DETAILED ACTION
This communication responsive to the Application No. 18/462,817 filed on 07/22/2026. Claims 1-20 are pending and are directed towards SOFTWARE SECURITY MANAGEMENT.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to arguments
The Rejection of Claims Under §101
Applicants’ arguments regarding rejection of claims under 1-20 have been fully considered and are not persuasive. Determining whether a rule meets a threshold and whether that control prevents a risk corresponding to a defect and then reducing the security debt score are evaluations and judgement that a person can perform in the mind. The claim is directed to a method of organizing human activity, in that assessing an obligation and crediting a mitigating act against it and adjusting the outstanding balance is a standard risk management practice. Hence, the claims 1-6,8-20 have been rejected under 35 U.S.C. 101.
The Rejection of Claims Under §103
Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
The new rejection relies on Roytman, Kao and Ji. Roytman scores risk from detected vulnerabilities, compares those scores to thresholds and recommends remediation timeframes, which is what has to be fixed inside a stated window. This is analogous to determining remediation options for a particular time period and the display and user selection and re-computation of the score as fixes land. Roytman also ranks remediation by score which impact across an asset population. Kao supplies the debt framing and the score’s composition. It scores an application as a composite that includes Domain Score 2, technical debt (outstanding security findings), alongside code-quality and defect rate inputs. Kao gates release on the score clearing a threshold. It applies an exponential aging function to open findings and scopes assessment to the enterprise ecosystem by enumerating programming language, framework, platform and deploy model as weighted drivers and credits a WAF in the infrastructure terms, which establishes that a compensating control lowers the score. Ji supplies the validation gate. It generates candidate WAF rules from a scanner report, presents them for administrator approval, checks them against a rule schema and by regular expression content check, then replays the reported attack message and confirms from the log that the rule fired before deployment. This provides both user selection and validating that a rule meets a baseline along with the control preventing the risk corresponding to the defect.
Kao already labels its metric technical debt and credits a WAF as yes or no, so imposing Roytman’s time bound obligations on Kao’s debt score and conditioning Kao’s WAF credit on Ji’s test before deploy verification is a combination which holds remediation to a defined schedule while ensuring the score reflects only compensating controls verified to block the specific defect.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of
matter, or any new and useful improvement thereof, may obtain a patent therefore, subject to the
conditions and requirements of this title.
Claims 1,15 and 19 are rejected under 35 U.S.C. 101 because the claimed
invention is directed to non-statutory subject matter.
Independent claim
Step 1:
Claims 1, 15,19 are drawn to a method, therefore falls under one of four
categories of statutory subject matter (process/method, machines/products/apparatus
manufactures, and compositions of matter).
Step 2A, Prong 1:
Nonetheless, claims 1,15,19 is directed to a judicially recognized exception of an abstract idea without significantly more. Claim 1,15,19 recites a method of "identifying a security risk assessment', "determining, using a model, a security debt score", "comparing the security debt score”, “displaying” on a user interface, “receiving” selected option and “updating” the displayed score, enumerates a mental concept. human can evaluate data and make decisions. These are steps that are carried out using basic mental processes and mathematical evaluation which can be performed in the human mind or using pen and paper. A security analyst reviewing a firewall ruleset against a policy checklist, concluding that the rule sufficiently covers a known defect and marking down a risk tally on a sheet performs the recited claim. As such, the steps of identifying, determining and comparing are nothing more than an abstract mental concept (MPEP 2106.04(a)(2)(III})).
Step 2A, Prong 2:
Claims 1,15 and 19 recites additional step of "determining, for a particular time
period, a minimum remediation for the at least one security defect" and "reducing the
security debt score based on detection of implementation of a compensating security
control including at least one of a web application firewall an intrusion detection system,
or an intrusion prevention system", "outputting an indication of the reduced security debt
score" that fails to integrate the abstract idea into a practical application. Determining a
remediation is a post- solution activity taken after the abstract idea is performed. This
additional step, to determine a remediation action constitutes as basic planning or
scheduling function and detection of implementation of a compensating control and
outputting the score are functional and outcome-based. These reflect the collection,
evaluation and presentation of security-related information and do not recite any
technical steps for deploying, enforcing or modifying the operation of a web application
firewall, IDS/IPS and hence is a form of insignificant extra solution activity where
updating a score based on detection is necessary for all uses of the judicial exception.
