20 recite substantially similar limitations.
Under Step 1, independent claims 1, 11, and 20 recite at least one step or act, including classifying network nodes based on security risks and associated vulnerabilities. Thus, the claims fall within one of the statutory categories of invention. See MPEP 2106.03.
Taking independent claim 11 as representative, amended claim 11 recites the following limitations:
configuring an importance node module generate to one or more graphs and determine an importance metric of a network node in the one or more graphs based on at least two or more factors that at least include a hierarchy of a user in an organization, a job title of the user in the organization, aggregated account privileges from multiple different network domains for the user, and a level of shared resource access for the user;
configuring an attack path modeling component to i) receive the one or more graphs as input from the importance node module, ii) conduct analytics of the one or more graphs to determine an importance of a particular network node in the network compared to other network nodes in the network, iii) determine key pathways within the network and associated vulnerable network nodes in the network that a potential cyber-attack could exploit and iv) conduct a modeling of the potential cyber-attack with a cyber threat attack simulator, where the attack path modeling component is configured to understand the importance of the network nodes in the network based on the supplied input of the one or more graphs from the importance node module;
configuring a grouping module to cooperate with the importance node module and the attack path modeling component and analyze the importance of the network nodes in the network compared to the other network nodes in the network, and the key pathways within the network and the associated vulnerable network nodes in the network used during the potential cyber-attack, where the grouping module is further configured to classify the network nodes based on security risks and associated vulnerabilities of the network nodes in order to generate reports including areas of vulnerability and known weaknesses of the network under analysis, where the reports are generated based on calculations to determine riskiest network nodes and risk factors associated with each network node;
configuring one or more processing units to execute software instructions associated with the importance node module, the attack path modeling component, and the grouping module; and
configuring one or more non-transitory storage mediums to store at least software associated with the importance node module, the attack path modeling component, and the grouping module,
wherein the automated training system is configured to counter cyberthreats by performing simulations to counter potential cyber-attacks where the simulations are directed to groups of users of the network nodes with common susceptibility to a particular type of cyber-attack to conduct a targeted training session.
Under Step 2A Prong One, the method steps of claim 11 for configuring software modules to perform data analysis and simulation functions (software instructions), as drafted, illustrates a process that, under its broadest reasonable interpretation covers performance of the limitation in the mind (measuring security threats and generating reports regarding user vulnerability and known weaknesses), as detailed below:
configuring an importance module to generate one or more graphs; and determine an importance metric of a network node in the one or more graphs
Abstract idea: organizing and manipulating data through mathematical correlations - “a process that employs mathematical algorithms to manipulate existing information to generate additional information is not patent eligible.” See DigitechImage Techs, LLC v. Elecs. for Imaging, Inc., 758 F.3d 1344, 1351 (Fed. Cir. 2014).
configuring the attack path modeling component to i) receive graphs as input; ii) conduct analytics of the graphs, iii) determine key pathways, and iv) conduct modeling of the potential cyber-attack
Abstract idea: comparing data to make a determination could be performed mentally. Receiving data as input is insignificant extra-solution activity (i.e., data gathering). See MPEP § 2106.05(g).
a modeling of the cyber-attack
Modeling is outside of the scope of the claim requirements, while the model is referenced to make a determination, the claims limitations do not positively recite limitations for modeling a cyber-attack.
The attack path modeling component is configured to understand the importance of the network modes in the network compared to other network nodes
Abstract idea: comparing data to make a determination could be performed mentally.
configuring a grouping module to cooperate with the importance node module and the attack path modeling component
Cooperating with software modules over a network is a form of transmitting and/or receiving data and amounts to insignificant extra-solution activity (i.e., data gathering). See MPEP § 2106.05(g).
configuring a grouping module to … analyze the importance of the network nodes in the network compared to other network nodes in the network
Abstract idea: comparing data to make a determination could be performed mentally.
The grouping module is further configured to classify the network nodes based on security risks and associated vulnerabilities of the network nodes
Abstract idea: classifying data involves evaluating and making judgements which can be performed mentally.
in order to generate reports … , where the reports are prepared based on calculations to determine riskiest network nodes and risk factors associated with each network node
The reporting step is an intended result of the data analysis steps, generating a report is the output of data and is construed as insignificant extra solution activity. See MPEP 2106.05(g). Further, generating a report is not actively claimed or positively recited.
configuring one or more processing units to execute software instruction associated with the importance node module, the attack path modeling component, and the grouping module
Abstract idea: processing data to generate an output could be performed mentally.
configuring one or more non-transitory storage mediums to store at least software associated with the importance node module, the attack path modeling component, and the grouping module
Storing information is insignificant extra solution activity. See MPEP 2106.05(g).
The automated training system is configured to counter cyberthreats by performing simulations
Presenting content to a user or group of users in the form of a training simulation based on data analysis output is a mental process. Simulations can be carried out by human beings imitating the actual process with the aid of pencil and paper.
The Specification at paragraph [0089] states: “… feeding of the details of the detected incident into multiple hypothetical simulations of that incident will be performed by the importance node module in order to predict and/or control the autonomous response to the detected incident as well as subsequently improve the detection of the cyber threat causing that ongoing attack … running parallel simulations of the actual attack about what might happen in terms of what the cyber threat may do in response to the autonomous response and an impact on the network being protected.” The Specification at paragraph [151] states: “… modules may cooperate to improve the analysis of the how vulnerable the organization is based on any of the observed (or trained/simulated/pentested) unusual events are to that specific organization and thus improve the formalized report generation.” Therefore, the claimed limitations analyze known data using models to output a prediction/simulation result related to a potential cyberattack incident for a specific group of users. The claimed limitations improve the process of how the data is analyzed using data processing modules. None of the additional elements preclude the steps from practically being performed in the human mind, or by a human using a pen and paper. See MPEP 2106.04(a)(2)(III). The claim limitations for performing calculations using a mathematical function and use of one or more graphs falls under both the mathematical concepts grouping and mental processes grouping, and the claims recite an abstract idea of collecting, analyzing, and outputting results. See MPEP § 2106.04(a)(2)(I). Therefore, the limitations the claims recite an abstract idea. See MPEP § 2106.04(a). Because performing cybersecurity training based on analysis of known data and generation of a report of a user’s (or group of users) vulnerability and known weakness is a form of managing personal behavior and the claims fall within the abstract concept grouping of certain methods of organizing human activity. See MPEP 2106.04(a)(2)(II).
