Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is the initial Office action based on the application filed on July 18. 2024.
Claims 1-20 are presently pending in the application have been examined below, of which, claims 1 and 13 are presented in independent form.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Under MPEP Revised Patentable Subject Matter Analysis Step 2A Prong 1: the representative claim 1 limitations “computing the cybersecurity index for the entity, by the computer, including computing a first term by multiplying a first weight factor by a sum of the severities in the first list, computing a second term by multiplying a second weight factor by a sum of the severities in the second list, and adding the first term to the second term” recite an abstract idea of mathematical concepts grouping, which defines mathematical relationships, mathematical formulas or equations, and mathematical calculations. See MPEP 2106.04(a)(2)I.
Under MPEP Revised Patentable Subject Matter Analysis Prong 2 Step 2A: This judicial exception is not integrated into a practical application. The claim recites the following additional element “a computer having a processor and memory”. The element is recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, or merely a generic computer or generic computer components to perform the judicial exception. The claim does not improve the functioning of a computer or any other technology, but instead uses a generic computer as tool to perform the abstract idea. Accordingly, the additional element do not integrate the recited judicial exception into a practical application, and the claim is therefore directed to the judicial exception. See MPEP 2106.05(f).
The additional element of “providing a first list of cybersecurity vulnerabilities for the entity and a second list of cybersecurity vulnerabilities for the entity, along with a corresponding severity for each of the vulnerabilities” is insignificant extra solution activities of data gathering and outputting (MPEP 2106.05 (g)), The claim does not improve the functioning of a computer or any other technology, but instead uses a generic computer as tool to perform the abstract idea. Accordingly, the additional elements do not integrate the recited judicial exception into a practical application, and the claim is therefore directed to the judicial exception.
Under Step 2B: The claim recites the following additional elements “a computer having a processor and memory”
The additional element of “triggering the feature freeze when the cybersecurity index for the entity exceeds a threshold” is recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, or merely a generic computer or generic computer components to perform the judicial exception. The additional element ““providing a first list of cybersecurity vulnerabilities for the entity and a second list of cybersecurity vulnerabilities for the entity, along with a corresponding severity for each of the vulnerabilities” is a well-understood, routine, and conventional data gathering activity. The additional element of “triggering the feature freeze when the cybersecurity index for the entity exceeds a threshold” is also a well-understood, routine, and conventional activity in the software development field as taught in US 10,635,985, US 2015/0254985, and CN 118306060. See MPEP § 2106.05(d).
Accordingly, these additional elements are well-understood, routine, and conventional activities previously known in the industry, as evidenced by their widespread use in software development. Therefore, they do not amount to significant more than the judicial exception. The claim is therefore directed to an abstract idea.
Dependent claims 2-12, further recite abstract idea: mental process (determining), recite a well-understood, routine, and conventional activity (data gathering ), or text description. Accordingly, they are rejected for the same reason set forth in the rejection of claim 1.
Claims 13-20 are rejected by applying the same reasoning set forth in the rejections of claims 1-12.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 1 is rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”).
In the following claim analysis, Applicant’s claim limitations are presented in bold text, the Examiner’s explanations, notes, and remarks are enclosed in square brackets; and emphasized portions are underlined.
