Notice of Pre-AIA or AIA Status
present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is in response to the original filing of 12/24/2025. Claims 1 and 10-11 have been amended. Claims 12 and 13 have been added. Claims 1-13 are pending and have been considered below.
Priority
18582961 filed 02/21/2024 claims foreign priority to 2023-115650, filed 07/14/2023.
Drawings
The drawings filed on 02/21/2024 are accepted.
Specification
The specification filed on 102/21/2024 is accepted.
Response to Arguments
Applicant’s arguments with respect to newly amended independent claims 1 and 10-11 have been considered but are moot in view of the new ground of rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3 and 9-11 are rejected under 35 U.S.C. 103 as being unpatentable over Sato et al U.S. 2020/0097663 A1 in view of Hiroshi et al W.O. 2008/004498 A1.
Claims 1, 10 and 11: Sato et al teaches an information processing device comprising:
one or more processors configured (par.42-44, 66) to:
an information processing method performed by an information processing device (par. 42-44, 66), the method comprising:
a computer program product comprising a non-transitory computer-readable medium including programmed instructions, the instructions causing a computer to execute(par.42-44, 66):
detect, from a plurality of target components included in an information processing system to be evaluated, one or more of first components affected by a vulnerability included in the information processing system (par.8 a vulnerability evaluation processing unit that calculates the threat levels of the security holes of the respective components on a basis of the asset values par.9, 55-56, a vulnerability evaluation apparatus that evaluates the threat levels of the security holes of the respective components on the basis of the number of products and the asset values of the respective components);
specify, by using assessment information that associates one or more assets having data that is stored in one or more of the target components, one or more of the target components that store the one or more assets(pa.11, 33, a configuration information holding unit 41 that holds a configuration information table 5 described later with reference to FIG. 5; a component-vulnerability correspondence holding unit 42 that holds a component-vulnerability correspondence table 6 described later with reference to FIG. 6; an asset information holding unit 43 that holds an asset information table 7 described later with reference to FIG. 7),
Sato et al fails to teach, however Hiroshi et al in the same field of endeavor teaches
specify, a degree of impact when the one or more of the assets are attacked, the one or more of the assets corresponding to the detected one or more of the first components (par.33, 58, the presence / absence of the vulnerability of the target system and the assets of the target system are analyzed. A threat model that defines the value and frequency of occurrence of security threats in advance, a threat that predefines the relationship between vulnerabilities and threats related to the emergence of threats based on the presence or absence of vulnerabilities, and a threat model Based on the threat asset model that defines the relationship between the asset and the threat related to the impact on the asset due to the materialization of risk. Par.24, A risk analysis means for calculating a risk value based on the frequency of occurrence of each threat in the target system, the degree of vulnerability to each threat, and the degree of impact on the assets of the target system when each threat becomes apparent.); and
obtain an evaluation value of damage when the vulnerability is attacked, based on the degree of impact corresponding to the specified one or more of the assets (par. 74-81, For each confidential level, the asset value of the confidential level, that is, the average amount of damage when information is leaked, is set. By doing so, it is possible to calculate the final risk value with a specific index called damage amount. ).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Sato et al with the additional features of Hiroshi et al in order to provide a security management device, method and program for managing security risk in a target device, system and program, and in particular, a security management device, system and program used for security risk management during operation of the target system, as suggested by Hiroshi et al par.1.
Claim 2: the combination teaches
wherein the degree of impact includes a degree of impact of confidentiality, a degree of impact of integrity, and a degree of impact of availability, and the one or more processors are configured to obtain, as the evaluation value, a statistical value of the degree of impact of confidentiality, the degree of impact of integrity, and the degree of impact of availability (Hiroshi et al, par. 51-56, 74-81).
The same motivation to modify Sato et al, in view of Horishi et al applied to claim 1 above applies here.
Claim 3: the combination teaches
wherein the statistical value includes a maximum value of the degree of impact of confidentiality, the degree of impact of integrity, and the degree of impact of availability (Hiroshi et al, par. 51-56, 74-81).
The same motivation to modify Sato et al, in view of Horishi et al applied to claim 1 above applies here.
Claim 9: the combination teaches
wherein the one or more processors are configured to output the evaluation value (Hiroshi et al, par. 33, 58, 74-81).
The same motivation to modify Sato et al, in view of Horishi et al applied to claim 1 above applies here.
Claims 4-8 are rejected under 35 U.S.C. 103 as being unpatentable over Sato et al U.S. 2020/0097663 A1 in view of Hiroshi et al W.O. 2008/004498 A1 in further view of Hercock et al U.S. 2022/0027478 A1.
