DETAILED ACTION
This Final Office Action is in response Applicant communication filed on
2/17/2026. In Applicant’s amendment, claims 1 and 11 were amended.
Claims 1-20 are currently pending and have been rejected as follows.
Response to Amendments
Claim objections have been withdrawn. Rejections under 35 USC 101 are maintained. Applicant’s amendments necessitated new grounds of rejection under 35 USC 103.
Response to Arguments
Applicant’s 35 USC 101 rebuttal arguments and amendments have been fully considered but they are not persuasive to overcome the rejection.
Applicant argues on p. 11-16 that the claim is not properly characterized as a mental process under Step 2A, Prong One because the proper inquiry is practical performability, not conceptual analogy, claim 1 recites technical operations that are not practically performable mentally, and because claim 1 merely involves but does not recite an abstract mental process.Examiner respectfully disagrees. Under Step 2A, Prong 1, examiners should determine whether a claim recites an abstract idea by (1) identifying the specific limitation(s) in the claim under examination that the examiner believes recites an abstract idea, and (2) determining whether the identified limitations(s) fall within at least one of the groupings of abstract ideas. Applicant improperly extends this principle to the claim as a whole. the If the identified limitation(s) falls within at least one of the groupings of abstract ideas, it is reasonable to conclude that the claim recites an abstract idea in Step 2A Prong One. The claim then requires further analysis in Step 2A Prong Two, to determine whether any additional elements in the claim integrate the abstract idea into a practical application. A claim requiring a computer may still recite a mental process, see MPEP 2106.04(a)(2)(III). The computer functions called out by the applicant to not be performable mentally are considered as additional elements at Step 2A, Prong Two. Examiner further submits, the claim remains directed to certain methods of organizing human activity like managing personal behavior or relationships characterized by the creation and execution of a test intended to entice users to evaluate compliance and susceptibility, which applicant does not contend in the response.
Applicant argues on p. 16-17 that the claim is eligible under Step 2A, Prong Two because the claim recites automated cybersecurity remediation, recites a technical dataflow and integration with user records, the claim as a whole analysis is improper, and because the claim recites more than generic computer use.Examiner respectfully disagrees. The claimed “automatically initiating, by a training unit of the server based at least on the benchmarking and to improve cybersecurity of an organization, to at least one of limit access of the user to one or more information technology functions of the organization or provide electronic cybersecurity training to a user interface on a second display device of the user based at least on the benchmarking” is merely a high level system instruction to either limit user access to unspecified information technology functions or alternatively delivering training. There is no improvement to a concrete technical mechanism or computer.Regarding the technical dataflow and integration with user records, the claim defines what information moves from one functional stage to another, which amounts to generic storage and retrieval. There is no recited technical improvement to the storage and retrieval of information.Regarding the allegation that the claim as a whole analysis is improper and that the claim recites more than generic computer use, Examiner respectfully submits the additional elements are employed to perform their ordinary functions to carry out the abstract idea. Listing several “units” does not establish several specialized machines. Each unit is defined only by the abstract/ordinary information processing function it performs. Dividing functions among named modules does not create a nonconventional architecture. There is no technical improvement recited.
Applicant's prior art arguments have been fully considered but they are not persuasive to overcome the rejection.
Applicant argues on p. 19 that the combination of Sites and O’Reilly fail to disclose the limitation “scaling, by the determination unit of the security system implemented on the one or more servers the phish-prone percentage to a pre-determined score range, to provide a first value for a security knowledge level of the user.” Examiner respectfully disagrees. The previously cited paragraph [0067] of Sites discusses the risk score derivation and is further demonstrated to be normalized in [0198] “normalized so that 0≤RS≤100” scaling the risk score to be between 0 and 100.
Applicant argues on p. 20 that the combination of Sites and O’Reilly fail to disclose the limitation “determining, by the determination unit of the security system implemented on the one or more servers, a fourth value of a security maturity score of the user based at least on a function of a combination, with one or more weighting factors, the first value for the security knowledge level of the user, the second value for the security awareness level of the user and the third value for the security culture level of the group of user.” Examiner respectfully disagrees. As previously mapped, Sites provides the security knowledge level, security awareness level, and a security culture level. O’Reilly supplies a weighted combination of three scores. An average of three values is a weighted combination with equal weights. The claim requires “one or more weighting factors.” Under the BRI, an equal weighting factor satisfies one weighting factor. Upon further review, Sites also discloses a weighted combination of three values to produce a fourth value and expressly uses the claimed security knowledge level, security awareness level, and a security culture level, see [0193]-[0196] “In step 308, artificial intelligence machine learning system 215 establishes a risk score for the user based at least on the frequency score, the severity score and the propensity score … The function RS(f, p, s) in some embodiments may be represented as a weighted sum of logarithms.”
