DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Response to Amendment
The Amendment filed on 05/12/2026 has been entered.
The double patenting rejection of claims is maintained. The current amendment claims are not distinct from the conflicting application.
The rejection under 35 U.S.C 101 is maintained, see below.
Claims 1, 3, 8, 10 and 15, 17 are amended.
Claims 2, 9 and 16 are cancelled.
Claims 21-23 are new.
Claims 1, 3-8, 10-15 and 17-23 are pending of which claims 1, 8 and 15 are independent claims.
Response to Arguments
The applicant's arguments filed on 05/12/2026 have been fully considered.
The argument regarding to double patenting rejection is not persuasive and rejection based on the amended claims is made below.
The argument regarding to 101 rejection is not persuasive. The amended limit “analyzing network traffic among the plurality of configuration items to identify the one or more relationships” is still an abstract idea as the static network traffic recorded for the configuration items analyzed can be still performed my human with pen and paper. Further, limitation “calculating the service-level security threat score comprises determining, based on the one or more relationships, one or more algorithms to calculate the service-level security threat score using the one or more severity factors” as claimed can be also performed by human. Claims as amended do not integrate the abstract idea into a practical application, nor include additional elements that are sufficient to amount to significantly more than the judicial exception.
The argument regarding to 103 rejection is persuasive and the rejection is withdrawal.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Regarding claims 1, 8 and 15:
Applying the subject matter eligibility test, as outlined in MPEP 2106:
Step 1: Statutory Category
The claims fall within a statutory category. Claims 8-20 are considered “machines” based claims and claims 1-7 are considered “processes”. Thus, the analysis moves towards step 2A, prong one of the subject matter eligibility tests.
Step 2A, Prong One: Judicial Exception
The claims recite a judicial exception, specifically an abstract idea. For example, claims recite receiving results of a vulnerability analysis performed on plurality of configuration items (the configuration items represent computing devices deployed within the managed network and software applications installed on the computing devices) and added definition of the plurality of configuration items, analyzing network traffic among the plurality of configuration items to identify the one or more relationships; obtaining, from the results, one or more severity factors (severity factors indicating respective criticalities of one or more vulnerabilities of the configuration items) and calculating, based on the one or more severity factors, a service-level security threat score with relationship and algorithm. Such processes are akin to methods of organizing human activity, which have been recognized as abstract ideas. Thus, the analysis moves towards step 2A, prong two.
Step 2A, Prong Two: Integration into a Practical Application
The claims do not integrate the abstract idea into a practical application. The additional elements, such as “a managed network“, “computing devices”, “a networked service” do not impose any meaningful limits of on the abstract idea. The additional steps are recited at a high-level of generality (i.e., as a generic network computer performing a generic computer function/service) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Thus, the analysis moves towards step 2B.
Step 2B: Inventive concept
Finally, the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of “a managed network“, “computing devices”, “ a networked service” amount to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is “directed to” an abstract idea.
With respect to dependent claims 2–10 and 12–16, the additional limitations do not change the characterization of the claims as being directed to an abstract idea and do not amount to significantly more, as explained below.
Regarding Claim 3:
Specifies calculating a software-level security threat score by determining a count of the computing devices on which the particular software application is installed based on the one or more relationships; and calculating the software-level security threat score for the particular vulnerability of the particular software application based on the severity factor associated with the particular vulnerability and the count of computing devices. These are types of information for calculating threat score that does not change the abstract character of the idea or add significantly more.
Regarding Claim 4:
Specifies that the service-level security threat score is calculated based on an algorithm using software-level security threat scores of the one or more vulnerabilities of the configuration items. This further characterizes the information involved but remains within calculating security threat scores, an abstract idea.
Regarding Claim 5:
Specifies that a particular configuration item of the configuration items has a first vulnerability on a first type of software application and a second vulnerability on a second type of software application. Further define the particular configuration item does not change the abstract character of the idea or add significantly more.
Regarding Claim 6:
Recites calculating a configuration item-level security threat score for the particular configuration item based on the first vulnerability and the second vulnerability. This does not change the abstract character of the idea or add significantly more.
Regarding Claim 7:
Adds an additional vulnerability of the particular configuration item of the configuration item does not meaningfully limit the abstract idea.
Regarding Claim 21:
Adds determining an exploitability factor indicating a degree of ability to exploit the one or more vulnerabilities based on the one or more relationships, wherein the exploitability factor is associated with the one or more algorithms does not meaningfully limit the abstract idea.
Regarding Claim 22:
Adds the one or more relationships comprises a relationship between a first type of software application and a second type of software application does not meaningfully limit the abstract idea.
Regarding Claim 23:
Adds the one or more algorithms comprises a nonlinear algorithm determined based on the relationship does not meaningfully limit the abstract idea.
