DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Examiner Note
The office action mailed on 10/01/2025 is withdrawn. Upon further consideration of the application, including a 101 rejection, the prosecution is reopened and this Office action is made non-final.
Status of Claims
The following is a Non-Final Office Action in response to applicant’s filing on March 2, 2026. Claims 1, 11 and 20 were amended. Claims 1-20 are pending, of which claims 1, 11 and 20 are in independent form.
Response to Amendment
Applicant’s amendments and arguments regarding the Abstract obviated the objection. Therefore, the Abstract objection is withdrawn.
Applicant’s amendment regarding claims 1, 10, and 11 does not obviate the claim rejection under 35 USC § 112(b). Therefore, the examiner maintains the 112(b) rejection.
Applicant’s amendments and arguments regarding claims 1, 10, and 11 obviate the claim interpretation under 35 USC § 112(f). Therefore, the claim interpretation under 35 USC § 112(f) is withdrawn.
Response to Arguments
Applicant’s arguments with respect to claim(s) are rejected, under 35 USC 103(a), have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter.
Claim Interpretation under 35 U.S.C. 112(f)
On Page 11 of remarks, Applicant’s argument is persuasive and the claim Interpretation under 35 U.S.C. 112(f) is withdrawn.
Rejection under U.S.C. 103
On Pages 20-24 of remarks Applicant argues that “Applicant notes that the cited prior art of record is silent at least in these respects. Specifically, the Office Action relies on Goudal '792 to teach analyzing a synthetic cyberattack in a "mimic network”.
Applicant’s arguments, with respect to the rejection(s) of claim(s) 1, 11 and 20 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Morton et al. (US 2020/0215414 A1).
Therefore, the examiner maintains the rejection under 35 USC § 103.
As to the dependent claims 2-10, and 12-19, these claims remain rejected by virtue of dependency to their independent claims.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-2, and 4-15 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Analysis
Step 1 (Statutory Categories) — 2019 PEG pq. 53
Claims 1-20 are directed to the statutory categories of invention.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 11 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “providing a cyber security training tool to have a natural language processor and a large language model to be able to analyze both i) a synthetic cyberattack … as well as ii) a real cyberattack in the real world network, and then to dynamically generate provide analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat … providing the cyber security training tool with a user interface component to display security awareness training for the synthetic cyberattack and/or the real cyberattack” recite a mental process and/or methods of organizing human activity involving the collection, analysis, and presentation of information.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “a natural language processor,” “a large language model,” “a mimic network comprising … virtual clones,” “a user interface component,” “one or more non-transitory machine readable mediums,” and “one or more processing units,” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 11 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 12 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “providing the cyber security training tool …output a color coded visualization of i) an inducement email with a malicious inducement portion directed to an email user identified ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified.” recite a mental process, i.e., an observation, evaluation, and judgment of information.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool,” and “a large language model,” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, such as “the cyber security training tool,” and “a large language model,” considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 12 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 13 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “providing the cyber security training tool … to analyze malicious emails … provide training to the end user upon detecting the malicious inducements and/or emails impersonating the style of the other email user” recite a mental process and/or methods of organizing human activity involving the collection, analysis, and presentation of information.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “an email inducement text highlighting tool” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 13 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 14 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “providing the email inducement text highlighting tool with a user interface to visualize … portions of an email …, and providing the user interface to explain and display why this email under analysis is malicious ...” recite a mental process and/or methods of organizing human activity involving the reviewing, highlighting those portions, and explaining the reasoning.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “an email inducement text highlighting tool” and “user interface” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 14 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 15 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “… providing the email inducement text highlighting tool with a user interface to provide immediate on the spot feedback on a display screen … on why machine learning believes that this email … is malicious… recite a mental process and/or methods of organizing human activity involving the reasoning and judgment.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “an email inducement text highlighting tool” and “user interface” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 15 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 16 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “providing the cyber security training tool … to understand and transform the machine learning analysis… and log data in their natural formats from the synthetic cyberattack … in order for the end user and/or the cyber security team member to understand the analysis …” recite a mental process and/or methods of organizing human activity involving analyzing the information, transforming, summarizing that information, and presenting it in a human-understandable form with explanation..
