DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
The present action is responsive to communications that was filed on 03/31/2026. Claims 1-5, 7-8, 14-15, and 20 are amended. 6, 13, and 19 are cancelled. Claims 1-5, 7-12, 14-18, and 20 are currently pending. Applicant arguments filed 03/31/2026 have been fully considered but they are not fully
persuasive. With regards to applicant’s arguments and amendments made regarding the rejections of claims 1-20 under 35 U.S.C. § 112 and 35 U.S.C. § 101, as seen on pages 8-15, are fully considered and persuasive.
Regards to applicant’s argument regarding the rejections of the claims under 35 U.S.C. § 103 on pg. 16-21:
“Brown teaches using its aggregated data 134 to train language models. Brown at 63:1-5. However, Brown's teaching of aggregated data, which is used for model training does not teach or suggest "preparing and transmitting language model inputs that include... instructions directing a language model to return an output identifying a next investigative action..." as recited in the Applicant's independent claim 1. The "instructions" in claim 1 clearly define a model inferencing task that is distinct from the model training tasks discussed by Brown. The Office Action maps the "instruction directing a language model to identify a next investigative action . . ." to Brown's teaching of back-end analysis functions 132 used to analyze vast amounts of aggregated data to detect patterns and anomalies. Brown at 63:1-25. However, Brown's teaching of back-end functions do not teach or suggest a "function list" provided to a language model in "language model inputs," as recited in the Applicant's independent claim 1. Further, Brown's training of language models to apply threat pattern recognition functions that are used to classify or score historical data do not teach or suggest "instructions" provided, during inference, to a language model as part of "language model inputs," as recited in the Applicant's independent claim 1. Accordingly, Brown does not teach or suggest "preparing and transmitting language model inputs that include ... a function list describing functions that execute different types of investigative operations; and instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list," as recited in the Applicant's independent claim 1.
Ahmed, which was not cited in the Office Action as purportedly teaching the language model inputs, also does not teach or suggest the above-recited features of the Applicant's independent claim 1 and does not cure the disclosure deficiencies of Brown discussed above. Ahmed teaches security threat detection and mitigation in a virtualized computing environment (Ahmed at 3:20-23), and does not disclose or suggest "preparing and transmitting language model inputs that include ... a function list describing functions that execute different types of investigative operations; and instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list," as recited in the Applicant's independent claim 1.
Accordingly, neither of Brown and Ahmed teaches or suggests the above-recited features. Further, the combination of Brown and Ahmed does not teach or suggest the above-recited features. Even assuming, arguendo, that the combination of Brown and Ahmed teaches using aggregated data to train language models (Brown), back-end functions including threat pattern recognition functions for classifying or scoring historical data (Brown), and security threat detection and mitigation in a virtualized computing environment (Ahmed), the combination does not teach or suggest the claimed "preparing and transmitting language model inputs that include ... a function list describing functions that execute different types of investigative operations; and instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list," as recited in the Applicant's independent claim 1.”
Applicant contends that Brown and Ahmed teaches or suggests the limitation "preparing and transmitting language model inputs that include ... a function list describing functions that execute different types of investigative operations; and instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list,". The examiner respectfully disagrees. Although the claims are interested in light of the specification, limitations from the specification from the specification are not read into the claims, see In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Brown does disclose the limitation of "preparing and transmitting language model inputs that include ... a function list describing functions that execute different types of investigative operations; and instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list,". As seen in the combination of Figure 3C, showing steps executing by security application 150 and/or multi-context threat assessment system 160, paragraphs 319-320 disclose, “… In step 350C, a set of analysis functions are selected to analyze risk assessment attributes 165 corresponding to the one or more detected content types… In step 360C, the security application 150 generates risk quantification data 170 based, at least in part, on the outputs of the analysis functions. This risk quantification data 170 may be transmitted to an end-user's computing device 110 and/or one or more external systems for usage in evaluating or mitigating any detected security threats or risks.” which implies a function list along with its investigative operations are being described with the emphasis of the resources being security resources. Further, as seen in paragraph 320 shows “more external systems for usage in evaluating or mitigating any detected security threats or risks” , showing an additional investigative operation could be performed. Therefore, based on the at least above paragraphs, Examiner respectfully maintains that Brown teaches the limitation.
Additionally, Applicant’s amendment with addressing the 35 U.S.C. § 103 with regarding Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1) Schmidtler et al. (US-20180013772-A1), and Roytman et al. (US-20240330481-A1) with respect to the independent claims, as seen in page 19, have been fully considered and persuasive. Therefore, the rejection has been withdrawn. However, upon, further consideration, a new ground of rejection is made in view Hasan et al. (US PGPub No. 20170214701-A1).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1 and 3 are rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1) and Hasan et al. (US PGPub No. 20170214701-A1).
With respect to claim 1, Brown teaches a threat investigation system comprising: a threat investigation agent stored in memory that performs investigative operations to investigate to a potential cyber security threat, the investigative operations comprising: (¶0031:As seen in a combination of Figure 1A and Figure 1B , the storage devices 101 may be physical, non-transitory mediums. The one or more storage devices 101 can store instructions associated with functions executed by the security application 150 (including, but not limited to any, functionality associated with the security learning 130, the language model 135, and/or the multi-context threat assessment system 160).);
preparing and transmitting language model inputs that include: known threat event information pertaining to the potential cyber security threat; (¶0361-0363: As seen in Figure 2E, some or all aggregated data 134 collected and stored by security application 150 may be utilized to fine-tine or train the one or more language model 135 to perform or execute various functions including, but limited to, back-end analysis functions 132 and/or end-user interaction functions 133. In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. )
a function list describing functions that execute different types of investigative operations; and (¶0359-0362: In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. By utilizing various algorithms and computational techniques, the back-end analysis functions 132 can provide deep insights into the nature and potential impact of various cybersecurity threats.);
instructions directing a language model to return an output identifying a next investigative action that the language model selects as appropriate based on the known threat event information and the function list; (¶0362-0366: One example of the back-end analysis functions 132 may include a threat pattern recognition function. This function can be configured to sift through historical security data to identify common characteristics of past cybersecurity incidents. By recognizing these patterns, the function can predict and flag potential future threats, enabling proactive measures to be taken before an actual breach or incident occurs.);
discovering additional threat event information by executing the next investigative action in response to receiving the output from the language model; (¶0368: In response to receiving prompts, the language model 135 may execute one or more NLP tasks 131 for analyzing, understanding, and/or interpreting the prompts and/or more NLP tasks 131 for generating prompts to the prompts. In generating these responses, the language model 135 may leverage the aggregated data 292 and/or a current state of data stored on the security application 150. In some scenarios, the responses can include risk quantification data 170 and/or other textual content that identify, quantify, or provide details on security threats or risks related to the prompts (additional threat event information) . The responses generated by the language model 135 can be returned, or transmitted to, the front-end of the security application 150 (e.g., for presentation on a system interface 151) and/or accessed via the API 148.);
Brown does not disclose:
updating the known threat event information to include the additional threat event information; and repeating the investigative operations subsequent to updating the known threat event information.
