Prosecution Insights
Last updated: October 02, 2026
Application No. 18/055,180

DETECTING VULNERABILITIES IN CONFIGURATION CODE OF A CLOUD ENVIRONMENT UTILIZING INFRASTRUCTURE AS CODE

Non-Final OA §101§103
Filed
Nov 14, 2022
Priority
Nov 24, 2021 — provisional 63/264,550 +3 more
Examiner
SWIFT, CHARLES M
Art Unit
2100
Tech Center
2100 — Computer Architecture & Software
Assignee
Wiz Inc.
OA Round
2 (Non-Final)
81%
Grant Probability
Favorable
2-3
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
726 granted / 900 resolved
+25.7% vs TC avg
Strong +23% interview lift
Without
With
+22.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
38 currently pending
Career history
939
Total Applications
across all art units

Statute-Specific Performance

§101
11.1%
-28.9% vs TC avg
§103
57.2%
+17.2% vs TC avg
§102
16.3%
-23.7% vs TC avg
§112
6.1%
-33.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 900 resolved cases

Office Action

§101 §103
DETAILED ACTION This office action is in response to arguments/amendments filed on 9/10/2025. Claim 20 is added. Claims 1 – 20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1 – 20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea of mental processes without significantly more. Claims 1, 10 and 11: Under Prong 1, the claimed limitations of “querying a security graph to detect a node having an attribute value which matches a value extracted from a first code object of the plurality of code objects, wherein the security graph includes a representation of a cloud computing environment;” and “and generating a mitigation action in response to determining that the detected node is associated with a cybersecurity issue.” are functions that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Under prone 2, the additional elements “for deploying instances in a cloud computing environment" merely recite instructions to implement an abstract idea on a generic computer, or merely uses a generic computer or computer components as a tool to perform the abstract idea, thus is not a practical application under Prong 2, or amount to significantly more than the judicial exception under Step 2B. See MPEP 2106.05(f). The additional elements “accessing a configuration code, the configuration code including a plurality of code objects, each code object of the plurality of code objects corresponding to a deployable virtual instance;” merely recite insignificant extra solution activity such as gathering, displaying, updating, transmitting and storing data which does not integrate the judicial exception into a practical application under Prong 2. See MPEP 2106.05(g). Under Step 2B, the courts have identified functions such as gathering, displaying, updating, transmitting and storing data as well-understood, routine, conventional activity, thus do not amount to significantly more than the judicial exception. See MPEP 2106.05(d). Accordingly, the claim is not patent eligible under 35 USC 101. Claims 2 and 12: Regarding claims 2 and 12, the limitation “deploying a virtual instance based on the first code object in response to determining that the detected node is not connected to a node representing a cybersecurity issue.” is function that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claims 3 and 13: Regarding claims 3 and 13, the limitation “generating an alert based on the cybersecurity issue” merely recite instructions to implement an abstract idea on a generic computer, or merely uses a generic computer or computer components as a tool to perform the abstract idea, thus is not a practical application under Prong 2, or amount to significantly more than the judicial exception under Step 2B. See MPEP 2106.05(f).. Claims 4 and 14: Regarding claims 4 and 14, the limitation “detecting in the configuration code a data field of a code object having any one of: a string, and a value.” is function that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claims 5 and 15: Regarding claims 5 and 15, the limitation “wherein the data field represents any one of: a private key identifier, a public key identifier, a policy identifier, a user account identifier, a service account identifier, a version identifier, and a resource type identifier.” merely further define the “data field of a code object” detected in claim 4, thus is also analyzed under prong 1 as a mental process. Claims 6 and 16: Regarding claims 6 and 16, the limitation “generating a query directed at the security graph, the query including an identifier of the first code object.” is function that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claims 7 and 17: Regarding claims 7 and 17, the limitation “wherein the identifier is any one of: a user account identifier, a service account identifier, a version identifier, and a resource type identifier.” merely further define the “data field of a code object” detected in claim 4, thus is also analyzed under prong 1 as a mental process. Claims 8 and 18: Regarding claim 8, the limitation “traversing the security graph to detect a node, wherein the node represents the first code object, wherein a node representing the first code object includes a data field value which matches with a data field value of the first code object.” is function that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claims 9 and 19: Regarding claim 9, the limitation “wherein a cybersecurity risk is represented by a risk node in the security graph, and the detected node is connected to the risk node.” is function that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claim 20: Regarding claim 20, the limitations “identifying a code author based on an identifier in the configuration code;” and “generating a notification to the code author to update an outdated software version, wherein the outdated software version is associated with the cybersecurity issue;” are functions that can be reasonably carried out in the human mind with the aid of pen and paper, through observation, evaluation, judgment, opinion, thus it is reasonable to identify these limitation as reciting a mental process. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 2, 4 – 12 and 14 – 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Burle et al (US 20210234889, prior art part of IDS dated 4/11/2024, hereinafter Burle), in view of Carpenter et al (US 20170026416, hereinafter Carpenter). As per claim 1, Burle discloses: A method for detecting a vulnerable code object in configuration code for deploying instances in a cloud computing environment, comprising: querying a security graph to detect a node having an attribute value which matches a value extracted from a first code object of the plurality of code objects, wherein the security graph includes a representation of a cloud computing environment; (Burle [0061] “scanning the networked computer system (e.g., networked computer system 100) to identify one or more vulnerable computer resources (e.g., Vulnerable Resource Nos. 1-M 21). The scanning may be performed by commercially-available vulnerability detection and reporting systems”; [0062]: “conducting a graph-based reachability analysis (202) of networked computer system 100 showing paths to different computer resources in the networked computer system that are accessible from the vulnerable computer resources 21. Method 200 may include, based on the graph-based reachability analysis 202, determining a blast radius of each vulnerable computer resource (203) in the networked computer system.”; [0063]: “After the blast radius of a vulnerable computer resource has been determined, method 200 may include determining if any critical computer resources are impacted (204) by the vulnerable computer resource.”.) and generating a mitigation action in response to determining that the detected node is associated with a cybersecurity issue. (Burle [0065]: “If one or more critical computer resources are impacted (i.e., the one or more critical computer resources are within the blast radius of the vulnerable computer resource), method 200 may include identifying a remediation action on the vulnerable computer resource (206).”; [0069]: “building remediation action chains (i.e., a series of one or more remediation actions) including the previously determined safe remediation actions (e.g., first layer remediation at 208, and second, third, and nth layer remediations at 209) for each of computer resources 21 that have security vulnerabilities.”; [0070]: “executing or implementing the remediation action chains (211).”.) Burle did not explicitly disclose: accessing a configuration code, the configuration code including a plurality of code objects, each code object of the plurality of code objects corresponding to a deployable virtual instance; However, Carpenter teaches: accessing a configuration code, the configuration code including a plurality of code objects, each code object of the plurality of code objects corresponding to a deployable virtual instance; (Carpenter figure 3 and [0025]: “developers may use “Infrastructure-as-Code” (IaC) to specify and create an IT environment. In particular, an IaC template 302 may be parsed, a graphical representation 304 generated, and a static analysis report 306 generated using static analysis. IaC encodes the parameters of a specific IT in a template that enables the IaaS platform to create an environment on-demand. A portion of an example template is shown in the IaC template 302 of FIG. 3. As shown, the IaC template 302 lists several fields to the left of the colon (:) and values for those fields to the right of the colon. These fields and values are parsed and represented as a graph 304 (e.g., by the server 140), which may be stored as a graph database in the data repository 150.”) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching Carpenter into that of Burle in order to access a configuration code, the configuration code including a plurality of code objects, each code object of the plurality of code objects corresponding to a deployable virtual instance. Burle [0061] teaches scanning the resource list for a vulnerable resource, one of ordinary skill in the art can easily recognize that the scanning process can be improved by having an up-to-date configuration of full list of resources available before the scanning step, such combination would improve the overall appeals of all references by making the vulnerability scanning process more efficient and accurate, and is therefore rejected under 35 USC 103. As per claim 2, the combination of Burle and Carpenter further teach: The method of claim 1, further comprising: generating an alert based on the cybersecurity issue. (Carpenter [0045].) As per claim 4, the combination of Burle and Carpenter further teach: The method of claim 1, further comprising: detecting in the configuration code a data field of a code object having any one of: a string, and a value. (Carpenter figure 3 and [0025].) As per claim 5, the combination of Burle and Carpenter further teach: The method of claim 4, wherein the data field represents any one of: a private key identifier, a public key identifier, a policy identifier, a user account identifier, a service account identifier, a version identifier, and a resource type identifier. (Carpenter [0024] and [0029]: version.) As per claim 6, the combination of Burle and Carpenter further teach: The method of claim 1, further comprising: generating a query directed at the security graph, the query including an identifier of the first code object. (Carpenter [0057].) As per claim 7, the combination of Burle and Carpenter further teach: The method of claim 6, wherein the identifier is any one of: a user account identifier, a service account identifier, a version identifier, and a resource type identifier. (Carpenter [0024] and [0029]: version.) As per claim 8, the combination of Burle and Carpenter further teach: The method of claim 1, further comprising: traversing the security graph to detect a node, wherein the node represents the first code object, wherein a node representing the first code object includes a data field value which matches with a data field value of the first code object. (Burle [0061] – [0063].) As per claim 9, the combination of Burle and Carpenter further teach: The method of claim 1, wherein a cybersecurity risk is represented by a risk node in the security graph, and the detected node is connected to the risk node. (Burle [0061] – [0063]: blast radius.) As per claim 10, it is the non-transitory computer readable medium variant of claim 1 and is therefore rejected under the same rationale. (Burle [0135]: CRM) As per claim 11, it is the system variant of claim 1 and is therefore rejected under the same rationale. (Burle [0009]) As per claim 12, it is the system variant of claim 2 and is therefore rejected under the same rationale. As per claim 