As to claim 1, Belfiore discloses A method for applying a feature freeze based on a cybersecurity index for an entity (Belfiore, claim 11, A method for assessing cybersecurity risk for an organization), said method comprising:
providing a first list of cybersecurity vulnerabilities for the entity (Belfiore, Fig. 3, col. 10, ln. 11-19, one or more threat actors relevant to each aspect and/or asset of the technology infrastructure are identified (304). The threat actors, in some examples, can be cyber criminals, state-sponsored actors, hacktivists, insiders, partners (suppliers/customers), disasters, and the like) and a second list of cybersecurity vulnerabilities for the entity, along with a corresponding severity for each of the vulnerabilities (Belfiore, Fig. 3-4, col. 10, ln. 20-23, at least one capability of each threat actor is determined; col. 10, ln. 44-52, one or more objectives are determined for each threat actor (308). The threat actor's capabilities, for example, may be mapped to one or more objectives, such as disrupting data availability, harming data integrity, or damaging data confidentiality[It is noted that the second list taught by Belfiore includes threat actor's capabilities and mapped to one or more objectives. Thus is a different list from the first list of cybersecurity vulnerabilities.]), to a computer having a processor and memory (Belfiore, claim 11, evaluating, by one or more processors; col. 20, ln. 15-18, The cloud computing environment 1030 may also include one or more databases 1038 or other data storage, such as cloud storage and a query database);
computing the cybersecurity index for the entity, by the computer, including computing a first term by multiplying a first weight factor by a sum of the severities in the first list (Belfiore, Fig. 3, col. 10, ln. 53-67, one or more threat scores are calculated for each threat actor based on a criticality evaluation (310). The threat score (or threat rating), for example, may be a function of both a particular capability and the relative criticality (e.g., criticality score) of the corresponding asset … The threat score, in a particular example, may be ranked on a three-point scale (e.g., low, medium, or high). In another example, the threat score may be applied on a 5-point, 10-point or other type of scale … the asset criticality score may be weighted by a threat actor score (e.g., relative capability of the threat actor on an n-point scale); col. 15, ln. 16-21, vulnerability (e.g., vulnerability assessment 140 of FIG. 1 generated from (516) of FIG. 5) including a “low”, “medium”, and “high” portion of each axis. The “low”, “medium”, and “high” may correspond to the severity of the threat [It is noted that Belfiore teaches weighting threat scores according to relative criticality. It would have been obvious to express the weighted threat score as the product of a weighting factor and the summed severity values because weighted summations are well-known mathematical techniques for combining multiple risk values into a single cybersecurity index.]), computing a second term by multiplying a second weight factor by a sum of the severities in the second list, and adding the first term to the second term (Belfiore, col.11, ln. 9-14, a low threat score can correspond to no access to asset, a medium threat score can correspond to remote access to asset, and a high threat score can correspond to privileged access to asset. These factors of threat actor score may be combined into a comprehensive threat actor score [Thus, it is obvious to multiply a second weight factor by a sum of the severities in the second list, and adding the first term to the second term.]).
Belfiore does not appear to explicitly disclose triggering the feature freeze when the cybersecurity index for the entity exceeds a threshold. However, Kumar teaches triggering the feature freeze when the cybersecurity index for the entity exceeds a threshold (Kumar, ¶ 58, fraud risk system 222 may send a risk score to agent device 224 indicating an eighty-six percent chance that the current communication is fraudulent. … An agent operating agent device 224 may decide to freeze the accounts of the customer associated with the current communication so that fraudulent actions may not be performed on the accounts).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching with the teaching taught by Kumar. The modification would be obvious because one of ordinary skill in the art would be motivated to incorporate Kumar’s risk score that indicates a percentage that the current communication as potentially fraudulent within an organization network so that a corrective security action that automatically freezes the accounts of the customer associated with the current communication when the calculated risk score exceeds a predetermined cybersecurity threshold, thereby improving responsiveness and reducing delay in mitigating cybersecurity risks.
Claims 2-4 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) and further in view of US 2023/0153443 (hereinafter “Coppins”).
As to claim 2, the rejection of claim 1 is incorporated. Belfiore as modified does not appear to explicitly disclose A method for applying a feature freeze based on a cybersecurity index for a computer system, said method comprising: providing a feature-enhancing proposed update of the computer system; determining, using a computer having a processor and memory, a current cybersecurity risk level of an organizational group associated with the computer system; computing, using the computer, a cybersecurity risk level of the proposed update; determining whether the current cybersecurity risk level of the organizational group exceeds a first threshold or the cybersecurity risk level of the proposed update exceeds a second threshold.
