Prosecution Insights
Last updated: August 18, 2026
Application No. 18/707,738

Generating a Security Metric Using a Machine Learning Model

Final Rejection §103
Filed
May 06, 2024
Priority
Nov 12, 2021 — nonprovisional of PCTIB2021060489
Examiner
BROWN, CHRISTOPHER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Telefonaktiebolaget LM Ericsson
OA Round
2 (Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
1y 1m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
537 granted / 713 resolved
+17.3% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
34 currently pending
Career history
757
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
63.5%
+23.5% vs TC avg
§102
11.5%
-28.5% vs TC avg
§112
11.5%
-28.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 713 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 5/11/26 have been fully considered but they are not persuasive. Applicant argues that there is no motivation to combine the Ramarao reference with the Pokhrel reference since one is a “non-ML approach” and one is a ML reference. Examiner respectfully disagrees. The application involves producing a security metric based on a model of a system. There is nothing that teaches away from incorporation of ML model to improve or more accurately model a system. A machine learning system is merely one that takes training, and or feedback into consideration in order to more accurately represent something. In the instant case the machine learning would take training or feedback to more accurately represent the security metric. Applicant argues that the Ramarao reference does not teach calculating a distance metric between the directed graph of the training system and the directed graph of the reference system. Applicant argues that the distance calculations as taught by Ramarao are not sufficient to meet the claim limitations as stated. Examiner respectfully disagrees. Examiner points out that the term “training system” in the claim language has no context compared to a directed graph which has a “security metric” of an over all system. The claim states that a “distance value” is used as training input for a ML model and that the ML uses this “distance value” to “provide output comprising a value of the security metric” It is unclear what is being trained, or how this training is relevant to a directed graph of a modeled system, which comprises a plurality of security metrics to provide an overall security metric of the system, all of which are taught in Pokhrel. Examiner asserts that the distance calculations of Romarao are “entity vectors” meaning that the vectors interpreted as entity nodes on the directed graph as taught by Pokhrel. Romarao teaches that distance is calculated from reference entity/vectors and training entity/vectors. Romarao teaches that these distance measurements maybe used as input into a ML model. Examiner asserts that this input produced by and submitted in Romarao in combination with the directed graph of Pokhrel thus teaches the claims as stated. Examiner encourages further clarification on what the invention is trying to accomplish rather that mere generation of a model, and a single security metric. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 43-50, 53-57, 59-65, 68, 69 is/are rejected under 35 U.S.C. 103 as being unpatentable over Pokhrel US 10,848,515 in view of Ramarao US 2023/0123132 As per claim 43. (New) Pokhrel teaches generating a security metric for a target system comprising a plurality of logical components, and wherein the security metric comprises a quantitative representation of the security of the target system, which representation is non-specific to any given component of the system or point of attack, the method comprising: (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches an directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel teaches for each of a plurality of reference systems, and for each of a plurality of training systems: generating an analogical model of the system, the analogical model comprising a plurality of vulnerability resistance elements, each vulnerability resistance element corresponding to a security vulnerability of the modelled system; (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches an directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel teaches and mapping the generated analogical model to a directed graph of the modelled system; wherein for each of the plurality of training systems, a value of the security metric is available; (Column 2 lines 18-60) (teaches a directed attack graph of the target system or network) Pokhrel teaches and to provide an output comprising a value of the security metric. (Column 3 lines 42-60) Pokhrel fails to explicitly teach ML, or calculated distance. Ramarao teaches a machine learning model having a plurality of trainable parameters, the method further comprising, for each of the plurality of training systems: calculating a distance metric between the directed graph of the training system and the directed graph of each of the plurality of reference systems; ; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches and adding to a training data set the calculated distance metrics and the security metric value for the training system; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches and the method further comprising: using the training data set to update values of the trainable parameters of the ML model, wherein the ML model is operable to