The additional step fails to integrate the abstract idea into a practical application
because it does not impose any meaningful limits on practicing the abstract idea (MPEP
2106.05(g)) (MPEP 2106.05(g)).
Step 2B:
The additional step that is a form of insignificant extra-solution activity, does not
amount to significantly more than an abstract idea because the courts have recognized
that this additional step to be well-understood, routine, and conventional when claimed
in a merely generic manner for comparison and determination (See MPEP
2106.05(d)(IN)(i)). As such claims 1,15 and 19 is not patent eligible.
Dependent claims
Dependent claims 2-6,8-14, 16-18, 20 are ineligible for the same reasons given with respect to claims 1, 15, 19.
Step 1:
Claims 2-6,8-14,16-18, 20 are drawn to a method, therefore falls under one of four categories of statutory subject matter (process/method, machines/products/apparatus, manufactures, and compositions of matter).
Step 2A-2B:
Dependent claims 2-6,8-14, 16-18, 20 recites additional steps of "identifying a largest cause of the security debt score" and others that fails to integrate the abstract idea into a practical application. These steps involve observation, evaluation, judgment and opinion of a method that can be performed in a human mind. The steps performed in the dependent claims are either of longstanding economic principles (interest) or routine data processing steps that lack inventive concepts and amount to a mental or mathematical process.
These additional steps that is a form of insignificant extra-solution activity, does not amount to significantly more than an abstract idea because the courts have recognized that this additional step to be well-understood, routine, and conventional when claimed in a merely generic manner for identifying and determining a remediation (See MPEP 2106.05(d)(II)(i)). As such dependent claims 2-6,8-14, 16-18, 20 are not patent eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 4,5,6,8-14 are rejected under 35 U.S.C. 103 as being unpatentable over Roytman et al. (US 20210336984 A1), hereinafter referred to as Roytman in view of Kao et al. (US 20190205542 A1), hereinafter referred to as Kao in further view of Ji et al. (US 20130019314 A1), hereinafter referred to as Ji
As per claim 1, Roytman discloses A method for security debt management comprising:
identifying a security risk assessment including at least one security defect of an application; (Computing a time to remediate for asset vulnerabilities, computing a third time to remediate for the first category, Roytman, para [0010], claim 10. The asset vulnerabilities are processed to identify vulnerabilities in assets/ applications and categorizing them)
determining, using a model, a security debt score for the application based on the security risk assessment; (Causing displaying a remediation grid, identifying a number of asset vulnerabilities to be remediated within the first time, the second time, the third time and the fourth time, Roytman, claim 10, para [0025]).
However, Kao does not explicitly disclose the limitations:
determining whether the security debt score is below a security debt threshold for the application by comparing the security debt score to the security debt threshold for the application;
in response to determining the security debt score is below the security debt threshold, automatically determining, for a particular time period, one or more remediation options to reduce the security debt score, the one or more remediation options including a minimum remediation due during the particular time period, the minimum remediation based on the at least one security defect and the security debt score;
displaying, on a user interface, the security debt score and a selectable menu including the one or more remediation options;
reducing the security debt score based on detection of implementation of the user selected remediation option, the user selected remediation option being a compensating security control including at least one of a web application firewall, an intrusion detection system, or an intrusion prevention system,
updating, on the user interface, the displayed security debt score
Kao discloses:
determining whether the security debt score is below a security debt threshold for the application by comparing the security debt score to the security debt threshold for the application; (The server computing device generates a security risk score for the software application under development based upon the generated security requirements and the identified security vulnerabilities and gates on it upon determining that the security risk score satisfies a predetermined criterion. The score is compared against a defined threshold any score below midpoint is considered “insufficient” or “high risk,” while any score above the positive mark is considered “sufficient” or “low risk., Kao, para [0011]).
