Prosecution Insights
Last updated: October 04, 2026
Application No. 18/770,095

Dynamic Asset Relationship Mapping and Risk Propagation Analysis Using Degree of Connections

Non-Final OA §101§103
Filed
Jul 11, 2024
Examiner
SCHEUNEMANN, RICHARD N
Art Unit
3624
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Ordr Inc.
OA Round
3 (Non-Final)
6%
Grant Probability
At Risk
3-4
OA Rounds
1y 8m
Est. Remaining
15%
With Interview

Examiner Intelligence

Grants only 6% of cases
6%
Career Allowance Rate
35 granted / 560 resolved
-45.7% vs TC avg
Moderate +8% lift
Without
With
+8.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
33 currently pending
Career history
622
Total Applications
across all art units

Statute-Specific Performance

§101
36.4%
-3.6% vs TC avg
§103
39.7%
-0.3% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 560 resolved cases

Office Action

§101 §103
DETAILED ACTION Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on May 19, 2026, has been entered. Claims 1-8, 10, and 14-21 are amended. Claims 1-8, 10, and 14-21 are pending. Interview The Examiner acknowledges the interview conducted on June 9, 2026, in which proposed amendments were discussed with respect to the outstanding rejection. Response to Remarks/Amendments 35 USC §101 Rejections The Applicant traverses the rejection of the claims as being directed to an ineligible abstract idea, contending that the present claims are not directed to risk analysis. In response, the Examiner points to the Applicant’s present Remarks, which state that the term: “risk” has been replaced with “network security threat.” See Remarks p. 15. The term “network security threat” appears to be synonymous with risk. Even assuming, for the sake of argument, that the scope of the claims has been materially altered by the substation of terms, threat analysis (like risk analysis), is still an abstract idea. Editing a graph to add graph components does not provide a practical application. Mapping vectors on a graph does not provide a practical application. These steps, and the other recited steps, are merely graphing methods that are part of the abstract idea of determining a remediation action to perform to address a network security threat event. Lack of conventionality does not imply subject matter eligibility. Additional elements outside the scope of the abstract idea have been considered, but they have been found to amount to generic computer hardware and mere instructions to apply the judicial exception. The rejection for lack of subject matter eligibility is updated and maintained. 35 USC §103 Rejections Amendments to the claims changed the scope of the claims, necessitating further consideration of the prior art. Independent claim 1, 14, and 21 now stand rejected as being obvious over Adamson in view of Hernacki, Lavi, Lokamathe, Komavec Osojnik, and Lewis. The Applicant submits that these references do not teach or suggest determining a number of connections to traverse, as recited in the independent claims. In response, the Examiner submits that cited ¶[0012]-[0014] and [0018]-[0019] of Lokamathe teaches this element, by disclosing an aggregated risk that is propagated to neighboring nodes based on the probability of selection of a path. As the risk is propagated, the effect is to traverse the all affected nodes as they are impacted. Therefore, this teaching reads on the recited limitation. Contrary to the Applicant’s assertions, the early termination of generated of a propagation tree discussed by Komavec Osojnik reads on the recited “traversal termination criteria.” Cited ¶[0064] and [0078] of Komavec Osojnik discloses a threshold for early termination of traversal, which reads on a “traversal termination criteria.” The independent claims are obvious over the cited prior art. The rejection of the dependent claims stands or falls with the rejection of the independent claims. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. The Manual of Patent Examining Procedure (MPEP) provides detailed rules for determining subject matter eligibility for claims in §2106. Those rules provide a basis for the analysis and finding of ineligibility that follows. Claims 1-8, 10, and 14-21 are rejected under 35 U.S.C. 101. The claimed invention is directed to non-statutory subject matter because the claimed invention recites a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Under Step 1 of the subject matter eligibility analysis, claims(s) 1-8, 10, and 14-21 are all directed to one of the four statutory categories of invention. However, under step 2A, prong one, the claims recite a judicial exception: determining a remediation action to perform to address a network security threat event (as evidenced by exemplary independent claim 1; “determining . . . at least one remediation action to perform against the one or more network infrastructure components to address the network security threat event”), an abstract idea. Certain methods of organizing human activity are ineligible abstract ideas, including managing personal behavior or relationships or interactions between people. See MPEP §2106.04(a). The limitations of exemplary claim 1 include: [1] “generating a network infrastructure graph;” [2] “updating the network infrastructure graph;” [3] “identifying a network security threat event;” [4] “determining a network security threat severity associated with the network security threat event;” [5] “selecting a number of connections to traverse from the target network infrastructure graph component;” [6] “traversing a subset of the network infrastructure components;” [7] “determining at least a particular route . . . to determine a remediation action;” [8] “determining . . . at least one remediation action to perform;” and [9] “executing the at least one remediation action.” Steps [1]-[8] are steps for managing personal behavior related to the abstract idea of determining a remediation action to perform to address a network security threat event that, when considered alone and in combination, are part of the abstract idea of determining a remediation action to perform to address a network security threat event. The dependent claims further recite steps for managing personal behavior that are part of the abstract idea of determining a remediation action to perform to address a network security threat event. These claim elements, when considered alone and in combination, are considered to be abstract ideas because they are directed to a method of organizing human activity which includes using a graph as a tool to analyze a network of computer components to determine security threats and mitigate the security threats. Under step 2A, prong two, of the subject matter eligibility analysis, a claim that recites a judicial exception must be evaluated to determine whether the claim provides a practical application of the judicial exception. Additional elements of the independent claims amount to generic computer hardware that does not provide a practical application (a non-transitory computer readable medium in independent claim 1; a system with a processor in independent claim 14, and a processor in independent claim 21). See MPEP §2106.04(d)[I]. The claims do not recite an improvement to another technology or technical field, nor do they recite an improvement to the functioning of the computer itself. See MPEP §2106.05(a). Step [9], identified above, merely amounts to instructions to apply the judicial exception of determining a remediation action to perform to address a network security threat event. Therefore, step [9] does not provide a practical application. See MPEP §2105.05(f). Because the claims only recite use of a generic computer, they do not apply the judicial exception with a particular machine. See MPEP §2106.05(b). Under step 2B of the subject matter eligibility analysis, the claims do not integrate the abstract idea into a judicial exception. Referring to the additional elements provided in the analysis in step one, above, the generic computer hardware does not provide significantly more than the recited abstract idea. See MPEP §2106.05(f). For these reasons, the claims do not provide a practical application of the abstract idea, nor do they amount to significantly more than an abstract idea under step 2B of the subject matter eligibility analysis. Using a generic computer to implement an abstract idea does not provide an inventive concept. Therefore, the claims recite ineligible subject matter under 35 USC §101. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6, 7, 10, 14-17, and 19-21 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20220021697 A1 to Adamson et al. (hereinafter ‘ADAMSON’) in view of US 7984504 B2 to Hernacki et al. (hereinafter ‘HERNACKI’), US 20220019495 A1 to Lavi (hereinafter ‘LAVI’), US 20180048669 A1 to Lokamathe et al. (hereinafter ‘LOKAMATHE’), US 20260010853 A1 to Komavec Osojnik et al. (hereinafter ‘KOMAVEK OSOJNIK’), and US 12021680 B1 to Lewis (hereinafter ‘LEWIS’). Claim 1 (Currently Amended) ADAMSON discloses one or more non-transitory computer readable media comprising instructions (see ¶[0016]; aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having program code embodied thereon) which, when executed by one or more hardware processors (see ¶[0018]; modules may also be implemented in software for execution by various types of processors), causes performance of operations comprising: generating a network infrastructure component graph representing network infrastructure components in a network (see abstract and ¶[0004]-[0006] & [0046]; apparatuses, methods, systems, and program products are disclosed for network asset risk analysis. An interface module that provides an interactive interface that graphically presents the data network and visually highlights each of the plurality of network assets according to their calculated risk levels. Physical and virtual computing components such as computers, servers, Internet of Things devices, routers, switches, bridges, storage devices, and/or the like), each of the network infrastructure components represented in the network infrastructure component graph corresponding to one of devices (see ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), software (see ¶[0046]; the virtual computing components, in certain embodiments, include such things as programs, applications, operating systems, virtual machines, hypervisors, and/or the like), or servers corresponding to the network (see again ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), wherein the network infrastructure component graph defines connections between the network infrastructure components (see ¶[0003]-[0005], [0034]-[0035], [0055], and [0060]; data networks may include numerous interconnected components such as devices and programs. Identify a plurality of network assets of a data network 106, which may include a plurality of physical and virtual computing components that are interconnected via the data network 106, calculate a risk level for each of the plurality of network assets based on a plurality of factors, and provide an interactive interface that graphically presents the data network 106 and visually highlights each of the plurality of network assets according to their calculated risk levels. The interactive interface may include a graphical map illustrating the topology of the data network 106, including the connections between different devices and applications within the data network 106). ADAMSON does not specifically disclose, but HERNACKI discloses, updating the network infrastructure component graph to include a new connection between network infrastructure components in the network (see col 6, ln 9-24 & 56-67; Data collector 304 also sends the collected event to an event driver 314, which analyzes the event data, and updates the asset graph if the event introduces changes in the objects, their attributes or their asset relationships. The asset graph is then updated according to the object risk levels (406). In this embodiment, the object risk levels of the primary targets of the direct event are updated accordingly). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. HERNACKI discloses network risk analysis that includes updating graphs when relationships and values have changed. It would have been obvious to update the graphs as taught by HERNACK in in the system executing the method of ADAMSON with the motivation to determine risk to assets. ADAMSON does not specifically disclose, but LAVI discloses, identifying a network security threat event with a target network infrastructure component of the network infrastructure components in the network at least in part by: tracking activity patterns to detect anomalies (see ¶[0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations); applying machine learning to classify the detected anomalies into network security threat categories (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON does not specifically disclose, but LOKAMATHE discloses, mapping an attack vector based on network architecture (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes) and network infrastructure component criticality (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). ADAMSON does not specifically disclose, but LAVI discloses, probing a network device to discover a misconfiguration (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON further discloses determining a network security threat severity associated with the network security threat event based at least in part on historical incident data and a probability of exploitation of the network security threat event (see ¶[0052]-[0054]; a history of service tickets and a probability that a network asset may fail are used to determine risk). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat severity associated with the network security threat event: selecting a number of connections to traverse from the target network infrastructure component within the network infrastructure component graph for network security threat analysis associated with the network security threat event, wherein the number of connections is selected in proportion to the network security threat severity associated with the network security threat event (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes); wherein the selecting is based at least in part on assigning weights to connections within the network infrastructure component graph based on a criticality of network infrastructure components linked with the connections (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes); for the network security threat analysis associated with the network security threat event, traversing a subset of the network infrastructure components in the network, to determine a plurality of routes of network security threat transmission based on the number of connections (see again ¶[0012]-[0014] and [0018]-[0019]; propagate risk to neighboring nodes based on probability of selection of a path. Compute propagated risk on neighboring nodes). The combination of ADAMSON and LOKAMATHE does not explicitly disclose, but KOMAVEC OSOJNIK discloses, the subset of the network infrastructure components (a) including a first group of the network infrastructure components in the network that are within the number of connections from the asset network infrastructure component within the network infrastructure component graph and (b) not including a second group of the network infrastructure components in the network that are not within the number of connections from the asset network infrastructure component within the network infrastructure component graph (see ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,), wherein the traversing the subset of the network infrastructure components in the network comprises terminating traversal of at least one route of the plurality of routes before the number of connections as traversed for at least one other route of the plurality of routes based at least in part on determining that a next network infrastructure component along the at least one route is secure at least in part by determining