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are clearly drawn to at least one of the four categories of patent eligible subject matter recited in 35 U.S.C. 101 (method and system). Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without integrating the abstract idea into a practical application or amounting to significantly more than the abstract idea.
Regarding Step 1 of the 2019 Revised Patent Subject Matter Eligibility Guidance (‘2019 PEG”), Claims 1-10 are directed toward the statutory category of a “process” (reciting a “method”).Claims 11-20 are directed toward the statutory category of a machine (reciting a “system”).
Regarding Step 2A, prong 1 of the 2019 PEG, Claims 1 and 11 are directed to an abstract idea by reciting executing … one or more simulated phishing campaigns to a user … determining, by … and configured to determine one or metrics from results of the one or more simulated phishing campaigns, a phish-prone percentage for the user based at least on a number of times the user failed the one or more simulated phishing campaigns out of a total number of the one or more simulated phishing campaigns, the user failing the one or more simulated phishing campaigns by at least interacting with one of the link or attachment of the one or more simulated phishing messages, …;
scaling, by … the phish-prone percentage to a pre-determined score range, to provide a first value for a security knowledge level of the user;
determining, by … based at least on a rate at which the user interacts with one of the link or the attachment of the one or more simulated phishing messages of the one or more simulated phishing campaigns, a second value for a security awareness level of the user, the … interfacing to the user record to determine the rate at which the user interacted with one of the link or attachment;
determining, by … based at least on a severity of one or more security policies of a group of the user that are applied by the … for failing the one or more simulated phishing campaigns, a third value for a security culture level of a group of the user; determining, by …, a fourth value of a security maturity score of the user based at least on a function of a combination, with one or more weighting factors, the first value for the security knowledge level of the user, the second value for the security awareness level of the user and the third value for the security culture level of the group of user; categorizing, by …, the user into a class of users comprising one or more additional users, wherein the fourth value of the security maturity score of the user falls within a predetermined range of security maturity score values associated with the class of users, the class of users comprising one or more additional users;
benchmarking, by … and configured to execute a comparative analysis of phish prone percentage between users, the phish prone percentage of the user with the phish phone percentage of one or more additional users of the class of users; creating, by … of results of benchmarking by the benchmarking unit, a graphical representation of one or more radar plots to visualize the security maturity score of the user in a single view as a function of the security knowledge level of the user, security awareness level of the user and the security culture level of the group of the user and with an enclosed shaped area within the one or more radar plots providing a comparative metric between users; …
automatically initiating, by … based at least on the benchmarking and to improve cybersecurity of an organization, to at least one of limit access of the user to one or more information technology functions of the organization or provide electronic cybersecurity training to … of the user based at least on the benchmarking (Example claim 1).
The claims are considered abstract because these steps recite mental processes (e.g., observation, evaluation, judgement) and certain methods of organizing human activity like managing personal behavior or relationships. The claims recite steps involving collecting data, analyzing data, categorizing data, displaying results, and limiting user access or providing training based on the results.
Regarding Step 2A, prong 2 of the 2019 PEG, the judicial exception is not integrated into a practical application because the claims (the judicial exception and the additional elements such as a security system implemented on one or more servers and configured to generate and communicate simulated phishing messages to one or more devices of a user that mimic a real phishing message and appear genuine to entice the user to interact with the simulated phishing message; wherein the one or more simulated phishing campaigns comprises one or more simulated phishing messages with one of a link or attachment; a determination unit of the security system implemented on the one or more servers; the server monitoring behavior of the user and storing results of the one or more simulated phishing campaigns in a user record, the determination unit interfacing to the user record to determine that the user interacted with one of the link or attachment; a benchmarking unit of a security system implemented on the one or more servers; a displaying unit of the security system implemented on the one or more servers configured to present graphical representations; displaying, by the displaying unit of the security system implemented on the one or more servers, the graphical representation a display device; a training unit of the server; a user interface on a second display device) are not an improvement to a computer or a technology, the claims do not apply the judicial exception with a particular machine, the claims do not effect a transformation or reduction of a particular article to a different state or thing nor do the claims apply the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment such that the claims as a whole is more than a drafting effort designed to monopolize the exception (see MPEP §§ 2106.05(a-c, e)).