However, Ahmed teaches updating the known threat event information to include the additional threat event information; (¶0065: As illustrated in example, the method may also include (e.g., periodically and/or in response to detecting a security threat), classification data (may include the data upon which classification was dependent) for subsequent analysis and/or used update inference rules, and (optionally) returning the classification data to the customer. As further seen in ¶0025, the second activity may be to train a machine model (e.g., a machine learning engine) based on training data sets that associated with known good and bad behavior. In other words, the machine model may be trained recognize the patterns (within the extracted data) that represent malicious behavior, and the patterns (within the extracted data) that represent good communication (e.g., benign behavior). Once the machine model has been training, it may be fed unknown (e.g., classified) traffic patterns and, based on its training, may classify the traffic as malicious, good, or indifferent (e.g., benign).) and repeating the investigative operations subsequent to updating the known threat event information, (¶0066: The operations shown as 720-760 may be repeated, as appropriate while there are more potential threats and/or threat types to evaluate. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Ahmed of updating the known threat event information to the language model of Brown in order to mitigate security threats on a very large scale and reduce the latency between the time that an event takes place and the ability of the security platform to correctly classify malicious events and contains events (if the event represents malicious behavior) (Ahmed: ¶0024 & ¶0089).
Brown in view of Ahmed does not disclose:
wherein the threat investigation agent includes branching logic configured to, upon determining that the additional threat event information comprises multiple distinct entities, instantiate a plurality of sub-agents that store different subsets of the known threat event information in a respective working memory and concurrently iterate through the investigative operations based on the respective subset of information.
However, Hasan teaches wherein the threat investigation agent includes branching logic configured to, upon determining that the additional threat event information comprises multiple distinct entities, (¶00272: Referring the Self-Critical Knowledge Density 474 of Figure 70, incoming raw logs Incoming raw logs represent technical knowledge known by the SPMA 526. This module 474 estimates the scope and type of potential unknown knowledge that is beyond the reach of the reportable logs. This way the subsequent critical thinking features of CTMP can leverage the potential scope of all involved knowledge, known and unknown directly by the system. Perception Observer Emulator (POE) 475 produces an emulation of the observer and tests/compares all potential points of perception with such variations of observer emulations. The input is all of the potential points of perception in addition to the enhanced data logs (additional threat event).)
instantiate a plurality of sub-agents that store different subsets of the known threat event information in a respective working memory (¶0077: For, SCKD, Known Data Categorization (KDC) categorically separates known information from Input so that appropriate DB analogy query can be performed and separates the information into categories, wherein the separate categories individually provide input to the CVFG (Comparable Variable Format Generator) which outputs the categorical information in CVF format, which used by Storage Search to check for similarities for Known Data Scope DB, wherein each category is tagged with its relevant scope of known data according to the SS (Storage Search) results, where in the tagged scopes of unknown information per category are reassembled back into the same stream of original input at Unknown Data Combiner (UDC)) and concurrently iterate through the investigative operations based on the respective subset of information. (¶0299: Figure 112-115 display the Perception Observer Emulator (POE) 475. This module produces an emulation of the observer, and tests/compares all potential points of perception with such variations of observer emulations. . Whilst the input are all the potential points of perception plus the enhanced data logs; the output is the resultant security decision produced of such enhanced logs according to the best, most relevant, and most cautious observer with such mixture of selected perceptions. Input System Metadata 484 is the initial input that is used by Raw Perception Production (RP2) 465 to produce perceptions in the Comparable Variable Format CVF 547. With Storage Search (SS) 480 the CVF derived from the data enhanced logs is used as criteria in a database lookup of the Perception Storage (PS) 478. Logs 723 are the input logs of the system with the original security incident. The Self-Critical Knowledge Density (SCKD) 492 tags the logs to define the expected upper scope of unknown knowledge.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Hasan with regarding threat investigation agent includes branching logic of Brown in view of Ahmed in order to mitigate the risk of real data and/or devices becoming compromised and further analyze malware (Hasan: ¶0010-0014).
With respect to claim 3, the combination of Brown in view of Ahmed and Hasan teaches the system of claim 1 (see rejection of claim 1 above), wherein the output from the language model includes a function call to a function described within function list, (Brown ¶0319: As seen in Figure 3C, in step 350C, a set of analysis functions are selected to analyze risk assessment attributes 165 corresponding to the one or more detected content types.) the function call including a parameter identifying at least a portion of the known threat event information. (Brown ¶0319: The security application 150 can be configured with wide-ranging set of analysis functions, but only some of those functions may be applicable to the particular machine-readable code 145 under analysis. Thus, in step 350C, the security application 150 selects a relevant subset of analysis functions that are applicable to assessing the security threats or risks corresponding to the content types detected in decoded data 155.);
Claims 2, 15, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), Schmidtler et al. (US-20180013772-A1), and Roytman et al. (US-20240330481-A1) .
With respect to claim 2, the combination of Brown in view of Ahmed and Hasan teaches the agent of claim 1 (see rejection of claim 1 above), but does not disclose wherein preparing the language model inputs further comprise: generating an event vector encoding the known threat event information; and extracting contextually-relevant investigation guidance from a database by comparing the event vector to vectorized representations of portions of threat investigation reference materials, wherein the instructions direct the language model to use the contextually-relevant investigation guidance and the known threat event information to determine the next investigative action.
However, Schmidtler teaches wherein preparing the language model inputs further comprise: generating an event vector encoding the known threat event information; and (¶0029: Figure 3, the operation 306, one or more feature vectors may be created. In aspects, extracted static data may be used to generate a feature vector. Generating a feature vector may comprise, for example, grouping static data fields, and/or values, labeling identified anomalies, converting data into hex representations, building n-grams and/or word-grams and encapsulating special characters.);
extracting contextually-relevant investigation guidance [from a database] by comparing the event vector to vectorized representations of portions of threat investigation reference materials, (¶0035: At operation 308, features vectors may be scored. In aspects, scores or other values may be determined and assigned to a feature vector or one or data points in a feature vector. The scores or values may represent, for example, the security status of a file, the similarity between the feature vector and a predefined feature vector, whether the feature vector exceeds a threshold, the degree of similarity between the feature vector and known malicious content, the probability that the feature vector includes potentially unwanted content, an identified threat as a percentage of the analyzed file, unexpected content, etc.);
wherein the instructions direct the language model to use the contextually-relevant investigation guidance and the known threat event information to determine the next investigative action. (¶0037: In aspects, an action may be taken on the input based on the feature vector score and/or a determined security status for a file. In at least one aspect, if a feature vector score or value exceeds a predefined threshold or otherwise indicates that a file is not benign, input processing unit 200 may prevent the input from being transmitted to an intended recipient.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Schmidtler of generating event vector to the system of Brown in view of Ahmed and Hasan in order to better detect malware and to identify potentially malicious items (Schmidtler ¶0001-0003).
