Prosecution Insights
Last updated: August 17, 2026
Application No. 18/214,088

EXPLOITABILITY PREVENTION GUIDANCE ENGINE

Non-Final OA §101§103
Filed
Jun 26, 2023
Examiner
WALIULLAH, MOHAMMED
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
635 granted / 732 resolved
+26.7% vs TC avg
Moderate +11% lift
Without
With
+10.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
29 currently pending
Career history
751
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
62.3%
+22.3% vs TC avg
§102
4.8%
-35.2% vs TC avg
§112
12.0%
-28.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 732 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. At step 1, the claim recites a method comprising a combination of “receiving…”, “identifying…”, “recommending…” is a process, which is a statutory category of invention. At step 2A, prong one, the claim recites “identifying an analogous computer environment in a context database that performed better against the simulated cybersecurity attack, the context database storing information associated with a plurality of computer environments and previously performed cybersecurity attack simulations on the plurality of computer environments;” and “recommending configurations associated with the analogous computer environment to the target computer environment” , like disconnecting target computer from network from previous experience could be a suggestion/recommendation. These limitations - recite a mental process – that is a concept which may be performed in the human mind, such as an observation, evaluation, judgment, or opinion. (see MPEP 2106.04(a)(2). The courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper or a slide rule) to perform the claim limitation. (see MPEP 2106.04(a)(2).) At step 2A, prong two, this judicial exception is not integrated into a practical application. In particular, the claim recites “identifying an analogous computer environment in a context database that performed better against the simulated cybersecurity attack, the context database storing information associated with a plurality of computer environments and previously performed cybersecurity attack simulations on the plurality of computer environments;” and “recommending configurations associated with the analogous computer environment to the target computer environment” are not integrated useable solution. Claim require a recommendation generation not implemented yet. At step 2B, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As recited in claim “receiving results of a simulated cybersecurity attack performed against a target computer environment” As discussed above with respect to integration of the abstract idea into a practical application, the additional elements “receiving simulation result” no more than mere instructions to apply the exception using generic computer components. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept. Considering the additional elements individually and in combination and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. The claim is not patent eligible. Independent claims 7 and 13 has similar limitations also rejected by same rational. Claims 2-6, 8-12, 14- 19 recites the limitations are insignificant extra solution activity. Thus, these claims recite an abstract idea (see 2106.05(g). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 7-8, 13-14, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree et al(US 20220224723 A1) in view of ALI et al(JP 2022092600 A). With regards to claim 1, 7, 13 Crabtree discloses, A computer-implemented method ([0028] Accordingly, the inventor has developed a system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. [0183] Software/hardware hybrid implementations of at least some of the aspects disclosed herein may be implemented on a programmable network-resident machine (which should be understood to include intermittently connected network-aware machines) selectively activated or reconfigured by a computer program stored in memory. [0186] CPU 12 may include one or more processors 13 such as, for example, a processor from one of the Intel, ARM, Qualcomm, and AMD families of microprocessors. In some aspects, processors 13 may include specially designed hardware such as application-specific integrated circuits (ASICs), electrically erasable programmable read-only memories (EEPROMs), field-programmable gate arrays (FPGAs), and so forth, for controlling operations of computing device 10)comprising: receiving results of a simulated cybersecurity attack performed against a target computer environment ([0028]; The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators. [0027] What is needed is a system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a business cost/benefit analysis tailored to the operations of each enterprise environment and informed by the role and criticality of the data and services provided.); and recommending configurations associated with the analogous computer environment to the target computer environment ([0030]; determining a cybersecurity improvement recommendation for the network under test based on the comparison; [0081] The inventor has conceived, and reduced to practice, a system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators.). Crabtree does not exclusively but ALI teaches, identifying an analogous computer environment in a context database that performed better against the simulated cybersecurity attack, the context database storing information associated with a plurality of computer environments and previously performed cybersecurity attack simulations on the plurality of computer environments (ALI Page 2 ; Recommendation Manager 110 has a meaningful and viable stage (both mitigation and prevention) that has worked in the past to remedy similar threats to its environment and to similar targets. It can be a system that provides security recommendations. Security recommendations may be automatically sent to the client or to the analyst for verification according to the confidence level provided by the recommendation manager 110.