DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
The present office action is responsive to communication received 01/28/2026. Claims 1, 4, 5, 8, 8, 11, 13-15, and 18 have been amended. Claims 1-20 are currently pending.
Applicant’s amendments filed 01/26/2026 with regards to 35 USC 112, as seen in pages 13-18, have been fully considered but not fully persuasive.
Applicant’s amendments considered but not fully persuasive with regards to defining and customizing a balance between security measure and productivity requirement has not been considered persuasive. On pages 16-17 of the remarks, applicant stated that the subjective term “balance” with objective associations between security parameters and productivity has been replaced, but in claims 12 and 17 recites, “…the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measure and productivity requirements…”. Therefore, indefiniteness concern has not been resolved.
Additionally, applicant’s arguments and amendments with respect to claims 1-5, 7, 17, 19, and 20 stand rejected under 35 U.S.C. § 103 over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Black et al. (US PGPub No. 20250124137-A1) and Thompson et al. (US PGPub No. 20240257263-A1), as seen in pages 18-24, are fully considered and fully persuasive. Therefore, the rejection have been withdrawn. However, upon further consideration, a new grounds of rejection is made in view of Crabtree et al. (US PGPub No. 20220263860-A1).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claims 1, 8, and 15:
“…quantify anticipated changes in security metrics and productivity metrics…” is indefinite because the claims do not specify what a security and productivity metric represent, how it is derived, or how it is derived, or from what inputs it is calculated. Functional limitations must be supported by structure in the specification, but the application fails to disclose any algorithm, flowcharts, pseudo-code, etc. that offer structural support for this limitation.
Claims 2-7, 9-14 and 16-20 do no overcome the rejection of their respective base claims that have rejected above, and therefore rejected under the same grounds provided to claim 1.
Regarding claims 12 and 17:
“…the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measure and productivity requirements…” is indefinite because the claim does not specify what constitutes as “a balance” nor how a balance is obtained between security measures and productivity requirements. It is unclear whether “balance between security measures and productivity requirements” refers to certain percentages, user defined, or organizationally defined.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-4, 7, 15, 16, 17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Crabtree et al. (US PGPub No. 20220263860-A1) and Black et al. (US PGPub No. 20250124137-A1) .
With respect to claim 1, Yellapragada teaches a computerized system comprising: one or more computer processors; and computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising: (¶0030: As seen in Figure 2, a flow diagram illustrating operations 200 of a method for predictive analysis of potential attack patterns based on contextual security information according to some embodiments. Some or all of the operations 200 (or other processes described herein, or variations, and/or combinations thereof) are performed under the control of one or more computer systems configured with executable instructions and are implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) executing collectively on one or more processors, by hardware or combinations thereof.);
identifying a security exposure associated with a computing environment; (Abstract: Systems and method for predictive analysis of potential attack patterns based on contextual security information are described. In one embodiment, a method includes generating a profile for an enterprise that indicates one or more software application stacks and a network architecture for the one or more software application stacks; determining one or more vulnerabilities of the one or more software application stacks and one or more vulnerabilities of the network architecture; );
accessing a security configuration anticipated impact analysis model, wherein the security configuration anticipated impact analysis model is a machine learning model trained using historical telemetry data (¶0075: To create an anomaly detection ML model, certain embodiments use several of these fields and use certain calculated fields e.g., which overall define the features of the data set. n certain embodiments, the process of training the anomaly detection ML model involves providing training data to an ML algorithm, e.g., with the training data including one or any combination of: source IP (e.g., for traffic entering from internet 410 in Figure 4), number of distinct IPs seen in a time period (e.g., per day, per week, per month, etc.) (historical data) );
using the security configuration anticipated impact analysis model to generate a security configuration anticipated impact analysis for the security exposure and the computing environment, (¶0018: The below sections include (i) predictive analysis of potential attack paths based on contextual vulnerability information, (ii) methods for prioritizing security findings using machine learning models (iii) scoring for application based historical, predictive, and inherent factors, (iv) methods for proposing counter measures for security vulnerabilities using contextual and attack prediction patterns, and (v) methods for vulnerability assessment for cloud assets using imaging methods. Further in ¶0027: In certain embodiments, during the “infer” 114 phase, all the collected information (e.g., collected by vulnerability detectors 500 in Figure 5) is analyzed. In the depicted embodiment, the attack inference engine 112 performs the inference(s). In certain embodiments, the collected information includes vulnerabilities (e.g., and weaknesses and/or misconfigurations) information. In certain embodiments, a network architecture map previously discovered is employed to infer potential attack paths. In certain embodiments, one or more machine learning models are employed to predict the next attack sequence in an attack pattern);
Yellapragada does not disclose:
wherein the security configuration anticipated impact analysis is a targeted assessment generated using machine learning to quantify anticipated changes in security metrics and productivity metrics associated with implementation of a security resolution of the security exposure within the computing environment; accessing a security-productivity configuration associated with the computing environment, the security-productivity configuration comprising security parameters and productivity parameters that are associated with generating security configurations for security exposures,
wherein the security parameters are associated with security controls and the productivity parameters are associated with productivity requirements, and wherein the security parameters and the productivity parameters are user-defined for generating the security configurations in accordance with the security controls and productivity requirements based on the security-productivity configuration and the security configuration anticipated impact analysis,
However, Crabtree teaches wherein the security configuration anticipated impact analysis is a targeted assessment (¶0072-0073: Figure 1 is a diagram of an exemplary architecture of an advanced cyber decision platform (ACDP). Client access to system 105 for specific data entry, system control and for interaction with system output such as automated predictive decision making and planning and alternate pathway simulations. Results of the transformative analysis process may then be combined with further client directives, additional business rules and practices relevant to the analysis and situational in formation external to the already available data in the automated planning service module 130 which is also runs powerful information theory 130a based predicative statistics functions and machine learning algorithms to allow future trends and outcomes to be rapidly forecasted based upon current system rived results and choosing each a plurality possible business decision. ) generated using machine learning to quantify anticipated changes in security metrics and productivity metrics associated with implementation of a security resolution of the security exposure within the computing environment; (¶0079: Figure 3 , is a process diagram showing a general flow 300 of business operating system functions in use to mitigate cyberattacks ( a part of the cyber decision platform). Input network data may pass into 315 the business operating system 310 for analysis as part of tis cybersecurity function. These multiple types of data from a plurality of sources may be transformed for analysis 311 (quantify) 311, 312 using at least one of the specialized cybersecurity, risk assessment or common functions of the business operating system in the role of cybersecurity system, but not limited to incident identification and resolution performance analytics (security metrics) , value at risk (VAR) modeling and simulation 341, anticipatory vs. reactive cost estimations of different types of data breaches to establish priorities 342, work factor analysis 343 (productivity metrics) and cyber event discovery rate 344 as a part of the system’s risk analytics capabilities, and the ability to generate cyber-physical system graphing 354 as part of the business operating system’s common capabilities. );
accessing a security-productivity configuration associated with the computing environment, the security-productivity configuration comprising security parameters and productivity parameters that are associated with generating security configurations for security exposures, wherein the security parameters are associated with security controls and the productivity parameters are associated with productivity requirements, and (¶0108: Figure 14 is a flow diagram of an exemplary method 1400 for cybersecurity risk management ( a part of the cyber decision platform) . According to the aspect multiple methods described previously combined to provide live assessment of attacks as they occur, buy first receiving 1401 time-series data for an infrastructure (as described previously, in Figure 10) to provide live monitoring of network events. This data is then enhanced 1402 with CPG (as described above in Figure 11) to correlate events with actual infrastructure elements, such as servers or accounts. When an event occurs 1403, the event is logged in the time-series data 1404, and compared against the CPG 1405 to determine the impact. impact. This is enhanced with the inclusion of impact assessment information 1406 for any affected resources, and the attack is then checked against a baseline score 1407 to determine the full extent of the impact of the attack and any necessary modifications to the infrastructure or policies (security parameters and productivity parameters). );
wherein the security parameters and the productivity parameters are user-defined for generating the security configurations in accordance with the security controls and productivity requirements based on the security-productivity configuration and the security configuration anticipated impact analysis, (¶0074: The system 100, based on this data and analysis, was able to detect and recommend mitigation of a cyberattack and represented an existential threat to all business operations, presenting, a the time of the attack, information most needed for an actionable plan to human analysts (user-defined) at multiple levels in the mitigation and remediation effect through use of the observation and the state estimation service 140 which also been specifically preprogrammed to handle cybersecurity events);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the security configuration anticipated impact analysis to the method of Yellapragada in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
Yellapragada in view of Crabtree does not disclose:
generating a first security configuration associated with a first entity; and configuring the first entity associated with the computing environment with the first security configuration associated with remediating the security exposure.