14, it is the system variant of claim 4 and is therefore rejected under the same rationale. As per claim 15, it is the system variant of claim 5 and is therefore rejected under the same rationale. As per claim 16, it is the system variant of claim 6 and is therefore rejected under the same rationale. As per claim 17, it is the system variant of claim 7 and is therefore rejected under the same rationale. As per claim 18, it is the system variant of claim 8 and is therefore rejected under the same rationale. As per claim 19, it is the system variant of claim 9 and is therefore rejected under the same rationale. Claim(s) 3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Burle and Carpenter, and further in view of Lin et al (US 20210208983, hereinafter Lin). As per claim 3, the combination of Burle and Carpenter did not teach: The method of claim 1, further comprising: deploying a virtual instance based on the first code object in response to determining that the detected node is not connected to a node representing a cybersecurity issue. However, Lin teaches: The method of claim 1, further comprising: deploying a virtual instance based on the first code object in response to determining that the detected node is not connected to a node representing a cybersecurity issue. (Lin [0013]: “The ability to predict faulty nodes may enable cloud service systems to allocate VMs to healthier nodes, therefore reducing the occurrences and duration of VM down time caused by node failures.”) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching Lin into that of Burle and Carpenter in order to deploy a virtual instance based on the first code object in response to determining that the detected node is not connected to a node representing a cybersecurity issue. Burle [0061] teaches scanning the resource list for a vulnerable resource. Lin [0013] teaches that one can reduce the occurrences and duration of VM downtime by deploying VM on healthy nodes after predicting faulty nodes, such combination would result in better overall health of the deployment system and is therefore rejected under 35 USC 103. As per claim 13, it is the system variant of claim 3 and is therefore rejected under the same rationale. Claim(s) 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Burle and Carpenter, and further in view of A et al (USPAT 11379294, hereinafter A). As per claim 20, the combination of Burle and Carpenter further reach: The method of claim 1, further comprising: and initiating the mitigation action on the configuration code to mitigate the cybersecurity issue. (Burle [0070]) The combination of Burle and Carpenter did not explicitly teach: identifying a code author based on an identifier in the configuration code; generating a notification to the code author to update an outdated software version, wherein the outdated software version is associated with the cybersecurity issue; However, A teaches: identifying a code author based on an identifier in the configuration code; generating a notification to the code author to update an outdated software version, wherein the outdated software version is associated with the cybersecurity issue; (A col 3, lines 42 – 58.) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching A into that of Burle and Carpenter in order to identify a code author based on an identifier in the configuration code; generating a notification to the code author to update an outdated software version, wherein the outdated software version is associated with the cybersecurity issue. A col 3, lines 42 – 58 teaches doing so would “expedite the development fixes (i.e., patches) and reduce application downtime”, such combination would result in better overall health of the deployment system and is therefore rejected under 35 USC 103. Response to Arguments Applicant's arguments filed 10 9/10/2025 on 35 USC 101 rejection of claims 1 – 19 have been fully considered but they are not persuasive as the claims are directed to an abstract idea of mental process, see the 35 USC 101 rejection section above for detailed mappings. Applicant’s arguments, filed 9/10/2025, with respect to the rejection(s) of claim(s) 1 – 19 under 35 USC 103, through the combination of Luttwak and Github have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of 35 USC 103, see appropriate sections above for detailed mappings. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Maor et al (US 20210203684) teaches “The detection of a risky edge in a lateral movement path is detected by determining the weakest point in the configuration of the user accounts, groups, and devices having access to the resources of a tenant of the cloud service. A lateral movement graph having nodes of user accounts, devices, and groups and edges representing relationships between the nodes is used to compute a risk score for each edge in the graph. The risk score of an edge is used to identify a weak connection and potential target for a lateral movement attack.”. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHARLES M SWIFT whose telephone number is (571)270-7756. The examiner can normally be reached Monday - Friday: 9:30 AM - 7PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, April Blair can be reached at 5712701014. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHARLES M SWIFT/Primary Examiner, Art Unit 2196
Read full office action

Prosecution Timeline

Nov 14, 2022
Application Filed
Jun 09, 2025
Non-Final Rejection mailed — §101, §103
Sep 09, 2025
Response after Non-Final Action
Sep 09, 2025
Response Filed
Sep 10, 2025
Response Filed
Aug 18, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730667
SWITCH FOR MANAGING SERVICE MESHES
4y 8m to grant Granted Sep 08, 2026
Patent 12730670
Queue Management for Task Graphs
3y 0m to grant Granted Sep 08, 2026
Patent 12724634
MEDICAL INFORMATION PROCESSING SYSTEM AND MEDICAL INFORMATION PROCESSING METHOD, MEDICAL INFORMATION PROCESSING SERVICE PROVIDING METHOD, AND PROGRAM
2y 12m to grant Granted Sep 01, 2026
Patent 12717614
SYSTEMS AND METHODS FOR COMPLETING TASKS
4y 6m to grant Granted Aug 25, 2026
Patent 12717632
DYNAMIC PROCESSING OF TRANSACTIONS BASED ON PREDICTED COMPUTATION COSTS
3y 1m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
81%
Grant Probability
99%
With Interview (+22.6%)
3y 0m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 900 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month