Prosecution Insights
Last updated: August 18, 2026
Application No. 18/958,676

PRIORITIZING SECURITY VULNERABILITIES IN COMPUTING ECOSYSTEMS

Non-Final OA §101§102§103
Filed
Nov 25, 2024
Examiner
LIN, AMIE CHINYU
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Optum Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
257 granted / 304 resolved
+26.5% vs TC avg
Strong +31% interview lift
Without
With
+31.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
11 currently pending
Career history
315
Total Applications
across all art units

Statute-Specific Performance

§101
14.6%
-25.4% vs TC avg
§103
46.7%
+6.7% vs TC avg
§102
15.2%
-24.8% vs TC avg
§112
18.2%
-21.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 304 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to the communication filed on 11/25/2024. Claims 1-20 are pending. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claim 1 recites steps of determining…a vulnerability graph for the computing ecosystem that defines a set of component nodes, a set of vulnerability nodes, and a set of graph edges, wherein a first component node of the set of component nodes is associated with a discrete hardware or software component different from other components identified by remaining component nodes of the set of component nodes; determining…a degree measure and a betweenness measure for a vulnerability node of the set of vulnerability nodes within the vulnerability graph, wherein the degree measure quantifies a number of edges connected to the vulnerability node and the betweenness measure quantifies a number of shortest paths associated with the vulnerability node; determining…a set of prioritized vulnerability nodes from the vulnerability graph based on the degree measure and the betweenness measure. The limitations above, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting one or more processors, nothing in the claim element precludes the steps from practically being performed in the mind. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the Mental Processes grouping of abstract ideas. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application. In particular, the additional elements recited in the claim of receiving a security vulnerability detection for a computing ecosystem; and providing a prioritized list of security vulnerabilities for the computing ecosystem in response to the security vulnerability detection and based on the set of prioritized vulnerability nodes are merely insignificant extra-solution activities, e.g., data gathering and pre or post solution activities. In addition, the claim recites the additional elements of using one or more processors to perform the steps recited in the claim. These additional elements are recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using generic computer components. Accordingly, the combination of the above additional elements does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of using the one or more processors to perform the steps recited in the claim amounts to no more than mere instructions to apply the exception using generic computer components; mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. In addition, the addition elements of receiving a security vulnerability detection and providing a prioritized list of security vulnerabilities are insignificant extra-solution activities that cannot provide an inventive concept. The claim is not patent eligible. Dependent claims 2-10 further clarify the concept recited in claim 1 that is directed to an abstract idea; however, the clarifications still fall under the concept recited in claim 1 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. Claim 11 although not using the exact claim language, contains similar elements as recited in claim 1 and is also rejected for similar reasons. For example, the steps of determining a vulnerability graph, determining a degree measure and a betweenness measure for a vulnerability node, determining a set of prioritized vulnerability nodes from the vulnerability graph recited in claim 11 fall within the mental processes grouping of abstract ideas as explained above with respect to claim 1. Claim 11 recites the additional elements of one or more processors to perform the steps. The one or more processors is recited at a high-level of generality and is a generic computer component such that it amounts to simply implementing the abstract idea on a computer, and thus cannot provide an inventive concept. The addition elements of receiving a security vulnerability detection and providing a prioritized list of security vulnerabilities are insignificant extra-solution activities that cannot provide an inventive concept. Dependent claims 12-16 further clarify the concept recited in claim 11 that is directed to an abstract idea; however, the clarifications still fall under the concept recited in claim 11 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. Claim 17 although not using the exact claim language, contains similar elements as recited in claim 1 and is also rejected for similar reasons. Dependent claims 18-20 further clarify the concept recited in claim 17 that is directed to an abstract idea; however, the clarifications still fall under the concept recited in claim 17 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-2, 5-6, 8-11, 13-15, 17-18, and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Lee (US 2020/0195673). Claim 1, Lee teaches: A computer-implemented method comprising: receiving, by one or more processors, a security vulnerability detection for a computing ecosystem; (e.g., [0060], “the processing system determines an anomaly factor of the first node from the network traffic data (e.g., from the at least the first set of flow data). For example, the anomaly factor may quantify a deviation of the at least the first set of flow data associated with the first node from a normal flow data associated with the first node”) determining, by the one or more processors, a vulnerability graph for the computing ecosystem that defines a set of component nodes, a set of vulnerability nodes, and a set of graph edges, wherein a first component node of the set of component nodes is associated with a discrete hardware or software component different from other components identified by remaining component nodes of the set of component nodes; (e.g., [0032], “communication within the network may be modeled using graph analysis. For instance, graphs may be composed of a number of distinct nodes and edges. In network traffic data, source and target IP addresses may define the nodes in a graph representation, and edges may contain a variety of information such as the bytes or number of packets that move between the nodes. To illustrate, FIG. 2 illustrates a first graph 210 having a plurality of nodes 212 interconnected by a plurality of edges 214. To use graph theory to quantify the influence of a node, the present disclosure may use one or several measures of centrality which may describe the connectedness of a node. For instance, in one example, the present disclosure determines an “influence” measure from: a degree centrality metric, a closeness centrality metric, and a betweenness centrality metric. These different centrality metrics are described in connection with the example graphs 220, 230, and 240 of FIG. 2”) determining, by the one or more processors, a degree measure and a betweenness measure for a vulnerability node of the set of vulnerability nodes within the vulnerability graph, wherein the degree measure quantifies a number of edges connected to the vulnerability node and the betweenness measure quantifies a number of shortest paths associated with the vulnerability node; (e.g., [0033], “The degree of a node is a measure of centrality that may be calculated by counting the number of edges that are attached to a node. In one example, the present disclosure utilizes a normalized degree measure, e.g., in accordance with Equation 1:” [0034], “In Equation 1, D.sub.i(n.sub.i) is the number of connections for a node n and N−1 is the maximum possible number of connections. The normalized measure may be used to ensure that all values are comparable, even among separate graphs, with values between 0 and 1. A high normalized degree could indicate that a node is performing a function that is important to the network. In graph 220 of FIG. 2, the number beside each node indicates the normalized degree of the node. According to degree centrality, the most important nodes in the graph 220 of FIG. 2 are the two nodes with a normalized degree of ½, or 3/6. In the context of network traffic, these nodes are the nodes with the most connections to other nodes” [0035], “There are cases when degree centrality may not completely capture the importance of a node. For instance, degree centrality may not capture the ability of a node to broker communications between groups or send communications to far reaching parts of the network. To quantify a node's ability to broker communication, a betweenness centrality may be used. Betweenness identifies when many paths must pass through a node to reach other parts of a network. Notably, failure or infection of a node with high betweenness centrality could result in major disruption to the network. In one example, the present disclosure utilizes a normalized betweenness centrality measure, e.g., in accordance with Equation 2: represents the fraction of shortest paths that travel through a node n.sub.i, and (N−1)(N−2)/2 is the number of pairs of nodes (excluding the node itself) in the network. In the graph 230 depicted of FIG. 2, the node with the highest betweenness has a value of 9/15 and may be designated as an influential node of the network, e.g., when the concern is the ability of information to travel from one part of the network to another”) determining, by the one or more processors, a set of prioritized vulnerability nodes from the vulnerability graph based on the degree measure and the betweenness measure; and (e.g., [0042], “In one example, when estimating the potential impact of a node that may be behaving suspiciously, the level of anomalousness of the node…in question as well as presence of unusual behavior in any node with which the suspected node has communications may be considered. For example, nodes that exhibit anomalous behavior as well as communicate with other anomalous nodes might indicate a spreading threat, and in one example, may be ranked higher in an overall risk assessment. In one example, this is accomplished by adjusting the influence measure by an anomaly factor” [0067], “the processing system may generate a ranked list of nodes in the network associated with potential threats to the network, e.g., where the nodes are ranked in accordance with respective