Prosecution Insights
Last updated: October 04, 2026
Application No. 18/111,293

INFORMATION TECHNOLOGY ISSUE SCORING AND VERSION RECOMMENDATION

Final Rejection §103
Filed
Feb 17, 2023
Priority
Feb 18, 2022 — provisional 63/311,769
Examiner
RUSIN, KAYO LISA
Art Unit
2114
Tech Center
2100 — Computer Architecture & Software
Assignee
Bugzero Inc.
OA Round
4 (Final)
89%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
24 granted / 27 resolved
+33.9% vs TC avg
Strong +18% interview lift
Without
With
+17.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
14 currently pending
Career history
45
Total Applications
across all art units

Statute-Specific Performance

§101
14.1%
-25.9% vs TC avg
§103
51.4%
+11.4% vs TC avg
§102
13.5%
-26.5% vs TC avg
§112
18.4%
-21.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 27 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1, 3-21 are pending. Claims 1, 3-21 are rejected. Response to Arguments Applicants’ arguments filed 06/09/2026 have been fully considered. In regard to arguments pertaining to 35 U.S.C. 103, the argument is not persuasive and the Examiner maintains the rejection. Independent Claims 1 and 14 The Applicant argues that the prior art fails to teach “identifying, from the issue data store, a set of issues associated with the version, wherein the set of issues includes: a first issue that is a security issue; and a second issue that is a non-security issue, different from the first issue; [and] generating an aggregated score for the version based on the set of issues associated with the version, wherein each of the first issue and the second issue has a respective score with which the aggregated score is generated” for the following reasons: Wang exclusively concerned with security vulnerabilities. However, the Examiner respectfully disagrees. Although the prior art is focused on measuring the security of the operational environment, the collected issues are not exclusive to security. For instance, Wang recites measuring the security score based off of “misconfiguration [issues]” (page 1, col 2, paragraph 1) and other “information about software products… [and] other relevant information, to help make high-level decisions about vulnerability mitigation” (page 1, col 2, paragraph 2). Because non-security issues such as configuration of specific software is collected in Wang, the prior art teaches the amended claim limitation. As per claims 14, they recite similar claim language as that of claim 1 and thus are rejected for similar reasons. Independent Claim 8 The Applicant argues that neither Wang nor Rao teach or suggest at least “identifying … a set of versions for the same instance of hardware or software,” much less “ranking the set of versions… thereby facilitating comparison between different versions of instance of hardware or software.” However, the Examiner disagrees. The ontology represents the nodes representing each product at a version level (Wang, section 3.3: Data Retrieval for Security Metrics, Figure 6), which indicates that separate versions would have separate nodes. Thus, when similar products are returned, Internet Explorer 7 would be separate from Internet Explorer 5 since they belong to separate super-classes (Wang, section 3.3: Data Retrieval for Security Metrics, col 2, middle of the page). Dependent claims As per the dependent claims, they inherit similar qualities as that of their parent claims, and thus the dependent claims are also rejected for similar reasons. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made Claims 1, 3-21 are rejected under 35 U.S.C. 103 as being unpatentable over Rao (US Patent 11,947,946 B1), from henceforth referred to as Rao further in view of Wang (Environmental Metrics for Software Security Based on a Vulnerability Ontology, 2009), from henceforth referred to as Wang. Regarding claim 1, Rao teaches a system comprising: at least one processor (Fig 23, 2302, “Processing device”); and memory (Fig 23, 2304 “Main Memory”) storing instructions (Fig 23, 2326, “Instructions”) that, when executed by the at least one processor, causes the system to perform a set of operations (“The processing device 2302 may be configured to execute instructions 2326 for performing the operations and steps described herein (Col 23 Line 34-35)), the set of operations comprising: …a set of data sources…(col 10, line 9-13: data sources 560 may include an issue tracker, ticket system, etc), obtaining customer information indicating at least one of hardware or software, wherein the at least one of hardware or software has a version corresponding to the at least one of hardware or software (Rao teaches obtaining customer information through “updates” and receiving the customer information as part of the “parameter” associated with the said update: “to receive such updates, per 1802, processor 2302 may be configured to query or poll at least one service” (Col 17 Line 55-56) and “a set of parameters may be associated with any given update” (Col 18 Line 25-26). Additionally, "parameters and/or corresponding data may be derived from tags, properties, attributes, metrics, or analytics associated with..