DETAILED ACTION
Claims 21-40 are presented for consideration.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 01/07/2026 has been entered.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 21-40 are rejected under 35 U.S.C. 103 as being unpatentable over Sharan et al. [ US Patent Application No 2020/0175077 ], in view of Zettel, II et al. [ US Patent Application No 2019/0268354 ].
4. As per claim 21, Sharan discloses the invention as claimed including a cyber situational awareness and response system [ i.e. security information and event management ] [ Figure 1; Abstract; and paragraphs 0031, and 0032 ], comprising:
one or more processors; and one or more memories coupled to the one or more processors to store instructions, which when executed by the one or more processors, cause the cyber situational awareness and response system to perform operations, the operations comprising:
receiving a user input from a user of the cyber situational awareness and response system [ i.e. text-based, voice-based, visual-based input ] [ 110, 112, 114, Figure 1; and paragraph 0032 ], the user input having one or more nouns or pronouns, and one or more verbs [ i.e. user inputs a natural language command ] [ paragraphs 0034, and 0038 ];
determining one or more first entities based on the one or more nouns or pronouns; determining an intent based on the one or more verbs [ i.e. applying lemmatization and tokenized concepts to language inputs to extract the entities and intent of the given instruction ] [ 400, Figure 3; and paragraphs 0033, and 0037 ]; and
in accordance with the one or more first entities and the intent, displaying, via a user interface, a plurality of threat events associated with the one or more first entities [ i.e. commands such as “show me a bar graph of login failures by user”, and returning the results of the query, and then visually displaying the results in a bar graph of login failures per username ] [ paragraph 0034, and 0047 ].
Sharan does not specifically disclose
wherein the intent comprises a cyber security action relating to the one or more first entities to be performed by the cyber situational awareness and response system;
receiving a first user selection of a first threat event of the plurality of threat events;
in response to the first user selection, displaying, via a second user interface, event information of the first threat event;
extracting one or more second entities from the event information of the first threat event;
determining a first actionable entity from the one or more second entities; and
displaying, via a third user interface, a plurality of first available security actions associated with the determined first actionable entity to the user to resolve the first threat event.
Zettel discloses
wherein the intent comprises a cyber security action relating to the one or more first entities to be performed by the cyber situational awareness and response system [ i.e. tools for analyzing and resolving a security incident ] [ Abstract; and paragraphs 0005, 0036, and 0081 ];
receiving a first user selection of a first threat event of the plurality of threat events [ i.e. critical incidents ] [ Figure 3; and paragraph 0059 ];
in response to the first user selection, displaying, via a second user interface, event information of the first threat event [ i.e. display a peek view of each security incident in container upon selecting the graphic 330 next to the identification number of each security incident ] [ Figure 6; and paragraph 0067 ];
extracting one or more second entities from the event information of the first threat event [ i.e. display data associated with a particular security incident on a dashboard ] [ Figure 7; and paragraph 0069-0072 ];
determining a first actionable entity from the one or more second entities [ i.e. “Playbook” for a category and/or subcategory of a particular incident, display a html page describing how to resolve incidents ] [ Figure 7; and paragraphs 0081, and 0082 ]; and
displaying, via a third user interface, a plurality of first available security actions associated with the determined first actionable entity to the user to resolve the first threat event [ report may be generated for each security incident to communicate the progress in resolving each security incident ] [ paragraphs 0085, 0093, and 0103 ].
It would have been obvious to person skill in the art before the effective filing date of the claimed invention to combine the teaching of Sharan and Zettel because the teaching of Zettel would enable to provide incident response tools useful for personas with a variety of experience levels [ Zettel, paragraph 0002 ].
As per claim 22, Zettel discloses receiving a second user selection of a second threat event of the plurality of threat events; and in response to the second user selection, displaying, via the second user interface, event information of the second threat event [ i.e. “Phishing” category and/or in a “Scam e-mail activity” sub-category, and enable customizable arrangement of data visualized ] [ paragraphs 0074, and 0082 ] .
As per claim 23, Zettel discloses extracting one or more third entities from the event information of the second threat event; determining a second actionable entity from the one or more third entities [ i.e. “Playbook” for a category and/or subcategory of a particular incident, display a html page describing how to resolve incidents ] [ Figure 7; and paragraphs 0081, and 0082 ]; and displaying, via the third user interface, a plurality of second available security actions associated with the determined second actionable entity to the user to revolve the second threat event [ i.e. resolve the incidents ] [ Figure 3; and paragraphs 0057-0060 ].
As per claim 24, Zettel discloses receiving or retrieving a plurality of tickets associated with the plurality of threat events; ticket information of each ticket of the plurality of tickets comprises at least one of: an identifier of a threat event, a description of the threat event, a date of the threat event, a caller of the threat event, or a priority level of the threat event [ i.e. identification number of each security incident ] [ Figures 3, 6-8; and paragraphs 0058, 0067-0070 ].
8. As per claim 25, Zettel discloses wherein determining the first actionable entity from the one or more second entities comprises determining the first actionable entity from the one or more second entities based on a set of predetermined actionable entities [ i.e. playbook comprising a series of tasks to be implemented for resolution of the security incident ] [ paragraphs 0006, and 0007 ].
9. As per claim 26, Zettel discloses receiving a user selection of a security action from the plurality of first available security actions; and in response to the user selection of the security action, automating a performance of the user selected security action, without the user’s input, to resolve the first threat event [ i.e. automated playbook my provide a fully or partially customizable workflow ] [ paragraphs 0035, and 0091 ].
10. As per claim 27, Zettel discloses wherein the event information of the first threat event comprises at least one of: endpoint information, one or more Internet protocol (IP) addresses, a hostname, or a possible threat actor [ i.e. list of IP address associated with particular incident ] [ paragraph 0098 ].
11. As per claim 28, Zettel discloses wherein the cyber security action relating to the one or more first entities includes a response to a knowledge-seeking or contextual awareness-based question about the one or more first entities [ i.e. question to complete the task ] [ paragraphs 0087, and 0089 ]
12. As per claim 29, Zettel discloses wherein the action relating to the one or more first entities includes an automation-based action for incident response operation [ i.e. “Playbook” widget for guiding a security analyst through a workflow for resolving a particular security incident ] [ Figure 7; and paragraphs 0075, and 0081 ].
13. As per claim 30, Sharan discloses wherein the intent is a knowledge-based intent, a contextual awareness-based intent, or an automation-based intent [ paragraphs 0037, and 0038 ].
14. As per claims 31-40, they are rejected for similar reasons as stated above in claims 21-30.
Response to Arguments
Applicant’s arguments with respect to claim(s) 21-40 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
O’Brien et al. [ US Patent Application No 2020/0394587 ] discloses threat assessment having scorecard
Schwartz et al. [ WO 2019/204129 A1 ] discloses dynamic incident console interfaces
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUSTIN NGUYEN whose telephone number is (571)272-3971. The examiner can normally be reached Monday-Friday 9-6 PST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Gillis can be reached on 571-2727952. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DUSTIN NGUYEN/Primary Examiner, Art Unit 2446