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “a large language model” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 16 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 17 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “… use a Large Language Model trained to generate software code that creates data visualizations, … to showcase cyber security breaches, user activity, and current cyber threat trends” recite a mental process and/or methods of analyzing information, organizing that information and presenting it in a visual format.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “a Large Language Model” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 17 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 18 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “… to deduce a level of cyber security sophistication of the end user and/or cyber security team member out of multiple different levels of sophistication, and then tailor training … explaining things to the deduced level …” recite a mental process and/or methods of organizing human activity involving evaluating information about a user, classifying the user into a category, and tailoring information. These steps involve observation, evaluation, judgment and decision making.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool” and “a large language model” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 18 is not patent eligible.
Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54
Claim 19 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental process:
The steps of “… take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email … highlight words and phrases which correspond to different types of inducements” recite a mental process and/or methods of organizing human activity involving revieing, interpreting and classifying. These steps involve observation, evaluation, judgment and decision making.
Accordingly, the claim fails to integrate the abstract idea into a practical application.
Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54
additional elements do not integrate the exception into a practical application. The limitations “the cyber security training tool”, “an email inducement text highlighting tool”, “natural language processor” and “transformer model” are recited at a high level of generality and amount to no more than generic computer implementation. Therefore, under Step 2A, Prong Two, the claim does not integrate the abstract idea into a practical application because the additional elements do not impose any meaningful limit on the judicial exception, do not improve the functioning of a computer or another technology, and merely use generic computing components to perform the abstract idea.
Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56
The additional elements, considered individually and in combination, do not amount to significantly more than the abstract idea because they are well-understood, routine, conventional activities and components.
Accordingly, under Step 2B of the PEG, the claim 19 is not patent eligible.
Claim 1 includes all the limitations of claim 11. Therefore, claim 1 recites the same abstract idea of claim 11. Claim 1 recites the additional limitations “An apparatus…a cyber security training tool … a natural language processor and a large language model”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 2 depends from claim 1 includes all the limitations of claim 12. Therefore, claim 2 recites the same abstract idea of claim 12. Claim 2 recites the additional limitations “An apparatus…a cyber security training tool … a natural language processor and a large language model”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 3 depends from claim 1 includes all the limitations of claim 13. Therefore, claim 3 recites the same abstract idea of claim 13. Claim 3 recites the additional limitations “An apparatus…a cyber security training tool”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 4 depends from claim 1 includes all the limitations of claim 14. Therefore, claim 4 recites the same abstract idea of claim 14. Claim 4 recites the additional limitations “An apparatus…a cyber security training tool”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 5 depends from claim 1 includes all the limitations of claim 15. Therefore, claim 5 recites the same abstract idea of claim 15. Claim 5 recites the additional limitations “An apparatus…a cyber security training tool… an email inducement text highlighting tool”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 6 depends from claim 1 includes all the limitations of claim 16. Therefore, claim 6 recites the same abstract idea of claim 16. Claim 6 recites the additional limitations “An apparatus…a cyber security training tool… a large language model… a data transformation tool”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 7 depends from claim 1 includes all the limitations of claim 17. Therefore, claim 7 recites the same abstract idea of claim 17. Claim 7 recites the additional limitations “An apparatus…a cyber security training tool… a large language model”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 8 depends from claim 1 includes all the limitations of claim 18. Therefore, claim 8 recites the same abstract idea of claim 18. Claim 8 recites the additional limitations “An apparatus…a cyber security training tool… a large language model”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 9 depends from claim 1 includes all the limitations of claim 19. Therefore, claim 9 recites the same abstract idea of claim 19. Claim 9 recites the additional limitations “An apparatus…a cyber security training tool… an email inducement text highlighting tool… a natural language processor … a transformer model”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Claim 20 includes all the limitations of claims 1 and 11. Therefore, claim 20 recites the same abstract idea of claim 1 and 11. Claim 20 recites the additional limitations “A non-transitory storage medium … a processor… a cyber security training tool … a natural language processor … a large language mode”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea.