However, Black teaches generating a first security configuration associated with a first entity; (¶0036-0040: As seen in Figure 1, the risk and compliance data 139 can include various information about datasets, benchmarks, and other enterprise standards for managing risks and vulnerabilities. The one or more recommendations 153 can represent a guide to resolve the vulnerabilities present on a device. In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. In some instances, the recommendation 153 can be a recommendation to adjust security standards, compliance standards based at least in part on the electronic device usage (e.g., meets HIPAA standards if used for health records or medical information, state related data privacy standards such as California Consumer Privacy Act, etc.), and performance standards (e.g., resource usage, memory usage, battery life, etc.);
and configuring the first entity associated with the computing environment with the first security configuration associated with remediating the security exposure. (¶0040-0041: In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. The UEM application 119 can inform the administrator computing device 106 of the severity, implications, and remediation recommendations associated with one or more vulnerabilities. The UEM application 119 could automate update deployment, ensure end-to-end security, and compliance across the devices in the enterprise. Additionally, the UEM application 119 can facilitates device management policies, automated compliance checks, and vulnerability response mechanisms to ensure seamlessly integration.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Black of generating a first security configuration associated with a first entity to the method of Yellapragada in view of Crabtree in order to enable automation and less time-consuming for the remedial actions (Black ¶0001-0007).
With respect to claim 2, the combination of Yellapragada in view of Crabtree and Black teaches the system of claim 1 (see rejection of claim 1 above) wherein the security exposure is a weakness or vulnerability within the computing environment that could potentially be exploited by malicious actors or a security incident that is an adverse occurrence or violation that poses a threat to the computing environment, (Yellapragada ¶0020: Additionally, services and applications might have vulnerabilities in that environment . In certain embodiments, the services and the communication channels could have misconfigurations. In certain embodiments, weaknesses are identified during the development stage by building the control and data flows in the application and identifying security issues in such flows. In certain embodiments, this information is used to predict potential attack patterns that an attacker could employ to exploit the weakness in the control and data flows.).
the security exposure is associated with the security resolution that is a known remediation to the security exposure to the computing environment. (Yellapragada ¶0028-0029: In certain embodiments, the countermeasures 118 and/or remediations 120 are enforced through the various security controls 124 and/or tools existing in a particular environment. These could range from firewall rules, access control list (ACL) rules, WAF rules, and/or intrusion prevention system (IPS) signatures.).
With respect to claim 3, the combination of Yellapragada in view of Crabtree and Black teaches the system of claim 1 (see rejection of claim 1 above) wherein the security configuration anticipated impact analysis model supports evaluating and assessing potential effects of implementing the security resolution for the security exposure in the computing environment. (Yellapragada ¶0065-0067: In certain embodiments, the highest risk vulnerabilities and software in the business application are identified, e.g., by attack inference engine. In certain embodiments, a score (e.g., EPR score) for a potential risk of exploitation for each of the components (e.g., assets and business applications) is determined (e.g., calculated). In certain embodiments, a risk score serves as an indicator of the exploitability of a particular business application (or the whole computing environment), e.g., such that this knowledge would help a security officer and/or security platform to prioritize the mitigating or fixing of the issue(s).).
With respect to claim 4, the combination of Yellapragada in view of Crabtree and Black teaches the system of claim 1 (see rejection of claim 1 above) wherein generating the security configuration anticipated impact analysis comprises one or more of the following: evaluating expected performance of one or more entities in the computing environment; determining expected usability of the one or more entities in the computing environment; determining an organizational context of the one or more entities; and evaluating user-defined metrics. (Black ¶0033-0039: For example, the device information 129 can include information about enterprise resources to which a particular user has access, such as email, calendar data, documents, media, applications, network sites, or other resources. The device information 129 can also identify one or more user groups of which a particular user is a member (organizational context of the one or more entities) , which can in turn define the access rights of the user to one or more enterprise resources as well as identify which applications should be deployed to one or more device(s) associated with the user. The list of available updates 143 can be customized based at least in part on the device information 129. The one or more vulnerability reports 149 can include comprehensive information on the one or more identified vulnerabilities. The vulnerability report 149 could include detailed documentation of the one or more vulnerabilities. In some embodiments, the vulnerability reports 149 can be customized to a user, a device, a operating system, an application, a firmware, and/or a combination of the aforementioned.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Black of using the security productivity configuration to the method of Yellapragada in view of Crabtree in order to enable automation and less time-consuming for the remedial actions (Black ¶0001-0007).
With respect to claim 7, the combination of Yellapragada in view of Crabtree and Black teaches the system of claim 1 (see rejection of claim 1 above) the operations further comprising: monitoring productivity impact parameters associated with the first entity; (Crabtree ¶0076: Figure 2, is a flow diagram of an exemplary function of the business operating system in the detection and mitigation of predetermining factors leading to steps to mitigate cyberattacks 200. The system may continuously retrieves network traffic data 201 which may be stored and preprocessed by the multidimensional time series data store 120 and its programming wrappers 120a. Analysis of network traffic may include graphical analysis of parameters such as network item to network usage using specifically developed programming in the graph stack service 145, 145a, analysis of usage by each network item may be accomplished by specifically pre-developed algorithms associated with the directed computational graph module 155, general transformer service module 160 and decomposable service module 150, depending on the complexity of the individual usage profile 201.);
identifying a potential or actual productivity impact issue; generating a contextualized insight for the potential or actual productivity impact issue; (Crabtree ¶0076-0077: These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology. This same data would be combined with up-to-date known cyberattack methodology reports, possibly retrieved from several divergent and exogenous sources through the use of the multi-application programming interface aware connector module 135 to present preventative recommendations to the enterprise decision makers for network infrastructure changes, physical and configuration-based to cost effectively reduce the probability of a cyberattack and to significantly and most cost effectively mitigate data exposure and loss in the event of attack 203, 204. );
generating an alert associated with the potential or actual productivity impact issue; (Crabtree ¶0076-0078: Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207. This may include the exact subset of information included in alerts and updates and the format in which may be through the enterprise’s existing security information and event management system. );
and autonomously updating the first security configuration associated with the first entity. (Crabtree ¶0101: Further shown in Figure 8, showing an exemplary for cybersecurity behavior analytics, according to one aspect (showing the same scope of the invention), wherein in step 806, the suggested behaviors may then be automatically implemented 806 as needed. Passive monitoring 801 then continues, collecting information after new security solutions are implemented 806, enabling machine learning to improve operation over time as the relationship between and security changes and observed behaviors and threats are observed behaviors and threats are observed analyzed. ).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the monitoring the productivity parameters to the method of Yellapragada and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
With respect to claim 15, Yellapragada teaches a computer-implemented method, the method comprising: (¶0011: The present disclosure relates to methods, apparatus, systems, and non-transitory computer-readable storage media for predictive analysis of potential attack patterns based on contextual security information. In certain enterprises and/or public cloud environments, there are several assets, applications, servers, services (e.g., software application stack(s)) which are connected through various networks. In turn, there could arise various vulnerabilities (e.g., including weaknesses and/or misconfigurations) related to these resources.);
identifying a security exposure associated with a computing environment; (Abstract: Systems and method for predictive analysis of potential attack patterns based on contextual security information are described. In one embodiment, a method includes generating a profile for an enterprise that indicates one or more software application stacks and a network architecture for the one or more software application stacks; determining one or more vulnerabilities of the one or more software application stacks and one or more vulnerabilities of the network architecture; );
