DETAILED ACTION
713.09 Interviews Between Final Rejection and Notice of Appeal [R-08.2017]
Normally, one interview after final rejection is permitted in order to place the application in condition for allowance or to resolve issues prior to appeal. However, prior to the interview, the intended purpose and content of the interview should be presented briefly, preferably in writing. Such an interview may be granted if the examiner is convinced that disposal or clarification for appeal may be accomplished with only nominal further consideration. Interviews merely to restate arguments of record or to discuss new limitations which would require more than nominal reconsideration or new search should be denied. See MPEP § 714.13.
Interviews may be held after the expiration of the shortened statutory period and prior to the maximum permitted statutory period of 6 months without an extension of time. See MPEP § 706.07(f).
A second or further interview after a final rejection may be held if the examiner is convinced that it will expedite the issues for appeal or disposal of the application.
For interviews after notice of appeal, see MPEP § 1204.03.
Interview time will be revised to a limit of 1 hour per new application or RCE (utility)/CPA (design), when during prosecution, the examiner conducts an interview. When more than one interview is needed in an application supervisors will have the flexibility to approve additional time and ensure that the interviews are being used to advance prosecution.
Authorization for Internet Communications
The examiner encourages Applicant to submit an authorization to communicate with the examiner via the Internet by making the following statement (from MPEP 502.03):
“Recognizing that Internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.”
Please note that the above statement can only be submitted via Central Fax (not Examiner's Fax), Regular postal mail, or EFS Web using PTO/SB/439.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
In response to claims amendment, in view of the Remarks filed 03/31/2026, the claim objections have been withdrawn.
In response to the claims amendment, in view of the Remarks, the 112 rejection have been withdrawn.
In response to the claims amendment, in view of the Remarks, the 101 rejection have been withdrawn.
Claim Objections
Claim 6 is objected to because of the following informalities:
Regarding claim 6; there appears to be a typographical error “according claim 1” of -- according to claim 1 --.
Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1 – 2, 5, 7 – 8, 11, 13 – 14 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Cotton et al., (US 2015/0237063 A1), (hereinafter “Cotton”) in view of Sudia et al., (US 2002/0029337 A1) (hereinafter “Sudia”).
Regarding claim 1, Cotton discloses; a determination system [i.e., (see figures 1 and 19)] comprising:
at least one memory storing a set of instructions [i.e., non-transitory computer-readable media include instructions (page 1, para 0012)]; and
at least one processor configured to execute the set of instructions to [i.e., a processor execute instructions to perform method (page 1, para 0012)]:
receive (i) a first inspection result that is a result of a first inspection of vulnerability of target software [i.e., results of the SAST assessment are stored…SAST assessment results which may include security vulnerabilities for the assessed application (page 9, para 0107), (see ref. 1904 of figure 19), (page 10, para 0117)];
receive a second inspection result [i.e., imported network vulnerability assessment (page 9, para 0104), (see ref. 1902 of figure 19), (page 10, para 0117)] that is a result of a second inspection of vulnerability of the target software [i.e., associates the SAST assess application with the application discovered by the network vulnerability assessment (page 9, para 0110) i.e., loading instrumented software onto the network host and performing the network vulnerability scan on that same software application (page 1, para 0010)], wherein the first inspection is performed by the first inspection agency [i.e., SAST systems allow a user to upload a software application that they want to assessed into the SAST provider system (see ref. 1701 of figure 17), (page 9, para 0107)], and the second inspection is performed by a second inspection agency different from the first inspection agency [i.e., third-party network vulnerability assessment scanners (page 9, para 0104)];
determine validity of the first inspection from undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability] that is vulnerability detected in the result of the second inspection and not detected in the result of the first inspection [i.e., retrieves vulnerabilities from the network vulnerability assessment and also retrieves the SAST assessment weakness from the SAST assessment result and determines whether the weakness identifies are present in both result sets. Common findings are added to a common list (see ref. 1902 - 1910 of figure 19), (page 10, para 0117 and 0113)]; and
output [i.e., renders vulnerability assessment reports…allow users to view results…allows users to obtain scan reports (page 2, para 0037)] (i) a result of determination of the validity [Note; determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment], (ii) the vulnerability detected by the first inspection [i.e., SAST_Discovered_vulnerability, vulnerability dictionary and mapping table (see figure 18)], and (iii) the vulnerability detected by the second inspection [i.e., Machine_Discovered_Vulnerability (see figure 18) Note: corresponds to vulnerabilities from the network assessment], to be displayed and stored in a destination device [i.e., scanner engine 404 reads data that is stored within these four data tables and serializes data into an output file…once the file has been serialized, Scanner Engine 404 signal Platform Messaging Gateway 402 to send the results to NSOC 100 (page 5, para 0063), (see figure 4) i.e., store selected match list results in DB (see ref. 1403 of figure 14), (page 8, para 0091)].
