DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending, with independent claims 1 and 6.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 3/12/2026 has been entered.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 4/3/2023 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Response to Arguments
Applicant’s arguments, see page(s) 13-14, filed 7/15/2026, with respect to the rejection of claim(s) 1 and 6 under 35 U.S.C. 112(a) have been fully considered but they are not persuasive.
Regarding the arguments directed to claims 1 and 6:
Applicant asserts that support for the amendments can be found in ¶¶ 0015, 0016, 0030, and 043. None of the provided excerpts, nor any other portion of the original disclosure, sufficiently describe the claimed functions of calculating any of the claimed evaluation points. Simply declaring that a value is calculated, as is the case in at least the excerpt from at least ¶ 0015 (“the threat evaluation unit 105 calculates, for example, an evaluation point indicating a risk.”), is not a sufficient written description of how an evaluation point is calculated. For computer-implemented claims, a sufficient written description includes an algorithm or steps for performing a claimed function, not simply an assertion of a result. See MPEP 2161.01 (emphasis added), “Similarly, original claims may lack written description when the claims define the invention in functional language specifying a desired result but the specification does not sufficiently describe how the function is performed or the result is achieved. For software, this can occur when the algorithm or steps/procedure for performing the computer function are not explained at all or are not explained in sufficient detail (simply restating the function recited in the claim is not necessarily sufficient). For at least these reasons, these rejections are maintained, though updated to reflect the amended claim language.
Examiner notes that Applicant response and amendments are non-responsive to the individual rejections of claims 3, 4, 8, 9, and 13. These rejections are maintained.
Applicant's arguments, see pages 14-18, filed 7/15/2026, with respect to the rejection of claims 1-14 under 35 USC 112(b) have been fully considered.
Regarding the arguments directed to claims 1 and 6:
Examiner notes that none of the provided arguments nor amendments address any of the points explained in the rejection in the previous office action, nor is it clear how they are meant to address those points. As amended, reasons for indefiniteness in the claims include but are not necessarily limited to:
They still ambiguously describe “attack strategy information” and “attack technique information and their relationship to each other. They are first read as a singular pair, then multiple combinations of this single pair are claimed, then they are referred to as singular again.
They still reference the effectiveness of an attack with no explanation of to what attack is being referred or how the effectiveness is measured.
They still do not explain to what a “piece” of information refers.
They still do not explain how multiple combinations of attack and technique information are selected despite only reciting a single pair.
They still recite multiple evaluation scores despite only one being calculated.
For at least these reasons, these rejections are maintained.
Regarding arguments directed to claims 2, 7, 13, and 14:
These arguments are persuasive. The associated rejections have been withdrawn.
Applicant’s arguments, see pages 11-15, filed 2/9/2026, with respect to the rejection of claims 1-14 under 35 USC 101 have been fully considered but they are not persuasive.
Regarding the claims as a mental process:
Examiner notes that no particular arguments are presented which constitute more than an assertion of disagreement with this portion of the eligibility assessment. Where Applicant quotes SRI Int'l, Inc. v. Cisco Systems, Inc., examiner notes that there is nothing analogous to the physical “network monitors” in the claims which would preclude the performance of the claimed steps in the mind or with pen and paper.
Regarding integrating the judicial exception into a practical application:
Examiner respectfully disagrees and notes that the newly added limitations are representative of additional data processing steps, are not cannot be said to indicate an improvement to technology where the claimed steps may be performed by a human in the mind or with pen and paper. Where Applicant cites Finjan Inc. v. Blue Coat Systems, Inc., examiner notes that the claims do not describe any subject matter which could be described as enabling a “computer security system to do things it could not do before.” Reading information, selecting combinations of data, and outputting the result are all processes which can be accomplished by already existing computer systems.
Regarding addressing a specific problem:
Applicant argues that the purpose of the claimed invention is “to generate an attack scenario by evaluating an attack strategy and an attack technique according to characteristic of an attacker and a target system, and combining an attack strategy and a technique on the basis of the evaluation.” Examiner notes that these are among the most fundamental and basic concepts of penetration testing, and no improvement is indicated in addressing them.
Regarding “specific technical components”:
Examiner respectfully disagrees and notes that the components argued represent already available technology, with their already available basic functions, to use as a tool in executing the claimed process. As far as the claimed evaluations and planning of a countermeasure, no evidence is provided as to why these steps cannot be performed in the mind. Indeed, Applicant’s arguments describe this planning step as nothing more than “identifying a countermeasure content and placing the countermeasure in an order of priority.” A human is clearly capable of performing these steps as a mental process.
Applicant’s arguments, see pages 21-24, filed 7/15/2026, with respect to the rejection of claims 1-14 under 35 USC 103 have been fully considered. A new ground(s) of rejection is made in view of GANOR (Doc ID US 20180375892 A1).