accessing a security configuration anticipated impact analysis model, wherein the security configuration anticipated impact analysis model is a machine learning model trained using historical telemetry data; (¶0075: To create an anomaly detection ML model, certain embodiments use several of these fields and use certain calculated fields e.g., which overall define the features of the data set. n certain embodiments, the process of training the anomaly detection ML model involves providing training data to an ML algorithm, e.g., with the training data including one or any combination of: source IP (e.g., for traffic entering from internet 410 in Figure 4), number of distinct IPs seen in a time period (e.g., per day, per week, per month, etc.) (historical data));
using the security configuration anticipated impact analysis model to generate a security configuration anticipated impact analysis for the security exposure and the computing environment (¶0018: The below sections include (i) predictive analysis of potential attack paths based on contextual vulnerability information, (ii) methods for prioritizing security findings using machine learning models (iii) scoring for application based historical, predictive, and inherent factors, (iv) methods for proposing counter measures for security vulnerabilities using contextual and attack prediction patterns, and (v) methods for vulnerability assessment for cloud assets using imaging methods. Further in ¶0027: In certain embodiments, during the “infer” 114 phase, all the collected information (e.g., collected by vulnerability detectors 500 in Figure 5) is analyzed. In the depicted embodiment, the attack inference engine 112 performs the inference(s). In certain embodiments, the collected information includes vulnerabilities (e.g., and weaknesses and/or misconfigurations) information. In certain embodiments, a network architecture map previously discovered is employed to infer potential attack paths. In certain embodiments, one or more machine learning models are employed to predict the next attack sequence in an attack pattern);
Yellapragada does not disclose:
wherein the security configuration anticipated impact analysis is a targeted assessment generated using machine learning to quantify anticipated changes in security metrics and productivity metrics associated with implementation of a security resolution of the security exposure within the computing environment; and based on the security configuration anticipated impact analysis, configuring an entity associated with the computing environment with a security configuration associated with remediating the security exposure.
However, Crabtree teaches wherein the security configuration anticipated impact analysis is a targeted assessment (¶0072-0073: Figure 1 is a diagram of an exemplary architecture of an advanced cyber decision platform (ACDP). Client access to system 105 for specific data entry, system control and for interaction with system output such as automated predictive decision making and planning and alternate pathway simulations. Results of the transformative analysis process may then be combined with further client directives, additional business rules and practices relevant to the analysis and situational in formation external to the already available data in the automated planning service module 130 which is also runs powerful information theory 130a based predicative statistics functions and machine learning algorithms to allow future trends and outcomes to be rapidly forecasted based upon current system rived results and choosing each a plurality possible business decision. ) generated using machine learning to quantify anticipated changes in security metrics and productivity metrics associated with implementation of a security resolution of the security exposure within the computing environment; and (¶0079: Figure 3 , is a process diagram showing a general flow 300 of business operating system functions in use to mitigate cyberattacks ( a part of the cyber decision platform). Input network data may pass into 315 the business operating system 310 for analysis as part of tis cybersecurity function. These multiple types of data from a plurality of sources may be transformed for analysis 311 (quantify) 311, 312 using at least one of the specialized cybersecurity, risk assessment or common functions of the business operating system in the role of cybersecurity system, but not limited to incident identification and resolution performance analytics (security metrics) , value at risk (VAR) modeling and simulation 341, anticipatory vs. reactive cost estimations of different types of data breaches to establish priorities 342, work factor analysis 343 (productivity metrics) and cyber event discovery rate 344 as a part of the system’s risk analytics capabilities, and the ability to generate cyber-physical system graphing 354 as part of the business operating system’s common capabilities. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the security configuration anticipated impact analysis to the method of Yellapragada in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
Yellapragada in view of Crabtree does not disclose:
based on the security configuration anticipated impact analysis, configuring an entity associated with the computing environment with a security configuration associated with remediating the security exposure.
However, Black teaches based on the security configuration anticipated impact analysis, configuring an entity associated with the computing environment (¶0036-0040: As seen in Figure 1, the risk and compliance data 139 can include various information about datasets, benchmarks, and other enterprise standards for managing risks and vulnerabilities. The one or more recommendations 153 can represent a guide to resolve the vulnerabilities present on a device. In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. In some instances, the recommendation 153 can be a recommendation to adjust security standards, compliance standards based at least in part on the electronic device usage (e.g., meets HIPAA standards if used for health records or medical information, state related data privacy standards such as California Consumer Privacy Act, etc.), and performance standards (e.g., resource usage, memory usage, battery life, etc.) with a security configuration associated with remediating the security exposure. (¶0040-0041: In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. The UEM application 119 can inform the administrator computing device 106 of the severity, implications, and remediation recommendations associated with one or more vulnerabilities. The UEM application 119 could automate update deployment, ensure end-to-end security, and compliance across the devices in the enterprise. Additionally, the UEM application 119 can facilitates device management policies, automated compliance checks, and vulnerability response mechanisms to ensure seamlessly integration.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Black of generating a first security configuration associated with a first entity to the method of Yellapragada in view of Crabtree in order to enable automation and less time-consuming for the remedial actions (Black ¶0001-0007).
With respect to claim 16, the combination of Yellapragada in view of Crabtree and Black teaches the method of claim 15 (see rejection of claim 15 above), wherein the security configuration anticipated impact analysis model supports evaluating and assessing potential effects of implementing the security resolution for the security exposure in the computing environment. (Yellapragada ¶0065-0067: In certain embodiments, the highest risk vulnerabilities and software in the business application are identified, e.g., by attack inference engine. In certain embodiments, a score (e.g., EPR score) for a potential risk of exploitation for each of the components (e.g., assets and business applications) is determined (e.g., calculated). In certain embodiments, a risk score serves as an indicator of the exploitability of a particular business application (or the whole computing environment), e.g., such that this knowledge would help a security officer and/or security platform to prioritize the mitigating or fixing of the issue(s).).
With respect to claim 17, the combination of Yellapragada in view of Crabtree and Black teaches the method of claim 15 (see rejection of claim 15 above), wherein generating the security configuration anticipated impact analysis (Yellapragada ¶0028: In certain embodiments, the “secure” 118 phase uses the attack paths and exploitability information to proactively propose countermeasures and/or remediations. In certain embodiments, these measures, if implemented, are to prevent/mitigate potential attack scenarios.) is further based on a security-productivity configuration associated with the computing environment, (Yellapragada ¶0057-0059: In certain embodiments herein (e.g., for an attack inference engine 112), a machine learning model is to predict (i) the exploitability of a vulnerability (e.g., and/or a weakness and/or a misconfiguration), and/or (ii) the exploitability of software (e.g., and its version), for example, even when the software has no current vulnerabilities associated with it. In certain embodiments, the training data includes one or any combination of the following features related to vulnerabilities (e.g., and weaknesses and/or misconfigurations) and software: identifier for the vulnerability/weakness, identifier for the software along with its version, number of references to the vulnerability, number of software and versions affected by vulnerability, number of exploits available for vulnerability, number of advisories published for vulnerability, time between exploit availability and disclosure of vulnerability, availability of a fix for a vulnerability, type of fixes available (e.g., patch and/or workaround), time between disclosure/exploit availability and fix provided, time since fix was available, popularity of the software affected (e.g., based on percentage of exploits existing or number of instances of software in a particular environment), percentage of vulnerabilities associated with the software, standard severity rating of the vulnerability, references indicating if vulnerability is widely exploited, type of service/application affected (e.g., web application, database application, security application, etc.), general impact in case of exploitation, ease of exploitation, and/or number of vulnerability identifiers associated with a weakness. In certain embodiments, a machine learning model determines the exploitability of a vulnerability of the assets, services, and/or infrastructure (e.g., software) regardless of their (e.g., its) placement in an enterprise.).