Dependent claims 2-10 and 12-20 do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the limitations recite mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea ‐ see MPEP 2106.05(f).
Regarding Step 2B of the 2019 PEG, the additional elements have been considered above in Step 2A Prong 2. The claim limitations do not amount to significantly more than the judicial exception because they are directed to limitations referenced in MPEP 2106.05I.A. that are not enough to qualify as significantly more when recited in a claim with an abstract idea because the limitations recite mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea ‐ see MPEP
2106.05(f).
Applicant's claims mimic conventional, routine, and generic computing by their similarity to other concepts already deemed routine, generic, and conventional [Berkheimer Memorandum, Page 4, item 2] by the following [MPEP § 2106.05(d) Part (II)]. The claims recite steps like: “Receiving or transmitting data over a network, e.g., using the Internet to gather data,” Symantec, “Performing repetitive calculations,” Flook, and “storing and retrieving information in memory,” Versata Dev. Group, Inc. v. SAP Am., Inc. (citations omitted), by performing steps of “determining” a first value, “determining” a second value, “determining” a third value, “determining” a fourth value, “categorizing” the user, “benchmarking” a phish prone percentage, “creating” a graphical representation, “displaying” the benchmarking results, and “initiating” to limit user access or provide training (example Claim 1).
By the above, the claimed computing “call[s] for performance of the claimed information collection, analysis, and display functions ‘on a set of generic computer components' and display devices” [Elec. Power Group, 830 F.3d at 1355] operating in a “normal, expected manner” [DDR Holdings, LLC v. Hotels.com, L.P., 773 F.3d at 1245, 1258 (Fed. Cir. 2014)].
Conclusively, Applicant's invention is patent-ineligible. When viewed both individually and as a whole, Claims 1-20 are directed toward an abstract idea without integration into a practical application and lacking an inventive concept.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 USC 103 as being unpatentable over the teachings of
Sites et al., US 20190356679 A1, hereinafter Sites,
O'Reilly et al., US 20190124120 A1, hereinafter O'Reilly. As per,
Claims 1, 11
Sites teaches
A method comprising: /
A system comprising: one or more servers comprising: (Sites [0119] “the system 200 includes one or more servers 106, one or more clients 102, and one or more security services providers 210.”)
executing, by a security system implemented on one or more servers and configured to generate and communicate simulated phishing messages to one or more devices of a user that mimic a real phishing message and appear genuine to entice the user to interact with the simulated phishing message, one or more simulated phishing campaigns to a user, wherein the one or more simulated phishing campaigns comprises one or more simulated phishing messages with one of a link or attachment; (Sites [0003] “an email may be sent to a target, the email having an attachment that performs malicious actions when executed or a link to a webpage that either performs malicious actions when accessed or prompts the user to execute a malicious program” note the link and attachment; [0019] “Server 106 may include simulated phishing campaign manager 230;” [0134] “a simulated phishing message can be sent to a large number of users” note the server performing a simulated phishing campaign to users; [0142] “system 200 includes security services provider 210”)
determining, by a determination unit of the security system implemented on the one or more servers and configured to determine one or metrics from results of the one or more simulated phishing campaigns, a phish-prone percentage for the user based at least on a number of times the user failed the one or more simulated phishing campaigns out of a total number of the one or more simulated phishing campaigns, the user failing the one or more simulated phishing campaigns by at least interacting with one of the link or attachment of the one or more simulated phishing messages, the server monitoring behavior of the user and storing results of the one or more simulated phishing campaigns in a user record, the determination unit interfacing to the user record to determine that the user interacted with one of the link or attachment; (Sites [0065] “Sending a reply message in response to receiving a simulated phishing message can be classified as a failure. In embodiments, forwarding a received simulated phishing message can be classified as a failure. … Once the identity of the target has been determined, a record of the target's failure can be stored;” [0119] “Server 106 may include administrator console 295, while may include metrics generator 296, phish-prone percentage calculator 297” note the dedicated calculator for determining a phish-prone percentage for individuals)
scaling, by the determination unit of the security system implemented on the one or more servers the phish-prone percentage to a pre-determined score range, to provide a first value for a security knowledge level of the user; (Sites [0067] “the risk score derivation will be based on training history, phishing history, responses to simulated phishing tests … breach data, user assessment surveys and data which may be obtained from a SIEM;” [0068] “records reflecting user responses to real and simulated phishing attacks may considered in creating the risk score;” [0142] “collectively referred to as a security information and event management system (SIEMS), automates the process of collecting, monitoring and analyzing security-related data from computer logs, including event log data from security devices;” [0143] “SEIMS may use normalization, which means automatically pulling common data items from each event (like who, what, when and where) and storing this subset of information into a common format” noting the normalization of the security event data corresponding to scaling the phish-prone percentage to determine a first value for a security knowledge level)
