Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
2. This action is in response to the original filing on 07/19/2024. Claims 1-5 and 7-16 are pending and have been considered below.
Information Disclosure Statement
3. The information disclosure statement (IDS(s)) submitted on 07/19/2024, 04/30/2026 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections – 35 USC § 103
4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
5. Claims 1, 2, 7-9, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Speck et al. (U.S. Patent Pub. No. US 11863578 B1) in view of Ismail et al. (A Game-Theoretical Model for Security Risk Management of Interdependent ICT and Electrical Infrastructures, IEEE, published 2015, pages 101-109), and further in view of Li et al. (Research on situation assessment of active distribution networks considering cyberattacks, Frontiers, published 08 August 2022, pages 1-12).
Claim 1: Speck teaches a multi-terminal collaborative dynamic security analysis (i.e. The Cyber Vulnerability Assessment Tool (CVAST) and CVAST Threat Assessment Heuristic (THRASH) provide a collection of novel automation tools for assessment of the cybersecurity risk posture of Cyber Physical Systems (CPSs), utilizing ontological models in conjunction with large-scale computational analysis; col. 2, lines 29-35) method for distributed power supply (i.e. The CPS may be one found in power grids, manufacturing plants, nuclear power plants, utility companies, and aviation systems; col. 3, lines 25-30), comprising:
building a physical-cyber network topology model for a distributed power supply control system by using physical topology connections and communication cyber relationships (i.e. the CPS Semantic Model can model a CPS asset, the hardware and software installed on the asset, the interfaces between the asset and other components of the CPS, and the logical ports, protocols, and services used over those interface. Further, the CPS Semantic Model can characterize physical access attributes such as the asset's location aboard a Naval vessel, whether that physical location is locked or otherwise secured, and whether the asset itself is physically secured (e.g., held within a locked enclosure) or specific physical ports on the asset are physically secured (e.g., an Ethernet port that is blocked using a port blocker); col. 7, lines 25-41) of all distributed power terminal units (i.e. The Cyber Vulnerability Assessment Tool (CVAST) and CVAST Threat Assessment Heuristic (THRASH) provide a collection of novel automation tools for assessment of the cybersecurity risk posture of Cyber Physical Systems (CPSs), utilizing ontological models in conjunction with large-scale computational analysis. A CPS can be modeled as a combination of network elements and physical elements. Examples of CPS include, among others, ship engineering systems, smart grids, manufacturing plants, nuclear power plants, water utility companies, and aviation systems. Conducting cyber risk assessment on CPSs requires the analysis of multiple knowledge domains including the engineering, information technology, cybersecurity, and mission (business) domains; col. 2, lines 29-42);
by using prior knowledge (i.e. The CPS Information Extraction System also operates over Open-Source Intelligence (OSINT) and non-publicly accessible Department of Defense (DoD) databases describing cyber security vulnerabilities, vulnerability mitigations, security controls, attack patterns, and adversary attributes; col. 4, lines 35-41), giving a security risk probability Ci (i.e. The Threat and Vulnerability scores each range from 0.0 to 1.0. The Likelihood Score for a CPS component, which can range between 0.0 and 1.0, captures how likely it is that a threat could cause an adverse impact (i.e., exploit a system vulnerability), regardless of how severely the system might be damaged; col. 19, lines 65-67]) and a security risk probability Pi of each distributed power terminal unit of the distributed power terminal units (i.e. The CVAST Chain of Impacts Algorithm provides a method for automatically inferring how the effects of a cybersecurity compromise can propagate through other CPS devices and sub-systems, ultimately affecting the functions and missions supported by the CPS. This helps cybersecurity analysts and system designers prioritize the protection of CPS components and sub-systems, and facilitates assessment of “impact” when evaluating the cyber risk posture of CPSs; col. 16, lines 17-25), and giving cyber domain impact weights and physical domain impact weights of each distributed power terminal unit on other distributed power terminal units of the distributed power terminal units in the cyber domain and the physical domain (i.e. Numerous existing methods and tools for performing automated reasoning can be used to infer connections, as will be appreciated by those of skill in the art, using the novel contribution of semantic relationships defined in the CVAST CPS Semantic Model. For example, if Component X is compromised and impacted by a cyber attack and if Component X controls Component Y, then Component Y is impacted