the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements. (Black: ¶0036-0040: As seen in Figure 1, the risk and compliance data 139 can include various information about datasets, benchmarks, and other enterprise standards for managing risks and vulnerabilities. The risk and compliance data 129 can include historical vulnerability management, risk assessment matrices, and internal policies. In some examples, the risk and compliance data 139 could be used to generate the vulnerability report 149 and/or the recommendation 153. The one or more vulnerability reports 149 can include comprehensive information on the one or more identified vulnerabilities. The vulnerability report 149 could include detailed documentation of the one or more vulnerabilities. In other instances, the vulnerability report can contain information on current operating system updates, security patches, applications, and settings/networking configurations. The one or more recommendations 153 can represent a guide to resolve the vulnerabilities present on a device. In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. In some instances, the recommendation 153 can be a recommendation to adjust security standards, compliance standards based at least in part on the electronic device usage (e.g., meets HIPAA standards if used for health records or medical information, state related data privacy standards such as California Consumer Privacy Act, etc.), and performance standards (e.g., resource usage, memory usage, battery life, etc.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Black of using the security productivity configuration to the method of Yellapragada in order to enable automation and less time-consuming for the remedial actions (Black ¶0001-0007).
Yellapragada in view of Black does not disclose
the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements;
Although, Yellapragada in view of Black does disclose the customization of parameters but the prior the art does not disclose productivity requirements rather Black discloses requirements for compliance and performance.
However, Crabtree teaches the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements; (¶0076: This same data would be combined with up-to-date known cyberattack methodology reports, possibly retrieved from several divergent and exogenous sources through the use of the multi-application programming interface aware connector module 135 to present preventative recommendations to the enterprise decision makers for network infrastructure changes, physical and configuration-based to cost effectively reduce the probability of a cyberattack (customizing security measures and productivity requirements) and to significantly and most cost effectively mitigate data exposure and loss in the event of attack 203, 204.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to customizing a balance between a security measures and productivity requirements to the method of Yellapragada and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
With respect to claim 19, the combination of Yellapragada in view of Black and Crabtree teaches the method of claim 15 (see rejection of claim 15 above) the method further comprising: monitoring productivity impact parameters associated with the entity; (Crabtree ¶0076: Figure 2, is a flow diagram of an exemplary function of the business operating system in the detection and mitigation of predetermining factors leading to steps to mitigate cyberattacks 200. The system may continuously retrieves network traffic data 201 which may be stored and preprocessed by the multidimensional time series data store 120 and its programming wrappers 120a. Analysis of network traffic may include graphical analysis of parameters such as network item to network usage using specifically developed programming in the graph stack service 145, 145a, analysis of usage by each network item may be accomplished by specifically pre-developed algorithms associated with the directed computational graph module 155, general transformer service module 160 and decomposable service module 150, depending on the complexity of the individual usage profile 201.);
identifying a potential or actual productivity impact issue; generating a contextualized insight for the potential or actual productivity impact issue; and (Crabtree ¶0076-0077: These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology. This same data would be combined with up-to-date known cyberattack methodology reports, possibly retrieved from several divergent and exogenous sources through the use of the multi-application programming interface aware connector module 135 to present preventative recommendations to the enterprise decision makers for network infrastructure changes, physical and configuration-based to cost effectively reduce the probability of a cyberattack and to significantly and most cost effectively mitigate data exposure and loss in the event of attack 203, 204. );
generating an alert associated with the potential or actual productivity impact issue. (Crabtree ¶0076-0078: Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207. This may include the exact subset of information included in alerts and updates and the format in which may be through the enterprise’s existing security information and event management system. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the monitoring the productivity parameters to the method of Yellapragada and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
With respect to claim 20, the combination of Yellapragada in view of Crabtree and Black teaches the method of claim 19 (see rejection of claim 19 above) the method further comprising based on the alert, autonomously updating the security configuration associated with the entity. (Crabtree ¶0101: As seen in Figure 8 is a flow diagram of an exemplary method 800 for cybersecurity behavioral analytics, according to one aspect. These anomalous behaviors may then be used 804 to analyze potential angles of attack and then produce 805 security suggestions (alert) based on this second-level analysis and predictions generated by an action outcome simulation module 125 to determine the likely effects of the change. The suggested behaviors may then be automatically implemented 806 as needed. ).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the autonomous update to the method of Yellapragada and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Crabtree et al. (US PGPub No.20220263860-A1), Black et al. (US PGPub No. 20250124137-A1), and Thompson et al. (US PGPub No. 20240257263-A1 ).
With respect to claim 5, the combination of Yellapragada in view of Crabtree and Black does teaches the system of claim 1 (see rejection of claim 1 above) the security-productivity configuration is associated with parameters associated with security exposures, security resolutions, and productivity impacts identified in the historical telemetry data associated with training the security configuration anticipated impact analysis model. (Yellapragada ¶0057-0058: In certain embodiments herein (e.g., for an attack inference engine 112), a machine learning model is to predict (i) the exploitability of a vulnerability (e.g., and/or a weakness and/or a misconfiguration), and/or (ii) the exploitability of software (e.g., and its version), for example, even when the software has no current vulnerabilities associated with it. In certain embodiments, the training data includes one or any combination of the following features related to vulnerabilities (e.g., and weaknesses and/or misconfigurations) and software: identifier for the vulnerability/weakness, identifier for the software along with its version, number of references to the vulnerability, number of software and versions affected by vulnerability, number of exploits available for vulnerability, number of advisories published for vulnerability, time between exploit availability and disclosure of vulnerability, availability of a fix for a vulnerability, type of fixes available (e.g., patch and/or workaround), time between disclosure/exploit availability and fix provided, time since fix was available, popularity of the software affected (e.g., based on percentage of exploits existing or number of instances of software in a particular environment), percentage of vulnerabilities associated with the software, standard severity rating of the vulnerability, references indicating if vulnerability is widely exploited, type of service/application affected (e.g., web application, database application, security application, etc.), general impact in case of exploitation, ease of exploitation, and/or number of vulnerability identifiers associated with a weakness.);
Yellapragada in view of Crabtree and Black does not disclose:
wherein configuring the first entity associated with the computing environment is based on: selecting a security configuration pipeline associated the first entity; and communicating the first security configuration for the first entity via the security configuration pipeline, the first security configuration comprising instructions for applying the first security configuration, wherein the first security configuration is associated with a security enforcement mechanism that applies the first security configuration,
However, Thompson teaches wherein configuring the first entity associated with the computing environment is based on: selecting a security configuration pipeline associated the first entity; and (¶0328: As seen in Figure 25, a block diagram implementation of security architecture for dynamic valuation of protection products is shown. The implementation shown in Figure 25 includes a client 110, response system 130, a third-party device 150, data sources 160, and data acquisition engine 180 for pipeline modeling. ¶0291: In some arrangements, the processing circuits can receive an activation of a cybersecurity plan offering from an entity's computing system. This signals that the entity has selected a plan from the marketplace and is ready to implement it.).
communicating the first security configuration for the first entity via the security configuration pipeline, the first security configuration comprising instructions for applying the first security configuration, ( ¶0291: The activation triggers a series of processes, including setting up the necessary connections between the entity and the third-party (described in block 2320), configuring the plan according to the entity's specific requirements, and monitoring the implementation to ensure that it is successful. In some arrangements, the processing circuits can provide the cybersecurity plan offerings to entities for purchase before the modeling process at block 2320 takes place.).
wherein the first security configuration is associated with a security enforcement mechanism that applies the first security configuration, (¶0294: In some arrangements, the processing circuits, in response to the activation of the cybersecurity protection obligation, model the activated cybersecurity plan offering. This modeling phase translates the theoretical aspects of the plan into practical measures that are incorporated into the entity's existing infrastructure).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Thompson of a security configuration pipeline to the method of Yellapragada in view of Crabtree and Black in order to prevent exposure of an organization to a constant evolving threat landscape while maintaining a robust security posture (Thompson ¶0053).
