Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is in response to the amendment and argument field on 5 April 2026.
2. Claim 6 has been cancelled.
3. Claim 21 newly added.
4. Claims 1 and 16 have been amended.
5. Claims 1-5, 7-21 remain Pending and Rejected.
Responses to the Argument
6. The applicant’s arguments filed on 5 April 2026 are moot in view of new ground of rejection rendered.
Claim Rejections - 35 USC § 103
7. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5 and 7-21 are rejected under 35 U.S.C §103 as being unpatentable over Agarwwal et al. (US Publication No. 20210294901), hereinafter Agarwwal and in view of Lotem et al. (US Publication No. 20060218640), hereinafter Lotem.
Regarding claim 1:
A risk determination system, comprising one or more processors, and a memory, wherein the memory has stored therein a plurality of instructions, that when run by the one or more processors cause the one or more processors to perform a plurality of steps, the steps comprising (Agarwwal, ¶16):
receiving incident information associated with an item, the incident information comprising information regarding detected anomalous behavior in the item or information regarding a detected vulnerability in the item (Agarwwal, ¶245, ¶75).
Agarwwal does not explicitly suggest, based at least in part on the received incident information, identifying one or more attack steps of one or more of a plurality of attack paths stored in an attack path database, each of the one or more attack paths associated with a respective one of a plurality of assets contained within the item, wherein each of the identified one or more attack steps is associated with the anomalous behavior or vulnerability; however in a same field of endeavor Lotem discloses this limitation (Lotem, ¶9, ¶135, ¶51, ¶20).
for each respective asset, adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset (Agarwwal, ¶110, ¶148).
and for each respective asset, outputting information associated with the adjusted one or more respective risk levels, wherein each attack step of each of the plurality of attack paths stored in the attack path database is an action that an attacker has to perform as part of a cyber-attack (Agarwwal, ¶148, ¶158, ¶82-84).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of cyberattack detection of Agarwwal with the identifying step of attack disclosed in Lotem because to have better intrusion detection and prevention, stated by Lotem at para.14.
Regarding claim 2:
wherein each of the one or more attack paths comprises a portion of a respective attack tree (Agarwwal, FIG.17, ¶172).
Regarding claim 3:
wherein, for each of the identified attack steps, the steps further comprise adjusting a feasibility rating of the respective attack step, and wherein the adjustment of the one or more respective risk levels is based at least in part on the adjusted feasibility rating of the respective attack step (Agarwwal, ¶222).
Regarding claim 4:
wherein the identification of one or more attack steps of one or more attack paths associated with a respective asset is based at least in part on a software bill of material (SBOM) associated with the respective asset (Agarwwal, ¶82-84).
Regarding claim 5:
wherein the identification of each attack step is based at least in part on a linguistic analysis associated with a textual description contained within the received incident information and a textual description contained within the respective attack step (Agarwwal, ¶134).
Regarding claim 6:
wherein the steps further comprise: loading a template database comprising data regarding a plurality of templates, each template comprising information regarding an associated resource and information regarding one or more attack steps associated with the respective resource; associating the respective attack step to a respective one of the plurality of templates, wherein the associating to the respective template comprises a respective linguistic comparison of the textual description of the respective attack step to one or more of the plurality of templates; performing a linguistic comparison of the textual description of the received incident information to one or more of the plurality of templates; and based at least in part on an outcome of the performed linguistic comparison of the textual description of the received incident information, matching the received incident information to one of the plurality of templates, wherein the identification of the respective attack step is based at least in part on the association of the respective attack step with the matched template (Agarwwal, ¶178, ¶180, 84).
Regarding claim 7:
wherein the steps further comprise: loading a control database comprising data regarding a plurality of security controls, each of the plurality of security controls associated with a respective attack step of the attack path database; and for each identified attack step, outputting an identifier of the respective security control associated with the respective identified attack step (Agarwwal, ¶84, ¶182).
Regarding claim 8:
wherein the received incident information comprises information regarding a vulnerability in a respective resource, wherein the steps further comprise: loading a control database comprising data regarding a plurality of security controls; loading an implementation database comprising a plurality of security control implementations, each of the plurality of security controls associated with one or more of the plurality of security control implementations; and identifying one or more of the plurality of security control implementations associated with the respective resource, and wherein the adjustment of the one or more risk levels is based at least in part on the identified one or more security control implementations (Agarwwal, ¶73).
Regarding claim 9:
wherein the steps further comprise, for at least one of the identified attack steps, identifying one or more alternative attack steps of the respective attack path that the treatment thereof will treat the respective attack path (Agarwwal, ¶187).