receive an input comprising a plurality of distance metrics; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ramarao with the method/system of Pokhrel because it increases accuracy of the model [Ramarao: par. 0046] As per claim 44. (New) Pokhrel and Ramarao disclose the method of claim 43, Pokhrel further teaches wherein generating the analogical model of the system comprises: obtaining configuration information for the system, the configuration information comprising a system topology and an identification of security vulnerabilities of the system; generating from the configuration information a plurality of system security states, wherein each system security state comprises at least one of a pre or post condition of an identified vulnerability; and for a physical domain of the analogical model, representing: each identified security vulnerability of the system as a vulnerability resistance element of the analogical model; each generated system security state as a node between two or more vulnerability resistance elements of the analogical model; and attack paths traversing vulnerabilities between system security states as flow conduits for a flow variable in the analogical model. (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) (Column 8 lines 11-20) (teaches scores including post condition impact and score) As per claim 45. (New) Pokhrel and Ramarao disclose the method of claim 44, Pokhrel further teaches wherein a precondition of a security vulnerability comprises prerequisites for the system and for an attacker that are required for an attack on the security vulnerability to be successful; and wherein a post condition of a security vulnerability comprises the consequences for the system and for the attacker of successfully executing an attack on the security vulnerability. (Column 3 lines 14-25) (Column 8 lines 11-20) (teaches software vulnerabilities and scores of impact and consequences via CVSS). As per claim 46. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further discloses wherein, for generating the analogical model of a system, the method further comprises adding a one-way flow gate to each vulnerability resistance element to direct flow of a flow variable around the model in a direction consistent with the flow of attacks in the system. (Column 3 lines 25-35) (constructing an attack graph directional chain of exploits) As per claim 47. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further teaches wherein a magnitude of the resistance provided by each vulnerability resistance element is based on a severity of the corresponding security vulnerability. (Column 2 lines 50-67) (CVSS framework provides exploitability and impact metrics) (Column 7 lines 40-50) As per claim 48. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further teaches wherein, for each system security state represented in the analogical model, the method includes generating an importance score, wherein a magnitude of the importance score represents a magnitude of a consequence for the modelled system of an attacker reaching that state. (Column 2 lines 50-67) (CVSS framework provides exploitability and impact metrics) (Column 7 lines 40-50) As per claim 49. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further teaches wherein, for generating the analogical model of the system, the method includes, for each potential attack entry point in the modelled system, adding a source of the analogical model flow variable to the analogical model. (Column 3 lines 26-34) (attack graph with attack paths) (Column 7 lines 10-20) (attacker source node/entry) As per claim 50. (New) Pokhrel and Ramarao disclose the method of claim 49. Pokhrel further discloses setting a magnitude of each source such that a potential energy provided by the source increases with decreasing importance score of a system security state represented by a node that is adjacent to the source. (Column 2 lines 50-67) (Column 7 lines 40-50) (Column 3 1-15) (CVSS framework provides exploitability and impact metrics, scores can be formed and adjusted by an analyst as desired.) As per claim 53. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further teaches wherein at least one of the plurality of reference systems or the plurality of training systems comprises a subsystem for which a value of the security metric is available, and wherein generating the analogical model of the system includes: representing the subsystem in the analogical model with a number of vulnerability resistance elements corresponding to a number of potential attack entry points in the subsystem; representing a system security state of the subsystem at which the subsystem connects to the rest of the modelled system as a node in the analogical model; and determining a resistance value of the vulnerability resistance elements such that a difference between the available value of the security metric for the subsystem and a predicted value of the security metric for the subsystem is minimized. (Column 3 lines 25-35) (constructing an attack graph directional chain of exploits) (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) As per claim 54. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel further teaches wherein mapping a generated analogical model to a directed graph of a modelled system comprises: mapping each node in the analogical model to a node in the directed graph; determining a magnitude of flow of the flow variable of the analogical model through each of the vulnerability resistance elements; and for each pair of nodes connected by a single vulnerability resistance element in the analogical model: if the vulnerability resistance element has a non-zero flow magnitude, mapping the vulnerability resistance element to an edge between the nodes in the directed graph. (Column 3 lines 25-35) (constructing an attack graph directional chain of exploits) (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) As per claim 55. (New) Pokhrel and Ramarao disclose the method of claim 54. Pokhrel further teaches wherein mapping the vulnerability resistance element to an edge between the nodes in the directed graph comprises: setting a direction of the edge to be the direction of flow through the vulnerability resistance element; and setting a magnitude of the edge to be the magnitude of the flow through the vulnerability resistance element. (Column 3 lines 25-35) (constructing an attack graph directional chain of exploits) (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) As per claim 56. (New) Pokhrel and Ramarao disclose the method of claim 43. Ramarao further teaches wherein calculating the distance metric between the directed graph of the training system and the directed graph of each of the plurality of reference systems comprises: calculating a measure of similarity between the directed graph of the training system and the directed graph of each of the plurality of reference systems. [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models). The motivation is the same that of claim 43 above. As per claim 57. (New) Pokhrel and Ramarao disclose the method of claim 43, Ramarao further teaches wherein the ML model comprises a regression model. [0052] (regression model). The motivation is the same that of claim 43 above. As per claim 59. (New) Pokhrel teaches a computer implemented method for generating a security metric for a target system comprising a plurality of logical components, wherein the security metric comprises a quantitative representation of the security of the target system, which representation is non-specific to any given component of the system or point of attack, the method comprising: generating an analogical model of the target system, the analogical model comprising a plurality of vulnerability resistance elements, each vulnerability resistance element corresponding to a security vulnerability of the target system; (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches an directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel teaches mapping the generated analogical model to a directed graph of the target system; (Column 2 lines 18-60) (teaches a directed attack graph of the target system or network) Pokhrel teaches generate an output comprising a value of the security metric for the target system. Pokhrel fails to explicitly teach ML, or calculated distance. . (Column 3 lines 42-60) Ramarao teaches calculating a distance metric between the directed graph of the target system and a directed graph of each of a plurality of reference systems; and inputting a tensor comprising the calculated distance metrics to a trained Machine Learning (ML) model; ; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches wherein the ML model has been trained using a training data set that is based on the same plurality of reference systems; and wherein the ML model is operable to process the input tensor and to ; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ramarao with the system/method of Pokhrel because it increases accuracy of the model. [Ramarao: par. 0046] As per claim 60. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein generating the analogical model of the target system comprises: obtaining configuration information for the target system, the configuration information comprising a system topology and an identification of security vulnerabilities of the target system; generating from the configuration information a plurality of system security states, wherein each system security state comprises at least one of a pre or post condition of an identified vulnerability; and for a physical domain of the analogical model, representing: each identified security vulnerability of the target system as a vulnerability resistance element of the analogical model; each generated system security state as a node between two or more vulnerability resistance elements of the analogical model; and attack paths traversing vulnerabilities between system security states as flow conduits for a flow variable in the analogical model. (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) (Column 8 lines 11-20) (teaches scores including post condition impact and score) As per claim 61. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein a precondition of a security vulnerability comprises prerequisites for the system and for an attacker that are required for an attack on the security vulnerability to be successful; and wherein a post condition of a security vulnerability comprises the consequences for the system and for the attacker of successfully executing an attack on the security vulnerability. (Column 3 lines 14-25) (Column 8 lines 11-20) (teaches software vulnerabilities and scores of impact and consequences via CVSS) As per claim 62. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein, for generating an analogical model of the target system, the method includes further comprises adding a one-way flow gate to each vulnerability resistance element to direct flow of the flow variable around the model in a direction consistent with the flow of attacks in the target system. (Column 3 lines 25-35) (constructing an attack graph directional chain of exploits) As per claim 63. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein a magnitude of the resistance provided by each vulnerability resistance element is based on a severity of the corresponding security vulnerability. (Column 2 lines 50-67) (CVSS framework provides exploitability and impact metrics) (Column 7 lines 40-50) As per claim 64. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein, for generating the analogical model of the target system, the method includes, for each system security state represented in the analogical model, generating an importance score, wherein a magnitude of the importance score represents a magnitude of a consequence for the target system of an attacker reaching that state. (Column 2 lines 50-67) (CVSS framework provides exploitability and impact metrics) (Column 7 lines 40-50) As per claim 65. (New) Pokhrel and Ramarao disclose the method of claim 59, Pokhrel further teaches wherein, for generating the analogical model of the target system, the method includes, for each potential attack entry point in the target system, adding a source of the analogical model flow variable to the analogical model. (Column 3 lines 26-34) (attack graph with attack paths) (Column 7 lines 10-20) (attacker source node/entry) As per claim 68. (New) Pokhrel teaches a Training module for training a Machine Learning (ML) model having a plurality of trainable parameters, wherein the ML model is for generating a security metric for a target system comprising a plurality of logical components, and wherein the security metric comprises a quantitative representation of the security of the target system, which representation is non-specific to any given component of the system or point of attack, the training module comprising processing circuitry configured to: for each of a plurality of reference systems, and for each of a plurality of training systems: generate an analogical model of the system, the analogical model comprising a plurality of vulnerability resistance elements, each vulnerability resistance element corresponding to a security vulnerability of the modelled system; (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches an directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel teaches and map the generated analogical model to a directed graph of the modelled system; (Column 2 lines 18-60) (teaches a directed attack graph of the target system or network) Pokhrel teaches wherein for each of the plurality of training systems, a value of the security metric is available; (Column 3 lines 42-60) (teaches a security metric as risk of entire system) Pokhrel teaches to provide an output comprising a value of the security metric. ; (Column 3 lines 42-60) Pokhrel fails to explicitly teach ML, or calculated distance. Ramarao teaches the processing circuitry being further configured to, for each of the plurality of training systems: calculate a distance metric between the directed graph of the training system and the directed graph of each of the plurality of reference systems; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches and add to a training data set the calculated distance metrics and the security metric value for the training system; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches the processing circuitry being further configured to use the training data set to update values of the trainable parameters of the ML model, wherein the ML model is operable to receive an input comprising a plurality of distance metrics, [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine teaching of Ramarao with the method of Pokhrel because it increases accuracy of the model [Ramarao: par. 0046] As per claim 69. (New) Pokhrel teaches a prediction module for generating a security metric for a target system comprising a plurality of logical components, wherein the security metric comprises a quantitative representation of the security of the target system, which representation is non- specific to any given component of the system or point of attack, the prediction module comprising processing circuitry configured to: generate an analogical model of the target system, the analogical model comprising a plurality of vulnerability resistance elements, each vulnerability resistance element corresponding to a security vulnerability of the target system; (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches an directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel teaches map the generated analogical model to a directed graph of the target system; (Column 2 lines 18-60) (teaches a directed attack graph of the target system or network) Pokhrel teaches generate an output comprising a value of the security metric for the target system. (Column 2 lines 18-60; Column 3 lines 42-60; Column 5 lines 4-28; Column 5 lines 57- Column 6 line 34) (teaches a directed attack graph of a system; including CVSS scores of vulnerability resistance elements, which is used to create a predictive model of the system; teaches using the sub-scores and summing them to get an overall security metric of risk) Pokhrel fails to explicitly teach ML, or calculated distance. Ramarao teaches calculate a distance metric between the directed graph of the target system and a