Prosecution Insights
Last updated: September 17, 2026
Application No. 18/691,920

A TOP-DOWN CYBER SECURITY SYSTEM AND METHOD

Final Rejection §102§103
Filed
Mar 14, 2024
Priority
Sep 14, 2021 — provisional 63/243,751 +1 more
Examiner
HUANG, CHENG-FENG
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Cytwist Ltd.
OA Round
2 (Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
427 granted / 487 resolved
+29.7% vs TC avg
Strong +16% interview lift
Without
With
+16.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
20 currently pending
Career history
507
Total Applications
across all art units

Statute-Specific Performance

§101
16.7%
-23.3% vs TC avg
§103
58.1%
+18.1% vs TC avg
§102
3.8%
-36.2% vs TC avg
§112
10.5%
-29.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 487 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This is a reply to the amendment filed on 05/04/2026, in which, claim(s) 1-2, 4-10, 14-15, 17, 19-23 and 27 are pending. Claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 are amended. Claim(s) 3, 11-13, 16, 18, and 24-26 are cancelled. No claim(s) are newly added. Response to Arguments Specification Objection: Applicant’s arguments with respect to specification objection have been considered. The specification objection has been withdrawn in view of the amendment to the specification (the abstract). Claim Objection: Applicant’s arguments with respect to objection of claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 have been considered. The objection of claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 have been withdrawn in view of the amendment to claim. Double Patenting (DP): Applicant submitted an eTD on 05/04/2026 to overcome DP rejection issued in the previous office action. The eTD has been approved. The DP rejection issued in the previous action has been withdrawn. Claim Rejections - 35 U.S.C. § 102 and 35 U.S.C. § 103: Applicant’s arguments with respect to the rejection of claim(s) 1-2, 4-10, 14-15, 17, 19-23 and 27 have been considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1-2, 4-10, 14-15, 17, 19-23 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Ben Ezra et al. (US 2018/0069876 A1) in view of Sebastien Meriot (US 2020/0007575 A1) further in view of Sonnenberg (US 2016/0261615 A1). Regarding Claims 1, 14, and 27, Ben Ezra discloses obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, each of the cyber tactics being associated with one or more respective cyber techniques which are possible manifestations of the corresponding cyber tactic in the context of the attack-vector scenario ([0009], “a DDoS burst attack is a sequence of high traffic volumes communicated in bursts. A sequence of actions would include intermittent bursts of attack traffic and then pauses. As another example, a sequence of actions can begin with information gathering, continue with lateral movement, and end in data exfiltration”) , at least one cyber technique is associated with at least one sequence of events that can execute on one or more processors of at least one entity of a plurality of entities of an organizational network, wherein execution of the at least one sequence of events indicates implementation of the respective cyber technique, and (b) information about actual sequences of events that executed on the one or more processors ([0053], “at S320, every pair of event sequences in the list of sequences are compared to each other to identify patterns having similar behavior. In an embodiment, S320 includes listing, for each sequence, its fixed and step features (Ffixed and Fstep); comparing each fixed feature (Ffixed) of one sequence to Fstep of another sequence; identifying patterns of similar steps (based on the Ffixed and Fstep)”); identify, based on the information, the cyber techniques that occurred on the organizational network by matching the actual sequences of events with the at least one sequence of events associated with the cyber techniques, giving rise to implemented cyber techniques ([0059-0061], “At S520, the new event is matched to any event sequence created during the learning process in order to update any such sequence. In an embodiment, S520 can be performed using the sequencing process described in FIG. 4”, “At S530, any updated sequences of events, new sequences of events, or a combination thereof, created in response to the matching performed at S520 is compared to the identified attack patterns”); and alert a user of the cyber security system of a potential cyber-attack upon determining that each of the cyber tactics forming the attack vector scenario, is associated with at least one of the implemented cyber techniques ([0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated”), Ben Ezra does not explicitly teach but Meriot teaches sequences of events are sequences of machine language instructions ([0028], “locating a predetermined machine language instruction sequence in the malware”); Ben Ezra and Meriot are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Meriot with the disclosure of Ben Ezra. The motivation/suggestion would have been for defending an infrastructure against a distributed denial of service (DDoS) attack (Meriot, [0030]). The combined teaching of Ben Ezra and Meriot does not explicitly teach but Sonnenberg teaches wherein the information about the actual sequences of machine language instructions is obtained by a trapping mechanism, capable of retrieving machine language instructions from an instruction unit, storing fetched machine learning instruction for at least one processor of the processors (Sonnenberg, [0050], “The NLEDM 512 is comprised of machine or instruction level event trapping algorithms that detect low-level attacks intended to directly disrupt the operations of the network node 102. As such, the event trapping algorithms described herein will advantageously be designed to detect low-level attacks (including code injection attacks) which interrupt or interfere with the machine code or machine language instructions which execute on processor 306”), Ben Ezra, Meriot and Sonnenberg are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sonnenberg with the combined teaching of Ben Ezra and Meriot. The motivation/suggestion would have been for defending a communication network by using a distributed infrastructure that leverages coordination across disparate abstraction levels (Sonnenberg, Abstract). Regarding Claims 2, and 15, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein alerting the user of the potential cyber-attack is upon further determining that a causality connection exists between one or more of the implemented cyber techniques associated with each given cyber tactic of the cyber tactics and one or more of the implemented cyber techniques associated with a subsequent cyber tactic subsequent to the given cyber tactic (Ben Ezra, [0010], “analyze connections of events across different devices”, [0030], “an attack prediction system 150 is also communicatively connected to the network 120 and configured to perform the various disclosed embodiments for predictive cyber-attack detection”). Regarding Claims 4, and 17, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein: (a) at