DETAILED ACTION
Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
2. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on July 6, 2026 has been entered.
Response to Amendment
3. Claims 1, 4, 8, 9, 10, 14, 23 and 27 have been amended. Claim 17 was cancelled. Claim 28 is a new claim. Claims 1-16 and 18-28 are presented for examination.
Response to Arguments
4. Applicant’s arguments, filed July 6, 2026, with respect to the rejection of claims 1-27 under 35 U.S.C. § 103 have been considered but are moot in view of the new grounds of rejection. The claims (as amended) do not overcome the new ground of rejection made in view of newly found prior art references.
Claim Objections
5. Claims 22 is objected to for reciting “a plurality of computers,” which is inconsistent with the “computer system(s)” recited in claim 14 from which it depends (and with the corresponding “plurality of computer systems” in claim 9. For consistency, “computers” should be amended to “computer systems.” Appropriate correction is required.
Claim Rejections - 35 USC § 112
6. The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
7. Claims 10, 23 and 28 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 10 recites “wherein the predetermined period of time is associated with a period of time during which any of the threat indicators was active before the execution of the plurality of validation tests.” The phrase “is associated with” does not definite the relationship between the predetermined period of time and the period during which the indicator was active. It is unclear whether the predetermined period equals that active period, is bounded by it, is offset by it, or is merely computed from it. Therefore, the claim fails to inform one of ordinary skill in the art of its scope with reasonable certainty. Claims 23 and 28 are rejected for the same reasons stated for claim 10.
Claim Rejections - 35 USC § 103
8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
9. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
10. Claims 1-4, 6, 8, 9, 11-15, 19, 20, 22, 24-27 are rejected under 35 U.S.C. 103 as being unpatentable over Khalid et (US 10,587,647 B1) et al, hereafter Khalid, Eidissen (US 2022/0150269 A1), hereafter Eidissen, and further in view of Martin et al. (US 10,366,299 B2), hereafter Martin.
Regarding claim 1, Khalid teaches a vulnerability and compromise detection (“VCD”) system for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, {Khalid [col. 6, ll. 1-9] “A testing network 310 of the testing environment 300 may include… and one or more network security devices whose efficacy of detecting the malware is to be assessed, i.e., the security devices are tested to determine whether they can accurately detect the malware and/or malicious behavior.“} Khalid’s system tests security devices to determine whether they can accurately detect malware, and therefore is a VCD system.
the VCD system comprising at least one computer device comprising at least one processor, and at least one memory device in communication therewith, the at least one processor programmed to: {Khalid [col. 4, ll. 31-40; Fig. 2] “The end node 200 may include one or more CPUs 212, a memory 220, one or more network interfaces 214, one or more devices 216....”}
filter a plurality of indicators of compromise associated with active threat actors using the received selection criteria; As disclosed in Khalid, the test administrator selects test samples by identifier (col. 10, ll. 6-27), and in response, the content engine retrieves from the sample database the indicators of compromise associated with the selected test samples (col. 10, ll. 28-36).
generate a plurality of validation tests to test for the filtered plurality of indicators of compromise; The virtualized endpoint running on the test console requests to acquire test samples (col. 14, ll. 29-49; col. 7, ll. 29-54).
execute the plurality of validation tests in a simulation environment to generate a plurality of results; A virtualized endpoint instantiated on the test console to simulate one or more actual endpoints (col. 7, ll. 61-col. 8, ll. 10; col. 14, ll. 50-67).
analyze the plurality of results to detect one or more failed validation tests of the plurality of validation tests; each failed validation test reflecting a failure of one or more Internet security controls of the computer network to block or prevent a respective indicator of compromise; {Analysis of the gateway logs to determine whether a flow bypassed, that is failed, detection by a security device; (col. 13, line 35-43). A test application reports on IOCs not detected by the UUTs, reflecting a failure of the UUTs to block those IOCs (col. 11, line 43-64).
