Detailed Action
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-13 are pending, claims 14 and 18 have been canceled, and claims 1, 5, 8, 10-13, 15, 17, 19 and 20 have been canceled.
In light of Applicant’s amendments consideration of claims 1, 5, 8, 10, 11,13, 14 and 20 under 35 USC 112 (f) have been withdrawn.
In light of Applicant’s amendments previous rejections of the 1, 5, 8, 10, 11,13, 14 and 20 under 35 USC 112 (a) and (b) have been withdrawn. However, claims are newly rejected under 35 USC 112 (a) for reason discussed in the office action below.
Response to Arguments
Applicant's arguments filed 07-16-2026 have been fully considered.
With respect to rejections of claims under 35 USC 101 applicant argues “The amended claim requires automatically generating executable threat hunt queries in a STIX pattern format and executing those queries on normalized organization data and normalized data logs associated with a computing infrastructure to detect cyber threats. Such operations involve processing structured cyber threat intelligence, generating machine-executable query syntax, and executing the generated queries across normalized enterprise data sources. These are computer-centric operations that require interaction with computing infrastructure and cannot practically be performed mentally or with pen and paper.”
The argument is not persuasive. The fact that the claimed operations are performed using computer does not establish that the underlying steps are not directed to an abstract idea. The generation and use of queries to select, organize, and evaluate information merely automate information processing activities using a computer. The selection or use of STIX as a format for representing the threat hunt query is likewise matter of organizing information according to a known format and can be performed by a human, e.g., by identifying the relevant threat information and expressing it using the corresponding STIX format. Likewise, reciting a STIX format and normalized data does not, without more, recite an improvement to the function of the computer or another particular technological improvement.
Applicant argues that “Moreover, the amended claim does not merely analyze or organize information. Instead, the claim recites a specific sequence of technical operations that transforms unstructured threat intelligence into executable threat hunt queries, executes the generated threat hunt queries on normalized organization data and normalized data logs associated with a computing infrastructure to detect cyber threats, and automatically performs a mitigation action to respond to, resolve, or mitigate the detected threat. Accordingly, the claim is directed to a specific machine-implemented cybersecurity workflow rather than a mental process.”.
The argument is not persuasive. The recitation of a particular sequence of information processing operations does not, by itself, remove the claim from the abstract idea exception. The transformation of unstructured threat intelligence into queries and execution of those queries constitute information processing to identify a threat. In the context of the claimed information processing operation, a human can review threat intelligence, organize the information into corresponding query criteria, apply those criteria to information to identify a threat, and determine an appropriate mitigation response. Further, although the claim recites automatically performing a mitigation action, the mitigation action is merely the result of the preceding information processing step and is not recited as providing an improvement to the computer technology or cybersecurity functionality.
Applicant asserts that “Therefore, for at least these reasons, Applicant respectfully submits that the amended independent claim 1 is not directed to an abstract idea under Prong One of Step 2A.”.
For the reasons set forth above, claim is directed at an abstract idea. The recited LLM based processing, STIX format query generation, execution of queries against the normalized data, and threat detection and mitigation amount to computer implemented information processing and do not as claimed recite a sufficient technological improvement to remove the claim form judicial exception.
Applicant argues that “As amended, claim 1 is directed to a specific technological solution for automating cyber threat operations within a computing infrastructure. Rather than merely collecting, organizing, or analyzing information, the claim recites a particular sequence of machine-implemented operations in which a first LLM converts unstructured threat content into structured data, one or more second LLMs automatically generate threat hunt queries in a Structured Threat Information eXpression (STIX) pattern format based on the structured data, the generated threat hunt queries are executed on normalized organization data and normalized data logs associated with the computing infrastructure, threats are dynamically detected based on execution of the threat hunt queries, and a mitigation action is automatically performed to respond to, resolve, or mitigate the detected threat. Accordingly, the amended claim applies any alleged abstract idea in a manner that is specifically directed to improving cybersecurity operations within a computing environment, rather than merely using a computer as a tool to perform data analysis.”
The argument is not persuasive. The recited operations, converting information into structured data, generating queries, executing the queries on normalized data, detecting threat, and performing mitigation action amount to collecting, transforming, analyzing and acting on information using generic computing components. Merely performing these information processing operations in the context of cybersecurity does not, by itself, integrate the recited abstract idea into a practical application. The claimed use of an LLM or STIZ format likewise does not change the nature of the underlying information processing operations.