determining, by the determination unit implemented on the one or more servers based at least on a rate at which the user interacts with one of the link or the attachment of the one or more simulated phishing messages of the one or more simulated phishing campaigns, a second value for a security awareness level of the user, the determination unit interfacing to the user record to determine the rate at which the user interacted with one of the link or attachment; (Sites [0119] “Server 106 may include simulated phishing campaign manager 230, which may include a storage for simulated phishing messages 232, event tracker 234, phishing message interaction tracker 236;” [0183] “p(R|H) is the probability that a given user will respond, for example click, in response to a malicious attack, for example a phishing email, at a particular point in time;” [0184] “When users are categorized by their predicted p(R|H) value, the percent of actual clicks in each category closely tracks the predicted p(R|H) value for the category” note the event and interaction trackers including an interaction rate utilized to determine a categorization of users)
determining, by the determination unit of the security system implemented on the one or more servers based at least on a severity of one or more security policies of a group of the user that are applied by the security system for failing the one or more simulated phishing campaigns, a third value for a security culture level of a group of the user; (Sites [0186] “the severity may by a function of a risk booster value, which may be set by a company or system administrator to customize the assessed risk of individuals or of groups of individuals” note the risk booster value corresponding to a security policy of a group of the user and the severity score corresponding to the security culture level of a group of the user)
[…];
categorizing, by the security system implemented on the one or more servers, the user into a class of users comprising one or more additional users, wherein the fourth value of the security maturity score of the user falls within a predetermined range of security maturity score values associated with the class of users, the class of users comprising one or more additional users; (Sites [0112] “The value of p(R|H) is a very good predictor in the aggregate for a group of users with similar profiles … users are categorized by their predicted p(R|H) value… The average over all individual risk scores in the group is one possible approach to aggregating the risk scores, however this may tend to underestimate the contribution of isolated outliers. In some examples, the approach taken may be referred to as using the standard distance to the perfect score (0)” noting users grouped into classes based on their risk scores within a predetermined range)
benchmarking, by a benchmarking unit of a security system implemented on the one or more servers and configured to execute a comparative analysis of phish prone percentage between users, the phish prone percentage of the user with the phish phone percentage of one or more additional users of the class of users; (Sites [0203] “system 215 may establish a group risk score based on a function of risk scores of each user within the group;” [0012] “When users are categorized by their predicted p(R|H) value, the percent of actual clicks in each category closely tracks the predicted p(R|H) value for the category” noting the user’s phish prone percentage compared to that of other user’s in their class)
[…];
displaying, by the displaying unit of the security system implemented on the one or more servers, the graphical representation on a display device; and (Sites fig. 4 noting the graphical illustration of the predicted propensity vs. actual percentage clicked, by user; [0036 noting display devices)
automatically initiating, by a training unit of the server based at least on the benchmarking and to improve cybersecurity of an organization, to at least one of limit access of the user to one or more information technology functions of the organization or provide electronic cybersecurity training to a user interface on a second display device of the user based at least on the benchmarking. (Sites [0141] “Being correctly able to identify the target user of a simulated phishing communication message may guide learning manager 250 to choose specific remedial training that addresses the mistake that the target user made which lead the target user failing the simulated phishing test” corresponding to providing cybersecurity training to the user)
Sites does not explicitly teach, O’Reilly however in the analogous art of security determination teaches