Cotton does not disclose;
(ii) an electronic signature of the first inspection result that is generated by encrypting a hash value of the first inspection result using a private key from a first inspection agency.
However, Sudia discloses;
(ii) an electronic signature that is generated by encrypting a hash value of the first result using a private key from a first agency [i.e., to sign a message, the message is first digested (hashed) into a single block 22 using a one-way hash function 21…the digest is then encrypted with the user’s private key, and the result is appended to the message as its signature (page 1, para 0009), (see figure 2) i.e., the signer’s organizational sponsor (page 5, para 0072 - 0073)].
Before the effective filing date of the claimed invention, it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton by adapting the teachings of Sudia so that a receiving system can verify the origin and integrity of the report (See Sudia; page 5, para 0073).
Regarding claim 2, Cotton discloses; the determination system according to claim 1, wherein the at least one processor is further configured to execute the instructions to determine the validity from a count of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Regarding claim 5, Cotton discloses; the determination system according claim 1, wherein the at least one processor is further configured to execute the instructions to determine the validity from a count for each type of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Regarding claim 7, Cotton discloses; a determination method [i.e., matching process (see ref. 1900 of figure 19), (page 10, para 0117)] comprising:
receiving (i) a first inspection result that is a result of a first inspection of vulnerability of target software [i.e., results of the SAST assessment are stored…SAST assessment results which may include security vulnerabilities for the assessed application (page 9, para 0107), (see ref. 1904 of figure 19), (page 10, para 0117)];
receiving a second inspection result [i.e., imported network vulnerability assessment (page 9, para 0104), (see ref. 1902 of figure 19), (page 10, para 0117)] that is a result of a second inspection of vulnerability of the target software [i.e., associates the SAST assess application with the application discovered by the network vulnerability assessment (page 9, para 0110) i.e., loading instrumented software onto the network host and performing the network vulnerability scan on that same software application (page 1, para 0010)], wherein the first inspection is performed by the first inspection agency [i.e., SAST systems allow a user to upload a software application that they want to assessed into the SAST provider system (see ref. 1701 of figure 17), (page 9, para 0107)], and the second inspection is performed by a second inspection agency different from the first inspection agency [i.e., third-party network vulnerability assessment scanners (page 9, para 0104)];
determining validity of the first inspection from undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability] that is vulnerability detected in the result of the second inspection and not detected in the result of the first inspection [i.e., retrieves vulnerabilities from the network vulnerability assessment and also retrieves the SAST assessment weakness from the SAST assessment result and determines whether the weakness identifies are present in both result sets. Common findings are added to a common list (see ref. 1902 - 1910 of figure 19), (page 10, para 0117 and 0113)]; and
outputting [i.e., renders vulnerability assessment reports…allow users to view results…allows users to obtain scan reports (page 2, para 0037)] (i) a result of determination of the validity [Note; determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment], (ii) the vulnerability detected by the first inspection [i.e., SAST_Discovered_vulnerability, vulnerability dictionary and mapping table (see figure 18)], and (iii) the vulnerability detected by the second inspection [i.e., Machine_Discovered_Vulnerability (see figure 18) Note: corresponds to vulnerabilities from the network assessment], to be displayed and stored in a destination device [i.e., scanner engine 404 reads data that is stored within these four data tables and serializes data into an output file…once the file has been serialized, Scanner Engine 404 signal Platform Messaging Gateway 402 to send the results to NSOC 100 (page 5, para 0063), (see figure 4) i.e., store selected match list results in DB (see ref. 1403 of figure 14), (page 8, para 0091)]..
