Prosecution Insights
Last updated: October 02, 2026
Application No. 18/390,047

INFORMATION PROCESSING APPARATUS, INFORMATION PROCESSING METHOD, AND COMPUTER-READABLE RECORDING MEDIUM

Non-Final OA §103§112
Filed
Dec 20, 2023
Priority
Dec 26, 2022 — JP 2022-208773
Examiner
ZHENG, BIN QING
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
NEC Corporation
OA Round
3 (Non-Final)
66%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 66% — above average
66%
Career Allowance Rate
27 granted / 41 resolved
+7.9% vs TC avg
Strong +62% interview lift
Without
With
+62.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
13 currently pending
Career history
60
Total Applications
across all art units

Statute-Specific Performance

§101
6.9%
-33.1% vs TC avg
§103
61.8%
+21.8% vs TC avg
§102
6.9%
-33.1% vs TC avg
§112
24.0%
-16.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 41 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment 2. The Amendment filed July 21, 2026, has been entered. Claims 1, 2, 5, 7, 8, 11, 13, 14 and 17 have been amended. Claims 3, 9 and 15 were canceled. Claim 1, 2, 5-8, 11-14, 17 and 18 are presented for examining. Information Disclosure Statement 3. The information disclosure statement (IDS) submitted on September 08, 2026, is in compliance with the provisions of 37 CFR 1.97 and has been considered by the examiner. Claim Objections 4. Claims 5, 11 and 17 are objected to because of the following informalities: Each of claims 5, 11 and 17 recites “the identified trace is associated with a plurality of types of traces”. This limitation is not introduced by “wherein” or otherwise grammatically joined to the preceding clause. Appropriate correction is required. Claim Rejections - 35 USC § 112 5. The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. 6. Claims 5, 11 and 17 are rejected under 35 U.S.C. § 112(a) or 35 U.S.C. § 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. Each of claims 5, 11 and 17 recites “the identified trace is associated with a plurality of types of traces” and “determine that the identified trace is correct if the plurality of types of traces associated with the identified trace are included in the combination of types of traces representing the preset correct solution condition.” The specification describes a different arrangement. Each type of trace is defined separately, with its own log source and filter criteria (FIG. 7). Each identified trace carries a single artifact group identifier (FIG. 8, “IDENTIFIED TRACES,” one “artifact_group_id” per trace object). Where the correct solution condition combines two types of traces, the condition is satisfied by two traces, one of each type ([0047], FIG. 9); FIG. 9 states, “[s]ince both traces are specified, they can be adopted as correct.” The written description states the determination the same way: the correct solution determination unit “determines that the extracted traces are correct if all types of the identifies traces are included in the combination represented by the correct solution condition” ([0031]). The disclosure thus shows a plurality of traces, each associated with one type of trace. The specification therefore does not reasonably convey that the inventor had possession of the claim arrangement, in which one identified trace is associated with a plurality of types of traces and is determined to be correct from the types of traces associated with it. Claim Interpretation 7. Claims 1, 7 and 13 recite “deter determine, based on a result of the comparison, whether or not the identified trace is correct,” with no further use, storage, or output of the determination. Under the broadest reasonable interpretation, this limitation encompasses any comparison of the identified trace against a stored criterion that yields a binary result. Claims 5, 11 and 17 depends from claims 1, 7 and 13, respectively, further limits the correct solution condition to “a combination of types of traces,” confirming that the conditions of claims 1, 7 and 13 are not so limited. Claim Rejections - 35 USC § 103 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 9. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 10. Claims 1, 2, 7, 8, 13 and 14 are rejected under 35 U.S.C. § 103 as being unpatentable over Takahashi, (WO 2020/255359 A1, citations are to the attached machine translation obtained from the European Patent Office website), hereafter Takahashi, in view of and further in view of Sakakibara et al, (US 2015/0256554 A1), hereafter Sakakibara, and further in view of Yang et al., (CN 115051873A, citations are to the attached machine translation obtained from the European Patent Office website), hereafter Yang, as evidenced by admissions in the specification regarding the technology of WO 2020/255359A1 ([0024]-[0027]). Regarding claim 1, Takahashi discloses an information processing apparatus comprising: at least one memory storing instructions; and at least one processor configured to execute the instructions to: ([0083]; FIG. 10, computer 110 with CPU 111 and main memory 112; [0084], the CPU loads the programs into the main memory and executes them). acquire a set