Examiner notes that due to the change in scope of the claims created by the new amendments, the previous prior art rejections are withdrawn. However, examiner notes that, as the claims continue to remain in a state which makes a thorough examination and search for prior art impossible, each of the references cited in the previous office action may or may not be used to map to the current limitations according to the most sensible possible interpretation that the Examiner is able to apply.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim(s) 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. As drafted, the claim limitations are processes that, under their broadest reasonable interpretation, may be performed in the mind. That is, nothing in the claim elements precludes the steps from practically being performed in the mind (or with pen and paper).
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claims recite an abstract idea.
The claims, minus their recited generic computer components, are summarized as follows:
Claim(s) 1 and 6 recite(s):
Receiving various pieces of information.
Evaluating effectiveness of an attack.
Calculating various scores.
Selecting combinations of parameters based on criteria.
Generating an “attack scenario” with the selected parameters.
Displaying generated scenarios.
Planning a countermeasure.
Claim(s) 2 and 7 recite(s):
Evaluating a threat.
Generating an “attack scenario” based on parameters and the evaluation.
Claim(s) 3 and 8 recite(s):
Analyzing a “trend of the cyber attack.”
“Using” the analysis result in other evaluations.
Claim(s) 4 and 9 recite(s):
Performing “narrowing” on various pieces of information.
Evaluating the “narrowed” information.
Claim(s) 5 and 10 recite(s):
Generating “attack scenarios.”
Outputting the scenarios based on evaluations.
Claim(s) 11 recite(s):
Calculating a score using points for devices based on their roles.
Claim(s) 12 recite(s):
Selecting “constituents” of a computer system and threat information based on a score.
Selecting information that “realizes” other information.
Claim(s) 13 recite(s):
Calculating a score by multiplying or subtracting other values.
Selecting information based on comparing the score to a threshold.
Claim(s) 14 recite(s):
Calculate a score based on “device role information and malware countermeasure information.”
Give higher scores to devices “responsible for data saving.
Claim(s) 16 recite(s):
Performing “narrowing” on various pieces of information.
Claim(s) 18 recite(s):
Outputting information.
This judicial exception is not integrated into a practical application because other aspects of the claims’ limitations amount no more than mere instructions to apply the exception using generic computer components and functions (computer system, storage device, processor, memory). Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea.
Regarding the generic computer components, patents may be directed to abstract ideas where they disclose the use of an already available technology, with its already available basic functions, to use as a tool in executing the claimed process.
The claims further do not include additional elements that amount to significantly more than the judicial exception because there is nothing in the claims, whether considered individually or in their ordered combination, that would transform the application into something “significantly more” than the abstract idea of collecting data, processing and evaluating data, and generating scenarios. Further, the claims do not contain steps through which the invention represents an improvement to computer technology, to include improvement over computers or developing scenarios for penetration testing. The claims are not patent eligible.
Regarding claims 15, 17, 19, and 20:
They are dependent on one or more rejected claims, and thus inherit those rejections. This rejection could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claims such that they are no longer dependent on any rejected claim.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL. — The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement. The claim(s) contain(s) subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, at the time the application was filed, had possession of the claimed invention.
Regarding claim(s) 1 and 6:
Claim 1 recites, “… calculating an evaluation point indicating effectiveness of an attack …”. Claim(s) 6 recite(s) similar language. The specification fails to adequately describe this limitation. The specification does recite that an “… evaluation point indicates effectiveness of an attack in each piece of the attack strategy/technique information 500.” in ¶ 0016; however, the specification teaches only that this “evaluation point” is calculated based on “information of the system configuration storage unit,” and not how it is calculated, how it is used to evaluate the “effectiveness” of an attack, nor any other guidance vis a vie how the claimed evaluation is performed.
Claim 1 also recites, “… calculating an evaluation point indicating a risk for the threat information …”. Claim(s) 6 recite(s) similar language. The specification fails to adequately describe this limitation. The specification does recite that an “… the threat evaluation unit 105 calculates, for example, an evaluation point indicating a risk.” in ¶ 0015; however, the specification teaches only that this “evaluation point” is calculated based on “information of the system configuration storage unit,” and not how it is calculated, nor how it is used to calculate the “threat evaluation score.” There is a portion of an algorithm found in ¶ 0058, “In the example of FIG. 17, … Group A is selected as a threat trend from the trend analysis information 1600. … Furthermore, … Group A is a group with the risk level 1650 of "high" associated with threat information of "falsification of data". For this reason, in the threat evaluation point 1730, 12 obtained by multiplying the original value 4 by three is set as a threat evaluation point of "falsification of data" of Threat identification number 1.” A careful reading indicates that the value of ‘4’ is obtained from Fig. 10, but there is no indication from where the value of ‘3’ is obtained to achieve the result of ’12.’
