DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/11/2026 has been entered.
Examiner’s Note
Claim 17 recites “One or more computer-storage media having…”. It is noted that paragraph 0104 of the specification as filed states that “Computer storage media excludes signals per se.” Therefore, the claimed “One or more computer-storage media” in claim 17 are not signals per se.
Response to Arguments
The Applicant argues, with respect to the rejection of claims 1-20 under 35 U.S.C. 101, that Claim 1 recites a non-generic system that performs contextual attack analysis using a predictive model and an attack path context that integrates real-time security telemetry (see page 10). The claimed system transforms raw security telemetry into a structured contextual model that enables machine-driven impact quantification and dynamic mitigation selection-operations that improve the functioning of the computer system itself and enhance the accuracy and responsiveness of cybersecurity controls (see page 11). The invention therefore provides a technological solution to a technological problem: how to automatically and adaptively prioritize disruption actions based on resource-specific impact in real-time attack prediction. The invention therefore provides a technological solution to a technological problem: how to automatically and adaptively prioritize disruption actions based on resource-specific impact in real-time attack prediction. The recited features collectively define a specialized computer architecture that improves contextual attack modeling and disruption planning.
The Applicant further argues that the claim defines a detailed process for generating and updating a contextual attack disruption framework, technological solution to a technological problem, improve computer capabilities or technology, meaningful limitations and particularity of application (see pages 12-14). The Applicant argues (see pages 13-14), with respect to the rejection of claims 1-20 under 35 U.S.C. 101, that claim 1 recites specific computer-implemented operations that enable context-aware cybersecurity management and the claims are integrated into a practical application. On page 16, the Applicant argues that Claim 1 addresses a specific technological problem in computer security: how to automatically evaluate and mitigate complex, multi-stage cyberattacks in a way that distinguishes between incurred losses and preventable impact.
In response to the Applicant’s augments, the Examiner respectfully disagrees. First, claim 1 does not require or recite automatically and adaptively prioritize disruption actions based on resource-specific impact in real-time attack prediction, even if the claim does recite “prioritize disruption actions based on resource-specific impact in real-time attack prediction”, prioritizing disruption actions is a mental process since humans prioritize actions in the mind.
Second, claim 1 recites “identifying a security incident, generating a security incident predictive model analysis… generating a security incident impact analysis… generating an attack disruption plan…” These steps merely involve identifying information and generating information, which are performed in the human mind. Claim 1 fails to recite using the identified information, result of analysis or disruption plan to improve the system. The Applicant fails to show how merely analyzing and generating information without using the information to improve the system functionality would result in improvement in computer functionality. In other words, how can the claim provide a technological solution to a technological problem (improves automated threat response accuracy and speed (see Applicant’s Arguments, pages 12-13)) or improve computer capabilities or technology when the implementation of such improvement is not required by the claim?. Therefore, claim 1 is not directed to the specific asserted solution, specialized computer architecture or improvement in computer functionality. Instead, the claim focuses on steps that qualify as mental processes and abstract idea for which computers are used to perform generic function or merely executing “apply it” to the abstract idea.
In response to the Applicant’s argument that “The improvement is analogous to recognized technical advancements in Enfish (database architecture) and McRO (automated rule-based processing): here, the improvement lies in how the system represents and processes security impact data to achieve dynamic, optimized mitigation (see page 13 of Applicant’s arguments), Enfish requires configuring a memory according a logical table to improve the way a computer stores and retrieves data in memory. Unlike, Enfish, the claims here require no configuration of the system according to the attack disruption plan or to make any improvement. Likewise, unlike McRo, which requires applying first set of rules to each sub-sequence, and applying final stream of output morph weight sets to a sequence of animated characters to produce lip synchronization and facial expression control of animated characters, the claims here require no application of the result of the analysis or the attack disruption plan. Accordingly, the claims are not eligible under 35 U.S.C. 101.