of logs from a computing system that has been subjected to a cyberattack. The attack agent 51 executes a transmitted command sequence and attacks other terminals 52 ([0063]). The agent then “acquires logs from each terminal 52… and sends these to attack execution unit 41 as information indicating the results of the attack” [0064]). The attack execution unit 41 then “transmits the attack result information transmitted from the attack agent 51 to the security training support device 30” ([0064]). Takahashi, as confirmed by applicant’s own specification, teaches history data indicating an execution of the cyberattack, wherein the history data comprises attack commands for each stage of a plurality of stages of the cyberattack. For each generated step of the attack scenario, the attack control unit “converts the information of the software selected in the generation process into an executable format such as a command sequence” ([0062]), and the agent executes the command sequence at each step ([0063]). The specification acknowledges that the attack process “can be generated using a technology disclosed in Internation Publication No. 2022/255359” (Specification: [0024]) and describes the result of “using the above technology” (Specification: [0025]): “[e]xecution history is generated. The generated execution history serves as history data. The execution history includes an attack command for each stage of the cyberattack” (Specification: [0027]). These statements are admission of fact regarding the operation of the technology of WO 2020/255359 (MPEP 2129). Takahashi ([0062]-[0063]) and applicant’s characterization at [0027] supersedes the prior action’s statement that Takahashi does not teach this limitation. Takahashi does not teach identify, from the acquired set of logs, a trace indicating a result of the cyberattack by using history data indicating an execution history of the cyberattack; compare the history data with a template in which information indicating a trace of an attack for each of the attack commands is registered; identify information indicating the trace of the attack based on the attack commands included in the history data; and identify the trace of the cyberattack from the set of logs based on identified information. The examiner withdraws the prior reliance on Takahashi [0065]-[0066] for the trace identification limitation; those paragraphs concern the state of the virtual attacker, not identification of a trace from the acquired logs. Sakakibara cures the deficiency. Sakakibara searches “a log for a trace of the attack” ([0055]). Each attack scenario element includes attack information 1104 ([0116]) containing “a keyword” ([0119]): “the keyword of the attack information 1104b indicates an event that may occur when the attack occurs. To take an example, if registry rewriting of the OS occurs, the keyword is described as ‘OS, registry, modify’” ([0122]). The attack scenario “is searched for from the attack scenario DB 1013, based on the attack identification information 1103” ([0112]). Sakakibara describes an example in which a firewall deny occurs due to the determination target attack; “this information is recorded in the keyword of the attack information 1104b” ([0215]; see also [0219]). Sakakibara places the registered keyword into the log search condition, for example “keyword (firewall, deny) against the firewall log ([0217]) and “keyword (OS, registry, modify)” against the asset log ([0221], [0222]), and generates the log search information 1113 ([0223]). The log analysis apparatus transmits “whether or not an entry has been searched for (presence or absence of the entry)” as the search result ([0233]), and the apparatus determines from that result whether the attack is detected ([0060]-[0061]). Sakakibara is analogous art. Sakakibara analyzes logs collected from a monitored computer system to search for traces of cyberattacks, which is the same field of endeavor as Takahashi and the claimed invention. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Takahashi to compare the history data with a template in which information indicating a trace of an attack for each of the attack commands is registered, to identify information indicating the trace of the attack based on the attack commands included in the history data, and to identify the trace of the cyberattack from the set of logs based on identified information, in the manner taught by Sakakibara ([0112], [0119], [0122], [0217]). In the modification, the system registers, for each attack command in Takahashi’s execution history ([0062]-[0063]; Specification. [0027]), the keyword indicating the event that the attack produces (Sakakibara: [0119], [0122]). The system retrieves the registered information by comparing the executed attack’s identifying information against the database (Sakakibara: [0112]), and applies the retrieved keyword, as a search condition, to the logs that Takahashi’s agent acquired (Sakakibara: [0217], [0221]). The combination thereby identifies, from the acquired set of logs, a trace indicating a result of the cyberattack by using history data indicating an