Prosecution Insights
Last updated: October 01, 2026
Application No. 18/532,521

Dynamic Honeypot Generation and Deployment

Non-Final OA §103
Filed
Dec 07, 2023
Examiner
COLIN, CARL G
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
3 (Non-Final)
48%
Grant Probability
Moderate
3-4
OA Rounds
1y 6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 48% of resolved cases
48%
Career Allowance Rate
65 granted / 136 resolved
-10.2% vs TC avg
Strong +54% interview lift
Without
With
+54.1%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
6 currently pending
Career history
145
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
17.2%
-22.8% vs TC avg
§112
16.9%
-23.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 136 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION In communications filed on 1/22/2026, the following claims 1-20 are canceled, and new claims 21-40 are presented for examination. Claims 21-40 are pending. Response to Arguments Applicant's arguments filed on 1/22/2026 have been fully considered but they are not persuasive. Applicant files new claim 21 to include previous limitations from claims 1, 2, and 6-8. The added features are “…wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage; …wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment”. Applicant argues that the combination of Miretsky and Huang does not suggest the claimed invention. Miretsky's service-oriented decoys and Huang's observational honeypots address different problems-broad attack response vs. isolated monitoring-without motivation to integrate the claimed ML training with detailed labeled data, chained honeypot generation based on patterns/tactics, timed behavior-based termination, or commanded reporting. Adding these would require hindsight, as the references lack the enterprise-specific attack details and adaptive redirection for deterrence/intelligence. Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. With respect to the arguments regarding claims 30-40, the new features are being considered and a new ground of rejection below is set forth as appropriate. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 1/22/2026 has been entered. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 21-26, 30-31, and 33-36 is/are rejected under 35 U.S.C. 103 as being unpatentable over US Patent 11,818,172 to Miretsky et al hereinafter Miretsky in view of Foreign Patent CN 117040871 to Huang et al hereafter Huang in view of Foreign Patent Publication CN 117544349 to Jiang et al hereinafter Jiang, in view of US Patent Publication US 20230011004 to Fellows hereinafter Fellows, and in view of Applicant’s Admitted Prior Art (AAPA). Regarding claim 21, Miretsky discloses a dynamic honeypot generation and deployment system for providing adaptive defense against threat actors in a computing environment comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: train a machine learning model to identify threat actor activity using historical threat actor event occurrences and information related to the threat actor event occurrences, (See Miretsky fig.4 disclosing a system for implementing the invention, and further discloses an attack response service using ML and AI to collect, monitor activities and provides the system the ability to automatically learn and identify and classify threat actor activities, see col. 4, lines 33-57); Miretsky discloses monitor a computing network for threat actor activity (see column 2, lines 16-30 monitoring file transfer activity); detect the threat actor activity on the computing network (see col. 2, lines 31-36); analyze the detected threat actor activity with the machine learning model (see col. 3, lines 24- 35); generate at least one dynamic honeypot (see col. 2, lines 41-45 a honeypot is created); deploy the at least one generated dynamic honeypot into the computing network (see col. 2, lines 41-45 and 58-60 honeypot may be simulated); monitor the deployed at least one dynamic honeypot for additional threat actor activity (see col. 3, lines 12-23 any activity is monitored within the honeypot). Miretsky does not explicitly disclose: wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage; analyze the detected threat actor activity with the machine learning model to determine that the threat actor is using a port detection tool; generate at least one dynamic honeypot having open ports based on the analyzed threat actor activity. detect the additional threat actor activity associated with the deployed at least one dynamic honeypot;- analyze the detected additional threat activity associated with the at least one dynamic honeypot with the machine learning model;- generate at least one additional dynamic honeypot based on the analyzed threat actor activity associated with the at least one dynamic honeypot, wherein generating the at least one additional dynamic honeypot is based on insights determined from the analysis of patterns or tactics of the threat actor in the deployed at least one dynamic honeypot, and wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment;- deploy the at least one generated additional dynamic honeypot into the computing network;- monitor the deployed at least one additional dynamic honeypot for further threat actor activity;- detect the further threat actor activity associated with the deployed additional at least one dynamic honeypot;- analyze the detected further threat activity associated with the at least one additional dynamic honeypot with the machine learning model;- terminate a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment;- generate a summary of results of threat actor detection based on the monitoring and the detection by a reporting system; and- transmit the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. Although Miretsky teaches that the invention uses “ML, an application of AI to automatically learn and improve from experience without being explicitly programmed” (column 4, lines 47-58), Miretski is silent about repeating the process to generate additional dynamic honeyspot. However, Huang in an analogous art discloses a dynamic honeypot (see abstract) and further discloses “the invention simulates the vulnerability in the target system and attracts the attacker to attack by deploying the honey pot technology” (see page 3, third paragraph). “As a preferred solution, the protected honey pot is deployed with a monitoring tool, detecting network intrusion, malicious software and user abnormal behaviour, generating alarm and evaluation information, obtaining a honey pot with complete log and monitoring function, comprising: ; …deploying the network intrusion detection system, monitoring the network intrusion action, including port scanning” (see page 3, sixth paragraph and page 4, first paragraph) that meets the recitation of analyze the detected threat actor activity to determine that the threat actor is using a port detection tool with the machine learning model. Huang further discloses “As a preferred solution, based on the attacker's behavior and system risk, and the deployment environment of the honey can, determining whether to reuse the honey can, comprising: evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker; if at least one item is judged not to reuse the honey pot based on the attacker action and system risk and the deployment environment of the honey pot, finally not to reuse the honey pot;” (see page 5, paragraphs 3-4) that meets the recitation of generate at least one dynamic honeypot having open ports based on the analyzed threat actor activity. Huang further discloses detect the additional threat actor activity associated with the deployed at least one dynamic honeypot (see page 2, from the middle content of the invention to page 3, paragraph 1 disclosing determining