Brown in view of Ahmed, Hasan, and Schmidtler does not disclose:
extracting contextually-relevant investigation guidance from a database
Schmidtler does disclose extracting contextually-relevant investigation guidance and comparing the event vector but the prior art does not explicitly disclose the contextually-relevant investigation guidance being from a database. However, Roytman teaches extracting contextually-relevant investigation guidance from a database (¶0090: Some of the positions in the threat vector 116 can be assigned values corresponding to categories in a method of exploitation database 300, as illustrated in Figure 3. Additionally, some of the positions in the threat vector 116 can be assigned values corresponding to categories in the impact/scope of exploitation database.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Roytman of a database to the agent of Brown in view Ahmed, Hasan, and Schmidtler in order to keep up with the proliferation of vulnerabilities and to better efficiency for classification and triaging software vulnerabilities (Roytman: ¶0002).
With respect to claim 15, Brown teaches a tangible processor-readable storage media encoding instructions (¶0387-0388: A data processing system suitable for storing and/or executing program code may include at least one processor coupled directly or indirectly to memory elements through a system bus. The memory elements can include local memory employed during actual execution of the program code, bulk storage, and cache memories that provide temporary storage of at least some program code to reduce the number of times code is retrieved from bulk storage during execution.)
for executing a process for autonomously (¶0001: The present disclosure generally relates to the field of cybersecurity, and more specifically, to systems, methods, and apparatuses for assessing and quantifying security threats and risks associated with machine-readable codes and/or other types of digital data. As seen in Figure 1A and ¶0070, the API 158 may be utilized as an integration point for both automated systems and manual user queries alike.) investigating a potential cyber security threat, (Abstract: A security application comprises a multi-context threat assessment system configured to analyze a broad spectrum of risk assessment attributes across multiple contexts.);
preparing and transmitting language model inputs that include: the known threat event information; the contextually-relevant investigation guidance; (¶0361-0363: As seen in Figure 2E, some or all aggregated data 134 collected and stored by security application 150 may be utilized to fine-tine or train the one or more language model 135 to perform or execute various functions including, but limited to, back-end analysis functions 132 and/or end-user interaction functions 133. In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. )
a function list describing functions that execute different types of investigative operations; and (¶0359-0362: In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. By utilizing various algorithms and computational techniques, the back-end analysis functions 132 can provide deep insights into the nature and potential impact of various cybersecurity threats.);
instructions directing a language model to return an output identifying a next investigative action is selected as appropriate to advance based on the known threat event information, the contextually-relevant investigation guidance, and the function list; (¶0362-0366: One example of the back-end analysis functions 132 may include a threat pattern recognition function. This function can be configured to sift through historical security data to identify common characteristics of past cybersecurity incidents. By recognizing these patterns, the function can predict and flag potential future threats, enabling proactive measures to be taken before an actual breach or incident occurs.);
discovering additional threat event information by executing the next investigative action in response to receiving the output from the language model; (¶0368: In response to receiving prompts, the language model 135 may execute one or more NLP tasks 131 for analyzing, understanding, and/or interpreting the prompts and/or more NLP tasks 131 for generating prompts to the prompts. In generating these responses, the language model 135 may leverage the aggregated data 292 and/or a current state of data stored on the security application 150. In some scenarios, the responses can include risk quantification data 170 and/or other textual content that identify, quantify, or provide details on security threats or risks related to the prompts (additional threat event information) . The responses generated by the language model 135 can be returned, or transmitted to, the front-end of the security application 150 (e.g., for presentation on a system interface 151) and/or accessed via the API 148.);
Brown does not disclose:
the process comprising: generating an event vector encoding known threat event information pertaining to the potential cyber security threat; extracting contextually-relevant investigation guidance from a database based on a comparison between the event vector and vectorized representations of portions of threat investigation reference materials;
However, Schmidtler teaches the process comprising: generating an event vector encoding known threat event information pertaining to the potential cyber security threat; (¶0029: Figure 3, the operation 306, one or more feature vectors may be created. In aspects, extracted static data may be used to generate a feature vector. Generating a feature vector may comprise, for example, grouping static data fields, and/or values, labeling identified anomalies, converting data into hex representations, building n-grams and/or word-grams and encapsulating special characters.);
extracting contextually-relevant investigation guidance [from a database] based on a comparison between the event vector and vectorized representations of portions of threat investigation reference materials; (¶0035: At operation 308, features vectors may be scored. In aspects, scores or other values may be determined and assigned to a feature vector or one or data points in a feature vector. The scores or values may represent, for example, the security status of a file, the similarity between the feature vector and a predefined feature vector, whether the feature vector exceeds a threshold, the degree of similarity between the feature vector and known malicious content, the probability that the feature vector includes potentially unwanted content, an identified threat as a percentage of the analyzed file, unexpected content, etc.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Schmidtler of generating event vector to the storage media of Brown in view of Ahmed in order to better detect malware and to identify potentially malicious items (Schmidtler ¶0001-0003).
Brown in view of Schmidtler does not disclose:
extracting contextually-relevant investigation guidance from a database
Schmidtler does disclose extracting contextually-relevant investigation guidance and comparing the event vector but the prior art does not explicitly disclose the contextually-relevant investigation guidance being from a database. However, Roytman teaches extracting contextually-relevant investigation guidance from a database (¶0090: Some of the positions in the threat vector 116 can be assigned values corresponding to categories in a method of exploitation database 300, as illustrated in Figure 3. Additionally, some of the positions in the threat vector 116 can be assigned values corresponding to categories in the impact/scope of exploitation database.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Roytman of a database to the storage media of Brown in view Schmidtler in order to keep up with the proliferation of vulnerabilities and to better efficiency for classification and triaging software vulnerabilities (Roytman: ¶0002).
Brown in view of Schmidtler and Roytman does not disclose:
updating the known threat event information to include the additional threat event information; and subsequent to and based on updating of the known threat event information, repeating the process to autonomously identify and execute another instance of the next investigative action.
