Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Response to Amendment
Claim 1 has been amended.
Claims 1-20 are pending.
Response to Arguments
Applicant’s arguments with respect to the pending claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
I. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
II. CLAIMS 1-15 AND 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over CRABTREE et al (US 2025/0039228) in view of JOSHI et al (US 2022/0222089).
Per claim 1, CRABTREE et al teach a computer-implemented method for cybersecurity management comprising:
accessing a plurality of cybersecurity threat protection applications, wherein the plurality of cybersecurity threat protection applications is deployed across a managed cybersecurity network, and wherein the plurality of cybersecurity threat protection applications is managed using a security orchestration, automation, and response (SOAR) platform [paras 0008-13, 0057, 0069, 0116, 0122—detecting security threats in applications, application deployment managed by SOAR workflows to mitigate cyberattacks];
executing a cybersecurity workflow, using the SOAR platform that, includes instructions to manage search hijacking operations, insider threat protection operations, and cryptojacking operations [paras 0012, 0031, 0052, 0057, 0063, 0067, 0071, 0075-76, 0084-85, 0089, 0093, 0101, 0104—execution of SOAR workflow for handling session hijacking, cyberattacks, security breaching, theft of user authentication/token and security threats];
capturing data representing one or more cybersecurity actions that are performed in response to execution of the cybersecurity workflow, wherein the captured data comprise reports generated by the SOAR platform, the plurality of cybersecurity threat protection applications, and network devices [paras 0036-37, 0046-50, 0060—monitoring transactions and tracking how the network and various applications interact to generate reports for evaluation and behavioral analysis, detecting and reporting on safety issues and corruption vulnerabilities exploitable by attackers];
analyzing the one or more cybersecurity actions for workflow relevance based on providing the one or more cybersecurity actions as input to a machine learning model [paras 0064-66—analyzing cyberattack types using a BYOML model or AI planner enhanced SOAR workflow for updating the system for detection and prevention], wherein:
the AI machine learning model was trained to (i) analyze the one or more cybersecurity actions and timings of automated responses in the cybersecurity workflow and (ii) compare the analysis to historic cybersecurity actions and timings of automated responses [paras 0011-12, 0029-31, 0057, 0079, 0093, 0095—analyzing and identifying traffic patterns, attack patterns or anomalous behavior…tracking path and timing of request to understand the sequence of events leading to a security incident, performing automated planning and automated static and dynamic analysis of application crash dumps and failures; paras 0063, 0071, 0074-75, 0094—machine learning applied as simulations to identify hidden or previously-unknown vulnerabilities and avenues for defending against certain types of attacks and for providing automated generation of ongoing potential security threats and vulnerability discovery as processes occur throughout a network],
the AI machine learning model was trained using (i) data from a natural language and data, (ii) data from the plurality of cybersecurity threat protection applications, and (iii) historic cybersecurity events data captured by the SOAR platform [paras 0046, 0074—natural language processing for supporting identification of data of interest or relating to a specific risk, compliance, reporting, or handling processes and machine learning algorithms may be applied as simulations to identify hidden or previously-unknown vulnerabilities and avenues for defending against certain types of attacks; paras 0052, 0057—NDA, network detection analytics analyze network traffic to identify potential security threats], and
the analyzing further comprises: generating multiple versions of the SOAR platform using the AI machine learning model, wherein the multiple versions of the SOAR platform comprise alternative workflows, reordering of steps in the alternative workflows, added tasks in the alternative workflows, and parallel remedial steps in the alternative workflows [para 0076—using a SOAR workflow, with a non-exhaustive list of exemplary workflows, that implements each workflow triggered by the attacker intercept manager, wherein multiple workflows can be implemented in series or in parallel to mitigate an attack depending on the type of attack or number of device affected];
executing each of the multiple versions of the SOAR platform to test potential actions and responses to different cybersecurity threats and application update requirements creating SOAR workflows based on the type of attack that has been detected [paras 0008, 0063, 0074-75, 0079-80—simulation engines for simulating an attack to test the SOAR actions and response to different types of attacks]; and
determining, based on executing the multiple versions of the SOAR platform, respective workflow relevance [paras 0008-11—an AI planner to determine from the prospective cyberattack type, at least one appropriate SOAR workflow to implement to mitigate the cyberattack and applying a configuration change to the pattern of identified traffic to prevent further compromises by the cyberattack or abuse];
automatically updating, in real-time, the cybersecurity workflow on the SOAR platform based on the analyzing, wherein updating the cybersecurity workflow comprises reordering existing remedial steps in the cybersecurity workflow for the search hijacking operations, the insider threat protection operations, and the cryptojacking operations to improve efficiency and effectiveness of the one or more cybersecurity actions [paras 0011, 0036, 0065, 0075, 0079, 0093-96, 0106—real-time prevention and immediate response to potential threats, mitigate attacks in real-time…periodic updates, remediation, IDS/IPS signature updates for attacker interdiction, the AI or automated planning enhanced SOAR workflow comprises updating of intrusion detection system (IDS) signatures, intrusion prevention system (IPS)]; and
executing, in parallel to updating the cybersecurity workflow and in real-time, one or more of the remedial steps of the updated cybersecurity workflow, wherein executing the one or more of the remedial steps causes the AI computer system to automatically perform the one or more of the remedial steps in the cybersecurity workflow for the search hijacking operations, the insider threat protection operations, and the cryptojacking operations [paras 0075, 0106—SOAR workflow remediation including recovering from cybersecurity incidents, updating security software, taking actions to contain the threat; paras 0008-12—AI planner to determine from the prospective cyberattack type at least one appropriate security orchestration, SOAR workflow implemented to mitigate the cyberattacks including session hijacking, token theft/forgery].