However, Beek teaches providing a feature-enhancing proposed update of the computer system (Beek, col. 14, ln. 12-19, the one or more security actions may include generating a vulnerability report, recommending corrective actions for one or more cybersecurity vulnerabilities, or automatically performing one or more corrective actions to address one or more cybersecurity vulnerabilities);
determining, using a computer having a processor and memory, a current cybersecurity risk level of an organizational group associated with the computer system (Beek, col. 5, ln. 14-24, determine a vulnerability score indicative of the level of risk posed by cybersecurity vulnerability);
computing, using the computer, a cybersecurity risk level of the proposed update (Belfiore, the col. 17, ln. 5-13, threat tracking and analysis engine 826 may automatically propose additional threat profile data (e.g., threat actors, threat scenarios, and/or threat vectors) presently missing from the evaluation performed by the threat profile engine 822 and cyber control evaluation engine 818. For example, the threat tracking and analysis engine 826 may alert an administrator user of the system 802 regarding previously unidentified threat actors, threat scenarios, and/or threat vectors; col. 14, ln. 3-7, The target level control environment may include target scores (e.g., levels of recommended cybersecurity preparedness) based on the threat vectors and threat scenarios for each of the security domains);
determining whether the current cybersecurity risk level of the organizational group exceeds a first threshold (Beek, col. 14, ln. 33-42, these vulnerabilities may be selected because they have current risk scores exceeding a threshold current risk score. In some embodiments, a subset of vulnerabilities may be selected based on their current risk scores, for example the top N riskiest vulnerabilities may be selected for performing security actions) or the cybersecurity risk level of the proposed update exceeds a second threshold (Beek, claim 3, identifying the one or multiple cybersecurity vulnerabilities with respect to which to perform a security action comprises: identifying cybersecurity vulnerabilities, from among the plurality of cybersecurity vulnerabilities, as those cybersecurity vulnerabilities that have scores greater than a threshold score).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Beek. The modification would be obvious because one of ordinary skill in the art would be motivated to improve the accuracy of determining whether a proposed update exceeds a cybersecurity risk threshold before deployment, thereby enhancing the effectiveness of the overall cybersecurity management system.
Belfiore as modified discloses when either the first threshold or the second threshold is exceeded, applying a feature freeze to prevent implementation of the proposed update (Kumar, ¶ 58, fraud risk system 222 may send a risk score to agent device 224 indicating an eighty-six percent chance that the current communication is fraudulent. … An agent operating agent device 224 may decide to freeze the accounts of the customer associated with the current communication so that fraudulent actions may not be performed on the accounts), does not appear to explicitly disclose when neither the first threshold nor the second threshold is exceeded, proceeding with implementation of the proposed update; and when either the first threshold or the second threshold is exceeded, applying a feature freeze to prevent implementation of the proposed update. However, Coppins teaches when neither the first threshold nor the second threshold is exceeded, proceeding with implementation of the proposed update (Coppins, ¶ 35, But if a CSR score is at or above the threshold, sensitive data at a location 108 may be remediated (block 136) … Another sensitive data scan may be initiated (block 104) to collect new scan results 110 reflecting the remediation (e.g., removal or encryption) of sensitive data. This process of remediating and scanning may be reiterated until the CSR scores are below the desired threshold values).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Coppins. The modification would be obvious because one of ordinary skill in the art would be motivated to improve the security and reliability of update deployment by allowing low risk updates to proceed while preventing deployment of high updates until the identified risks have been addressed.
As to claim 3, the rejection of claim 2 is incorporated. Belfiore as modified further discloses The method according to Claim 2 wherein the computer system includes any of an application, a program, an algorithm, an operating system, a network or a computing device including a server computer (Belfiore, Fig. 1 and its associated paragraphs).