However, Ahmed teaches updating the known threat event information to include the additional threat event information; (¶0065: As illustrated in example, the method may also include (e.g., periodically and/or in response to detecting a security threat), classification data (may include the data upon which classification was dependent) for subsequent analysis and/or used update inference rules, and (optionally) returning the classification data to the customer. As further seen in ¶0025, the second activity may be to train a machine model (e.g., a machine learning engine) based on training data sets that associated with known good and bad behavior. In other words, the machine model may be trained recognize the patterns (within the extracted data) that represent malicious behavior, and the patterns (within the extracted data) that represent good communication (e.g., benign behavior). Once the machine model has been training, it may be fed unknown (e.g., classified) traffic patterns and, based on its training, may classify the traffic as malicious, good, or indifferent (e.g., benign).)and subsequent to and based on updating of the known threat event information, repeating the process to autonomously identify and execute another instance of the next investigative action. (¶0066: The operations shown as 720-760 may be repeated, as appropriate while there are more potential threats and/or threat types to evaluate. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Ahmed of updating the known threat event information to the language model of Brown in view of Schmidtler and Roytman in order to mitigate security threats on a very large scale and reduce the latency between the time that an event takes place and the ability of the security platform to correctly classify malicious events and contains events (if the event represents malicious behavior) (Ahmed: ¶0024 & ¶0089).
Brown in view of Schmidtler, Roytman, and Ahmed does not disclose:
conditionally instantiating multiple sub-agents in response to determining that the additional threat event information includes a multi-entity array, wherein different sub-agents of the multiple sub-agents store different subsets of the known threat event information in working memory and iteratively perform the investigative operations based on the different subsets of the known threat event information;
conditionally instantiating multiple sub-agents in response to determining that the additional threat event information includes a multi-entity array, wherein different sub-agents of the multiple sub-agents store different subsets of the known threat event information in working memory and iteratively perform the investigative operations based on the different subsets of the known threat event information;
However, Hasan teaches conditionally instantiating multiple sub-agents in response to determining that the additional threat event information includes a multi-entity array, (¶00272: Referring the Self-Critical Knowledge Density 474 of Figure 70, incoming raw logs Incoming raw logs represent technical knowledge known by the SPMA 526. This module 474 estimates the scope and type of potential unknown knowledge that is beyond the reach of the reportable logs. This way the subsequent critical thinking features of CTMP can leverage the potential scope of all involved knowledge, known and unknown directly by the system. Perception Observer Emulator (POE) 475 produces an emulation of the observer and tests/compares all potential points of perception with such variations of observer emulations. The input is all of the potential points of perception in addition to the enhanced data logs (additional threat event).)
wherein different sub-agents of the multiple sub-agents store different subsets of the known threat event information in working memory (¶0299: Figure 112-115 display the Perception Observer Emulator (POE) 475. This module produces an emulation of the observer, and tests/compares all potential points of perception with such variations of observer emulations. . Whilst the input are all the potential points of perception plus the enhanced data logs; the output is the resultant security decision produced of such enhanced logs according to the best, most relevant, and most cautious observer with such mixture of selected perceptions. Input System Metadata 484 is the initial input that is used by Raw Perception Production (RP2) 465 to produce perceptions in the Comparable Variable Format CVF 547. With Storage Search (SS) 480 the CVF derived from the data enhanced logs is used as criteria in a database lookup of the Perception Storage (PS) 478. Logs 723 are the input logs of the system with the original security incident. The Self-Critical Knowledge Density (SCKD) 492 tags the logs to define the expected upper scope of unknown knowledge.) and iteratively perform the investigative operations based on the different subsets of the known threat event information; (¶0077: For, SCKD, Known Data Categorization (KDC) categorically separates known information from Input so that appropriate DB analogy query can be performed and separates the information into categories, wherein the separate categories individually provide input to the CVFG (Comparable Variable Format Generator) which outputs the categorical information in CVF format, which used by Storage Search to check for similarities for Known Data Scope DB, wherein each category is tagged with its relevant scope of known data according to the SS (Storage Search) results, where in the tagged scopes of unknown information per category are reassembled back into the same stream of original input at Unknown Data Combiner (UDC));
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Hasan with regarding threat investigation agent includes branching logic of Brown in view of Schmidtler, Roytman, and Ahmed in order to mitigate the risk of real data and/or devices becoming compromised and further analyze malware (Hasan: ¶0010-0014).
With respect to claim 16, the combination of Brown in view of Schmidtler, Roytman, Ahmed, and Hasan teaches storage media of claim 15 (see rejection of claim 15 above) wherein the output from the language model includes a function call to a function described within the function list, (Brown ¶0319: As seen in Figure 3C, in step 350C, a set of analysis functions are selected to analyze risk assessment attributes 165 corresponding to the one or more detected content types.) the function call including a parameter identifying at least a portion of the known threat event information. (Brown ¶0319: The security application 150 can be configured with wide-ranging set of analysis functions, but only some of those functions may be applicable to the particular machine-readable code 145 under analysis. Thus, in step 350C, the security application 150 selects a relevant subset of analysis functions that are applicable to assessing the security threats or risks corresponding to the content types detected in decoded data 155.);
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), and Murphy et al. (US-20240291853-A1).
With respect to claim 4, the combination of Brown in view of Ahmed and Hasan teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein the instructions included in the language model inputs further instruct the language model to output a description of a software tool capable of performing the next investigative action in response to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action.
However, Murphy teaches wherein the instructions included in the language model inputs further instruct the language model to output a description of a software tool capable of performing the next investigative action in response ( ¶0135: Additionally, threat mitigation process 10 may identify 514 a comparative for at least one of the non-deployed security-relevant subsystems (e.g., a CDN subsystem, a WAF subsystem, a DAM subsystem; a UBA subsystem; an API subsystem, and an MDM subsystem) defined within the list of ranked & recommended security-relevant subsystems (e.g., non-deployed security-relevant subsystem list 550).) to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action. ( ¶0319-0144: Figure 12, and as will be explained below, threat mitigation process 10 may generate 608 comparison information 650 that compares the current security-relevant capabilities of computing platform 60 to the possible security-relevant capabilities of computing platform 60 to identify security-relevant deficiencies.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Murphy of a database to the system of Brown in view Ahmed and Hasan in order to prevent malware, allow continuous modifications to the system, and allow more precision to detect malware (Murphy: ¶0051-0066).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), Murphy et al. (US-20240291853-A1), and Sansom et al. (US-20240406195-A1).
With respect to claim 5, the combination of Brown in view of Ahmed, Hasan, and Murphy teaches the system of claim 4 (see rejection of claim 4 above), but does not disclose further comprising: a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action, wherein the threat investigation agent executes the software tool generated by the tool maker to discover the additional threat event information.