directed graph of each of a plurality of reference systems; and input a tensor comprising the calculated distance metrics to a trained ML model; [0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) Ramarao teaches wherein the ML model has been trained using a training data set that is based on the same plurality of reference systems, and wherein the ML model is operable to process the input tensor[0048][0052][0088][0089] (teaches calculating a distance metric between reference and current model and using the tensor/vector as feedback to improve the ML model, teaches that the model may be a combination of multiple models) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine teaching of Ramarao with the method of Pokhrel because it increases accuracy of the model [Ramarao: par. 0046] Claim(s) 58, is/are rejected under 35 U.S.C. 103 as being unpatentable over Pokhrel US 10,848,515 in view of Ramarao US 2023/0123132 in view of DiMaggio US 2019/0258807 As per claim 58. Pokhrel and Ramarao the method of claim 43. Pokhrel and Ramarao fail to teach a diversity metric. DiMaggio teaches selecting at least the plurality of reference systems such that the plurality fulfils a diversity criterion with respect to the domain of systems for which the trained ML model is to be used; and such that individual systems in the plurality fulfil: a significance criterion with respect to the domain of systems for which the trained ML model is to be used; and a consensus criterion with respect to the value of a security metric that is available for the system [0077][0078] (teaches using a diversity score in order to cluster entities in order to improve a predictive machine learning model to detect vulnerabilities) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to combine the teachings of DiMaggio with the method of Pokhrel and Ramarao because it improves accuracy and efficiency. Claim(s) 51, 52, 66, 67 is/are rejected under 35 U.S.C. 103 as being unpatentable over Pokhrel US 10,848,515 in view of Ramarao US 2023/0123132 in view of Tripp US 2014/0123293 As per claim 51. (New) Pokhrel and Ramarao disclose the method of claim 43. Pokhrel and Ramarao fail to teach sink elements. Tripp teaches wherein, for each system security state represented by a node in the analogical model, the method includes adding a sink resistance element and a sink of the analogical model flow variable downstream of the node. [0047]-[0051] (teaches security analysis including vulnerability analysis of a flow from a source to a sink and weighing the values of the flow/sink appropriately for the vulnerability metric) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tripp with the method/system of Pokhrel and Ramarao because it further narrows the field of security analysis. As per claim 52. (New) Pokhrel, Ramarao and Tripp disclose the method of claim 51. Tripp teaches further comprising setting a resistance of each sink resistance element such that the resistance to flow of the flow variable provided by the sink resistance element increases with decreasing importance score of a system security state represented by the node that is adjacent to the sink resistance element. [0047]-[0051] (teaches security analysis including vulnerability analysis of a flow from a source to a sink and weighing the values of the flow/sink appropriately for the vulnerability metric). The motivation is the same that of claim 51 above. As per claim 66. (New) Pokhrel and Ramarao disclose the method of claim 59. Pokhrel and Ramarao fail to teach sink elements. Tripp teaches wherein, for generating the analogical model of the target system, the method includes, for each system security state represented by a node in the analogical model, adding a sink resistance element and a sink of the analogical model flow variable downstream of the node. [0047]-[0051] (teaches security analysis including vulnerability analysis of a flow from a source to a sink and weighing the values of the flow/sink appropriately for the vulnerability metric) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tripp with the method/system of Pokhrel and Ramarao because it further narrows the field of security analysis. As per claim 67. (New) Pokhrel and Ramarao disclose the method of claim 66, Pokhrel and Ramarao fail to teach sink elements. Tripp teaches setting a resistance of each sink resistance element such that the resistance to flow of the flow variable provided by the sink resistance element increases with decreasing importance score of a system security state represented by the node that is adjacent to the sink resistance element. [0047]-[0051] (teaches security analysis including vulnerability analysis of a flow from a source to a sink and weighing the values of the flow/sink appropriately for the vulnerability metric). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tripp with the method/system of Pokhrel and Ramarao because it further narrows the field of security analysis. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

May 06, 2024
Application Filed
Feb 12, 2026
Non-Final Rejection mailed — §103
May 11, 2026
Response Filed
Jul 30, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Patent 12652290
CYBER SECURITY FOR SOFTWARE-AS-A-SERVICE FACTORING RISK
5y 3m to grant Granted Jun 09, 2026
Patent 12652315
REMOTE MONITORING OF A SECURITY OPERATIONS CENTER (SOC)
3y 8m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 713 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month