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Crabtree et al. (US PGPub No.20220263860-A1), Black et al. (US PGPub No. 20250124137-A1), Calmon et al. (US PGPub No. 20210319348-A1 ), and Bao et al. (US PGPub No. 20230259635-A1 ) .
With respect to claim 6, the combination of Yellapragada in view of Crabtree and Black teaches the system of claim 1 (see rejection of claim 1 above) wherein the security configuration anticipated impact analysis model is generated based on: accessing historical telemetry data; analyzing the historical telemetry data for security exposures and corresponding productivity impact of security resolutions to the security exposures; (Yellapragada ¶0057-0059: In certain embodiments herein (e.g., for an attack inference engine 112), a machine learning model is to predict (i) the exploitability of a vulnerability (e.g., and/or a weakness and/or a misconfiguration), and/or (ii) the exploitability of software (e.g., and its version), for example, even when the software has no current vulnerabilities associated with it. In certain embodiments, the training data includes one or any combination of the following features related to vulnerabilities (e.g., and weaknesses and/or misconfigurations) and software: identifier for the vulnerability/weakness, identifier for the software along with its version, number of references to the vulnerability, number of software and versions affected by vulnerability, number of exploits available for vulnerability, number of advisories published for vulnerability, time between exploit availability and disclosure of vulnerability, availability of a fix for a vulnerability, type of fixes available (e.g., patch and/or workaround), time between disclosure/exploit availability and fix provided, time since fix was available, popularity of the software affected (e.g., based on percentage of exploits existing or number of instances of software in a particular environment), percentage of vulnerabilities associated with the software, standard severity rating of the vulnerability, references indicating if vulnerability is widely exploited, type of service/application affected (e.g., web application, database application, security application, etc.), general impact in case of exploitation, ease of exploitation, and/or number of vulnerability identifiers associated with a weakness. In certain embodiments, a machine learning model determines the exploitability of a vulnerability of the assets, services, and/or infrastructure (e.g., software) regardless of their (e.g., its) placement in an enterprise.).
generating a security configuration anticipated impact analysis model that supports evaluating and assessing potential effects of implementing a security resolution for a security exposure in a computing environment; and (Yellapragada ¶0057-0058: In certain embodiments, a machine learning model (e.g., trained using the above) is then utilized on an enterprise (e.g., a profile identifying that enterprise and/or their assets, services, and/or infrastructure) and the output of the model is one or more predictions about exploitability of a vulnerability and/or exploitability of the assets, services, and/or infrastructure (e.g., assets, services, and infrastructure 102 in FIG. 1) of the user, e.g., even when there is no current vulnerability).
Yellapragada in view Crabtree and Black does not disclose:
generating logic to support executing contextual similarity-based assessment when historical telemetry data for an entity is not sufficient to support generating a security configuration anticipated impact analysis for the entity;
deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments.
However, Calmon generating logic to support executing contextual similarity-based assessment when historical telemetry data for an entity is not sufficient to support generating a security configuration anticipated impact analysis for the entity; (¶0065-0068: If one or more data protection appliances 130 do not have sufficient historical data to train the employed machine learning models (or are new data protection appliances without available training data), data from one or more similar data protection appliances 130 can be employed (e.g., based on one or more predefined similarity criteria). For example, the exemplary data protection appliances 130 can be clustered using the same features discussed above, if present, and some features that are not inside the data of the table 400 of FIG. 4, but rather on the specifications of each data protection appliance 130, such as product model and allowable number of concurrent jobs. This serves as input for clustering algorithms such as a k-means clustering algorithm (similarity-based assessment) . One or more aspects of the disclosure recognize that for such unsupervised steps, there is no need to separate the datasets. After clustering is complete, the regression learning pipeline can be re-executed using data from a single data protection appliance 130 and/or data from a cluster of similar data protection appliances 130.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Calmon of contextual similarity-based assessment to the method of Yellapragada in view of Crabtree and Black in order to protect the system further from data loss (Calmon ¶0018).
Yellapragada in view of Crabtree, Black, and Calmon does not disclose:
deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments.
However, Bao teaches deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments. (¶0040: As seen in Figure 1A and 1B, the system 100 can implement functionality defined by an application 102, defining functionality associated with features of a classification model for determining expected exploitability for a software vulnerability over time. Further in ¶0131-0133: At a second time frame (@T 2), the system can update the training data to include information available for (@T 2), train the classification model on the updated training data, and then deploy the (now-updated) classification model using updated vulnerability information (e.g., test-case or deployment-case information) available for (@T 2) to obtain re-evaluated EE scores. This can include information about new software vulnerabilities that were not available for (@T 1), and can also include new or updated information (including PoC info, exploits data and labels) about software vulnerabilities that were previously included in (@T 1). This process can be repeated indefinitely to ensure that the classification model is up to date. As new information becomes available for each respective software vulnerability, the EE scores will update to reflect how exploitability of a given software vulnerability changes over time.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Bao of deploying a security configuration anticipated impact model to the method of Yellapragada in view of Crabtree and Black and Calmon in order to stay up to date as new information become available for each respective software vulnerability (Bao ¶0133).
Claims 8, 11, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Bao et al. (US PGPub No. 20230259635-A1 ) and Crabtree et al. (US PGPub No.20220263860-A1) .
With respect to claim 8, Yellapragada teaches one or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising: (¶0011: The present disclosure relates to methods, apparatus, systems, and non-transitory computer-readable storage media for predicative analysis of potential attack patterns based on contextual security information. In certain enterprises and/or public cloud environments, there are several assets, applications, servers, services (e.g., software application stack(s)) which are connected through various networks. In turn, there could arise various vulnerabilities (e.g., including weaknesses and/or misconfigurations) related to these resources.).
accessing historical telemetry data; (¶0018: The below sections include (i) predictive analysis of potential attack paths based on contextual vulnerability information, (ii) methods for prioritizing security findings using machine learning models, (iii) risk scoring for applications based on historical, predictive, and inherent factors, (iv) methods for proposing counter measures for security vulnerabilities using contextual and attack prediction patterns, and (v) methods for vulnerability assessment for cloud assets using imaging methods.).
analyzing the historical telemetry data for security exposures and corresponding productivity impact of security resolutions to the security exposures; (¶0027: In certain embodiments, during the “infer” 114 phase, all the collected information (e.g., collected by vulnerability detectors 500 in FIG. 5) is analyzed. In the depicted embodiment, the attack inference engine 112 performs the inference(s). In certain embodiments, the collected information includes vulnerabilities (e.g., and weaknesses and/or misconfigurations) information. In certain embodiments, a network architecture map previously discovered is employed to infer potential attack paths. In certain embodiments, one or more machine learning models are employed to predict the next attack sequence in an attack pattern (e.g., as discussed below))).
generating a security configuration anticipated impact analysis model that supports evaluating and assessing potential effects of implementing a security resolution for a security exposure in a computing environment; and (¶0023-0027: In certain embodiments, security platform 100 is to generate one or more indication of vulnerabilities 110 in assets, services, and/or infrastructure 102, e.g., generated from the discover 104, analyze 106, and monitor 108. In certain embodiments, security platform 100 (e.g., attack inference engine 110 thereof) is to perform an inference at infer 114 (e.g., as shown by the square labeled with a “4”) to determine potential attack path(s), risk score(s), and/or compliance status(es).).
deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments.