the attacker action and the system risk; based on the attacker action and system risk, and the deployment environment of the honey pot, determining whether to reuse the honey pot; aiming at the honey pot which cannot be multiplexed directly with risk, judging whether it is the configuration of partially updated honey pot or completely replaced honey pot which meets the claimed limitation); analyze the detected additional threat activity associated with the at least one dynamic honeypot with the machine learning model (see page 2, from the middle content of the invention to page 3, paragraph 1, monitoring attacker activities, obtaining vulnerability information); generate at least one additional dynamic honeypot based on the analyzed threat actor activity associated with the at least one honeypot wherein generating the at least one additional dynamic honeypot is based on insights determined from the analysis of the threat actor's patterns or tactics in the deployed at least one dynamic honeypot (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity). wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment (see page 13, judging whether there is known loophole and there is no timely repairing condition. according to the network topology, system architecture and device configuration attribute of the honey pot, obtaining the deployment environment of the honey pot, and evaluating the network topology, if at least one of the following conditions is not judged, the honey pot is not used repeatedly, comprising the following steps: evaluating the connection mode and position of the honey pot and the network device, determining whether the network flow is effectively isolated and monitored; evaluating the system design and component configuration of the honey pot, comprising hardware device, operating system and application program, determining whether the system design and component configuration meet the expected safety requirement; evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker). deploy the at least one generated additional dynamic honeypot into the computing network (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity); monitor the deployed at least one additional dynamic honeypot for further threat actor activity (see also steps S107 and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots). Huang further discloses detect the further threat actor activity associated with the deployed additional at least one dynamic honeypot (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity, see also steps S107and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots). (See also end of page 13, where Huang discloses reconfiguring honeypots to attract further and two or more machines can be deployed in the honeypot and different network services and applications can be simulated to increase the interest of attackers). analyze the detected further threat activity associated with the at least one additional dynamic honeypot with the machine learning model (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity, see also steps S107and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots); (See also page 14 evaluating the updating ability of the current honey pot). Huang further discloses generate a summary of the results of threat actor detection based on the monitoring and the detection by a reporting system, ( see page 2 last paragraph disclosing vulnerability report so as to improve the vulnerability scanning; page 4 discloses “performing evaluation on the monitored honey pot activity and attacker behavior, determining the risk level in the system, generating a risk evaluation report, determining the attacker behavior and the system risk, the risk evaluation report comprises dividing the risk into low, middle, three higher levels, and association of attacker behaviour and system risk; further comprising: using the density based outlier detection algorithm to evaluate the monitored honey pot activity and attacker action, determining the risk level in the system, and generating the risk evaluation report”. Huang also discloses display a summary, see page 5, paragraph 2 “generating an outlier distribution map according to the position information of the outlier, and visually displaying the risk condition in the system. Information is provided for each outlier, including the eigenvector of the outlier, the class to which the outlier belongs. according to the historical monitoring data, evaluating the change trend of the outlier in the system, predicting the future risk condition and generating the risk evaluation report”. Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky to analyze with the machine learning model the detected threat actor activity to determine that the threat actor is using a port detection tool and to generate at least one dynamic honeypot based on the analyzed threat actor activity and to generate additional dynamic honeypots based on detection and analysis of additional threat activity as suggested by Huang. One of ordinary skill in the art would have been motivated to do so because it would allow the system to optimize the vulnerability scanning and honey pot technoloby by constantly simulating, detecting the attacker behavior, and based on the attacker action and system risk updating the honeypot (See Huang, abstract). Miretsky further discloses wherein deployment of the at least one generated dynamic honeypot into the computing network comprises deployment into a sandbox of the computing network and wherein the sandbox isolates the threat actor for further analysis of the threat actor's patterns or tactics (see col. 3, lines 41-58 honeypot may be connected to a sandbox). (See also Huang, page 3, paragraph 2 honey pot isolated from the real system and monitored the attacker). Huang discloses monitoring isolated honeypot as a sandbox. The combination of Miretski and Huang does not explicitly disclose terminate a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment. However, Jiang in the same field of endeavor teaches dynamically generating honey pot according to attack protocol and further discloses terminate a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment. (See abstract disclosing if the honeypot does not detect the attack flow over a period of time release it to avoid attack trace of other attackers, attack flow is guided and stored in the honey tank). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky to and after a specific predetermined time period, terminate the sandbox to remove threat actor associated with the further threat activity, wherein the specific predetermined time period is based on the analysis of the threat actor's behavior within the sandbox as taught by Jiang. One of ordinary skill in the art would have been motivated to do so because the attack trace of other attackers will not be detected, the feasibility of tracing source is improved; the attack flow is guided into the honey tank and stored in the honey tank, which increases the difficulty for the attacker to destroy the attack evidence as suggested by (Jiang, see abstract). Miretski does not explicitly disclose and transmit a summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. However, Fellows in the same field of endeavor discloses generate a summary of results of threat actor detection based on the monitoring and the detection by a reporting system (see para. 20 disclosing generating recorded events); and transmit the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary (see para. 20 disclosing configuring the recorded events to be displayed to a user to watch and observe what is happening… that meets the claimed limitation). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky and Huang to send the reports and results of Huang to an administrator so as to generate, by a reporting system, a summary indicating results of the monitoring and detection; and transmit the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. as taught by Fellows. One of ordinary skill in the art would have been motivated to do so because it would allow a human to visually contextualize the events occurring in the network in light of the activities and then to confirm the detected cyber threat as suggested by Fellows (see para 86). Miretski does not explicitly disclose wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. However, AAPA discloses wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. (See original specification, paragraphs 2-3). Regarding claim 22, the references as combined above disclose the dynamic honeypot generation and deployment system of claim 21, wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences include what was accessed, where it was accessed from, communication information, and how often information was accessed, (See Huang page 3, Huang discloses access rules that controls access by unauthorized users including a login auditing tool to monitor time of access, IP address for where it was access from) .and wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences are labelled based on whether or not corresponding threat occurrence information was ultimately identified as corresponding to a threat actor (See Huang page 4 obtaining the information from the external threat information source, identifying the potential attacker and the attack type, obtaining the threat information evaluation result; according to the behaviour mode of the user, comprising the login information of the user, the network communication flow of the system, the access behaviour of the user to the system file and the use condition of the system call, detecting the abnormal user behaviour and the potential attack behaviour, obtaining the user behaviour evaluation result). Regarding claim 23, the references as combined above disclose the dynamic honeypot generation and deployment system of claim 22, wherein deploying the at least one generated dynamic honeypot into the computing network comprises deploying the at least one generated dynamic honeypot into a sandbox environment within the computing network, wherein the deployment entices the threat actor into the sandbox environment, and wherein the sandbox environment isolates the threat actor and allows for further analysis of patterns or tactics of the threat actor for additional insights and system security. (See Huang, abstract and page 3, paragraph 2 honey pot isolated from the real system and monitored the attacker). (Huang discloses monitoring isolated honeypot as a sandbox.). Regarding claim 24, Miretsky discloses a method for generating and deploying dynamic honeypots performed by a computing platform that includes a processor and a non volatile memory storing computer executable instructions the method comprising: training, by the processor, a machine learning model to identify threat actor activity using historical threat actor event occurrences and information related to the threat actor event occurrences, (See Miretsky fig.4 disclosing a system for implementing the invention, and further discloses an attack response service using ML and AI to collect, monitor activities and provides the system the ability to automatically learn and identify and classify threat actor activities, see col. 4, lines 33-57); Miretsky discloses monitoring, by the processor, a computing network for threat actor activity (see column 2, lines 16-30 monitoring file transfer activity); detecting, by the processor, the threat actor activity on the computing network (see col. 2, lines 31-36); analyzing, by the processor, the detected threat actor activity with the machine learning model (see col. 3, lines 24- 35); generating, by the processor, at least one dynamic honeypot (see col. 2, lines 41-45 a honeypot is created); deploying, by the processor, the at least one generated dynamic honeypot into the computing network (see col. 2, lines 41-45 and 58-60 honeypot may be simulated); monitoring, by the processor, the deployed at least one dynamic honeypot for additional threat actor activity (see col. 3, lines 12-23 any activity is monitored within the honeypot); and transmitting by a processor, a notification of the detection of the threat actor activity and the deployment of the at least one generated dynamic honeypot (see col. 3, lines 20-23 issuing alert as a result of activity being determined to correlate to the honeypot reads on the claimed limitation as the honeypot is being simulated, see also col. 5, lines 5-10), wherein the method provides deterrence, adaptive defense, and intelligence gathering on threat actors and their associated threat activities (see page 13 For example, by analyzing the threat information, it is found that a group of attackers are targeted at the network server of the enterprise, and the motive is to obtain sensitive commercial secret information. .. Two or more virtual machines can be deployed in the honey pot, and different network services and applications can be simulated to increase the interest of attackers… Their technical capabilities are relatively high, they are able to make use of vulnerabilities for remote command execution, and they have a large number of attacking tools and resources. the security information and event management tool is used for counting and analyzing the attack mode of the attacker, the target IP address and the used attack tool. The attack action of the attacker to the honey pot is observed, and the configuration of the honey pot can be updated in time to increase the identification and defence ability of the new attack mode after the new attack method is found). Miretsky does not explicitly disclose: wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage;- detecting, by the processor, the further threat actor activity associated with the deployed additional at least one dynamic honeypot; analyzing, by the processor, the detected threat actor activity with the machine learning model to determine that the threat actor is using a port detection tool; generating, by the processor, at least one dynamic honeypot based on the analyzed threat actor activity; terminating, by the processor, a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment;- generating, by a reporting system, a summary of results of threat actor detection based on the monitoring and the detection;- transmitting, by the processor, the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. Although Miretsky teaches that the invention uses “ML, an application of AI to automatically learn and improve from experience without being explicitly programmed” (column 4, lines 47-58), Miretski is silent about repeating the process to generate additional dynamic honeyspot. However, Huang in an analogous art discloses a dynamic honeypot (see abstract) and further discloses “the invention simulates the vulnerability in the target system and attracts the attacker to attack by deploying the honey pot technology” (see page 3, third paragraph). “As a preferred solution, the protected honey pot is deployed with a monitoring tool, detecting network intrusion, malicious software and user abnormal behaviour, generating alarm and evaluation information, obtaining a honey pot with complete log and monitoring function, comprising: ; …deploying the network intrusion detection system, monitoring the network intrusion action, including port scanning” (see page 3, sixth paragraph and page 4, first paragraph) that meets the recitation of analyzing by the processor the detected threat actor activity with the machine learning model to determine that the threat actor is using