[…].. other mutable or immutable characteristics of a given component of a software deployment" (Col 19 Line 3-14). For instance, in Col 17 Line 63-Col 18 Line 7, Rao provides an example in which references to specific software packages that can be updated was stored in a data structure, so that these references can later be used to indicate a specific software version. Similarly, an indication of a specific version of a software can be stored in the parameter and passed along as part of an update); and providing an indication of the aggregated score for the version (Fig 11 “Total risk score” the total risk score that is considered an aggregate score is shown below to the user). PNG media_image1.png 678 1173 media_image1.png Greyscale Rao fails to teach generating, based on unstructured issue information from …, one or more issue data structures for an issue data store; identifying, from the issue data store, a set of issues associated with the version, wherein the set of issues includes a first issue that is a security issue a second issue that is a non-security issue, different from the first issue; generating an aggregated score for the version based on the set of issues associated with the version, wherein each of the first issue and the second issue has a respective score with which the aggregated score is generated However, Wang teaches generating, based on unstructured issue information …, one or more issue data structures for an issue data store (page 2, section 2 Evaluating Software Trustworthiness; second paragraph; the gathered vulnerabilities information is structured into the ontology called OVM, Ontology for Vulnerability Management); identifying, from the issue data store, a set of issues associated with the version, wherein the set of issues includes a first issue that is a security issue; a second issue that is a non-security issue, different from the first issue; (page 1, col 2, paragraph 1, the invention collects data such as security related issues as well as “misconfiguration [issues];” and page 1, col 2, paragraph 2: “information about software products… [and] other relevant information, to help make high-level decisions about vulnerability mitigation) generating an aggregated score for the version based on the set of issues associated with the version, wherein each of the first issue and the second issue has a respective score with which the aggregated score is generated (page 8, section 1.1-1.5; the EnvironmentalScore signifies the aggregate score that has been generated. This score is generated based off of each issue having a rating of either “P” for Partial, “N” for None, and “C” for Complete. The Examiner’s interpretation is that the P, N, and C can easily be substituted for a numerical score such as 1, 0, 2, respectively). Wang and Rao are analogous art that both teaches accessing data and displaying it to the users. Wang specifically teaches the method of retrieving data from NVD and using the CVSS scoring system. Rao is a system that has the capability of accessing data from multitude of external databases (not only NVD), but it makes sense for the system to use NVD as a data source for vulnerability data since, as stated in Wang, NVD provides “standardized information regarding existing vulnerabilities for most of the software products available today” (Wang, pg. 160). Similarly, it makes sense for Rao to use CVSS as a scoring tool when accessing the vulnerability data since the scoring tool is already integrated into the NVD, and integrated features and functionalities are often times more convenient to use. Because CVSS scores includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI) score components in its evaluations, it is reasonable to assume that the CVSS evaluates the issues based on categories such as confidentiality, integrity, and availability. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Rao to incorporate the teachings of Wang to use NVD as a way to identify a set of issues associated with the version, wherein the set of issues includes two or more of a confidentiality issue, an integrity issue, and an availability issue. Regarding Claim 3, Rao in view of Wang teaches the system of Claim 1. Rao further teaches wherein the aggregated score is generated based on one or more of: a confidentiality score component; an integrity score component; or an availability score component. (security issues can be broken down into other categories such as confidentiality, integrity, and availability (Col 11 Line 1-8). The aggregate score is generated by "combining (e.g., adding, averaging, statistically representing, or otherwise summarizing) multiple evaluation results into one evaluation result" (Col 11, Line 9-11). PNG media_image2.png 353 1167 media_image2.png Greyscale Regarding Claim 4, Rao in view of Wang teaches the system of Claim 3. Rao further teaches wherein the aggregated score is generated based on a set of user-configured weights including at least one of: a first weight for the confidentiality score component; a second weight for the integrity score component; or a third weight for the availability score component. (Any of these calculated scores "may have predetermined or customized quantitative values or weights assigned for purposes of evaluating specific parameters at a given time of 1806" (Col 19 Line 15-27). See FIG 21. Furthermore, "such qualitative and/or quantitative values or weights may be processed accordingly via at least one algorithm to generate at least one evaluation result" (Col 19 Line 25-27)). Regarding Claim 5, Rao in view of Wang