Regarding claim 10:
wherein the steps further comprise, for each of the identified attack steps, determining whether previous attack steps within the respective attack path were performed, and wherein the adjustment of the one or more risk levels is based at least in part on the determination that previous attack steps within the attack path were performed (Agarwwal, ¶4, ¶95).
Regarding claim 11:
wherein the steps further comprise receiving information output by one or more security sensors, the determination whether previous attack steps within the respective attack path were performed based at least in part on the received information output by the one or more security sensors over a predetermined time period (Agarwwal, ¶168).
Regarding claim 12:
wherein the steps further comprise prioritizing the received incident information based at least in part on the determination whether previous attack steps within the respective attack path were performed (Agarwwal, ¶178).
Regarding claim 11:
wherein the steps further comprise prioritizing the received incident information based at least in part on the number of identified attack steps and/or the number of identified attack paths containing the identified one or more attack steps (Agarwwal, ¶177).
Regarding claim 14:
wherein the one or more respective risk levels are associated with the item, wherein the one or more respective risk levels are associated with the respective asset, and wherein the steps further comprise: comparing one or more permissions of the respective asset to the adjusted one or more respective risk levels; and based at least in part on an outcome of the comparison indicating that the one or more permissions are not allowed at the adjusted one or more respective risk levels, in accordance with a predetermined rule, generating an alert (Agarwwal, ¶84, ¶241).
Regarding claim 15:
wherein the one or more respective risk levels are associated with the item and the respective asset, wherein at least a subset of the plurality of assets are signal assets, and wherein the steps further: based at least in part on the one or more respective risk levels of each of the signal assets, generating signal priority data for the signal assets; outputting the generated signal priority data; based at least in part on the adjustment of the one or more risk level of one or more of the signal assets, adjusting the generated signal priority data; and outputting the adjusted signal priority data (Agarwwal, ¶110).
Regarding claim 16:
receiving incident information associated with an item, the incident information comprising information regarding detected anomalous behavior in the item or information regarding a detected vulnerability in the item (Agarwwal, ¶245, ¶75).
Agarwwal does not explicitly suggest, based at least in part on the received incident information, identifying one or more attack steps of one or more of a plurality of attack paths stored in an attack path database, each of the one or more attack paths associated with a respective one of a plurality of assets contained within the item, wherein each of the identified one or more attack steps is associated with the anomalous behavior or vulnerability; however in a same field of endeavor Lotem discloses this limitation (Lotem, ¶9, ¶135, ¶51, ¶20).
for each respective asset, adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset (Agarwwal, ¶110, ¶148).
and for each respective asset, outputting information associated with the adjusted one or more respective risk levels, wherein each attack step of each of the plurality of attack paths stored in the attack path database is an action that an attacker has to perform as part of a cyber-attack (Agarwwal, ¶148, ¶158, ¶82-84).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of cyberattack detection of Agarwwal with the identifying step of attack disclosed in Lotem because to have better intrusion detection and prevention, stated by Lotem at para.14.
Regarding claim 17:
wherein each of the one or more attack paths comprises a portion of a respective attack tree (Agarwwal, FIG.17, ¶172).
Regarding claim 18:
wherein, for each of the identified attack steps, the method further comprises adjusting a feasibility rating of the respective attack step, and wherein the adjustment of the one or more respective risk levels is based at least in part on the adjusted feasibility rating of the respective attack step (Agarwwal, ¶222).
Regarding claim 19:
wherein the identification of each attack step is based at least in part on a linguistic analysis associated with a textual description contained within the received incident information and a textual description contained within the respective attack step (Agarwwal, ¶222, ¶192).
Regarding claim 20:
further comprising: loading a control database comprising data regarding a plurality of security controls, each of the plurality of security controls associated with a respective attack step of the attack path database; and for each identified attack step, outputting an identifier of the respective security control associated with the respective identified attack step (Agarwwal, ¶222).
Regarding claim 21:
wherein the steps further comprise matching a description contained within the received incident information to a respective one of the plurality of attack paths, the matching based at least in part on a previous match of the respective attack path to a similar description, wherein the matched attack path is associated with a respective one of the plurality of assets contained within the item, and wherein the identified one or more attack steps are of the matched attack path (Agarwwal, ¶84, ¶184).
Conclusion
8. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (See form “PTO-892 Notice of reference cited).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONJUR RAHIM whose telephone number is (571)270-3890.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Monjur Rahim/
Patent Examiner
United States Patent and Trademark Office
Art Unit: 2436; Phone: 571.270.3890
E-mail: monjur.rahim@uspto.gov
Fax: 571.270.4890