Regarding label each indicator of compromise associated with a corresponding failed validation test as a threat indicator, Khalid identifies the malicious object that bypassed the security control. Consistent with the specification ([0070], describing the indicators of compromise associated with the failed validation tests as the basis for the log scan), “threat indicator” is given its broadest reasonable interpretation as the indicator of compromise associated with a failed validation test, which Khalid discloses (col. 13, line 40-43). “the test application… can report such detection failure” (identifying the flow/object that bypassed, i.e., the not-blocked IoC). The object/flow that “did manage to avoid detection” and is “report[ed]” as a “detection failure” is the indicator of compromise the security control failed to block, which under the construction confirmed by spec [0070], is the claimed “threat indicator.”
However, Khalid does not (a) explicitly teach receiving selection criteria associated with a threat assessment of a computer network.
However, Eidissen teaches receiving selection criteria associated with a threat assessment of a computer network. Eidissen teaches receiving data describing one or more security tests, the data indicating one or more predetermined threat indicators associated with a particular predetermined threat ([0014], [0025]), including an IP address, a domain name, a file, a hash value, or a DNS record ([0025]). The received data indicating predetermined threat indicators associated with a particular predetermined threat corresponds to the claimed selection criteria associated with a threat assessment of a computer network.
Eidissen constitutes analogous art because it is in the same field of endeavor as the claimed invention – testing security of a computer network using threat indicators. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Khalid to receive selection criteria associated with a threat assessment, as taught by Eidissen, and to filter the indicators of compromise using those selection criteria , in order to direct the validation tests to the indicators of compromise associated with a particular assessed threat. Doing so “enable[s] a user to efficiently perform multiple useful security tests with respect to one or more networks without the need for specialized knowledge” (Eidissen, [0015]). The combination combines prior-art elements according to known methods to yield predictable results.
However, neither Khalid nor Eidissen teaches “scan a plurality of system logs of the computer network for any access instance associated with one or more of the threat indicators by any computer system within the computer network that took place within a predetermined period of time antedating the execution of the plurality of validation tests; and determine whether the computer network is compromised based on the scan of the plurality of system logs, wherein the computer network is determined to be compromised when at least one scanned system log identifies at least one access instance of a computer system within the computer network.”
However, Martin teaches the recited scan and determination. Regarding scan a plurality of system logs of the computer network, Martin records network events to a network accounting log (col. 7, ll. 27-30; col. 7, ll. 50 – col. 2, ll. 23; Block S110), and maintains compressed log file thereof. Martin scans the compressed logfile and then the network accounting log (col. 6, ll. 22-28 & 33-48; Blocks S130-S140; col. 9, ll. 33-46).
Regarding any access instance associated with one or more of the threat indicators by any computer system within the computer network, Martin scans the compressed log file for an element indicating that a computer on the network previously connected to the IP address or domain name of the indicator of compromise (col. 6, ll. 22-28; Block S130), and confirms the connection by scanning the network accounting for a cluster of event records (col .6, ll. 33-41; Block S140) – the threat element being an indicator of compromise such an IP address or domain name (col. 5, ll. 10-14).
Regarding that took place within a predetermined period of time antedating the execution of the plurality of validation tests, Martin records the network events over a period of time and receives the threat intelligence identified after that period, such that the detected connection predates the identification (col. 1, ll. 48-49 “identified after the period of time”, the threat is identified after the events were recorded, so the logged access instance predates the identification; col. 2, ll. 33-36: the system look back on historical network traffic to detect malware).
Regarding determine whether the computer network is compromised based on the scan of the plurality of system logs, Martin determines whether the newly-identified security threat is present on the network (col .4, ll. 2-10).
Regarding wherein the computer network is determined to be compromised when at least one scanned system log identifies at least one access instance of a computer system within the computer network, Martin, upon confirming the attack via the cluster of event records in the network accounting log, treats and quarantines the identified computer as compromised computer (col. 6, ll. 37-41 & 57-58).