a port detection tool. Huang further discloses “As a preferred solution, based on the attacker's behavior and system risk, and the deployment environment of the honey can, determining whether to reuse the honey can, comprising: evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker; if at least one item is judged not to reuse the honey pot based on the attacker action and system risk and the deployment environment of the honey pot, finally not to reuse the honey pot;” (see page 5, paragraphs 3-4) that meets the recitation of generating, by the processor, at least one dynamic honeypot based on the analyzed threat actor activity. Huang further discloses detecting, by the processor, the additional threat actor activity associated with the deployed at least one dynamic honeypot (see page 2, from the middle content of the invention to page 3, paragraph 1 disclosing determining the attacker action and the system risk; based on the attacker action and system risk, and the deployment environment of the honey pot, determining whether to reuse the honey pot; aiming at the honey pot which cannot be multiplexed directly with risk, judging whether it is the configuration of partially updated honey pot or completely replaced honey pot which meets the claimed limitation); analyzing, by the processor, the detected additional threat activity associated with the at least one dynamic honeypot with the machine learning model (see page 2, from the middle content of the invention to page 3, paragraph 1, monitoring attacker activities, obtaining vulnerability information); generating, by the processor, at least one additional dynamic honeypot based on the analyzed threat actor activity associated with the at least one honeypot wherein generating the at least one additional dynamic honeypot is based on insights determined from the analysis of the threat actor's patterns or tactics in the deployed at least one dynamic honeypot (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity). wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment” (see page 13, judging whether there is known loophole and there is no timely repairing condition. according to the network topology, system architecture and device configuration attribute of the honey pot, obtaining the deployment environment of the honey pot, and evaluating the network topology, if at least one of the following conditions is not judged, the honey pot is not used repeatedly, comprising the following steps: evaluating the connection mode and position of the honey pot and the network device, determining whether the network flow is effectively isolated and monitored; evaluating the system design and component configuration of the honey pot, comprising hardware device, operating system and application program, determining whether the system design and component configuration meet the expected safety requirement; evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker). deploying, by the processor, the at least one generated additional dynamic honeypot into the computing network (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity); monitoring, by the processor, the deployed at least one additional dynamic honeypot for further threat actor activity (see also steps S107and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots). Huang further discloses detecting, by the processor, the further threat actor activity associated with the deployed additional at least one dynamic honeypot (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity, see also steps S107and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots). (See also end of page 13, where Huang discloses reconfiguring honeypots to attract further and two or more machines can be deployed in the honeypot and different network services and applications can be simulated to increase the interest of attackers). analyzing, by the processor, the detected further threat activity associated with the at least one additional dynamic honeypot with the machine learning model (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity, see also steps S107and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots); (See also page 14 evaluating the updating ability of the current honey pot). Huang further discloses generating, by a reporting system, a summary of results of threat actor detection based on the monitoring and the detection, ( see page 2 last paragraph disclosing vulnerability report so as to improve the vulnerability scanning; page 4 discloses “performing evaluation on the monitored honey pot activity and attacker behavior, determining the risk level in the system, generating a risk evaluation report, determining the attacker behavior and the system risk, the risk evaluation report comprises dividing the risk into low, middle, three higher levels, and association of attacker behaviour and system risk; further comprising: using the density based outlier detection algorithm to evaluate the monitored honey pot activity and attacker action, determining the risk level in the system, and generating the risk evaluation report”. Huang also discloses displaying a summary, see page 5, paragraph 2 “generating an outlier distribution map according to the position information of the outlier, and visually displaying the risk condition in the system. Information is provided for each outlier, including the eigenvector of the outlier, the class to which the outlier belongs. according to the historical monitoring data, evaluating the change trend of the outlier in the system, predicting the future risk condition and generating the risk evaluation report”. Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky to analyze with the machine learning model the detected threat actor activity to determine that the threat actor is using a port detection tool and to generate at least one dynamic honeypot based on the analyzed threat actor activity and to generate additional dynamic honeypots based on detection and analysis of additional threat activity as suggested by Huang. One of ordinary skill in the art would have been motivated to do so because it would allow the system to optimize the vulnerability scanning and honey pot technoloby by constantly simulating, detecting the attacker behavior, and based on the attacker action and system risk updating the honeypot (See Huang, abstract). Miretsky further discloses wherein deployment of the at least one generated dynamic honeypot into the computing network comprises deployment into a sandbox of the computing network and wherein the sandbox isolates the threat actor for further analysis of the threat actor's patterns or tactics (see col. 3, lines 41-58 honeypot may be connected to a sandbox). (See also Huang, page 3, paragraph 2 honey pot isolated from the real system and monitored the attacker). Huang discloses monitoring isolated honeypot as a sandbox. The combination of Miretski and Huang does not explicitly disclose terminating, by the processor, a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment. However, Jiang in the same field of endeavor teaches dynamically generating honey pot according to attack protocol and further discloses terminating, by the processor, a sandbox environment into which the at least one dynamic honeypot was deployed after a specific predetermined time period to remove the threat actor associated with the further threat actor activity, wherein the specific predetermined time period is based on the analysis of the behavior of the threat actor within the sandbox environment; (see abstract disclosing if the honeypot does not detect the attack flow over a period of time release it to avoid attack trace of other attackers, attack flow is guided and stored in the honey tank). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky to and after a specific predetermined time period, terminate the sandbox to remove threat actor associated with the further threat activity, wherein the specific predetermined time period is based on the analysis of the threat actor's behavior within the sandbox as taught by Jiang. One of ordinary skill in the art would have been motivated to do so because the attack trace of other attackers will not be detected, the feasibility of tracing source is improved; the attack flow is guided into the honey tank and stored in the honey tank, which increases the difficulty for the attacker to destroy the attack evidence as suggested by (Jiang, see abstract). Miretski does not explicitly disclose transmitting, by the processor, the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. However, Fellows in the same field of endeavor discloses generating, by a reporting system, a summary of results of threat actor detection based on the monitoring and the detection; (see para. 20 disclosing generating recorded events); transmitting, by the processor, the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary (see para. 20 disclosing configuring the recorded events to be displayed to a user to watch and observe what is happening… that meets the claimed limitation). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky and Huang to send the reports and results of Huang to an administrator so as to generating, by a reporting system, a summary of results of threat actor detection based on the monitoring and the detection; transmitting, by the processor, the summary and one or more commands directing an administrator device to display the summary to the administrator device, wherein sending the one or more commands directing the administrator device to display the summary causes the administrator device to display the summary. as taught by Fellows. One of ordinary skill in the art would have been motivated to do so because it would allow a human to visually contextualize the events occurring in the network in light of the activities and then to confirm the detected cyber threat as suggested by Fellows (see para 86). Miretski does not explicitly disclose wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. However, AAPA discloses wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. (See original specification, paragraphs 2-3). Regarding claim 25, the references as combined above disclose the method of claim 24, wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences include what was accessed, where it was accessed from, communication information, and how often information was accessed, (See Huang page 3, Huang discloses access rules that controls access by unauthorized users including a login auditing tool to monitor time of access, IP address for where it was access from), and wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences are labelled based on whether or not corresponding threat occurrence information was ultimately identified as corresponding to a threat actor (See Huang page 4 obtaining the information from the external threat information source, identifying the potential attacker and the attack type, obtaining the threat information evaluation result; according to the behaviour mode of the user, comprising the login information of the user, the network communication flow of the system, the access behaviour of the user to the system file and the use condition of the system call, detecting the abnormal user behaviour and the potential attack behaviour, obtaining the user behaviour evaluation result). Claim 25 is rejected based on the same rationale as the rejection of claim 24. Regarding claim 26, the references as combined above disclose the method of claim 25, wherein deploying the at least one generated dynamic honeypot into the computing network comprises deploying the at least one generated dynamic honeypot into a sandbox environment within the computing network, wherein the deployment entices the threat actor into the sandbox environment, and wherein the sandbox environment isolates the threat actor and allows for further analysis of patterns or tactics of the threat actor for additional insights and system security. (See Huang, abstract and page 3, paragraph 2 honey pot isolated from the real system and monitored the attacker). (Huang discloses monitoring isolated honeypot as a sandbox.). Claim 26 is rejected based on the same rationale as the rejection of claim 24. Regarding claim 30, the references as combined above disclose the dynamic honeypot generation and deployment system of claim 21, wherein generating the at least one dynamic honeypot comprises replicating at least a portion of the computing network to simulate a production environment of the enterprise computing system, and wherein the replication is determined based on output from the machine learning model analyzing the threat actor activity. (See Huang, page 13, last paragraph through page 14, first paragraph, disclosing two or more virtual machines can be deployed in the honey pot and different network services and applications can be simulated to increase the interest of attackers). Claim 30 is rejected based on the same rationale as the rejection of claim 21. Regarding claim 31, the references as combined above disclose the dynamic honeypot generation and deployment system of claim 30, wherein replicating at least a portion of the computing network comprises fully replicating an entire organization computing network with dynamic honeypots to simulate a full production environment. (See Huang, page 13, last paragraph through page 14, first paragraph, disclosing two or more virtual machines can be deployed in the honey pot and different network services and applications can be simulated to increase the interest of attackers ). On page 14 Huang discloses partially updating or completely replacing an environment. See also Jiang, paragraph 38, disclosing “he cyber security sandbox environment disclosed herein clones the entire network of virtual machines, including a copy of the cyber security appliance, the machine learning algorithms, the user devices and the IP packet traffic, and then isolates the clone network, and unleashes the cyber threats in the clone network”). Claim 31 is rejected based on the same rationale as the rejection of claim 21. Regarding claim 33, the references as combined above disclose the method of claim 24, wherein the insights determined from the analysis of patterns or tactics of the threat actor are used to train internal cyber security personnel and to update the machine learning model for generating more realistic dynamic honeypots. (See for instance Huang, page 8 with creating new network environment with new honeypot based on analysis of patterns and tactics of threat actor activity for generating more realistic dynamic honeypots). Claim 33 is rejected based on the same rationale as the rejection of claim 24. Regarding claim 34, the references as combined above disclose the method of claim 24, wherein the sandbox environment is integrated into a dynamic honeypot generation and deployment platform, and wherein the integration allows for real-time isolation and analysis of the threat actor without impacting the computing network. (See Fellows, paragraphs 37-38 disclosing isolate the clone network into sandbox environment and unleashes the cyber threats in the clone network... without disrupting the reference network). Claim 34 is rejected based on the same rationale as the rejection of claim 24. Regarding claim 35, the references as combined above disclose the method of claim 24, further comprising: monitoring network patterns using a network pattern analysis server communicatively coupled to the computing network; and incorporating the monitored network