CRABTREE et al teach the method of claim 1 and natural language processing, as applied above, yet fail to explicitly teach “a natural language user interface…and rootkit operations”. JOSHI et al teach natural language processing [para 0286], a user interface [paras 0028, 0124], cryptojacking [paras 0031, 0034, 0036], rootkits operations and browser hijacking [para 0111].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention to combine the teachings of CRABTREE et al and JOSHI et al to provision a natural language user interface and managing cybersecurity vulnerabilities such as rootkit operations, which are well-known in the art for implementing user interfaces specific workflows capable of handling specific cyberattacks for prevention and remediation.
Claim 14 contains limitations that are substantially equivalent to the limitations of claim 1, and are therefore rejected under the same basis.
Per claim 2, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach the method further comprising automatically executing the updated cybersecurity workflow on the SOAR platform [paras 0011, 0065—automated planning enhanced SOAR workflow comprising updating; JOSHI et al: para 0134—automated update].
Per claim 3, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the one or more cybersecurity actions are implemented in response to an element of the cybersecurity workflow being executed [paras 0008, 0075-76—implementing a recommended or determined SOAR workflow from the planning choices, SOAR workflow is a predefined sequence of actions and automated tasks that are executed in response to a cybersecurity incident, SOAR workflow manager implements each workflow triggered by attacker intercept manager].
Per claim 4, CRABTREE et al and JOSHI et al teach the method of claim 3, JOSHI et al further teach wherein the element includes an action initiated by personnel staffing a security operations center [paras 0246, 0278—receiving commands from a security administrator].
Per claim 5, CRABTREE et al and JOSHI et al teach the method of claim 3, CRABTREE et al further teach wherein the element includes an action initiated by a separate AI system [paras 0010-12, 0025—AI automated planner enhanced SOAR workflow].
Per claim 6, CRABTREE et al and JOSHI et al teach the method of claim 5, CRABTREE et al further teach wherein the separate AI system is distinct from the SOAR platform [para 0008—AI planner to determine the prospective cyberattack type].
Per claim 7, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further wherein the one or more cybersecurity actions are implemented in response to an input from the plurality of cybersecurity threat protection applications [paras 0029, 0031-35, 0071, 0075—a predefined sequence of actions and automated tasks that are executed in response to a cybersecurity incident, data input used for automated vulnerability discovery techniques].
Per claim 8, CRABTREE et al and JOSHI et al teach the method of claim 7, further wherein in response to the analyzing, the method further comprises automatically triggering a remedial step action suggestion to be performed by personnel staffing a security operations center, wherein the remedial step action suggestion is provided to and displayed at a computing device of the personnel [JOSHI et al: paras 0246, 0278, 0339—recommended remedial action, receiving commands from a security administrator; CRABTREE et al: paras 0075, 0106—remediation and recovery].
Per claim 9, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the workflow relevance includes identifying a recidivistic security operations center human response to the one or more cybersecurity actions [paras 0029-30, 0079, 0093, 0095, 0101—analyzing network logs and traffic patterns to trace the path of data and identify any anomalies or suspicious activities, identifying known attack pattern or anomalous behaviors, an alert is generated to notify security administrators of a potential security incident, security vendors and organizations continuously research and develop new IPS signatures to improve detection and prevention capabilities, allowing administrators to detecting and mitigating attacks, and identify abnormal traffic patterns or unauthorized access attempts and facilitate compliance].