determining, by the determination unit of the security system implemented on the one or more servers, a fourth value of a security maturity score of the user based at least on a function of a combination, with one or more weighting factors, the first value for the security knowledge level of the user, the second value for the security awareness level of the user and the third value for the security culture level of the group of user; (O’Reilly [0086] “The dashboard view 198 further includes active assessments 202 that include the assessments (e.g., scores), associated with the system under evaluation 98, which are open and under evaluation. For example, the assessments depicted in FIG. 4A indicate a baseline score for the system under evaluation 98, while the “Cyberstrong” score is a “rollup” score (e.g., overall score) of all three assessments, which represents an average of the assessment scores” note the combining of multiple cybersecurity scores into a single overall score corresponding to the security maturity score comprised of a function of the first three security levels; see also fig. 6 illustrating a section for a user to assign weights to security controls)
creating, by a displaying unit of the security system implemented on the one or more servers configured to present graphical representations of results of benchmarking by the benchmarking unit, a graphical representation of one or more radar plots to visualize the security maturity score of the user in a single view as a function of the security knowledge level of the user, security awareness level of the user and the security culture level of the group of the user and with an enclosed shaped area within the one or more radar plots providing a comparative metric between users; (O'Reilly fig. 4A noting the cybersecurity radar plots with a comparative view; [0024] “the cybersecurity scoring and recommendation system 99 may allow an organization to compare its system risk profile and/or posture (e.g., current state) against other organization profiles in their sector or other sectors” corresponding to the comparison between users; [0082] “The dashboard view 198 may further include a spider chart 200 that depicts that current and target states for the overall assessment of the system under evaluation 98”)
Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to modify Sites’s risk determination scoring to include displaying phish performance data relative to peers in view of O'Reilly in an effort to use that information to improve the security programs of clients with different needs (see O'Reilly ¶ [0007] & MPEP 2143G).
Claims 2, 12
Sites teaches
determining, the determination unit of the security system implemented on by the one or more servers, the first value for the security knowledge level of the user based on one or more of results of quizzes or tests, detection of behaviors of the user, a skills-based assessment of the user, a risk score of the user, and the results of one or more simulated phishing campaigns of the user. (Sites [0067] “the risk score derivation will be based on training history, phishing history, responses to simulated phishing tests, demographic information, information about the organization, breach data, user assessment surveys and data which may be obtained from a SIEM” noting the training history, simulated tests, breach data)
Claims 3, 13
Sites teaches
wherein determining, by the determination unit of the security system implemented on the one or more servers, the second value for a security awareness level of the user comprises classifying the user into a security awareness level comprising one or more of an undefined security awareness level, a compliance-driven security awareness level, a Basic Awareness & Information Dissemination (BAID) security awareness level, and a behavior-shaped security awareness level. (Sites [0067] “the risk score derivation will be based on training history, phishing history, responses to simulated phishing tests, demographic information, information about the organization, breach data, user assessment surveys and data which may be obtained from a SIEM” noting the user training and phishing history corresponding to a behavior-shaped security awareness level; [0083] noting a user’s job not matching a category or has no information available corresponding to an undefined security awareness level;)
Claims 4, 14
Sites teaches
determining, by the determination unit of the security system implemented on the one or more servers, the third value for the security culture level of the group of the user based at least on the group to which the user is assigned. (Sites [0009] “A group score can be calculated based on a function of risk scores of each user within the group of users”)
Claims 5, 15
Sites teaches
determining, by the determination unit of the security system implemented on the one or more servers, the third value for a security culture level based on one or more of security policies of the group of the user, security communications to the group of the user, or security incentives offered to the group of the user. (Sites [0010] “Information contained in a security awareness system may be combined with information from external sources and used collectively to profile a user or group of users' past behavior;” [0069] “In some embodiments, the user's organizational unit, job title, and manager may be considered in creating the risk score. In some examples, the user's membership in distribution lists or groups may be taken into consideration in calculating the risk score. In embodiments, information about data breaches related to the user or to the organization may be considered in creating the risk score” noting the security communications considered when determining the third value)
Claims 6, 16
Sites teaches
wherein the group of the user is the organization of the user. (Sites [0069] “In some embodiments, the user's organizational unit … may be considered in creating the risk score.”)