teaches the system of Claim 1. Wang further teaches wherein the set of issues relates to a confidentiality issue for the version; an integrity issue for the version; and an availability issue for the version. (Wang, page 8, section 1.1, issues associated with the specific version is retrieved and the issues are related to availability, confidentiality, and integrity as depicted in its metric: ConfImpact, IntegImpact, AvailImpact). Regarding Claim 6, Rao in view of Wang teaches the system of Claim 1. Rao further teaches wherein the set of data sources comprises: for security issues, a centralized data source; and (col 10, line 21-31, DevSecOps architecture pipeline is used to collect security related information from various data stores and databases) for non-security issues, at least one of: a crowd-sourced data source; or a vendor of the hardware or software (col 10, line 9-13: data sources 560 may include an issue tracker, ticket system, … versioning system such as source code control and/or configuration management database (CMDB)), Regarding Claim 7, Rao in view of Wang teaches the system of Claim 1. Rao further teaches wherein: the customer information (stored in “parameters”) is obtained as part of a request (“update”), from a computing device, for an issue score associated with the at least one of hardware or software (FIG 5 “Feedback (Communication) 540”, Col 9 Line 62-66: “Feedback 540 may include any of various forms of communication, such as messaging 542 between other tools…” Feedback can be used to facilitate the communication between the computing device and this invention in order to obtain the customer information from the specific request sent out by the computing device); and the set of operations further comprises providing the indication of the aggregated score (Fig 9: “Total Score”) for the version to the computing device in response to the request. (FIG 5 “Feedback (Communication) 540”, Col 9 Line 62-66: “Feedback 540 may include any of various forms of communication, such as messaging 542 between other tools…” Similarly, Feedback can be used to send back an indication of the resulting aggregated score back to the computing device). Regarding Claim 8, Rao teaches a system comprising: at least one processor (Fig 23, 2302, “Processing device”); and memory (Fig 23, 2304 “Main Memory”) storing instructions (Fig 23, 2326, “Instructions”) that, when executed by the at least one processor, causes the system to perform a set of operations, the set of operations comprising: receiving a recommendation request (a specific “update” (Col 16 Line 35-40) which may contain a “parameter” (Col 19 Line 3-14) that indicates the type of “update” as that of recommendation) comprising an indication of at least one of computer software or computer hardware (Rao teaches obtaining customer information through “updates” and receiving the customer information as part of the “parameter” associated with the said update: “to receive such updates, per 1802, processor 2302 may be configured to query or poll at least one service” (Col 17 Line 55-56) and “a set of parameters may be associated with any given update” (Col 18 Line 25-26). Additionally, "parameters and/or corresponding data may be derived from tags, properties, attributes, metrics, or analytics associated with..[…].. other mutable or immutable characteristics of a given component of a software deployment" (Col 19 Line 3-14). For instance, in Col 17 Line 63-Col 18 Line 7, Rao provides an example in which references to specific software packages that can be updated was stored in a data structure, so that these references can later be used to indicate a specific software version. Similarly, an indication of a specific version of a software can be stored in the parameter and passed along as part of an update); …a set of data sources…(col 10, line 9-13: data sources 560 may include an issue tracker, ticket system, etc); and providing an indication of a highest-ranked version from the ranked set of versions. (“Feedback 540 may include any of various forms of communication, such as messaging 542 between other tools or stages of DevSecOps pipeline 100 or DevSecOps architecture 500, and/or notifications 544 via channels for organizations or users.” Feedback can be used to communicate and provide the indication of a highest-ranking version to other tools or to users. (Col 9 Line 61-66)) Rao fails to teach identifying, based on the recommendation request, a set of versions for the same instance of hardware or software, wherein the set of versions are each associated with an issue within an issue data store, and issues of the issue data store were generated based on unstructured issue information …; generating, for each version of the set of versions of the instance of hardware or software, an aggregated score based on a set of issues of the issue data store that are each associated with the version, wherein the set of issues comprises at least a first issue of a first issue type and a second issue of a second issue type different than the first issue type; ranking the set of versions based on an associated aggregated score for each version, thereby facilitating comparison between different version of the instance of hardware or software However, Wang teaches identifying, based on the recommendation request, a set of versions for the same instance of hardware