Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 4/17/2025 in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
The drawings submitted on 11/03/2023 have been considered and accepted.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-7 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over 1, 3, 5 of co-pending Application No. 18235776, in view of Boyer et al., (Pub. No. US 2024/0045990).
This is a provisional non statutory double patenting rejection.
An exemplary to show obviousness among the conflicting claims (see table below).
Examined Application
Submitted 8/18/2023
copending Application No. 18/235776
Submitted 3/19/2025
A method of providing cyber threat information (CTI), the method comprising: receiving a CTI analysis request for a file from a client;
analyzing the file to obtain analysis information of the CTI for the file;
generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and
providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model [to the client as visualization information based on a Web service.]
A method of providing cyber threat information (CTI), the method comprising: receiving a CTI analysis request for assembly code from a client;
analyzing the assembly code to obtain analysis information of the CTI for the assembly code;
generating a CTI query based on the analyzed CTI and delivering the CTI query to a natural language model;
wherein the CTI query includes a keyword of the analyzed CTI or a supplementary query generated from the analyzed CTI;
and providing natural language description information according to the CTI query obtained from the CTI for the assembly code and the natural language model.
4. An apparatus for providing CTI, the apparatus comprising: a database configured to store data; and a processor,
wherein the processor performs operations comprising: an operation of receiving a CTI analysis request for a file from a client;
an operation of analyzing the file to obtain analysis information of the CTI for the file;
an operation of generating a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and
an operation of providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service.
3. An apparatus for providing CTI, the apparatus comprising: a database configured to store data; and a processor,
wherein the processor performs operations comprising: an operation of receiving a CTI analysis request for assembly code from a client;
an operation of analyzing the assembly code to obtain analysis information of the CTI for the assembly code;
an operation of generating a CTI query based on the analyzed CTI and delivering the CTI query to a natural language model,
wherein the CTI query includes a keyword of the analyzed CTI or a supplementary query generated from the analyzed CTI; and an operation of providing natural language description information according to the CTI query obtained from the CTI for the assembly code and the natural language model.
7. A storage medium for storing a program for providing CTI executable by a computer, the program comprising instructions configured to:
receive a CTI analysis request for a file from a client;
analyze the file to obtain analysis information of the CTI for the file;
generate a CTI query related to the file based on the analyzed CTI and delivering the CTI query to a natural language model; and
provide natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service.
5. A non-transitory computer-readable storage medium for storing a program for providing CTI executable by a computer, the program comprising instructions configured to:
receive a CTI analysis request for assembly code from a client;
analyze the assembly code to obtain analysis information of the CTI for the assembly code;
generate a CTI query based on the analyzed CTI and deliver the CTI query to a natural language model,
wherein the CTI query includes a keyword of the analyzed CTI or a supplementary query generated from the analyzed CTI;
and provide natural language description information according to the CTI query obtained from the CTI for the assembly code and the natural language model.
Regarding Claim 1, and substantially claims 4 and 7; Claims 1, 3, and 5 of co-pending application 18/235776 recite claim 1, 4, and 7 respectively. Co-pending application 18/235776 does not recite an operation of providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service. In an analogous art, Boyer teaches the claimed limitations (in [0081], In FIG. 5B, illustrates a block diagram of an embodiment of an interactive cyber security user interface having a LLM module. The interactive cyber security user interface 710 (e.g. a chatbot) can be combination of software and computing hardware on a platform that enables machines to communicate with humans in a natural, conversational manner, and vice versa. In [0135], a user agent, such as a browser, can act as a client in a network protocol used in communications within a client-server distributed computing system.)
Boyer is analogous to the copending Application because they are both concerned with analyzing cybersecurity threat information. It would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the co-pending with the teachings of Boyer, to use the interactive cyber security user interface, because it would facilitate an ongoing, multistage communication with the user. During a multistage communication, the interactive cyber security user interface may request clarifications from a user about their questions or actions, ask for input about actions taken by the user, or knowledge retained by the user. (Boyer, [0072]).