too. This helps determine the propagation of threats. A method for assigning weights or properties to entities found in the CPS domains as well as to the relationships between CPS domains can then be used for qualitative and quantitative cyber risk assessment; col. 8, lines 38-49), to create a physical-cyber security risk network topology map, wherein i denotes a distributed power terminal unit (i.e. the CPS Semantic Model provides a mapping over which to perform automated reasoning about the connections across multiple knowledge domains relevant to CPS Cybersecurity Risk Posture in general and NCS Cybersecurity Risk Posture specifically (or other complex CPS), as in the case of a vulnerability (cybersecurity domain) linked to a specific device configuration (information technology domain) that characterizes a CPS asset (engineering domain) that provides a function (engineering domain) that supports a specific mission or business area (mission domain); col. 8, lines 4-37);
in response to at least one distributed power terminal unit failing or being successfully intruded (i.e. A method for inferencing (for example if Component X is compromised and impacted by a cyber attack and if Component X controls Component Y, then Component Y is impacted too). This allows for an automated analysis of the propagation of threats; col. 23, lines 29-33), updating security risk probabilities and domain security risk probabilities of the other distributed power terminal units (i.e. At this stage, the criticality score of each CPS component accounts for its impacts on mission areas, functions, and interfacing relationships. The final pass accounts for CPS Semantic Model “impacts” relationships between components. If any component that is impacted has a criticality score greater than the component's score from the first and second passes, the score of the impacted component is assigned; col. 17, lines 45-53), to dynamically update security risk network topology map (i.e. A method for inferencing (for example if Component X is compromised and impacted by a cyber attack and if Component X controls Component Y, then Component Y is impacted too). This allows for an automated analysis of the propagation of threats; col. 23, lines 29-33);
based on the dynamically updated physical-cyber security risk network topology map, searching a target attack path according to different attack entrances and attack intensities (i.e. When identifying all possible attack paths between the selected entry and goal components, the Attack Graph Algorithm evaluates: Each path's exploitability, a heuristic computing the cumulative exploitability contributed by each component's known vulnerabilities (i.e., vulnerability metrics associated with vulnerabilities linked to each component). The “energy,” or resource use, required for the threat to successfully exploit all components along each path; col. 10, lines 29-67); and
processing system index data in an attacked state by taking the target attack path as guidance (i.e. The Average Resistance to Attack Index for a given component averages the total resistance to attack of all potential paths from any plausible entry point, to the device, again leveraging output of the CVAST Attack Graph Algorithm; col. 21, lines 9-14) and to assess a business damage degree caused by the target attack path (i.e. The information gathered by the CPS Information Extraction System and the modeling of the information by the CPS Semantic Model provide support to the following novel cyber risk assessment methods, and their implementation as part of CVAST: Attack Graph Algorithm based on electric circuit theory for evaluating attack paths that traverse a CPS. Chain of Impacts Algorithm for evaluating the propagation of kinetic effects and other mission/business impacts when one or more components of a CPS are successfully compromised. CPS Criticality Algorithm for evaluating the criticality of a component, subsystem, or system within a CPS with respect to the impacts that may result from a successful compromise. THRASH Cyber Risk Algorithm for quantifying and evaluating the overall cyber risk posture at the component and system levels in a CPS; col. 2, lines 53-67).
Speck does not explicitly teach giving a cyber domain security risk Ci and a physical domain security risk Pi of each distributed power terminal unit of the distributed power terminal units; establishing a cyber domain updating matrix and a physical domain updating matrix according to the cyber domain impact weights and the physical domain impact weights, respectively, and in response to at least one distributed power terminal unit failing or being successfully intruded, updating cyber domain security risk probabilities and physical domain security risk probabilities of the other distributed power terminal units, to dynamically update the physical-cyber security risk network topology map; processing system index data in an attacked state by taking the target attack path as guidance and taking system index data in a normal state as a reference, and calculating a relational coefficient of each evaluation index.