execution history of the cyberattack. One of ordinary skill would have been motivated to make this modification. Takahashi collects the logs of a multi-stage simulated attack ([0064]) but provides no mechanism for locating the traces of the attack leaves in them. Sakakibara states the advantage of its technique, “allowing an efficient search for a trace of the attack ([0242]). The efficiency arises from the searching with conditions targeted to the attacks, including registered keyword (Sakakibara: [0217]). The modification applies Sakakibara’s known search technique to Takahashi’s training system in the same way, yielding the predictable result that the system locates the traces of each executed attack command in the collected logs. In the combination, the system retains the command sequences that it generates and executes at each step (Takahashi: [0062]-[0063]), because Sakakibara’s lookup requires that identifying information as its input. One of ordinary skill in the art would have a reasonable expectation of success: Takahashi already possesses both inputs the search requires, the collected logs ([0064]) and the per-step record of executed attack commands ([0062]-[0063]; Spec. [0045]). Takahashi in view of Sakakibara does not teach compare the identified trace with a preset correct solution condition, and determine based on a result of the comparison, whether or not the identified trace is correct. Yang teaches the recited comparison and determination. Yang’s traffic monitor “compares the simulated execution data of the attack command with preset results to determine whether the target traffic has successfully carried out the attack,” comparing “the network behavior implemented after the attack command is executed” with “the preset network behavior” and the echo information with “the preset response packet,” and determines the success against preset similarity thresholds ([n0033]) of the translation of record. See also Sakakibara ([0060]-[0061]). Yang is analogous art. Yang analyzes the results of attack commands executed against a computer system, the same field of endeavor as the claimed invention. Yang is also reasonably pertinent to a problem the inventor addresses: determining, without manual analysis, whether an executed attack produced the expected result (Specification: [0009]-[0011]). Yang addresses the same problem ([n0031]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined system of Takahashi and Sakakibara to compare the identified trace with a preset correct solution condition, and determine based on a result of the comparison, whether or not the identified trace is correct, in the manner taught by Yang ([n0033]). In the combination, Yang’s preset results, corresponding to the attack command, serve as the preset correct solution condition, and the system compares the trace identified for each executed attack command against that condition and determines from the comparison whether that trace is correct. One of ordinary skill would have been motivated to do so in order to “accurately detect behaviors that have actually been successfully carried out as network attacks” (Yang: [n0031]), verifying that the executed attack produced expected traces. The modification applies Yang’s known comparison technique to the combined system of Takahashi and Sakakibara, yielding the predictable result of a binary correctness determination for each identified trace. One of ordinary skill in the art would have a reasonable expectation of success. For each attack command, the combined system of Takahashi and Sakakibara already holds both inputs of Yang’s comparison ([n0033]): the expected event registered for that command (Sakakibara: [0122]) and the trace identified from the collected logs. Claim 2: Regarding claim 2, the combination of Takahashi, Sakakibara and Yang teaches the limitations of claim 2 as set forth above. Takahashi further teaches execute the cyberattack comprising the plurality of stages on the computing system; and generate the history data. The attack scenario comprises a plurality of steps, and the attack agent executes each step’s command sequence against the terminals (Takahashi: [0062]-[0063], [0016]). Applicant’s specification stats that, as the result of using the technology of WO 2020/255359, that “[e]xecution history is generated. The generated execution history servs as the history data. (Specification: [0027]; MPEP 2129); the data-retention rational set forth for claim 1 applies equally here. Claims 7 and 8: Regarding claims 7 and 8, the claims are directed to an information processing method comprising the operations recited by claims 1 and 2. Therefore the rejections applied to claims 1 and 2 also applies to claims 7 and 8. Claims 1 and 2 are rejected under the same rationale as claims 7 and 8. Claim 7 further recites an information processing method comprising: the operations recited by claim 1. Takahashi further teaches a security training support method that is implemented by a security training support device 10 ([0067]). Claims 13 and 14: Regarding claims 13 and 14, the claim are directed to a non-transitory computer readable