Prosecution Insights
Last updated: August 17, 2026
Application No. 18/953,005

SYSTEM FOR AUTOMATED CYBERSECURITY ACTIONS AND DYNAMIC SECURITY POSTURE ADJUSTMENT

Non-Final OA §102§112
Filed
Nov 19, 2024
Priority
May 31, 2022 — provisional 63/347,389 +2 more
Examiner
LOPEZ, MIGUEL ALEXANDER
Art Unit
Tech Center
Assignee
As0001 Inc.
OA Round
1 (Non-Final)
7%
Grant Probability
At Risk
1-2
OA Rounds
1y 5m
Est. Remaining
18%
With Interview

Examiner Intelligence

Grants only 7% of cases
7%
Career Allowance Rate
2 granted / 29 resolved
-53.1% vs TC avg
Moderate +11% lift
Without
With
+11.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
23 currently pending
Career history
60
Total Applications
across all art units

Statute-Specific Performance

§101
6.9%
-33.1% vs TC avg
§103
34.6%
-5.4% vs TC avg
§102
22.6%
-17.4% vs TC avg
§112
34.2%
-5.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 29 resolved cases

Office Action

§102 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119(e) as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994). The disclosure of the prior-filed applications, Application Nos. 63/457,671, 63/347,389, and 18/203,630 fail to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. None of the relied upon applications provide adequate written description support for the claim limitations “implementing at least one safeguard in the at least one computing environment of the at least one entity” found in independent claims 1, 9, and 17. Application Nos. 63/457,671, 63/347,389 do not provide adequate written description support for the claim limitations “provide, to a third party computing system, a public address or a location corresponding with the security posture” found in claims 4, 12, and 20. Accordingly, claims 1- 20 are not entitled to the benefit of the prior-filed applications. Information Disclosure Statement The information disclosure statement (IDS) submitted on 11/19/2024, 12/05/2024, 12/19/2024, 03/07/2025, 12/04/2025, 03/18/2026, 05/03/2026, 05/12/2026, 07/10/2026, are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner. Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(4) because reference character “700” has been used to refer to different interfaces of Figures 7A-7J. Similarly, Figures 8A-8E utilize the same reference character “800” to refer to different interfaces, reference character “900” for Figures 9A-9H respectively, and so on. This deficiency is found in the following figures: Figures 7A-7J, 7L-7O, 8A-8E, 9A-9H, 10A-10E, 11A-11D, 13A-13E, 14A-14B, 15A-15G, 16A-16D, 18A-18C, 20A-20B, and 21A-21B with the respective reference characters 700, 800, 900, 1000, 1100, 1200, 1300, 1400, 1500, 1600, 1800, 2000, and 2100. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. The disclosure is objected to because of the following informalities: Paragraphs [0037] and [0041] refer to “Figure 1” generically, while there is no Figure 1 specifically, there is Figure 1A and Figure 1B. The citation to “Figure 1” should be amended such that it properly references the correct figures. Paragraphs [0049] refers to “FIGS. 2-49” while the originally filed figure numbers only go up to Figure 24. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 4, 12, and 20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Regarding Claims 4, 12, and 20: Dependent claims 4, 12, and 20 recite the limitations “provide, to a third party computing system, a public address or a location corresponding with the security posture; and verify the security posture using the public address or the location”. There is no support in the disclosure regarding how the inventor intended to perform these various claimed functionalities. The algorithm or steps/procedures for these claimed functions is not explained at all or is not explained in sufficient detail (simply restating the function recited in the claim is not necessarily sufficient) so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. The originally filed disclosure is silent with respect to how the inventor intended to have the claimed invention provide a “public address or a location” to a third party, nor how the claimed security posture is verified using the same. It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015). The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 4, 12, and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The term “public address or location” in claims 4, 12, and 20, is a relative term which renders the claim indefinite. The term “public” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. It is currently unclear what the public address or location actually refers to in the context of the claims in light of the disclosure, nor what would be considered a public or non-public address or location. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Berger et. al. (US Publication No. US 2023/0283521 A1) hereinafter Berger. Regarding Claims 1 and 9: Claim 9. Berger discloses a system for protecting data, the system comprising: one or more processing circuits configured to (Berger et. al. (US Publication No. US 2023/0283521 A1)): identify a security posture, the security posture comprising one or more configuration data, safeguard data, or remediation data (Berger Fig. 3, [0058] “The present disclosure is directed to a cybersecurity assessment system for monitoring, assessing, and addressing the cybersecurity status of a target network and/or a hierarchical group of target networks”, [0075], and [0077-0078] cybersecurity status interface enumerated); monitor environmental data corresponding with at least one computing environment (Berger Fig. 3, [0058] “The present disclosure is directed to a cybersecurity assessment system for monitoring, assessing, and addressing the cybersecurity status of a target network and/or a hierarchical group of target networks”; [0065-0066]; [0071] “As a further example, data stream unit 125C may be configured to generate cybersecurity vulnerability data identifying vulnerabilities in hardware and software components in a network environment, such as missing updates, unsecured ports, deprecated technology, and the like. This data stream may be referred to as ‘vulnerability data.’”); determine, in real-time, at least one vulnerability, threat, or security gap based at least on the environmental data and the security posture (Berger [0058] “The cybersecurity assessment system can also provide information regarding cybersecurity events in substantially real time”, [0076] “In some embodiments, portal interface 200 may also include cybersecurity event ticker 224. Cybersecurity event ticker 224 can present real-time alerts, warnings, and notifications of cybersecurity events and risks detected during continuous cybersecurity monitoring, event scanning, and vulnerability scanning. In some embodiments, ticker 224 displays cybersecurity event display objects 226A, 226B, 226C, 226D, and 226E in the order in which each event is detected by the cybersecurity assessment system 120. In some embodiments, selection of a cybersecurity event object—or the ticker 224 in general—may cause display of ticker interface 500, discussed in greater detail below. While the ticker 224 is portrayed as a component of portal interface 200, it will be appreciated that in some embodiments the alerts and warnings presented in ticker 224 may be transmitted to a client system on the target network 100, stored in a database within the cybersecurity assessment system 120, or transmitted to a remote device”); and in response to determining the at least one vulnerability, threat, or security gap, update, in real-time, the security posture by performing at least one of (i) updating at least one security configuration, (ii) implementing at least one safeguard in the at least one computing environment, (iii) performing at least one remediation action, or (iv) updating at least one security policy or document (Berger [0213] “At block 1975, the cybersecurity AI/ML service 1742 may provide information regarding the determined remediation(s). Illustratively, the information regarding the determined remediation(s) may be presented in any of a variety of modalities, such as: text-based and/or graphic-based presentations via a GUI; text-based output provided via a chatbot; audio output via a voice-based system using pre-recorded or synthesized speech; etc. The information may identify the highest-probability remediation(s), information about implementing the remediations, etc. In some embodiments, a recommended remediation may be automatically implemented without manual intervention”, [0259] “At block 2614, the computing system performing the process 2600 may update an overall assessment score (also referred to as the cybersecurity status score) for the target network. The update may be performed so that the cybersecurity status score for the target network reflects compliance or noncompliance with the objective evidenced by the artifact approved during process 2600. Subsequently, when a user accesses an interface to review cybersecurity status information, such as interfaces 300, 1400, and/or 2500, the cybersecurity status score that is displayed will reflect compliance or noncompliance with the objective”; [0261-0262]). Claims 1 and 17 contain substantially the same content and are therefore rejected under the same rationales. Berger further discloses a method for protecting data (Berger [0102], [0275], claim 1). Berger further discloses a non-transitory computer readable medium (CRM) comprising one or more instructions stored thereon and executable by one or more processors (Berger [0268-0269], [0275]) … receive cyberattack information and incident information (Berger [0171-0177], [0183] The cybersecurity system 1720 can also include at least a partially automated SOC 1744 to monitor applications to identify a possible cyber-attack or intrusion events). Regarding Claims 2, 10, and 18: Claim 10. Berger further discloses