Prosecution Insights
Last updated: August 14, 2026
Application No. 18/980,609

SYSTEMS AND METHODS FOR AN AUTOMATED TOOL FOR STIX REPORT GENERATION FROM THREAT INTELLIGENCE TEXT

Non-Final OA §102§103§112
Filed
Dec 13, 2024
Priority
Dec 15, 2023 — provisional 63/610,945
Examiner
CHOUDHURY, RAQIUL A
Art Unit
Tech Center
Assignee
Hamad Bin Khalifa University (Hbku)
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
5m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
221 granted / 254 resolved
+27.0% vs TC avg
Moderate +6% lift
Without
With
+6.0%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
28 currently pending
Career history
277
Total Applications
across all art units

Statute-Specific Performance

§101
7.7%
-32.3% vs TC avg
§103
55.3%
+15.3% vs TC avg
§102
14.7%
-25.3% vs TC avg
§112
18.0%
-22.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 254 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Abstract The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details. The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided. The abstract of the disclosure is objected to because on page 1, line 1, the first occurrence of “STIX” should be spelled out. Correction is required. The disclosure is objected to because of the following informalities: On par 2, line 2, the first occurrence of “STIX” should be spelled out Appropriate correction is required. Claim Objections Claims 1, 3-7, 9, 11-12, and 14-19 are objected to because of the following informalities: In claim 1, line 1, the first occurrence of “STIX” should be spelled out. In claim 1, line 11, the first occurrence of “RegEx” should be spelled out. In claim 3, line 1, the first occurrence of “URL” should be spelled out. In claim 3, line 1, the first occurrence of “PDF” should be spelled out. In claim 4, line 3, the first occurrence of “HTML” should be spelled out. In claim 4, line 4, the first occurrence of “CTI” should be spelled out. In claim 5, line 3, the first occurrence of “HTML” should be spelled out. In claim 6, line 3, the first occurrence of “SDO” should be spelled out. In claim 6, line 3, the first occurrence of “SCO” should be spelled out. In claim 6, line 6, the first occurrence of “IP” should be spelled out. In claim 6, line 7, the first occurrence of “MAC” should be spelled out. In claim 6, line 7, the first occurrence of “URL” should be spelled out. In claim 7, line 3, the first occurrence of “IoC” should be spelled out. In claim 7, line 3, the first occurrence of “URL” should be spelled out. In claim 7, line 3, the first occurrence of “IP” should be spelled out. In claim 7, line 3, the first occurrence of “MITRE ATT&CK” should be spelled out. In claim 7, line 4, the first occurrence of “ID” should be spelled out. In claim 7, line 4, the first occurrence of “YARA” should be spelled out. In claim 7, line 4, the first occurrence of “ASN” should be spelled out. In claim 9, line 4, the first occurrence of “SRO” should be spelled out. In claim 11, line 2, the first occurrence of “SRO” should be spelled out. In claim 11, line 3, the first occurrence of “JSON” should be spelled out. In claim 12, line 1, the first occurrence of “JSON” should be spelled out. In claim 14, line 1, the first occurrence of “STIX” should be spelled out. In claim 14, line 10, the first occurrence of “RegEx” should be spelled out. In claim 15, line 11, the first occurrence of “SRO” should be spelled out. In claim 15, line 15, the first occurrence of “JSON” should be spelled out. In claim 16, line 2, the first occurrence of “HTML” should be spelled out. In claim 16, line 3, the first occurrence of “CTI” should be spelled out. In claim 16, line 6, the first occurrence of “SDO” should be spelled out. In claim 16, line 6, the first occurrence of “SCO” should be spelled out. In claim 16, line 9, the first occurrence of “IP” should be spelled out. In claim 16, line 10, the first occurrence of “MAC” should be spelled out. In claim 16, line 10, the first occurrence of “URL” should be spelled out. In claim 17, line 1, the first occurrence of “STIX” should be spelled out. In claim 17, line 19, the first occurrence of “JSON” should be spelled out. In claim 18, line 1, the first occurrence of “URL” should be spelled out. In claim 18, line 1, the first occurrence of “PDF” should be spelled out. In claim 19, line 1, the first occurrence of “JSON” should be spelled out. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 16 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Claims 1, 6-10, and 13-16 are interpreted under 35 U.S.C. 112(f) because it/they use(s) the term “configured to” with functional language without reciting sufficient structure to achieve the function. Regarding Claim 1, “wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output”. There is no corresponding structure or algorithm disclosed. Regarding Claim 6, “wherein the entity detection component is configured to receive one of plain text from the report parser or segmented output from the section splitter, wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs”. There is no corresponding structure or algorithm disclosed. Regarding Claim 7, “wherein the entity detection component is in communication with a plurality of LLMs”. There is no corresponding structure disclosed. Regarding Claim 8, “wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between multiple type designations to result in a resolved output”. There is no corresponding structure or algorithm disclosed. Regarding Claim 9, “wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component, wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs), wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) module to determine if two entities are related given the entities’ names and types and a text”. There is no corresponding structure or algorithm disclosed. Regarding Claim 10, “wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component” There is no corresponding structure disclosed. “wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types” There is no corresponding structure or algorithm disclosed. “wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine if the relationship type between two entities given the entities’ names and types and a text”. There is no corresponding structure or algorithm disclosed. Regarding Claim 13, “wherein the Human Verification