recording medium containing instructions for implementing the operations recited by claims 1 and 2. Therefore the rejections applied to claims 1 and 2 also applies to claims 13 and 14. Claims 1 and 2 are rejected under the same rationale as claims 13 and 14. Claim 13 further recites a non-transitory computer readable recording medium that comprises s a program recorded thereon, the program comprising instructions that causes a computer to carry out: the operations recited by claim 1. Computer 110 includes “a CPU 111, a main memory 112, a storage device 113” (Takahashi: [0083]). “The CPU 111 loads the programs (codes)… stored in the storage device 113 into the main memory 112 and executes them” ([0084]). The program is “stored in a computer-readable recording medium 120” ([0084]). 11. Claims 5, 11 and 17 are rejected under 35 U.S.C. § 103 as being unpatentable over Takahashi in view of Sakakibara and Yang as applied to claims 1, 7 and 13 above, and further in view of Black et al. (US 2021/0320945 A1), hereafter Black, and further in view of Kawauchi (US 2016/0239661 A1), hereafter Kawauchi, as evidenced by Sigma (Roth, “Specification,” Sigma project wiki, archived March 14,2020). Claims 5, 11 and 17 use “types of traces” consistently with FIGS. 7 and 9 of the application, which label the named artifact group defined in the solution template as types of trace. Under the broadest reasonable interpretation, a type of trace is a named category of artifact. Regarding claim 5, the combination of Takahashi, Sakakibara and Yang teaches the limitations of claim 1 as outlined above. The combination does not teach the preset correct solution condition is represented by a combination of types of traces, the identified trace is associated with a plurality of types of traces, or determine that the identified trace is correct if the plurality of types of traces associated with the identified trace are included in the combination of types of traces representing the preset correct solution condition. Black cures the first two deficiencies. Black deploys a phrase, within “an attack validation scenario analogous to a network security threat,” to a target asset ([0007]). Each phrase prescribes actions executed on the target asset ([0042]). Black populates “a descriptor file with artifact warrants that trigger generation of artifacts on the network” and writes the descriptor file to the phrase. The descriptor file includes “a first artifact warrant that triggers generation of a registry key,” “a second artifact warrant that triggers a ping or query to a particular known IP or MAC address,” and “a third artifact warrant that triggers transmission of a query containing a particular file hash, IPv4 address, or tactic ID” for the actions of the phrase ([0042]). Black sets a target response type for each phrase and for individual actions ([0036], [0037]). Black filters observed events “by artifact characteristics (e.g., register key, IP address) defined by artifact warrants assigned to the phase” ([0053]) and correlates the artifacts contained in an event with the “known artifact values defined in artifact warrants contained in the first action” ([0063]). Black is analogous art. Black analyzing the results of attack actions executed against a computer system, the same field of endeavor as the claimed invention. Black is also reasonably pertinent to a problem the inventor addresses: determining, without manual analysis, whether an executed attack produced the expected result (Specification: [0009]-[0011]). Black addresses the same problem ([0013]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined system of Takahashi, Sakakibara and Yang such that the preset correct solution condition is represented by a combination of types of traces and the identified trace is associated with a plurality of types of traces, in the manner taught by Black ([0042], [0063]). In the modification, the system registers, for the executed attack, expected artifacts of plural named kinds across the attack’s actions (Black: [0042]). The system compares the artifacts contained in the identified trace with the registered values and associates the trace with the kinds of artifacts that match (Black: [0063]). One of ordinary skill in the art would have been motivated to make this modification; Black states that the system “can confirm configuration of the security technology” ([0013]). The modification applies Black’s known multi-kind artifacts registration to the registration already performed in the combined system (Sakakibara ([0122]), yielding the predictable result that the preset correct solution condition comprises plural named artifact types and that the identified trace is associated with the kinds of artifacts that match. One of ordinary skill would have had a reasonable expectation of success; the combined system of Takahashi, Sakakibara and Yang already registers trace information (Sakakibara: [0119], [0215]) and matches it against the logs (Sakakibara: [217]). The combination of Takahashi, Sakakibara, Yang and Black does not teach determine that the identified trace is correct if the plurality of