Claim 1 also recites, “… calculating respective evaluation scores for each piece of attack strategy and technique information …”. Claim(s) 6 recite(s) similar language. The specification fails to adequately describe this limitation. The specification does recite that “… in Step S703, an evaluation point for the read attack strategy/technique information 500 is calculated” in ¶ 0034; however, the specification gives no detail vis a vie how this calculation is performed.
Regarding claims 1, 6, and 14:
Claim 1 recites, “… the evaluation point indicating a risk is calculated based on a countermeasure status of each constituent …”. Claim(s) 6 recite(s) similar language. Claim 14 similarly recites, “… calculates the evaluation point indicating a risk based on device role information and malware countermeasure information … of each constituent …”. The specification fails to adequately describe this limitation. The specification does recite using “… information indicating a countermeasure status in Step S602 and Step S703 for performing each evaluation” in ¶ 0025; however, the specification provides no details vis a vie how this “countermeasure” status is actually used in the claimed calculations.
Regarding claims 2 and 7:
Claim 2 recites, “… evaluating, for each constituent of the computer system, the threat that is stored in the storage device and calculating a threat evaluation score for each constituent …”. Claim(s) 7 recite(s) similar language. The specification fails to adequately describe this limitation. The specification does recite that an “… the threat evaluation unit 105 calculates, for example, an evaluation point indicating a risk.” in ¶ 0015; however, the specification teaches only that this “evaluation point” is calculated based on “information of the system configuration storage unit,” and not how it is calculated, nor how it is used to calculate the “threat evaluation score.”
Regarding claims 3 and 8:
Claim 3 recites, “… analyzing a trend of the cyber attack …”. Claim(s) 8 recite(s) similar language. The specification fails to adequately describe this limitation for largely the same reasons as detailed in the rejection of claims 1 and 6 above vis a vie “evaluating effectiveness of the cyber attack.” The specification provides no description of how the claimed trend analysis is performed.
Regarding claims 4 and 9:
Claim 4 recites, “… executing evaluation of the attack strategy and technique information …”. Claim(s) 8 recite(s) similar language. The specification fails to adequately describe this limitation for largely the same reasons as detailed in the rejection of claims 1 and 6 above vis a vie “calculating respective evaluation scores for each piece of attack strategy and technique information.” The specification provides no description of how the claimed evaluation is performed.
Regarding claim 13:
Claim 13 recites, “… a strategy evaluation point is calculated by multiplication or a difference in the respective evaluation scores, which serve as technical evaluation points …”. The specification fails to adequately describe this limitation. The specification does recite that “… there is also a method of calculating an evaluation point by addition with, multiplication by, or a difference from an evaluation point up to a previous stage …” in ¶ 0048; however, there is no indication how this is performed, or to what “previous stage” is being referred.
Examiner further notes that there is no indication in the specification that the “technical evaluation points” are equivocal to the “evaluation scores,” as claimed. This amended limitation represents new matter.
Regarding claim 15:
Claim 15 recites, “… applying at least one countermeasure to the computer system …”. This limitation lacks sufficient written description in the original disclosure, and thus constitutes new matter. No application of any configuration is performed on the disclosed computer system in the original disclosure. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which is explicitly supported by the original disclosure.
Regarding claim 17:
Claim 17 recites, “… configuring security settings of at least one constituent of the computer system based on the generated attack scenarios …”. This limitation lacks sufficient written description in the original disclosure, and thus constitutes new matter. The term “security settings” does not appear anywhere in the original disclosure. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which is explicitly supported by the original disclosure.
Regarding claim 18:
Claim 18 recites, “… a file for use in penetration testing of the computer system.” This limitation lacks sufficient written description in the original disclosure, and thus constitutes new matter. The term “penetration testing” does not appear anywhere in the original disclosure. Examiner further notes that this portion of the claim also does not further limit the claim, as it represents intended use. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which is explicitly supported by the original disclosure.
Regarding claim 19:
Claim 19 recites, “… allocating security resources to constituents of the computer system based on the total evaluation scores of the generated attack scenarios …” and “… constituents … having higher total evaluation scores are allocated greater security resources.” These limitations lack sufficient written description in the original disclosure, and thus constitute new matter. The original disclosure does not discuss allocating of any resources, security resources or otherwise. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which is explicitly supported by the original disclosure.
Regarding claim 20:
Claim 20 recites, “… updating system configuration … based on the generated attack scenarios to reflect implemented countermeasures …” and “… regenerating attack scenarios based on the updated system configuration information.” These limitations lack sufficient written description in the original disclosure, and thus constitute new matter. The original disclosure discusses neither updating the system configuration, nor regenerating attack scenarios for any reason. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which is explicitly supported by the original disclosure.
These rejections can be overcome by amending the claim(s) such that they recite only that subject matter which is has adequate description in the original disclosure.
It is important to note that in regards to an adequate written description, “It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015)” (MPEP 2161.01).
Regarding claims 5, 10-12, and 16:
They are dependent on one or more rejected claims, and thus inherit those rejections. This rejection could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claims such that they are no longer dependent on any rejected claim.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION. — The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-120 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention.