Applicant argues that “The present specification describes the invention as addressing deficiencies in conventional Security Operations (SecOps) workflows, where security analysts manually review threat intelligence, operationalize the threat intelligence, perform threat hunting, and respond to detected threats. The disclosed system automates these technical operations by converting unstructured threat intelligence into structured information, automatically generating executable threat hunt queries, executing those queries across normalized enterprise data sources, dynamically detecting threats, and automatically performing mitigation actions. The specification further explains that the mitigation actions include responding to, resolving, and mitigating detected threats, including containment, eradication, recovery, updating firewall or intrusion prevention system (IPS) rules, deploying security patches, and changing system configurations. Thus, the claimed invention is directed to improving the operation and security of the computing infrastructure itself, rather than merely producing information for human consideration.”.
This argument is not persuasive because an asserted improvement described in the specification does not establish eligibility where the claims themselves do not recite a technological improvement to the operation of the computer infrastructure. The claimed detection and mitigation operation merely apply the result of the recited information processing to cybersecurity environment. Moreover, the alleged benefits of automating conventional SecOps activities do not demonstrate an improvement in the computer technology.
Applicant argues that “Moreover, the amended claim applies the recited operations in a manner that improves cybersecurity operations within a computing infrastructure, rather than merely analyzing or organizing information.”
The argument is not persuasive. Applying information processing to cybersecurity operation is merely an application of the identified information processing concept to a particular field. The limitation is directed to generating threat hunt queries, executing the queries, detecting threats, and performing a mitigation action, the limitation does not recite a particular improvement to the function of the computer itself. Rather, they define the desired result of using the processes information for cybersecurity purposes.
Applicant argues that “These limitations are directed to a specific technological implementation for automated threat detection and response and are integral to the claimed solution, rather than constituting insignificant extra-solution activity or mere field-of-use limitations.”
The argument is not persuasive. Characterizing the limitation as “integral” to the claimed solution does not establish that they integrate the abstract idea into a practical application. The claimed threat detection and response operations remain conventional uses of computer systems to process information and perform actions based on the processing. The claim does not recite a practical technical mechanism that improves functioning of the computing system or otherwise imposes a meaningful technological limitation beyond applying the information processing operation to cybersecurity.
Applicant argues that “As amended, claim 1 does not merely recite generic data collection or analysis. Rather, the claim requires converting unstructured threat content into structured data using a first Large Language Model (LLM), automatically generating threat hunt queries in a Structured Threat Information eXpression (STIX) pattern format using one or more second LLMs based on the structured data, executing the generated threat hunt queries on normalized organization data and normalized data logs associated with a computing infrastructure, dynamically detecting threats based on execution of the threat hunt queries, and automatically performing a mitigation action to respond to, resolve, or mitigate the detected threat. These limitations define a specific machine-implemented workflow for autonomously operationalizing threat intelligence and performing automated threat detection and response.”
The argument is not persuasive. The limitations, individually and in combination, are directed to receiving, transforming, generating, searching, evaluating information, followed by taking an action based on the resulting information. Merely specifying an LLM, STIX format, normalizing data, or automated execution does not recite an improvement to the functioning of the computer itself, but instead defines the manner in which the information is processed.
Further, characterizing the claimed steps as a “specific machine-implemented workflow” does not establish an integration of the alleged abstract idea into a practical application. The claimed workflow remains directed to information processing and threat analysis, with the computer merely being used as tool to perform those operations.
Applicant argues that “The Examiner has not established that the claimed ordered combination of operations was well-understood, routine, or conventional at the time of the invention. Even if individual components, such as processors, memory, or Large Language Models, were known, the claimed invention is directed to a particular integration of those components to automatically operationalize threat intelligence through machine-generated threat hunt queries executed on normalized enterprise data, followed by automated threat mitigation.”
The argument is not persuasive. The fact that the claim recites an ordered sequence of operations, or the at the operations are performed using an LLM, normalized enterprise data, STIX pattern, and automated mitigation, does not by itself establish that the claim recites a patent-eligible improvement. The claim limitations, considered individually and as an ordered combination, recite receiving and transforming threat information, generating queries, executing those queries against data, evaluating the results, and initiating a mitigation action. These are information processing operations performed using conventional computing resources. Also, the claimed arrangement does not improv the operation of the processor, memory, LLM or other computer components themselves. Nor does the claim require a particular improvement to the computer technology, such as a new model architecture, query execution technique, or mechanism for improving the operation of the enterprise system being analyzed. Instead, the claimed components are used for their ordinary functions to process threat related information and produce a result based on the information.