Dependent claims 10-14 and 17-20 are similar to claims 3-7 and therefore are rejected for the same rational as claims 3-7.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1, 3-4, 8, 10-11 and 15, 17-18 and 21 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 12,067,127 (hereinafter “PAT127”) in view of
Claims of PAT127 teaches every limitation of Claims 1, 8 and 15 except “analyzing network traffic among the plurality of configuration items to identify the one or more relationships”.
However, in an analogous art, DOYLE discloses analyzing network traffic among the plurality of configuration items to identify the one or more relationships ([0026]: one or more passive scanners 120 may be deployed within the network 100 to observe or otherwise listen to traffic in the network 100 … the model or topology built from the information obtained with the active scanners 110 and the passive scanners 120 may describe any network devices 140 and/or other assets 130 that are detected or actively running in the network 100, any services or client-side software actively running or supported on the network devices 140 and/or other assets 130, and trust relationships associated with the various network devices 140).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 with DOYLE so that the relationship of devices and services is determined based on analysis of network traffic. The modification would have allowed the system to build up relationship for further analysis.
Claims 3-4, 10-11 and 17-18 are rejected by claims of Patent No. 12,067,127 as presented in prior office action.
Regarding Claim 21, Claim of PAT127 as modified teaches determining an exploitability factor indicating a degree of ability to exploit the one or more vulnerabilities based on the one or more relationships, wherein the exploitability factor is associated with the one or more algorithms (PAT127, Claim 7, the security threat score is calculated based at least in part on an exploitability factor indicative of a skill level required to exploit the vulnerability and an exposure factor indicative of an ease of access to exploit the vulnerability).
Claims 5, 12 and 19 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 12,067,127 (hereinafter “PAT127”) in view of
Regarding Claims 5, 12 and 19, Claims of PAT127 as modified does not explicitly teach but Murthy discloses wherein a particular configuration item of the configuration items has a first vulnerability on a first type of software application and a second vulnerability on a second type of software application (Murthy - [0026]: The vulnerability assessment service 113 can be executed to perform various functions. For example, the vulnerability assessment service 113 can collect information from various vulnerability feeds 104 regarding particular vulnerabilities, as well as generate and store standardized vulnerability records 129 that synthesize this information. [0033]: The vulnerability feed 104 can represent a computing device or hosted service that is accessible via the network 106).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 and DOYLE with Murthy so that the vulnerabilities of a computer device are assessed. The modification would have allowed the system to determine vulnerabilities of related computer device.
Claims 6-7, 13-14 and 20 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 12,067,127 (hereinafter “PAT127”) in view of
Regarding Claims 6, 13 and 20, Claims of PAT127 as modified does not explicitly teach but Chen discloses comprising calculating a configuration item-level security threat score for the particular configuration item based on the first vulnerability and the second vulnerability (Cheng - [0047]: A risk reputation of an application can include a level or levels of vulnerability an application introduced in one or plurality of networks based on past operation of IoT devices in using the application to access network services through the one or plurality of networks).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 and DOYLE with Chen so that the application risk score includes different levels vulnerability. The modification would have allowed the system to be assessed based on the calculated score.
Regarding Claims 7 and 14, Claims of PAT127 as modified does not explicitly teach but Chen discloses wherein the particular configuration item of the configuration items has an additional vulnerability in an operating system associated with the particular configuration item (Cheng - [0045]: the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to device characteristics of the IoT device. Device characteristics of an IoT device include applicable characteristics of an IoT device itself. For example, device characteristics of an IoT device include a device type of an IoT device, applications, operating systems, and firmware used by an IoT device, a version of applications, operating systems).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 and DOYLE with Chen so that device characteristics includes an operating system. The modification would have allowed the system to enhance OS security.
Claim 22 is rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 12,067,127 (hereinafter “PAT127”) in view of
Regarding Claim 22, Claim of PAT127 as modified doesn’t explicitly teach but Keller discloses wherein the one or more relationships comprises a relationship between a first type of software application and a second type of software application (Ketireddy - [Col. 9, Line 18-20]: Components of the enterprise 185, such as ETL tools that provide information about software products and their relationships, may convey network-based service requests to the threat modeler 100 via one or more networks).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 and DOYLE with Ketireddy so that two types of software relationship is determined. The modification would have allowed the system to do analysis.
Claim 23 is rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 12,067,127 (hereinafter “PAT127”) in view of
Regarding Claim 23, Claim of PAT127 as modified doesn’t explicitly teach but discloses wherein the one or more algorithms comprises a nonlinear algorithm determined based on the relationship (Keller - [0143]: More than one algorithm may be used to match mutually exclusive parameters of the RF energy emission signature and then combine those using numerically weighted coefficients for each in a linear or nonlinear equation to yield a final overall score approximating the degree of match to an infected device).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT127 and DOYLE with Keller so that non-linear algorithm is used to determine relationship. The modification would have allowed the system to do analysis.