Regarding Claim 2; The Claim of the co-pending in view of Boyer discloses, wherein the visualization information comprises summary information of the CTI of the analyzed file. Additionally, Boyer discloses: (in [0070], by querying the interactive cyber security user interface, they can receive a summary.) (See above for motivation to combine the co-pending with Boyer.)
Regarding Claim 3; The Claim of the co-pending in view of Boyer discloses, The method according to claim 2, wherein the summary information comprises at least one of a first collection date of the analyzed file, a last activity date of an attack related to the analyzed file, a type of the analyzed file, a size of the analyzed file, file name information related to the analyzed file, or attack pattern detection name information of the analyzed file. Additionally, Boyer discloses: (in [0070], by querying the interactive cyber security user interface, they can receive a summary of whether similar patterns of behavior have been detected elsewhere from the cyber security user interface.) (See above for motivation to combine the co-pending with Boyer.)
Regarding Claim 5; Claim 5 is substantially similar to claim 2. Therefore, Claim 5 is rejected on the same grounds as Claim 2.
Regarding Claim 6; Claim 6 is substantially similar to claim 3. Therefore, Claim 6 is rejected on the same grounds as Claim 3.
This is a provisional nonstatutory double patenting rejection because the co-pending application has not been patented.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 7 is rejected under 35 U.S.C. 101 because the claims are directed to non-statutory subject matter.
Claim 7 is directed to a storage medium; the specification does not describe the storage-medium. Therefore, the BRI used for medium by the examiner include signals, which is not statutory. The examiner recommends to amend claim 7 to exclude signals, for instance by claiming "a non- transitory storage medium ...".
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-7 are rejected under 35 U.S.C. 103 as being unpatentable over McNelly et al., (Pub. No. US 2024/0223578), hereinafter, McNelly, in view of Boyer et al., (Pub. No. US 2024/0045990), hereinafter, Boyer.
Regarding Claim 4; McNelly discloses:
the apparatus (FIG. 1B, Threat Framework Platform 102), comprising:
a database configured to store data; (FIG. 1B, Threat Framework Database 112b)
and a processor (FIG. 1B, Processor(s) 111), wherein the processor performs operations comprising:
an operation of receiving a CTI analysis request for a file from a client; (In [0003], The computing platform may receive (e.g., from a client user device of the client and/or other devices), a request for the cyber threat investigation information.)
an operation of analyzing the file to obtain analysis information of the CTI for the file; (In [0032], The Rule Based Cybersecurity System 105 may be incorporated in the Threat Framework Platform 102. Rule based cybersecurity system 105 may be a computer system that includes one or more computing devices (e.g., servers, server blades, or the like) and/or other computer components (e.g., processors, memories, communication interfaces) that may be used to analyze metadata/attributes (e.g., IP address, domain, hash, indicators of compromise, command line, and/or other metadata) and classify domains with proprietary threat intelligence and/or otherwise.)
an operation of generating a CTI query related to the file based on the analyzed CTI (In [0040], the rule based cybersecurity system 105 may query the external information source 107 for EDR information. For example, the rule based cybersecurity system 105 may send an application programming interface (API) request that includes a query for logs, events, security information, behaviors, asset attributes, and/or other information that may be used to indicate TTP and/or IOC information corresponding to a particular threat investigation, which may, for example, include investigating for any threats associated with one or more clients.)
McNelly does not explicitly disclose:
delivering the CTI query to a natural language model; and an operation of providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service.
However, Boyer discloses:
delivering the CTI query to a natural language model; (In [0061], The interactive cyber security user interface 710 is configured to be in communication with the external cyber security system 750, and in particular with the cyber security hub, so as to be able to query and receive information from it. In [0006], an interactive cyber security user interface is configured with software code and electronic hardware to comprise a large language model, LLM, module configured to receive a natural language input from a user; analyze the natural language input to determine contextual information from the natural language input; determine one or more components of a cyber security system to query based on the contextual information and the natural language input; and generate a query in a software code format accepted by the one or more components of the cyber security system based on an analysis of the natural language input, the contextual information, and the determined one or more components to be queried.
and an operation of providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service. (in [0081], In FIG. 5B, illustrates a block diagram of an embodiment of an interactive cyber security user interface having a LLM module. The interactive cyber security user interface 710 (e.g. a chatbot) can be combination of software and computing hardware on a platform that enables machines to communicate with humans in a natural, conversational manner, and vice versa. In [0135], a user agent, such as a browser, can act as a client in a network protocol used in communications within a client-server distributed computing system.)