As to claim 4, the rejection of claim 2 is incorporated. Belfiore as modified further discloses The method according to Claim 2 further comprising, before determining a current cybersecurity risk level of the organizational group, determining whether the proposed update of the computer system includes a cybersecurity enhancement (Beek, col. 16, ln.25-27, performing one or more corrective actions or by prioritizing vulnerabilities for corrective actions; col. 9, ln. 52-57, the presence of a vulnerability in a cybersecurity vulnerability testing platform indicates the computing environment may be tested to determine its susceptibility and that there is likely to be one or more corrective actions which may mitigate the risk of the vulnerability), and when the proposed update includes a cybersecurity enhancement, proceeding with implementation of the proposed update (Beek. Col. 14, ln. 9-17, the system may perform the one or more security actions in response to receiving a user input indicating the one or more actions are to be performed … the one or more security actions may include … automatically performing one or more corrective actions to address one or more cybersecurity vulnerabilities). The motivation to combine the references is the same as set forth in the rejection of claim 2.
Claims 5-6 and 13-15 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) in view of US 2023/0153443 (hereinafter “Coppins”) and further in view of US 2025/0173444 (hereinafter “Koren”).
As to claim 5, the rejection of claim 2 is incorporated. Belfiore as modified does not appear to explicitly disclose The method according to Claim 2 further comprising, before applying the feature freeze, determining whether an authorization has been provided from an executive having credentials commensurate with attributes of the computer system and with a value of the cybersecurity risk level which exceeded one of the thresholds and, when the authorization has been provided, proceeding with implementation of the proposed update. However, Koren teaches The method according to Claim 2 further comprising, before applying the feature freeze, determining whether an authorization has been provided from an executive having credentials commensurate with attributes of the computer system (Koren, the identity risk server 120 is configured to initiate a verification of user credentials; ¶ 70, the identity risk profile indicates a cybersecurity risk associated with a particular identity) and with a value of the cybersecurity risk level which exceeded one of the thresholds (Koren, ¶ 43, the identity risk server 120 is configured to initiate a verification of user credentials, for example in response to determining that a cybersecurity risk score exceeds a predetermined threshold) and, when the authorization has been provided, proceeding with implementation of the proposed update (Koren, ¶ 74, a check is performed to determine if access can be granted. … the determination is performed based on the identity risk profile, device information, and resource information. For example, in an embodiment, an aggregate cybersecurity risk score is determined based on a risk score associated with the identity risk profile, a risk score associated with the device, and a risk score associated with the resource; ¶ 75, the aggregate cybersecurity risk score is utilized to determine access, for example based on a predetermined threshold. In an embodiment, where access is denied, execution ends. In some embodiments, where access is granted, execution continues at S440).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Koren. The modification would be obvious because one of ordinary skill in the art would be motivated to incorporate Koren’s authorization verification into the modified system because requiring approval from an appropriately credentialed user before overriding a feature freeze provides an additional security safeguard against unauthorized implementation of high risk updates..
As to claim 6, the rejection of claim 2 is incorporated. Belfiore as modified further discloses The method according to Claim 2 wherein the organizational group is either an application development group which developed the computer system or a department of a business which has a business need for the computer system (Koren, ¶ 71, a particular identity is associated with the “dev” user group, the “dev” user group having a set of predetermined permissions; ¶ 72, a group risk profile is generated for a user group, and applied to individual identities associated with the user group). The motivation to combine the references is the same as set forth in the rejection of claim 5.