In response to the Applicant’s argument regarding the rejections under 35 U.S.C. 103, the amendments made to claims 1, 11 and 17 have overcome the rejections under 35 U.S.C. 103. Therefore, the rejections under 35 U.S.C. 103 have been withdrawn.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 11 and 17 satisfy Step 1 because the claims are a process, article of manufacture or machine.
In Step 2A prong 1, claim 1 recites “identifying a security incident… generating a security incident predictive model analysis… generating an attack path context… generating a security incident impact analysis… generating an attack disruption plan…”, which, under the broadest reasonable interpretation, are steps that are performed in the human mind. Claim 1 merely involves identifying, analyzing and generating information. Such steps of identifying, analyzing and generating information are performed in the human mind or by using a pen and paper.
Claim 17 recites “based on communicating the request, receiving a security posture visualization comprising contextual attack disruption data…causing a display…”, which is performed in the human mind. Claim 17 involves gathering information and identifying information to be displayed. Such step of identifying information to be displayed is performed in the human mind.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Claim 11 recites limitations similar to claim 1 and therefore, claim 11 also falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claims recite an abstract idea.
In Step 2A prong 2, the judicial exception is not integrated into a practical application because processor and memory are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component. The claims also recite the additional steps of “communicating the attack disruption plan”, “communicating the contextual attack disruption data…” and “communicating a request for a security posture…” and “causing display…”. However, these steps are insignificant extra-solution activity, e.g., mere data gathering or displaying data in conjunction with the abstract idea. These steps are performed to gather data so that the data can be analyzed by an abstract mental process and the result of the mental process can be displayed. Adding insignificant extra-solution activity to the judicial exception is not enough to qualify as “significantly more”. The additional elements or steps do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
In Step 2B, the claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because memory and processor are general purpose computer components, which are well-understood, routine and conventional (see Decasper et al. (U.S. PGPub 2007/0192474) paragraph 0004 where include conventional components such as a processor, a memory (e.g., RAM)… a network interface, such as a conventional modem), performing the steps recited in the claims and are not sufficient to transform a judicial exception into a patentable invention.
Regarding claims 2-10, 12-16 and 18-20, claims 2-10, 12-16 and 18-20 recite “the security incident is a multi-stage security incident…hypothetical sequence of steps…”, “generating the security incident predictive model analysis…”, “comprises a predicted quantified security incident cost…”, “…based on determining positive costs and negative costs…”, “generating the attack disruption plan is based on the predicted attack plan…”, “generating a plurality attack disruption plans as candidate attack disruption plan…”, “…generating a security posture visualization comprising contextual attack disruption data…”, “communicating, from a security management client, a request for a security posture…causing display of the security posture visualization”, and “receiving an indication…communicating the indication to execute the remediation…” However, these features are merely information, involve selecting or identifying information, generating information or are insignificant extra-solution activities (requesting or gathering data, visualization or displaying data). While claim 10 recites “communicating the indication to execute the remediation action…”, claim 10 does not specify what the “remediation action” is and does not require the execution of the remediation action. Therefore, under the broadest reasonable interpretation, “communicating the indication to execute the remediation action…”, as claimed, is an insignificant extra-solution activity such as displaying data. Thus, claims 2-10, 12-16 and 18-20 do not add meaningful limitation to the abstract idea.
The elements recited in claims 1-20, when considered individually or in an ordered combination, fail to amount to significantly more than the abstract idea. Accordingly, claims 1-20 are not eligible.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. This includes:
U.S. PGPub 2022/0217163, which describes a method and system for analyzing cybersecurity threats and improving defensive intelligence; and
U.S. PGPub 2021/0357507, which describes a framework for automated penetration testing.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MENG VANG whose telephone number is (571)270-7023. The examiner can normally be reached M-F 8AM-2PM, 3PM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, NICHOLAS TAYLOR can be reached at (571) 272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MENG VANG/Primary Examiner, Art Unit 2443