in response to determining the security debt score is below the security debt threshold, automatically determining, for a particular time period, one or more remediation options to reduce the security debt score, the one or more remediation options including a minimum remediation due during the particular time period, the minimum remediation based on the at least one security defect and the security debt score; (Creates a second set of development tasks in the software development issue tracking platform based upon the identified security vulnerabilities and converting each mitigation plan into one or more development tasks and this score should be updated at the beginning or end of each sprint, Kao, para [0014]. Here, the auto-created backlog tasks and mitigation plans are the remediation options and the sprint is the particular time period)
displaying, on a user interface, the security debt score and a selectable menu including the one or more remediation options; (Apply a scoring model on application-characteristic information, then displays the results in an easily-digestible format, Kao, para [0009])
reducing the security debt score based on detection of implementation of the user selected remediation option, the user selected remediation option being a compensating security control including at least one of a web application firewall, an intrusion detection system, or an intrusion prevention system, (Table 3 scores “WAF Protection Yes 10/ No 50”, alongside “DDoS Protection” and “RASP Protection” shows the presence of the control drives the risk term down and the score is updated in near real time based on events. The security controls that the application has already implemented, or the external security components and/or security services that the application is leveraging, Kao, para [0040] and [0051]. Here, the WAF term in the infrastructure factor S_i is the compensating security control whose presences reduces the score).
updating, on the user interface, the displayed security debt score (The score can be updated in near real time based on events and/or at a scheduled frequency. This domain score should be updated in near real-time, as new security issues are identified via various process/ tools and as existing findings get remediated and closed with results displayed on the GUI, Kao, para [0051]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
However, Roytman in view of Kao does not explicitly disclose:
receiving a user selected remediation option from the one or more remediation options;
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and
Ji discloses:
receiving a user selected remediation option from the one or more remediation options; (The details of generated rule candidate, the candidate list for rule review. The security administrator preferably approves the rules generated from the App Scan report as shown in FIG. 23, and then the rules are imported to the runtime WASP engine for further testing. Search for rules that prevent similar vulnerability, test the rule, extend and improve the rules, and then deploy the rule, Ji, para [0084], [0113], [0154])
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and (Generate WASP rules using rule templates and an App Scan vulnerability report where templates come from WASP rule schema and application context information and the schema comprises a hypertext transfer protocol message model and a rule model, [0144]. in some cases, carry out regular expression checking on rule content, Ji, para [0157]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman and Kao with Ji by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao with virtual patching using firewall of Ji. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman and Kao with Ji so that the compensating control reduces the security debt score only once its rule has been checked against a baseline and confirmed to block the reported defect, preventing credit for controls that do not mitigate the vulnerability (See Ji, para [0157])
As per claim 4, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Roytman discloses:
the security risk assessment includes metadata corresponding to the at least one security defect, the metadata including at least one of type, severity, or age of the at least one security defect (Generating a remediation grid including asset vulnerabilities with attributes such as severity, vulnerability type and time since discovery, Roytman, para [0036]).
As per claim 5, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Kao discloses:
the security risk assessment corresponds to a set of applications, and wherein the minimum remediation applies to at least one of the set of applications (a consistent measurement of security risk across multiple applications in the entire enterprise ecosystem and the system takes into consideration of all dependency applications within the application ecosystem. Remediation tasks are created per application, Kao, para [0062]. The minimum remediation is interpreted as the application ecosystem or the dependency set is the set of applications)
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 6, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Kao discloses:
the security risk assessment corresponds to an enterprise, and wherein the minimum remediation applies to a common security defect among a plurality of applications of the enterprise (Enterprise scope is the business unit/enterprise level assessment or risk score and scoring is across different originations, Kao, para [0128]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 8, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Roytman discloses:
the security debt score is based on an amount, a type, a severity, or an age of an unmet security requirement of the application (Vulnerabilities with attributes such as severity of the vulnerability are factored into remediation timeframe calculations, Roytman, para [0007]).
As per claim 9, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Kao discloses:
interest is accrued on the security debt score, and wherein the minimum remediation is increased for a subsequent time period based on the interest. (FIG. 4 is an exemplary graph depicting the exponential behavior of age as a function of days operating within Domain score 2: technical debt which is outstanding security findings, Kao, para [0022]. Here, the exponential age function on outstanding findings is the accrued interest, the growth in findings needed to reach the unchanged release threshold is the increased minimum remediation)
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 10, Roytman, Kao ad Ji disclose the method of claim 1, wherein
Furthermore, Roytman discloses:
the minimum remediation is increased at an end of a subsequent time period when the minimum remediation is not addressed during the subsequent time period (A time to remediate may be computed for only a subset of the first vulnerability data where the resolution of the vulnerability was remediation. A time to remediate may be computed for only a subset of the first vulnerability data where the resolution of the vulnerability was the use of the vulnerability in an attack. Multiple times to remediate may be computed using the subsets of the first vulnerability data, Roytman, para [0046]).