However, Sansom teaches further comprising: a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, ( ¶0229: The cyber-attack simulator 105 with its Artificial Intelligence trained on how to conduct and perform cyberattack in a simulation in either a simulator or in a clone creator spinning up virtual instances on virtual machines will take a sequence of actions ) the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action, ( ¶0193: The cyber-attack simulator 105 may be implemented via i) a simulator to model the system being protected and/or ii) a clone creator to spin up a virtual network and create a virtual clone of the system being protected configured to pentest one or more defenses provided by scores based on both the level of confidence that the cyber threat is a viable threat and the severity of the cyber threat (e.g., attack type where ransomware attacks has greater severity than phishing attack; degree of infection; computing devices likely to be targeted, etc.).) wherein the threat investigation agent executes the software tool generated by the tool maker to discover the additional threat event information. (¶0273: The simulated attack module 750, via a simulator and/or a virtual network clone creator, can be programmed to model and work out the key paths and devices in the system (e.g., a network, with its nets and subnets) via initially mapping out the system being protected and querying the cyber security appliance on specific's known about the system being protected by the cyber security appliance 100.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Sansom of a database to the system of Brown in view Ahmed, Hasan, and Murphy in order to prevent escalations of ongoing actual cyberattacks (Sansom: ¶0034).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Murphy et al. (US-20240291853-A1), Hasan et al. (US PGPub No. 20170214701-A1), and Yue et al. (US- US-8195953-B1).
With respect to claim 7, the combination of Brown in view of Ahmed and Hasan teaches the system of claim 1 (see rejection of claim 1 above),but does not disclose wherein the threat investigation agent is configured to instantiate a sub-agent that: iteratively executes the investigative operations based on a version of the known threat event information that is stored in working memory of the sub-agent; and self-terminates and reports investigative findings back to the threat investigation agent in response to receiving an output from the language model indicating that the next investigative action could not be identified.
However, Murphy teaches wherein the threat investigation agent is configured to instantiate a sub-agent that: iteratively executes the investigative operations based on a version of the known threat event information that is stored in working memory of the sub-agent; and (¶0195-0197: Referring also to Figure 21, threat mitigation process 10 may be configured to receive updated threat event information for security-relevant subsystems 226. For example, threat mitigation process 10 may receive 1100 updated threat event information 270 concerning computing platform 60, wherein updated threat event information 270 may define one or more of: updated threat listings; updated threat definitions; updated threat methodologies; updated threat sources; and updated threat strategies. Threat mitigation process 10 may enable 1102 updated threat event information 270 for use with one or more security-relevant subsystems 226 within computing platform 60. When enabling 1102 updated threat event information 270 for use with one or more security-relevant subsystems 226 within computing platform 60, threat mitigation process 10 may install 1104 updated threat event information 270 on one or more security-relevant subsystems 226 within computing platform 60.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Murphy of executing investigative operations based on a version of known threat event information to the system of Brown in view Ahmed in order to better protect against complex computer attacks (Murphy ¶0003-0004).
Brown in view of Ahmed, Hasan, and Murphy does not disclose:
self-terminates and reports investigative findings back to the threat investigation agent in response to receiving an output from the language model indicating that the next investigative action could not be identified.
However, Yue teaches self-terminates and reports investigative findings back to the threat investigation agent in response to receiving an output from the language model indicating that the next investigative action could not be identified. (¶0028: Because a particular computer program itself knows (or its developer knows) what is a normal, accepted set of behaviors and what is not, the present invention can take advantage of that knowledge and use it to detect when abnormal behavior is occurring. When the abnormal behavior occurs, it is likely that malicious software is at work and the present invention can choose to report the incident, terminate the malicious software or stop execution of the program itself. As further seen in ¶0069 and Figure 6B, step 556 determines if a mismatch occurs between the current behavior of the program and the accepted behaviors listed in the ability section. Action may result in operations or data being held up or termination of the program. If there is a mismatch then a warning will be issued as described above and action taken. In one embodiment, a warning includes sending an e-mail message to an anti-virus control center along with an attachment that includes the run-time state of the executing program. If the mismatch is relatively benign the program may be allowed to continue, but if risk is present the program may be terminated. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yue of self-terminating and reporting when there is no identification to the system of Brown in view Ahmed, Hasan, and Murphy in order to better detect malicious activities and to allow that static state and running condition to be examined (Yue ¶0012).
Claim 8 and 10 rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1), and Hasan et al. (US PGPub No. 20170214701-A1).
With respect to claim 8, Brown teaches a method for autonomously investigating a potential cyber security threat, the method comprising: (¶0001: The present disclosure generally relates to the field of cybersecurity, and more specifically, to systems, methods, and apparatuses for assessing and quantifying security threats and risks associated with machine-readable codes and/or other types of digital data. As seen in Figure 1A and ¶0070, the API 158 may be utilized as an integration point for both automated systems and manual user queries alike.);
preparing and transmitting a language model prompt that includes: (¶0072: In some examples, the security learning network 130 may comprise one or more language models (e.g., one or more large language models or LLMs) that are trained on security data that is aggregated and stored in one or more databases 159 of the security application. Additionally, in some cases, the language models may be configured with AI chatbot functionalities, enabling end-users or external systems to submit natural language prompts for querying the security application in connection with risk assessments.);
known threat event information pertaining to the potential cyber security threat; (¶0361-0363: As seen in Figure 2E, some or all aggregated data 134 collected and stored by security application 150 may be utilized to fine-tine or train the one or more language model 135 to perform or execute various functions including, but limited to, back-end analysis functions 132 and/or end-user interaction functions 133. In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. );
a function list describing functions that execute different types of investigative operations; (¶0359-0362: In certain embodiments, the back-end analysis functions 132 of the security learning network 130 can be designed to leverage the power of artificial intelligence and machine learning to enhance the security capabilities of the security application 150. These functions can be configured to analyze vast amounts of aggregated data 134 to detect patterns, anomalies, and trends associated with security threats or risks. By utilizing various algorithms and computational techniques, the back-end analysis functions 132 can provide deep insights into the nature and potential impact of various cybersecurity threats.);
and instructions directing a language model to return a first output identifying a next investigative action that the language model selects as appropriate to advance based on the known threat event information and the function list; (¶0362-0366: One example of the back-end analysis functions 132 may include a threat pattern recognition function. This function can be configured to sift through historical security data to identify common characteristics of past cybersecurity incidents. By recognizing these patterns, the function can predict and flag potential future threats, enabling proactive measures to be taken before an actual breach or incident occurs.);
discovering additional threat event information by executing the next investigative action; (¶0368: In response to receiving prompts, the language model 135 may execute one or more NLP tasks 131 for analyzing, understanding, and/or interpreting the prompts and/or more NLP tasks 131 for generating prompts to the prompts. In generating these responses, the language model 135 may leverage the aggregated data 292 and/or a current state of data stored on the security application 150. In some scenarios, the responses can include risk quantification data 170 and/or other textual content that identify, quantify, or provide details on security threats or risks related to the prompts (additional threat event information) . The responses generated by the language model 135 can be returned, or transmitted to, the front-end of the security application 150 (e.g., for presentation on a system interface 151) and/or accessed via the API 148.);
Brown does not disclose:
updating the known threat event information to include the additional threat event information; and subsequent to and based on the updating of the known threat event information,
However Ahmed, updating the known threat event information to include the additional threat event information; (¶0065: As illustrated in example, the method may also include (e.g., periodically and/or in response to detecting a security threat), classification data (may include the data upon which classification was dependent) for subsequent analysis and/or used update inference rules, and (optionally) returning the classification data to the customer. As further seen in ¶0025, the second activity may be to train a machine model (e.g., a machine learning engine) based on training data sets that associated with known good and bad behavior. In other words, the machine model may be trained recognize the patterns (within the extracted data) that represent malicious behavior, and the patterns (within the extracted data) that represent good communication (e.g., benign behavior). Once the machine model has been training, it may be fed unknown (e.g., classified) traffic patterns and, based on its training, may classify the traffic as malicious, good, or indifferent (e.g., benign).)