As to claim 13, the rejection of claim 2 is incorporated. Belfiore as modified discloses
A cybersecurity-based feature freeze system (Belfiore, Abstract, methods and systems for cybersecurity assessment of an organization's technology infrastructure), said system comprising: a computer having a processor and memory (Belfiore, Fig. 3-4, col. 10, ln. 20-23, at least one capability of each threat actor is determined; col. 10, ln. 44-52, one or more objectives are determined for each threat actor (308). The threat actor's capabilities, for example, may be mapped to one or more objectives, such as disrupting data availability, harming data integrity, or damaging data confidentiality), where the computer is configured to perform steps including; computing a cybersecurity risk level of a feature-enhancing proposed update of a computer system (Belfiore, the col. 17, ln. 5-13, threat tracking and analysis engine 826 may automatically propose additional threat profile data (e.g., threat actors, threat scenarios, and/or threat vectors) presently missing from the evaluation performed by the threat profile engine 822 and cyber control evaluation engine 818. For example, the threat tracking and analysis engine 826 may alert an administrator user of the system 802 regarding previously unidentified threat actors, threat scenarios, and/or threat vectors; col. 14, ln. 3-7, The target level control environment may include target scores (e.g., levels of recommended cybersecurity preparedness) based on the threat vectors and threat scenarios for each of the security domains [including a feature-enhancing proposed update], where the computer system includes any of an application, a program, an algorithm, an operating system, a network or a computing device including a server computer (Belfiore, Fig. 1 and its associated paragraphs);
determining a current cybersecurity risk level of an organizational group associated with the computer system (Beek, col. 16, ln.25-27, performing one or more corrective actions or by prioritizing vulnerabilities for corrective actions; col. 9, ln. 52-57, the presence of a vulnerability in a cybersecurity vulnerability testing platform indicates the computing environment may be tested to determine its susceptibility and that there is likely to be one or more corrective actions which may mitigate the risk of the vulnerability), where the organizational group is either an application development group which developed the computer system or a department of a business which has a business need for the computer system (Koren, ¶ 71, a particular identity is associated with the “dev” user group, the “dev” user group having a set of predetermined permissions; ¶ 72, a group risk profile is generated for a user group, and applied to individual identities associated with the user group);
determining whether the current cybersecurity risk level of the organizational group exceeds a first threshold (Beek, col. 14, ln. 33-42, these vulnerabilities may be selected because they have current risk scores exceeding a threshold current risk score. In some embodiments, a subset of vulnerabilities may be selected based on their current risk scores, for example the top N riskiest vulnerabilities may be selected for performing security actions) or the cybersecurity risk level of the proposed update exceeds a second threshold (Beek, claim 3, identifying the one or multiple cybersecurity vulnerabilities with respect to which to perform a security action comprises: identifying cybersecurity vulnerabilities, from among the plurality of cybersecurity vulnerabilities, as those cybersecurity vulnerabilities that have scores greater than a threshold score);
when neither the first threshold nor the second threshold is exceeded, proceeding with implementation of the proposed update (Coppins, ¶ 35, But if a CSR score is at or above the threshold, sensitive data at a location 108 may be remediated (block 136) … Another sensitive data scan may be initiated (block 104) to collect new scan results 110 reflecting the remediation (e.g., removal or encryption) of sensitive data. This process of remediating and scanning may be reiterated until the CSR scores are below the desired threshold values); and
when either the first threshold or the second threshold is exceeded, applying a feature freeze to prevent implementation of the proposed update (Kumar, ¶ 58, fraud risk system 222 may send a risk score to agent device 224 indicating an eighty-six percent chance that the current communication is fraudulent. … An agent operating agent device 224 may decide to freeze the accounts of the customer associated with the current communication so that fraudulent actions may not be performed on the accounts). The motivation to combine the references is the same as set forth in the rejections of claims 1-5.
As to claims 14-15, the rejection of claim 13 is incorporated and the claims are system claims corresponding to method claims 4-5. Therefore, they are rejected under the same rational set forth in the rejections of claims 4-5.
Claims 7-8 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) in view of US 2023/0153443 (hereinafter “Coppins”) in view of US 2025/0173444 (hereinafter “Koren”) and further in view of US 9,294,498 (hereinafter “Yampolskiy”).