As per claim 11, Roytman, Kao and Ji disclose the method of claim 1, further comprising
Furthermore, Kao discloses:
displaying a carried debt balance, the minimum remediation, an interest accrued if the carried debt balance is not paid, and a penalty due if the minimum remediation is not addressed (Updated in near real-time, as new security issues are identified via various process/tools and as existing findings get remediated and closed, Kao, para [0134]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 12, Roytman, Kao and Ji disclose the method of claim 1, further comprising
Furthermore, Roytman discloses:
determining, for a subsequent time period, a future minimum remediation, before the subsequent time period, for the at least one security defect of the application to prevent a penalty based on the security debt score (The server computer is then able to categorize asset vulnerabilities in second vulnerability data corresponding to a particular networked environment and assign the computed time to remediate for each category to each asset vulnerability in said category, Roytman, para [0019]).
As per claim 13, Roytman, Kao and Ji disclose the method of claim 1, further comprising
Furthermore, Kao discloses:
identifying a largest cause of the security debt score including at least one of a programming language, a host, a deployment, or a framework of the application, and displaying the largest cause (Every enumerated cause appears as a scored, weighted contributor: programming language (e.g., Java, Node JS), framework like Spring MVC, MEAN Stack, code components/ external libraries, platform such as Web sphere, Tomcat, Windows Server, RedHat and Deploy Model Physical data center 10 or private cloud 25 and public cloud 50, each with the weight based on the severity of each CVE according to the CVSS score. The weighted per factor breakdown makes ranking them a design choice, Kao, para [0120]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 14, Roytman, Kao and Ji disclose the method of claim 1, wherein
Furthermore, Kao discloses:
the minimum remediation is based on a total technical debt score, the total technical debt score including the security debt score and at least one other technical debt score based on a bug or a missing feature of the application (Domain Score 2: Technical Debt (i.e. Outstanding Security Findings) as a component of composite total: S=R.sub.min+S.sub.R+S.sub.D+S.sub.M+Δ, where D is technical debt, concerning vulnerabilities. Low code quality, low QA code coverage, and high QA defect rates has a negative impact on the score, Kao, para [0064], [0193])
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 15, Roytman discloses at least one non-transitory machine-readable medium including instructions for security debt management, which when executed by processing circuitry, cause the processing circuitry to:
identify a security risk assessment including at least one security defect of an application; (Computing a time to remediate for asset vulnerabilities, computing a third time to remediate for the first category, Roytman, para [0010], claim 10. The asset vulnerabilities are processed to identify vulnerabilities in assets/ applications and categorizing them)
determine, using a model, a security debt score for the application based on the security risk assessment; (Causing displaying a remediation grid, identifying a number of asset vulnerabilities to be remediated within the first time, the second time, the third time and the fourth time, Roytman, claim 10, para [0025]).
determine whether the security debt score is below a security debt threshold for the application by comparison of the security debt score to the security debt threshold for the application; (The server computing device generates a security risk score for the software application under development based upon the generated security requirements and the identified security vulnerabilities and gates on it upon determining that the security risk score satisfies a predetermined criterion. The score is compared against a defined threshold any score below midpoint is considered “insufficient” or “high risk,” while any score above the positive mark is considered “sufficient” or “low risk., Kao, para [0011]).
in response to determining the security debt score is below the security debt threshold, automatically determine, for a particular time period, one or more remediation options to reduce the security debt score, the one or more remediation options including a minimum remediation due during the particular time period, the minimum remediation based on the at least one security defect and the security debt score; (Creates a second set of development tasks in the software development issue tracking platform based upon the identified security vulnerabilities and converting each mitigation plan into one or more development tasks and this score should be updated at the beginning or end of each sprint, Kao, para [0014]. Here, the auto-created backlog tasks and mitigation plans are the remediation options and the sprint is the particular time period)
display, on a user interface, the security debt score and a selectable menu including the one or more remediation options; (Apply a scoring model on application-characteristic information, then displays the results in an easily-digestible format, Kao, para [0009])
reduce the security debt score based on detection of implementation of the user selected remediation option, the user selected remediation option being a compensating security control including at least one of a web application firewall, an intrusion detection system, or an intrusion prevention system, (Table 3 scores “WAF Protection Yes 10/ No 50”, alongside “DDoS Protection” and “RASP Protection” shows the presence of the control drives the risk term down and the score is updated in near real time based on events. The security controls that the application has already implemented, or the external security components and/or security services that the application is leveraging, Kao, para [0040] and [0051]. Here, the WAF term in the infrastructure factor S_i is the compensating security control whose presences reduces the score).