the system of claim 9, one or more processing circuits configured to (Berger [0217], [0268-0269], [0273-0274]): receive one or more requirements corresponding with at least one third party and with the at least one security configuration, the at least one safeguard, the at least one remediation action, or the at least one security policy or document (Berger [0069] “A single cybersecurity assessment system 120 may be configured to assess the cybersecurity status of any number of target networks 100. In some embodiments, a single target network 100 may be assessed by multiple cybersecurity assessment systems 120”, [0078] statistics regarding requirements compliance; [0098] “In some embodiments, the cybersecurity assessment system 120 may be configured to assess target networks for compliance with multiple distinct cybersecurity frameworks. Each cybersecurity framework may or may not share individual cybersecurity factors or subsets thereof with any number other cybersecurity frameworks. A single target network may be assessed for compliance with any or all of the cybersecurity frameworks available to the cybersecurity assessment system 120”); and update the at least one security configuration, the at least one safeguard, the at least one remediation action, or the at least one security policy or document based at least on the one or more requirements (Berger [0105] “Cybersecurity unit 140 can then analyze the data against a series of rules, such as: Is the model number the most recent model produced by the vendor? If so, apply a first adjustment, otherwise apply a second adjustment. Is the model still supported by the vendor? If so, apply a first adjustment, otherwise apply a second adjustment. Is the software version the most recent software version available for the model? If so, apply a first adjustment, otherwise apply a second adjustment. Does the model have critical unresolved vulnerabilities? If so, apply a first adjustment, otherwise apply a second adjustment. Is the firewall (or set of firewalls) configured to manage all traffic between devices of target network 100 and the internet? If so, apply a first adjustment, otherwise apply a second adjustment”; [0213], [0259], [0261-0262]); or implement by the one or more processing circuits, a new configuration, safeguard, remediation action, or security policy based at least on the one or more requirements (Berger [0105], [0213], [0259], [0261-0262]). Claims 2 and 18 contain substantially the same content and are therefore rejected under the same rationales. Regarding Claims 3, 11, and 19: Claim 11. Berger further discloses the system of claim 9, the one or more processing circuits configured to (Berger [0217], [0268-0269], [0273-0274]), in updating the security posture: update at least one of a set of cybersecurity attributes of the security posture (Berger [0213], [0259], [0261-0262]); and tokenize and broadcast the security posture in a distributed ledger or database (Berger [0176-0177]; [0214-0215]), the security posture corresponding with a verifiable proof of the security posture (Berger [0214-0215], [0257-0258] proof of compliance with a particular objective). Claims 3 and 19 contain substantially the same content and are therefore rejected under the same rationales. Regarding Claims 4, 12, and 20: Claim 12. Berger further discloses the system of claim 9, the one or more processing circuits configured to (Berger [0217], [0268-0269], [0273-0274]): provide, to a third party computing system, a public address or a location corresponding with the security posture (Berger [0214-0215] blockchain address to maintain “facts, solutions, threats, or remediation data or documents”); and verify the security posture using the public address or the location (Berger [0214-0215] blockchain address to maintain “facts, solutions, threats, or remediation data or documents”). Claims 4 and 20 contain substantially the same content and are therefore rejected under the same rationales. Regarding Claims 5 and 13: Claim 13. Berger further discloses the system of claim 9 (Berger [0217], [0268-0269], [0273-0274]), wherein performing the at least one remediation action comprises mitigating or eliminating the at least one vulnerability, threat, or security gap in the at least one computing environment (Berger [0213] “At block 1975, the cybersecurity AI/ML service 1742 may provide information regarding the determined remediation(s). Illustratively, the information regarding the determined remediation(s) may be presented in any of a variety of modalities, such as: text-based and/or graphic-based presentations via a GUI; text-based output provided via a chatbot; audio output via a voice-based system using pre-recorded or synthesized speech; etc. The information may identify the highest-probability remediation(s), information about implementing the remediations, etc. In some embodiments, a recommended remediation may be automatically implemented without manual intervention”, [0259] “At