Under Step 2A Prong Two, the judicial exception of claim 11 is not integrated into a practical application. In particular, the claims only recite a processor and storage device for performing the recited steps. These elements are recited at a high level of generality (i.e., as a generic processor performing a generic computer function) and amount to no more than mere instructions to apply the exception using generic computer components. See MPEP 2106.05(f). For example, Applicant’s specification at paragraph [0204] states: “FIG. 7 illustrates a block diagram of an embodiment of one or more computing devices that can be a part of the automated training system to counter cyber-threats for an embodiment of the disclosure. The computing device may include one or more processors or processing units 620 to execute instructions, one or more memories 630- 632 to store information, one or more data input components 660-663 to receive data input from a user of the computing device 600, one or more modules that include the management module, a network interface communication circuit 670 to establish a communication link to communicate with other computing devices external to the computing device.” Adding generic computer components to perform generic functions, such as data gathering, performing calculations, and outputting a result would not transform the claim into eligible subject matter. See MPEP 2106.05(h).
Claim 11 recites the following additional elements: (1) an importance module, (2) attack path modeling component, and (3) a grouping module. Each of these additional elements are construed as software modules comprising instructions for processing the data input, without significantly more. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
Under Step 2B, claim 11 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional elements of a processor and storage device amount to no more than mere instructions to apply the exception using a generic computer component which cannot provide an inventive concept. There is no indication in the Specification that Applicant has achieved an advancement or improvement in computer processing technology. See generally Spec. All of the data processing, memory, and input-output devices, as well as their interconnections, are described at a high level of generality that presumes familiarity on the part of the reader. The recited claim limitations merely tell a computer to “apply” the abstract idea of Step 2A, Prong 1.
Dependent claims 2-10 and 12-19 include the abstract ideas of the independent claims. The limitations of the dependent claims merely narrow the mental process of collecting data, analyzing it, and generating certain output/method of organizing human activity related to behavior on a network that creates cyber-security risks or threats abstract idea by describing how the analyzed data is intended to be used for implementing cyber security training and reporting, including training specific to the intended user or group of users. The limitations of the dependent claims are not integrated into a practical application because none of the additional elements set forth any limitations that meaningfully limit the abstract idea implementation. There are no additional elements that transform the claim into a patent eligible idea by amounting to significantly more. The analysis above applies to all statutory categories of invention. Accordingly, independent claims 1 and 20 and the claims that depend therefrom are rejected as ineligible for patenting under 35 U.S.C. 101 based upon the same analysis applied to claim 11 above. Therefore claims 1 -20 are ineligible under 35 U.S.C. 101.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Moskovich et al. (US 11,582,256) - systems and methods for penetration testing of networked systems which identify attack methods that an attacker can use to compromise a network node. In particular, the present invention is suitable for penetration testing of networked systems to determine multiple attack methods that an attacker can use to compromise a given networked node.
Powell et al. (US 8,601,587) - a cyber threat analysis system generates a network model of a network infrastructure that is used by an organization, assigns a weighting value to each of a plurality of network elements of the network infrastructure according to a relative importance of each network element to the organization, and generates an attack vector according to a determined vulnerability of the network infrastructure. The attack vector represents one or more illicit actions that may be performed to compromise the network infrastructure. The system may simulate, using a network modeling tool, the attack vector on the network model to determine one or more resulting ramifications of one or more of the plurality of network elements due to the attack vector, and determine a criticality level of the attack vector according to the weighting value of the one or more network elements.
Muddu et al. (US 9,699,205) - security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Pinney Wood et al. (US 9,210,185) - The cyber threat monitor and control (hereinafter “CTMC”) apparatuses, methods and systems, for example, determine risk across a global Internet data model graph (e.g., a network graph reflecting structural information of network elements, and/or a factor graph that has threat indicator confidence score information) for various virtual or physical network elements. In one implementation, the CTMC defines a data model graph structure representation of the Internet network elements (e.g., a virtual element or a physical element), including but not limited to an Internet protocol (IP) host, a classless inter-domain router (CIDR), a fully qualified domain name (FQDN), an autonomous system number (ASN), applications or application identifiers, malware, collections of networks, users, and/or the like. A probabilistic cyber security measure (e.g., a threat indicator confidence score, etc.) is calculated and/or updated for each of the network elements (e.g., nodes) in the network graph, which indicates a likelihood that the respective network element is at risk of cyber-attack.
Jain et al. (US 9,800,592) - identification of inbound and outbound network and application attacks with respect to a data center. Commodity servers are used to monitor ingress and egress traffic flows, and anomalies are detected in the traffic flows. Responsive to detecting an anomaly, a mitigation strategy is executed to mitigate damage caused by a cyber-attack.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LETORIA G KNIGHT whose telephone number is (571)270-0485. The examiner can normally be reached M-F 9am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rutao WU can be reached at 571-272-6045. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/L.G.K/Examiner, Art Unit 3623 /RUTAO WU/Supervisory Patent Examiner, Art Unit 3623