or software, wherein the set of versions are each associated with an issue within an issue data store (Wang gives an example of populating a vulnerability ontology in which “software products that belong to the same product category” are grouped together by their object property ‘hasProductCategory’ or ‘hasProductInstance’ (Wang, pg.163). This allows for a mechanism to identify a set of versions of similar products (for instance, “Internet Explorer 7, Opera Browser 9, Apple Safari 4, etc”) from a given indication of a software version (for instance, “Mozilla Firefox 3”). Because they are grouped by the version number, if “Internet Explorer 6” and “Internet Explorer 7” exists, they would appear as separate nodes and is returned as separate product for comparison (Wang, pg. 165), wherein issues of the issue data store were generated based on unstructured issue information … (page 2, section 2 Evaluating Software Trustworthiness; second paragraph; the gathered vulnerabilities information is structured into the ontology called OVM, Ontology for Vulnerability Management); PNG media_image3.png 308 649 media_image3.png Greyscale generating, for each version of the set of versions of the instance of hardware or software, an aggregated score based on a set of issues of the issue data store that are each associated with the version, wherein the set of issues comprises at least a first issue of a first issue type and a second issue of a second issue type different than the first issue type (Wang provides a calculation “to calculate the overall environment score for each product series,” in which “overall environment score” refers to the vulnerability score of the software version in a given environment (Wang, pg. 166)); ranking the set of versions based on an associated aggregated score for each version, thereby facilitating comparison between different versions of the instance of hardware or software (Wang orders the set of versions based on an associated aggregated score: “the higher the overall score, the less secure the product with regard to the given environment. The overall EnvironmentScore for each version is compared in order to obtain a conclusion that a specific versioned product is more secure in the computing environment. (Wang, pg. 168)) Wang and Rao are analogous art and both teach a system that displays relevant vulnerability data to the users. One of Rao’s data source options is a configuration management database (Rao, FIG. 5, “Configuration Management Database 566”) which can utilize ontology as a way to organize their managed software. Wang teaches a specific ontology in order to accomplish this, and by doing so, the user is able to identify a set of versions related to a given version. It is also worth noting that it makes sense – when given a set of versions – to provide an analysis for each version and ranking them in a specific order since the user is most likely interested in knowing which version is the best version to consider. Thus, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Rao to incorporate the teachings of Wang to add the ability to use ontology as a way to identify a set of related versions from a given version and generating, for each version, an aggregated score and ranking them based on an associated aggregated score for each version. Regarding Claim 9, Rao in view of Wang teaches the system of Claim 8. Rao further teaches wherein providing the indication of the highest-ranked version further comprises providing an indication of an aggregated score for the highest ranked version (“Insight 520 may reveal some or all of the inputs (e.g., updates and/or risk-based criteria), outputs, or intermediate representations” (Col 9 Line 42-45). And “Feedback 540 may include any of various forms of communications, such as messaging 542 between other tools or stages of DevOps pipeline 100 or DevSecOps architecture 500, and/or notifications 544 via channels for organizations or users” (Col 9 Line 62-66)). Regarding Claim 10, Rao in view of Wang teaches the system of Claim 8. Rao further teaches wherein providing the indication of the highest-ranked version further comprises providing an indication of a set of score components used to generate the aggregated score for the highest-ranked version. (“Insight 520 may reveal some or all of the inputs (e.g., updates and/or risk-based criteria), outputs, or intermediate representations” (Col 9 Line 42-45). And “Feedback 540 may include any of various forms of communications, such as messaging 542 between other tools or stages of DevOps pipeline 100 or DevSecOps architecture 500, and/or notifications 544 via channels for organizations or users” (Col 9 Line 62-66)). Regarding Claim 11, Rao in view of Wang teaches the system of Claim 8. Rao further teaches wherein generating the aggregated score for each version comprises: generating the aggregated score based on a set of user-configurable weights, wherein each weight of the set of user-configurable weights corresponds to a score component of the set of score components (Any of these calculated scores "may have predetermined or customized quantitative values or weights assigned for purposes of evaluating specific parameters at a given time of 1806" (Col 19 Line 15-27). See FIG 21. Furthermore, "such qualitative and/or quantitative values or weights may be processed accordingly via at least