Claim 4: the combination teaches
wherein the one or more processors are configured to detect one or more of components having the vulnerability from the plurality of target components (Hiroshi et al, par. 51-56, 74-81), and
The same motivation to modify Sato et al, in view of Horishi et al applied to claim 1 above applies here.
the combination fails to teach, however Hercock et al in the same field of endeavor teaches
specify one or more of the first components affected by the vulnerability in the detected one or more of components from the plurality of target components (par. 7).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the combined disclosure of Sato et al with the additional features of Hercock et al in order to provide the ability for detecting an increased vulnerability of a software system including a plurality of software components, as suggested by Hercock et al abstract.
Claim 5: the combination teaches
wherein the one or more processors are configured to perform at least one of addition of a component to the one or more of the first components and deletion of a component from the one or more of the first components by using modification information for defining a component to be added or deleted for each type of vulnerability (Hercock et al, par. 7, 14, 34, 42-48).
The same motivation to modify Sato et al, in view of Hercock et al applied to claim 1 above applies here.
Claim 6: the combination teaches
wherein the one or more processors are configured to specify the one or more of the first components affected by the vulnerability in the detected one or more of components, depending on a type of the detected one or more of components (Hercock et al, par. 7, 14, 34, 42-48).
The same motivation to modify Sato et al, in view of Hercock et al applied to claim 1 above applies here.
Claim 7: the combination fails to teach, however Hercock et al in the same field of endeavor teaches
wherein the one or more processors are configured to detect, by using vulnerability information indicating the vulnerability in one or more of components, the one or more of the first components from the plurality of target components (par. 7, 14, 34, 42-48).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the combined disclosure of Sato et al with the additional features of Hercock et al in order to provide the ability for detecting an increased vulnerability of a software system including a plurality of software components, as suggested by Hercock et al abstract.
Claim 8: the combination fails to teach, however Hercock et al in the same field of endeavor teaches
wherein the one or more processors are configured to detect the vulnerability in the information processing system, and detect the one or more of the first components having the detected vulnerability (par. 14, 34, 42-48).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the combined disclosure of Sato et al with the additional features of Hercock et al in order to provide the ability for detecting an increased vulnerability of a software system including a plurality of software components, as suggested by Hercock et al abstract.
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Sato et al U.S. 2020/0097663 A1 in view of Hiroshi et al W.O. 2008/004498 A1 in further view of Greenshpoon et al U.S. 2010/0125912 A1.
Claim 12: the combination fails to teach, however Greenshpon et al in the same field of endeavor
the one or more of the assets include at least one of measured data, a password, and user information (par.6, Figs.7-9).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the combined disclosure of Sato et al with the additional features of Greenshpon et al in order to provide a security assessment of an IT asset that is generated to indicate the type of security problem encountered, the severity of the problem, and the fidelity of the assessment, as suggested by Greenshpon et al abstract.
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Sato et al U.S. 2020/0097663 A1 in view of Hiroshi et al W.O. 2008/004498 A1 in further view of Gusler et al U.S. 6,880,108 B1.
Claim 13: the combination fails to teach, however Gusler et al in the same field of endeavor
wherein the assessment information is obtained as a result of a risk assessment for the information processing system that is performed in advance (col.9, line 58 to col.10, line 6).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the combined disclosure of Sato et al with the additional features of Gusler et al in order to provide an accurate risk assessment of a computer system as suggested by Gusler et al col.1, lines .
The following prior art are cited to further show the state of the art at the time of applicant’s invention.
Zhou et al 2024/0372884 A1 teaches Hardware Vulnerability Assessment Device For Evaluating Risk From Collection Of Threats From Data Communication Network To Private Network, Has Aggregate Threat Engine For Determining Score For Collection Of Vulnerabilities, And Security Action Module For Taking Security Action.
LaBumbard US 2012/0304300 A1 teaches an enterprise vulnerability management application (EVMA), enterprise vulnerability management process (EVMP) and system.
Basavapatna U.S. 2013/0191919 A1 teaches standardized vulnerability score is identified for a particular vulnerability in a plurality of known vulnerabilities, the standardized vulnerability score indicating a relative level of risk associated with the particular vulnerability relative other vulnerabilities.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FATOUMATA TRAORE whose telephone number is (571)270-1685. The examiner can normally be reached 6:30-3:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 5712724219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Wednesday, April 15, 2026
/FATOUMATA TRAORE/Primary Examiner, Art Unit 2436