and Feedback component is configured to receive the output of entity detection component, entity type identification component, and the related pairs detection component, wherein the Human Verification and Feedback component allows users to edit the outputs of entity detection component, entity type identification component, and the related pairs detection component”. There is no corresponding structure or algorithm disclosed. Regarding Claim 14, “wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output”. There is no corresponding structure or algorithm disclosed. Regarding Claim 15, “wherein the entity detection component is configured to receive one of the plain text from the report parser or segmented output from the section splitter”. There is no corresponding structure or algorithm disclosed. “wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component”. There is no corresponding structure disclosed. “wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component”. “wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs), wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types”. There is no corresponding structure or algorithm disclosed. Regarding Claim 16, “wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs”. There is no corresponding structure or algorithm disclosed. “wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, the descriptions of Course of Action objects, wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between the multiple type designations to result in a resolved output”. There is no corresponding structure or algorithm disclosed. “wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) to determine if two entities are related given the entities names and types and a text”. There is no corresponding structure or algorithm disclosed. “and wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) to determine if the relationship type between two entities given the entities names and types and a text”. There is no corresponding structure or algorithm disclosed. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. For a computer-implemented 35 U.S.C. 112(f) claim limitation, the specification must disclose an algorithm for performing the claimed specific computer function, or else the claim is indefinite under 35 U.S.C. 112(b) (b). See Net MoneyIN, Inc. v. Verisign. Inc., 545 F.3d 1359, 1367 (Fed. Cir. 2008). See also In re Aoyama, 656 F.3d 1293, 1297, 99 USPQ2d 1936, 1939 (Fed. Cir. 2011) ("[W]hen the disclosed structure is a computer programmed to carry out an algorithm, ‘the disclosed structure is not the general purpose computer, but rather that special purpose computer programmed to perform the disclosed algorithm.’") (quoting WMS Gaming, Inc. v. Int’l Game Tech., 184 F.3d 1339, 1349, 51 USPQ2d 1385, 1391 (Fed. Cir. 1999)). In cases involving a special purpose computer-implemented means-plus-function limitation, the Federal Circuit has consistently required that the structure be more than simply a general purpose computer or microprocessor and that the specification must disclose an algorithm for performing the claimed function. See, e.g., Noah Systems Inc. v. Intuit Inc., 675 F.3d 1302, 1312, 102 USPQ2d 1410, 1417 (Fed. Cir. 2012); Aristocrat, 521 F.3d at 1333, 86 USPQ2d at 1239. For a computer-implemented means-plus-function claim limitation invoking 35 U.S.C. 112(f) the Federal Circuit has stated that "a microprocessor can serve as structure for a computer-implemented function only where the claimed function is ‘coextensive’ with a microprocessor itself." EON Corp. IP Holdings LLC v. AT&T Mobility LLC, 785 F.3d 616, 622, citing In re Katz Interactive Call Processing Patent Litigation, 639 F.3d 1303, 1316 (Fed. Cir. 2011). "‘It is only in the rare circumstances where any general-purpose computer without any special programming can perform the function that an algorithm need not be disclosed.’" EON Corp., 785 F.3d at 621, quoting Ergo Licensing, LLC v. CareFusion 303, Inc., 673 F.3d 1361, 1365 (Fed. Cir. 2012). "‘[S]pecial programming’ includes any functionality that is not ‘coextensive’ with a microprocessor or general purpose computer." EON Corp., 785 F.3d at 623 (citations omitted). "Examples of such coextensive functions are ‘receiving’ data, ‘storing’ data, and ‘processing’ data—the only three functions on which the Katz court vacated the district court’s decision and remanded for the district court to determine whether disclosure of a microprocessor was sufficient." Id. at 622. Thus, "[a] microprocessor or general purpose computer lends sufficient structure only to basic functions of a microprocessor. All other computer-implemented functions require disclosure of an algorithm." Claims 1-16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Regarding Claim 9, Claim 9 is indefinite because “wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) module to determine if two entities are related given the entities’ names and types and a text” is unclear. Regarding Claim 10, Claim 10 is indefinite because “wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine if the relationship type between two entities given the entities’ names and types and a text” is unclear. Regarding Claim 16, Claim 16 is indefinite because “wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) to determine if the relationship type between two entities given the entities names and types and a text” is unclear. Regarding Claim 1, Claim 1 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output. Regarding Claim 6, Claim 6 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the entity detection component is configured to receive one of plain text from the report parser or segmented output from the section splitter, wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs. Regarding Claim 7, Claim 7 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure disclosed for wherein the entity detection component is in communication with a plurality of LLMs. Regarding Claim 8, Claim 8 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between multiple type designations to result in a resolved output. Regarding Claim 9, Claim 9 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component, wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs), wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) module to determine