threat levels, and where the ranked list includes at least the first node and the threat level of the first node”) providing, by the one or more processors, a prioritized list of security vulnerabilities for the computing ecosystem in response to the security vulnerability detection and based on the set of prioritized vulnerability nodes. (e.g., [0068], “the processing system may present the ranked list of anomalies to at least one of a device associated with personnel of the network or a SDN controller. For instance, network personnel may prioritize investigation of those anomalies that have the greatest potential for harming the network while a SDN controller may configure other nodes to avoid the node(s) comprising potential threats according to the list, may identify other network resources for potentially offloading network traffic of the first node, and so forth”) Claim 2, Lee teaches: further comprising automatically initiating one or more vulnerability resolution actions for the prioritized list of security vulnerabilities. (e.g., [0067]-[0069]) Claim 5, Lee teaches: wherein a component node of the set of component nodes comprises a risk weight that is based on at least one of: a data sensitivity or data access privilege of a software application corresponding to the component node, an exposure level of the software application corresponding to the component node, or a value outcome of the software application corresponding to the component node. (e.g., [0040], [0048], [0061], [0063]) Claim 6, Lee teaches: wherein generating the degree measure for the vulnerability node comprises: determining a set of weighted edge measurements for the vulnerability node, wherein: (i) the set of weighted edge measurements comprises a respective weight edge measurement for each of a subset of the set of graph edges connected to the vulnerability node, (ii) a weighted edge measurement of the set of weighted edge measurements corresponds to an edge that connects the vulnerability node to the component node, and (iii) the weighted edge measurement is based on the risk weight of the component node; and generating the degree measure by aggregating the set of weighted edge measurements. (e.g., [0040]-[0041], [0048]-[0049], [0061]-[0063]) Claim 8, Lee teaches: wherein a component node of the set of component nodes comprises an owner attribute and the computer-implemented method further comprises: determining a subset of impacted component nodes from the set of component nodes based on a subset of the set of graph edges that respectively connect the set of prioritized vulnerability nodes to the subset of impacted component nodes, wherein the subset of impacted component nodes comprises the component node; (e.g. [0032]-[0035], [0042]) determining a set of owners for the prioritized list of security vulnerabilities based on the owner attribute of the component node; and providing a near-real time security alert that identifies at least one of the prioritized list of security vulnerabilities and a software application corresponding to the component node to at least one owner of the set of owners. (e.g., fig. 3, [0066]-[0069]) Claim 9, Lee teaches: wherein determining the subset of impacted component nodes comprises: traversing, via a breadth-first graph search from a prioritized vulnerability node of the set of prioritized vulnerability nodes, an initial subset of impacted component nodes from the set of component nodes; and removing at least one impacted component node from the initial subset of impacted component nodes based on a comparison between a risk weight of the at least one impacted component node and a risk threshold. (e.g., fig. 3, [0026], [0057], [0060]-[0061], [0069]) Claim 10, Lee teaches: wherein determining the set of prioritized vulnerability nodes from the vulnerability graph comprises: generating (a) a degree node ranking from the vulnerability graph based on the degree measure and (b) a betweenness node ranking from the vulnerability graph based on the betweenness measure; determining the set of prioritized vulnerability nodes from the vulnerability graph based on a set of first positions respectively corresponding to the set of prioritized vulnerability nodes within the degree node ranking; and verifying the set of prioritized vulnerability nodes based on a set of second positions respectively corresponding to the set of prioritized vulnerability nodes within the betweenness node ranking. (e.g., [0032]-[0035], [0042], [0067]-[0068]) Claim 11, this claim is directed to a system containing similar limitations as recited in claim 1 and is rejected for similar rationale. Claim 13, this claim is directed to a system containing similar limitations as recited in claim 5 and is rejected for similar rationale. Claim 14, this claim is directed to a system containing similar limitations as recited in claim 6 and is rejected for similar rationale. Claim 15, Lee teaches: wherein the weighted edge measurement is based on at least one of (i) a data sensitivity of the software application corresponding to the component node, (ii) an exposure level of the software application corresponding to the component node, or (iii) a value outcome of the software application corresponding to the component node. (e.g., [0040], [0048], [0061], [0063]) Claim 17, this claim is directed to a non-transitory computer-readable media containing similar limitations as recited in claim 1 and is rejected for similar rationale. Claim 18, this claim is directed to a non-transitory computer-readable media containing similar limitations as recited in claim 8 and is rejected for similar rationale. Claim 20, this claim is directed to a non-transitory computer-readable media containing similar limitations as recited in claim 9 and is rejected for similar rationale. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3-4, and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 2020/0195673) in view of Difonzo et al. (US 2022/0414228). Claim 3, Lee teaches the computing ecosystem and the vulnerability graph (see above) and does not appear to explicitly teach but Difonzo teaches: initiating, at a scanning frequency, a vulnerability scan for a computing ecosystem; and (e.g., [0072]-[0073]) modifying a vulnerability graph based on a scan result from the vulnerability scan. (e.g., [0052], [0068]-[0069]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Difonzo into the invention of Lee, and the motivation for such an implementation would be for the purpose of automated processing and translating natural language-based user queries into graph database queries to facilitate ease-of-use and enable efficient access to powerful graph database analytical tools (Difonzo [0005]-[0006]). Claim 4, Lee-Difonzo teaches: wherein the scan result comprises a unique vulnerability identifier, a unique component identifier, and a vulnerability description for a security vulnerability, and modifying the vulnerability graph comprises: determining a particular vulnerability node for the security vulnerability based on the unique vulnerability identifier; and updating a subset of the set of graph edges that connects to the particular vulnerability node based on the unique component identifier. (e.g., Difonzo [0047], [0052], [0059], [0069]) Same motivation as presented in claim 3 would apply. Claim 12, this claim is directed to a system containing similar limitations as recited in claim 3 and is rejected using the same rationale to combine the references. Claims 7, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 2020/0195673) in view of Smith-Creasey et al. (US 2026/0127254). Claim 7, Lee teaches wherein generating the betweenness measure for the vulnerability node comprises: determining a set of shortest paths between pairs of nodes within the vulnerability graph; determining a subset of the set of shortest paths that comprise the vulnerability node (e.g., [0032], [0035]-[0036]), determining the betweenness measure for the vulnerability node, the subset of the set of shortest paths that comprise the vulnerability node (see above) and does not appear to explicitly teach but Smith-Creasey teaches: dividing a first number of a subset of a set of shortest paths by a second number of the set of shortest paths between pairs of all nodes. (e.g., [0022], [0057]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Smith-Creasey into the invention of Lee, and the motivation for such an implementation would be for the purpose of providing an authentication method that do not require specialized hardware and do not require users to remember special information (Smith-Creasey [0004]). Claim 16, this claim is directed to a non-transitory computer-readable media containing similar limitations as recited in claim 7 and is rejected using the same rationale to combine the references. Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 2020/0195673) in view of Huang (US 2017/0118099). Claim 19, Lee teaches the at least one owner of the set of owners (see above) and does not appear to explicitly teach but Huang teaches: detecting an expiration of an escalation time period; and responsive to detecting the expiration of the escalation time period, providing an escalation alert to at least one owner of a set of owners. (e.g., [0047]-[0051]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Huang into the invention of Lee, and the motivation for such an implementation would be for the purpose of performing automatic error resolving (Huang [0047]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: 2021/0400077 discloses creating an organization graph with centrality calculated to arrive at a risk score for each node. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIE C LIN whose telephone number is (571)272-7752. The examiner can normally be reached M-F 9:00AM -5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GELAGAY SHEWAYE can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMIE C. LIN/ Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Nov 25, 2024
Application Filed
Jun 24, 2026
Examiner Interview (Telephonic)
Jul 30, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699764
CERTIFICATE RESILIENCY VALIDATION USING CHAOS ENGINEERING
3y 4m to grant Granted Aug 04, 2026
Patent 12665894
SYSTEMS AND METHODS FOR AUTHENTICATION BROKERING
2y 9m to grant Granted Jun 23, 2026
Patent 12664268
METHODS AND APPARATUS TO IDENTIFY STRUCTURAL SIMILARITY BETWEEN WEBPAGES
2y 8m to grant Granted Jun 23, 2026
Patent 12664255
Preventing EDR Termination using Vulnerable Drivers
2y 0m to grant Granted Jun 23, 2026
Patent 12665950
CENTRALIZED IOT DASHBOARD
1y 5m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+31.0%)
2y 8m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 304 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month