Therefore, claims 1-20 are rejected under 101 rejection.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 1 recites the limitation “least one or more virtual clones of components corresponding to a real world network”, is vague because it does not specify what degree of correspondence is required to be real world. The claim does not define the criteria by which such correspondence is determined. As a result, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “least one or more virtual clones of components corresponding to a real cyberattack”, is not well bounded. The term “real cyberattack” lacks a clear boundary. It is not specified whether a “real cyberattack” requires an actual malicious event occurring in a live network. The claim does not define the criteria, or characteristics that distinguish a “real cyberattack” from other types of network events. As a result, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “to show the end user and/or the cyber security team member an understanding” renders the claim indefinite because the term “an understanding” is relative by nature and it is not clear as to what level of “understanding” is sufficient. Accordingly, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “a large language model to be able to analyze”, “” renders the claim indefinite because the phrase “to be able” introduces ambiguity as to whether the claim requires a present ability or a future ability, therefore fails to define a definite functional limitation. Accordingly, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “then to dynamically generate”, renders the claim indefinite because it is unclear whether “then” refers to a sequence or a list of functions. Accordingly, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack” renders the claim indefinite because the term “dynamic” is a relative and functional term that fails to provide an objective boundary for the claimed subject matter. It is unclear whether “dynamically” refers to when the generation occurs. Accordingly, the metes and bonds of the claim are not certain and render the claim indefinite.
Claim 1 recites the limitation “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack” renders the claim indefinite because the limitation appears unrelated to the core invention as claimed, which is directed to displaying security awareness training and presenting an understanding of machine learning results via a user interface. Accordingly, the metes and bonds of the claim are not certain and render the claim indefinite.
Independent claims 11 and 20 are similarly rejected. As to dependent claims 2-10, and 12-19, these claims remain rejected by virtue of dependency to their independent claims.
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AlA), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AlA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claims 1, 11 and 20, recite “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack”.
According to MPEP 2161.01, "computer-implemented functional claim language must still be evaluated for sufficient disclosure under the written description". And MPEP 2161.01(I) “generic claim language in the original disclosure does not satisfy the written description requirement if it fails to support the scope of the genus claimed." For computer- implemented inventions, the determination of the sufficiency of disclosure will require an inquiry into the sufficiency of both the disclosed hardware and the disclosed software due to the interrelationship and interdependence of computer hardware and software. The critical inquiry is whether the disclosure of the application relied upon reasonably conveys to those skilled in the art that the inventor had possession of the claimed subject matter as of the filing date.
In the instant application, the disclosure of the application relies on essential matter which fails to convey to those skilled in the art that the inventor had possession of the claimed subject matter as of the filing date. The instant application’s specification fails to provide written description support for the claim limitations of “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack”. The disclosure lacks any description of specific algorithm, or model operations that would enable a system to generate such analysis and explanation in a dynamic manner. Further, the limitation “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack” renders the claim vague because the limitation appears unrelated to the core invention as claimed, which is directed to displaying security awareness training and presenting an understanding of machine learning results via a user interface (i.e., The synthetic cyberattack tool 125 can cooperate with the cyberattack simulator 105, as well as the cloud based war gaming virtual machine platform 60 to autonomously generate the synthetic cyberattack incidents, which are dynamically generated to perform steps of the cyberattack based on a current status of components in the wargaming environment and counter measures taken, as current actual vulnerabilities and known behaviors of the end users at the time the decision for a step in the cyberattack is being made versus some hard coded example pre-programmed scenarios, see paragraph 0029). Thus, the specification fails to provide adequate written description to support the limitation “dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack”.
As to the dependent claims 2-10, and 12-19, these claims remain rejected by virtue of dependency to their independent claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 8, 10-11, 18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Morton et al. (US 2020/0215414 A1), hereinafter Morton in view of GOUTAL et al. (US 2024/0403792 A1), hereinafter GOUTAL.