if two entities are related given the entities’ names and types and a text. Regarding Claim 10, Claim 10 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component; wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types; wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine if the relationship type between two entities given the entities’ names and types and a text. Regarding Claim 13, Claim 13 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the Human Verification and Feedback component is configured to receive the output of entity detection component, entity type identification component, and the related pairs detection component, wherein the Human Verification and Feedback component allows users to edit the outputs of entity detection component, entity type identification component, and the related pairs detection component. Regarding Claim 14, Claim 14 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output. Regarding Claim 15, Claim 15 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the entity detection component is configured to receive one of the plain text from the report parser or segmented output from the section splitter; wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component; wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component; wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs), wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types. Regarding Claim 16, Claim 16 invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. There is no corresponding structure or algorithm disclosed for wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs; wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, the descriptions of Course of Action objects, wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between the multiple type designations to result in a resolved output; wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) to determine if two entities are related given the entities names and types and a text. Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Regarding Claims 2-5 and 11-12, Dependent Claims 2-5 and 11-12 are rejected under 35 U.S.C. 112(b) for inheriting the deficiencies of Claim 1. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 3, 8-12, and 14 are rejected under 35 U.S.C. 102(a) (2) as being anticipated by Siracusano et al (“Siracusano”, US 20240411994). Regarding Claim 1, Siracusano teaches a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser (Fig. 10, element 1004, par 192; The main module is the overall architecture 1000.), a section splitter (par 96), an entity detection component (par 195), an entity type identification component (par 184), a related pairs detection component (par 184), a relationship types identification component (par 184), a STIX output generator (par 194), and a Human Verification and Feedback module (par 86), and a Fine-tuned Large Language Model (LLM) module with a RegEx engine (par 221-222; par 242), wherein the main module is configured to receive an input (Fig. 10, element 1002, par 192; The main module is the overall architecture 1000.), wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module (par 117-119; Fig. 10, elements {1000, 1016} par 192-193; The main module is the overall architecture 1000.), wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output (par 117-119; Fig. 10, elements {1000, 1016} par 192-193; The main module is the overall architecture 1000.). Regarding Claim 3, Siracusano teaches the system of claim 1. Siracusano further teaches wherein the input is one of a URL, a PDF document, or a text document (par 68). Regarding Claim 8, Siracusano teaches the system of claim 1. Siracusano further teaches wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects (par 184), wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between multiple type designations to result in a resolved output (par 117-119; Fig. 10, elements {1000, 1016} par 184; par 192-197; par 220-222). Regarding Claim 9, Siracusano teaches the system of claim 1. Siracusano further teaches wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component (par 184), wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs) (par 184), wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) module to determine if two entities are related given the entities’ names and types and a text (par 117-119; Fig. 10, elements {1000, 1016} par 184; par 192-197; par 220-222). Regarding Claim 10, Siracusano teaches the system of claim 1. Siracusano further teaches wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component (par 184), wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types, wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine if the relationship type between two entities given the entities’ names and types and a text (par 117-119; Fig. 10, elements {1000, 1016} par 184; par 192-197; par 220-222). Regarding Claim 11, Siracusano teaches the system of claim 1. Siracusano further teaches wherein the STIX output generator is configured to receive a STIX relations matrix that defines valid pair-wise relationships (SROs) (par 184), wherein the STIX output generator merges the STIX relations matrix to generate a JSON file encompassing entities and their relations in STIX format (par 49; par 184). Regarding Claim 12, Siracusano teaches the system of claim 11. Siracusano further teaches wherein the JSON file is the threat analysis output (par 49; par 184). Regarding Cliam 14, Claim 14 is rejected with the same reasoning as Claim 1. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference; nor is it that the claimed invention must be expressly suggested in any one or all of the references. Rather, the test is what the combined teachings of the references would have suggested to those of ordinary skill in the art. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981). Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Siracusano in view of Owhadi Kareshk et al (“Owhadi”, US 20250013909). Regarding Claim 2, Siracusano teaches the system of claim 1. Siracusano does not explicitly teach wherein the main module is model agnostic such that it is configured to communicate with a variety of LLM models in parallel. Owhadi teaches wherein the main module is model agnostic such that it is configured to communicate with a variety of LLM models in parallel (par 19). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Siracusano with the model-agnostic functionality of Owhadi because it allows for the use of different machine learning models, thereby improving output. Allowable Subject Matter Claims 17-20 are allowed. Claims 4-7, 13, and 15-16 would be allowable if rewritten to overcome the rejection(s) under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), 2nd paragraph, set forth in this Office action and to include all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: In interpreting the currently amended claims, in light of the specification, the Examiner finds the claimed invention to be patentably distinct from the prior art of record. Regarding Claim 4, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, a STIX output generator, and a Human Verification and Feedback module, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the report parser is configured to receive the input and convert the input into plain text, wherein the report parser removes all formatting except headings HTML tags from the input, and wherein the report parser converts textual and non-textual content found in CTI reports, tables, and bullet points in the input into plain text. Regarding Claim 5, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, a STIX output generator, and a Human Verification and Feedback module, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the section splitter is configured to receive plain text from the report parser, and wherein the section splitter processes the plain text and segments the plain text into paragraphs using HTML headings to result in a segmented output. Regarding Claim 6-7, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, a STIX output generator, and a Human Verification and Feedback module, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the entity detection component is configured to receive one of plain text from the report parser or segmented output from the section splitter, wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs, and wherein the entity detection component has an identified output. Regarding Claim 13, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, a STIX output generator, and a Human Verification and Feedback module, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the Human Verification and Feedback component is configured to receive the output of entity detection component, entity type identification component, and the related pairs detection component, wherein the Human Verification and Feedback component allows users to edit the outputs of entity detection component, entity type identification component, and the related pairs detection component. Regarding Claim 15, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, and a STIX output generator, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the report parser is configured to receive the input and convert the input into plain text, wherein the section splitter is configured to receive the plain text from the report parser, wherein the entity detection component is configured to receive one of the plain text from the report parser or segmented output from the section splitter, wherein the entity detection component has an identified output, wherein the related pairs detection component is configured to receive an entity type identified output from the entity type identification component, wherein the relationship types identification component, is configured to receive an identified relationship pair from the related pairs detection component, wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships (SROs), wherein the related pairs detection component loads a STIX relations matrix that defines valid pair-wise relationships types, wherein the STIX output generator is configured to receive the STIX relations matrix that defines valid pair-wise relationships (SROs), and wherein the STIX output generator merges the STIX relations matrix to generate a JSON file encompassing entities and their relations in STIX format. Regarding Claim 16, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a system for STIX report generation from threat intelligence text, comprising: a main module, comprising report parser, a section splitter, an entity detection component, an entity type identification component, a related pairs detection component, a relationship types identification component, and a STIX output generator, and a Fine-tuned Large Language Model (LLM) module with a RegEx engine, wherein the main module is configured to receive an input, wherein the main module is in communication with the Fine-tuned Large Language Model (LLM) module, wherein the main module fuses an output from the Fine-tuned Large Language Model (LLM) module to generate a threat analysis output; wherein the report parser removes all formatting except headings HTML tags from the input, wherein the report parser converts textual and non-textual content found in CTI reports, tables, and bullet points in the input into the plain text, wherein the section splitter processes the plain text and segments the plain text into paragraphs using HTML headings to result in the segmented output, wherein the entity detection component identifies the SDOs and SCOs, wherein the entity detection component identifies names of Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, descriptions of Course of Action objects, and value and sub-type of Indicator objects for SDOs, wherein the entity detection component identifies IP addresses, domain names, hashes, emails, MAC addresses, and URLs for SCOs, wherein the entity type identification component is configured to detect entity types such as Attack Pattern, Identity, Location, Malware, Threat Actor, Tool, Vulnerability, the descriptions of Course of Action objects, wherein the entity type identification component communicates with the Fine-tuned Large Language Model (LLM) module to determine a correct entity type between the multiple type designations to result in a resolved output, wherein the related pairs detection component communicates with the Fine-tuned Large Language Model (LLM) to determine if two entities are related given the entities names and types and a text, and wherein the relationship types identification component communicates with