Regarding claims 1-14:
The claims are generally indefinite because the metes and bounds of the claims, taken, as a whole, cannot be determined. The claims, by their plain wording, recite a method of:
Read a pair of data objects.
One of the objects is labeled “attack strategy.”
The other is labeled “attack technique.”
Read a data object labeled “threat information.”
Somehow calculate an “evaluation point” which indicates the effectiveness of an attack “in each of the attack strategy and technique information”.
Somehow calculate an “evaluation point” which indicates the “risk for the threat information based on a device role of each constituent”.
Use the evaluation point for effectiveness to somehow calculate evaluation scores for each “piece” of the “attack strategy” and “technique information”.
Somehow select “multiple combinations” of “attack strategy” and “technique information” – despite reading only a single instance of each from storage – based on the pair’s evaluation scores being above a “predetermined threshold.”
Somehow generate an “attack scenario,” which involves combining the selected combinations based on their score (note score is indicated as singular despite earlier claiming multiple scores) and the “evaluation point” for risk.
Weight the combination by “both scores” (though it is unclear at this point to which scores are being referred), which is claimed to somehow “determine attack effectiveness against specific constituents.”
Display a list of generated scenarios (despite only generating one scenario), each with a “total evaluation score” which is the sum of the evaluation scores for each of the “attack strategy” and “technique information”.
Base the “evaluation point” for risk on the “countermeasure status of each constituent,” which conflicts with the earlier limitation of basing the “point” on “a device role of each constituent.”
Plan a countermeasure against the cyber attack by “identifying a countermeasure content and placing the countermeasure in an order of priority,” despite there being only one countermeasure to list.
These steps are not sufficiently explained to enable one of skill in the art to determine how these steps are being performed, or in some cases, what steps are being performed at all. The invention as claimed ultimately seems to receive parameters for a cyber-attack, in order to use those parameters to generate a scenario for the attack, where the attack then uses those parameters. At various points throughout the claims, the core parameters (strategy and technique) are treated as a single immutable pair, a pair among many pairs, or independent data objects. Many terms used in the claims do not appear in the specification, and those that do largely lack any specific definitions which would aid in understanding the claims. The claims are overall impossible to parse sensibly, and are therefore indefinite.
Regarding claims 1 and 6:
Claim 1 recites, “… a scenario generation device that generates a scenario of a cyber attack …”, “… reading, from a storage device, … an attack strategy indicating an action for executing the cyber attack and an attack technique indicating a method of realizing the attack strategy …”, and “… calculating an evaluation point indicating effectiveness of an attack in each of the attack strategy and technique information …”. Claim 6 recites similar language. It is firstly unclear whether the attacks referred to in these limitations are meant to be one attack or multiple attacks. “Scenario of a cyber attack” indicates one attack. “Executing the cyber attack” implies it is the same cyber attack to which is being referred. “Effectiveness of an attack” indicates a different attack. However, the language also indicates it is one pair of a single “attack strategy” and a single “attack technique” to which is referred throughout.
It is also unclear how the effectiveness of a cyber-attack may be evaluated if the claimed generation of the scenario for the attack has not yet been performed.
It is also unclear by what measure “effectiveness of an attack” is measured. Similarly, where the claim previously describes the “attack strategy” as an action, and the “attack technique” as a “method for realizing the attack strategy,” it is unclear how any measure of effectiveness would differ between the two information objects, as they are described one simply being a part of the other.
Claim 1 also recites, “… calculating an evaluation point indicating a risk for the threat information based on a device role of each constituent …”. Claim 6 recites similar language. The verbiage of this limitation is confusing and indefinite. It is unclear what is meant by “risk.” “Risk for the threat information” implies a danger to the threat information itself. It is also ambiguous whether one “evaluation point” is being calculated for all “constituents” (“calculating an evaluation point), or for each constituent. The other portion of this limitation, “… wherein constituents having higher security risks based on their device roles are assigned higher evaluation points indicating a risk …”, is similarly poorly worded. It is unclear whether “higher points” indicates a greater value overall, or whether it refers to the value of a single “evaluation point” applied to either a constituent or the plurality of constituents.
Claim 1 also recites, “… calculating respective evaluation scores for each piece of attack strategy and technique information …”. Claim 6 recites similar language. The meaning of “pieces of” information is ambiguous. A “piece” of information is not a common term in the art, and neither the claim nor specification elaborate on the term. The claim is indefinite because it cannot be determined whether a “piece” refers to a portion (and further, which portion) or the whole of either or both strategy or technique information.