Regarding claim 1, GOUTAL discloses an apparatus, comprising: a cyber security training tool is configured to have a natural language processor and a large language model to be able to analyze (Morton, Abstract, a mission-based cyber training platform allows both offensive and defensive oriented participants to test their skills in a game-based virtual environment against a live or virtual opponent) and (Morton, Para. 0117, the AI opponent feature uses machine learning and modeling to generate responses and weigh up evidence to add more complex mission scenarios to its internal AI neural network over time),
both i) a synthetic cyberattack in a mimic network comprising at least one or more virtual clones of components corresponding to a real world network as well as (Morton, Para. 0015, the training takes place within the framework of a game environment combining an AI opponent within a realistic virtual environment and hacking simulation) and (Morton, Para. 0016, by capturing essential network elements and components such as topology maps, component lists, host types and configurations, to name a few, extensible virtualized environments can emulate the key aspects of the production networks) and (Morton, Para. 0082, the Cyber Range is a collection of virtualized and/or physical computers, infrastructure (e.g., firewalls, routers), services (e.g., DNS, e-mail, file sharing, mission specific), synthetic users and traffic that represent a real-world system) ii) a real cyberattack in the real world network (Morton, Para. 0017, a specific targeted hardware device such as part of an industrial control system may be required to co-exist with virtual network elements and components to collectively form an extensible virtualized and physical environment that properly emulates a targeted production network) and (Morton, Para. 0082, the Cyber Range is a collection of virtualized and/or physical computers, infrastructure (e.g., firewalls, routers), services (e.g., DNS, e-mail, file sharing, mission specific), synthetic users and traffic that represent a real-world system, such as a business, military agency or base with sufficient detail to support cyber training, test or evaluation), and
Morton does not explicitly disclose then to dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of i) an end user of the real world network and ii) a cyber security team member for the real world network,
where the cyber security training tool further has a user interface component configured to display security awareness training for the synthetic cyberattack and/or the real cyberattack, and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component; and
where instructions for the cyber security training tool are configured to be stored in one or more non-transitory machine readable mediums to be executed by one or more processing units.
However, GOUTAL teaches then to dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of (GOUTAL, Para. 0035, the prompt template 604 shown in FIG. 7 may be used to generate a training sample of business email compromise (BEC) known as ‘CEO fraud’, where the attacker impersonates the CEO of an organization and instructs an accountant to perform a wire transfer to a fraudulent bank account-pretexting for instance an urgent outstanding invoice from a supplier) i) an end user of the real world network (GOUTAL, Para. 0021, training of an employee of an organization using the training sample generated by a security awareness training samples generator according to an embodiment)(GOUTAL, Para. 0049) and ii) a cyber security team member for the real world network (GOUTAL, Para. 0049, the training samples may then be used to educate the user (in this case, a William Smith) against, in this example, the specific risk of CEO fraud. As shown in FIG. 19, William Smith may be invited to view and evaluate this training sample and to provide feedback by clicking the ‘Legitimate’ or ‘Suspicious’ buttons, depending upon whether William Smith believes the training sample to be a legitimate request from the company's CEO John Doe),
where the cyber security training tool further has a user interface component configured to display security awareness training for the synthetic cyberattack and/or the real cyberattack (GOUTAL, Para. 0044, the communication with the large language model may be carried out through an API (Application Programming Interface). The large language model 210 processes the prompt, and then returns the text it has generated responsive to the submission of the specialized large language model prompt S604. An example of text generated and returned by the large language model 210 is shown in FIG. 16 at 162. Note that the generated text 162 mimics the writing style of the sample text provided), and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component (GOUTAL, Para. 0051, for instance, the CEO fraud training sample may be sent directly to the user inbox, without informing the recipient that the received email constitutes part of a training exercise. If the user fails to identify the email as suspicious and does not carry out the expected action (such as reporting the email to an administrator of the organization), then an explanation similar to that shown in FIG. 20 may be provided to educate the user against the risk of CEO fraud and similar scams); and
where instructions for the cyber security training tool are configured to be stored in one or more non-transitory machine readable mediums to be executed by one or more processing units (GOUTAL, Para. 0047, as shown, the generated electronic message (in this case, a CEO fraud email shown FIG. 17) includes both the specialized electronic message template S606 as well as the text 162 generated by the large language model 210 responsive to receipt of the specialized prompt template S604 and received by the security awareness training samples generator 202. The generated electronic message or messages or training samples (an exemplar of which is shown in FIG. 17) may then be stored in the training samples database 212, as shown at B188).
Morton and GOUTAL, both considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack.
Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton to incorporate the teaching of GOUTAL to include then to dynamically generate analysis and an explanation as to why machine learning identified the synthetic cyberattack and/or the real cyberattack as a cyber threat for a purpose of providing cyber security training to at least one of (GOUTAL, Para. 0035) i) an end user of the real world network (GOUTAL, Para. 0021) and (GOUTAL, Para. 0049) and ii) a cyber security team member for the real world network (GOUTAL, Para. 0049),
where the cyber security training tool further has a user interface component configured to display security awareness training for the synthetic cyberattack and/or the real cyberattack (GOUTAL, Para. 0044), and to show the end user and/or the cyber security team member an understanding of the machine learning of the synthetic cyberattack and/or the real cyberattack displayed in the user interface component (GOUTAL, Para. 0051); and
where instructions for the cyber security training tool are configured to be stored in one or more non-transitory machine readable mediums to be executed by one or more processing units (GOUTAL, Para. 0047). Doing so would aid the large language models to be leveraged to generate security awareness training content that can be used to educate stakeholders of the organization (such as employees, but also actors up and down the organization's supply chain such as customers, suppliers, and partners of the organization) against the risk of cyberattacks (GOUTAL, Para. 0025).
Regarding claim 8, the combination of Morton in view of GOUTAL teaches the apparatus of claim 1, where the cyber security training tool is configured to use the large language model trained to deduce a level of cyber security sophistication of the end user and/or cyber security team member out of multiple different levels of sophistication, and then tailor training and a way that the cyber security training tool is explaining things to the deduced level of sophistication of the end user or the cyber security team member (GOUTAL, Para. 0025, however, these large language models may also be leveraged to generate security awareness training content that can be used to educate stakeholders of the organization (such as employees, but also actors up and down the organization's supply chain such as customers, suppliers, and partners of the organization) against the risk of cyberattacks. Indeed, with the increasing sophistication of targeted cyberattacks and the inherent limits of security technology, security awareness training has been playing a major role in hardening organizations against cyberattacks, where people are the last line of defense). Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton to incorporate the teaching of GOUTAL to include the apparatus of claim 1, where the cyber security training tool is configured to use the large language model trained to deduce a level of cyber security sophistication of the end user and/or cyber security team member out of multiple different levels of sophistication, and then tailor training and a way that the cyber security training tool is explaining things to the deduced level of sophistication of the end user or the cyber security team member (GOUTAL, Para. 0025). Doing so would aid the large language models to be leveraged to generate security awareness training content that can be used to educate stakeholders of the organization (such as employees, but also actors up and down the organization's supply chain such as customers, suppliers, and partners of the organization) against the risk of cyberattacks (GOUTAL, Para. 0025).
Regarding claim 10, the combination of Morton in view of GOUTAL teaches the apparatus of claim 1, where the cyber security training tool is configured to have an add-in extension configured to be installed in a software application, where the software application is at least one of i) an email application, ii) a cyber security application, and iii) a browser application such that the end user can activate the add-in extension to query whether something is malicious and then have the user interface display what the understanding of the machine learning considered malicious or not malicious (GOUTAL, Paras. 0039-0041, according to one embodiment, a first type of action may include adding one or more extended headers to the email to indicate and to alert the email recipient that the textual content of the received email contains synthetic text. Extended headers are non-standard headers that are used to store additional information regarding the email. Extended headers are used by email filtering technologies to store the result of the analysis. Let's consider the example of FIG. 10 where the textual content is detected as being synthetic text generated by GPT-4 with a confidence score of 0.967 (where confidence scores closer to 1 indicate strong probability that the received email contains synthetic text and where confidence scores closer to 0 indicate a weak probability that the received email contains synthetic text). In this case, the following extended headers may be added to the email: X-SyntheticEmail-Status: synthetic X-SyntheticEmail-Detection: model=GPT-4; score=0.967). Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton to incorporate the teaching of GOUTAL to include where the cyber security training tool is configured to have an add-in extension configured to be installed in a software application, where the software application is at least one of i) an email application, ii) a cyber security application, and iii) a browser application such that the end user can activate the add-in extension to query whether something is malicious and then have the user interface display what the understanding of the machine learning considered malicious or not malicious (GOUTAL, Paras. 0039-0041). Doing so would aid the large language models to be leveraged to generate security awareness training content that can be used to educate stakeholders of the organization (such as employees, but also actors up and down the organization's supply chain such as customers, suppliers, and partners of the organization) against the risk of cyberattacks (GOUTAL, Para. 0025).
In regard to claim 11, the method of claim 11 relates to the apparatus claim 1. Therefore, claim 11 is rejected for the same reason.
In regard to claim 18, the method of claim 18 relates to the apparatus claim 8. Therefore, claim 18 is rejected for the same reason.
In regard to claim 20, the non-transitory storage medium of claim 20 relates to the apparatus claim 1 and the method claim 11. Therefore, claim 20 is rejected for the same reason.