patterns into the analysis by the machine learning model to generate the at least one dynamic honeypot. (See Fellows, para 72). Claim 35 is rejected based on the same rationale as the rejection of claim 24. Regarding claim 36, the references as combined above disclose the method of claim 24, further comprising: generating the at least one additional dynamic honeypot comprises mimicking a specific vulnerability different from a vulnerability mimicked by the at least one dynamic honeypot, based on the analyzed additional threat actor activity (See Huang, page 8, disclosing setting different IP addresses as different environment based on threat actor activity). Claim 36 is rejected based on the same rationale as the rejection of claim 24. Claim(s) 32 is/are rejected under 35 U.S.C. 103 as being unpatentable over US Patent 11,818,172 to Miretsky et al hereinafter Miretsky in view of Foreign Patent CN 117040871 to Huang et al hereafter Huang in view of Foreign Patent Publication CN 117544349 to Jiang et al hereinafter Jiang, in view of US Patent Publication US 20230011004 to Fellows hereinafter Fellows, in view of Applicant’s Admitted Prior Art (AAPA), as applied to claim 21 and further in view of Nasr-Azadani et al hereafter Nasr-Azadani (US Patent Publication US 2021/0224696). Regarding claim 32, the references as combined above disclose the dynamic honeypot generation and deployment system of claim 21. The references as combined above do not explicitly disclose further comprising a library of environments stored in the memory wherein generating the at least one dynamic honeypot comprises selecting and deploying an environment from the library based on output from the machine learning model analyzing the threat actor activity. Nasr-Azadani discloses a library of environments stored in the memory wherein generating the at least one dynamic honeypot comprises selecting and deploying an environment from the library based on output from the machine learning model analyzing the threat actor activity (See paragraph 33, disclosing, training and validating library of machine learning models based on output from the machine learning model). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify the references as combined above to deploy library based on output from the machine learning model. One of ordinary skill in the art would have been motivated to do so because machine learning model may be first trained then tested against test data as suggested by Nasr-Azadani (paragraph 33). Claim(s) 27-29 and 37-39 is/are rejected under 35 U.S.C. 103 as being unpatentable over US Patent 11,818,172 to Miretsky et al hereinafter Miretsky in view of Foreign Patent CN 117040871 to Huang et al hereafter Huang and in view of Applicant’s Admitted Prior Art (AAPA). Regarding claim 27, Miretsky discloses one or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface communicatively coupled to the at least one processor, and memory, cause the computing platform to: train a machine learning model to identify threat actor activity using historical threat actor event occurrences and information related to the threat actor event occurrences, (See Miretsky fig.4 disclosing a system for implementing the invention, and further discloses an attack response service using ML and AI to collect, monitor activities and provides the system the ability to automatically learn and identify and classify threat actor activities, see col. 4, lines 33-57); Miretsky discloses monitor a computing network for threat actor activity (see column 2, lines 16-30 monitoring file transfer activity); detect the threat actor activity on the computing network (see col. 2, lines 31-36); analyze the detected threat actor activity with the machine learning model (see col. 3, lines 24- 35); generate at least one dynamic honeypot (see col. 2, lines 41-45 a honeypot is created); deploy the at least one generated dynamic honeypot into the computing network (see col. 2, lines 41-45 and 58-60 honeypot may be simulated); monitor the deployed at least one dynamic honeypot for additional threat actor activity (see col. 3, lines 12-23 any activity is monitored within the honeypot). and transmit a notification of the detection of the threat actor activity and the deployment of the at least one generated dynamic honeypot (see col. 3, lines 20-23 issuing alert as a result of activity being determined to correlate to the honeypot reads on the claimed limitation as the honeypot is being simulated, see also col. 5, lines 5-10), wherein the instructions provides deterrence, adaptive defense, and intelligence gathering on threat actors and their associated threat activities (see page 13 For example, by analyzing the threat information, it is found that a group of attackers are targeted at the network server of the enterprise, and the motive is to obtain sensitive commercial secret information. .. Two or more virtual machines can be deployed in the honey pot, and different network services and applications can be simulated to increase the interest of attackers… Their technical capabilities are relatively high, they are able to make use of vulnerabilities for remote command execution, and they have a large number of attacking tools and resources. the security information and event management tool is used for counting and analyzing the attack mode of the attacker, the target IP address and the used attack tool. The attack action of the attacker to the honey pot is observed, and the configuration of the honey pot can be updated in time to increase the identification and defence ability of the new attack mode after the new attack method is found). Miretsky does not explicitly disclose: wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage; analyze the detected threat actor activity with the machine learning model to determine that the threat actor is using a port detection tool; generate at least one dynamic honeypot based on the analyzed threat actor activity. detect the additional threat actor activity associated with the deployed at least one dynamic honeypot;- analyze the detected additional threat activity associated with the at least one dynamic honeypot with the machine learning model;- generate at least one additional dynamic honeypot based on the analyzed threat actor activity associated with the at least one dynamic honeypot, wherein generating the at least one additional dynamic honeypot is based on insights determined from the analysis of patterns or tactics of the threat actor in the deployed at least one dynamic honeypot, and wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment;- deploy the at least one generated additional dynamic honeypot into the computing network;- monitor the deployed at least one additional dynamic honeypot for further threat actor activity. Although Miretsky teaches that the invention uses “ML, an application of AI to automatically learn and improve from experience without being explicitly programmed” (column 4, lines 47-58), Miretski is silent about repeating the process to generate additional dynamic honeyspot. However, Huang in an analogous art discloses a dynamic honeypot (see abstract) and further discloses “the invention simulates the vulnerability in the target system and attracts the attacker to attack by deploying the honey pot technology” (see page 3, third paragraph). “As a preferred solution, the protected honey pot is deployed with a monitoring tool, detecting network intrusion, malicious software and user abnormal behaviour, generating alarm and evaluation information, obtaining a honey pot with complete log and monitoring function, comprising: ; …deploying the network intrusion detection system, monitoring the network intrusion action, including port scanning” (see page 3, sixth paragraph and