least one machine language instruction of the sequence of machine language instructions comprises one or more first opcodes, and (b) the identification of the implemented cyber techniques is based on matching the opcodes comprised in the actual sequences of machine language instructions with second opcodes comprised in the at least one sequence of machine language instructions (Meriot, [0092], “the ciphering key is automatically recuperated by searching for a predetermined operation code sequence that is indicative of a ciphering routine used in the malware. This opcode sequence may contain other operation codes besides PUSH and MOV. As a non-limiting example, FIG. 7 is an illustration of a routine used by the malware MIRAI to encrypt character chains. A On FIG. 7, a routine 500 defines a value 510 labelled “table_key”. The table_key 510 is placed in variables k1, k2, k3 and k4 using SHIFT operation codes. A SHIFT 24 operation code 520 actually shifts the table_key 510 by 24 bits into variable k4. While SHIFT operations by 8 or 16 bits are not uncommon, the SHIFT 24 operation code 520 is an infrequently (or rarely) used operation code and provides a clue to the reverse engineering process of the location of the ciphering key. Otherwise stated, the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”). Regarding Claim 5, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein the at least one sequence of machine language instructions is at least a partial translation of code realizing the corresponding cyber technique into machine langue instructions (Meriot, [0092], “This opcode sequence may contain other operation codes besides PUSH and MOV. As a non-limiting example, FIG. 7 is an illustration of a routine used by the malware MIRAI to encrypt character chains. A On FIG. 7, a routine 500 defines a value 510 labelled “table_key”. The table_key 510 is placed in variables k1, k2, k3 and k4 using SHIFT operation codes. A SHIFT 24 operation code 520 actually shifts the table_key 510 by 24 bits into variable k4. While SHIFT operations by 8 or 16 bits are not uncommon, the SHIFT 24 operation code 520 is an infrequently (or rarely) used operation code and provides a clue to the reverse engineering process of the location of the ciphering key. Otherwise stated, the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”). Regarding Claims 6, and 19, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein the at least one sequence of machine language instructions includes one or more suspicious machine langue instructions, being machine learning instructions being a translation of suspicious code (Meriot, [0098], “the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”). Regarding Claims 7, and 20, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein: (a) at least one cyber technique is associated with a corresponding event type of a plurality of event types that occur on the one or more entities of the organizational network, wherein occurrence of an actual event of the respective event type indicates implementation of the respective cyber technique, (b) the information further includes actual events that occurred on the one or more entities of the organizational network, wherein each of the actual events is associated with a respective actual event type, and (c) the identification of the implemented cyber techniques is further based on matching the actual event types with the event types associated with the cyber techniques, giving rise to implemented cyber techniques (Ben Ezra, [0009], “a DDoS burst attack is a sequence of high traffic volumes communicated in bursts. A sequence of actions would include intermittent bursts of attack traffic and then pauses. As another example, a sequence of actions can begin with information gathering, continue with lateral movement, and end in data exfiltration”, [0053], “at S320, every pair of event sequences in the list of sequences are compared to each other to identify patterns having similar behavior. In an embodiment, S320 includes listing, for each sequence, its fixed and step features (Ffixed and Fstep); comparing each fixed feature (Ffixed) of one sequence to Fstep of another sequence; identifying patterns of similar steps (based on the Ffixed and Fstep)”). Regarding Claims 8, and 21, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein the information is obtained periodically or continuously and wherein the identify and the alert are performed periodically or continuously while maintaining previously identified implemented cyber techniques (Ben Ezra, [0015], “periodically receiving new security events”, [0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated” periodically or continuously). Regarding Claims 9, and 22, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches predict, based on: (a) the attack-vector scenario, (b) the implemented cyber techniques, and (c) the previously identified implemented cyber techniques, a next step cyber tactic of the cyber tactics; and perform a prevention action to prevent the next step cyber tactic (Ben Ezra, [0030], “an attack prediction system 150 is also communicatively connected to the network 120 and configured to perform the various disclosed embodiments for predictive cyber-attack detection. Specifically, the attack prediction system 150 is configured to analyze events to generate sequences of events”, [0062]). Regarding Claims 10, and 23, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches wherein the prevention action is one or more of: (a) report the next step cyber tactic to the user of the cyber security system, (b) simulate the next step cyber tactic, or (c) implement one or more honeypots within one or more entities of the organizational network wherein events associated with the next step cyber tactic occurrence (Ben Ezra, [0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated; otherwise, execution terminates. Alternatively, or collectively, S560 may include activating one more mitigation actions”). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHENG-FENG HUANG whose telephone number is (571)272-6186. The examiner can normally be reached Monday-Friday: 9 am - 5 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHENG-FENG HUANG/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Mar 14, 2024
Application Filed
Nov 04, 2025
Non-Final Rejection mailed — §102, §103
May 04, 2026
Response Filed
Jul 30, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737442
SYSTEM AND METHOD FOR CREATING AND MANAGING INTERACTIVE TRANSACTION FRAMEWORKS
1y 7m to grant Granted Sep 15, 2026
Patent 12732528
SYSTEMS AND METHODS FOR IMPROVED CYBERSECURITY NAMED-ENTITY-RECOGNITION CONSIDERING SEMANTIC SIMILARITY
2y 1m to grant Granted Sep 08, 2026
Patent 12726527
CUSTOMIZABLE CERTIFICATE VALIDATION POLICY
2y 5m to grant Granted Sep 01, 2026
Patent 12719932
SELF-ADJUSTING CYBERSECURITY ANALYSIS WITH NETWORK MAPPING
2y 3m to grant Granted Aug 25, 2026
Patent 12719933
PARAMETRIC ANALYSIS OF INTEGRATED OPERATIONAL AND INFORMATION TECHNOLOGY SYSTEMS
2y 0m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+16.4%)
2y 5m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 487 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month