Claims 2-6, 9, 12-16, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Morton et al. (US 2020/0215414 A1), hereinafter Morton in view of GOUTAL et al. (US 2024/0403792 A1), hereinafter GOUTAL, and further in view of Goutal et al. (US 2024/0354403 A1), hereinafter Goutal.
Regarding claim 2, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to use the large language model, which is trained to output a color coded visualization of i) an inducement email with a malicious inducement portion directed to an email user identified ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified, or iii) a combination of both i) and ii).
However, Goutal (US 2024/0354403 A1) teaches where the cyber security training tool is configured to use the large language model, which is trained to output a color coded visualization (Goutal (US 2024/0354403 A1), Para. 0060, several large language models that generated the synthetic textual content; an indication of one or more synthetic text detection scores; an indication of one or more score thresholds, and/or an indication of whether the synthetic textual content was detected using a watermark-based method or a classifier-based method. In addition, the performed action, according to embodiments, may further include highlighting the detected textual content in the received email; highlighting any watermarks found in the detected synthetic textual content)of i) an inducement email with a malicious inducement portion directed to an email user identified (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046, the first two paragraphs were detected as being synthetic and are highlighted, while the third paragraph was not detected as being synthetic and was left as is) ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified (Goutal (US 2024/0354403 A1), Para. 0022, if an email is detected as being spam, phishing, or malware, then the MTA may delete the email, or alternatively move it to a specific folder), or iii) a combination of both i) and ii).
Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to use the large language model, which is trained to output a color coded visualization (Goutal (US 2024/0354403 A1), Para. 0060 )of i) an inducement email with a malicious inducement portion directed to an email user identified (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046) ii) a phishing email impersonating a style of another email user with differences from the style of the other email user identified (Goutal (US 2024/0354403 A1), Para. 0022). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
Regarding claim 3, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool to analyze malicious emails based upon historical information about one or more malicious inducements as well as one or more phishing emails impersonating a style of another email user in order to provide training to the end user upon detecting the one or more malicious inducements and/or emails impersonating the style of the other email user.
However, Goutal (US 2024/0354403 A1) teaches where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool to analyze malicious emails based upon historical information about one or more malicious inducements as well as one or more phishing emails impersonating a style of another email user in order to provide training to the end user upon detecting the one or more malicious inducements and/or emails impersonating the style of the other email user (Goutal (US 2024/0354403 A1), Para. 0034, the synthetic email detection engine 502 may then determine the size of the extracted textual content and compare the determined size to a configured size threshold) and (Goutal (US 2024/0354403 A1), Para. 0038, as shown at B620, if at least one score is greater than or equal to the associated configured score threshold, then the synthetic email detection engine may carry out, or may cause to be carried out, one or several actions to indicate or otherwise alert the recipient that the email contains synthetic text. There are different types of actions, and the list of actions performed may be configured at will). Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool to analyze malicious emails based upon historical information about one or more malicious inducements as well as one or more phishing emails impersonating a style of another email user in order to provide training to the end user upon detecting the one or more malicious inducements and/or emails impersonating the style of the other email user (Goutal (US 2024/0354403 A1), Para. 0034) and (Goutal (US 2024/0354403 A1), Para. 0038). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
Regarding claim 4, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to visualize through highlighting identified malicious portions of an email under analysis for a purpose of providing training to the end user, where the user interface is configured to explain and display why this email under analysis is malicious because the email under analysis is attempting to induce the end user to do a harmful act.
However, Goutal (US 2024/0354403 A1) teaches the apparatus of claim 1, where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to visualize through highlighting identified malicious portions of an email under analysis for a purpose of providing training to the end user (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046, the first two paragraphs were detected as being synthetic and are highlighted, while the third paragraph was not detected as being synthetic and was left as is), where the user interface is configured to explain and display why this email under analysis is malicious because the email under analysis is attempting to induce the end user to do a harmful act (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046). Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to visualize through highlighting identified malicious portions of an email under analysis for a purpose of providing training to the end user (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046), where the user interface is configured to explain and display why this email under analysis is malicious because the email under analysis is attempting to induce the end user to do a harmful act (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
Regarding claim 5, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to provide immediate on the spot feedback on a display screen to the end user during their routine work activity within a software application that the end user is using on why machine learning believes that this email, under analysis, is malicious versus generating a long form written and printed report days later on why the machine learning believes that this email, under analysis, is malicious.