page 4, first paragraph) that meets the recitation of analyze the detected threat actor activity to determine that the threat actor is using a port detection tool with the machine learning model. Huang further discloses “As a preferred solution, based on the attacker's behavior and system risk, and the deployment environment of the honey can, determining whether to reuse the honey can, comprising: evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker; if at least one item is judged not to reuse the honey pot based on the attacker action and system risk and the deployment environment of the honey pot, finally not to reuse the honey pot;” (see page 5, paragraphs 3-4) that meets the recitation of generate at least one dynamic honeypot having open ports based on the analyzed threat actor activity. Huang further discloses detect the additional threat actor activity associated with the deployed at least one dynamic honeypot, wherein the at least one additional dynamic honeypot is generated to mimic a different vulnerability based on the analyzed additional threat activity; (see page 2, from the middle content of the invention to page 3, paragraph 1 disclosing determining the attacker action and the system risk; based on the attacker action and system risk, and the deployment environment of the honey pot, determining whether to reuse the honey pot; aiming at the honey pot which cannot be multiplexed directly with risk, judging whether it is the configuration of partially updated honey pot or completely replaced honey pot… according to the monitoring data and the judging result, using the safety information and the event management system, determining the specific action of the attacker in the honey pot, comprising detecting, permeating, collecting information, operating malicious code, side channel attack and cleaning trace; using the behaviour rule matching algorithm to match the specific behaviour of the attacker in the honey pot, determining whether the attacker triggers the pre-defined rule, including the attack behaviour, malicious code behaviour and vulnerability utilization attempt, evaluating the safety of the honey pot and the degree of the potential risk in the system, which meets the claimed limitation); analyze the detected additional threat activity associated with the at least one dynamic honeypot with the machine learning model (see page 2, from the middle content of the invention to page 3, paragraph 1, monitoring attacker activities, obtaining vulnerability information); generate at least one additional dynamic honeypot based on the analyzed threat actor activity associated with the at least one honeypot wherein generating the at least one additional dynamic honeypot is based on insights determined from the analysis of the threat actor's patterns or tactics in the deployed at least one dynamic honeypot (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity). wherein the at least one dynamic honeypot and the at least one additional dynamic honeypot adapt to breaches based on behavior of the threat actor and identified tools used to gain access, thereby causing redirection of the threat actor into a specific computing environment (see page 13, judging whether there is known loophole and there is no timely repairing condition. according to the network topology, system architecture and device configuration attribute of the honey pot, obtaining the deployment environment of the honey pot, and evaluating the network topology, if at least one of the following conditions is not judged, the honey pot is not used repeatedly, comprising the following steps: evaluating the connection mode and position of the honey pot and the network device, determining whether the network flow is effectively isolated and monitored; evaluating the system design and component configuration of the honey pot, comprising hardware device, operating system and application program, determining whether the system design and component configuration meet the expected safety requirement; evaluating the network configuration, the access control list and the port opening condition of the honey pot, determining whether the network configuration, the access control list and the port opening condition prevent the unauthorized access; evaluating the stability and usability of the honey pot, comprising the operation time, backup and recovery mechanism of the system, determining whether the honey pot continuously and effectively attracts and monitors the attacker). deploy the at least one generated additional dynamic honeypot into the computing network (see for instance page 8 with creating new network environment with new honeypot based on threat actor activity); monitor the deployed at least one additional dynamic honeypot for further threat actor activity (see also steps S107 and S108 disclosing increasing the number of honey-pot deployments or completely replacing honeypots and continuing the monitoring and updating of the honeypots). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify Miretsky to analyze with the machine learning model the detected threat actor activity to determine that the threat actor is using a port detection tool and to generate at least one dynamic honeypot based on the analyzed threat actor activity and to generate additional dynamic honeypots based on detection and analysis of additional threat activity as suggested by Huang. One of ordinary skill in the art would have been motivated to do so because it would allow the system to optimize the vulnerability scanning and honey pot technoloby by constantly simulating, detecting the attacker behavior, and based on the attacker action and system risk updating the honeypot (See Huang, abstract). Miretski does not explicitly disclose wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. However, AAPA discloses wherein the computing network is an enterprise computing system selected from the group consisting of educational institution computing systems, corporate computing systems, financial institution computing systems, and government computing systems, and wherein the threat actor activity comprises data entry attacks selected from the group consisting of malware, computer viruses, worms, Trojan horses, ransomware, spyware, adware, scareware, phishing, and fraud, wherein the data entry attacks are initiated via executable code accessed via a link or embedded in an attachment selected from the group consisting of documents, slide decks, and spreadsheets, and wherein the executable code is disguised as benign code or hidden to run in the background upon launching an application or accessing a webpage. (See original specification, paragraphs 2-3). Regarding claim 28, the references as combined above disclose the one or more non-transitory computer-readable media of claim 27, wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences include what was accessed, where it was accessed from, communication information, and how often information was accessed, (See Huang page 3, Huang discloses access rules that controls access by unauthorized users including a login auditing tool to monitor time of access, IP address for where it was access from), and wherein the historical threat actor event occurrences and the information related to the historical threat actor event occurrences are labelled based on whether or not corresponding threat occurrence information was ultimately identified as corresponding to a threat actor (See Huang page 4 obtaining the information from the external threat information source, identifying the potential attacker and the attack type, obtaining the threat information evaluation result; according to the behaviour mode of the user, comprising the login information of the user, the network communication flow