Yellapragada does not disclose:
deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments.
However, Bao teaches deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for security exposures in computing environments. (¶0040: As seen in Figure 1A and 1B, the system 100 can implement functionality defined by an application 102, defining functionality associated with features of a classification model for determining expected exploitability for a software vulnerability over time. Further in ¶0131-0133: At a second time frame (@T 2), the system can update the training data to include information available for (@T 2), train the classification model on the updated training data, and then deploy the (now-updated) classification model using updated vulnerability information (e.g., test-case or deployment-case information) available for (@T 2) to obtain re-evaluated EE scores. This can include information about new software vulnerabilities that were not available for (@T 1), and can also include new or updated information (including PoC info, exploits data and labels) about software vulnerabilities that were previously included in (@T 1). This process can be repeated indefinitely to ensure that the classification model is up to date. As new information becomes available for each respective software vulnerability, the EE scores will update to reflect how exploitability of a given software vulnerability changes over time.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Bao of deploying a security configuration anticipated impact model to the method of Yellapragada in order to stay up to date as new information become available for each respective software vulnerability (Bao ¶0133).
With respect to claim 8, Yellapragada teaches one or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising: (¶0011: The present disclosure relates to methods, apparatus, systems, and non-transitory computer-readable storage media for predicative analysis of potential attack patterns based on contextual security information. In certain enterprises and/or public cloud environments, there are several assets, applications, servers, services (e.g., software application stack(s)) which are connected through various networks. In turn, there could arise various vulnerabilities (e.g., including weaknesses and/or misconfigurations) related to these resources.).
accessing historical telemetry data; (¶0018: The below sections include (i) predictive analysis of potential attack paths based on contextual vulnerability information, (ii) methods for prioritizing security findings using machine learning models, (iii) risk scoring for applications based on historical, predictive, and inherent factors, (iv) methods for proposing counter measures for security vulnerabilities using contextual and attack prediction patterns, and (v) methods for vulnerability assessment for cloud assets using imaging methods.).
analyzing the historical telemetry data for security exposures and corresponding productivity impact of security resolutions to the security exposures; (¶0027: In certain embodiments, during the “infer” 114 phase, all the collected information (e.g., collected by vulnerability detectors 500 in FIG. 5) is analyzed. In the depicted embodiment, the attack inference engine 112 performs the inference(s). In certain embodiments, the collected information includes vulnerabilities (e.g., and weaknesses and/or misconfigurations) information. In certain embodiments, a network architecture map previously discovered is employed to infer potential attack paths. In certain embodiments, one or more machine learning models are employed to predict the next attack sequence in an attack pattern (e.g., as discussed below))).
generating a security configuration anticipated impact analysis model that supports evaluating and assessing potential effects of implementing a security resolution for a security exposure in a computing environment (¶0023-0027: In certain embodiments, security platform 100 is to generate one or more indication of vulnerabilities 110 in assets, services, and/or infrastructure 102, e.g., generated from the discover 104, analyze 106, and monitor 108. In certain embodiments, security platform 100 (e.g., attack inference engine 110 thereof) is to perform an inference at infer 114 (e.g., as shown by the square labeled with a “4”) to determine potential attack path(s), risk score(s), and/or compliance status(es).)
wherein the security configuration anticipated impact analysis model is a machine learning model trained using the historical telemetry data; and (¶0075: To create an anomaly detection ML model, certain embodiments use several of these fields and use certain calculated fields e.g., which overall define the features of the data set. n certain embodiments, the process of training the anomaly detection ML model involves providing training data to an ML algorithm, e.g., with the training data including one or any combination of: source IP (e.g., for traffic entering from internet 410 in Figure 4), number of distinct IPs seen in a time period (e.g., per day, per week, per month, etc.) (historical data));
Yellapragada does not disclose:
deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for additional security exposures in computing environments
However, Bao teaches deploying the security configuration anticipated impact analysis model to support generating security configuration impact analyses for additional security exposures in computing environments. (¶0040: As seen in Figure 1A and 1B, the system 100 can implement functionality defined by an application 102, defining functionality associated with features of a classification model for determining expected exploitability for a software vulnerability over time. Further in ¶0131-0133: At a second time frame (@T 2), the system can update the training data to include information available for (@T 2), train the classification model on the updated training data, and then deploy the (now-updated) classification model using updated vulnerability information (e.g., test-case or deployment-case information) available for (@T 2) to obtain re-evaluated EE scores. This can include information about new software vulnerabilities that were not available for (@T 1), and can also include new or updated information (including PoC info, exploits data and labels) about software vulnerabilities that were previously included in (@T 1). This process can be repeated indefinitely to ensure that the classification model is up to date. As new information becomes available for each respective software vulnerability, the EE scores will update to reflect how exploitability of a given software vulnerability changes over time.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Bao of deploying a security configuration anticipated impact model to the method of Yellapragada in order to stay up to date as new information become available for each respective software vulnerability (Bao ¶0133).
Yellapragada in view of Bao does not disclose:
wherein a security configuration anticipated impact analysis is a targeted assessment generated using machine learning to quantify anticipated changes insecurity metrics and productivity metrics associated with implementation of the security resolution of the security exposure within the computing environment.
However, Crabtree teaches wherein a security configuration anticipated impact analysis is a targeted assessment (¶0072-0073: Figure 1 is a diagram of an exemplary architecture of an advanced cyber decision platform (ACDP). Client access to system 105 for specific data entry, system control and for interaction with system output such as automated predictive decision making and planning and alternate pathway simulations. Results of the transformative analysis process may then be combined with further client directives, additional business rules and practices relevant to the analysis and situational in formation external to the already available data in the automated planning service module 130 which is also runs powerful information theory 130a based predicative statistics functions and machine learning algorithms to allow future trends and outcomes to be rapidly forecasted based upon current system rived results and choosing each a plurality possible business decision. ) generated using machine learning to quantify anticipated changes insecurity metrics and productivity metrics associated with implementation of the security resolution of the security exposure within the computing environment. (¶0079: Figure 3 , is a process diagram showing a general flow 300 of business operating system functions in use to mitigate cyberattacks ( a part of the cyber decision platform). Input network data may pass into 315 the business operating system 310 for analysis as part of tis cybersecurity function. These multiple types of data from a plurality of sources may be transformed for analysis 311 (quantify) 311, 312 using at least one of the specialized cybersecurity, risk assessment or common functions of the business operating system in the role of cybersecurity system, but not limited to incident identification and resolution performance analytics (security metrics) , value at risk (VAR) modeling and simulation 341, anticipatory vs. reactive cost estimations of different types of data breaches to establish priorities 342, work factor analysis 343 (productivity metrics) and cyber event discovery rate 344 as a part of the system’s risk analytics capabilities, and the ability to generate cyber-physical system graphing 354 as part of the business operating system’s common capabilities. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the security configuration anticipated impact analysis to the method of Yellapragada in view of Bao in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
With respect to claim 11, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) the operations further comprising: identifying a first security exposure associated with a first computing environment; (Abstract: Systems and method for predictive analysis of potential attack patterns based on contextual security information are described. In one embodiment, a method includes generating a profile for an enterprise that indicates one or more software application stacks and a network architecture for the one or more software application stacks; determining one or more vulnerabilities of the one or more software application stacks and one or more vulnerabilities of the network architecture; )
using the security configuration anticipated impact analysis model associated with historical telemetry data, (Yellapragada ¶0018: The below sections include (i) predictive analysis of potential attack paths based on contextual vulnerability information, (ii) methods for prioritizing security findings using machine learning models (iii) scoring for application based historical, predictive, and inherent factors, (iv) methods for proposing counter measures for security vulnerabilities using contextual and attack prediction patterns, and (v) methods for vulnerability assessment for cloud assets using imaging methods. Further in ¶0027: In certain embodiments, during the “infer” 114 phase, all the collected information (e.g., collected by vulnerability detectors 500 in FIG. 5) is analyzed. In the depicted embodiment, the attack inference engine 112 performs the inference(s). In certain embodiments, the collected information includes vulnerabilities (e.g., and weaknesses and/or misconfigurations) information. In certain embodiments, a network architecture map previously discovered is employed to infer potential attack paths. In certain embodiments, one or more machine learning models are employed to predict the next attack sequence in an attack pattern (e.g., as discussed below));
generating a first security configuration anticipated impact analysis for the first security exposure and the first computing environment; and based on the first security configuration anticipated impact analysis, configuring an entity associated with the first computing environment with a security configuration associated with remediating the security exposure. (Yellapragada ¶0027-0028: In certain embodiments, the “secure” 118 phase uses the attack paths and exploitability information to proactively propose countermeasures and/or remediations. In certain embodiments, these measures, if implemented, are to prevent/mitigate potential attacks attack scenarios. In certain embodiments, the vulnerability (e.g., and weakness/misconfiguration) information is mapped to standard weakness (e.g., and/or vulnerability) identifiers such as CWE (Common Weakness Enumeration) and CVE (Common Vulnerability Enumeration). In certain embodiments, these standard identifiers provide suggested remediations, which are mapped by the security platform 100 based on the network architecture and relevant specifics are added to the remediations.)