subsequent to and based on the updating of the known threat event information, repeating the method to instruct the language model to identify another instance of the next investigative action; and(¶0066: The operations shown as 720-760 may be repeated, as appropriate while there are more potential threats and/or threat types to evaluate. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Ahmed of updating the known threat event information to the language model of Brown in order to mitigate security threats on a very large scale and reduce the latency between the time that an event takes place and the ability of the security platform to correctly classify malicious events and contains events (if the event represents malicious behavior) (Ahmed: ¶0024 & ¶0089).
Brown in view of Ahmed does not disclose:
generating and transmitting a report summarizing investigative findings in response to receiving a second output indicating that the next investigative action could not be identified by the language model.
However, Yue teaches generating and transmitting a report summarizing investigative findings in response to receiving a second output indicating that the next investigative action could not be identified by the language model. (¶0028: Because a particular computer program itself knows (or its developer knows) what is a normal, accepted set of behaviors and what is not, the present invention can take advantage of that knowledge and use it to detect when abnormal behavior is occurring. When the abnormal behavior occurs, it is likely that malicious software is at work and the present invention can choose to report the incident, terminate the malicious software or stop execution of the program itself. As further seen in ¶0069 and Figure 6B, step 556 determines if a mismatch occurs between the current behavior of the program and the accepted behaviors listed in the ability section. Action may result in operations or data being held up or termination of the program. If there is a mismatch then a warning will be issued as described above and action taken. In one embodiment, a warning includes sending an e-mail message to an anti-virus control center along with an attachment that includes the run-time state of the executing program. If the mismatch is relatively benign the program may be allowed to continue, but if risk is present the program may be terminated. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yue of self-terminating and reporting when there is no identification to the method of Brown in view Ahmed in order to better detect malicious activities and to allow that static state and running condition to be examined (Yue ¶0012).
Brown in view Ahmed and Yue does not disclose:
conditionally instantiating multiple sub-agents in response to determining that the additional threat event information includes a multi-entity array, wherein different sub-agents of the multiple sub-agents store different subsets of the known threat event information in working memory and iteratively perform the investigative operations based on the different subsets of the known threat event information;
However, Hasan teaches conditionally instantiating multiple sub-agents in response to determining that the additional threat event information includes a multi-entity array, (¶00272: Referring the Self-Critical Knowledge Density 474 of Figure 70, incoming raw logs Incoming raw logs represent technical knowledge known by the SPMA 526. This module 474 estimates the scope and type of potential unknown knowledge that is beyond the reach of the reportable logs. This way the subsequent critical thinking features of CTMP can leverage the potential scope of all involved knowledge, known and unknown directly by the system. Perception Observer Emulator (POE) 475 produces an emulation of the observer and tests/compares all potential points of perception with such variations of observer emulations. The input is all of the potential points of perception in addition to the enhanced data logs (additional threat event).)
wherein different sub-agents of the multiple sub-agents store different subsets of the known threat event information in working memory (¶0299: Figure 112-115 display the Perception Observer Emulator (POE) 475. This module produces an emulation of the observer, and tests/compares all potential points of perception with such variations of observer emulations. . Whilst the input are all the potential points of perception plus the enhanced data logs; the output is the resultant security decision produced of such enhanced logs according to the best, most relevant, and most cautious observer with such mixture of selected perceptions. Input System Metadata 484 is the initial input that is used by Raw Perception Production (RP2) 465 to produce perceptions in the Comparable Variable Format CVF 547. With Storage Search (SS) 480 the CVF derived from the data enhanced logs is used as criteria in a database lookup of the Perception Storage (PS) 478. Logs 723 are the input logs of the system with the original security incident. The Self-Critical Knowledge Density (SCKD) 492 tags the logs to define the expected upper scope of unknown knowledge.) and iteratively perform the investigative operations based on the different subsets of the known threat event information; (¶0077: For, SCKD, Known Data Categorization (KDC) categorically separates known information from Input so that appropriate DB analogy query can be performed and separates the information into categories, wherein the separate categories individually provide input to the CVFG (Comparable Variable Format Generator) which outputs the categorical information in CVF format, which used by Storage Search to check for similarities for Known Data Scope DB, wherein each category is tagged with its relevant scope of known data according to the SS (Storage Search) results, where in the tagged scopes of unknown information per category are reassembled back into the same stream of original input at Unknown Data Combiner (UDC));
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Hasan with regarding threat investigation agent includes branching logic of Brown in view of Ahmed and Yue in order to mitigate the risk of real data and/or devices becoming compromised and further analyze malware (Hasan: ¶0010-0014).
With respect to claim 10, the combination of Brown in view of Ahmed, Yue, and Hasan teaches the method of claim 8 (see rejection of claim 8 above) wherein the first output from the language model includes a function call to a function described within the function list, (Brown ¶0319: As seen in Figure 3C, in step 350C, a set of analysis functions are selected to analyze risk assessment attributes 165 corresponding to the one or more detected content types.) the function call including a parameter identifying at least a portion of the known threat event information. (Brown ¶0319: The security application 150 can be configured with wide-ranging set of analysis functions, but only some of those functions may be applicable to the particular machine-readable code 145 under analysis. Thus, in step 350C, the security application 150 selects a relevant subset of analysis functions that are applicable to assessing the security threats or risks corresponding to the content types detected in decoded data 155.);
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1), Hasan et al. (US PGPub No. 20170214701-A1), Schmidtler et al. (US-20180013772-A1), and Roytman (US-20240330481-A1).