Two aspects of the limitation are supplied by the combination rather than by Martin alone. First, Martin obtain its threat element from external threat intelligence. In the combination with Khalid, the indicator of compromise that failed the validation tests of Khalid serve as Martin’s threat elements, so that the scanned access instance is one associated with the claimed threat indicators. Second, Martin’s historical window antedates the identification of that threat intelligence; because the failed-test indicators are searched only after the validation tests are executed, the matching prior connection took place within a pre-determined period antedating the tests.
Martin constitutes analogous art, in the same field of endeavor as the claimed invention, namely the detection of cyber-attacks on a network using indicators of compromise. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the network-accounting-log-scan and compromise determination of Martin into the system of Khalid and Eidissen. One of ordinary skill in the art would have been motivated to make this combination in order to determine whether a security control failure identified by a validation test had already resulted in a compromise of the network. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30), a benefit Martin achieves while “requiring limited processing time and power….while also maintaining a high degree of accuracy” (Martin, col. 4, ll. 22-26). The combination combines prior art elements according to known methods to yield predictable results.
Claim 2:
Regarding claim 2, Khalid, Eidissen and Martin teaches the limitations of claim 1 as set forth above. The combination further teaches wherein the at least one processor is further programmed to report threat posture information about the computer network and related systems as a form of threat intelligence. Specifically, Khalid teaches generating a report on the efficacy and comparison of the detection results of the security devices, including whether samples were falsely identified and the attack vector (e.g., email, web) and sample type (col. 14, ll. 6-28).
Claim 3:
Regarding claim 3, Khalid, Eidissen and Martin teach the limitations of claim 1 as stated.
However, Khalid and Eidissen do not teach receiving the plurality of indicators of compromise on a periodic basis.
However, Martin teaches wherein the at least one processor is further programmed to receive the plurality of indicators of compromise on a periodic basis. Martin discloses that the IOCs are received on a periodic basis – the system regularly pulls threat intelligence updates from the ISAC database, such as once per day (col. 4, ll. 58-61 & 64-67).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to configure the system of Khalid, Eidissen and Martin to receive the indicators of compromise on a periodic basis, as taught by Martin. One of ordinary skill in the art would have been motivated to do so in order to keep the indicators of compromise current with newly-identified threats, yielding the predictable result of testing against and scanning for the most recent threats. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30).
Claim 4:
Regarding claim 4, Khalid, Eidissen and Martin teaches the limitations of claim 1 as set forth above. Khalid further teaches wherein each validation test of the plurality of validation tests is performed in a simulated environment in communication with the one or more internet security controls. In Khalid, the tests run through a virtualized endpoint on the test console, with the security device (unit under test)as a recipient (col.7, ll. 61 - col.8, ll. 10; col. 14, ll. 50-67).
Claim 6:
Regarding claim 6, Khalid, Eidissen and Martin teaches the limitations of claim 1 as set forth above. Khalid further teaches wherein the simulation environment simulates a computer system on the computer network. In Khalid, the virtualized endpoint simulates one or more actual endpoints on the enterprise network (col. 7, ll. 61 - col. 8, ll.10).
Claim 8:
Regarding claim 8, Khalid, Eidissen and Martin teaches the limitations of claim 1 as set forth above. Khalid further teaches wherein a validation test succeeds if the one or more Internet security controls blocks access during the validation test. (col. 13, ll. 8-28; col. 14, ll. 6-28). A flow that that is not bypassed, i.e., detected and blocked by the security devices, is the converse of the bypassed (failed) flow (col. 13, ll. 35-40). A unit under test determines that a request message is directed to a blacklisted domain and therefore blocks the request (col. 13, ll. 8-28), col. 14, ll. 6-28).