types of traces associated with the identified trace are included in the combination of types of traces representing the preset correct solution condition. Kawauchi cures the deficiency. Kawauchi observes an event and “searches for the attack activity definition information 205 which describes the same event 220 as the observed event” ([0132]), then searches for other attack activity definition information depending on the achieved phenomenon described in the attack activity definition information ([0133]). Kawauchi “then checks whether all preconditions are satisfied for each of the attack activity definition information 201 and 204” ([0141]). “When attack activity definition information for which all the preconditions are satisfied is found,” Kawauchi extracts the event defined in that attack activity definition information ([0149]). Kawauchi is analogous art. Kawauchi detects multi-stage attack activities by matching observed events against defined attack activity information, the same field of analyzing observed events of cyberattacks against defined attack information. Kawauchi is also reasonably pertinent to the problem of determining without manual analysis whether observed results satisfy a defined set of conditions (Specification: [0009]-[0011]). Kawauchi’s apparatus makes that determination automatically, checking observed events against the preconditions defined in attack activity definition information ([0132], [0141]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined system of Takahashi, Sakakibara, Yang and Black to determine that the identified trace is correct if the plurality of types of traces associated with the identified trace are included in the combination of types of traces representing the preset correct solution condition, in the manner taught by Kawauchi ([0141], [0149]). In the modification, the system applies Kawauchi’s check to the correctness determination; the check requires that every member of a defined set of conditions is satisfied (Kawauchi: [0141]). The system determines that the identified trace is correct if the plurality of types of traces associated with the identified trace are included in the registered combination. Expressing such a condition as a combination over named groups was conventional, as evidenced by Sigma, which defines detection conditions as “Logical OR (1 of them) or AND (all of them) across all defined search identifiers” (Condition section, page 12). One of ordinary skill in the art would have been motivated to make this modification so that the system may “detect an attack when a series of attack activities occur, without exhaustively preparing attack scenarios or trees in advance” (Kawauchi: [0057]). The modification substitutes Kawauchi’s known all-precondition for Black’s score determination (Black: composite score, [0065]); threshold comparison, [0007]). The substitution replaces one known determination with another, and result is predictable; the check’s outcome follows directly from its two inputs. One of ordinary skill would have had a reasonable expectation of success; the combined system of Takahashi, Sakakibara, Yang and Black already holds both inputs the check requires, the registered combination of artifact kinds (Black: [0042]) and the kinds of artifacts associated with the identified trace (Black: [0063]). The check operates on data the combined system already produces; no new capacity is required. Claim 11: Regarding claim 11, the claim is rejected to an information processing method comprising the operations recited by claim 5. Therefore, the rejections applied to claim 5 also applies to claims 11. Claim 5 is rejected under the same rationale as claim 11. Claim 17: Regarding claim 17, the claim is directed to a computer readable recording medium containing instructions for implementing the operations recited by claim 5. Therefore, the rejections applied to claim 5 also applies to claim 17. Claim 5 is rejected under the same rationale as claim 17. 12. Claims 6, 12 and 18 are rejected under 35 U.S.C. § 103 as being unpatentable over Takahashi and Yang as applied to claims 1, 7 and 13 above, and further in view of Kennedy et al. (US 9,325,728 B1), hereafter Kennedy Regarding claim 6, the combination of Takahashi, Sakakibara and Yang teaches the limitations of claim 1 as outlined above. The combination does not teach compare at least one trace of the cyberattack that is input as external information with the identified trace; and calculate a score based on a proportion by which the compared traces match. Kennedy cures the deficiencies. Kennedy scores forensic analysts who examine attacked targets and report their findings: the analyst “communicate their findings via tickets to the White Team to receive score for their findings, although certain key elements will be detected in the ticket automatically scored without manual intervention” (col. 23, ll. 20-28). In the Forensic game, participants report “specific information such as the method of intrusion, the IP address of the attacker, the evidence of misuse left by the attacker,” and “[t]he game is scored based on tickets containing