that a security profile stored in association with the next network infrastructure component meets one or more traversal termination criteria (see again ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat analysis of the subset of the network infrastructure components; determining at least a particular route of the plurality of routes for which to determine a remediation action (see abstract; provide mitigation plans which will reflect reduced risk in an attack tree simulation); and determining, based at least in part on one or more network infrastructure component types of one or more network infrastructure components along the particular route, at least one remediation action to perform against the one or more network infrastructure components to address the network security threat event (see again abstract; provide mitigation plans which will reflect reduced risk). ADAMSON does not specifically disclose, but LEWIS discloses, wherein the determining the at least one remediation action prioritizes a particular remediation action that offers a greater predicted network security threat reduction than another remediation action (see col 6, ln 1-7 and col 21, ln 4-9; “Optimization” or “optimal allocation” refers to one or more levels of prioritization of mitigation interventions to improve resilience based on the efficacy of an intervention or its cost-effectiveness in reducing risk affordably or within a pre-set budget or obeying the constraint of positive return on investment for reduced risk in return for mitigation investment. ! method for effectively prioritizing mitigation interventions and investments to reduce the network's total risk or consequence posed by cascading failure is provided. The method may be based on relative efficacy and/or net cost effectiveness, using the combination of at least five distinct prioritization methods.). ADAMSON does not specifically disclose, but LOKAMATHE discloses, executing the at least one remediation action to address the network security threat event (see claims 10 and 14; a mitigation plan for providing one or more alternate source or path for the data to be derived or propagated respectively; modifying constraints imposed on the information flow from logical conjunction (“AND”) to logical disjunction (“OR”) or vice-versa; isolating at least one of the one or more affected nodes or the one or more affected paths therebetween deploying data encryption scheme; and implementing diagnostic measures to measure health of the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LAVI discloses providing focus to problematic resources in a dependency graph that includes finding anomalies and classifying resources based on the anomalies. It would have been obvious for one of ordinary skill in the art to find anomalies as taught by LAVI in the system executing the method of ADAMSON with the motivation to assess risk to assets. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. KOMAVEC OSOJNIK discloses impact propagation that includes pruning nodes from a propagation tree when values are lower than a threshold. It would have been obvious for one of ordinary skill in the art at the time of invention to include the pruning of nodes or edges as taught by KOMAVEC OSOJNIK in the system executing the method of ADAMSON and LOKAMATHE with the motivation to terminate propagation early (see KOMOVEC OSOJNIK ¶[0064]). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LEWIS discloses detecting and mitigating errors in a network to improve resilience that includes prioritizing mitigation interventions based on efficacy. It would have been obvious for one of ordinary skill in the art at the time of invention to prioritize interventions as taught by LEWIS in the system executing the method of ADAMSON with the motivation to optimize allocation or mitigation interventions. Claim 2 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media of Claim 1. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: determining a network security threat analysis pathway through at least some of the connections, wherein the network security threat analysis pathway indicates a possible vulnerability traversal through the network (see ¶[0018]; pre-defined weights assigned to the propagated risk and probability of selection of a path in the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes probability of a selection of a network path. It would have been obvious to include the probability of selection of a path as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 3 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media as set forth in Claim 2. ADAMSON further discloses wherein the determining the at least one remediation action comprises identifying at least one network infrastructure component, in the network infrastructure component graph, that is included in the network security threat analysis pathway for analysis corresponding to the network security threat event (see abstract and ¶[0080]; network asset risk analysis. In certain embodiments, the interface 300 allows a user to select and sort by different columns, e.g., to proactively mitigate risk, a user may sort the list by the overall risk score/level 312 to address network assets that pose the highest risk to the business, service, or the like.). Claim 4 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media as set forth in Claim 1. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: determining a plurality of network security threat analysis pathways (see abstract; One or more affected nodes or paths therebetween are identified and attack risk is computed) commencing at the target network infrastructure component (see again abstract; a system in a network) corresponding to the network security threat event (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes) wherein each of the plurality of network security threat analysis pathways traverses the number of connections (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attach to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 6 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media as set forth in Claim 1. ADAMSON does not specifically disclose, but HERNACKI discloses, wherein the operations further comprise dynamically updating the network infrastructure component graph of the network infrastructure components in the network as new network infrastructure components are added to the network and as new connections between the network infrastructure components are determined (see col 6, ln 9-24 & 56-67; Data collector 304 also sends the collected event to an event driver 314, which analyzes the event data, and updates the asset graph if the event introduces changes in the objects, their attributes or their asset relationships. The asset graph is then updated according to the object risk levels (406). In this embodiment, the object risk levels of the primary targets of the direct event are updated accordingly). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. HERNACKI discloses network risk analysis that includes updating graphs when relationships and values have changed. It would have been obvious to update the graphs as taught by HERNACKIN in the system executing the method of ADAMSON with the motivation to determine risk to assets. Claim 7 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media as set forth in Claim 1. ADAMSON further discloses wherein the generating the network infrastructure component graph in the network comprises monitoring communications between pairs of the network infrastructure components and generating links between the network infrastructure components based on the communications between the pairs of the network infrastructure components (see ¶[0040] and [0066]; the data network 106, in one embodiment, includes a digital communication network that transmits digital communications. The dependency module 212 may monitor network traffic (e.g., on incoming and outgoing ports), may use a traceroute command, and/or the like to determine the path through the data network 106, a path through a service group, and/or the like to determine which network assets are dependent upon other network assets within the data network 106). Claim 10 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS the one or more non-transitory computer readable media as set forth in Claim 1. ADAMSON does not specifically disclose, but LEWIS discloses wherein the operations further comprise executing a second remediation action for a second network infrastructure component in the network infrastructure component graph, wherein the second network infrastructure component is further from the target network infrastructure component than the first network infrastructure component and wherein the second remediation action is less substantial than the remediation action (see col 21 ln 55-col 22, ln 19; the right side of the graph 824 may correspond to a higher degree of improvement and the left side of the graph 824 may correspond to a lower degree of improvement. Therefore, using the numerical improvement metric, an optimal network error prevention and or mitigation strategy may be determined). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). LEWIS discloses mitigating errors in a network, where different degrees of improvement are associated with different mitigation strategies. It would have been obvious to include mitigation strategies as taught by LEWIS in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 14 (Currently Amended) ADAMSON discloses A system comprising: at least one device including a hardware processor (see ¶[0018]; modules may also be implemented in software for execution by various types of processors); the system being configured to perform operations comprising: generating a network infrastructure component graph representing network infrastructure components in a network (see abstract and ¶[0004]-[0006] & [0046]; apparatuses, methods, systems, and program products are disclosed for network asset risk analysis. An interface module that provides an interactive interface that graphically presents the data network and visually highlights each of the plurality of network assets according to their calculated risk levels. Physical and virtual computing components such as computers, servers, Internet of Things devices, routers, switches, bridges, storage devices, and/or the like), each of the network infrastructure components represented in the network infrastructure component graph corresponding to one of devices (see ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), software (see ¶[0046]; the virtual computing components, in certain embodiments, include such things as programs, applications, operating systems, virtual machines, hypervisors, and/or the like), or servers corresponding to the network (see again ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), wherein the network infrastructure component graph defines connections between the network infrastructure components (see ¶[0003]-[0005], [0034]-[0035], [0055], and [0060]; data networks may include numerous interconnected components such as devices and programs. Identify a plurality of network assets of a data network 106, which may include a plurality of physical and virtual computing components that are interconnected via the data network 106, calculate a risk level for each of the plurality of network assets based on a plurality of factors, and provide an interactive interface that graphically presents the data network 106 and visually highlights each of the plurality of network assets according to their calculated risk levels. The interactive interface may include a graphical map illustrating the topology of the data network 106, including the connections between different devices and applications within the data network 106). ADAMSON does not specifically disclose, but HERNACKI discloses, updating the network infrastructure component graph to include a new connection between network infrastructure components in the network (see col 6, ln 9-24 & 56-67; Data collector 304 also sends the collected event to an event driver 314, which analyzes the event data, and updates the asset graph if the event introduces changes in the objects, their attributes or their asset relationships. The asset graph is then updated according to the object risk levels (406). In this embodiment, the object risk levels of the primary targets of the direct event are updated accordingly). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. HERNACKI discloses network risk analysis that includes updating graphs when relationships and values have changed. It would have been obvious to update the graphs as taught by HERNACK in in the system executing the method of ADAMSON with the motivation to determine risk to assets. ADAMSON does not specifically disclose, but LAVI discloses, identifying a network security threat event with a target network infrastructure component of the network infrastructure components in the network at least in part by: tracking activity patterns to detect anomalies (see ¶[0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations); applying machine learning to classify the detected anomalies into network security threat categories (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON does not specifically disclose, but LOKAMATHE discloses, mapping an attack vector based on network architecture (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes) and network infrastructure component criticality (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). ADAMSON does not specifically disclose, but LAVI discloses, probing a network device to discover a misconfiguration (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON further discloses, determining a network security threat severity associated with the network security threat event based at least in part on historical incident data and a probability of exploitation of the network security threat event (see ¶[0052]-[0054]; a history of service tickets and a probability that a network asset may fail are used to determine risk). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat severity associated with the network security threat event: selecting a number of connections to traverse from the target network infrastructure component within the network infrastructure component graph for network security threat analysis associated with the network security threat event, wherein the number of connections is selected in proportion to the network security threat severity associated with the network security threat event (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). wherein the selecting is based at least in part on assigning weights to connections within the network infrastructure component graph based on a criticality of network infrastructure components linked with the connections (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes); for the network security threat analysis associated with the network security threat event, traversing a subset of the network infrastructure components in the network, to determine a plurality of routes of network security threat transmission based on the number of connections (see again ¶[0012]-[0014] and [0018]-[0019]; propagate risk to neighboring nodes based on probability of selection of a path. Compute propagated risk on neighboring nodes). The combination of ADAMSON and LOKAMATHE does not explicitly disclose, but KOMAVEC OSOJNIK discloses, the subset of the network infrastructure components (a) including a first group of the network infrastructure components in the network that are within the number of connections from the target network infrastructure component within the network infrastructure component graph and (b) not including a second group of the network infrastructure components in the network that are not within the number of connections from the target network infrastructure component within the network infrastructure component graph (see ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,), wherein the traversing the subset of the network infrastructure