Applicant’s arguments with respect to rejections of claims under 35 USC 103 have been fully considered and are persuasive. The rejection of claims has been withdrawn.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement.
The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor, or joint inventor, had possession of the claimed invention at the time the application was filed. Particularly, the claims (1, 15 and 20) recite “Large Language Model” that allegedly is used for example to generate one or more threat hunt queries.
The specification, however, does not adequately disclose the specific model structure, common structural features, or algorithmic procedure by which the claimed LLM models perform the recited functions.
Stated differently, the disclosure treats the LLM models as a black box but does not explain with sufficient detail how the claimed function is achieved so as to demonstrate possession.
As explained in MPEP 2161.01 and reflected in the PTAB’s reasoning in the attached decision, for computer-implemented functional claim language, original claims may lack written description where they define the invention in functional terms specifying a desired result but the specification does not sufficiently describe how the function is performed or the result is achieved; it is not enough that one of ordinary skill could theoretically program or employ a model to achieve the function. See also Ariad Pharm., Inc. v. Eli Lilly & Co., 598 F.3d 1336 (Fed. Cir. 2010).
Further, there is a full-scope written description problem here as the claims are not limited to any particular model type or architecture and thus read on essentially any model capable of performing the recited functions, while the specification at most generically references to LLM. The disclosure therefore does not provide either a representative number of species commensurate with the breadth of the claimed genus or identifying common structural features that would allow one of ordinary skill in the art to recognize possession of the full scope. Under LizardTech, Inc. v. Earth Res. Mapping, Inc., 424 F.3d 1336 (Fed. Cir. 2005), disclosure of one way, or merely result-oriented examples, does not entitle applicant to claim any and all means for achieving the claimed objective. Accordingly, the specification does not reasonably convey possession of the full scope of the “large language model” limitations, and thus of the claimed invention as a whole.
Dependent claims 2-13, 16, 17 and 19 are rejected under 35 U.S.C. 112(a) for being dependent on the independent claims and including LLM model.
Claim Rejections - 35 USC § 101
835 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
The claims when analyzed under 2019 Revised Patent Subject Matter Eligibility Guidance, are directed to abstract idea. Claim 1 for example, recites a system and, therefore, is a process.
The claim recites the limitation of: “obtain … an unstructured data having threat content…
convert…the unstructured data into a structured data… execute… a threat hunt model to detect a presence of a threat to a computing infrastructure of an organization based on the structured data … generate…one or more threat hunt queries…executing the one or more threat hunt queries…dynamically detect… the threat based on the execution of the threat hunt queries… and automatically perform…a mitigation action …”. These limitations, under broadest reasonable interpretation are directed performance of the limitation by a human using pen and paper or in a human mind. That is, nothing in the claim element precludes the step from practically being performed by a human. For example, the claim encompasses a human obtaining/receiving on a piece of a paper unstructured data including threat content, converting the unstructured data into structured data by rewriting the unstructured data into a converted format, analyzing the converted structured data to identify unusual or threat data patterns, generating threat hut queries, detecting the threat based on analyzing the threat hunt quarries, and when threats detected performing a mitigation action such as reporting the detected threats to infected computing system of an organization.
Claim is further analyzed in step 2A prong 2, to evaluate whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by identifying whether there are any additional elements recited in the claim beyond the judicial exception, and evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. However, each of the remaining limitation (i.e., processor, memory, LLM) appears to be generic computer functions which do not constitute meaningful limitations that would amount to significantly more than the abstract idea. The combination of these additional element is no more than generic computer functions. Thus, even in combination, additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limitations on practicing the abstract idea.
Claim is additionally analyzed under Step 2B to evaluate whether the claim as a whole amount to significantly more than the recited exception, whether any additional element, or combination of additional elements, adds an inventive concept to the claim. When claims are evaluated under step 2B, it is no more than what is well-understood, routine, conventional activity in the field. The specification does not provide any indication anything other than a generic computer component. The mere “… “obtain … an unstructured data having threat content…
convert…the unstructured data into a structured data… execute… a threat hunt model to detect a presence of a threat…generating…one or more threat hunt queries…executing the one or more threat hunt queries…dynamically detect… the threat…and automatically perform…a mitigation action …”…” is a well-understood, routing and conventional function when it is claimed in a merely generic manner as it is here.