these artifacts that will demonstrate that the participant has discovered the specific data”; the artifact include “the MD5 hash value of the malware, the username of the account that was attacked, the IP address of the attacker” (col. 23, ll. 66 – col. 24, ll. 1-14). The comparison is automated: a ticket “is scored either by the White Team or by an automated process looking for specific keywords” (col. 26, ll. 43-47), and the base score is computed from the artifacts found against the set of all artifacts (col. 31, ll. 17-30). Kennedy scores by proportion. For the Forensic game, the base score depends on “the Green Team finding artifacts and reporting them in tickets,” and the textual algorithm defines it as the weighted sum of artifacts found divided by the weighted sum of all artifacts: “Base score = {per host weights}*(∑{Artifacts Found}*{their weightings/(∑{All Artifacts}*their weightings))” (col. 31, ll. 17-30). Quantitative evaluation factors include the “percentage of exploits detected” (col. 9, ll. 52-63), and an exemplary scoring design normalizes scores “based on percentage of vulnerabilities and their value” (col .21, ll. 9-10). Kennedy is analogous art. Kennedy evaluates reported findings of attacks executed on target computer systems, the same filed of endeavor as the claimed invention. Kennedy is also reasonably pertinent to the problem of determining without manual analysis whether reported traces of an attack are correct (Specification: [0009]-]0011], [0067]). In Kennedy, “certain key elements will be detected in the ticket automatically score without manual intervention” (col .23, ll. 24-28). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the combined system of Takahashi, Sakakibara and Yang to compare at least one trace of the cyberattack that is input as external information with the identified trace, and to calculate a score based on a proportion by which the compared traces match, in the manner taught by Kennedy (col. 23, ll. 66 – col .24, ll. 1-14; col. 31, ll. 17-30). In the combination, the trace identified from the set of logs corresponds to the specific keywords that Kennedy’s automated process looks for (col. 26, ll. 43-47) and serves as the reference for the comparison. The system receives a reported trace of the cyberattack in a ticket that is input as external information. The system detects the key elements of the ticket and compares them with the trace identified from the set of logs. The system calculates the score as the proportion by which compared trace that match, using Kennedy’s ratio of artifacts found to all artifacts (Kennedy: col. 31, ll. 17-30). In the ratio, the trace identified from the set of logs supplies the set of all artifacts, and the matching key elements of the ticket are the artifact found. One of ordinary skill would have been motivated to make this modification because Kennedy’s scoring “provides for automated analysis of man and machines” and “allows evaluation against best practices” (col. 10, ll. 36-40). The modification applies Kennedy’s known automatic scoring of reported findings to the combined system of Takahashi, Sakakibara and Yang. The result is predictable; the modification changes only the content of the comparison reference, while the ticket receipt, the keyword matching, and the ratio-based score computation as they do in Kennedy. The modified system thus compares a trace of the cyberattack input as external information with the identified trace and calculates the score from the proportion by which the compared traces match. One of ordinary skill would have had a reasonable expectation of success. The combined system of Takahashi, Sakakibara and Yang supplies the input the scoring requires: the identified trace that serves as the comparison reference. Kennedy supplies the operations that act on that input: the automated keyword comparison (col .23, ll. 23-28; col. 26, ll. 43-47) and the ratio-based score computation (col. 31, ll. 17-30). No new capability is required; each component performs the function it performs in its own reference. Claim 12: Regarding claim 12, the claim is directed to an information processing method comprising the operations recited by claim 6. Therefore, the rejections applied to claim 6 also applies to claim 12. Claim 6 is rejected under the same rationale as claim 12. Claim 18: Regarding claim 18, the claim is directed to a computer readable recording medium containing instructions for implementing the operations recited by claim 6. Therefore, the rejections applied to claim 6 also applies to claim 18. Claim 6 is rejected under the same rationale as claim 18. Response to Arguments 13. Applicant’s argument filed July 21, 2026, with respect to the rejection of claims 5, 11 and 17 under 35 U.S.C. § 112(b) is persuasive. Applicant argues that the rejection is moot in view of the amendments to the claims. The rejection was based on the use of the work “type”. The amendment defines the types of traces by their role in the correctness determination, and the metes and bounds of the claims are cleat. The rejection is withdrawn. However, the newly added recitation is not described in the specification as filed; see the rejection of claims 5, 11 and 17 under 35 U.S.C. § 112(a) above. 