Cotton does not disclose;
(ii) an electronic signature of the first inspection result that is generated by encrypting a hash value of the first inspection result using a private key from a first inspection agency.
However, Sudia discloses;
(ii) an electronic signature that is generated by encrypting a hash value of the first result using a private key from a first agency [i.e., to sign a message, the message is first digested (hashed) into a single block 22 using a one-way hash function 21…the digest is then encrypted with the user’s private key, and the result is appended to the message as its signature (page 1, para 0009), (see figure 2) i.e., the signer’s organizational sponsor (page 5, para 0072 - 0073)].
Before the effective filing date of the claimed invention, it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton by adapting the teachings of Sudia so that a receiving system can verify the origin and integrity of the report (See Sudia; page 5, para 0073).
Regarding claim 8, Cotton discloses; the determination method according to claim 7, further comprising determining the validity from a count of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Regarding claim 11, Cotton discloses; the determination method according to claim 7, further comprising determining the validity from the count for each type of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Regarding claim 13, Cotton discloses; a non-transitory computer readable storage medium storing a program for causing a computer to execute [i.e., non-transitory computer-readable media include instructions (page 1, para 0012)]:
first result reception processing of receiving (i) a first inspection result that is a result of a first inspection of vulnerability of target software [i.e., results of the SAST assessment are stored…SAST assessment results which may include security vulnerabilities for the assessed application (page 9, para 0107), (see ref. 1904 of figure 19), (page 10, para 0117)];
second result reception processing of receiving a second inspection result [i.e., imported network vulnerability assessment (page 9, para 0104), (see ref. 1902 of figure 19), (page 10, para 0117)] that is a result of a second inspection of vulnerability of the target software [i.e., associates the SAST assess application with the application discovered by the network vulnerability assessment (page 9, para 0110) i.e., loading instrumented software onto the network host and performing the network vulnerability scan on that same software application (page 1, para 0010)], wherein the first inspection is performed by the first inspection agency [i.e., SAST systems allow a user to upload a software application that they want to assessed into the SAST provider system (see ref. 1701 of figure 17), (page 9, para 0107)], and the second inspection is performed by a second inspection agency different from the first inspection agency [i.e., third-party network vulnerability assessment scanners (page 9, para 0104)];
determination processing of determining a validity of the first inspection from undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability] that is vulnerability detected in the result of the second inspection and not detected in the result of the first inspection [i.e., retrieves vulnerabilities from the network vulnerability assessment and also retrieves the SAST assessment weakness from the SAST assessment result and determines whether the weakness identifies are present in both result sets. Common findings are added to a common list (see ref. 1902 - 1910 of figure 19), (page 10, para 0117 and 0113)]; and
output processing of outputting [i.e., renders vulnerability assessment reports…allow users to view results…allows users to obtain scan reports (page 2, para 0037)] (i) the result of determination of the validity [Note; determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment], (ii) the vulnerability detected by the first inspection [i.e., SAST_Discovered_vulnerability, vulnerability dictionary and mapping table (see figure 18)], and (iii) the vulnerability detected by the second inspection [i.e., Machine_Discovered_Vulnerability (see figure 18) Note: corresponds to vulnerabilities from the network assessment], to be displayed and stored in a destination device [i.e., scanner engine 404 reads data that is stored within these four data tables and serializes data into an output file…once the file has been serialized, Scanner Engine 404 signal Platform Messaging Gateway 402 to send the results to NSOC 100 (page 5, para 0063), (see figure 4) i.e., store selected match list results in DB (see ref. 1403 of figure 14), (page 8, para 0091)]..
Cotton does not disclose;
(ii) an electronic signature of the first inspection result that is generated by encrypting a hash value of the first inspection result using a private key from a first inspection agency.
However, Sudia discloses;
(ii) an electronic signature that is generated by encrypting a hash value of the first result using a private key from a first agency [i.e., to sign a message, the message is first digested (hashed) into a single block 22 using a one-way hash function 21…the digest is then encrypted with the user’s private key, and the result is appended to the message as its signature (page 1, para 0009), (see figure 2) i.e., the signer’s organizational sponsor (page 5, para 0072 - 0073)].