components in the network comprises terminating traversal of at least one route of the plurality of routes before the number of connections as traversed for at least one other route of the plurality of routes based at least in part on determining that a next network infrastructure component along the at least one route is secure at least in part by determining that a security profile stored in association with the next network infrastructure component meets one or more traversal termination criteria (see again ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat analysis of the subset of the network infrastructure components; determining at least a particular route of the plurality of routes for which to determine a remediation action (see abstract; provide mitigation plans which will reflect reduced risk in an attack tree simulation); and determining, based at least in part on one or more network infrastructure component types of one or more network infrastructure components along the particular route, at least one remediation action to perform against the one or more network infrastructure components to address the network security threat event (see again abstract; provide mitigation plans which will reflect reduced risk). ADAMSON does not specifically disclose, but LEWIS discloses, wherein the determining the at least one remediation action prioritizes a particular remediation action that offers a greater predicted network security threat reduction than another remediation action (see col 6, ln 1-7 and col 21, ln 4-9; “Optimization” or “optimal allocation” refers to one or more levels of prioritization of mitigation interventions to improve resilience based on the efficacy of an intervention or its cost-effectiveness in reducing risk affordably or within a pre-set budget or obeying the constraint of positive return on investment for reduced risk in return for mitigation investment. ! method for effectively prioritizing mitigation interventions and investments to reduce the network's total risk or consequence posed by cascading failure is provided. The method may be based on relative efficacy and/or net cost effectiveness, using the combination of at least five distinct prioritization methods.). ADAMSON does not specifically disclose, but LOKAMATHE discloses, and executing the at least one remediation action to address the network security threat event (see claims 10 and 14; a mitigation plan for providing one or more alternate source or path for the data to be derived or propagated respectively; modifying constraints imposed on the information flow from logical conjunction (“AND”) to logical disjunction (“OR”) or vice-versa; isolating at least one of the one or more affected nodes or the one or more affected paths therebetween deploying data encryption scheme; and implementing diagnostic measures to measure health of the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LAVI discloses providing focus to problematic resources in a dependency graph that includes finding anomalies and classifying resources based on the anomalies. It would have been obvious for one of ordinary skill in the art to find anomalies as taught by LAVI in the system executing the method of ADAMSON with the motivation to assess risk to assets. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. KOMAVEC OSOJNIK discloses impact propagation that includes pruning nodes from a propagation tree when values are lower than a threshold. It would have been obvious for one of ordinary skill in the art at the time of invention to include the pruning of nodes or edges as taught by KOMAVEC OSOJNIK in the system executing the method of ADAMSON and LOKAMATHE with the motivation to terminate propagation early (see KOMOVEC OSOJNIK ¶[0064]). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LEWIS discloses detecting and mitigating errors in a network to improve resilience that includes prioritizing mitigation interventions based on efficacy. It would have been obvious for one of ordinary skill in the art at the time of invention to prioritize interventions as taught by LEWIS in the system executing the method of ADAMSON with the motivation to optimize allocation or mitigation interventions. Claim 15 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 14. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: determining a network security threat analysis pathway through at least some of the connections, wherein the network security threat analysis pathway indicates a possible vulnerability traversal through the network (see ¶[0018]; pre-defined weights assigned to the propagated risk and probability of selection of a path in the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes probability of a selection of a network path. It would have been obvious to include the probability of selection of a path as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 16 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 15. ADAMSON further discloses wherein the determining the at least one remediation action comprises identifying at least one network infrastructure component, in the network infrastructure component graph, that is included in the network security threat analysis pathway for analysis corresponding to the network security threat event (see abstract and ¶[0080]; network asset risk analysis. In certain embodiments, the interface 300 allows a user to select and sort by different columns, e.g., to proactively mitigate risk, a user may sort the list by the overall risk score/level 312 to address network assets that pose the highest risk to the business, service, or the like.). Claim 17 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 14. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: determining a plurality of network security threat analysis pathways (see abstract; One or more affected nodes or paths therebetween are identified and attack risk is computed) commencing at the target network infrastructure component (see again abstract; a system in a network) corresponding to the network security threat event (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes) wherein each of the plurality of network security threat analysis pathways traverses the number of connections (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attach to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 19 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 14. ADAMSON does not specifically disclose, but HERNACKI discloses, wherein the operations further comprise dynamically updating the network infrastructure component graph of the network infrastructure components in the network as new network infrastructure components are added to the network and as new connections between the network infrastructure components are determined (see col 6, ln 9-24 & 56-67; Data collector 304 also sends the collected event to an event driver 314, which analyzes the event data, and updates the asset graph if the event introduces changes in the objects, their attributes or their asset relationships. The asset graph is then updated according to the object risk levels (406). In this embodiment, the object risk levels of the primary targets of the direct event are updated accordingly). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. HERNACKI discloses network risk analysis that includes updating graphs when relationships and values have changed. It would have been obvious to update the graphs as taught by HERNACKIN in the system executing the method of ADAMSON with the motivation to determine risk to assets. Claim 20 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 14. ADAMSON further discloses wherein the generating the network infrastructure component graph in the network comprises monitoring communications between pairs of the network infrastructure components and generating links between the network infrastructure components based on the communications between the pairs of the network infrastructure components (see ¶[0040] and [0066]; the data network 106, in one embodiment, includes a digital communication network that transmits digital communications. The dependency module 212 may monitor network traffic (e.g., on incoming and outgoing ports), may use a traceroute command, and/or the like to determine the path through the data network 106, a path through a service group, and/or the like to determine which network assets are dependent upon other network assets within the data network 106). Claim 21 (Currently Amended) ADAMSON discloses a method comprising: generating a network infrastructure component graph representing network infrastructure components in a network (see abstract and ¶[0004]-[0006] & [0046]; apparatuses, methods, systems, and program products are disclosed for network asset risk analysis. An interface module that provides an interactive interface that graphically presents the data network and visually highlights each of the plurality of network assets according to their calculated risk levels. Physical and virtual computing components such as computers, servers, Internet of Things devices, routers, switches, bridges, storage devices, and/or the like), each of the network infrastructure components represented in the network infrastructure component graph corresponding to one of devices (see ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), software (see ¶[0046]; the virtual computing components, in certain embodiments, include such things as programs, applications, operating systems, virtual machines, hypervisors, and/or the like), or servers corresponding to the network (see again ¶[0022]; the network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and/or edge servers), wherein the network infrastructure component graph defines connections between the network infrastructure components (see ¶[0003]-[0005], [0034]-[0035], [0055], and [0060]; data networks may include numerous interconnected components such as devices and programs. Identify a plurality of network assets of a data network 106, which may include a plurality of physical and virtual computing components that are interconnected via the data network 106, calculate a risk level for each of the plurality of network assets based on a plurality of factors, and provide an interactive interface that graphically presents the data network 106 and visually highlights each of the plurality of network assets according to their calculated risk levels. The interactive interface may include a graphical map illustrating the topology of the data network 106, including the connections between different devices and applications within the data network 106). ADAMSON does not specifically disclose, but HERNACKI discloses, updating the network infrastructure component graph to include a new connection between network infrastructure components in the network (see col 6, ln 9-24 & 56-67; Data collector 304 also sends the collected event to an event driver 314, which analyzes the event data, and updates the asset graph if the event introduces changes in the objects, their attributes or their asset relationships. The asset graph is then updated according to the object risk levels (406). In this embodiment, the object risk levels of the primary targets of the direct event are updated accordingly). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. HERNACKI discloses network risk analysis that includes updating graphs when relationships and values have changed. It would have been obvious to update the graphs as taught by HERNACK in in the system executing the method of ADAMSON with the motivation to determine risk to assets. ADAMSON does not specifically disclose, but LAVI discloses, identifying a network security threat event with a target network infrastructure component of the network infrastructure components in the network at least in part by: tracking activity patterns to detect anomalies (see ¶[0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations); applying machine learning to classify the detected anomalies into network security threat categories (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON does not specifically disclose, but LOKAMATHE discloses, mapping an attack vector based on network architecture (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes) and network infrastructure component criticality (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). ADAMSON does not specifically disclose, but LAVI discloses, probing a network device to discover a misconfiguration (see ¶[0004], [0030], and [0047]; extract health features of nodes of a dependency graph, including anomalies in request counts and durations. Features are provided to a classification model. The classification model outputs a score indicative that a resource is problematic. Scores exceeding a threshold are provided focus). ADAMSON further discloses, determining a network security threat severity associated with the network security threat event based at least in part on historical incident data and a probability of exploitation of the network security threat event (see ¶[0052]-[0054]; a history of service tickets and a probability that a network asset may fail are used to determine risk). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat severity associated with the network security threat event: selecting a number of connections to traverse from the target network infrastructure component within the network infrastructure component graph for network security threat analysis associated with the network security threat event, wherein the number of connections is selected in proportion to the network security threat severity associated with the network security threat event (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes); wherein the selecting is based at least in part on assigning weights to connections within the network infrastructure component graph based on a criticality of network infrastructure components linked with the connections (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes); for the network security threat analysis associated with the network security threat event, traversing a subset of the network infrastructure components in the network, to determine a plurality of routes of network security threat transmission based on the number of connections (see again ¶[0012]-[0014] and [0018]-[0019]; propagate risk to neighboring nodes based on probability of selection of a path. Compute propagated risk on neighboring nodes). The combination of ADAMSON and LOKAMATHE does not explicitly disclose, but KOMAVEC OSOJNIK discloses, the subset of the network infrastructure components (a) including a first group of the network infrastructure components in the network that are within the number of connections from the target network infrastructure component within the network infrastructure component graph and (b) not including a second group of the network infrastructure components in the network that are not within the number of connections from the target network infrastructure component within the network infrastructure component graph (see ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,), wherein the traversing the subset of the network infrastructure components in the network comprises terminating traversal of at least one route of the plurality of routes before the number of connections as traversed for at least one other route of the plurality of routes based at least in part on determining that a next network infrastructure component along the at least one route is secure at least in part by determining that a security profile stored in association with the next network infrastructure component meets one or more traversal termination criteria (see again ¶[0064] and [0078]; While traversing a propagation tree 207 and generating the edge risks (w), early termination of generation is possible. This can occur if the generated value is below or above a specific threshold, if the generated value in comparison with some other value has not changed for a specified amount (for example, if edge risks (w) for a previous level and a current level do not change by a