14. Applicant argues that Shachar does not disclose “compare the history data with a template in which information indicating a trace of an attack for each of the attack commands is registered” and “identify information indicating the trace of the attack based on the attack commands included in the history data.” The arguments are persuasive. Shachar is no longer relied upon, and the rejection over Takahashi in view of Yang, Shachar and Sakakibara is withdrawn. Claims 1 and 2 are rejected on a new ground over Takahashi in view of Sakakibara and Yang, as set forth above. 15. Applicant further argues that Sakakibara’s scheduled search does not use information indicating the trace of the attack based on the attack commands. The argument address [0055], [0056], [0058] and [0061] as previously cited and does not address the portions of Sakakibara now relied upon: the attack information 1104b, in which a keyword indicating the event that occurs when the attack occurs is registered ([0119], [0122]; the retrieval of the attack scenario based on the attack identification information [0112]; and the conversion of the registered keyword into a log search condition ([0215], [0217], [0221], [0222]). In the combination, Takahashi supplies the attack commands and the execution history; the rejection does not rely on Sakakibara alone for the linkage between the attack commands and the registered trace information. The argument is therefore not persuasive as to the new ground. 16. The examiner no longer relies on WO 2023/228299 A1 for claims 6, 12 and 18. The similarity score of [0031]-[0032], derived from the Levenshtein distance, is not a score based on a proportion by which the compared traces match. Claims 6, 12 and 18 are rejected on a new ground further un view of Kennedy (US 9,325,728 B1), as set forth above. 17. Applicant’s concluding argument that claims 1, 7 and 13, and the claims depending from them, are patentable over the recited references is moot in view of the new grounds of rejection set forth above. Conclusion 18. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Yagyu (US 2022/0237302 A1) derives, for each attack scenario, “traces during attacks,” that is, what traces are left behind when the scenario executed ([0082], [0084], [0087]). Mizoi et al. (JP6104149B2) extracts traces of an attack from a log using parametrized log search functions ([0091]-[0092], [0111]). Komori et al. (JP2019-191671A) collected logs from equipment used in a cyberattack exercise and extracts, from the collected logs, attack history that matches each attack event of the attack scenario to determine whether the attack succeeded ([0047], [0084]). Nishikawa et al. (WO2021/124528 A1) discloses attack execution, attack log acquisition, and trace log extraction units ([0007]). Yamaoka et al. (US 2017/0070515 A1) determines a setting value from a record of logs collected from a plurality of computers to be a search key, and identifies further record containing the search key (Abstract). Qian et al. (CN 114244623A) scores team-submitted attack-and-defense results against a preset judgment rule. Andreolini et al. (“A Framework for the Evaluation of Trainee Performance in Cyber Range Exercises”) monitors trainee activity in cyber-range exercises, models each trainee’s actions as a directed graph, and scores performance by comparing the trainee’s graph with a reference solution graph - including a precision score computed as a set-overlap proportion between the trainee’s action and the reference set. 19. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BIN QING ZHENG whose telephone number is (703)756-1535. The examiner can normally be reached on M-F 10:00 am -6:00 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip J. Chea can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BIN QING ZHENG/ Examiner, Art Unit 2499 /PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Dec 20, 2023
Application Filed
Dec 16, 2025
Non-Final Rejection mailed — §103, §112
Mar 10, 2026
Response Filed
Apr 21, 2026
Non-Final Rejection mailed — §103, §112
Jul 21, 2026
Response Filed
Sep 16, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737488
DISCONNECTED DATABASE DATA STRUCTURE PROTECTION
2y 10m to grant Granted Sep 15, 2026
Patent 12724899
VULNERABILITY ANALYSIS METHOD AND VULNERABILITY ANALYSIS SYSTEM
2y 12m to grant Granted Sep 01, 2026
Patent 12665815
Method for detecting anomalies in a communication network, method for coordinating anomaly detection, corresponding devices, router equipment, anomaly management system and computer programs.
3y 6m to grant Granted Jun 23, 2026
Patent 12664290
MEMORY PROTECTION
3y 2m to grant Granted Jun 23, 2026
Patent 12634149
AUTHENTICATION METHOD AND APPARATUS FOR SATELLITE NAVIGATION MESSAGE AND CORRECTION MESSAGES
3y 1m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
66%
Grant Probability
99%
With Interview (+62.3%)
2y 10m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 41 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month