Claim 1 also recites, “… selecting multiple combinations of attack strategy and attack technique, wherein the attack strategy and technique information includes an attack strategy identification number, a strategy name, a technique identification number, and a technique name …”. Claim 6 recites similar language. It is unclear what this selecting entails. Previously, the claim recites (emphasis added), “reading, from a storage device, attack strategy and technique information in which an attack strategy indicating an action for executing the cyber attack and an attack technique indicating a method of realizing the attack strategy are associated”. If “strategy and technique information” is a bound pair of information objects, such as a strategy name and number paired with a technique name and number, it is unclear how “selecting” them is functionally distinct from this previously indicated pairing. Additionally, as only one of each strategy and technique information are read, it is unclear what other selection could even be possible where only two pieces of information are considered.
Claim 1 also recites, “… the attack strategy and technique information is selected based on having evaluation scores above a predetermined threshold according to a result of the evaluation score …”. Claim 6 recites similar language. It is unclear what is meant by a “result of the evaluation score.” It is also unclear to even which score is being referred, as the limitation first refers to multiple scores.
Claim 1 also recites, “… generating an attack scenario by combining the selected multiple combinations of attack strategy and attack technique based on both the evaluation score for the attack strategy and technique information and the evaluation point indicating a risk …”. This limitation also is unclear for being ambiguous about to which scores and the number of scores are referred.
Claim 1 also recites, “… wherein the combination is weighted by both scores to prioritize attack scenarios targeting constituents having higher evaluation points indicating a risk, to determine attack effectiveness against specific constituents …”. The limitation is ambiguous because the claims previously recite determining attack effectiveness as occurring before the scenario is generated.
Claim 1 also recites, “… displaying a list of generated attack scenarios sorted by their respective total evaluation scores in descending order …”. The limitation is ambiguous because it is unclear how any ordered list can be created, as the generation of only one scenario is previously recited.
Claim 1 also recites, “… wherein the evaluation point indicating a risk is calculated based on a countermeasure status ….”. The limitation is also ambiguous because the evaluation point indicating a risk is previously recited as being based on device roles.
Claim 1 also recites, “… plan a countermeasure against the cyber attack by identifying a countermeasure content and placing the countermeasure in an order of priority.” The limitation is ambiguous because it is unclear in what list the countermeasure is being prioritized in, as only one countermeasure plan has been created.
For at least these reasons, the metes and bounds of the claims are not clear; the claims are thus indefinite.
Regarding claims 1, 6, and 13:
The claims vacillate between the terms “technique information” and “attack technique.” The inconsistency makes it unclear whether these terms are interchangeable or whether they are distinct from each other. For the sake of readability and clarity, the claims should be amended such that it is clear whether the terms are equivocal or distinct.
Regarding claims 2 and 7:
Claim 2 recites, “… generating the attack scenario by … using the evaluation result having a highest score for the threat.” Claim 7 recites similar language. It is unclear to which “evaluation result” is being referred, from among the various evaluation “points” and “scores” previously recited.
Regarding claims 5 and 10:
Claim 5 recites, “… outputting a plurality of generated scenarios according to a result of the effectiveness evaluation. Claim 10 recites similar language. The claims are indefinite because it is unclear in what way the “result of the effectiveness evaluation” influences the output of the multiple scenarios.
Regarding claim 11:
Claim 11 recites, “… the threat evaluation score is calculated …”. The claim is indefinite because “the threat evaluation score” lacks antecedent basis. It is unclear to what threat evaluation score is being referred, as no such score has been previously recited in this claim or its parent claims. This rejection can be overcome by amending the claim(s) such that the threat evaluation score is given antecedence.
Regarding claims 3, 4, 8, 9, and 12-20:
They are dependent on one or more rejected claims, and thus inherit those rejections. This rejection could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claims such that they are no longer dependent on any rejected claim.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-10, 12, 15-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over SATO et al (Doc ID US 20200311284 A1), and further in view of GANOR (Doc ID US 20180375892 A1) and KITO et al (Doc ID US 20230137325 A1).
