Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 6/24/26 have been fully considered but they are not persuasive.
Applicant argues that the prior art fails to teach “the engine receives a users responsive action to a simulated event”, “the engine determines that the action modifies the scenarios progression or causes the simulation to progress based on the action”, “generates modified data reflecting the user action”
Examiner disagrees. Examiner first asserts that while Applicant points to the specification for the meaning of “cyber security restoration engine”, the Examiner may not import narrow meanings from the specification into the claim language. Examiner broadly, but reasonably interprets the term “cyber security restoration engine” in the claim language.
Examiner points to Crabtree [0061] which states “trained machine learning algorithms assist attackers…. Suggests attack avenues…assist defenders of blue team by suggesting defense strategies…especially when attack strategies by the red team are unique and novel.
Examiner asserts that thus… the engine determines that an “indication of an action” is taken by a user (red team) the AI/ML algorithm then “determines an action to modify progression” (suggestion of a defensive action to be taken) and “generates data of a modified progression” (reports the results of the simulation and the success of red team and blue team.
Examiner notes that the claim recites language in the broadest possible manner and thus lacks any relevant detail that might advance prosecution. For example the phrase “indication of an action” does not specify any relevant action, or if the action is even taken by an attacker or defender.
The phrase “determine that the action is to modify a progression” does not teach what the modification is. Examiner asserts that almost any action input would “modify a progression” even if the modification was insignificant, and reaches the same ultimate conclusion.
The phrase “generates data representative of a modified progression” is vague and does not specify if for example, an alternate simulation strategy is used, or rather a report is made of the simulation results. The term “generates data representative” is broad and must be read as such.
Examiner notes that the limitations are taken from Claim 19, and thus no new matter has been incorporated into the claims. Examiner has cited more paragraphs of the Crabtree reference in an attempt to clarify the current rejection.
Examiner cites, but does not rely upon Hadar US 2020/0201992, particularly, [0048] [0053][0058]-[0060][0063] which Examiner believes possibly closer align to Applicant’s intent.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-9, 11-20 are rejected under 35 USC 101 as being directed to an abstract idea without being integrated into a practical application or being significantly more.
Regarding claims 1-9, 11-20; Claim 1 recites the limitations “generate data representative of a simulated cyber security scenario;” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea.
Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the operations “cyber security restoration engine configured to simulate an asset;”
However, said operations are not sufficient to consider that the abstract idea is being interpreted into a practical application. Said operations are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity.
It’s also noted that the claims recite additional limitation/elements (i.e., system, non-transitory medium, etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
The claims do not include additional elements/limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-15, 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree US 2025/0007942 in view of Barai US 2021/0352100.
As per claim 1, Crabtree teaches an apparatus, comprising: a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, which is further configured to: generate data representative of a simulated cyber security scenario involving the asset of the computing network, wherein the simulated cyber security scenario is derived from a real-world cyber security scenario mapped to the asset;
and where instructions implemented in software for the cyber security restoration engine are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units. [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response )
Crabtree teaches receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario. Crabtree teaches determine that the action is to modify a progression of the simulated cyber security scenario, and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation)
Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset.
Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack.
