DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
This is a reply to the amendment filed on 07/16/2026, in which, claim(s) 1-20 are pending. Claim(s) 1-2, 4, 8, 11-12, 14 and 18 are amended. No claim(s) are cancelled or newly added.
Response to Arguments
Claim Rejections - 35 U.S.C. § 102 and 35 U.S.C. § 103:
Applicants’ arguments, see pages 1-5, filed 07/16/2026, regarding the U.S.C. 102 and 103 rejections of claims 1-7, 9-17, and 19-20 have been fully considered and are not persuasive.
Applicants’ arguments that “The cited references do not teach or suggest "wherein the simulated attacks and defense es are selected and generated by a machine learning model utilizing reinforcement learning”” have been considered but are moot in view of the new ground(s) of rejection.
Applicants further argue that “Gula does not teach or suggest to "correlate, by analyzing the captured traffic in real-time, network events with historical incident data"”.
Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Gula teaches analyzing and correlating events logged in the network (i.e., historical incident data) with the information describing the observed network traffic (i.e., the captured traffic in real-time) ([0014]),
Therefore, the rejection is maintained.
Applicants’ arguments with respect to claims 8 and 18 rejected under prior art have been fully considered and are persuasive. The rejection of 35 U.S.C. § 103 of claims 8 and 18 have been withdrawn in view of the amendment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-7, 9-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Gula et al. (US 2015/0222655 A1) in view of Levy et al. (US 8,881,288 B1) further in view of Vasseur et al. (US 2015/0193694 A1).
Regarding Claims 1 and 11, Gula discloses A computer system configured to execute software instructions stored on nontransitory machine-readable storage media ([0018], “the computer-executable instructions, when executed on the one or more processors, may further cause the one or more processors to”), wherein the software instructions comprise instructions that:
capture traffic on a network as a plurality of network events ([0014], “received from the sources distributed across the network and aggregate the normalized events with information describing the network snapshot obtained with the active scanners and/or the network traffic observed with the passive scanners”);
correlate, by analyzing the captured traffic in real-time, network events with historical incident data ([0014], “analyze and correlate events logged in the network with the information describing the observed network traffic”) to:
identify active threats in real time; or identify emerging vulnerabilities within the network ([0014], “to automatically detect statistical anomalies, correlate the events with the vulnerabilities and assets in the network, search the analyzed and correlated information to identify events meeting certain criteria”, [0031], “monitor the network in real-time to detect any potential vulnerabilities in the network in response to identifying interactive or encrypted sessions in the packet stream”);
Gula does not explicitly teach but Levy teaches
instantiate a distributed computational graph (DCG) (Abstract, “generating network-specific attack graphs”) configured to:
create a graph-based model representing the network (Abstract, “generating network-specific attack graphs (model) by combining the type abstract graph with specific network information”);
run simulated attacks and defenses using the model to generate simulation results that predict future states of the network (Abstract, “monitoring an intruder alert; and generating a real-time attack graph by correlating the intruder alert with the network-specific attack graph. The real-time attack graph can be generated using reachability checking, bridging, and exploit prediction based on consequence alerts and may further include the step of calculating the likelihood of queries using a Bayesian network model”, Column 6, “in order to match current, ongoing scenarios and predict future paths for better situational awareness and security response”);
evaluate the simulation results to identify security improvements related to the identified active threats or emerging vulnerabilities; and generate recommendations for implementing the security improvements (Column 12, “suggesting the weakest hosts in the network, while the subject invention incorporates dynamic analysis to carry out dynamic situational awareness, prediction, and responsive action planning”).
Gula and Levy are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Levy with the disclosure of Gula. The motivation/suggestion would have been to carry out dynamic situational awareness, prediction, and responsive action planning (Levy, Column 12).
The combined teaching of Gula and Levy does not explicitly teach but Vasseur teaches
wherein the simulated attacks and defenses are selected and generated by a machine learning model utilizing reinforcement learning ([0096-0099], “After a sufficient attack-free dataset has been collected, a dataset including attacks may be generated in order to appropriately train the ANN or other learning machine. Thus, the techniques herein provide mechanisms whereby attacks are generated and simulated (reinforced) (i.e., initiated by the network itself in a controlled manner)”, “the FAR agent (i.e., the learning machine hosted on the FAR) selects the nodes to be turned into attackers by using a learning machine-agnostic policy (e.g., by random or round robin selection)”),
Gula, Levy and Vasseur are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Vasseur with the combined teaching of Gula and Levy. The motivation/suggestion would have been to increase the variability captured in the dataset and improves convergence in the training (Vasseur, [0098]).
