Prosecution Insights
Last updated: October 04, 2026
Application No. 18/970,219

SYSTEM AND METHODS FOR VULNERABILITY ASSESSMENT AND PROVISIONING OF RELATED SERVICES AND PRODUCTS FOR EFFICIENT RISK SUPPRESSION

Final Rejection §102§112
Filed
Dec 05, 2024
Priority
Jan 31, 2018 — provisional 62/624,575 +4 more
Examiner
CHAI, LONGBIT
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Aon Risk Consultants Inc.
OA Round
2 (Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
669 granted / 761 resolved
+29.9% vs TC avg
Strong +31% interview lift
Without
With
+31.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
13 currently pending
Career history
772
Total Applications
across all art units

Statute-Specific Performance

§101
16.0%
-24.0% vs TC avg
§103
41.7%
+1.7% vs TC avg
§102
35.0%
-5.0% vs TC avg
§112
6.5%
-33.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 761 resolved cases

Office Action

§102 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Currently pending claims are 1 – 20. Response to Arguments Applicant's arguments with respect to the subject matter of the instant claims have been fully considered but are not persuasive. As per claim 1, Applicant asserts prior-art(s) does not teach the newly added / amended claim elements such as between a first subset of the assessment data and a second subset of the assessment data regarding “a first subset of the assessment data corresponds to a set of control systems, each control system being configured to suppress, detect, or prevent cyber attack, and a second subset of the assessment data corresponds to enterprise policies, calculate, for each security domain of the plurality of security domains” (Remarks: Page 7 / 3rd Para). Examiner respectfully disagrees with the following rationale. (a) Examiner first notes according to 35 U.S.C. 112 (pre-AIA ), second paragraph, the newly added / amended claim elements such as between a first subset of the assessment data and a second subset of the assessment data are indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor due to in lack of uniqueness of patentable features between them, which are directed respectively to (i) a control system to suppress, detect, or prevent cyber-attack and (ii) enterprise control policies to calculate a respective domain-level vulnerability score because the purpose of any control policy to calculate a vulnerability (risk) score is essentially aimed to a control system to suppress, detect, or prevent cyber-attack – there is no significant patentable features distinguishable between both of these two features. (b) In light of that as regarding to (a), Seiver teaches, at least, to determine / calculate a vulnerability (risk) score based on a control policy (a guideline) by applying different weighting factors to various assessment data related to running the anti-virus security software based on (e.g. at least) the distance from the ideal (satisfactory) as specified in the guideline (policy) – e.g. whether the anti-virus security software had its virus definition data updated recently or not, and etc. so as to prevent malicious cyber attack (Seiver: Col. 29 Line 36 – 62 & Col. 32 Line 11 – 32). As such Applicant's arguments are respectfully traversed. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2 & 15 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention of the newly added / amended claim elements such as between a first subset of the assessment data and a second subset of the assessment data due to in lack of uniqueness of patentable features between them, which are directed respectively to (i) a control system to suppress, detect, or prevent cyber-attack and (ii) enterprise control policies to calculate a respective domain-level vulnerability score because the purpose of any control policy to calculate a vulnerability (risk) score is essentially aimed to a control system to suppress, detect, or prevent cyber-attack – there is no significant patentable features distinguishable between them. Any other claims not addressed are rejected by virtue of their dependency. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim 1 is rejected under 35 U.S.C. 102(a)(2) as being anticipated by Seiver et al. (U.S. Patent 9,648,036). As per claim 1 & 15, Seiver teaches system for assessing cyber security vulnerability of an enterprise, comprising: processing circuitry (Seiver: Col. 22 Line 55 – 6); and a non-transitory computer readable medium having instructions stored thereon, wherein the instructions, when executed on the processing circuitry, cause the processing circuitry to (Seiver: Col. 22 Line 47 – 54) obtain assessment data comprising information pertaining to a plurality of domains of cybersecurity vulnerability of the enterprise, wherein the assessment data comprises a plurality of answers to a plurality of questions (Seiver: Figure 16 / E-1600 & Col. 22 Line 4 – 8 / Line 31 – 40: (a) determining a security domain of a plurality of security domains associated with an enterprise entity and providing a respective survey with a list of (plurality) questions (i.e. questionnaire) associated with a company to the users, wherein (b) the plurality of security domains of cybersecurity vulnerability (Figure 16 / E-1600) of the enterprise can include, for example, (i) a domain of a network device (node) level, (ii) a domain of a specific user account level (Col. 19 Line 48 – 50), (iii) a domain of access rights (privileged permission) level (Col. 22 Line 35 – 40), (iv) a domain of overall user account level (Col. 19 Line 52 – 55), (v) a domain of overall system (network) level (Col. 19 Line 57 – 61) and etc. (c) so as evaluate an insurance cost associated with the cyber security risks – this is also consistent with the disclosure of the instant specification (SPEC-PG.PUB: Para [0199] Line 2 – 4: projecting cyber insurance cost across a number of security domains based on the answers from users to a list of questions), a first subset of the assessment data corresponds to a set of control systems, each control system being configured to suppress, detect, or prevent cyber attack, and a second subset of the assessment data corresponds to enterprise policies (Seiver: see above & Col. 29 Line 36 – 62 & Col. 32 Line 11 – 32: (a) Examiner first notes according to 35 U.S.C. 112 (pre-AIA ), second paragraph, the newly added / amended claim elements such as between a first subset of the assessment data and a second subset of the assessment data are indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor due to in lack of uniqueness of patentable features between them, which are directed respectively to (i) a control system to suppress, detect, or prevent cyber-attack and (ii) enterprise control policies to calculate a respective domain-level vulnerability score because the purpose of any control policy to calculate a vulnerability (risk) score is essentially aimed to a control system to suppress, detect, or prevent cyber-attack – there is no significant patentable features distinguishable between both of these two features; and (b) In light of that as regarding to (a), Seiver teaches, at least, to determine / calculate a vulnerability (risk) score based on a control policy (a guideline) by applying different weighting factors to various assessment data related to running the anti-virus security software based on (e.g. at least) the distance from the ideal (satisfactory) as specified in the guideline (policy) – e.g. whether the anti-virus security software had its virus definition data updated recently or not, and etc. so as to prevent malicious cyber attack (Seiver: Col. 29 Line 36 – 62 & Col. 32 Line 11 – 32). calculate, for each domain of the plurality of domains, a respective domain-level vulnerability score based on the information of the assessment data pertaining to the respective security domain (Seiver: see above & Col. 18 Line 46 – 49 and Col. 19 Line 48 – 61: calculating each of a domain compromise risk value (i.e. domain-level vulnerability score) of a plurality of security domains of cybersecurity associated with an enterprise (Figure 16 / E-1600) including, (i) a domain of a network device (node) level (Col. 19 Line 48 – 50), (ii) a domain of a specific user account level (Col. 19 Line 48 – 50), (iii) a domain of access rights (privileged permission) level (Col. 22 Line 35 – 40), (iv) a domain of overall user account level (Col. 19 Line 52 – 55), (v) a domain of overall system (network) level (Col. 19 Line 57 – 61) and etc.), wherein calculating the respective domain-level vulnerability score comprises identifying one or more answers of the plurality of answers corresponding to the respective security domain (Seiver: see above), and calculating, based at least in part on the one or more answers, the respective domain-level vulnerability score (Seiver: see above), identify, for at least one security domain of the plurality of domains, one or more risks relevant to the enterprise based upon at least one of the respective domain-level vulnerability score of each security domain of the at least one security domain, a portion of the first subset of the assessment data pertaining to the respective domain and a portion of the second subset of the assessment data pertaining to the respective