Prosecution Insights
Last updated: October 04, 2026
Application No. 18/119,202

METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR BREACH AND ATTACK SIMULATION

Non-Final OA §103§112
Filed
Mar 08, 2023
Examiner
SAVENKOV, VADIM
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Keysight Technologies Inc.
OA Round
3 (Non-Final)
61%
Grant Probability
Moderate
3-4
OA Rounds
0m
Est. Remaining
81%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
193 granted / 318 resolved
+2.7% vs TC avg
Strong +20% interview lift
Without
With
+20.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
27 currently pending
Career history
374
Total Applications
across all art units

Statute-Specific Performance

§101
10.6%
-29.4% vs TC avg
§103
53.7%
+13.7% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
17.3%
-22.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 318 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 11/13/2025 has been entered. Response to Amendment / Arguments Regarding claims rejected under 35 USC 112(b): Applicant’s amendment is considered to have overcome the applied rejection. Therefore, the rejection has been withdrawn. Regarding claims rejected under 35 USC 103: Applicant’s amendment is considered to have overcome the applied rejection. However, upon further consideration, a new ground(s) of rejection is made in view of Scheideler (US 2022/0269949 A1). Where Applicant argues that “there is no mention in Ulasen that the analysis includes analyzing network traffic produced from execution of the malware in the sandbox,” it is noted that at least [0004] and [0034] of Ulasen concern network packets carrying malicious functionality and dynamic features including operations with a network. Additionally, the newly discovered Scheideler reference includes characteristics such as a malware sample calling a known CNC server in [0062], where characteristics include observed behavior from execution in sandboxes as in [0056]. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 5-11, and 14-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ulasen (US 2023/0205877 A1) in view of Scheideler (US 2022/0269949 A1) and Ouzan (US 11,507,673 B1). Regarding claim 1, Ulasen discloses: A method for breach and attack simulation, the method comprising: detonating malware within a [test environment] (e.g., threat analysis server 306 in FIG. 3); Refer to at least [0029]-[0030] of Ulasen with respect to object data collection of a sample using the threat analysis server. The sample is run as an application. analyzing one or more impacts of the malware based on detonating the malware within the [test environment]; Refer to at least [0029]-[0030] of Ulasen with respect to recording information about the activity of the application during runtime, and obtaining static analysis information. Extracted feature information examples include API call sequences, operations with files, and other such impacts as per [0034] of Ulasen. generating, based on analyzing the one or more impacts of the malware, an executable malware emulation file; Refer to at least [0009], [0019], and [0026] of Ulasen with respect to data synthesis for creating synthetic malware objects for testing purposes. wherein generating the executable malware emulation file includes performing dynamic analysis of the malware as the malware executes in the [test environment], Refer to at least 310 and 312 in FIG. 3, and [0029] of Ulasen with respect to performing dynamic analysis of the object sample. Dynamic features are extracted. including analyzing network traffic produced from execution of the malware, Refer to at least [0034] of Ulasen with respect to operations with a network as part of dynamic features. performing static analysis of the malware without executing the malware, and Refer to at least 314 in FIG. 3, [0021], and [0029] of Ulasen with respect to static analysis of the object sample, the static analysis being concerned with what can be known before runtime. generating, based on the static and dynamic analysis, [an object] that, upon execution, produces [a feature set having features of the static and dynamic analysis feature sets]; Refer to at least [0019] and FIG. 4-5 of Ulasen with respect to creating new malware objects. Refer to at least [0032]-[0034] of Ulasen with respect to synthesized feature sets comprising mixed static and dynamic features taken from the respective sets. executing the malware emulation file on an endpoint system featuring [a security system]; Refer to at least [0019] of Ulasen with respect to using the synthetic malware objects to test the detection capabilities of existing computer security systems. analyzing the performance of the [security system] in response to executing the malware emulation file; and Refer to at least [0019] of Ulasen with respect to rating the detection capabilities of the existing computer security systems. Although Ulasen discloses testing and rating security systems with synthetic malware objects, Ulasen does not fully specify: the test environment further comprising a sandbox; the generated object further comprising a binary file; the produced feature set further comprising an execution chain that includes operations used by the malware to gain unauthorized access to systems or exfiltrate data; the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test; analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test. However, Ulasen in view of Scheideler discloses: the test environment further comprising a sandbox; Refer to at least [0056] of Scheideler with respect to malware sample characteristics including “observed behavior from execution in sandboxes, samples from the field, etc.” the produced feature set further comprising an execution chain that includes operations used by the malware to gain unauthorized access to systems or exfiltrate data. Refer to at least [0056]-[0063] and [0080] of Scheideler with respect to “us[ing] ML techniques to create a multitude of malware with similar characteristics as the samples exhibit,” where characteristics include “a sample calling a known CNC server, e.g., clientService.sin_addr.s_addr=inet_addr(“http://431tryme.sharkservers.co.uk/yahooimg/iq20000”).” The teachings of Ulasen and Scheideler both concern synthetic malware generation for security systems, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen to further implement creating synthetic malware with similar operations (e.g., calling a known CNC server) for at least the purpose of producing more true-to-life malware samples for security testing (i.e., testing actual malware behavior rather than arbitrarily mutated sample code introducing characteristics unrelated to security concerns). It further would have been obvious to utilize a sandbox for the test environment because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art (i.e., dynamic malware analysis using a sandbox). Ulasen-Scheideler does not specify: the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test; analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test; the