However, Ismail teaches building a physical-cyber network topology model for a distributed power supply control system by using physical topology connections and communication cyber relationships of all distributed power terminal units (i.e. We model the interdependency between the electrical and the communication infrastructures as a weighted directed interdependency graph D. The graph D is defined as the triplet (V,E,f).V={v1,v2,…,vN} is a finite set of vertices representing the set of electrical and communication nodes. E is a particular subset of V2 and referred to as the edges of D. An element of the set of ordered pairs of vertices E is defined as eij=(i,j), where i is the tail of the edge and j its head. Depending on the head and the tail of element eij the meaning of the edge is different. Finally, f: E→R+ is a function where f(eij) refers to the weight associated with the edge eij; Section III, pages 102-103);
by using prior knowledge (i.e. we propose a mathematical model for identifying the most critical communication equipment used in the power system that must be hardened. To achieve this goal, we use a set of parameters to assess the impact of attacks on system nodes. We suppose that these values are known as a result of a preliminary application of risk assessment methods in each infrastructure; Section I, page 101), giving a cyber domain security risk Ci and a physical domain security risk Pi of each distributed power terminal unit of the distributed power terminal units (i.e. Different factors affect the initial risk rei(0) on an electric equipment i such as the power P generated/consumed by the node, the cost of recovery in the event of a failure, the number of affected customers if the node fails, etc. The communication infrastructure is critical in today's power systems. On the other hand, communication equipment need electric power to function. Therefore, the risk on communication equipment should take into account the impact of compromised equipment in the power system. Similarly to electric nodes, we consider an initial risk rcj(0) on the communication equipment j. As for rei(0), we do not provide a definition for computing rcj(0). However, factors that may affect its value include the criticality/importance of electrical nodes' data processed by j, the number of electric equipment it controls; Section II, page 102), and giving cyber domain impact weights and physical domain impact weights of each distributed power terminal unit on other distributed power terminal units of the distributed power terminal units in the cyber domain and the physical domain (i.e. We model the interdependency between the electrical and the communication infrastructures as a weighted directed interdependency graph D. The graph D is defined as the triplet (V,E,f).V={v1,v2,…,vN} is a finite set of vertices representing the set of electrical and communication nodes. E is a particular subset of V2 and referred to as the edges of D. An element of the set of ordered pairs of vertices E is defined as eij=(i,j), where i is the tail of the edge and j its head. Depending on the head and the tail of element eij the meaning of the edge is different. Finally, f: E→R+ is a function where f(eij) refers to the weight associated with the edge eij. Matrix M represents the effects of nodes on each other and is a block matrix composed of left stochastic matrices B,D,F and S. Elements of these matrices are nonnegative real numbers. Matrix B represents the dependency between electrical nodes. Each element bij of B represents the impact of the failure of electrical node i on electrical node j. Dependencies between communication nodes are represented in matrix S; Section III, page 102), to create a physical-cyber security risk network topology map , wherein i denotes a distributed power terminal unit (i.e. We model the interdependency between the electrical and the communication infrastructures as a weighted directed interdependency graph D. The graph D is defined as the triplet (V,E,f).V={v1,v2,…,vN} is a finite set of vertices representing the set of electrical and communication nodes. E is a particular subset of V2 and referred to as the edges of D. An element of the set of ordered pairs of vertices E is defined as eij=(i,j), where i is the tail of the edge and j its head. Depending on the head and the tail of element eij the meaning of the edge is different. Finally, f: E→R+ is a function where f(eij) refers to the weight associated with the edge eij. Matrix M represents the effects of nodes on each other and is a block matrix composed of left stochastic matrices B,D,F and S. Elements of these matrices are nonnegative real numbers. Matrix B represents the dependency between electrical nodes. Each element bij of B represents the impact of the failure of electrical node i on electrical node j. Dependencies between communication nodes are represented in matrix S; Section III, page 102);