However, Goutal teaches where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to provide immediate on the spot feedback on a display screen to the end user during their routine work activity within a software application that the end user is using on why machine learning believes that this email, under analysis, is malicious versus generating a long form written and printed report days later on why the machine learning believes that this email, under analysis, is malicious (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046, the first two paragraphs were detected as being synthetic).
Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a user interface to provide immediate on the spot feedback on a display screen to the end user during their routine work activity within a software application that the end user is using on why machine learning believes that this email, under analysis, is malicious versus generating a long form written and printed report days later on why the machine learning believes that this email, under analysis, is malicious (Goutal (US 2024/0354403 A1), Fig. 11, Paras. 0045-0046). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
Regarding claim 6, the combination of Morton in view of GOUTAL teaches the apparatus of claim 1, and ii) apply natural language processing in order to turn data about the machine learning analysis (GOUTAL, Para. 0016) and (GOUTAL, Paras. [0028]-[0030]), the model breaches, and the log data from the synthetic cyberattack into information in a natural language format in order for the end user (GOUTAL, Para. 0032) and/or the cyber security team member to understand the analysis and the explanation as to why the machine learning identified the synthetic cyberattack and/or the real cyberattack as the cyber threat in order to train the end user (GOUTAL, Para. 0001) and (GOUTAL, Para, 0003) and/or the cyber security team member (GOUTAL, Paras [0034]-[0036]).
The combination of Morton in view of GOUTAL does not explicitly teach where the cyber security training tool is configured to use a large language model trained as i) a data transformation tool to understand and transform the machine learning analysis, model breaches, and log data in their natural formats from the synthetic cyberattack.
However, Goutal (US 2024/0354403 A1) teaches where the cyber security training tool is configured to use a large language model trained as i) a data transformation tool to understand and transform the machine learning analysis, model breaches, and log data in their natural formats from the synthetic cyberattack (Goutal (US 2024/0354403 A1), Para. 0056, the input signals may be either inline input signals (e.g., real time-based information) of offline input signals (e.g., information regarding trends or patterns over time). The input signals may be correlated into a common data repository or set of repositories and can correspond to tiered or processed data provided by multiple third-party service providers. For example, input signals can correspond to log files, performance metrics, alarms, notifications, memory contents, and the like. As will be described in detail below, one or more aspects of the present application can correspond to feedback or configuration of the input signals by the network service 110),
Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to use a large language model trained as i) a data transformation tool to understand and transform the machine learning analysis, model breaches, and log data in their natural formats from the synthetic cyberattack (Goutal (US 2024/0354403 A1), Para. 0056). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
Regarding claim 9, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a natural language processor and a transformer model trained on different types of malicious inducements, where the natural language processor is configured to take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email, under analysis, and then for the email inducement text highlighting tool to highlight words and phrases which correspond to different types of malicious inducements.
However, Goutal (US 2024/0354403 A1) teaches where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a natural language processor and a transformer model trained on different types of malicious inducements, where the natural language processor is configured to take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email, under analysis, and then for the email inducement text highlighting tool to highlight words and phrases which correspond to different types of malicious inducements (Goutal (US 2024/0354403 A1), Fig. 10, Para. 0043, the ‘Subject’ header may be prefixed with ‘[Synthetic]’. The ‘Subject’ header is then transformed into: Subject: [Synthetic] Outstanding invoice) and (Goutal (US 2024/0354403 A1), Fig. 10, Para. 0048, the email in which synthetic textual content has been detected may be moved to a folder named ‘Synthetic’. The email may also be moved to ‘Spam’ or ‘Junk’ folder).
Morton, GOUTAL and Goutal (US 2024/0354403 A1) are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of Goutal (US 2024/0354403 A1) to include where the cyber security training tool is configured to cooperate with an email inducement text highlighting tool, where the email inducement text highlighting tool has a natural language processor and a transformer model trained on different types of malicious inducements, where the natural language processor is configured to take in text and a structure of the fields of an email to understand the text in the email, and feed them to the transformer model to understand an intent of the text in the email, under analysis, and then for the email inducement text highlighting tool to highlight words and phrases which correspond to different types of malicious inducements (Goutal (US 2024/0354403 A1), Fig. 10, Para. 0043, the ‘Subject’ header may be prefixed with ‘[Synthetic]’. The ‘Subject’ header is then transformed into: Subject: [Synthetic] Outstanding invoice) and (Goutal (US 2024/0354403 A1), Fig. 10, Para. 0048). Doing so would aid to improve the functioning of computers by enabling the detection of synthetic text in emails received by individuals, enterprises and other organizations. Such computer-implemented methods are not capable of being effectively carried out by the mental processes of humans (Goutal (US 2024/0354403 A1), Para. 0063).