With respect to claim 13, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) the operations further comprising: monitoring productivity impact parameters associated with an entity; (Crabtree ¶0076: Figure 2, is a flow diagram of an exemplary function of the business operating system in the detection and mitigation of predetermining factors leading to steps to mitigate cyberattacks 200. The system may continuously retrieves network traffic data 201 which may be stored and preprocessed by the multidimensional time series data store 120 and its programming wrappers 120a. Analysis of network traffic may include graphical analysis of parameters such as network item to network usage using specifically developed programming in the graph stack service 145, 145a, analysis of usage by each network item may be accomplished by specifically pre-developed algorithms associated with the directed computational graph module 155, general transformer service module 160 and decomposable service module 150, depending on the complexity of the individual usage profile 201.);
identifying a potential or actual productivity impact issue; generating a contextualized insight for the potential or actual productivity impact issue; and (Crabtree ¶0076-0077: These usage pattern analyses, in conjunction with additional data concerning an enterprise's network topology. This same data would be combined with up-to-date known cyberattack methodology reports, possibly retrieved from several divergent and exogenous sources through the use of the multi-application programming interface aware connector module 135 to present preventative recommendations to the enterprise decision makers for network infrastructure changes, physical and configuration-based to cost effectively reduce the probability of a cyberattack and to significantly and most cost effectively mitigate data exposure and loss in the event of attack 203, 204. );
generating an alert associated with the potential or actual productivity impact issue. (Crabtree ¶0076-0078: Once a probable cyberattack is detected, the system then is designed to get needed information to responding parties 206 tailored, where possible, to each role in mitigating the attack and damage arising from it 207. This may include the exact subset of information included in alerts and updates and the format in which may be through the enterprise’s existing security information and event management system. );
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to the monitoring the productivity parameters to the method of Yellapragada and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Bao et al. (US PGPub No. 20230259635-A1 ), Crabtree et al. (US PGPub No.20220263860-A1), and Ciziunas et al. (US PGPub No. 20190377893-A1 ) .
With respect to claim 9, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) but does not disclose wherein the historical telemetry data is accessed based on a plurality of data sources associated a cloud computing environment, wherein the plurality of data sources are associated with security management applications, directory services, and security agents, the historical data is aggregated and enriched using security-productivity contextualization and enriching objects.
However, Ciziunas teaches wherein the historical telemetry data is accessed based on a plurality of data sources associated a cloud computing environment, wherein the plurality of data sources are associated with security management applications, directory services, and security agents, (¶0022: While a beacon agent is described above as being a local program, application, add-in, plugin, and/or the like stored by and/or executed by a user device, in other embodiments, a beacon agent can be a system agent, application, program, and/or the like stored by and/or executed by a system device such as a host device, administrator device, server, and/or any other cloud-based agent. )
the historical data is aggregated and enriched using security-productivity contextualization and enriching objects(¶0022: The Analysis Platform may be any suitable device and/or software application executed by hardware configured to record, annotate, enrich, and/or secure data in the Signal Log Server(s) and Beacon Log Server(s). For example, the Analysis Platform may aggregate the data in the Signal Log Server(s) and Beacon Log Server(s), can analyze the aggregated data based on any suitable policy and/or analysis method, and can present the aggregated and analyzed data to an Analyst (e.g., on a display of an electronic device. Furthermore, the Analysis Platform may be configured to enrich, expand upon, and/or otherwise extrapolate from the data stored in the Data Servers. For example, in some instances, the Analysis Platform may enrich the data stored in the Data Servers by associating additional information with the information stored in the Beacon Log Server and Signal Log Server. Such additional information can include, for example, IP addresses of relevant devices, geographic locations associated with those IP addresses, ownership information associated with a device or IP address, characterization of historical use (e.g., by bad actors, thieves, and/or attackers, whitelists or lists of IP address to ignore, blacklists or lists of IP address to flag or block, etc.)) .
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Ciziunas of the historical telemetry data to the method of Yellapragada in view of Bao and Crabtree in order to hele determine unauthorized actions and noncompliance (Ciziunas ¶0012-0013).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Bao et al. (US PGPub No. 20230259635-A1 ), Crabtree et al. (US PGPub No.20220263860-A1), and Calmon et al. (US PGPub No. 20210319348-A1) .
With respect to claim 10, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) wherein generating the security configuration anticipated impact analysis model is based on: (Yellapragada ¶0028: In certain embodiments, the “secure” 118 phase uses the attack paths and exploitability information to proactively propose countermeasures and/or remediations. In certain embodiments, these measures, if implemented, are to prevent/mitigate potential attack scenarios.) identifying security exposures, security resolutions, and productivity impacts associated with the historical telemetry data; analyzing the security exposures, security resolutions, and productivity impacts determining patterns in the security exposures, security resolutions, and productivity impacts; and (Yellapragada ¶0057-0059: In certain embodiments herein (e.g., for an attack inference engine 112), a machine learning model is to predict (i) the exploitability of a vulnerability (e.g., and/or a weakness and/or a misconfiguration), and/or (ii) the exploitability of software (e.g., and its version), for example, even when the software has no current vulnerabilities associated with it. In certain embodiments, the training data includes one or any combination of the following features related to vulnerabilities (e.g., and weaknesses and/or misconfigurations) and software: identifier for the vulnerability/weakness, identifier for the software along with its version, number of references to the vulnerability, number of software and versions affected by vulnerability, number of exploits available for vulnerability, number of advisories published for vulnerability, time between exploit availability and disclosure of vulnerability, availability of a fix for a vulnerability, type of fixes available (e.g., patch and/or workaround), time between disclosure/exploit availability and fix provided, time since fix was available, popularity of the software affected (e.g., based on percentage of exploits existing or number of instances of software in a particular environment), percentage of vulnerabilities associated with the software, standard severity rating of the vulnerability, references indicating if vulnerability is widely exploited, type of service/application affected (e.g., web application, database application, security application, etc.), general impact in case of exploitation, ease of exploitation, and/or number of vulnerability identifiers associated with a weakness. In certain embodiments, a machine learning model determines the exploitability of a vulnerability of the assets, services, and/or infrastructure (e.g., software) regardless of their (e.g., its) placement in an enterprise.).