As per claim 2. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is based on a template derived from data representative of an event that occurred as part of a real-life cyber security scenario that occurred on another computing network. [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events)
As per claim 3. The apparatus of claim 2, Crabtree teaches wherein the template is based on a synthetic cyber security scenario generated based on a historical real life cyber security scenario. [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events)
As per claim 4. The apparatus of claim 2, Crabtree teaches wherein the template is represented by a graph comprising one or more edges between one or more connecting assets of the computing network. [0013] (attack mission based on knowledge graph including entities, edges, relationships)
As per claim 5. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is artificial intelligence (AI) generated. [0013] (AI generated attack scenarios)
As per claim 6. The apparatus of claim 5, Crabtree teaches wherein the simulated cyber security scenario is AI generated based on one or more of a graph of interactions between assets in the computing network; and knowledge of threat actor techniques and tactics. [0012][0013] (teaches generating a scenario using contextual information of the network via knowledge graph and TTP information)
As per claim 7. The apparatus of claim 5, Crabtree teaches wherein the AI generated simulated cyber security scenario is generated at least one of: prior to the cyber security restoration engine generating the data representative of the simulated cyber security scenario; such that the AI generated simulated cyber security scenario is used as a basis for the data representative of the simulate cyber security scenario; or in response to a change to an environment associated with the computing network triggered by user input while the cyber security restoration engine is generating the data representative of the simulated cyber security scenario. [0006][0013] (teaches generation of cyber security scenario, which is based on network simulation of computing network)
As per claim 8. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario comprises an event, and wherein the generated data is representative of an effect that the event has on one or more of: the computing network and an organization associated with the computing network. [0087] (teaches monitoring progress of attack scenario including health indicators and relationship events)
As per claim 9. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to: receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario; determine that the action is to modify a progression of the simulated cyber security scenario; and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response )
As per claim 10. The apparatus of claim 9, Crabtree teaches wherein the action comprises one or more of the user instructing a simulated cyber security tool to perform a user-specified action to modify further progression of the simulated cyber security scenario; the user instructing a simulated cyber security tool to autonomously perform an action to modify further progression of the simulated cyber security scenario; and the user providing information about the simulated cyber security scenario to a specified individual in an organization, and the user indicating a response of the specified individual. [0003] [0007] [0061] (red team users, and blue team users perform simulated attack to further progress the scenario, including use of AI attack strategies)
As per claim 11. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is based on a configuration used by a real-life cyber security tool for protecting the computing network. [0006][0007] (teaches use of real-life tools, EDR, etc)
As per claim 12. The apparatus of claim 11, Crabtree teaches wherein the cyber security restoration engine is configured to generate a metric indicative of an effect that the configuration has on the simulated cyber security scenario. [0085] (teaches generating metrics based on the simulated attack)
As per claim 13. The apparatus of claim 12, Crabtree teaches wherein the cyber security restoration engine is configured to suggest a change to be made to the configuration of the real-life cyber security tool based on the metric. [0007][0079][0080] (teaches suggestion of additional security measures)
As per claim 14. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to progress the simulated cyber security scenario based an interaction of a user with a simulation based on the data representative of a simulated cyber security scenario. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including red team and blue team actions)
As per claim 15. The apparatus of claim 14, Crabtree teaches wherein progression of the simulation is displayed on a user interface, and wherein the interaction is input via the user interface. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including red team and blue team actions) [0063](team portals for implementing security controls)
As per claim 17. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to at least one of reference i) a database of restoration response scenarios stored in the database for the computing network and ii) a prediction engine configured to run Artificial Intelligence-based simulations and use an operational state of a node in a graph corresponding to the asset of the computing network during simulations of cyberattacks on the computing network to restore each node compromised by a cyber threat during the simulation of the cyberattack. [0013][0066][0078][0079] (teaches AI suggestions for actions for remediation, and defense improvement)
As per claim 18. Crabtree teaches A computer-implemented method for a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, comprising: generating data representative of a simulated cyber security scenario involving the asset of the computing network, wherein the simulated cyber security scenario is derived from a real-world cyber security scenario mapped to the asset. . [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response )
Crabtree teaches receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario. Crabtree teaches determine that the action is to modify a progression of the simulated cyber security scenario, and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation)
Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset.
Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets)
It would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack.
As per claim 19. Crabtree teaches An apparatus, comprising: a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, which is further configured to: receive an indication of an action taken by a user in response to an event that takes place during a simulation of a cyber security scenario involving the asset of the computing network, wherein the cyber security scenario is derived from a real world cyber security scenario mapped to the asset, and cause the simulation to progress the cyber security scenario based on the action taken by the user; and where instructions implemented in software for the cyber security restoration engine are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units. [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response )
[0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation)
Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset.
Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets)
It would have been obvious to one of ordinary skill in the art effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack.
As per claim 20. The apparatus of claim 19, Crabtree teaches wherein the cyber security restoration engine is configured to generate a metric indicative of an effect that the action had on the simulation. [0085] (teaches generating metrics based on the simulated attack)
Claim(s) 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree US 2025/0007942 in view of Barai US 2021/0352100 in view of Risoldi US 2020/0311630
As per claim 16. The apparatus of claim 15, Crabtree and Barai do not *explicitly* teach the following.
Risoldi teaches wherein the user interface is configured to display a representation of a plurality of assets of the computing network, and wherein the user interface is configured to allow the user to select, from the plurality of assets, the asset to use in the simulated cyber security scenario. [0045][0068] (teaches a user interface to select assets on the network for risk evaluation)
It would have been obvious to one of ordinary skill in the art effective filing date of the claimed invention to use the teaching of Risoldi with the prior art because it improves user accessibility and control.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439