Claim 9:
Regarding claim 9, Khalid, Eidissen and Martin teaches the limitations of claim 1 as set forth above. However, Khalid and Eidissen do not teach the limitation of claim 9. However, Martin teaches wherein the plurality of system logs includes activity and message logs of a plurality of computer systems in the computer network. In Martin, the network accounting log holds a record of every event occurring on the computers of the network (col. 7, ll. 27-30; col. 7, ll. 50 – col. 2, ll. 23; Block S110).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, in the plurality of system logs, activity and messages logs of a plurality of computer systems in the network, as taught by Martin, in order to capture events occurring across all computers on the network so that an access instance associated with one or more threat indicators on any of them can be detected, yielding predictable results. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30).
Claim 11:
Regarding claim 11, Khalid, Eidissen and Martin teach the elements of claim 1 as set forth above. Khalid further teaches where the wherein the indicator of compromise is a website. In Khalid, the test samples are identified by a domain or URL (col. 9, ll. 63-col. 10, ll. 1).
However, Khalid and Eidissen do not teach determining if any computer system in the computer network accessed the website based on the scan of the plurality of system logs of the computer network.
However, Martin teaches determine if any computer system in the computer network accessed the website based on the scan of the plurality of system logs of the computer network. Martin detects that a computer on the network previously connected to a domain such as mwindowsupdate5.com (col. 6, ll. 21-28).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine, based on the scan, whether any computer in the network accessed the website corresponding to the indicator of compromise, as taught by Khalid and Martin, in order to identify which computers may be compromised, yielding the predictable result of establishing the scope of compromise. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30), while “maintaining a high degree of accuracy” (Martin, col. 4, ll. 22-26).
Claim 12:
Regarding claim 12, Khalid, Eidissen and Martin teach the elements of claim 1 as set forth above. However, Khalid and Eidissen do not teach the limitations of claim 12.
However, Martin teaches detect at least one compromised computer system based on the scan of the plurality of system logs; and instruct the computer network to isolate the at least one compromised computer system. Martin scans the compressed log file to find the computer that connected to the IoC (col. 6, ll. 22-28; Block S130), and confirms via the accounting-log event record cluster (col. 6, ll. 37-41; Block S140). Subsequently, Martin quarantines one or more compromised computers within the network (col .6, ll. 49-58).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to detect and isolate the compromised computer system based on the scan, as taught by Martin, in order to contain the identified compromise and prevent its spread, yielding a predictable result. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30), while “maintaining a high degree of accuracy” (Martin, col. 4, ll. 22-26).
Claim 13:
Regarding claim 13, Khalid, Eidissen and Martin teach the elements of claim 1 as stated.
Khalid further teaches wherein the at least one processor is further programmed to report the plurality of results of the plurality of validation tests (Each UUT generates a report of detection, and the test application reports on the ability of the UUTs to detect the IOCs using the detection results reported by the UUTs (col. 15, ll. 13-36; Fig. 6).
However, Khalif and Eidissen do not teach reporting the results of the scan of the plurality of system logs.
However, Martin teaches reporting results of the scan of the plurality of system logs. To handle the threat on the internal network, Martin issues an alert (col. 49-57; Block S150).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to report both the validation-test results and the system log-scan results, as taught by Khalid and Martin, in order to give the analyst a complete view of the network’s security posture, yielding a predictable result. Doing so would “detect security threats that may have already compromised an asset on a network” (Martin, col. 3, ll. 25-30), while “maintaining a high degree of accuracy” (Martin, col. 4, ll. 22-26).
Claims 14-16, 19, 20, 22 and 24-26:
Regarding claims 14-16, 19, 20, 22 and 24-26 the claims are directed to a method for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, and the method compromises the steps recited by claims 1-3, 6, 8, 9 and 11-13. Therefore, the rejection applied to claims 1-3, 6, 8, 9 and 11-13 also applies to claims 14-16, 19, 20, 22 and 24-26. Claims 1-3, 6, 8, 9 and 11-13 are rejected under the same rationale as claims 14-16, 19, 20, 22 and 24-26.
