Prosecution Insights
Last updated: August 15, 2026
Application No. 18/069,019

RISK MANAGEMENT SECURITY SYSTEM

Final Rejection §103
Filed
Dec 20, 2022
Priority
Jan 24, 2022 — provisional 63/302,284
Examiner
SHINGLES, KRISTIE D
Art Unit
2453
Tech Center
2400 — Computer Networks
Assignee
Living Security Inc.
OA Round
5 (Final)
82%
Grant Probability
Favorable
6-7
OA Rounds
0m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
656 granted / 797 resolved
+24.3% vs TC avg
Moderate +13% lift
Without
With
+13.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
33 currently pending
Career history
832
Total Applications
across all art units

Statute-Specific Performance

§101
7.2%
-32.8% vs TC avg
§103
39.0%
-1.0% vs TC avg
§102
45.2%
+5.2% vs TC avg
§112
3.3%
-36.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 797 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Response to Amendment Claims 1, 4, 7, 9, 12-13 and 17 have been amended. Claims 1-20 are pending. Response to Arguments Applicant's arguments filed 6/15/2026 have been fully considered but they are not persuasive. The prior art citations for the rejected limitations have been updated with respect to the amended claim language. CLAIM REJECTIONS - 35 USC § 103 II. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. III. CLAIMS 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over COFFEY et al (USPN 11,171,980) in view of LAWSON (USPN 11,985,142) and XIE et al “Using Bayesian Networks for Cyber Security Analysis”. a. Per claim 1, COFFEY et al teach a method comprising: performing a risk evaluation via a risk management security platform (RMSP), including (col.8 line 43-col.9 line 2, col.10 line 23-col.11 line 3—risk management service and security analytics system that performs risk assessment operations): receiving activity data for a risk-oriented event corresponding to a user participant (col.10 lines 4-22, col.10 line 52-col.11 line 31, col.24 line 52-col.26 line 29—receiving user behavior and interaction, mouse activity and web browsing activity data for risk analytics); generating an insight as an output providing an evaluation of risk for the user participant in a risk category based on the activity data (Figure 8 steps 803-804, col.13 line 55-col.14 line 41, col.25 line 47-col.26 line 16, col.26 lines 30-65, col.29 line 66-col.30 line 39—evaluating risk for the user as anomalous, abnormal, unexpected or malicious based on the activity data; evaluating the electronic data and communications inputs for purposes of identifying high risk behavior by a user, performing an event risk analysis on events performed by an entity to assign corresponding risk scores); generating a risk score for the user participant based on the insight (Figure 8 step 805, col.30 lines 40-52—assigning risk scores based on risk analytics service associated with user’s behavior); and providing a notification based on the risk score (Figure 8 step 806, col.29 lines 3-52, col.30 line 53-col.31 line 7—propagating user’s risk scores to other users serves as a notice). COFFEY et al teach the limitations, as applied above, risk assessments that automatically provision auto-prevention policies enforcement tools, propagating user’s risk scores to other users (col.29 lines 3-52) and assigning risk scores based on risk analytics service associated with user’s behavior (col.17 line 1-col.18 line 18, col.26 line 30-col.27 line 15) , yet fail to explicitly teach “generating a risk score for the user participant based on the insight via a causal belief network (CBN), wherein the CBN comprises: wherein the CBN comprises: a plurality of input nodes corresponding to the activity data, a plurality of internal nodes configured to generate the insight based on causal relationships with the input nodes, and an output node configured to generate the risk score based on causal relationships with the plurality of internal nodes”. However, LAWSON using a Bayesian probabilistic analysis and framework for anomaly detection and cybersecurity analysis using input from raw sources of data, external and internal sources; performing analysis of internal and external data including readout from machine learning models; learning the normal ‘pattern of life’ for internal and external address identities in connection with the rest of the network and training the model from devices, users, behavior and activities, network flow traffic, outputs from one or more cyber security analysis tools analyzing the system, etc. (col.5 lines 57-64, col.7 lines 21-36, col.10 lines 30-47, col.12 line 50-col.13 line 35). The Bayesian probabilistic analysis provisioned in LAWSON teaches generating anomaly scores and threat values using Bayesian probabilistic analysis and discovery of true associations between different network components for modeling (col.16 lines 20-29 and 34-42, col.17 line 50-col.18 line 15), generating notifications and alerts based on the anomaly score (col.10 lines 30-67) and using Bayesian probabilistic analysis to identify meaningful relationships within data and quantifying the associated uncertainty by employing probabilistic scoring related to malign categories (col.27 lines 33-65). LAWSON further teaches using an intelligent-adversary simulator cooperating with a network module and network probes ingesting traffic data for network devices and network users in the network under analysis with machine learning models trained on a normal behavior of users, devices, peers, relationships among entities, and interactions between them, on a network to factor this network analysis into determining the threat risk parameter and analyzing behavior in the context of other similar network devices (col.5 lines 52-56, col.8 lines 12-24, col.17 lines 1-31). A Bayesian Network (also known as a Bayes network, belief network, or decision network) is a probabilistic graphical model that represents a set of variables and their conditional dependencies via a directed acyclic graph (DAG). This model is used for representing and solving problems that involve uncertainty and probabilistic events, which qualifies as a causal belief network. XIE et al teach the use of a causal belief network (i.e, a Bayesian network) for cyber security analysis. In particular, XIE et al (see the bridging paragraph of the left and right column, on page 212) describes that a “Bayesian network (BN) is a graphical representation of cause-and-effect relationships within a problem domain. More formally, a Bayesian network is a Directed Acyclic Graph (DAG) in which: the nodes represent variables of interest (propositions); the directed links represent the causal influence among the variables”. XIE et al describe a BN-based tool to measure network security risk (see section 3, on pages 216-217). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention to combine the teachings of COFFEY et al with LAWSON and XIE et al for the purpose of provisioning: notifications/alerts based on the risk/threat or scores via a Bayesian probabilistic framework that correlates causal links, wherein Bayesian networks are well-known in the art to model probabilities for risk analysis from activity data of a plurality of input devices, probes, internal and external sources related to the activity data in order to analyze and output data based on causal relationships with the input devices and peer associations. Furthermore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use a causal belief network (i.e., a Bayesian network) to determine network security risk as in XIE et al in the invention of COFFEY et al because the experimental results of XIE et al “show that using Bayesian networks may bring in new opportunities for improved enterprise security analysis” (see the last paragraph in section 6, on page 220), that “[o]ur work makes use of the output of intrusion detectors and incorporates it into a holistic security analysis framework” and that “[o]ur BN model address a wider range of security analysis, most importantly the problem of real-time situation awareness” (see the first and second paragraphs of section 5). Claims 9 and 17 contain limitations that are substantially equivalent to the limitations of claim 1, and are therefore rejected under same basis. As per claim 9, it is rejected for similar reasons as given for claim 1. COFFEY et al further teach an apparatus (information handling system 100, at Figure 1, and col.3 lines 13-15, which describes that “FIG. 1 is a generalized illustration of an information handling system that can be used to implement selected embodiments of the present disclosure”) comprising: a processor (CPU 102, at figure 1, and col.3 lines 16-17) configured to implement a risk management security platform to perform a risk evaluation (see col.3 lines 34-51, which describes that “[i]n various embodiments, the contagion risk analysis system 118 performs a contagion-based risk analysis operation). As per claim 17, COFFEY et al further teach a memory device storing instructions, that when executed, cause a processor (see col.32, lines 8-37, which describes that “[e]mbodiments of the invention are described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention). It will be understood that each block of the flowchart illustrations and/or block diagrams, and combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. b. Per claim 2, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, LAWSON further teaches the risk evaluation further including: grouping a plurality of user participants having a shared attribute into a segment; evaluating a risk trend for the segment based on the risk score for the plurality of user participants; and generating the notification regarding the risk trend for the segment (col.7 lines 61-67, col.9 line 64-col.10 line 6, col.10 lines 30-67, col.11 lines 15-22—identifying key patterns and trends in the data, evaluating and analyzing metrics to combine with patterns of behavior and life data, combining sets of metrics based on anomaly scores and threat alerts). Claims 10 and 19 contain limitations that are substantially equivalent to the limitations of claim 2, and are therefore rejected under same basis. c. Per claim 3, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, COFFEY et al further teach the risk evaluation further including: generating the risk score based on a probabilistic graphical model (col.14 lines 34-49, col.15 lines 22-43, col.15 line 56-col.16 line 67, col.17 lines 20-55—risk score and probability distribution function and temporal models for quantifying risk assessment; LAWSON: col.8 lines 50-63, col.12 line 50-col.13 line 19—Bayesian probabilistic analysis modeling, Bayesian network (BN) is a graphical representation of cause-and-effect relationships within a problem domain, graphically rendering anomaly scores). d. Per claim 4, COFFEY et al with LAWSON and XIE et al teach the method of claim 3, LAWSON further teaches the method further comprising: wherein the insight comprises a human-parsable explanation identifying at least one causal factor contributing to the risk score (col.5 line 57-col.6 line 64, col.7 lines 1-45—gathering data and feedback to form hypothesis that either support or refute the potential threat or suspicious activity; col.8 lines 25-49, col.9 lines 15-28—correlating causal links between activities to supply this input into the cyber-threat module, which can also factor this network activity link to a particular email causal link analysis into its determination of the threat risk parameter; cyber threat defense system monitoring email activity and network activity to feed this data to correlate causal links between these activities to supply this input into the cyber threat analysis; col.23 line 50-col.24 line 32—enabling the output of a prediction about the category of an email being analyzed using a learned hypothesis and including focused response actions selectable through the user interface; col.27 lines 12-24—utilizing human operator to for confirmation response). Claim 12 contains limitations that are substantially equivalent to the limitations of claim 4, and are therefore rejected under same basis. e. Per claim 5, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method further comprising: modeling the plurality of internal nodes and the output node based on conditional probability tables, with a conditional probability table defining a probability of a value for a corresponding node based on values from