Yellapragada in view of Bao and Crabtree does not disclose:
generating logic to support executing contextual similarity-based assessment when the historical telemetry data for an entity is not sufficient to support generating a security configuration anticipated impact analysis for the entity.
However, Calmon generating logic to support executing contextual similarity-based assessment when historical telemetry data for an entity is not sufficient to support generating a security configuration anticipated impact analysis for the entity. (¶0065-0068: If one or more data protection appliances 130 do not have sufficient historical data to train the employed machine learning models (or are new data protection appliances without available training data), data from one or more similar data protection appliances 130 can be employed (e.g., based on one or more predefined similarity criteria). For example, the exemplary data protection appliances 130 can be clustered using the same features discussed above, if present, and some features that are not inside the data of the table 400 of FIG. 4, but rather on the specifications of each data protection appliance 130, such as product model and allowable number of concurrent jobs. This serves as input for clustering algorithms such as a k-means clustering algorithm (similarity-based assessment) . One or more aspects of the disclosure recognize that for such unsupervised steps, there is no need to separate the datasets. After clustering is complete, the regression learning pipeline can be re-executed using data from a single data protection appliance 130 and/or data from a cluster of similar data protection appliances 130.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Calmon of contextual similarity-based assessment to the method of Yellapragada in view of Bao and Crabtree in order to protect the system further from data loss (Calmon ¶0018).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Bao et al. (US PGPub No. 20230259635-A1 ), Crabtree et al. (US PGPub No.20220263860-A1), and Black et al. (US PGPub No. 20250124137-A1).
With respect to claim 12, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) but does not disclose wherein generating the security configuration anticipated impact analysis is further based on a security-productivity configuration associated with the computing environment, the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements.
However, Black teaches wherein generating the security configuration anticipated impact analysis is further based on a security-productivity configuration associated with the computing environment, the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements. (¶0036-0040: As seen in Figure 1, the risk and compliance data 139 can include various information about datasets, benchmarks, and other enterprise standards for managing risks and vulnerabilities. The risk and compliance data 129 can include historical vulnerability management, risk assessment matrices, and internal policies. In some examples, the risk and compliance data 139 could be used to generate the vulnerability report 149 and/or the recommendation 153. The one or more vulnerability reports 149 can include comprehensive information on the one or more identified vulnerabilities. The vulnerability report 149 could include detailed documentation of the one or more vulnerabilities. In other instances, the vulnerability report can contain information on current operating system updates, security patches, applications, and settings/networking configurations. The one or more recommendations 153 can represent a guide to resolve the vulnerabilities present on a device. In some embodiments, the one or more recommendations 153 can be based at least in part on the one or more vulnerability reports 149. In some instances, the recommendation 153 can be a recommendation to adjust security standards, compliance standards based at least in part on the electronic device usage (e.g., meets HIPAA standards if used for health records or medical information, state related data privacy standards such as California Consumer Privacy Act, etc.), and performance standards (e.g., resource usage, memory usage, battery life, etc.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Black of using the security productivity configuration to the method of Yellapragada in view of Bao and Crabtree in order to enable automation and less time-consuming for the remedial actions (Black ¶0001-0007).
Yellapragada in view of Bao and Black does not disclose:
the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements.
Although, Yellapragada in view of Bao and Black does disclose the customization of parameters but the prior the art does not disclose productivity requirements rather Black discloses requirements for compliance and performance. However Crabtree, teaches the security-productivity configuration comprises a set of parameters and settings for defining and customizing a balance between security measures and productivity requirements; (¶0076: This same data would be combined with up-to-date known cyberattack methodology reports, possibly retrieved from several divergent and exogenous sources through the use of the multi-application programming interface aware connector module 135 to present preventative recommendations to the enterprise decision makers for network infrastructure changes, physical and configuration-based to cost effectively reduce the probability of a cyberattack (customizing security measures and productivity requirements) and to significantly and most cost effectively mitigate data exposure and loss in the event of attack 203, 204.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Crabtree with regards to customizing a balance between a security measures and productivity requirements to the method of Yellapragada in view of Bao and Black in order to efficiently protect against complex and frequent cyberattacks especially against attacks that requires too much active configuration, ongoing administrator interaction and support while providing limited protection against sophisticated adversaries (Crabtree ¶0019-0022).
Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Bao et al. (US PGPub No. 20230259635-A1 ), Crabtree et al. (US PGPub No.20220263860-A1), and Shachar et al. (US PGPub No. 20230169166-A1).
With respect to claim 14, the combination of Yellapragada in view of Bao and Crabtree teaches the media of claim 8 (see rejection of claim 8 above) wherein based on the security configuration anticipated impact analysis indicating an impact on productivity and security of the computing environment, the threat protection engine does not configure a second entity associated with the computing environment with the security configuration associated with remediating the security exposure
However, Shachar teaches wherein based on the security configuration anticipated impact analysis indicating an impact on productivity and security of the computing environment, the threat protection engine does not configure a second entity associated with the computing environment with the security configuration associated with remediating the security exposure (¶0039: The divergence of the operation of deployments 100, by virtue of the malicious entities, may prevent and/or reduce the capability of deployments 100 providing computer implemented services. In general, embodiments disclosed herein provide methods, systems, and devices for improving the likelihood of deployments providing computer implemented services. To do so, a system in accordance with an embodiment may proactively monitor for signs of malicious activities. If malicious activities are identified, one or more actions to remediate risk associated with the malicious activities may be performed. The actions may include, for example, suspending the operation of one or more entities associated with the malicious activities, reverting modifications to data impacted by the malicious activities, and/or any other types of actions that may be used to reduce the impact of malicious activities on a deployment.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Shachar of the security configuration anticipated impact analysis to the method of Yellapragada in view of Bao and Crabtree in order to prevent malicious parties to attempt to compromise the operation of one or more deployments. (Shachar ¶0037).
Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Yellapragada et al. (US PGPub No. 20230208870-A1 ) in view of Crabtree et al. (US PGPub No.20220263860-A1), Black et al. (US PGPub No. 20250124137-A1 ), and Shachar et al. (US PGPub No. 20230169166-A1).
With respect to claim 18, the combination of Yellapragada in view of Crabtree and Black teaches the method of claim 15 (see rejection of claim 15 above) but does not disclose wherein based on the security configuration anticipated impact analysis indicating an impact on productivity and security of the computing environment, the threat protection engine does not configure a second entity associated with the computing environment with the security configuration associated with remediating the security exposure
However, Shachar teaches wherein based on the security configuration anticipated impact analysis indicating an impact on productivity and security of the computing environment, the threat protection engine does not configure a second entity associated with the computing environment with the security configuration associated with remediating the security exposure. (¶0039: The divergence of the operation of deployments 100, by virtue of the malicious entities, may prevent and/or reduce the capability of deployments 100 providing computer implemented services. In general, embodiments disclosed herein provide methods, systems, and devices for improving the likelihood of deployments providing computer implemented services. To do so, a system in accordance with an embodiment may proactively monitor for signs of malicious activities. If malicious activities are identified, one or more actions to remediate risk associated with the malicious activities may be performed. The actions may include, for example, suspending the operation of one or more entities associated with the malicious activities, reverting modifications to data impacted by the malicious activities, and/or any other types of actions that may be used to reduce the impact of malicious activities on a deployment.).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Shachar of the security configuration anticipated impact analysis to the method of Yellapragada in view of Crabtree and Black in order to prevent malicious parties to attempt to compromise the operation of one or more deployments. (Shachar ¶0037).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.P.V./Examiner, Art Unit 2437
/MENG LI/Primary Examiner, Art Unit 2437