Before the effective filing date of the claimed invention, it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton by adapting the teachings of Sudia so that a receiving system can verify the origin and integrity of the report (See Sudia; page 5, para 0073).
Regarding claim 14, Cotton discloses; the non-transitory computer readable storage medium according to claim 13, wherein the determination processing determines the validity from a count of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Regarding claim 17, Cotton discloses; the non-transitory computer readable storage medium according to claim 13, wherein The determination processing determines the validity from the count for each type of the undetected vulnerability [i.e., figure 19 depicts that there is a determination of no VA CWE in SAST Results in the “is VA CWE in SAST Results” decision flow (see ref. 1908 of figure 19) Note; undetected vulnerability and determining whether a vulnerability exists in both assessment or only one assessment means determining the reliability/completeness of one assessment].
Claim(s) 3 – 4, 9 – 10 and 15 - 16 are rejected under 35 U.S.C. 103 as being unpatentable over Cotton in view of Sudia as applied to claims 2, 8 and 14 above, and further in view of the prior art of record, BOBROV et al., (US 2023/0021226 A1) (hereinafter “BOBROV”).
Regarding claim 3, Cotton discloses; the determination system according to claim 2 [i.e., (see claim 2 above)].
Cotton and Sudia do not disclose
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies.
However, BOBROV discloses;
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Regarding claim 4, Cotton discloses; the determination system according to claim 3 [i.e., (see claim 3 above)].
Cotton and Sudia do not disclose
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count for each severity degree of the undetected vulnerability.
However, BOBROV discloses;
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count for each severity degree of the undetected vulnerability [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044) i.e., compare the scanning tool output…determine whether the issues identified by the additional scanning tools are different than the issues identified by the first scanning tool (page 7, para 0067) i.e., the scanning tool identify three instances of the same vulnerability in the portion of the software under test 108. A different scanning tool identify four instances of the same vulnerability in the portion of the software under test 108 (page 4, para 0032), (see figure 1)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Regarding claim 9, Cotton discloses; the determination method according to claim 8 [i.e., (see claim 8 above)].
Cotton and Sudia do not disclose
determining the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies.
However, BOBROV discloses;
determining the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Regarding claim 10, Cotton discloses; the determination method according to claim 9 [i.e., (see claim 9 above)].
Cotton and Sudia do not disclose
determine the validity from the count for each severity degree of the undetected vulnerability.
However, BOBROV discloses;
determine the validity from the count for each severity degree of the undetected vulnerability [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044) i.e., compare the scanning tool output…determine whether the issues identified by the additional scanning tools are different than the issues identified by the first scanning tool (page 7, para 0067) i.e., the scanning tool identify three instances of the same vulnerability in the portion of the software under test 108. A different scanning tool identify four instances of the same vulnerability in the portion of the software under test 108 (page 4, para 0032), (see figure 1)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Regarding claim 15, Cotton discloses; the non-transitory computer readable storage medium according to claim 14 [i.e., (see claim 14 above)].
Cotton and Sudia do not disclose
Wherein the determination processing determine the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies.
However, BOBROV discloses;
Determination processing determine determine the validity from the count of the undetected vulnerability whose severity degree representing severity is higher than a predetermined severity degree, the severity degree being commonly defined among a plurality of agencies [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Regarding claim 16, Cotton discloses; the non-transitory computer readable storage medium according to claim 15 [i.e., (see claim 15 above)].
Cotton and Sudia do not disclose
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count for each severity degree of the undetected vulnerability.
However, BOBROV discloses;
wherein the at least one processor is further configured to execute the instructions to determine the validity from the count for each severity degree of the undetected vulnerability [i.e., the scanning tool output analyzer 122 classify the issues according to the severity of the issue (page 7, para 0058), (see figure 1) i.e., the output of the scanning tool includes a severity of each vulnerability (page 6, para 0053), (page 5, para 0044) i.e., compare the scanning tool output…determine whether the issues identified by the additional scanning tools are different than the issues identified by the first scanning tool (page 7, para 0067) i.e., the scanning tool identify three instances of the same vulnerability in the portion of the software under test 108. A different scanning tool identify four instances of the same vulnerability in the portion of the software under test 108 (page 4, para 0032), (see figure 1)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton and Sudia by adapting the teachings of BOBROV to secure applications and enterprises (See BOBROV; page 1, para 0009).