Independent claims 15 and 20 include limitations similar to the limitations of claim 1 and are rejected under 35 U.S.C. 101 as being directed to abstract idea for the same reasons discussed above with respect to claim 1.
Claim 2 recites, “…receive the unstructured data from the one or more external sources”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation is directed to data gathering and does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 3 recites, “…wherein the structured data is in a form of a knowledge graph”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea
Claim 4 recites, “… wherein the knowledge graph is based on a Structured Threat Information eXpression (STIX) format”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 5 recites, “… determine that the threat content is irrelevant for the organization by using the first LLM; and discard, via the threat intelligence integration module, the unstructured data responsive to a determination that the threat content is irrelevant for the organization”. The limitation is directed to an abstract idea that can be performed by a human or in human mind. A human could simply determine that threat content is irrelevant by for example looking at the threat content on a piece of paper; and discard unstructured data responsive to the determination. Claim does not recite additional elements that amounts to significantly more than the judicial exception.
Claim 6 recites, “…wherein the first LLM is trained by using a training dataset that is restricted to a predefined dataset”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 7 recites, “…convert the unstructured data into the structured data responsive to a determination that the threat content is relevant for the organization. The limitation is directed to an abstract idea that can be performed by a human or in human mind. Claim does not recite additional elements that amount to significantly more than the judicial exception.
Claim 8, recites, “… select the threat hunt model from a plurality of threat hunt models based on the structured data; and execute the threat hunt model responsive to the selection”. The limitation is directed to an abstract idea that can be performed by a human or in human mind. Claim does not recite additional elements that amount to significantly more than the judicial exception.
Claim 9 recites “…wherein the plurality of threat hunt models comprises an intel-based hunt model, a predictive hunt model, and a hypothesis-based hunt model”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 10 recites, “…obtain an organization data associated with the computing infrastructure; and normalize the organization data to form the normalized organization data”. The limitation of “obtaining an organization data…” is directed to data gathering and does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea. Additionally, normalizing the organization data to form a normalized organization data is an abstract idea that can be performed by a human or in human mind. Claim does not recite additional elements that amount to significantly more than the judicial exception.
Claim 11 recites, “…obtain a data logs associated with the computing infrastructure; and normalize the data log to form a normalized data log. The limitation is directed to an abstract idea that can be performed by a human or in human mind. A human could simply obtain a data log on a piece of paper and normalize the data logs. Claim does not recite additional elements that amount to significantly more than the judicial exception.
Claim 12 recites, “…wherein the normalized data log is associated with one or more of: an Endpoint Detection and Response (EDR) tool, a Security information and event management (SIEM) tool, or a customer specific data”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 13 recites, “…cause the processor to access the normalized organization data and the normalized data log”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 16 recites, “…wherein the structured data is in a form of a knowledge graph, and wherein the knowledge graph is based on a Structured Threat Information eXpression (STIX) format”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Claim 17 recites, “…selecting the threat hunt model from a plurality of threat hunt models based on the structured data, wherein the plurality of threat hunt models comprises an intel-based hunt model, a predictive hunt model, and a hypothesis-based hunt model; and executing the threat hunt model responsive to the selection”. The limitation is directed to an abstract idea that can be performed by a human or in human mind. Claim does not recite additional elements that amount to significantly more than the judicial exception.
Claim 19 recites…wherein the normalized data logs are associated with one or more of: an Endpoint Detection and Response (EDR) tool, a Security information and event management (SIEM) tool, or a customer specific data”. The limitation constitutes insignificant extra solution activity that is well-understood, routine, and conventional. The limitation does not integrate the abstract idea into a practical application because the limitation does not impose meaningful limits on practicing the abstract idea.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Ali Abyaneh whose telephone number is (571) 272-7961. The examiner can normally be reached on Monday-Friday from (8:00-5:00). If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone numbers for the organization where this application or proceeding is assigned as (571) 273-8300 Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/ALI S ABYANEH/ Primary Examiner, Art Unit 2437