Claim 14 further recites a computer-based method for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, the method implemented on a vulnerability and compromise detection (“VCD”) computer device including at least one processor in communication with at least one memory device, the method comprising: the operations recited by claim 1. {Khalid [Col. 5, ll. 27-31] “A testing technique to test and compare malware detection capabilities of network security devices and other cyber-attack security devices.” [col. 4, ll. 31-40] “The end node 200 may include one or more CPUs 212, a memory 220, one or more network interfaces 214, one or more devices 216,…connected by a system interconnect 218.”}
Claim 27:
Regarding claim 27, the claim is directed to a computer-readable storage media containing instructions that could be executed by a processor to implement the operations recited by claim 1. Therefore, the rejection applied to claim 1 also applies to claim 27.
Claim 27 further recites at least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon, wherein when executed by at least one processor, the computer-executable instructions cause the processor to: implement the steps recited by claim 1. {Khalid [col. 5, ll. 17-26] “Other types of processing elements and memory, including various computer-readable media, may be used to store and execute program instructions...” [col. 4 ll. 59-67 - col.5 ll. 1-4] “The CPU 212 may be embodied as a hardware processor… to execute the software program code and application programs...”}
11. Claims 5 and 18 are rejected under 35 U.S.C. § 103 as being unpatentable over Khalid, Eidissen and Martin as applied to claims 1, 4 and 14, and further in view of McClintock et al. (US 10,135, 862 B1), hereafter McClintock.
Regarding claim 5, Khalid teaches the limitations of claim 4 as set forth above. However, Khalid, Eidissen and Martin do not teach the explicitly teach instructing the one or more Internet security controls to block the indicators of compromise associated with the one or more failed validation tests.
However, McClintock teaches wherein the at least one processor is further programmed to instruct the one or more Internet security controls to block the indicators of compromise associated with the one or more failed validation tests. McClintock discloses that, in response to a known indicator of compromise, the system performs automated actions including “configuring a router to or firewall to block inbound or outbound network access for one or more network addresses or ports “(col. 4, ll. 30-39).
McClintock constitutes analogous art because it is in the same field of endeavor as the claimed invention, namely responding to indicators of compromise on a network. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to instruct the internet security controls to block the IoCs associated with the failed validation tests, as taught by McClintock, in order to remediate the security-control failures identified by the tests. Doing so “can assess the effect of any automated defenses” (McClintock, col.2, ll. 21-22). The combination combines prior-art elements according to known methods to yield predictable results.
Claim 18:
Regarding claim 18, the claim is directed to a method for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, and the method comprises the operations recited by claim 5. Therefore, the rejection applied to claim 5 also applies to claim 18. Claim 5 is rejected under the same rationale as claims 18.
12. Claims 7 and 21 are rejected under 35 U.S.C. § 103 as being unpatentable over Khalid, Eidissen and Martin as applied to claims 1 and 14, and further in view of Telang et al. (US 2018/0357422 A1), hereafter Telang.
Regarding claim 7, Khalid, Eidissen and Martin teach the elements of claim 1 as stated.
Khalid teaches wherein the plurality of results include… logs generated during the corresponding validation tests. The test application analyzes logs of the gateway generated during the testing (col. 13, ll.35-44). Khalid does not explicitly disclose that the logs are message logs.
However, Telang teaches message logs. Telang describes syslog message/syslog data -event records delivered as messages. ([0073] “Syslog data may be thought of as a standardized “envelope” in which to deliver one or more data types. For a typical entity, a single syslog data feed may contain dozens of different event record types (firewall, authentication, web proxy, end point, Internet provider security, intrusion detection system, etc.)… The authentication security event may be forwarded using a syslog message to network activity data capture device(s) 104.” [0074] “a syslog message may have three parts regardless of the content of the message. The first part… is associated with a priority value that represents a facility and a severity… [including] kernel messages, user-level messages, mail system messages, security/authorization messages, syslogd messages,…”) Under BRI, a syslog message is a log record in message form, which reads on the claimed message logs.