specific percent. Some nodes or edges can be pruned if their risks are below or above a certain threshold,). ADAMSON does not specifically disclose, but LOKAMATHE discloses, based on the network security threat analysis of the subset of the network infrastructure components; determining at least a particular route of the plurality of routes for which to determine a remediation action (see abstract; provide mitigation plans which will reflect reduced risk in an attack tree simulation); and determining, based at least in part on one or more network infrastructure component types of one or more network infrastructure components along the particular route, at least one remediation action to perform against the one or more network infrastructure components to address the network security threat event (see again abstract; provide mitigation plans which will reflect reduced risk). ADAMSON does not specifically disclose, but LEWIS discloses, wherein the determining the at least one remediation action prioritizes a particular remediation action that offers a greater predicted network security threat reduction than another remediation action (see col 6, ln 1-7 and col 21, ln 4-9; “Optimization” or “optimal allocation” refers to one or more levels of prioritization of mitigation interventions to improve resilience based on the efficacy of an intervention or its cost-effectiveness in reducing risk affordably or within a pre-set budget or obeying the constraint of positive return on investment for reduced risk in return for mitigation investment. ! method for effectively prioritizing mitigation interventions and investments to reduce the network's total risk or consequence posed by cascading failure is provided. The method may be based on relative efficacy and/or net cost effectiveness, using the combination of at least five distinct prioritization methods.). ADAMSON does not specifically disclose, but LOKAMATHE discloses, executing the at least one remediation action to address the network security threat event (see claims 10 and 14; a mitigation plan for providing one or more alternate source or path for the data to be derived or propagated respectively; modifying constraints imposed on the information flow from logical conjunction (“AND”) to logical disjunction (“OR”) or vice-versa; isolating at least one of the one or more affected nodes or the one or more affected paths therebetween deploying data encryption scheme; and implementing diagnostic measures to measure health of the network). wherein the method is performed by at least one device including a hardware processor (see ¶[0018]; modules may also be implemented in software for execution by various types of processors). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LAVI discloses providing focus to problematic resources in a dependency graph that includes finding anomalies and classifying resources based on the anomalies. It would have been obvious for one of ordinary skill in the art to find anomalies as taught by LAVI in the system executing the method of ADAMSON with the motivation to assess risk to assets. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. KOMAVEC OSOJNIK discloses impact propagation that includes pruning nodes from a propagation tree when values are lower than a threshold. It would have been obvious for one of ordinary skill in the art at the time of invention to include the pruning of nodes or edges as taught by KOMAVEC OSOJNIK in the system executing the method of ADAMSON and LOKAMATHE with the motivation to terminate propagation early (see KOMOVEC OSOJNIK ¶[0064]). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LEWIS discloses detecting and mitigating errors in a network to improve resilience that includes prioritizing mitigation interventions based on efficacy. It would have been obvious for one of ordinary skill in the art at the time of invention to prioritize interventions as taught by LEWIS in the system executing the method of ADAMSON with the motivation to optimize allocation or mitigation interventions. Claim(s) 5, 8, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20220021697 A1 to ADAMSON et al. in view of US 7984504 B2 to HERNACKI et al., US 20220019495 A1 to LAVI, US 20180048669 A1 to LOKAMATHE et al., US 20260010853 A1 to KOMAVEK OSOJNIK et al., and US 12021680 B1 to LEWIS as applied to claim 1 above, and further in view of US 20230325840 A1 to Visegrady et al. (hereinafter ‘VISEGRADY’). Claim 5 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the one or more non-transitory computer readable media as set forth in Claim 1. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: identifying a second network security threat event with a second network security threat severity (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes), the second network security threat severity being greater than the associated network security threat severity (see again ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Examiner Note: multiple simulations or calculations would result in different aggregated risk, one greater than the other). The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS does not specifically disclose, but VISEGRADY discloses, determining a second number of connections to traverse for generating a second network security threat analysis, the second number of connections being greater than the number of connections (see ¶[0040]; Preferred embodiments also weight risk attributes of nodes in dependence on the number of hops between each node and the CP node, such that nodes more distant from the CP node contribute less to the resulting risk value(s). Examiner Note: this teaches that number of hops or connections is proportional to risk, and lower risk scores result in fewer hops). ADAMSON does not specifically disclose, but LEWIS discloses, determining a second remediation action to address the second network security threat event, the second remediation action being more extensive than the at least one remediation action (see col 21 ln 55-col 22, ln 19; the right side of the graph 824 may correspond to a higher degree of improvement and the left side of the graph 824 may correspond to a lower degree of improvement. Therefore, using the numerical improvement metric, an optimal network error prevention and or mitigation strategy may be determined). ADAMSON does not specifically disclose, but LOKAMATHE discloses, executing the second remediation action to address the second network security threat event (see claims 10 and 14; a mitigation plan for providing one or more alternate source or path for the data to be derived or propagated respectively; modifying constraints imposed on the information flow from logical conjunction (“AND”) to logical disjunction (“OR”) or vice-versa; isolating at least one of the one or more affected nodes or the one or more affected paths therebetween deploying data encryption scheme; and implementing diagnostic measures to measure health of the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). VISEGRADY discloses risk evaluation that is dependent on the number of hops between nodes. It would have been obvious to calculate risk as taught by VISEGRADY in the system executing the method of ADAMSON with the motivation to proactively mitigate risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). LEWIS discloses mitigating errors in a network, where different degrees of improvement are associated with different mitigation strategies. It would have been obvious to include mitigation strategies as taught by LEWIS in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Claim 8 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS the one or more non-transitory computer readable media as set forth in Claim 1. The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS does not explicitly disclose, but VISEGRADY discloses, wherein the operations further comprise determining a second network security threat analysis pathway at least by: selecting a maximum length for the second network security threat analysis pathway corresponding