establishing a cyber domain updating matrix and a physical domain updating matrix according to the cyber domain impact weights and the physical domain impact weights, respectively (i.e. Let D be represented by the weighted adjacency matrix M=[mij]N×N defined as follows, Matrix M represents the effects of nodes on each other and is a block matrix composed of left stochastic matrices B,D,F and S. Elements of these matrices are nonnegative real numbers. Matrix B represents the dependency between electrical nodes. Each element bij of B represents the impact of the failure of electrical node i on electrical node j. Dependencies between communication nodes are represented in matrix S. Smax=[smaxij]Nc×Nc represents this maximum impact, where smaxij=maxl=1,…⌊tc⌋γlcslij. Similarly, we define the matrix Bmax=[bmaxij]Ne×Ne that represents the maximum impact of an attack on electrical equipment to reach electrical nodes during time te, where bmaxij=maxl=1,…,⌊te⌋γleblij. Let Smaxn and Bmaxn be the normalized matrices of Smax and Bmax with respect to their rows s.t. ∀j, ∑ibmaxnij=1 and ∑ismaxnij=1; Section III, pages 102-103), and in response to at least one distributed power terminal unit failing or being successfully intruded (i.e. In this section, we are interested in computing the risk on communication equipment after an attacker compromises a set of nodes in the communication system. We consider that the first cascading effects of an attack on communication equipment take place in the communication infrastructure itself. Afterwards, the impact of the attack propagates to the electric system. Finally, the failures in the power grid will affect the power supply of communication nodes; Section III, page 103), updating cyber domain security risk probabilities and physical domain security risk probabilities of the other distributed power terminal units (i.e. the system of equations for inter-and intra-infrastructure risk diffusion is given by: Rc(t+1)=Smax n Rc(t), Rc(t+1)=FRe(t), Re(t+1)=Bmax n Re(t), Re(t+1)=DRc(t); Section III, Equation 1, page 103), updating through the communication risk propagation matrix and through the electrical risk propagation matrix, to dynamically update the physical-cyber security risk network topology map (i.e. We take a similar approach to [10] by balancing the immediate risk and the future induced one. The value of risk on communication equipment at a given time is defined as: Rc(t+4)=δHRc(t)+βRc(0)+θDTRe(0) In equation (2), β,θ and δ are nonnegative real numbers and β+θ+δ=1.β and θ represent the weight of the initial risk on communication nodes and the weight of the diffused risk from electric equipment to communication equipment at time t = 0 respectively. Finally, δ reflects the weight of future cascading risk w.r.t the value of the total risk on communication equipment. Theorem 1 The iterative system of the cascading risk con-verges. An equilibrium solution exists whenever δ<1 and is given by equation 3; Section III, page 104);
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to modify the invention of Speck to include the feature of Ismail. One would have been motivated to make this modification because it provides a systematic and computationally efficient technique for updating the risk of interconnected CPS components following a compromise or failure.
However, Li teaches processing system index data in an attacked state by taking the target attack path as guidance (i.e. Situation assessment index system of ADNs. Situation assessment under attack scenarios. Situation assessment indexes of the ADN under different cyberattack scenarios. Standardized situation assessment indexes of the ADN under different cyberattack scenarios; Section II, 4.2, pages 3-4, 6-8) and taking system index data in a normal state as a reference (i.e. Selecting the reference sequence. It is necessary to draft the reference sequence before doing grey correlation analysis, and reference sequence should be an ideal reference standard. We use the data sample when the ADNs is not suffering from attacks as the reference sequence. we take the ADN operation status in normal as the reference scenario and set it as scenario 0; Section 3.2, 4.1, pages 5-6), and calculating a relational coefficient of each evaluation index (i.e. Calculating the difference sequences and determine the maximum and minimum values of the difference sequence. Calculate the absolute difference between each element of the original data sequences and the reference sequences, which can be used to form the difference sequence, it can be calculated as follows: |x0j−xij|. Calculating the correlation coefficient according to the maximum value maximaxj|x0j−xij| and the minimum value miniminj|x0j−xij| of the difference sequences. Correlation coefficient of each situation assessment index under different cyberattack scenarios; Section 3.2, Table 8, pages 5-6, 9), to assess a business damage degree caused by the target attack path (i.e. In this section, the basic thought of the situation assessment method of ADNs is as follows: first, after establishing the ADNs situation assessment indexes according to Section 2, the weights are assigned to the indexes according to the impact degree of each index on the assessment results; then, the normal operation status of ADN is taken as the reference scenario, and the correlation degrees between the attack scenarios to be assessed and the reference scenario are calculated based on the grey correlation analysis method; finally, the security risk levels of those scenarios can be determined according to the pre-defined criteria; Section 3, 4.2, pages 5-9).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to modify the combination of Speck and Ismail to include the feature of Li. One would have been motivated to make this modification because it provides an objective quantitative measure of the damage associated with an identified attack path.
Claim 2: Speck, Ismail, and Li teach the multi-terminal collaborative dynamic security analysis method for distributed power supply according to claim 1. Speck does not explicitly teach wherein the cyber domain updating matrix and the physical domain updating matrix are:
PNG
media_image1.png
188
264
media_image1.png
Greyscale
wherein, Tc is the cyber domain updating matrix, Tp is the physical domain updating matrix, wcij is a cyber domain impact weight between distributed power terminal unit i and distributed power terminal unit j, wpij is a physical domain impact weight between the distributed power terminal unit i and the distributed power terminal unit j, and n denotes the number of distributed power terminal units.