Regarding claim 1:
SATO teaches:
A cyber attack scenario generation method using a scenario generation device that generates a scenario of a cyber attack on a computer system, the cyber attack scenario generation method comprising: reading, from a storage device, attack strategy and technique information in which an attack strategy indicating an action for executing the cyber attack ([0054] "… Each ... scenario pattern information 800 has the fields of pattern number 801 ..., and scenario pattern 802 which stores the execution order of the attack method ...") and an attack technique indicating a method of realizing the attack strategy are associated ([0048] "The attack classification information ... stores an identifier for identifying the type of attack, and ... stores information indicating the classification of the attack ...");
reading threat information from the storage device (Fig. 10 and [0059] "The element name 901 stores information indicating the constituent elements configuring the evaluation target.");
calculating an evaluation point indicating effectiveness of an attack in each of the attack strategy and technique information, ([0070] "The test scenario priority evaluation result 1300 is configured from … the fields of priority 1301, attack target 1302, test scenario 1303, and evaluation value 1304.") and
calculating respective evaluation scores for each piece of attack strategy and technique information based on the evaluation of effectiveness indicating an evaluation result for the attack strategy and technique information ([0070] "The test scenario priority evaluation result 1300 … has the fields of priority 1301, attack target 1302, test scenario 1303, and evaluation value 1304.");
wherein the attack strategy and technique information includes an attack strategy identification number, a strategy name, a technique identification number, and a technique name, (Fig. 9 and Fig. 7) and
generating an attack scenario by combining the selected multiple combinations of attack strategy and attack technique based on both the evaluation score for the attack strategy and technique information and the evaluation point indicating a risk for the threat information ([0089] "… step S407, the scenario creation unit 23 … assigns the test scenario created in step S405, and which was not deleted in step S406, as the test scenario 1203 of the test scenario output result 1200."),
displaying a list of generated attack scenarios sorted by their respective total evaluation scores in descending order, where each total evaluation score is indicated by a sum of evaluation scores of combinations of attack strategy and attack technique included in the generated attack scenario (Fig. 13 and [0070] "The test scenario priority evaluation result 1300 ... has the fields of priority 1301, attack target 1302, test scenario 1303, and evaluation value 1304."),
GANOR teaches the following limitations not taught by SATO:
calculating an evaluation point indicating a risk for the threat information based on a device role of each constituent, wherein constituents having higher security risks based on their device roles are assigned higher evaluation points indicating a risk ([0091] "… Cyber risk management and strategic planning logic 330 may then generate an asset risk exposure score for each of the assets …");
wherein the evaluation point indicating a risk is calculated based on a countermeasure status of each constituent of the computer system, ([0069] "... security controls logic 340 may … determine whether the enterprise has installed the latest anti-virus software, has installed firewalls at the correct locations, etc.") and
wherein the generated attack scenarios are used to plan a countermeasure against the cyber attack by identifying a countermeasure content and placing the countermeasure in an order of priority ([0100] "… Cyber risk management and strategic planning logic 330 receives the input and may ... generate a work plan that indicates what steps are involved to reduce the exposure level .... The work plan may indicate ... the resources in time and cost to implement the plan.").
Retrieving attack information, assessing an attack, generating attack scenarios, and displaying them to a user are known techniques in the art, as demonstrated by SATO. Further, calculating an additional score based on a device role and countermeasures and planning countermeasures based on the score is a known technique in the art, as demonstrated by GANOR. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO with the scoring and countermeasure planning of GANOR with the motivation to react to attacks deemed successful against the target system, rather than limiting the testing system to scenario generation. This is a known technique which has been used to improve similar devices.
KITO teaches the following limitations not taught by the combination of SATO and GANOR:
selecting multiple combinations of attack strategy and attack technique ([0053] "In step S13, the means selection unit 120 selects an attack means … using the score value of each attack means of the plurality of attack means and the threshold 173."),
Examiner notes that "attack means" represents an aggregation of multiple attack steps.
wherein the attack strategy and technique information is selected based on having evaluation scores above a predetermined threshold according to a result of the evaluation score ([0053] "In step S13, the means selection unit 120 selects an attack means … using the score value of each attack means of the plurality of attack means and the threshold 173."), and
wherein the combination is weighted by both scores to prioritize attack scenarios targeting constituents having higher evaluation points indicating a risk, to determine attack effectiveness against specific constituents ([0053] "In step S13, the means selection unit 120 selects an attack means … using the score value of each attack means of the plurality of attack means and the threshold 173."); and
Selecting attack measures based on their scores is a known technique in the art, as demonstrated by KITO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO and GANOR with the score-based measure selection of KITO with the motivation to automate the process of choosing attack measures to use in the attack scenario. This is a known technique which has been used to improve similar devices.
Regarding claim 2:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: evaluating, for each constituent of the computer system, the threat that is stored in the storage device and calculating a threat evaluation score for each constituent (SATO [0061] "… In the example shown in FIG. 11, the attack route information 1100 is created as a separate table for each asset that may be attacked."); and
generating the attack scenario by using the attack strategy and technique information and, in addition to the attack strategy and technique information, using the evaluation result having a highest score for the threat (KITO [0053] "In step S13, the means selection unit 120 selects an attack means … using the score value of each attack means of the plurality of attack means and the threshold 173.").
Taking the highest-evaluated measured from among the selected measures for use in an attack scenario is a known technique in the art, as demonstrated by KITO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the score-based measure selection of KITO with the motivation to automate the process of choosing attack measures to use in the attack scenario.
Regarding claim 3:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 2, further comprising: analyzing a trend of the cyber attack (SATO [0054] "... Each record … stores the pattern number for uniquely identifying a pattern, and scenario pattern 802 which stores the execution order of the attack method …"); and
using an analysis result of the trend in evaluation for the attack strategy and technique information and evaluation for the threat (SATO [0054] "… The scenario pattern 802 stores the order of the attacks expressed using the attack classification ...").