Claims 7, 17
Sites teaches
wherein the predetermined range of security maturity values associated with the class of users comprises one or more of a lower bound of a security maturity value and an upper bound of a security maturity value. (Sites [0112] “the approach taken may be referred to as using the standard distance to the perfect score (0)” note the example of the lower bound set to 0 and the upper bound is a max of 100)
Claims 8, 18
Sites teaches
wherein categorizing the user into the class of users comprises adding the user to the class of users. (Sites [0112] “The value of p(R|H) is a very good predictor in the aggregate for a group of users with similar profiles … users are categorized by their predicted p(R|H) value”)
Claims 9, 19
Sites teaches
wherein benchmarking the phish prone percentage of the user with the phish phone percentage of the one or more additional users of the class of users comprises determining whether the phish prone percentage of the user is greater than or less than the phish phone percentage of one or more users of the one or more additional users of the class of users. (Sites [0203] “system 215 may establish a group risk score based on a function of risk scores of each user within the group;” [0012] “When users are categorized by their predicted p(R|H) value, the percent of actual clicks in each category closely tracks the predicted p(R|H) value for the category” noting the user’s phish prone percentage compared to that of other user’s in their class)
Claims 10, 20
Sites does not explicitly teach, O’Reilly however in the analogous art of security determination teaches
further comprising displaying a radar plot visualizing dimensions of security knowledge level of the user, security awareness level of the user, security culture level of the group of the user and security maturity of the user. (O'Reilly fig. 4A noting the cybersecurity radar plots with a comparative view; [0024] “the cybersecurity scoring and recommendation system 99 may allow an organization to compare its system risk profile and/or posture (e.g., current state) against other organization profiles in their sector or other sectors;” [0082] “The dashboard view 198 may further include a spider chart 200 that depicts that current and target states for the overall assessment of the system under evaluation 98”)
The motivation/rationale to combine Sites with O’Reilly persists
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
US 2021/0092162 A1: A system and method for the secure and private demonstration of cloud-based cyber-security tools. Using an advanced sandboxing design patterns, isolated instances of virtual networks allow a potential client to compare their existing cyber defense tools against a set of cloud-based tools. Capitalizing on non-persistent and secure sandboxes allow the invention to demonstrate fully functional and devastating cyber-attacks while guaranteeing strict privacy and security to both existing customers and potential ones. Additionally, instantiating separate sandboxed observed systems in a single multi-tenant infrastructure provide each customer with the ability to rapidly create actual representations of their enterprise environment offering the most realistic and accurate demonstration and comparison between products.
WO 2017/210738 A1: A system and method of using gamification and human behavioural analysis to quantify cyber security risks for a corporate or individual entity, the system can included a comprehensive real-time cyber security risk assessment, monitoring and remediation service, in particular through quantifying the qualitative aspects of individual user behaviour and entity-level cyber security activities, and incentivising and enabling effective cyber security outcomes through gamification. These capabilities will also enable the system to deliver real-time cyber insurance to users on a risk-effective basis.
Miserendino et al., ThreatVectors: contextual workflows and visualizations for rapid cyber event triage, 2017: Cyber security operations face a daily flood of security events generated by automated security tools and analytics. These events must be rapidly and accurately triaged to remove false positives and focus investigations on those presenting the greatest risks to the enterprise and requiring immediate remediation. We introduce ThreatVectors as a contextual triage workflow and event visualization tool to aid operators in event triage. ThreatVectors use a streaming event processing framework for event correlation, aggregation and prioritization based on user definable event collections and a cyber-triage domain specific language. Triage work progress is shown using a novel progress bar matrix. Event collection visualization includes abstract event thumbnails for event overview and a dynamic filtering mechanism based on metafield hierarchies. Bulk adjudication of filtered event views and event clusters is supported. User testing on large enterprise networks indicates the approach has significant potential for aiding in identifying multievent campaigns, supporting collaborative triage and reducing total time spent triaging events.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMED EL-BATHY whose telephone number is (571)270-5847. The examiner can normally be reached on M-F 8AM-4:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, PATRICIA MUNSON can be reached on (571) 270-5396. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MOHAMED N EL-BATHY/Primary Examiner, Art Unit 3624