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Crabtree’s method with teaching of ALI in order to provide a computer-implemented method for allowing potential targets of security incidents to respond to recommendations thereto by taking an action to prevent or mitigate damage caused by an actual or potential security incident(ALI Abstract). With regards to claim 2, 8, 14 Crabtree further discloses, wherein the context database stores, for each of the plurality of computer environments, previous exploit exercise result ([0030]; obtaining a simulation result comprising the cyberattack strategy sequence and a probability of success of the attack and the defense in each iteration;), system configuration data ([0171]Conversely, a certain attack strategy may be very unlikely to succeed, requiring circumvention of a long chain of defenses, but a successful attack would allow the attacker control over the entire network, in which case large expenditures are justified in defending against that attack. A non-limiting list of cost factors to be considered 3202a-n is the cost of replacing or improving hardware components in the network 3202a, the personnel cost to program software or change configurations on the system 3202b to implement certain security measures, the cost to train personnel to change operation procedures 3202c to improve security,), security tool data ([0171]; Conversely, a certain attack strategy may be very unlikely to succeed, requiring circumvention of a long chain of defenses, but a successful attack would allow the attacker control over the entire network, in which case large expenditures are justified in defending against that attack. A non-limiting list of cost factors to be considered 3202a-n is the cost of replacing or improving hardware components in the network 3202a, the personnel cost to program software or change configurations on the system 3202b to implement certain security measures, the cost to train personnel to change operation procedures 3202c to improve security, and the operational cost (including magnitude) 3202n if a successful attack occurs (e.g., the cost of lost productivity if the internal network is shut down, a distributed denial of service (DDoS) attack occurs preventing external access, the cost of data losses, etc.). A non-limiting list of technical difficulty and benefits 3203a-n is whether or not an attack is theoretically observable 3203a with existing network architecture (which impacts costs of upgrading the network), the limits of detectability (time scale, level of effort, expenditure of computing resources, etc.) of such an attack 3203b if an attack is theoretically observable, the ability of current defensive measures to respond to or mitigate the effects of an attack 3203c, the reduction in risk 3203d gained by implementing defensive measures against such an attack, and compliance impacts 3203n (i.e., does implementation of defensive measures against this attack reduce the effectiveness of defenses against other attacks, increase the risk in other areas, etc.)), and exploit tactic, technique and procedure (FIG 19-23 and associated text;[0125-126] For this, a pipeline manager 511a-b may spawn service connectors to dynamically create TCP connections between activity instances 512a-d. Data contexts may be maintained for each individual activity 512a-d, and may be cached for provision to other activities 512a-d as needed. A data context defines how an activity accesses information, and an activity 512a-d may process data or simply forward it to a next step. Forwarding data between pipeline steps may route data through a streaming context or batch context.). With regards to claim 19, Crabtree further discloses, wherein the recommended configurations include security control configurations the analogous computer environment has implemented ([0122] FIGS. 3A and 3B are process diagrams showing a general flow of business operating system functions in rise to mitigate cyberattacks. Input network data which may include network flow patterns 321, the origin and destination of each piece of measurable network traffic 322, system logs from servers and workstations on the network 323, endpoint data 329, any security event log data from servers or available security information and event (SIEM) systems 324, external threat intelligence feeds 324, identity or assessment context 325, external network health or cybersecurity feeds 326, Kerberos domain controller or ACTIVE DIRECTORY™ server logs or instrumentation 327 and business unit performance related data 328, among many other possible data types for which the invention was designed to analyze and integrate, may pass into 315 the business operating system 310 for analysis as part of its cyber security function. …generate cyber-physical systems graphing 354 as part of the business operating system's common capabilities. Output 317 can be used to configure network gateway security appliances 361, to assist in preventing network intrusion through predictive change to infrastructure recommendations 362, to alert an enterprise of ongoing cyberattack early in the attack cycle, possibly thwarting it but at least mitigating the damage 362, to