one algorithm to generate at least one evaluation result" (Col 19 Line 25-27)) Rao fails to teach determining set of score components comprising two or more of: a confidentiality score component for the version; an integrity score component for the version; and an availability score component for the version However, Wang teaches determining set of score components comprising two or more of: a confidentiality score component for the version; an integrity score component for the version; and an availability score component for the version (Wang utilizes data from NVD in order to identify vulnerability issues: “NVD could be automatically populated as an instance of the Vulnerability concept…[…]… NVD also integrates CVSS [1] as impact metrics…” (Wang, pg.162) and the CVSS base score includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI), which means the generated vulnerability issues regarding confidentiality, integrity, and availability (Wang, pg. 164)) Wang and Rao are analogous art that both teaches accessing data and displaying it to the users. Wang specifically teaches the method of retrieving data from NVD and using the CVSS scoring system. Rao is a system that has the capability of accessing data from multitude of external databases (not only NVD), but it makes sense for the system to use NVD as a data source for vulnerability data since, as stated in Wang, NVD provides “standardized information regarding existing vulnerabilities for most of the software products available today” (Wang, pg. 160). Similarly, it makes sense for Rao to use CVSS as a scoring tool when accessing the vulnerability data since the scoring tool is already integrated into the NVD, and integrated features and functionalities are often times more convenient to use. Because CVSS scores includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI) score components in its evaluations, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Rao to incorporate the teachings of Wang to add the CVSS as a way to determine set of score components including a confidentiality score component, integrity score component, and an availability score component for the version. Regarding Claim 12, Rao in view of Wang teaches the system of Claim 8. Rao further teaches wherein the indication of at least one of computer software or computer hardware is a first received indication and the set of operations further comprises: receiving a second indication to perform an action based on the provided indication ("In 1808, processor 2302 may be configured to perform at least one action of the set of actions in response to the update." (Col 20 Line 17-20)); and in response to the second received indication, automatically performing at least one action of: patching an instance of software; upgrading an instance of software; downgrading an instance of software; disabling a service; generating a knowledge article in a known error database comprising an indication to avoid functionality; or moving a workload to a different computing device. (“…the evaluation of elevated risk of compromise for a particular component may result in determining the set of actions that may be taken with respect to that same component, such as testing, patching, upgrading, omitting, substituting, or any combination thereof." (Col 20 Line 65-Col 21 Line 3); “the at least one action to be performed in 1808 may be selected… (Col 21, line 14-17) Regarding Claim 13, Rao in view of Wang teaches the system of Claim 12. Rao further teaches wherein the at least one action is performed in response to receiving approval from a user to perform the at least one action (FIG 13). PNG media_image4.png 650 971 media_image4.png Greyscale Regarding Claim 14, Rao teaches a method for managing at least one of hardware or software of an environment, the method comprising: …a set of data sources…(col 10, line 9-13: data sources 560 may include an issue tracker, ticket system, etc); receiving, from a computing device, a score request (an “update” for a score) for at least one of hardware or software of the environment, wherein the at least of hardware or software has a version corresponding to the at least one of hardware or software (Rao teaches obtaining customer information through “updates” and receiving the customer information as part of the “parameter” associated with the said update: “to receive such updates, per 1802, processor 2302 may be configured to query or poll at least one service” (Col 17 Line 55-56) and “a set of parameters may be associated with any given update” (Col 18 Line 25-26). Additionally, "parameters and/or corresponding data may be derived from tags, properties, attributes, metrics, or analytics associated with..