Claims 1,3, 8,10 and 15, 17, 21 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 11,423,155 (hereinafter “PAT155”) in view of
Claims of PAT155 teaches every limitation of Claims 1, 8 and 15 except “analyzing network traffic among the plurality of configuration items to identify the one or more relationships”.
However, in an analogous art, DOYLE discloses analyzing network traffic among the plurality of configuration items to identify the one or more relationships ([0026]: one or more passive scanners 120 may be deployed within the network 100 to observe or otherwise listen to traffic in the network 100 … the model or topology built from the information obtained with the active scanners 110 and the passive scanners 120 may describe any network devices 140 and/or other assets 130 that are detected or actively running in the network 100, any services or client-side software actively running or supported on the network devices 140 and/or other assets 130, and trust relationships associated with the various network devices 140).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 with DOYLE so that the relationship of devices and services. The modification would have allowed the system to build up relationship for further analysis.
Claims 3, 10 and 17 are rejected by claim 1 of PAT155.
Regarding Claim 21, Claim of PAT127 as modified teaches determining an exploitability factor indicating a degree of ability to exploit the one or more vulnerabilities based on the one or more relationships, wherein the exploitability factor is associated with the one or more algorithms (PAT155, Claims 4-6).
Claims 4-5, 11-12 and 18-19 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 11,423,155 (hereinafter “PAT155”) in view of
Regarding Claims 4, 11 and 18, Claims of PAT155 as modified does not explicitly teach but Murthy discloses wherein the service-level security threat score is calculated based on an algorithm using software-level security threat scores of the one or more vulnerabilities of the configuration items (Murthy - [0047]: calculate an enterprise-specific version of the vulnerability severity score 156. An enterprise-specific severity score can be calculated in any number of ways using a variety of factors. As a simple illustrative example, the vulnerability assessment service 113 can multiply the number of vulnerable client devices 103 by the vulnerability severity score 156 to generate an enterprise-specific severity score that represents the impact of a vulnerability on an enterprise).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Murthy so that service level vulnerability score is calculated based on the vulnerability severity score. The modification would have allowed the system to obtain service level thread score for enhancing security.
Regarding Claims 5, 12 and 19, Claims of PAT155 as modified does not explicitly teach but Murthy discloses wherein a particular configuration item of the configuration items has a first vulnerability on a first type of software application and a second vulnerability on a second type of software application (Murthy - [0026]: The vulnerability assessment service 113 can be executed to perform various functions. For example, the vulnerability assessment service 113 can collect information from various vulnerability feeds 104 regarding particular vulnerabilities, as well as generate and store standardized vulnerability records 129 that synthesize this information. [0033]: The vulnerability feed 104 can represent a computing device or hosted service that is accessible via the network 106).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Murthy so that the vulnerabilities of a computer device are assessed. The modification would have allowed the system to determine vulnerabilities of related computer device.
Claims 6-7, 13-14 and 20 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 11,423,155 (hereinafter “PAT155”) in view of
Regarding Claims 6, 13 and 20, Claims of PAT155 as modified does not explicitly teach but Chen discloses comprising calculating a configuration item-level security threat score for the particular configuration item based on the first vulnerability and the second vulnerability (Cheng - [0047]: A risk reputation of an application can include a level or levels of vulnerability an application introduced in one or plurality of networks based on past operation of IoT devices in using the application to access network services through the one or plurality of networks).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Murthy so that the application risk score includes different levels vulnerability. The modification would have allowed the system to be assessed based on the calculated score.
Regarding Claims 7 and 14, Claims of PAT155 as modified does not explicitly teach but Chen discloses wherein the particular configuration item of the configuration items has an additional vulnerability in an operating system associated with the particular configuration item (Cheng - [0045]: the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to device characteristics of the IoT device. Device characteristics of an IoT device include applicable characteristics of an IoT device itself. For example, device characteristics of an IoT device include a device type of an IoT device, applications, operating systems, and firmware used by an IoT device, a version of applications, operating systems).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Chen so that device characteristics includes an operating system. The modification would have allowed the system to enhance OS security.
Claim 22 is rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 11,423,155 (hereinafter “PAT155”) in view of
Regarding Claim 22, Claim of PAT155 as modified doesn’t explicitly teach but Keller discloses wherein the one or more relationships comprises a relationship between a first type of software application and a second type of software application (Ketireddy - [Col. 9, Line 18-20]: Components of the enterprise 185, such as ETL tools that provide information about software products and their relationships, may convey network-based service requests to the threat modeler 100 via one or more networks).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Ketireddy so that two types of software relationship is determined. The modification would have allowed the system to do analysis.