As to claim 7, the rejection of claim 6 is incorporated. Belfiore as modified does not appear to explicitly disclose The method according to Claim 6 wherein computing a cybersecurity risk level of the proposed update includes providing a first list of cybersecurity vulnerability severities to a risk level calculation model running on the computer, providing a cybersecurity history rating of the organizational group to the risk level calculation model, and computing the cybersecurity risk level of the proposed update using the model, where the model computes the cybersecurity risk level by multiplying a sum of the severities in the first list by a first weight factor and adding the cybersecurity history rating of the organizational group multiplied by a second weight factor. However, Yampolskiy teaches The method according to Claim 6 wherein computing a cybersecurity risk level of the proposed update includes providing a first list of cybersecurity vulnerability severities to a risk level calculation model running on the computer (US 9294498 B1,Yampolskiy, col. 20, ln. 63-col. 21,ln. 4, At block 302, the scorecard system 200 obtains a previous score for an entity. The score can be a preliminary security score, a normalized and/or weighted score, or an overall cybersecurity risk score. At block 304, the scorecard system 200 obtains a new score for the entity), providing a cybersecurity history rating of the organizational group to the risk level calculation model (Yampolskiy, col. 21, ln. 1-7, the scorecard system 200 may utilize benchmarking module 230 to compare an entity's calculated cybersecurity risk score to at least one historical cybersecurity score previously calculated for the entity), and computing the cybersecurity risk level of the proposed update using the model, where the model computes the cybersecurity risk level by multiplying a sum of the severities in the first list by a first weight factor and adding the cybersecurity history rating of the organizational group multiplied by a second weight factor ([It is noted that Belfiore expressly teaches weighting cybersecurity threat score based on relative in Fig. 3, col. 10, ln. 53-67: one or more threat scores are calculated for each threat actor based on a criticality evaluation (310). The threat score (or threat rating), for example, may be a function of both a particular capability and the relative criticality (e.g., criticality score) of the corresponding asset … The threat score, in a particular example, may be ranked on a three-point scale (e.g., low, medium, or high). In another example, the threat score may be applied on a 5-point, 10-point or other type of scale … the asset criticality score may be weighted by a threat actor score (e.g., relative capability of the threat actor on an n-point scale); col. 15, ln. 16-21, vulnerability (e.g., vulnerability assessment 140 of FIG. 1 generated from (516) of FIG. 5) including a “low”, “medium”, and “high” portion of each axis. The “low”, “medium”, and “high” may correspond to the severity of the threat [It is noted that Belfiore teaches weighting threat scores according to relative criticality. It would have been obvious to express the weighted threat score as the product of a weighting factor and the summed severity values because weighted summations are well-known mathematical techniques for combining multiple risk values into a single cybersecurity index.]]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Yampolskiy. The modification would be obvious because one of ordinary skill in the art would be motivated to employ Belfiore’s weighting methodology within Yampolskiy’s cybersecurity risk calculation model so that vulnerability severities and historical cyber security ratings contributed to the final risk score according to their respective significance.
As to claim 6, the rejection of claim 7 is incorporated. Belfiore as modified further discloses The method according to Claim 7 wherein the cybersecurity history rating of the organizational group is determined based on a cybersecurity incident track record of the organizational group (Yampolskiy, col. 22, ln. 24-36, the calculated cybersecurity risk score, either numeric, letter, or percentile, can be used by cyber insurance providers to determine premiums for companies … historical cybersecurity performance scores calculated using scorecard system 200 can be used by a cyber-insurance provider to assess the risk of an entity being breached), a degree to which the organizational group has taken cybersecurity risk training (Yampolskiy, col. 22, ln. 35-53, After the score is calculated, the scorecard system may inform the business partner of their company's security score and provide actionable items [e.g., providing trainings] that the entity can take to improve their score. … the original business can also be notified when the business partner addresses action items to improve its score), and a degree to which the organizational group uses designated information technology development tools to prevent new cybersecurity risks (Yampolskiy, col. 22, ln. 35-53, the scorecard system 200 may send the business partner a one-time URL through which the business partner may login to the scorecard system and access its score and view its recommended action items to improve its score). The motivation to combine the references is the same as set forth in the rejection of claim 7.
As to claim 16, the claim corresponding to method claims 7 and 8. Therefore, it is rejected under the same rational set forth in the rejections of the method claims.
Claims 9-10 and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) in view of US 2023/0153443 (hereinafter “Coppins”) in view of US 2025/0173444 (hereinafter “Koren”) in view of US 9,294,498 (hereinafter “Yampolskiy”) and further in view of US 2023/0351026 (hereinafter “Cohen”).