of the system, the access behaviour of the user to the system file and the use condition of the system call, detecting the abnormal user behaviour and the potential attack behaviour, obtaining the user behaviour evaluation result). Claim 28 is rejected based on the same rationale as the rejection of claim 27. Regarding claim 29, the references as combined above disclose one or more non-transitory computer-readable media of claim 28, wherein deploying the at least one generated dynamic honeypot into the computing network comprises deploying the at least one generated dynamic honeypot into a sandbox environment within the computing network, wherein the deployment entices the threat actor into the sandbox environment, and wherein the sandbox environment isolates the threat actor and allows for further analysis of patterns or tactics of the threat actor for additional insights and system security. (See Huang, abstract and page 3, paragraph 2 honey pot isolated from the real system and monitored the attacker). (Huang discloses monitoring isolated honeypot as a sandbox). Claim 29 is rejected based on the same rationale as the rejection of claim 27. Regarding claim 37, the references as combined above disclose the one or more non-transitory computer-readable media of claim 27, wherein the specific computing environment is a sandbox system separate from a dynamic honeypot generation and deployment platform, and wherein the sandbox system is configured to replicate and simulate at least a partial computer system of the enterprise computing system to entice and isolate the threat actor. (See Huang, page 13, last paragraph through page 14, first paragraph, disclosing two or more virtual machines can be deployed in the honey pot and different network services and applications can be simulated to increase the interest of attackers. On page 14, Huang discloses partially updating or completely replacing an environment). Claim 37 is rejected based on the same rationale as the rejection of claim 27. Regarding claim 38, the references as combined above disclose the one or more non-transitory computer-readable media of claim 27, wherein the instructions further cause the computing platform to: display, on a user device operated by an employee of an enterprise organization, a graphical user interface providing information related to the detected threat actor activity and the deployed at least one dynamic honeypot. Huang discloses visually displaying information related to the detected threat actor activity in the system, see page 5, paragraph 2 “generating an outlier distribution map according to the position information of the outlier, and visually displaying the risk condition in the system. Information is provided for each outlier, including the eigenvector of the outlier, the class to which the outlier belongs. according to the historical monitoring data, evaluating the change trend of the outlier in the system, predicting the future risk condition and generating the risk evaluation report”. Claim 38 is rejected based on the same rationale as the rejection of claim 27. Regarding claim 39, the references as combined above disclose the one or more non-transitory computer-readable media of claim 27, wherein the at least one dynamic honeypot is generated with specific purpose based on real-time threat activity analysis, and wherein the generation includes creating false sets of data that appear authentic to the threat actor. (See Huang abstract, “according to the honey pot with complete log and monitoring function, simulating and adding false sensitive data in the honey pot, periodically changing the bait and configuration of the honey pot, obtaining periodically updated honey pot; evaluating the monitored honey pot activity and attacker action by monitoring the periodically updated honey pot”). Claim 39 is rejected based on the same rationale as the rejection of claim 27. Claim(s) 40 is/are rejected under 35 U.S.C. 103 as being unpatentable over US Patent 11,818,172 to Miretsky et al hereinafter Miretsky in view of Foreign Patent CN 117040871 to Huang et al hereafter Huang and in view of Applicant’s Admitted Prior Art (AAPA) as applied to claim 27 above and further in view of Foreign Patent Publication CN 117544349 to Jiang et al hereinafter Jiang. Regarding claim 40 the references as combined above disclose the one or more non-transitory computer-readable media of claim 27 and does not disclose wherein the instructions further cause the computing platform to: terminate the sandbox environment based on a determination that the threat actor has been sufficiently analyzed, independent of inactivity, to optimize resource efficiency while gathering intelligence on threat activities. However, Jiang discloses wherein the instructions further cause the computing platform to: terminate the sandbox environment based on a determination that the threat actor has been sufficiently analyzed, independent of inactivity, to optimize resource efficiency while gathering intelligence on threat activities. (See abstract, where Jiang discloses releasing the honeypot analyzing the attack flow rate of the honeypot and if the attack flow is not detected over a certain period of time which increases the difficulty for the attacker to destroy the attack evidence, which reads on the claim limitation). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the invention to modify the references as combined above to terminate the sandbox environment based on a determination that the threat actor has been sufficiently analyzed, independent of inactivity, to optimize resource efficiency while gathering intelligence on threat activities as suggested by Jiang. One of ordinary skill in the art would have been motivated to do so because the feasibility of tracing source would improve (See Jiang’s abstract). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US Patent 12216648 to Chintala et al teaches using the cloud data platform's developer framework and programming environment runtimes and libraries, a user can securely deploy and process non-SQL code to build pipelines, machine-learning models, and applications in the cloud data platform. A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Carl G Colin whose telephone number is (571)272-3862. The examiner can normally be reached Monday-Thursday 8:00-5:00 PM, Friday 8-12 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amy Cohen Johnson can be reached at 571-272-2238. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CARL G COLIN/Supervisory Patent Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Dec 07, 2023
Application Filed
Jun 06, 2025
Non-Final Rejection mailed — §103
Jul 07, 2025
Response Filed
Aug 22, 2025
Final Rejection mailed — §103
Oct 21, 2025
Response after Non-Final Action
Jan 22, 2026
Request for Continued Examination
Jan 29, 2026
Response after Non-Final Action
Aug 19, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12634114
RECURRENT NEURAL NETWORK-BASED USER IDENTITY MISAPPROPRIATION PREVENTION FROM PUBLIC DOMAINS AND CONNECTIONS
2y 1m to grant Granted May 19, 2026
Patent 12608469
SYSTEMS AND METHODS FOR STORAGE SYSTEM ATTACK DETECTION AND RESPONSE
3y 1m to grant Granted Apr 21, 2026
Patent 12592963
DETECTION DEVICE, DETECTION METHOD, AND DETECTION PROGRAM
2y 11m to grant Granted Mar 31, 2026
Patent 12554808
PUBLIC KEY EMBEDDED IN CONTENT FOR VERIFICATION OF AUTHORSHIP
2y 3m to grant Granted Feb 17, 2026
Patent 12547704
AUTOMATED DEPLOYMENT OF RELOCATABLE CODE BLOCKS AS AN ATTACK COUNTERMEASURE IN SOFTWARE
2y 9m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
48%
Grant Probability
99%
With Interview (+54.1%)
4y 4m (~1y 6m remaining)
Median Time to Grant
High
PTA Risk
Based on 136 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month