record compliance to standardized guidelines or STA requirements 363, to continuously probe existing network infrastructure and issue alerts to any changes which may make a breach more likely 364, suggest solutions to any domain controller ticketing weaknesses detected 365, detect, presence of malware 366, and perform one time or continuous vulnerability scanning depending on client directives 367, and thwart or mitigate damage from cyber attacks 368. These examples are, of course, only a subset of the possible uses of the system, they are exemplary in nature and do not reflect any boundaries in the capabilities of the invention.). Claim(s) 3-6, 9-12, 15-18 are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree et al(US 20220224723 A1) in view of ALI et al(JP 2022092600 A) and further in view of Laidlaw et al(US 9503472 B2). With regards to claim 3, 9, 15 Crabtree in view of ALI do not but Laidlaw teaches, after the recommended configurations have been implemented on the target computer environment, receiving information associated with results of another simulated cybersecurity attack performed against the target computer environment and updating the context database with the information (Laidlaw col 11 line 40-55; These relative risk level estimations are derived from information pertaining to the attack retrieved from the target computer environment, and are based on reasoning using fuzzy logic over an expert fuzzy rule base derived from a predictive model generated using, for example, associative rule learning or statistical classifier learning, from a set of training data. The model is particular to a specific target environment, taking into account that environment's vulnerabilities, and may be updated and refined in use, for example periodically, to take in to account practical experience of cyber threat data obtained in the field.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Crabtree in view of ALI’s method/product/system with teaching of Laidlaw in order for automatically generating one or more rule bases for an expert system usable to profile cyber threats detected in a target environment (Laidlaw col 1line 15-21;). With regards to claim 4, 10, 16 Crabtree in view of ALI and Laidlaw teaches, wherein the context database is built based on results of the cybersecurity attack simulations on the plurality of computer environments (Laidlaw col 15 line 20-30; ) Through these competitions, it is possible to build a database of attack vectors to be used as example data in devising the predictive model for CT risk for given target environments 401. This collected CTF attack data can be normalised and used to build a predictive model by the predictive model generation engine 413 and correlated with new attacks and to allow real-time attack data to be analysed by the CTP 410 in use in the target environment 401 to determine the seriousness and sophistication of the attack and ultimately, to support decision-making.). With regards to claim 5, 11, 17 Crabtree in view of ALI and Laidlaw teaches, further including enhancing the context database with information associated with results of the simulated cybersecurity attack performed against the target computer environment (Laidlaw FIG 7 and associated text; Laidlaw col 11 line 40-55; These relative risk level estimations are derived from information pertaining to the attack retrieved from the target computer environment, and are based on reasoning using fuzzy logic over an expert fuzzy rule base derived from a predictive model generated using, for example, associative rule learning or statistical classifier learning, from a set of training data. The model is particular to a specific target environment, taking into account that environment's vulnerabilities, and may be updated and refined in use, for example periodically, to take in to account practical experience of cyber threat data obtained in the field.). With regards to claim 6, 12, 18 Crabtree in view of ALI and Laidlaw teaches, wherein the analogous computer environment is identified that exhibits acceptable cybersecurity hardening from types of exploits employed in the simulated cybersecurity attack (Laidlaw; FIG 8 and associated text; Note: low risk profile will consider acceptable ). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20240098114 A1 Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMED WALIULLAH whose telephone number is (571)270-7987. The examiner can normally be reached 8.30 to 430 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 1-571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOHAMMED WALIULLAH/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Jun 26, 2023
Application Filed
Dec 06, 2023
Response after Non-Final Action
Jul 28, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705390
PRIVACY-AWARE DATA TRANSFORMATIONS
3y 8m to grant Granted Aug 11, 2026
Patent 12695610
BLOCKCHAIN DATA PROCESSING METHOD AND APPARATUS, COMPUTER DEVICE, MEDIUM, AND PRODUCT
2y 7m to grant Granted Jul 28, 2026
Patent 12695613
DATA COMMUNICATION SYSTEM, CENTER DEVICE, MASTER DEVICE, STORAGE MEDIUM STORING ENCRYPTION PROGRAM, AND STORAGE MEDIUM STORING DECRYPTION PROGRAM
2y 4m to grant Granted Jul 28, 2026
Patent 12683763
COMPUTER-BASED SYSTEMS CONFIGURED TO SELECT A MONITORED DATA SEGMENTATION AND METHODS OF USE THEREOF
2y 6m to grant Granted Jul 14, 2026
Patent 12682081
KEY DEPRECATION WITHOUT CERTIFICATE REVOCATION
2y 6m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
98%
With Interview (+10.9%)
2y 4m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 732 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month