As to claim 9, the rejection of claim 7 is incorporated. Belfiore as modified does not appear to explicitly disclose The method according to Claim 7 wherein the first list of cybersecurity vulnerability severities includes documented cybersecurity vulnerabilities in a previous implementation of the computer system, and cybersecurity vulnerabilities added in the proposed update of the computer system, where each of the cybersecurity vulnerabilities includes a severity. However, Cohen teaches The method according to Claim 7 wherein the first list of cybersecurity vulnerability severities includes documented cybersecurity vulnerabilities in a previous implementation of the computer system (Cohen, Fig. 5, col. 14, ln. 47-51, inspection of an AI model [a previous implementation] includes generating a finding. In an embodiment, a finding is a data record indicating a detected cybersecurity risk), and cybersecurity vulnerabilities added in the proposed update of the computer system, where each of the cybersecurity vulnerabilities includes a severity (Cohen, Fig. 6, col. 14, ln. 27-51, the AI model is inspected for a cybersecurity object, a cybersecurity risk, a misconfiguration, a vulnerability, an exposure, a combination thereof, and the like. … inspection of an AI model includes generating a finding. In an embodiment, a finding [a severity] is a data record indicating a detected cybersecurity risk, misconfiguration, vulnerability, exposure, combination thereof, and the like).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Cohen. The modification would be obvious because one of ordinary skill in the art would be motivated to improve the comprehensiveness and accuracy of the resulting cybersecurity risk evaluation by accounting for both existing and newly introduced vulnerabilities.
As to claim 10, the rejection of claim 9 is incorporated. Belfiore as modified further discloses The method according to Claim 9 wherein determining a current cybersecurity risk level of the organizational group includes providing a second list of cybersecurity vulnerability severities and the cybersecurity history rating of the organizational group to the risk level calculation model (Yampolskiy, col. 21, ln. 1-7, the scorecard system 200 may utilize benchmarking module 230 to compare an entity's calculated cybersecurity risk score to at least one historical cybersecurity score previously calculated for the entity), where the second list of cybersecurity vulnerability severities includes documented cybersecurity vulnerabilities in all computer systems associated with the organizational group (Cohen, Fig. 5, col. 14, ln. 47-51, inspection of an AI model [a previous implementation] includes generating a finding. In an embodiment, a finding is a data record indicating a detected cybersecurity risk), where each of the cybersecurity vulnerabilities includes a severity (Cohen, Fig. 6, col. 14, ln. 27-51, the AI model is inspected for a cybersecurity object, a cybersecurity risk, a misconfiguration, a vulnerability, an exposure, a combination thereof, and the like. … inspection of an AI model includes generating a finding. In an embodiment, a finding [a severity] is a data record indicating a detected cybersecurity risk, misconfiguration, vulnerability, exposure, combination thereof, and the like). The motivation to combine the references is the same as set forth in the rejections of claims 7 and 9.
As to claims 17-18. The claims are corresponding to method claims 9-10. Therefore, they are rejected under the same rational set forth in the rejections of the method claims.
Claims 11 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) in view of US 2023/0153443 (hereinafter “Coppins”) in view of US 2025/0173444 (hereinafter “Koren”) in view of US 9,294,498 (hereinafter “Yampolskiy”) in view of US 2023/0351026 (hereinafter “Cohen”) and further in view of US 2024/0202343 (hereinafter “Darwatkar”).