Regarding claim 4:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: executing narrowing processing on the attack strategy and technique information according to a predetermined criterion (SATO [0068] "… the method of expression of the test scenario may be based on abbreviated codes such as in this embodiment… "); and
executing evaluation of the attack strategy and technique information on which the narrowing processing is executed (SATO [0070] "The test scenario priority evaluation result 1300 … has the fields of priority 1301, attack target 1302, test scenario 1303, and evaluation value 1304.").
Regarding claim 5:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: generating a plurality of attack scenarios (SATO [0087] "... the test scenarios of all combinations of the element number information and the attack classification information ... are created."); and
outputting a plurality of generated scenarios according to a result of the effectiveness evaluation (SATO [0089] "... the scenario creation unit 23 ... assigns the test scenario created in step S405, and which was not deleted in step S406, as the test scenario 1203 of the test scenario output result 1200. Subsequently, the scenario creation unit 23 stores the attack target 1202 corresponding to each test scenario ...").
Regarding claim 6:
SATO teaches:
A scenario generation device that generates a scenario of a cyber attack on a computer system, the scenario generation device comprising: a processor coupled to a memory storing instructions for the processor to execute ([0032] "The test scenario generation device 1, ... comprise a CPU ..., a memory 303 as a volatile storage area, an external storage device 304 such as a hard disk …"):
The remainder of this claim's limitations are rejected with the same prior art mapping and justification, mutatis mutandis, as its counterpart claim 1.
Regarding claims 7-10:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claims 2-5 above.
Regarding claim 12:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, wherein generating the attack scenario comprises: selecting a combination of a constituent of the computer system and the threat information based on the threat evaluation score (SATO [0092] "… The element name 502 selected here becomes the asset as the attack target in the attack route information 1100, and is stored in the attack target 1102."); and
selecting the attack strategy and technique information that realizes threat content of the selected threat information for the selected constituent (SATO [0097] "… generates a plurality of test scenarios in which a combination of the constituent elements and the attack classification is arranged in an order of the entry routes …").
Regarding claim 15:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: applying at least one countermeasure to the computer system based on the generated attack scenarios, wherein the at least one countermeasure is selected from the group consisting of malware countermeasure, authority management, and physical access restriction (GANOR [0024] "… the system may provide recommendations to mitigate the threats via a GUI and/or automatically initiate measures to mitigate the threat, such as automatically re-deploy network security equipment …").
Applying countermeasures to a target system is a known technique in the art, as demonstrated by GANOR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the countermeasure application of GANOR with the motivation to react to attacks deemed successful against the target system, rather than limiting the testing system to scenario generation. This is a known technique which has been used to improve similar devices.
Regarding claim 16:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: executing narrowing processing on the attack strategy and technique information based on system configuration information of the computer system to reduce a number of combinations of attack strategy and attack technique to be evaluated, thereby reducing computational resources required for generating the attack scenarios (SATO [0056] "… with an attack based a combination of multiple attacks, the combination patterns of the attack can be limited based on the type of attack that affects the product.").
Regarding claim 17:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: configuring security settings of at least one constituent of the computer system based on the generated attack scenarios, wherein the security settings include at least one of malware countermeasure settings and authority management settings (GANOR [0024] "… the system may provide recommendations to mitigate the threats via a GUI and/or automatically initiate measures to mitigate the threat, such as automatically re-deploy network security equipment …").
Applying countermeasures to a target system’s configuration is a known technique in the art, as demonstrated by GANOR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the countermeasure application of GANOR with the motivation to react to attacks deemed successful against the target system, rather than limiting the testing system to scenario generation. This is a known technique which has been used to improve similar devices.
Regarding claim 18:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: outputting the generated attack scenarios as a file for use in penetration testing of the computer system (SATO [0056] "… The combination patterns of that attack are stored in the scenario pattern 802.").
Regarding claim 20:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1, further comprising: updating system configuration information stored in the storage device based on the generated attack scenarios to reflect implemented countermeasures, ([0059] "… the system configuration database 108 is updated every time the attack means on the attack target system is executed …") and
regenerating attack scenarios based on the updated system configuration information ([0069] "In step S107, the score value calculation unit 110 recalculates the score value of each attack means based on the system configuration of the attack target system …").
Updating system configurations based on attack scenarios and recalculating scenarios after changes to the configuration is a known technique in the art, as demonstrated by KITO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the system configuration updating and scenario regeneration of KITO with the motivation to ensure that applied countermeasures are actually capable of mitigating the scenarios, and to ensure that additional scenarios are not successful against the target system. This is a known technique which has been used to improve similar devices.
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over SATO et al (Doc ID US 20200311284 A1), GANOR (Doc ID US 20180375892 A1), and KITO et al (Doc ID US 20230137325 A1) as applied to claim 1 above, and further in view of CASHIN (Doc ID US 8683598 B1).