With respect to claim 9, Brown in view of Ahmed, Yue, and Hasan teaches the method of claim 8 (see rejection of claim 8 above), but does not disclose further comprising: generating an event vector encoding the known threat event information; and extracting contextually-relevant investigation guidance from a database by comparing the event vector to vectorized representations of portions of threat investigation reference materials, wherein the instructions direct the language model to use the contextually-relevant investigation guidance and the known threat event information to determine the next investigative action.
However, Schmidtler teaches further comprising: generating an event vector encoding the known threat event information; (¶0029: Figure 3, the operation 306, one or more feature vectors may be created. In aspects, extracted static data may be used to generate a feature vector. Generating a feature vector may comprise, for example, grouping static data fields, and/or values, labeling identified anomalies, converting data into hex representations, building n-grams and/or word-grams and encapsulating special characters.);
and extracting contextually-relevant investigation guidance from a [database] by comparing the event vector to vectorized representations of portions of threat investigation reference materials, (¶0035: At operation 308, features vectors may be scored. In aspects, scores or other values may be determined and assigned to a feature vector or one or data points in a feature vector. The scores or values may represent, for example, the security status of a file, the similarity between the feature vector and a predefined feature vector, whether the feature vector exceeds a threshold, the degree of similarity between the feature vector and known malicious content, the probability that the feature vector includes potentially unwanted content, an identified threat as a percentage of the analyzed file, unexpected content, etc.);
wherein the instructions direct the language model to use the contextually-relevant investigation guidance and the known threat event information to determine the next investigative action. (¶0037: In aspects, an action may be taken on the input based on the feature vector score and/or a determined security status for a file. In at least one aspect, if a feature vector score or value exceeds a predefined threshold or otherwise indicates that a file is not benign, input processing unit 200 may prevent the input from being transmitted to an intended recipient.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Schmidtler of generating event vector to the method of Brown in view of Ahmed, Yue, and Hasan in order to better detect malware and to identify potentially malicious items (Schmidtler ¶0001-0003).
Brown in view of Ahmed, Yue, Hasan, and Schmidtler does not disclose:
extracting contextually-relevant investigation guidance from a database
Schmidtler does disclose extracting contextually-relevant investigation guidance and comparing the event vector but the prior art does not explicitly disclose the contextually-relevant investigation guidance being from a database. However, Roytman teaches extracting contextually-relevant investigation guidance from a database (¶0090: Some of the positions in the threat vector 116 can be assigned values corresponding to categories in a method of exploitation database 300, as illustrated in Figure 3. Additionally, some of the positions in the threat vector 116 can be assigned values corresponding to categories in the impact/scope of exploitation database.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Roytman of a database to the method of Brown in view Ahmed, Yue, Hasan, and Schmidtler in order to keep up with the proliferation of vulnerabilities and to better efficiency for classification and triaging software vulnerabilities (Roytman: ¶0002).
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1), Hasan et al. (US PGPub No. 20170214701-A1), and Murphy et al. (US-20240291853-A1).
With respect to claim 11, the combination of Brown in view of Ahmed, Yue, and Hasan teaches the method of claim 8 (see rejection of claim 8 above) but does not disclose wherein the instructions further instruct the language model to first output a description of a software tool capable of performing the next investigative action in response to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action.
However, Murphy teaches wherein the instructions further instruct the language model to first output a description of a software tool capable of performing the next investigative action in response ( ¶0135: Additionally, threat mitigation process 10 may identify 514 a comparative for at least one of the non-deployed security-relevant subsystems (e.g., a CDN subsystem, a WAF subsystem, a DAM subsystem; a UBA subsystem; an API subsystem, and an MDM subsystem) defined within the list of ranked & recommended security-relevant subsystems (e.g., non-deployed security-relevant subsystem list 550).) to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action. ( ¶0319-0144: Figure 12, and as will be explained below, threat mitigation process 10 may generate 608 comparison information 650 that compares the current security-relevant capabilities of computing platform 60 to the possible security-relevant capabilities of computing platform 60 to identify security-relevant deficiencies.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Murphy of a database to the method of Brown in view Ahmed, Yue, and Hasan in order to prevent malware, allow continuous modifications to the system, and allow more precision to detect malware (Murphy: ¶0051-0066).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1), Hasan et al. (US PGPub No. 20170214701-A1), Murphy et al. (US-20240291853-A1), and Sansom et al. (US-20240406195-A1).
With respect to claim 12, the combination of Brown in view of Ahmed, Hasan, and Murphy teaches the method of claim 11 (see rejection of claim 11 above) further comprising: providing the description of the software tool capable of performing the next investigative action to a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action; receiving the software tool from the tool maker; and executing the software tool to discover the additional threat event information.
However, Murphy teaches further comprising: providing the description of the software tool capable of performing the next investigative action to a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, ( ¶0229: The cyber-attack simulator 105 with its Artificial Intelligence trained on how to conduct and perform cyberattack in a simulation in either a simulator or in a clone creator spinning up virtual instances on virtual machines will take a sequence of actions ) the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action; ( ¶0193: The cyber-attack simulator 105 may be implemented via i) a simulator to model the system being protected and/or ii) a clone creator to spin up a virtual network and create a virtual clone of the system being protected configured to pentest one or more defenses provided by scores based on both the level of confidence that the cyber threat is a viable threat and the severity of the cyber threat (e.g., attack type where ransomware attacks has greater severity than phishing attack; degree of infection; computing devices likely to be targeted, etc.).) receiving the software tool from the tool maker; and executing the software tool to discover the additional threat event information. (¶0273: The simulated attack module 750, via a simulator and/or a virtual network clone creator, can be programmed to model and work out the key paths and devices in the system (e.g., a network, with its nets and subnets) via initially mapping out the system being protected and querying the cyber security appliance on specific's known about the system being protected by the cyber security appliance 100.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Sansom of a database to the method of Brown in view Ahmed, Yue, Hasan, and Murphy in order to prevent escalations of ongoing actual cyberattacks (Sansom: ¶0034).
Claims 13 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Ahmed et al. (US-10320813-B1), Yue et al. (US-8195953-B1), Hasan et al. (US PGPub No. 20170214701-A1), Murphy et al. (US-20240291853-A1), and Sansom et al. (US-20240406195-A1).