the Fine-tuned Large Language Model (LLM) to determine if the relationship type between two entities given the entities names and types and a text. Regarding Claims 17-20, the closest prior art of record Siracusano et al (US 20240411994) in view of Mulchandani et al (US 20170171235) in further view of DRIHEM et al (US 20180343277) and in even further view of Southgate et al (US 20250007926) does not teach a method of generating a STIX report from threat intelligence text, the method comprising: receiving an input in a report parser, converting the input into a plain text in the report parser, receiving the plain text from the report parser in a section splitter, segmenting the plain text into a segmented output in the section splitter, receiving one of the plain text from the report parser or the segmented output from the section splitter in an entity detection component, identifying one of the plain text or the segmented output into an identified output in the entity detection component, receiving the identified output from the entity detection component in an entity type identification component, identifying an entity type identified output in the entity type identification component, receiving the entity type identified output in a related pairs detection component, identifying an identified related pair in the related pairs detection component, receiving the identified related pair in a relationship types identification component, loading a STIX relations matrix to a STIX output generator, and merging the STIX relation matrix in the STIX output generator to generate a JSON file. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Mulchandani et al (US 20170171235), Abstract - Systems, methods, and apparatus, including computer programs encoded on computer storage media, for obtaining, processing, and presenting data related to security events, and for implementing courses of action to protect assets in response to the security events. An event management module identifies malicious activity present on a first network domain and/or a second network domain based on received network domain activity. A threat intelligence module receives data identifying the malicious activity in first data constructs of a predefined data structure. The threat intelligence module obtains additional data related to the identified malicious activity and generates second data constructs that include enriched data regarding the malicious activity. The enriched data includes data describing a campaign in which at least a portion of the malicious activity is involved and one or more courses of action. A course of action module receives the second data constructs and implements a given course of action. DRIHEM et al (US 20180343277), Abstract - Actively and passively monitoring current network security threats and impact, to evaluate and maintain cyber security includes using an innovative combination of threat feed, impact assessment, client profile, security policy, and vulnerability report to determine impact of malware, evaluate and maintain security policy, decrease vulnerability, and dynamically implement solutions to prevent malware attacks. Constantly re-evaluating the customer's cyber security implementation facilitates dynamic tuning of cyber security implementation. Southgate et al (US 20250007926), Abstract - Systems and methods of actor attribution utilizing a machine learning (ML) model, such as a large language model (LLM), are provided. The method includes generating a first ML model based on first data associated with a first cybersecurity incident of a plurality of cybersecurity incidents. The method includes training the first ML model based on actor attribution associated with the first cybersecurity incident to generate a second ML model. The method includes receiving second data that is associated with a second cybersecurity incident of the plurality of cybersecurity incidents. The method includes producing, by a processing device for the second ML model using the second data, an attribution of the second cybersecurity incident to an actor. Polyakov et al (US 20100077481), Abstract - A malware analysis system is described that provides information about malware execution history on a client computer and allows automated back-end analysis for faster creation of identification signatures and removal instructions. The malware analysis system collects threat information on client computers and sends the threat information to a back-end analysis component for automated analysis. The back-end analysis component analyzes the threat information by comparing the threat information to information about known threats. The system builds a signature for identifying the threat family and a mitigation script for neutralizing the threat. The system sends the signature and mitigation data to client computers, which use the information to mitigate the threat. Thus, the malware analysis system detects and mitigates threats more quickly than previous systems by reducing the burden on technicians to manually create environments for reproducing the threats and manually analyze the threat behavior. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RAQIUL AMIN CHOUDHURY whose telephone number is (571)272-2482. The examiner can normally be reached Monday-Friday 7:30 AM - 5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John Follansbee can be reached at 571-272-3964. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RAQIUL A CHOUDHURY/Examiner, Art Unit 2444
Read full office action

Prosecution Timeline

Dec 13, 2024
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706768
FACILITATING EFFICIENT MEETING MANAGEMENT
2y 9m to grant Granted Aug 11, 2026
Patent 12701175
Service Request Processing
1y 12m to grant Granted Aug 04, 2026
Patent 12695784
SYNTHETIC CYBERATTACK TOOL THAT USES A GENERATIVE ARTIFICIAL INTELLIGENCE COMPONENT
2y 1m to grant Granted Jul 28, 2026
Patent 12689536
SYSTEMS AND/OR METHODS FOR ONLINE CONTENT DELIVERY
2y 9m to grant Granted Jul 21, 2026
Patent 12689571
Identifying device type using machine learning on sparsely populated log data
2y 3m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
93%
With Interview (+6.0%)
2y 1m (~5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 254 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month