Regarding claim 11:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1,
CASHIN teaches the following limitation(s) not taught by the above combination:
wherein the threat evaluation score is calculated by assigning higher evaluation points to constituents having higher security risks based on their device roles (CASHIN (9) Col 3 lines 19-22 "This security score provides a mechanism to quantify the difference in security posture between user devices with a same software configuration, but taking different actions, within an organization.").
Assessing different device roles with different evaluation scores is a known technique in the art, as demonstrated by CASHIN. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the device role scoring adjustment of CASHIN with the motivation to reflect differences in security posture of different devices in their respective evaluations.
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over SATO et al (Doc ID US 20200311284 A1), GANOR (Doc ID US 20180375892 A1), and KITO et al (Doc ID US 20230137325 A1) as applied to claim 1 above, and further in view of ASHKENAZY et al (Doc ID US 10382473 B1).
Regarding claim 13:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1,
ASHKENAZY teaches the following limitations not taught by the combination of SATO, GANOR, and KITO:
wherein a strategy evaluation point is calculated by multiplication or a difference in the respective evaluation scores, which serve as technical evaluation points, of corresponding attack techniques, ((48) Col 27 lines 58-63 "… For each given path of attack, determine the cost of exploitation of the given path of attack to be the sum of the costs of exploitation of all attacker steps included in the given path of attack.") and
wherein the attack strategy and technique information may alternatively be selected by comparing the strategy evaluation point to the predetermined threshold ((93) Col 17 lines 9-12 "… the second Boolean condition is true if and only if the sum of remediation costs of all members of the list of attacker steps satisfies one member of the conditions group consisting of: higher than a pre-determined threshold …").
Using various previous evaluations to determine a total score for an evaluation is a known technique in the art, as demonstrated by ASHKENAZY. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the scoring system of ASHKENAZY with the motivation to use a more granular system which gives weight to the smaller details of the assessment.
Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over SATO et al (Doc ID US 20200311284 A1), GANOR (Doc ID US 20180375892 A1), and KITO et al (Doc ID US 20230137325 A1) as applied to claim 6 above, and further in view of MACHADO et al (Doc ID US 11256828 B1).
Regarding claim 14:
The combination of SATO, GANOR, and KITO teaches:
The scenario generation device according to claim 6, wherein the attack strategy and technique evaluation unit calculates the evaluation point indicating a risk based on device role information and malware countermeasure information, wherein the malware countermeasure information is a type of countermeasure status, of each constituent, (GANOR [0091] "… Cyber risk management and strategic planning logic 330 may then generate an asset risk exposure score for each of the assets …") and
Calculating an additional score based on a device role is a known technique in the art, as demonstrated by GANOR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the device role scoring adjustment of GANOR with the motivation to reflect differences in security posture of different devices in their respective evaluations.
MACHADO teaches the following limitations not taught by the above combination:
wherein constituents having a device role of data saving are assigned higher evaluation points indicating a risk for data-related threats ((29) Col 8 lines 14-29 "... the discovery engine 106 may be configured to generate a risk score … based on the device type .… a higher risk score indicates that that device is transmitting relatively more data and/or more sensitive types of data.").
Assigning a higher risk (threat) score to a device engaged in data operations is a known technique in the art, as demonstrated by MACHADO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the device role scoring of MACHADO with the motivation to give greater weight to the risk assessed for a device which engages in data operations.
Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over SATO et al (Doc ID US 20200311284 A1), GANOR (Doc ID US 20180375892 A1), and KITO et al (Doc ID US 20230137325 A1) as applied to claim 1 above, and further in view of ATTAR et al (Doc ID US 20210288995 A1).
Examiner notes that the subject matter of this new claim is not supported by the foreign application relied upon for the instant application’s effective filing date. This claim is assigned the effective filing date of the date on which the instant application was filed.
Regarding claim 13:
The combination of SATO, GANOR, and KITO teaches:
The cyber attack scenario generation method according to claim 1,
ATTAR teaches the following limitations not taught by the above combination:
further comprising: allocating security resources to constituents of the computer system based on the total evaluation scores of the generated attack scenarios, wherein constituents targeted by attack scenarios having higher total evaluation scores are allocated greater security resources ([0147] "In operation 414, risk scores … may be utilized to prioritize actions that should be taken in order to prevent an attacker from taking advantage of the different vulnerabilities …").
Prioritizing mitigation actions in response to penetration testing results is a known technique in the art, as demonstrated by ATTAR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the cyber-attack scenario generator of SATO, GANOR, and KITO with the security response prioritization of ATTAR with the motivation to ensure that the most vulnerable systems are attended to first. This is a well-known technique which has been used to improve similar devices.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
CRABTREE et al (US 20220201042 A1) teaches a similar system of cyber-attack scenario generation. However, CRABTREE probes vulnerabilities in order to decide which attacks to use, instead of the attack strategy retrieval claimed in the instant application.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703)756-4528. The examiner can normally be reached M-F 0800-1700.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BB/Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437