However, Ismail further teaches wherein the cyber domain updating matrix and the physical domain updating matrix are:
PNG
media_image1.png
188
264
media_image1.png
Greyscale
(i.e. Dependencies between communication nodes are represented in matrix S, S =[sij]Nc×Nc. Matrix B represents the dependency between electrical nodes, B =[bij]Ne×Ne; Section III, page 102)
wherein, Tc is the cyber domain updating matrix, Tp is the physical domain updating matrix, wcij is a cyber domain impact weight between distributed power terminal unit i and distributed power terminal unit j, wpij is a physical domain impact weight between the distributed power terminal unit i and the distributed power terminal unit j, and n denotes the number of distributed power terminal units (i.e. We model the interdependency between the electrical and the communication infrastructures as a weighted directed interdependency graph D. The graph D is defined as the triplet (V,E,f).V={v1,v2,…,vN} is a finite set of vertices representing the set of electrical and communication nodes. E is a particular subset of V2 and referred to as the edges of D. An element of the set of ordered pairs of vertices E is defined as eij=(i,j), where i is the tail of the edge and j its head. Depending on the head and the tail of element eij the meaning of the edge is different. Finally, f: E→R+ is a function where f(eij) refers to the weight associated with the edge eij. Let V={Te,Tc} such that Te={v1,v2,…,vNe} represents the set of electrical nodes in the grid, and Tc={vNe+1,vNe+2,…,vNe+Nc} represents the set of communication nodes. Let D be represented by the weighted adjacency matrix M=[mij]N×N; Section III, pages 102-103).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to modify the combination of Speck and Li to include the feature of Ismail. One would have been motivated to make this modification because it provides a systematic and computationally efficient technique for updating the risk of interconnected CPS components following a compromise or failure.
Claims 7-9 and 13 are similar in scope to Claims 1, 2 and are rejected under a similar rationale.
Allowable Subject Matter
Claims 3-5, 10-12, and 14-16 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
Mestha et al. (Pub. No. US 20180260561 A1), This process is shown in FIG. 9. At S910, the system calculates an initial load at each node of a power grid. At S920, t is set to “0” and a node or edge is removed. At S930, at t=t+1 the power model is run. At S940, the load is recalculated at each node to form a new adjacency matrix at S950. If the end of the dynamic evolution is reached at S960, the impact on the power grid is estimated at S970. If the end of the dynamic evolution is not reached at S960, the process continues at S930.
Munz et al. (Pub. No. US 20200153274 A1), a power distribution and control system for use with a bulk generation system having transmission and distribution systems, the power distribution and control system including a plurality of microgrids each including a power generation element and a load, a plurality of microgrid controllers each associated with one and only one of the plurality of microgrids, and a first communication network.
Engelberg et al. (Pub. No. US 20220263855 A1), Implementations are directed to receiving graph data representative of a process-aware AAG that is representative of potential lateral movement of adversaries within a computer network, receiving risk profile data representative of a risk profile of an enterprise with respect to two or more risk aspects, generating, by a process-aware risk assessment module, a risk assessment based on the process-aware AAG and the risk profile, and generating, by a mitigation simulator module, a mitigation list based on the process-aware AAG, the risk profile, and the risk assessment, the mitigation list comprising a prioritized list of two or more facts of the process-aware AAG
It is noted that any citation to specific pages, columns, lines, or figures in the prior art references and any interpretation of the references should not be considered to be limiting in any way. A reference is relevant for all it contains and may be relied upon for all that it would have reasonably suggested to one having ordinary skill in the art. In re Heck, 699 F.2d 1331, 1332-33, 216 U.S.P.Q. 1038, 1039 (Fed. Cir. 1983) (quoting In re Lemelson, 397 F.2d 1006, 1009, 158 U.S.P.Q. 275, 277 (C.C.P.A. 1968)).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAN TRAN whose telephone number is (303)297-4266. The examiner can normally be reached on Monday - Thursday - 8:00 am - 5:00 pm MT.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Matt Ell can be reached on 571-270-3264. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TAN H TRAN/Primary Examiner, Art Unit 2141