domain (Seiver: see above & FIG. 16, Col. 29 Line 36 – 42, Col. 22 Line 26 – 40, Col. 32 Line 24 – 26 and Col. 47 Line 45: (a) a combined domain-level risk exposure value, as a compromise risk value (i.e. vulnerability score(s)) representing an enterprise numeric quantification, can be determined (e.g.) on a per security domain basis from a plurality of security domains such as access rights control security domain, antivirus protection security domain, and etc.; (b) a weighting factor can be assigned to each of risk values associated with the vulnerability score(s) within each of the security domains (Seiver: Col. 32 Line 24 – 26 & Col. 47 Line 45) – risks – this is also consistent with the disclosure of the instant specification (SPEC-PG.PUB: Para [0125]: using a domain-level weight as a fractional or integer value as needed as a basis of calculating vulnerability score(s)). identify, based on the one or more risks, one or more recommended products or services for mitigating each of the one or more risks (Seiver: see above & FIG. 16 / E-1606, Col. 32 Line 11 – 32, Col. 21 Line 6 – 28, Col. 58 Line 51 – 67 & Col. 28 Line 22 – 26: the security system can present different options (recommendations) of respective software products or services (e.g. Sophos (anti-virus) software) to the users w.r.t. mitigation (reduction) of risk values to improve the system vulnerability as needed such that the user can select the desired option(s), wherein different mitigation options of recommendations are identified as one of highly recommended options w.r.t. urgency to the enterprise within a list of TOP INVESTMENTS including (i) purchasing (recommending) a respective software product or service on a basis of priority as needed (Figure 16 / E-1606), (ii) deploying patches on vulnerable applications, as well as implementing N-factor authentications, reducing enable high-privilege accounts and etc.), prepare, for presentation to a representative of the enterprise at a remote computing device, a first graphical user interface for selecting each of the one or more recommended products or services (Seiver: see above) receive, from the remote computing device through interaction with the first graphical user interface, selection of at least one recommended product or service of the one or more recommended products or services (Seiver: see above & FIG. 16, Col. 58 Line 56 – 58, Col. 21 Line 6 – 28, Col. 32 Line 11 – 32 & Col. 28 Line 22 – 26: the system can present different options (recommendations) to the users via the user interface w.r.t. the mitigation (reduction) of risk values such that the user can select the desired option(s) from the recommendations of the mitigation options);, and (i) apply one or more adjusted values to the assessment data based upon the one or more recommended products or services to obtain adjusted assessment data (Seiver: see above & Figure 15 / E-1510 – 3rd Entry, Figure 16 / E-1606, Col. 29 Line 58 – 62 and Col. 22 Line 35 – 40: (a) applying an improvement of different mitigations across different security issues on a plurality of security domains and a recommendation by an expert of insurance provider such as a recommendation of adding Sophos (anti-virus) software to improve baseline security – as a first prerequisite recommended products or services as a typical mitigation option (Seiver: Figure 15 / E-1510 – 3rd Entry & Col. 22 Line 35 – 40) – i.e. Sophos as one of respective responsible parties (providing services after deploying the security products) and wherein, (b) determining eligibility of a company for the Sophos (anti-virus) product upon assessing a risk value would be increased significantly if the company (or a network device) does not run anti-virus software and assigning a weight to a respective compromise vulnerability value (Seiver: Col. 29 Line 58 – 62)). ii) calculate, using the adjusted assessment data, an adjusted domain-level vulnerability score representing the respective domain-level vulnerability score in a respective security domain of the plurality of security domains impacted by application of the at least one recommended product or service (Seiver: see above & Col. 18 Line 46 – 49 and Col. 19 Line 48 – 61: calculating each of a domain compromise risk value (i.e. domain-level vulnerability score) of a plurality of security domains of cybersecurity associated with an enterprise (Figure 16 / E-1600) including, (i) a domain of a network device (node) level (Col. 19 Line 48 – 50), (ii) a domain of a specific user account level (Col. 19 Line 48 – 50), (iii) a domain of access rights (privileged permission) level (Col. 22 Line 35 – 