In regard to claim 12, the method of claim 12 relates to the apparatus claim 2. Therefore, claim 12 is rejected for the same reason.
In regard to claim 13, the method of claim 13 relates to the apparatus claim 3. Therefore, claim 13 is rejected for the same reason.
In regard to claim 14, the method of claim 14 relates to the apparatus claim 4. Therefore, claim 14 is rejected for the same reason.
In regard to claim 15, the method of claim 15 relates to the apparatus claim 5. Therefore, claim 15 is rejected for the same reason.
In regard to claim 16, the method of claim 16 relates to the apparatus claim 6. Therefore, claim 16 is rejected for the same reason.
In regard to claim 19, the method of claim 19 relates to the apparatus claim 9. Therefore, claim 19 is rejected for the same reason.
Claims 7, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Morton et al. (US 2020/0215414 A1), hereinafter Morton in view of GOUTAL et al. (US 2024/0403792 A1), hereinafter GOUTAL, and further in view of BETTHAUSER et al. (US 2024/0370570 A1), hereinafter BETTHAUSER.
Regarding claim 7, the combination of Morton in view of GOUTAL does not explicitly teach the apparatus of claim 1, where the cyber security training tool is configured to use a large language model trained to generate software code that creates data visualizations, including at least one of a graph and a chart, to showcase cyber security breaches, user activity, and current cyber threat trends.
However, BETTHAUSER teaches where the cyber security training tool is configured to use a large language model trained to generate software code that creates data visualizations, including at least one of a graph and a chart, to showcase cyber security breaches, user activity, and current cyber threat trends (BETTHAUSER, Para. 0049, each log line may be processed by a large language model to generate an embedding. Each embedding may be treated as a vertex in the graph 302, such that each vertex exists in an N-dimensional space, where N is the number of elements of the embedding vectors) and (BETTHAUSER, Para. 0050, graphs 300 are labeled based on a classification criteria 520 that was associated with raw input 102. In a security context, classification criteria may indicate if the log line is deemed suspicious. Suspiciousness may be based on a manual evaluation of the log line, alone or in the context of the entire log, e.g., as part of a post-mortem analysis of a security breach. For example, a log line may be deemed suspicious if a destination IP address is to an area known for phishing attacks. Log lines may also be deemed suspicious based on repetition of operations such as password changes, file access, privilege escalation, or other sensitive operations. Log lines may also be deemed suspicious based on an automated analysis).
Morton, GOUTAL and BETTHAUSER are all considered to be analogous to the claimed invention because they are in the same field of Cyber-attack training tool to train a user interface component and to demonstrate security awareness training for a synthetic cyberattack and a real cyberattack. Therefore, it would have been obvious to someone of ordinary skill in the art before the effective filling date of the claimed invention to have modified Morton and GOUTAL to incorporate the teaching of BETTHAUSER to include where the cyber security training tool is configured to use a large language model trained to generate software code that creates data visualizations, including at least one of a graph and a chart, to showcase cyber security breaches, user activity, and current cyber threat trends (BETTHAUSER, Para. 0049) and (BETTHAUSER, Para. 0050). Doing so would aid users can quickly and cheaply iterate over different graph topologies and bootstrap signal from existing encoder models. This enables the resolution of the analysis to be changed from the level of individual embeddings to the level of entire raw inputs. The downstream model is typically a much smaller model than the encoder model, and so adjusting the graph topology or retraining the downstream model is faster and cheaper than re-training the encoder model. Iterating over different graph topologies and/or downstream models leverages large encoder models that have processed a vast amount of data (BETTHAUSER, Para. 0018).
In regard to claim 17, the method of claim 17 relates to the apparatus claim 7. Therefore, claim 17 is rejected for the same reason.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GITA FARAMARZI/Examiner, Art Unit 2496
/JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496