block 2614, the computing system performing the process 2600 may update an overall assessment score (also referred to as the cybersecurity status score) for the target network. The update may be performed so that the cybersecurity status score for the target network reflects compliance or noncompliance with the objective evidenced by the artifact approved during process 2600. Subsequently, when a user accesses an interface to review cybersecurity status information, such as interfaces 300, 1400, and/or 2500, the cybersecurity status score that is displayed will reflect compliance or noncompliance with the objective”; [0261-0262]), wherein mitigating or eliminating the at least one vulnerability, threat, or security gap comprises enforcing one or more cybersecurity policies or implementing one or more response measures (Berger [0213], [0259], [0261-0262]). Claim 5 contains substantially the same content and is therefore rejected under the same rationales. Regarding Claims 6 and 14: Claim 14. Berger further discloses the system of claim 9 (Berger [0217], [0268-0269], [0273-0274]), wherein monitoring the environmental data comprises monitoring at least one of network traffic in the at least one computing environment, at least one user action in the at least one computing environment, or at least one threat intelligence feed corresponding with the at least one computing environment (Berger [0071] monitoring data streams of the target network). Claim 6 contains substantially the same content and is therefore rejected under the same rationales. Regarding Claims 7 and 15: Claim 15. Berger further discloses the system of claim 9 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: generate a graphical user interface (GUI) comprising at least one interactable element (Berger Fig. 2-3 [0061], [0101]); and receiving, via the GUI responsive to receiving an interaction with the at least one interactable element, an input corresponding with at least one of (i) updating the at least one security configuration, (ii) implementing the at least one safeguard, (iii) performing the at least one remediation action, or (iv) updating the at least one security policy or document (Berger Fig. 2-3 and 27, [0061], [0101], [0140] use user interface to initiate a request, [0151], [0178], [0184], [0246-0248]). Claim 7 contains substantially the same content and is therefore rejected under the same rationales. Regarding Claims 8 and 16: Claim 16. Berger further discloses the system of claim 15 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: generate and activate a cybersecurity protection obligation of at least one third party (Berger [0126] “In some embodiments, different instances of the cybersecurity assessment system 120 may include different components and/or data stores. For example, instance 1120B may provide different functionality to one hierarchical group of target networks than instance 1120A provides to a different hierarchical group of target networks. The difference in functionality may be due to any of a variety of different factors, such as different service level agreements, different versions, different preferences of the entities for which the instance is being used to manage cybersecurity data, some combination thereof, etc. In such cases, application component 1122B may be different than application component 1122A (e.g., the code to be executed may be different, the hardware on which the code executes may be different etc.); object data store 1124B may be different than object data store 1124A (e.g., additional and/or alternative data objects may be obtained and stored based on different functionality of the instance); and/or configuration data store 1126B may be different than configuration data store 1126A (e.g., configuration data defining different access levels based on the different functionality of the instances, different structure or content of the data objects, etc.)”), wherein the cybersecurity protection obligation comprises a plurality of protection attributes (Berger [0126]). Claim 8 contains substantially the same content and is therefore rejected under the same rationales. Conclusion The prior art made of record in the submitted PTO-892 Notice of References Cited and not relied upon is considered pertinent to applicant’s disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MIGUEL A LOPEZ whose telephone number is (703)756-1241. The examiner can normally be reached 8:00AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached on 5712727624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /M.A.L./ Examiner, Art Unit 2496 /KEVIN AYALA/ Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Nov 19, 2024
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §102, §112 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
7%
Grant Probability
18%
With Interview (+11.1%)
3y 2m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 29 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month