Claim 23 is rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over U.S. Patent No. 11,423,155 (hereinafter “PAT155”) in view of20200210590, hereinafter DOYLE) and Keller et al. (US 2016/0098561, hereinafter Keller) as obviousness type double patenting.
Regarding Claim 23, Claim of PAT155 as modified doesn’t explicitly teach but discloses wherein the one or more algorithms comprises a nonlinear algorithm determined based on the relationship (Keller - [0143]: More than one algorithm may be used to match mutually exclusive parameters of the RF energy emission signature and then combine those using numerically weighted coefficients for each in a linear or nonlinear equation to yield a final overall score approximating the degree of match to an infected device).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of PAT155 and DOYLE with Keller so that non-linear algorithm is used to determine relationship. The modification would have allowed the system to do analysis.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1, 3-8, 10-15 and 17-23 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Specifically, claims 1, 8 and 15 recite “calculating the service-level security threat score comprises determining, based on the one or more relationships, one or more algorithms to calculate the service-level security threat score”, the specification lacks a detailed description of any algorithmic details based on relationships. As a result, the disclosure does not appear to show possession of the full breadth of the claimed algorithm based on the relationship.
claim 21 recite “wherein the exploitability factor is associated with the first algorithm”, the specification lacks a detailed description of any algorithmic details. As a result, the disclosure does not appear to show possession of the full breadth of the claimed algorithm based on the relationship.
claim 23 recite “wherein the one or more algorithms comprises a nonlinear algorithm determined based on the relationship”, the specification lacks a detailed description of any algorithmic details nore nonlinear algorithm based on the relationship. As a result, the disclosure does not appear to show possession of the full breadth of the claimed algorithm based on the relationship.
Claims that depend on rejected base claims (i.e. claims 1, 8. 15) inherit by the nature of their dependency all rejections that are applied to their corresponding base claims. Thus, claims 2-7, 10-14 and 17-23 are, in addition to any separate rejection disclosed above, also rejected using the same grounds of rejection as indicated in the rejection of their corresponding base claims above.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing
out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the
invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly
claiming the subject matter which the applicant regards as his invention.
Claims 1, 3-8, 10-15 and 17-23 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 8 and 15:
The claims recite As a result, the disclosure does not appear to show possession of the full breadth of the claimed algorithm based on the relationship.
“calculating the service-level security threat score comprises determining, based on the one or more relationships, one or more algorithms to calculate the service-level security threat score”, without providing sufficient detail to inform, with reasonable certainty, those skilled in the art about the scope of the invention. Specifically, the claim language lacks clarity regarding how the service-level security threat score algorithm is determined based on relationships.
The claims also recite limitation such as “the plurality of configuration items are used by the managed network to provide a networked service implemented by the plurality of configuration items and one or more relationships therebetween”. It’s unclear what “one or more relationships therebetween” mean. Is the relationship between configuration items or between networked service and configuration item.
Claim 21 is rejected because limitation “wherein the exploitability factor is associated with the one or more algorithms”, without providing sufficient detail to inform, with reasonable certainty, those skilled in the art about the scope of the invention. Specifically, the claim language lacks clarity regarding how the exploitability factor is associated with the one or more algorithms.
As established in Nautilus, Inc. v. Biosig Instruments, Inc., 572 U.S. 898, 901, 910, 110 USPQ2d 1688, 1693 (2014), a claim is indefinite if, when read in light of the specification and the prosecution history, it fails to inform, with reasonable certainty, those skilled in the art about the scope of the invention. Additionally, MPEP § 2173.02 emphasizes that claims must be clear and precise to delineate the metes and bounds of the subject matter to be protected.
Claims that depend on rejected base claims (i.e. claims 1, 8. 15) inherit by the nature of their dependency all rejections that are applied to their corresponding base claims. Thus, claims 2-7, 10-14 and 17-23 are, in addition to any separate rejection disclosed above, also rejected using the same grounds of rejection as indicated in the rejection of their corresponding base claims above.
Allowable Subject Matter
Claims 1, 3-8, 10-15 and 17-23 would be allowable if the 101, 112a, 112b and double patenting rejection, set forth in this Office action, are overcome. The reason for allowance will be furnished upon allowance of the application.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
DiCorpo et al. (Patent No.: US 10,158,677) - Automated mitigation of electronic message based security threats
Grieco et al. (Pub. No.: US 2016/0232358) - Information Technology Vulnerability Assessment
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MENG LI whose telephone number is (571)272-8729. The examiner can normally be reached M-F 8:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MENG LI/
Primary Examiner, Art Unit 2437