update, on the user interface, the displayed security debt score (The score can be updated in near real time based on events and/or at a scheduled frequency. This domain score should be updated in near real-time, as new security issues are identified via various process/ tools and as existing findings get remediated and closed with results displayed on the GUI, Kao, para [0051]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
However, Roytman and Kao do not explicitly disclose the limitation:
receive a user selected remediation option from the one or more remediation options;
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and
Ji discloses:
receive a user selected remediation option from the one or more remediation options; (The details of generated rule candidate, the candidate list for rule review. The security administrator preferably approves the rules generated from the App Scan report as shown in FIG. 23, and then the rules are imported to the runtime WASP engine for further testing. Search for rules that prevent similar vulnerability, test the rule, extend and improve the rules, and then deploy the rule, Ji, para [0084], [0113], [0154])
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and (Generate WASP rules using rule templates and an App Scan vulnerability report where templates come from WASP rule schema and application context information and the schema comprises a hypertext transfer protocol message model and a rule model, [0144]. in some cases, carry out regular expression checking on rule content, Ji, para [0157])
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman and Kao with Ji by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao with virtual patching using firewall of Ji. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman and Kao with Ji so that the compensating control reduces the security debt score only once its rule has been checked against a baseline and confirmed to block the reported defect, preventing credit for controls that do not mitigate the vulnerability (See Ji, para [0157])
As per claim 17, Roytman, Kao and Ji disclose the at least one non-transitory machine-readable medium of claim 15, wherein
Furthermore, Roytman discloses:
the security risk assessment includes at least one compensating control for the application and metadata corresponding to the at least one security defect, the metadata including at least one of type, severity, or age of the at least one security defect (Generating a remediation grid including asset vulnerabilities with attributes such as severity, vulnerability type and time since discovery, Roytman, para [0036])
As per claim 18, Roytman, Kao and Ji disclose the at least one non-transitory machine-readable medium of claim 15, wherein
Furthermore, Kao discloses:
the minimum remediation is based on a total technical debt score, the total technical debt score including the security debt score and at least one other technical debt score based on a bug or a missing feature of the application (Domain Score 2: Technical Debt (i.e. Outstanding Security Findings) as a component of composite total: S=R.sub.min+S.sub.R+S.sub.D+S.sub.M+Δ, where D is technical debt, concerning vulnerabilities. Low code quality, low QA code coverage, and high QA defect rates has a negative impact on the score, Kao, para [0064], [0193]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
As per claim 19, Roytman discloses a system for security debt management comprising:
processing circuitry; (A processor, Roytman, para [0029])
a display device; (A display on a computing device, Roytman, para [0032])
memory, including instructions, which when executed by the processing circuitry, cause the processing circuitry to perform operations to: (Main memory, Roytman, para [0029]).
identify a security risk assessment including at least one security defect of an application; (Computing a time to remediate for asset vulnerabilities, computing a third time to remediate for the first category, Roytman, para [0010], claim 10. The asset vulnerabilities are processed to identify vulnerabilities in assets/ applications and categorizing them)
determine, using a model, a security debt score for the application based on the security risk assessment; (Causing displaying a remediation grid, identifying a number of asset vulnerabilities to be remediated within the first time, the second time, the third time and the fourth time, Roytman, claim 10, para [0025]).