Claim(s) 6, 12 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Cotton in view of Sudia and BOBROV as applied to claims 1, 7 and 13 above, and further in view of the prior art of record, Groeneveld et al., (US 6,981,151 B1) (hereinafter “Groeneveld”).
Regarding claim 6, Cotton discloses; the determination system according claim 1 [i.e., (see claim 1 above)].
However, BOBROV discloses;
information storage that stores the target software [i.e., the memory 134 store the software under text 108 (page 5, para 0042), (see figure 1)] and authenticity information of the target software [i.e., credentials associated with software copy (page 2, para 0022), (see figure 1)], wherein the at least one processor is further configured to execute the instructions to:
provide the target software and the authenticity information to a first inspection device that performs the first inspection and a second inspection device that performs the second inspection [i.e., the scanning tools 114 store credential data to access the scanning tool. The scanning tool 114 provide that data to the scanning tool manger 112. The scanning tool manager 112 access the third-party computing device and provide the third-party with the software copy (page 2, para 0022), (see figure 1)];
receive the result of the first inspection [i.e., receive, from the first scanning tool, a first scanning tool output that identifies a first issue of the software target (see ref. 530 of figure 5), (page 8, para 0071) and storing the received result of the first inspection in the information storage [i.e., the scanning manager 112 store the outputs and results in the scanning tool outputs 116 (page 3, para 0024), (see figure 1)];
receive the result of the second inspection [i.e., receive, from the second scanning tool, a second scanning tool output that identifies a second issue of the software target (see ref. 540 of figure 5), (page 8, para 0071);
output the result of determination of the validity [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)], and
the at least one processor is further configured to execute the instructions to output information on the undetected vulnerability [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)].
Cotton, Sudia and BORBOV does not disclose;
receive an electronic signature of the result of the first inspection; storing the electronic signature of the result of the first inspection in the information storage; receive an electronic signature of the result of the second inspection, wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed.
However, Groeneveld disclose;
receive an electronic signature of a result of a first inspection [i.e., digitally the sign snapshot (see ref. S18 of figure 3), (col. 9, lines 36 – 37)];
storing the electronic signature of the result of the first inspection in a information storage [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)];
receive an electronic signature of a result of the second inspection [i.e., newly signed snapshots (col. 5, line 32) i.e., snapshot database 32 is configured to store a series of snapshot data records (col. 5 lines 42 – 43) Note; each time, the snapshot process is run, there is a new processing results (data sets) that’s is stored with a digital sign], wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton, Sudia, and BORBOV by adapting the teachings of Groeneveld to provide an improved storage and verification systems utilizing digital signatures (See Groeneveld; col. 1, lines 57 – 58).
Regarding claim 12, Cotton discloses; the determination method according to claim 7 [i.e., (see claim 7 above)].
However, BOBROV discloses;
information storage that stores the target software [i.e., the memory 134 store the software under text 108 (page 5, para 0042), (see figure 1)] and authenticity information of the target software [i.e., credentials associated with software copy (page 2, para 0022), (see figure 1)], wherein the at least one processor is further configured to execute the instructions to:
provide the target software and the authenticity information to a first inspection device that performs the first inspection and a second inspection device that performs the second inspection [i.e., the scanning tools 114 store credential data to access the scanning tool. The scanning tool 114 provide that data to the scanning tool manger 112. The scanning tool manager 112 access the third-party computing device and provide the third-party with the software copy (page 2, para 0022), (see figure 1)];
receive the result of the first inspection [i.e., receive, from the first scanning tool, a first scanning tool output that identifies a first issue of the software target (see ref. 530 of figure 5), (page 8, para 0071) and storing the received result of the first inspection in the information storage [i.e., the scanning manager 112 store the outputs and results in the scanning tool outputs 116 (page 3, para 0024), (see figure 1)];
receive the result of the second inspection [i.e., receive, from the second scanning tool, a second scanning tool output that identifies a second issue of the software target (see ref. 540 of figure 5), (page 8, para 0071);
output the result of determination of the validity [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)], and
the at least one processor is further configured to execute the instructions to output information on the undetected vulnerability [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)].