Telang constitutes analogous art because it is in the same field of endeavor as the claimed invention – testing a cybersecurity system of a computer network using a simulated attack (Telang, abstract) – and is further reasonably pertinent to the particular problem with which the inventor was concerned, namely capturing and recording message logs of network activities generated in connection with such security testing (Telang, [0073]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to configure the logs generated during the validation tests, as taught by Khalid, to include message logs, as taught by Telang, in order to record the message traffic exchanged during the validation tests for analysis. Doing so “ensure[s] that cybersecurity system correctly responds to… different types of attacks” (Telang, [0705]). The combination combines prior-art elements according to known methods to yield predictable results.
Claim 21:
Regarding claim 21, the claims is directed to a method for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, and the method comprises the operations recited by claim 7. Therefore, the rejection applied to claim 7 also applies to claim 21. Claim 7 is rejected under the same rationale as claim 21.
13. Claims 10, 23 and 28 are rejected under 35 U.S.C. § 103 as being unpatentable over Khalid, Eidissen and Martin as applied to claims 1, 14 and 27, and further in view of Ward et al. (US 9,680,861 B2), hereafter Ward.
Regarding claim 10, Khalid, Eidissen and Martin teach the elements of claim 1 as stated.
However, Khalid, Eidissen and Martin do not disclose “wherein the predetermined period of time is associated with a period of time during which any of the threat indicators was active before the execution of the plurality of validation tests.”
However, Ward teaches the limitations of claim 10. Ward discloses gathering filtered historical network data associated with an asset and analyzing it to determine whether the asset is associated with a malware infection (Abstract). Ward triggers the analysis when a new threat intelligence indicator becomes available, and retroactively examines the period preceding identification of the indicator, for example, a threat identified at 8:35 a.m. triggers examination of files from before 8:35 a.m. (col. 7, ll. 1-3; col.8, ll. 36-57). Ward thus bounds the lookback period by the interval preceding identification, during which the indicator was active, which corresponds to the claimed period of time during which the threat indicator was active before the validation tests.
Ward constitutes analogous art because it is reasonably pertinent to the particular problem with which the inventor is concerned – determining, over a bounded look-back period, whether a threat indicator was present on a network prior to its identification (Abstract). Ward is additionally within the broader filed of network-security threat detection.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to bound the predetermined period of Martin by the indicator-active interval taught by Ward, in order to confine the scan to the interval in which a matching access instance is possible. Doing so “enable[s] retroactive discovery of stealthy infector malware that may have caused an initial infection on an asset machine” (Ward, col. 6, ll. 49-51 ), allowing the system to “detect new threats without any foreknowledge of the threat” (Ward, col. 9, ll. 44-47). The combination combines prior-art elements according to known methods to yield predictable results.
Claim 23:
Regarding claim 23, the claim is directed to a method for testing and analyzing computer networks for potential vulnerabilities to cyber-attacks, and the method comprises the operations recited by claim 10. Therefore, the rejection applied to claim 10 also applies to claim 23. Claim 10 is rejected under the same rationale as claim 23.
Claim 28:
Regarding claim 28, the claim is directed to a computer-readable storage media containing instructions that could be executed by the VCD system of claim 1 to implement the limitations recited by claim 10. Therefore, the rejection applied to claim 10 also applies to claim 28. Claim 10 is rejected under the same rationale as claim 28.
Conclusion
14. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
Fischer e Silva et al. (US 11,563,765 B2) discloses emulating a known attack and detecting a security technology’s failure to respond by the absence of a corresponding security event in the security technology’s log.
Nachenberg et al. (US 10,469, 509 B2) discloses gathering indicators of compromise from a plurality of providers, scoring them, and removing indicators based on the performance score.
15. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BIN QING ZHENG whose telephone number is (703)756-1535. The examiner can normally be reached on M-F 9:30 am -5:30 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip J. Chea can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BIN QING ZHENG/
Examiner, Art Unit 2499
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499