40), (iv) a domain of overall user account level (Col. 19 Line 52 – 55), (v) a domain of overall system (network) level (Col. 19 Line 57 – 61) and etc.), and iii) prepare, for presentation to the representative at the remote computing device, a second graphical user interface (see above), comprising: illustration of an improvement in vulnerability score between the vulnerability score of the respective security domain and the adjusted domain-level vulnerability score of the respective security domain (Seiver: see above & Figure 16 / E-1606). As per claim 2, Seiver teaches to classify each domain-level vulnerability score according to a respective level of severity of a set of levels of severity (Seiver: see above & FIG. 16 and Col. 41 Line 30 – 41: a set of levels of severity such as low / medium / high / very high and etc.). As per claim 3, 5 & 9, the instant claim is directed to a claimed content having functionality corresponding to the Claims 1 – 2, and are rejected by a similar rationale. As per claim 4, Seiver teaches classifying each domain-level vulnerability score comprises color-coding, within the first graphical user interface, each domain-level vulnerability score according to the set of levels of severity (Seiver: see above, Col. 41 Line 8 – 12 & Col. 26 Line 58 – 67: using graphical user interface with Green / Red, and etc.). As per claim 6 – 7 & 16 – 17 and 19, Seiver teaches wherein the one or more recommended products or services comprises an insurance policy (Seiver: see above, FIG. 15 / 16 & Col. 22 Line 9 – 40 and Col. 6 Line 9 – 17). As per claim 8, Seiver teaches wherein the enterprise policies comprise a password policy (Seiver: see above & FIG. 15 / E-1506: including user accounts with password policies). As per claim 10, Seiver teaches providing a third graphical user interface for reviewing vulnerability scores of each category of the set of categories of the target security domain (Seiver: see above & FIG. 15 & 16). As per claim 11 – 13, Seiver teaches wherein the adjusted domain-level vulnerability score is a prospective score representing an improvement anticipated from the enterprise applying the at least one recommended product or service (Seiver: see above, FIG. 15 / E-1510, Col. 40 Line 55 – 67 & Col. 23 Line 48 – 67). As per claim 14 & 18, Seiver teaches wherein the secure interface enables, upon selection, credential management for automatically logging into the third party system (Seiver: see above & FIG. 15 / E-1510 / 3rd- entry: when clicking on the button “Assign”, the system would automatically implement adding the Sophos anti-virus software product into the server system) – i.e. automatically logging into the third party Sophos anti-virus software product system to deploy the security software into the target system). As per claim 20, Seiver teaches wherein a number of insurance policies of the one or more potential insurance policies changes based upon a score adjustment of at least one vulnerability score of the plurality of domain-level vulnerability scores (Seiver: see above, FIG. 15 / E-1510, Col. 10 Line 22 – 26 / Line 56 – 61, Col. 9 Line 54 – 64: based on the vulnerability scores such as whether a selected user is rarely or never required to access a certain account or a certain node, a corresponding potential insurance policy can be changed to limit the user access rights that allows adjustment of a time period of actual access by the user account). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. --------------------------------------------------- /Longbit Chai/ Longbit Chai E.E. Ph.D. Primary Examiner, Art Unit 2431 No. #2589 – 2026 ---------------------------------------------------
Read full office action

Prosecution Timeline

Dec 05, 2024
Application Filed
Apr 17, 2026
Non-Final Rejection mailed — §102, §112
Jul 15, 2026
Response Filed
Aug 03, 2026
Final Rejection mailed — §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748870
Dynamically Controlling Access to Linked Content in Electronic Communications
2y 0m to grant Granted Sep 29, 2026
Patent 12750403
INITIAL SECURITY ACTIVATION FOR MEDIUM ACCESS CONTROL LAYER
2y 0m to grant Granted Sep 29, 2026
Patent 12732478
Systems, Methods And Apparatus For Local Area Network Isolation
2y 11m to grant Granted Sep 08, 2026
Patent 12732542
UNIFIED DEVICE MANAGEMENT ENGINE IN A DEVICE MANAGEMENT SYSTEM
2y 5m to grant Granted Sep 08, 2026
Patent 12719891
REALTIME EVENT DETECTION
1y 7m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+31.2%)
2y 8m (~10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 761 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month