to the number of connections that is determined based on the associated network security threat severity (see ¶[0040]; Preferred embodiments also weight risk attributes of nodes in dependence on the number of hops between each node and the CP node, such that nodes more distant from the CP node contribute less to the resulting risk value(s). Examiner Note: this teaches that number of hops or connections is proportional to risk, and lower risk scores result in fewer hops). ADAMSON does not specifically disclose, but LOKAMATHE discloses, commencing the second network security threat analysis pathway at the target network infrastructure component, of the network infrastructure component graph, corresponding to the network security threat event (see ¶[0012]-[0014] and [0018]-[0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Propagate risk to neighboring nodes based on probability of selection of a path. Compute business impact loss, information loss impact, and financial impact loss based on the aggregated risk. Compute propagated risk on neighboring nodes). The combination of ADAMSON, LOKAMATHE, and KOMAVEC OSOKNIK does not explicitly disclose, but VISEGRADY discloses, extending a length of the second network security threat analysis pathway from the target network infrastructure component by traversing, from the target network infrastructure component to additional network infrastructure components in the network infrastructure component graph until either (a) the maximum length for the second network security threat analysis pathway is reached or (b) a network infrastructure component is reached with a security profile that meets a pathway termination criteria (see ¶[0040]; Preferred embodiments also weight risk attributes of nodes in dependence on the number of hops between each node and the CP node, such that nodes more distant from the CP node contribute less to the resulting risk value(s). Examiner Note: this teaches that number of hops or connections is proportional to risk, and lower risk scores result in fewer hops). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). VISEGRADY discloses risk evaluation that is dependent on the number of hops between nodes. It would have been obvious to calculate risk as taught by VISEGRADY in the system executing the method of ADAMSON with the motivation to proactively mitigate risk. Claim 18 (Currently Amended) The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS discloses the system as set forth in Claim 14. ADAMSON does not specifically disclose, but LOKAMATHE discloses, wherein the operations further comprise: identifying a second network security threat event with a second network security threat severity (see ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes), the second network security threat severity being greater than the associated network security threat severity see again ¶[0013]-[0014] and [0019]; simulate an attack to affect one or more nodes. Compute an aggregated risk at one or more affected nodes. Examiner Note: multiple simulations or calculations would result in different aggregated risk, one greater than the other). The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, KOMAVEC OSOJNIK, and LEWIS does not specifically disclose, but VISEGRADY discloses, determining a second number of connections to traverse for generating a second network security threat analysis, the second number of connections being greater than the number of connections (see ¶[0040]; Preferred embodiments also weight risk attributes of nodes in dependence on the number of hops between each node and the CP node, such that nodes more distant from the CP node contribute less to the resulting risk value(s). Examiner Note: this teaches that number of hops or connections is proportional to risk, and lower risk scores result in fewer hops). The combination of ADAMSON, HERNACKI, LAVI, LOKAMATHE, and KOMAVEC OSOJNIK does not specifically disclose, but LEWIS discloses, determining a second remediation action to address the second network security threat event, the second remediation action being more extensive than the at least one remediation action (see col 21 ln 55-col 22, ln 19; the right side of the graph 824 may correspond to a higher degree of improvement and the left side of the graph 824 may correspond to a lower degree of improvement. Therefore, using the numerical improvement metric, an optimal network error prevention and or mitigation strategy may be determined). ADAMSON does not specifically disclose, but LOKAMATHE discloses, and executing the second remediation action to address the second network security threat event. further comprising [sic] (see claims 10 and 14; a mitigation plan for providing one or more alternate source or path for the data to be derived or propagated respectively; modifying constraints imposed on the information flow from logical conjunction (“AND”) to logical disjunction (“OR”) or vice-versa; isolating at least one of the one or more affected nodes or the one or more affected paths therebetween deploying data encryption scheme; and implementing diagnostic measures to measure health of the network). ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). VISEGRADY discloses risk evaluation that is dependent on the number of hops between nodes. It would have been obvious to calculate risk as taught by VISEGRADY in the system executing the method of ADAMSON with the motivation to proactively mitigate risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk and proactively mitigate risk (see ¶[0080]). LEWIS discloses mitigating errors in a network, where different degrees of improvement are associated with different mitigation strategies. It would have been obvious to include mitigation strategies as taught by LEWIS in the system executing the method of ADAMSON with the motivation to reduce risk. ADAMSON discloses network asset risk analysis that includes a risk graph with nodes representing assets to assess risk. LOKAMATHE discloses comprehensive risk assessment in a heterogeneous dynamic network that includes determining impact of risk on neighboring nodes to develop risk mitigation plans. It would have been obvious to include the aggregate assessment and mitigation plan as taught by LOKAMATHE in the system executing the method of ADAMSON with the motivation to reduce risk. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to RICHARD N SCHEUNEMANN whose telephone number is (571)270-7947. The examiner can normally be reached M-F 9am-5pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patricia Munson can be reached at 571-270-5396. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RICHARD N SCHEUNEMANN/ Primary Examiner, Art Unit 3624
Read full office action

Prosecution Timeline

Show 1 earlier event
Sep 26, 2025
Non-Final Rejection mailed — §101, §103
Nov 20, 2025
Examiner Interview Summary
Dec 04, 2025
Response Filed
Mar 12, 2026
Final Rejection mailed — §101, §103
May 19, 2026
Request for Continued Examination
May 22, 2026
Response after Non-Final Action
Jun 09, 2026
Examiner Interview Summary
Sep 16, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12579549
PLATFORM FOR FACILITATING AN AUTOMATED IT AUDIT
4y 8m to grant Granted Mar 17, 2026
Patent 12535999
A METHOD FOR EXECUTION OF A MACHINE LEARNING MODEL ON MEMORY RESTRICTED INDUSTRIAL DEVICE
6y 4m to grant Granted Jan 27, 2026
Patent 12033094
AUTOMATIC GENERATION OF TASKS AND RETRAINING MACHINE LEARNING MODULES TO GENERATE TASKS BASED ON FEEDBACK FOR THE GENERATED TASKS
4y 9m to grant Granted Jul 09, 2024
Patent 12026624
System and Method For Loss Function Metalearning For Faster, More Accurate Training, and Smaller Datasets
4y 1m to grant Granted Jul 02, 2024
Patent 11836746
AUTO-ENCODER ENHANCED SELF-DIAGNOSTIC COMPONENTS FOR MODEL MONITORING
9y 0m to grant Granted Dec 05, 2023
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
6%
Grant Probability
15%
With Interview (+8.3%)
3y 11m (~1y 8m remaining)
Median Time to Grant
High
PTA Risk
Based on 560 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month