Per claim 10, CRABTREE et al and JOSHI et al teach the method of claim 9, CRABTREE et al further teach wherein the recidivistic security operations center human response is received as input from a computing device of personnel staffing a security operations center [paras 0029-30, 0079, 0093, 0095, 0101—analyzing network logs and traffic patterns to trace the path of data and identify any anomalies or suspicious activities, identifying known attack pattern or anomalous behaviors, an alert is generated to notify security administrators of a potential security incident, security vendors and organizations continuously research and develop new IPS signatures to improve detection and prevention capabilities, allowing administrators to detecting and mitigating attacks, and identify abnormal traffic patterns or unauthorized access attempts and facilitate compliance].
Per claim 11, CRABTREE et al and JOSHI et al teach the method of claim 9, CRABTREE et al further teach wherein automatically updating the cybersecurity workflow comprises updating the cybersecurity workflow to mimic the recidivistic security operations center human response [paras 0075-76, 0079—workflows can be created to updated IDS/IPS signatures to mitigate attacks to prevent further occurrence].
Per claim 12, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the automatically updating occurs in real time [paras 0030, 0094-95—monitoring network traffic and system activities in real-time to detect and prevent malicious activities, generation of alerts and triggering of immediate actions to prevent or mitigate attacks in real-time].
Per claim 13, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the automatically updating enables parallel remedial step execution in the cybersecurity workflow that was updated automatically [paras 0076—multiple workflows can be implemented either in series or in parallel to mitigate an attack, depending on a number of factors such as the type of attack, the type of users or devices affected, the number of users or devices affected, the criticality of users or devices affected, and other factors which may be indicated either by best practices or by the outputs of modeling and simulation engine based on user-level dependency graph].
Per claim 15, CRABTREE et al and JOSHI et al teach the method of claim 1, JOSHI et al further teach wherein the analyzing comprises evaluation of workflow quality [paras 0038-40, 0043, 0090-95—reputation, security and utility scoring to indicate quality].
Per claim 18, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the AI machine learning model is embedded in the SOAR platform and trained using data gathered by one or more instantiations of the SOAR platform [paras 0008-11, 0064-66—AI planner enhanced SOAR workflow].
Per claim 19, CRABTREE et al and JOSHI et al teach the method of claim 1, CRABTREE et al further teach wherein the AI machine learning model is accessed through an application program interface in the SOAR platform [paras 0034-35, 0121-122—API integration; JOSHI et al: paras 0045—API browser integration].
Per claim 20, CRABTREE et al and JOSHI et al teach the method of claim 1, JOSHI et al further teach wherein the cybersecurity workflow further comprises non-cybersecurity elements [paras 0112, 0120, 0189-196—physical security access, security policy, privacy and risk score, authentication, banking].
III. CLAIM 16 is rejected under 35 U.S.C. 103 as being unpatentable over CRABTREE et al (US 2025/0039228) in view of JOSHI et al (US 2022/0222089) and TISHBI et al (US 2025/0063063).
Per claim 16, CRABTREE et al and JOSHI et al teach the method of claim 15, as applied above, with CRABTREE et al further identifying abnormal traffic patterns or unauthorized access attempts [para 0101]; yet fail to explicitly teach wherein the evaluation of workflow quality is based on analysis of repeated incidents having been logged by a security operations center. TISHBI et al disclose identifying trends, such as repeated incidents [paras 0074, 0144].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention to combine the teachings of CRABTREE et al and JOSHI et al with TISHBI et al for provisioning the identification of repeated incidents for determining the quality/efficacy of the workflow, which is well-known in the art for identifying repeated, similar attributes of incidents that qualify as patterns for training the workflows.
IV. CLAIM 17 is rejected under 35 U.S.C. 103 as being unpatentable over CRABTREE et al (US 2025/0039228) in view of JOSHI et al (US 2022/0222089) and STEVENS (US 2025/0363035).
Per claim 17, CRABTREE et al and JOSHI et al teach the method of claim 15, as applied above with CRABTREE et al teaching simulation engine for testing [paras 0008-9, 0063, 0074], yet fail to explicitly teach the method wherein the evaluation of workflow quality is based on analysis of operation regression exercises related to a security operations center. STEVENS teaches incorporating regression testing to validate the system functionality [paras 0166-167].
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention to combine the teachings of CRABTREE et al and JOSHI et al with STEVENS for provisioning regression testing, which is well-known in the art for performing quality assurance of the system.
Conclusion
V. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 2024/0045928; US 2022/0150275; US 2024/0340306.
VI. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
VII. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KRISTIE D SHINGLES whose telephone number is (571)272-3888. The examiner can normally be reached on Monday-Thursday, 10am-7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal Divecha can be reached on 571-272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KRISTIE D SHINGLES/
Primary Examiner, Art Unit 2453