parent nodes that provide causal input to the corresponding node (col.7 lines 28-36, col.9 lines 39-44—assigning probability of a given cyber threat hypothesis including abnormal behavior or suspicious activity, modeling including threat risk parameter score or probability indicative of the threat level; col.12 lines 50-61, col.16 lines 34-42—Bayesian mathematical model and probabilistic approach for detecting behavioral change in computers). Claims 13 and 18 contain limitations that are substantially equivalent to the limitations of claim 5, and are therefore rejected under same basis. f. Per claim 6, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method further comprising: modeling the CBN to include: a first input node representing the activity data for the user participant; and a second input node representing a risk modifier value for the user participant, wherein certain values for the second input node amplify a risk associated with the first input node (col.7 lines 28-36, col.9 lines 39-44—assigning probability of a given cyber threat hypothesis including abnormal behavior or suspicious activity, modeling including threat risk parameter score or probability indicative of the threat level; col.12 lines 50-61, col.16 lines 34-42—Bayesian mathematical model and probabilistic approach for detecting behavioral change in computers; col.23 lines 41-49—using a k-mean s model applied to a modified term frequency). g. Per claim 7, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method wherein: each of the plurality of internal nodes corresponds to a respective risk category and generates a respective insight explaining a contribution of the activity data to the risk score; and the output node aggregates outputs of the plurality of internal nodes to generate the risk score representing an aggregate risk across a plurality of risk categories (col.2 lines 11-67, col.10 lines 48-58, col.23 lines 50-59—classifying and categorizing of threat risk for determining score, metrics are combined and passed through machine learning algorithms to produce a single anomaly score; col.18 line 64-col.20 line 29—Likely Recipient Classifier wherein given recipient may be considered to be a label/class/category identifying the outbound emails that are sent to that recipient email address, plurality of metrics/characteristics may be extracted from each email, the rarer the characteristics are, then the more weight is given to those specific characteristics as key indicators, considering each of these known recipients in turn and determining a score associated with the probability of a match between the characteristics extracted from the draft email and the key identifiers for each known recipient, the Likely Recipient Classifier may determine the known recipient with the highest probability of a match for the draft email, who may be referred to as the expected recipient). h. Per claim 8, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, LAWSON further teaches the risk evaluation further including: implementing an action plan to reduce risk, including: identifying activity data having a value that corresponds to elevated risk; accessing a data structure of remedial actions based on a type of the activity data; and implementing a remedial action associated with the type of the activity data (col.3 lines 1-20, col.7 lines 61-67, col.8 line 33-col.9 line 14, col.9 lines 39-44, col.24 line 45-col.25 line 61—determining categories and types of cyber threats, threat levels, threshold exceeded event and appropriate response actions, autonomous action and response module implements actions to reduce risks; COFFEY et al: col.29 lines 3-52—automatically provision auto-prevention policies enforcement tools). Claims 16 and 20 contain limitations that are substantially equivalent to the limitations of claim 8, and are therefore rejected under same basis. i. Per claim 11, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 9, LAWSON further teaches comprising the processor further configured to: implement an integration service to gather and normal the activity data, including: obtain the activity data from a plurality of third-party sources via application program interface (API) calls; and convert the activity data from source formats corresponding to each of the plurality of third-party sources into a standard format; and store the activity data in the standard format to a data structure (col.6 lines 54-59, col.12 lines 10-17, col.25 lines 3-19—Open Source APIs, conversion of data into a safe format and storage). j. Per claim 14, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 10, LAWSON further teaches comprising the processor further configured to: implement a notification service to provide the notification, including: determine to provide a notification based on the risk score; generate a human-parsable notification message based on the risk score; and select a notification medium from a plurality of notification mediums by which to provide the notification (col.10 lines 30-67, col.26 lines 35-44—generating notifications and alerts based on the anomaly score, types of notifications triggered by anomalies). k. Per claim 15, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 10, LAWSON further teaches comprising the processor further configured to: receive a user request for information via a web application; and provide information regarding the insight via the web application (col.28 lines 46-60—receiving client request via web browser based applications; COFFEY et al—col.9 line 16-col.10 line 37, col.10 line 53-col.11 line 3, col.26 lines 52-65—user behavior information associated with user request). Conclusion IV. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 20240163312, US 2017/0359220. V. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. VI. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KRISTIE D SHINGLES whose telephone number is (571)272-3888. The examiner can normally be reached on Monday-Thursday 10am-7pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal Divecha can be reached on 571-272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KRISTIE D SHINGLES/ Primary Examiner, Art Unit 2453
Read full office action