With respect to claim 14, the combination of Brown in view of Ahmed, Yue, Hasan, Murphy, and Samson teaches the method of claim 12 (see rejection of claim 12 above) wherein the multiple sub-agents are individually configured to self-terminate and generate a report summarizing investigative findings in response to receiving the second output from the language model indicating that the next investigative action could not be identified. (Yue ¶0028: Because a particular computer program itself knows (or its developer knows) what is a normal, accepted set of behaviors and what is not, the present invention can take advantage of that knowledge and use it to detect when abnormal behavior is occurring. When the abnormal behavior occurs, it is likely that malicious software is at work and the present invention can choose to report the incident, terminate the malicious software or stop execution of the program itself. As further seen in ¶0069 and Figure 6B, step 556 determines if a mismatch occurs between the current behavior of the program and the accepted behaviors listed in the ability section. Action may result in operations or data being held up or termination of the program. If there is a mismatch then a warning will be issued as described above and action taken. In one embodiment, a warning includes sending an e-mail message to an anti-virus control center along with an attachment that includes the run-time state of the executing program. If the mismatch is relatively benign the program may be allowed to continue, but if risk is present the program may be terminated. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yue of the ability to self-terminate and report when there is no identification to the method of Brown in view Ahmed, Hasan, Murphy, and Samson in order to better detect malicious activities and to allow that static state and running condition to be examined (Yang ¶0012).
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Schmidtler et al. (US-20180013772-A1), Roytman et al. (US-20240330481-A1), Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), and Murphy et al. (US-20240291853-A1).
With respect to claim 17, the combination of Brown in view of Schmidtler, Roytman, Ahmed, and Hasan teaches storage media of claim 15 (see rejection of claim 15 above) but does not disclose wherein the instructions further instruct the language model to output a description of a software tool capable of performing the next investigative action in response to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action.
However, Murphy teaches wherein the instructions further instruct the language model to output a description of a software tool capable of performing the next investigative action in response ( ¶0135: Additionally, threat mitigation process 10 may identify 514 a comparative for at least one of the non-deployed security-relevant subsystems (e.g., a CDN subsystem, a WAF subsystem, a DAM subsystem; a UBA subsystem; an API subsystem, and an MDM subsystem) defined within the list of ranked & recommended security-relevant subsystems (e.g., non-deployed security-relevant subsystem list 550).) to determining that the function list does not describe an appropriate tool invokable to execute the next investigative action. ( ¶0319-0144: Figure 12, and as will be explained below, threat mitigation process 10 may generate 608 comparison information 650 that compares the current security-relevant capabilities of computing platform 60 to the possible security-relevant capabilities of computing platform 60 to identify security-relevant deficiencies.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Murphy of a database to the storage media of Brown in view of Schmidtler, Roytman, Ahmed, and Hasan in order to prevent malware, allow continuous modifications to the system, and allow more precision to detect malware (Murphy: ¶0051-0066).
Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Schmidtler et al. (US-20180013772-A1), Roytman et al. (US-20240330481-A1), Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), Murphy et al. (US-20240291853-A1), and Sansom et al. (US-20240406195-A1).
With respect to claim 18, the combination of Brown in view of Schmidtler, Roytman, Ahmed, Hasan, and Murphy teaches storage media of claim 17 (see rejection of claim 17 above) wherein the process further comprises: providing the description of the software tool to a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action; receiving the software tool from the tool maker; and executing the software tool to discover the additional threat event information.
However, Sansom teaches wherein the process further comprises: providing the description of the software tool to a tool maker trained on a corpus of executable code and corresponding descriptions of code functionality, ( ¶0229: The cyber-attack simulator 105 with its Artificial Intelligence trained on how to conduct and perform cyberattack in a simulation in either a simulator or in a clone creator spinning up virtual instances on virtual machines will take a sequence of actions ) the tool maker being configured to receive the description of the software tool and autonomously generate a software tool executable to carry out the next investigative action; ( ¶0193: The cyber-attack simulator 105 may be implemented via i) a simulator to model the system being protected and/or ii) a clone creator to spin up a virtual network and create a virtual clone of the system being protected configured to pentest one or more defenses provided by scores based on both the level of confidence that the cyber threat is a viable threat and the severity of the cyber threat (e.g., attack type where ransomware attacks has greater severity than phishing attack; degree of infection; computing devices likely to be targeted, etc.).) receiving the software tool from the tool maker; and executing the software tool to discover the additional threat event information. (¶0273: The simulated attack module 750, via a simulator and/or a virtual network clone creator, can be programmed to model and work out the key paths and devices in the system (e.g., a network, with its nets and subnets) via initially mapping out the system being protected and querying the cyber security appliance on specific's known about the system being protected by the cyber security appliance 100.);
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Sansom of a database to the storage media of Brown in view Ahmed, Schmidtler, Roytman, Hasan, and Murphy in order to prevent escalations of ongoing actual cyberattacks (Sansom: ¶0034).
Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Brown et al. (US-12149558-B1) in view of Schmidtler et al. (US-20180013772-A1), Roytman et al. (US-20240330481-A1), Ahmed et al. (US-10320813-B1), Hasan et al. (US PGPub No. 20170214701-A1), Murphy et al. (US-20240291853-A1), Sansom et al. (US-20240406195-A1), and Yue et al. (US-8195953-B1).
With respect to claim 20, the combination of Brown in view of Schmidtler, Roytman, Ahmed, Hasan, Murphy, and Samson teaches storage media of claim 18 (see rejection of claim 18 above) but does not disclose wherein the multiple sub-agents are individually configured to self-terminate and generate a report summarizing investigative findings in response to receiving an output from the language model indicating that the next investigative action could not be identified.
However, Yue teaches wherein the multiple sub-agents are individually configured to self-terminate and generate a report summarizing investigative findings in response to receiving an output from the language model indicating that the next investigative action could not be identified. (¶0028: Because a particular computer program itself knows (or its developer knows) what is a normal, accepted set of behaviors and what is not, the present invention can take advantage of that knowledge and use it to detect when abnormal behavior is occurring. When the abnormal behavior occurs, it is likely that malicious software is at work and the present invention can choose to report the incident, terminate the malicious software or stop execution of the program itself. As further seen in ¶0069 and Figure 6B, step 556 determines if a mismatch occurs between the current behavior of the program and the accepted behaviors listed in the ability section. Action may result in operations or data being held up or termination of the program. If there is a mismatch then a warning will be issued as described above and action taken. In one embodiment, a warning includes sending an e-mail message to an anti-virus control center along with an attachment that includes the run-time state of the executing program. If the mismatch is relatively benign the program may be allowed to continue, but if risk is present the program may be terminated. );
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention utilize the teachings of Yue of the ability of self-terminating and reporting when there is no identification to the storage media of Brown in view of Schmidtler, Roytman, Ahmed, Hasan, Murphy, and Samson in order to better detect malicious activities and to allow that static state and running condition to be examined (Yue ¶0012).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.P.V./ Examiner, Art Unit 2437
/MENG LI/ Primary Examiner, Art Unit 2437