[…].. other mutable or immutable characteristics of a given component of a software deployment" (Col 19 Line 3-14). For instance, in Col 17 Line 63-Col 18 Line 7, Rao provides an example in which references to specific software packages that can be updated was stored in a data structure, so that these references can later be used to indicate a specific software version. Similarly, an indication of a specific version of a software can be stored in the parameter and passed along as part of an update); and providing, to the computing device in response to the score request, an indication of the aggregated score for the version (“Feedback 540 may include any of various forms of communication, such as messaging 542 between other tools or stages of DevSecOps pipeline 100 or DevSecOps architecture 500, and/or notifications 544 via channels for organizations or users.” Feedback can be used to communicate and provide the indication of a highest-ranking version to other tools or to users). Rao fails to teach generating, within an issue data store, an issue data structure based on unstructured issue information…; identifying, from the issue data store, a set of issues associated with the version, wherein the set of issues includes a first issue that is a security issue; and a second issue that is a non-security issue, different from the first issue generating an aggregated score for the version based on the set of issues associated with the version, wherein each of the first issue and the second has a respective score with which the aggregated score is generated However, Wang teaches generating, within an issue data store, an issue data structure based on unstructured issue information… (page 2, section 2 Evaluating Software Trustworthiness; second paragraph; the gathered vulnerabilities information is structured into the ontology called OVM, Ontology for Vulnerability Management); identifying, from the issue data store, a set of issues associated with the version, wherein the set of issues includes a first issue that is a security issue; and a second issue that is a non-security issue, different from the first issue (page 1, col 2, paragraph 1, the invention collects data such as security related issues as well as “misconfiguration [issues];” and page 1, col 2, paragraph 2: “information about software products… [and] other relevant information, to help make high-level decisions about vulnerability mitigation) generating an aggregated score for the version based on the set of issues associated with the version, wherein each of the first issue and the second issue has a respective score with which the aggregated score is generated (page 8, section 1.1-1.5; the EnvironmentalScore signifies the aggregate score that has been generated. This score is generated based off of each issue having a rating of either “P” for Partial, “N” for None, and “C” for Complete. The Examiner’s interpretation is that the P, N, and C can easily be substituted for a numerical score such as 1, 0, 2, respectively). Wang and Rao are analogous art that both teaches accessing data and displaying it to the users. Wang specifically teaches the method of retrieving data from NVD and using the CVSS scoring system. Rao is a system that has the capability of accessing data from multitude of external databases (not only NVD), but it makes sense for the system to use NVD as a data source for vulnerability data since, as stated in Wang, NVD provides “standardized information regarding existing vulnerabilities for most of the software products available today” (Wang, pg. 160). Similarly, it makes sense for Rao to use CVSS as a scoring tool when accessing the vulnerability data since the scoring tool is already integrated into the NVD, and integrated features and functionalities are often times more convenient to use. Because CVSS scores includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI) score components in its evaluations, it is reasonable to assume that the CVSS evaluates the issues based on categories such as confidentiality, integrity, and availability. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Rao to incorporate the teachings of Wang to use NVD as a way to identify a set of issues associated with the version, wherein the set of issues includes two or more of a confidentiality issue, an integrity issue, and an availability issue. Regarding Claim 15, Rao in view of Wang teaches the method of Claim 14. Rao further teaches wherein providing the indication of the aggregated score further comprises providing an indication of at least one issue of the identified set of issues ((Col 12 Line 66-Col 13 Line 3: “In 1706, the at least one processor 2302 may be configured to create at least one new entry in a tracking system (e.g., bug tracking system or module), for example, corresponding to one or more items extracted/parsed in 1702 and/or 1704 as described above.” In this example, the issues identified can be sent out to other modules to be further processed). Regarding Claim 16, Rao in view of Wang teaches the method of Claim 14. Rao fails to teach wherein the aggregated score is generated based on one or more of: a confidentiality score component for the confidentiality issue; an integrity score component for the integrity issue; or an availability score component for the availability issue However, Wang teaches the method of claim 14, wherein the aggregated score is generated based on one or more of: a confidentiality score component for the confidentiality issue; an integrity score component for the integrity issue; or an availability score component for the availability issue (Wang utilizes data from NVD in order to identify vulnerability issues: “NVD could be automatically populated as an instance of the Vulnerability concept…[…]… NVD also integrates CVSS [1] as impact metrics…” (Wang, pg.162) and the CVSS base score includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI), which means the generated vulnerability issues regarding confidentiality, integrity, and availability (Wang, pg. 164)). Because CVSS scores includes Confidentiality Impact (CI), Integrity Impact (II), and Availability Impact (AI) score components in its evaluations, it would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have modified Rao to incorporate the teachings of Wang to add the CVSS as a way to generate the aggregated score based off of a confidentiality score component, an integrity score component, and an availability score component. Regarding Claim 17, Rao in view of Wang teaches the method of Claim 16. Rao further teaches wherein the aggregated score is generated based on a set of user-configured weights including at least one of: a first weight for the confidentiality score component; a second weight for the integrity score component; or a third weight for the availability score component (Any of these calculated scores "may have predetermined or customized quantitative values or weights assigned for purposes of evaluating specific parameters at a given time of 1806" (Col 19 Line 15-27). See FIG 21. Furthermore, "such qualitative and/or quantitative values or weights may be processed accordingly via at least one algorithm to generate at least one evaluation result" (Col 19 Line 25-27)) PNG media_image5.png 187 264 media_image5.png Greyscale Regarding Claim 18, Rao in view of Wang teaches the method of Claim 14. Rao further teaches wherein the set of issues relates to a confidentiality issue for the version; an integrity issue for the version; and an availability issue for the version (Wang, page 8, section 1.1, issues associated with the specific version is retrieved and the issues are related to availability, confidentiality, and integrity as depicted in its metric: ConfImpact, IntegImpact, AvailImpact). Regarding Claim 19, Rao in view of Wang teaches the method of Claim 14. Rao further teaches wherein the set of data sources comprises: for security issues, a centralized data source; and (col 10, line 21-31, DevSecOps architecture pipeline is used to collect security related information from various data stores and databases) for non-security issues, at least one of: a crowd-sourced data source; or a vendor of the hardware or software (col 10, line 9-13: data sources 560 may include an issue tracker, ticket system, … versioning system such as source code control and/or configuration management database (CMDB)) Regarding Claim 20, Rao in view of Wang teaches the method of Claim 14. Rao further teaches wherein the score request is received as part of a change management process corresponding to the environment (“Based on these inputs to a policy-driven DevSecOps pipeline 100 that may include an intelligent risk-based engine with at least one adaptive pipeline module 400, and as a result of implementing the enhanced technology described further elsewhere herein, an intelligent DevSecOps workflow may be efficiently scaled to handle security-related issues safely and transparently for large-scale software deployments, even when their complexity grows beyond the scalability or capability of a team of any number of engineers, developer, or managers.” The request can be received as part of a highly-configurable, scalable deployment infrastructure which includes a change management process). Regarding Claim 21, Rao in view of Wang teaches the system of claim 1, wherein the set of data sources comprises: a first data source that is a vulnerability database; and a second data source comprising unstructured issue information for non-security issues. (FIG. 5, col 8 lines 56-63, data can come from AppSec tools for security related issues and “data sources 560” for non-security issues) Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KAYO LISA RUSIN whose telephone number is (703)756-1679. The examiner can normally be reached Monday-Friday 8:30 - 5:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ashish Thomas can be reached at 571-272-0631. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /K.L.R./Examiner, Art Unit 2114 /ASHISH THOMAS/Supervisory Patent Examiner, Art Unit 2114
Read full office action

Prosecution Timeline

Show 6 earlier events
Mar 21, 2025
Final Rejection mailed — §103
Sep 22, 2025
Request for Continued Examination
Oct 01, 2025
Response after Non-Final Action
Jan 09, 2026
Non-Final Rejection mailed — §103
May 07, 2026
Examiner Interview Summary
May 07, 2026
Applicant Interview (Telephonic)
Jun 09, 2026
Response Filed
Sep 01, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699638
SYSTEM AND METHOD FOR VIRTUALIZATION SOFTWARE MANAGEMENT IN A WIRELESS NETWORK
2y 4m to grant Granted Aug 04, 2026
Patent 12632330
Identifying and Remediating Anomalies in a Self-Healing Network
3y 1m to grant Granted May 19, 2026
Patent 12632327
SYSTEMS AND METHODS FOR PERFORMING A ROOT CAUSE ANALYSIS UTILIZING PARAMETERS INCLUDING DEVICE CONTEXT FEATURES TO TROUBLESHOOT ENTERPRISE INFORMATION TECHNOLOGY PROBLEMS
2y 10m to grant Granted May 19, 2026
Patent 12625777
DATA BACKUP METHOD OF STORAGE DEVICE USING SENSOR INFORMATION, AND STORAGE DEVICE AND STORAGE SYSTEM PERFORMING THE SAME
2y 10m to grant Granted May 12, 2026
Patent 12591500
Event Monitoring and Code Autocorrecting Batch Processing System
2y 1m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+17.6%)
2y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 27 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month