As to claim 11, the rejection of claim 10 is incorporated. Belfiore as modified discloses The method according to Claim 10 wherein the vulnerability severities and the weight factors are periodically updated by analyzing historical data, including comparing actual cybersecurity incident occurrences for previous updates of different ones of the computer systems to a corresponding cybersecurity risk level (Yampolskiy, col. 21, ln. 1-7, the scorecard system 200 may utilize benchmarking module 230 to compare an entity's calculated cybersecurity risk score to at least one historical cybersecurity score previously calculated for the entity), but does not appear to explicitly disclose adjusting the vulnerability severities and the weight factors so that a first group comprising the computer systems which experienced cybersecurity incidents receive higher cybersecurity risk level scores than a second group comprising the computer systems which did not experience cybersecurity incidents, and so that a difference between the cybersecurity risk level scores of the first group and the second group is maximized. However, Darwatkar teaches adjusting the vulnerability severities and the weight factors so that a first group comprising the computer systems which experienced cybersecurity incidents receive higher cybersecurity risk level scores than a second group comprising the computer systems which did not experience cybersecurity incidents, and so that a difference between the cybersecurity risk level scores of the first group and the second group is maximized (Darwatkar, ¶ 18, A weight 136 for the vulnerability 102 can be adjusted to represent a severity 138 of the vulnerability with respect to deploying the image file 104; claim 5, adjusting a weight for the vulnerability based on the status of the vulnerability, wherein the weight for the vulnerability represents a severity of the vulnerability with respect to the deployment of the image file).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Darwatkar. The modification would be obvious because one of ordinary skill in the art would be motivated to improve the predictive accuracy of the calculation cybersecurity risk levels.
As to claim 19. The claim is corresponding to method claim 11. Therefore, it is rejected under the same rational set forth in the rejection of the method claim.
Claims 12 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over US 12,169,569 (hereinafter "Belfiore”) in view of US 2024/0112198 (hereinafter “Kumar”) in view of US 12,488,117 (hereinafter “Beek”) in view of US 2023/0153443 (hereinafter “Coppins”) in view of US 2025/0173444 (hereinafter “Koren”) in view of US 9,294,498 (hereinafter “Yampolskiy”) in view of US 2023/0351026 (hereinafter “Cohen”) in view of US 2024/0202343 (hereinafter “Darwatkar”) and further in view of US 2024/0414064 (hereinafter “Ayachitula”).
As to claim 12, the rejection of claim 11 is incorporated. Belfiore as modified discloses the adjusted vulnerability severities and weight factors are used by the risk level calculation model to compute the cybersecurity risk level for future proposed updates of any computer system ((Yampolskiy, col. 21, ln. 1-7, the scorecard system 200 may utilize benchmarking module 230 to compare an entity's calculated cybersecurity risk score to at least one historical cybersecurity score previously calculated for the entity). But does not appear to explicitly disclose including a machine learning algorithm in the risk level calculation model and computing a second value of the cybersecurity risk level using the machine learning algorithm, wherein the vulnerability severities and the weight factors are periodically adjusted via a supervised learning process using the historical data as a labelled training dataset. However, Ayachitula teaches including a machine learning algorithm in the risk level calculation model and computing a second value of the cybersecurity risk level using the machine learning algorithm (Ayachitula, ¶ 146, Training datasets (e.g., training data 206, training data 221) can be utilized to train the machine learning algorithms. The training datasets can include historical data of past tickets and the corresponding options/suggestions/resolutions/classification and change categories/verb noun pairs/etc.), wherein the vulnerability severities and the weight factors are periodically adjusted via a supervised learning process using the historical data as a labelled training dataset (Ayachitula, ¶ 145, The weights can be adjusted [i.e., periodically adjusted] and tuned based on experience, making neuromorphic systems adaptive to inputs and capable of learning; ¶ 146, The training datasets can include historical data of past tickets … Labels can be applied to respective tickets to train the machine learning algorithms, as part of supervised learning, as part of supervised learning. . … Once the model is trained, the model (including the adjusted weights) is saved).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Belfiore’s teaching as modified with the teaching taught by Ayachitula. The modification would be obvious because one of ordinary skill in the art would be motivated to provide an automated mechanism for refining those risk calculation parameters based on historical cybersecurity outcomes.
As to claim 20. The claim is corresponding to method claim 12. Therefore, it is rejected under the same rational set forth in the rejection of the method claim.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAXIN WU whose telephone number is (571) 270-7721. The examiner can normally be reached on M-F (7 am - 11:30 am; 1:30- 5 pm).
If attempts to reach the examiner by telephone are unsuccessful, the examiner' s supervisor, Wei Mui can be reached at (571) 272-3708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form.
/DAXIN WU/
Primary Examiner, Art Unit 2191