Cotton, Sudia and BORBOV does not disclose;
receive an electronic signature of the result of the first inspection; storing the electronic signature of the result of the first inspection in the information storage; receive an electronic signature of the result of the second inspection, wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed.
However, Groeneveld disclose;
receive an electronic signature of a result of a first inspection [i.e., digitally the sign snapshot (see ref. S18 of figure 3), (col. 9, lines 36 – 37)];
storing the electronic signature of the result of the first inspection in a information storage [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)];
receive an electronic signature of a result of the second inspection [i.e., newly signed snapshots (col. 5, line 32) i.e., snapshot database 32 is configured to store a series of snapshot data records (col. 5 lines 42 – 43) Note; each time, the snapshot process is run, there is a new processing results (data sets) that’s is stored with a digital sign], wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton, Sudia, and BORBOV by adapting the teachings of Groeneveld to provide an improved storage and verification systems utilizing digital signatures (See Groeneveld; col. 1, lines 57 – 58).
Regarding claim 18, Cotton discloses; the non-transitory computer readable storage medium according to claim 13 [i.e., (see claim 13 above)].
However, BOBROV discloses;
information storage that stores the target software [i.e., the memory 134 store the software under text 108 (page 5, para 0042), (see figure 1)] and authenticity information of the target software [i.e., credentials associated with software copy (page 2, para 0022), (see figure 1)], wherein the at least one processor is further configured to execute the instructions to:
provide the target software and the authenticity information to a first inspection device that performs the first inspection and a second inspection device that performs the second inspection [i.e., the scanning tools 114 store credential data to access the scanning tool. The scanning tool 114 provide that data to the scanning tool manger 112. The scanning tool manager 112 access the third-party computing device and provide the third-party with the software copy (page 2, para 0022), (see figure 1)];
receive the result of the first inspection [i.e., receive, from the first scanning tool, a first scanning tool output that identifies a first issue of the software target (see ref. 530 of figure 5), (page 8, para 0071) and storing the received result of the first inspection in the information storage [i.e., the scanning manager 112 store the outputs and results in the scanning tool outputs 116 (page 3, para 0024), (see figure 1)];
receive the result of the second inspection [i.e., receive, from the second scanning tool, a second scanning tool output that identifies a second issue of the software target (see ref. 540 of figure 5), (page 8, para 0071);
output the result of determination of the validity [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)], and
the at least one processor is further configured to execute the instructions to output information on the undetected vulnerability [i.e., the scanning tool output analyzer 122 output a issue notification 124 that indicates the synthetic issues and status of the synthetic issues (see figure 1), (page 4, para 0034), (page 7, para 0067)].
Cotton, Sudia and BORBOV does not disclose;
receive an electronic signature of the result of the first inspection; storing the electronic signature of the result of the first inspection in the information storage; receive an electronic signature of the result of the second inspection, wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed.
However, Groeneveld disclose;
receive an electronic signature of a result of a first inspection [i.e., digitally the sign snapshot (see ref. S18 of figure 3), (col. 9, lines 36 – 37)];
storing the electronic signature of the result of the first inspection in a information storage [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)];
receive an electronic signature of a result of the second inspection [i.e., newly signed snapshots (col. 5, line 32) i.e., snapshot database 32 is configured to store a series of snapshot data records (col. 5 lines 42 – 43) Note; each time, the snapshot process is run, there is a new processing results (data sets) that’s is stored with a digital sign], wherein the information storage stores the first inspection result in such a way that the stored first inspection result is not able to be changed [i.e., store the signed snapshot in snapshot database 32 (see ref. S20 of figure 3 and figure 2), (col. 9, lines 40 – 43)].
Before the effective filing date of the claimed invention it would have been obvious to a person of ordinary skill in the art to modify the teachings of Cotton, Sudia, and BORBOV by adapting the teachings of Groeneveld to provide an improved storage and verification systems utilizing digital signatures (See Groeneveld; col. 1, lines 57 – 58).
Response to Arguments
Applicant’s arguments with respect to pending claim(s) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED A RONI whose telephone number is (571)270-7806. The examiner can normally be reached M-F 9:00-5:00 pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SYED A RONI/Primary Examiner, Art Unit 2432