However, Roytman does not explicitly disclose the limitations:
determine whether the security debt score is below a security debt threshold for the application by comparison of the security debt score to the security debt threshold for the application;
in response to determining the security debt score is below the security debt threshold, automatically determine, for a particular time period, one or more remediation options to reduce the security debt score, the one or more remediation options including a minimum remediation due during the particular time period, the minimum remediation based on the at least one security defect and the security debt score;
cause the display device to display a carried debt balance, the minimum remediation, an interest accrued if the carried debt balance is not paid, and a penalty due if the minimum remediation is not addressed;
cause the display device to display the security debt score and a selectable menu including the one or more remediation options;
reduce the security debt score based on detection of implementation of the user selected remediation option, the user selected remediation option being a compensating security control including at least one of a web application firewall, an intrusion detection system, or an intrusion prevention system,
cause the display device to update the displayed security debt score
Kao discloses:
determine whether the security debt score is below a security debt threshold for the application by comparison of the security debt score to the security debt threshold for the application; (The server computing device generates a security risk score for the software application under development based upon the generated security requirements and the identified security vulnerabilities and gates on it upon determining that the security risk score satisfies a predetermined criterion. The score is compared against a defined threshold any score below midpoint is considered “insufficient” or “high risk,” while any score above the positive mark is considered “sufficient” or “low risk., Kao, para [0011]).
in response to determining the security debt score is below the security debt threshold, automatically determine, for a particular time period, one or more remediation options to reduce the security debt score, the one or more remediation options including a minimum remediation due during the particular time period, the minimum remediation based on the at least one security defect and the security debt score; (Creates a second set of development tasks in the software development issue tracking platform based upon the identified security vulnerabilities and converting each mitigation plan into one or more development tasks and this score should be updated at the beginning or end of each sprint, Kao, para [0014]. Here, the auto-created backlog tasks and mitigation plans are the remediation options and the sprint is the particular time period)
cause the display device to display a carried debt balance, the minimum remediation, an interest accrued if the carried debt balance is not paid, and a penalty due if the minimum remediation is not addressed; (Updated in near real-time, as new security issues are identified via various process/tools and as existing findings get remediated and closed, Kao, para [0134]).
cause the display device to display the security debt score and a selectable menu including the one or more remediation options; (Apply a scoring model on application-characteristic information, then displays the results in an easily-digestible format, Kao, para [0009])
reduce the security debt score based on detection of implementation of the user selected remediation option, the user selected remediation option being a compensating security control including at least one of a web application firewall, an intrusion detection system, or an intrusion prevention system, (Table 3 scores “WAF Protection Yes 10/ No 50”, alongside “DDoS Protection” and “RASP Protection” shows the presence of the control drives the risk term down and the score is updated in near real time based on events. The security controls that the application has already implemented, or the external security components and/or security services that the application is leveraging, Kao, para [0040] and [0051]. Here, the WAF term in the infrastructure factor S_i is the compensating security control whose presences reduces the score).
cause the display device to update the displayed security debt score (The score can be updated in near real time based on events and/or at a scheduled frequency. This domain score should be updated in near real-time, as new security issues are identified via various process/ tools and as existing findings get remediated and closed with results displayed on the GUI, Kao, para [0051])
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
However, Roytman in view of Kao does not explicitly disclose the limitations:
receive a user selected remediation option from the one or more remediation options;
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and
Ji discloses:
receive a user selected remediation option from the one or more remediation options; (The details of generated rule candidate, the candidate list for rule review. The security administrator preferably approves the rules generated from the App Scan report as shown in FIG. 23, and then the rules are imported to the runtime WASP engine for further testing. Search for rules that prevent similar vulnerability, test the rule, extend and improve the rules, and then deploy the rule, Ji, para [0084], [0113], [0154])
wherein reducing the security debt score is performed after automatically validating that a rule of the compensating security control meets a baseline and that the compensating security control deterred a risk corresponding to the at least one security defect; and (Generate WASP rules using rule templates and an App Scan vulnerability report where templates come from WASP rule schema and application context information and the schema comprises a hypertext transfer protocol message model and a rule model, [0144]. in some cases, carry out regular expression checking on rule content, Ji, para [0157]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman and Kao with Ji by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao with virtual patching using firewall of Ji. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman and Kao with Ji so that the compensating control reduces the security debt score only once its rule has been checked against a baseline and confirmed to block the reported defect, preventing credit for controls that do not mitigate the vulnerability (See Ji, para [0157])