Prosecution Timeline

Show 2 earlier events
Feb 21, 2025
Response Filed
Apr 09, 2025
Examiner Interview (Telephonic)
Apr 29, 2025
Non-Final Rejection mailed — §103
Jul 18, 2025
Response Filed
Mar 05, 2026
Non-Final Rejection mailed — §103
Mar 16, 2026
Non-Final Rejection mailed — §103
Jun 15, 2026
Response Filed
Jul 29, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701178
SYSTEMS AND METHODS FOR MULTI-CLIENT CONTENT DELIVERY
1y 11m to grant Granted Aug 04, 2026
Patent 12689596
METHODS AND SYSTEMS FOR REGULATING NETWORK CONNECTIVITY FROM A GATEWAY
2y 0m to grant Granted Jul 21, 2026
Patent 12683939
DEVICE AND A METHOD FOR THE DEVICE
2y 2m to grant Granted Jul 14, 2026
Patent 12683980
STREAMING AND FILTERING EVENT OBJECTS INTO A DATA LAKE
1y 10m to grant Granted Jul 14, 2026
Patent 12665927
SYSTEMS AND METHODS FOR INTERCEPTING CONVERGENT DATA STREAMS
2y 6m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

6-7
Expected OA Rounds
82%
Grant Probability
96%
With Interview (+13.4%)
2y 10m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 797 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month