McNelly and Boyer are analogous because they are both concerned with analyzing cybersecurity threat information. It would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine McNelly with Boyer, to include delivering CTI queries to a natural language model, as taught by Boyer because using a natural language model allows to determine different aspects and contexts of the queries, and receive multiple responses presented in a concise and helpful manner (Boyer [0068]).
Additionally, the motivation to combine NcNelly with Boyer is also to include an operation of providing natural language description information according to the CTI query obtained from the CTI for the analyzed file and the natural language model to the client as visualization information based on a Web service. The combination would modify the visualization of the user interfaces, as taught in the embodiment of McNelly, to use the interactive cyber security user interface, as taught in the embodiment of Boyer, which may include one or more large language models (LLMs). This would allow the embodiment of McNelly to have of an ongoing, multistage communication with the user. During a multistage communication, the interactive cyber security user interface may request clarifications from a user about their questions or actions, ask for input about actions taken by the user, or knowledge retained by the user. (Boyer, [0072])
Regarding Claims 5; McNelly in view of Boyer discloses: The method according to claim 4,
Boyer discloses:
wherein the visualization information comprises summary information of the CTI of the analyzed file. (in [0070], by querying the interactive cyber security user interface, they can receive a summary.) (See Claim 4 for motivation to combine McNelly with Boyer.)
Regarding Claim 6; McNelly in view of Boyer discloses: The method according to claim 5,
Boyer discloses:
wherein the summary information comprises
at least one of a first collection date of the analyzed file, a last activity date of an attack related to the analyzed file, a type of the analyzed file, a size of the analyzed file, file name information related to the analyzed file, or attack pattern detection name information of the analyzed file. (in [0070], by querying the interactive cyber security user interface, they can receive a summary of whether similar patterns of behavior have been detected elsewhere from the cyber security user interface.) (See Claim 4 for motivation to combine McNelly with Boyer.)
Regarding Claim 1; Claim 1 is substantially similar to claim 4. Therefore, Claim 1 is rejected on the same grounds as Claim 4.
Regarding Claim 2; Claim 2 is substantially similar to claim 5. Therefore, Claim 2 is rejected on the same grounds as Claim 5.
Regarding Claim 3; Claim 3 is substantially similar to claim 6. Therefore, Claim 3 is rejected on the same grounds as Claim 6.
Regarding Claim 7; Claim 7 is substantially similar to claim 4. Therefore, Claim 7 is rejected on the same grounds as Claim 4.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (see PTO-form 892).
The following Parents and Papers are cited to further show the state of the art at the time of Applicant’s invention with respect to Cyber Threat Information Processing Apparatus, Cyber Threat Information Processing Method, and Storage Medium Storing Cyber Threat Information Processing Program:
Taniguchi et al., (Pub. No. US 2020/0065482), “Evaluation Method, Information Processing Apparatus, and Storage Medium”;
storing a program that cause a processor included in an information processing apparatus to execute a process, the process includes collecting a plurality of types of cyberattack information; evaluating a number of types of cyberattacks in which feature information of the cyberattack appears based on the collected cyberattack information. (Taniguchi [0010]).
Yang et al., (Pub. No. US 2020/0042701), “Malware Identification Using Multiple Artificial Neural Networks”;
Systems and methods are described for malware detection using multiple neural networks that share and adjust weight and bias information with each other during training on distinct features of a common sample set. (Yang [0006]).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KEVIN LEKEITH BREWER whose telephone number is (703)756-1312. The examiner can normally be reached Monday -Friday 8:00 am to 5:00 pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, CATHERINE THIAW can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.L.B./
KEVIN LEKEITH BREWERExaminer, Art Unit 2407 /Catherine Thiaw/Supervisory Primary Examiner, Art Unit 2407 5/22/2025