As per claim 20, Roytman, Kao and Ji disclose the system of claim 19, wherein the instructions, when executed, further cause the processing circuitry to
Furthermore, Kao discloses:
identify a largest cause of the security debt score including at least one of a programming language, a host, a deployment, or a framework of the application; and wherein the display device is further caused to display the largest cause (Every enumerated cause appears as a scored, weighted contributor: programming language (e.g., Java, Node JS), framework like Spring MVC, MEAN Stack, code components/ external libraries, platform such as Web sphere, Tomcat, Windows Server, RedHat and Deploy Model Physical data center 10 or private cloud 25 and public cloud 50, each with the weight based on the severity of each CVE according to the CVSS score. The weighted per factor breakdown makes ranking them a design choice, Kao, para [0120]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman with Kao by incorporating the method of
computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao. It would have been obvious to a person of
ordinary skill in the art before the effective filing date of the claimed invention to
combine Roytman with Kao in order to treat an application’s outstanding security findings as an accruing debt that must be paid down within a defined remediation window so that aging findings are prioritized before they raise risk further (See Kao, para [0051])
Claims 2, 3 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Roytman et al. (US 20210336984 A1), hereinafter referred to as Roytman in view of Kao et al. (US 20190205542 A1), hereinafter referred to as Kao in further view of Ji et al. (US 20130019314 A1), hereinafter referred to as Ji in further view of Cerise et al. (US 20120317014 A1), hereinafter referred to as Cerise
As per claim 2, Roytman, Kao and Ji disclose the method of claim 1, wherein
However, Roytman, Kao and Ji do not explicitly disclose the limitation:
the minimum remediation is determined based on the security debt score traversing the security debt threshold.
Cerise discloses:
the minimum remediation is determined based on the security debt score traversing the security debt threshold. (If the customer's income greater than $75,000 and the customer's credit score is greater than 700, Cerise, para [0032]. These thresholds gate which minimum payment is extended)
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman, Kao, Ji with Cerise by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao and virtual patching using firewall of Ji with reducing debt of Cerise. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman, Kao, Ji with Cerise in order to actively optimize credit score and reduce debt (See Cerise, para [0032])
As per claim 3, Roytman, Kao and Ji disclose the method of claim 1, wherein
However, Roytman, Kao and Ji do not explicitly disclose the limitation:
the minimum remediation is based on a default minimum remediation for the particular time period when the security debt score does not traverse the security debt threshold.
Cerise discloses:
the minimum remediation is based on a default minimum remediation for the particular time period when the security debt score does not traverse the security debt threshold (If the customer decided not to allocate any of the available unallocated income to pay down debt, then the funds required to pay credit card minimums and expenses are allocated, Cerise, para [0027]).
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman, Kao, Ji with Cerise by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao and virtual patching using firewall of Ji with reducing debt of Cerise. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman, Kao, Ji with Cerise in order to actively optimize credit score and reduce debt (See Cerise, para [0032])
As per claim 16, Roytman, Kao and Ji disclose the at least one non-transitory machine-readable medium of claim 15, wherein
However, Roytman, Kao and Ji do not explicitly disclose the limitation:
the minimum remediation is determined based on whether the security debt score traverses the security debt threshold, and when the security debt score does not traverse the security debt threshold, applying a default minimum remediation for the particular time period
Cerise discloses:
the minimum remediation is determined based on whether the security debt score traverses the security debt threshold, and when the security debt score does not traverse the security debt threshold, applying a default minimum remediation for the particular time period (If the customer's income greater than $75,000 and the customer's credit score is greater than 700, Cerise, para [0032]. These thresholds gate which minimum payment is extended)
A person of ordinary skill in the art before the effective filing date of the claimed
invention would have combined Roytman, Kao, Ji with Cerise by incorporating the method of computing times to remediate for asset vulnerabilities of Roytman in the system of automated risk remediation of Kao and virtual patching using firewall of Ji with reducing debt of Cerise. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Roytman, Kao, Ji with Cerise in order to actively optimize credit score and reduce debt (See Cerise, para [0032])
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the
examiner should be directed to RAGHAVENDER CHOLLETI whose telephone number is (703) 756-1065. The examiner can normally be reached Monday - Thursday 8AM-5PM EST & Friday variable.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s
supervisor, RUPAL DHARIA can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be
obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service
Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully Submitted
/RAGHAVENDER NMN CHOLLETI/Examiner, Art Unit 2492
/RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492