generated object further comprising a binary file. However, Ulasen-Scheideler in view of Ouzan discloses: the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test; Refer to at least FIG. 1 of Ouzan concerning endpoints 1-N having respective agents. analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test; Refer to at least 132-148 in FIG. 2, Col. 2, Ll. 66-Col. 3, Ll. 5, and Col. 9, Ll. 26-65 of Ouzan with respect to “a cyber-attack emulation system compris[ing] multiple software agents ‘agents’) and a backend subsystem (‘backend’). The agents are deployed in endpoints such as workstations and servers of the target system, and are configured to apply emulated cyber-attacks specified by the backend, assess results of the attacks, and report back to the backend.” Additionally, a final report is prepared for a user. the generated object further comprising a binary file. Refer to at least Col. 6, Ll. 28-41 of Ouzan with respect to generated attack code comprising a binary file. The attack code is generated from code snippets associated with malware. The teachings of Ouzan likewise concern malware emulation for testing security systems, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen-Scheideler to further implement a cyber-attack emulation system and testing as in Ouzan for at least the reasons discussed in Col 2, Ll. 55-66 of Ouzan (i.e., testing customer systems; “[s]uch an iterative, adaptive process is highly effective in predicting the true performance of the target system's security controls against unknown real-world cyber threats”). It further would have been obvious to generate an attack code binary file for malware objects because the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., the cited portion of Ouzan specifies substitution any suitable format). Regarding claim 5, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein the execution chain includes leveraging at least one instance of process injection technique. Refer to at least [0070]-[0074] of Scheideler with respect to leveraging injection techniques. The claim would have been obvious because the substitution of one known element for another (attack features—e.g., [0034] of Ulasen) would have yielded predictable results to one of ordinary skill in the art at the time (i.e., additional features to synthesize with; improved testing because of breadth of samples). Regarding claim 6, it is rejected for substantially the same reasons as claims 1 and 3 above (i.e., the citations and obviousness rationale; [0056] of Scheideler). Regarding claim 7, it is rejected for substantially the same reasons as claim 1 above (e.g., Col. 6, Ll. 28-41 of Ouzan). Regarding claim 8, it is rejected for substantially the same reasons as claims 1 and 2 above (i.e., the citations—e.g., 312 and 314 in FIG. 3 of Ulasen). Regarding claim 9, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein reporting one or more test results based on analyzing the performance of the EDR-under-test comprises reporting a success or a failure of the EDR-under-test to detect and/or respond to the malware. Refer to at least Col. 10, Ll. 65-Col. 11, Ll. 24 of Ouzan with respect to reporting attack success / failure by the respective endpoint and agent. This claim would have been obvious for substantially the same reasons as claim 1 above. Regarding claim 10, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein executing the executable malware emulation file on an endpoint system executing an endpoint detection and response (EDR)-under-test comprises executing the executable malware emulation file on a virtual machine configured for a target test network. Refer to at least Col. 4, Ll. 45-55 of Ouzan with respect to the endpoints and servers comprising virtual machines. This claim would have been obvious for substantially the same reasons as claim 1 above. Regarding independent claim 11, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations and obviousness rationale). Regarding claims 14-20, they are substantially similar to elements of claims 1 and 5-10 above, and are therefore likewise rejected. Claim(s) 3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ulasen-Scheideler-Ouzan as applied to claims 1, 5-11, and 14-20 above, and further in view of Pruzinec (“KUBO: A Framework for Automated Efficacy Testing of Anti-virus Behavioral Detection with Procedure-Based Malware Emulation”). Regarding claim 3, Ulasen-Scheideler-Ouzan does not fully specify: wherein generating the executable malware emulation file comprises generating the executable malware emulation file such that, upon execution, the executable malware emulation file causes a plurality of steps of a kill chain for the malware. However, Ulasen-Scheideler-Ouzan in view of Pruzinec discloses: wherein generating the executable malware emulation file comprises generating the executable malware emulation file such that, upon execution, the executable malware emulation file causes a plurality of steps of a kill chain for the malware. Refer to at least [0034] of Ulasen with respect to synthesizing malware objects with features such as API call sequences and operations with files. Refer to at least section 2.3 of Pruzinec with respect to threat emulation having linked attack procedures under a correct context; section 3.2.3 of Pruzinec with respect to coordination data about the attack chain as context. The teachings of Pruzinec likewise concern malware emulation for testing security systems, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen-Scheideler-Ouzan to further implement attack chain context for at least the reasons discussed in 2.3 of Pruzinec (i.e., incoherently emulated attacks reduce the overall usefulness of testing). Regarding claim 13, it is substantially similar to claim 3 above, and is therefore likewise rejected. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432 /V.S/ Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 3 earlier events
Jan 29, 2025
Non-Final Rejection mailed — §103, §112
Apr 17, 2025
Response Filed
May 13, 2025
Final Rejection mailed — §103, §112
Jul 14, 2025
Response after Non-Final Action
Aug 13, 2025
Request for Continued Examination
Aug 20, 2025
Response after Non-Final Action
Nov 13, 2025
Response Filed
Aug 20, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12639449
SYSTEM AND METHOD FOR SCANNING CONTAINERS FOR VULNERABILITIES
2y 4m to grant Granted May 26, 2026
Patent 12632534
ACCESSING SECURE SYSTEM RESOURCES BY LOW PRIVILEGE PROCESSES
7y 12m to grant Granted May 19, 2026
Patent 12613999
DETECTING ELECTRONIC SYSTEM MODIFICATION
6y 10m to grant Granted Apr 28, 2026
Patent 12608482
DETERMINING A SECURITY SCORE IN BINARY SOFTWARE CODE
6y 5m to grant Granted Apr 21, 2026
Patent 12608501
Privacy-Preserving Log Analysis
5y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
61%
Grant Probability
81%
With Interview (+20.3%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 318 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month