Regarding Claims 2 and 12, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG is further configured to:
use the machine learning model to generate attack and defense strategies based on the simulation results (Vasseur, [0096-0099], “After a sufficient attack-free dataset has been collected, a dataset including attacks may be generated in order to appropriately train the ANN or other learning machine. Thus, the techniques herein provide mechanisms whereby attacks are generated and simulated (reinforced) (i.e., initiated by the network itself in a controlled manner)”, “the FAR agent (i.e., the learning machine hosted on the FAR) selects the nodes to be turned into attackers by using a learning machine-agnostic policy (e.g., by random or round robin selection)”);
run additional simulated attacks and defenses using the generated attack and defense strategies; determine effectiveness of the strategies using results of the additional simulated attacks and defenses; and modify the generated recommendations based on the defense strategies (Levy, Abstract, “monitoring an intruder alert; and generating a real-time attack graph by correlating the intruder alert with the network-specific attack graph. The real-time attack graph can be generated using reachability checking, bridging, and exploit prediction based on consequence alerts and may further include the step of calculating the likelihood of queries using a Bayesian network model”, Column 6-7, “in order to match current, ongoing scenarios and predict future paths for better situational awareness and security response”, “situational awareness 30 be provided in real-time in order to make the system effective”).
Regarding Claims 3 and 13, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG is further configured to:
enrich the captured traffic with metadata and contextual information comprising user activity, device configurations, and environmental factors, to improve threat detection accuracy (Levy, Column 2, “attack graph is rich in semantics, since essentially, it is capable of modeling all aspects of a network state, security attributes, and attack methods”).
Regarding Claims 4 and 14, the combined teaching of Gula, Levy and Vasseur teaches
receive the historical incident data, wherein the historical incident data comprises sequences of events and device responses from prior cyberattacks (Levy, Column 8, Lines 21-34, “To examine how previous (i.e. historical) attack actions/exploits may affect future actions, it can be seen how exploit 54a may lead to exploits 54b and 54c”);
analyze the historical incident data using machine learning algorithms to identify recurring patterns of attack strategies (Vasseur, [0039], “machine learning (ML) is concerned with the design and the development of algorithms that take as input empirical data (such as network statistics and performance indicators), and recognize complex patterns in these data”);
cluster similar attack patterns based on their characteristics and outcomes; generate predictions of probable future attack strategies based on the identified patterns; and simulate defensive responses against the predicted attack strategies using the graph-based model (Levy, Abstract, “monitoring an intruder alert; and generating a real-time attack graph by correlating the intruder alert with the network-specific attack graph. The real-time attack graph can be generated using reachability checking, bridging, and exploit prediction based on consequence alerts and may further include the step of calculating the likelihood of queries using a Bayesian network model”, Column 6-7, “in order to match current, ongoing scenarios and predict future paths for better situational awareness and security response”, “situational awareness 30 be provided in real-time in order to make the system effective”).
Regarding Claims 5 and 15, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG is further configured to display correlated threats, remediation pathways, and predicted network states through an interactive graphical interface (Levy, Column 9, “NAG 64 and RAG 66 can help provide situational awareness 80, prediction 82, and action planning 84. The output of the system includes several kinds of views. One view is the network topology, and the second view is the status-view. For example, some hosts under attack can be illustrated by different colors or flashes. The next view is the future-view, which shows possibilities, and which hosts are the most likely targets. The views can be shown on different displays”).
Regarding Claims 6 and 16, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG is further configured to tailor recommendations to individual user roles and operational contexts, using historical response effectiveness metrics to optimize recommended actions (Levy, Column 12, “suggesting the weakest hosts in the network”, “A known optimized logic reasoning engine, such as XSB, can be used as the logic analyzer to compute the network states, such as reachability and vulnerability, against the TAG interaction rules”).
Regarding Claims 7 and 17, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG is further configured to distribute processing tasks across multiple computing nodes wherein:
each computing node is configured to process a portion of the simulation workload; and the system scales computational resources dynamically based on simulation complexity and processing requirements (Levy, Column 8, “referring to FIG. 6, to achieve scalability, a state hierarchy, generally indicated as 110, is defined. Three layers of the hierarchy states include a host layer 112, a state layer 114a-c, and a vulnerability layer 116a-c”).
Regarding Claims 9 and 19, the combined teaching of Gula, Levy and Vasseur teaches
wherein the recommended security improvements are automatically implemented (Gula, [0030], “automatically reconstruct the network sessions, build or update the network model, identify the network vulnerabilities, and detect the traffic potentially targeting the network vulnerabilities in response to any new or changed information in the network”).
Regarding Claims 10 and 20, the combined teaching of Gula, Levy and Vasseur teaches
wherein the DCG operates continuously to provide ongoing security improvements (Gula, [0015], “continuously or periodically observe traffic traveling in the network to identify vulnerabilities”, Levy, Abstract, “network-specific attack graphs”).
Allowable Subject Matter
Claims 8 and 18 are objected to as being dependent upon rejected base claims 1 and 11 but would be allowable if rewritten in independent form including all the limitations of the base claim and any intervening claims.
None of the prior art, alone or in combination teaches the claim limitations of claims 8 and 18 in view of the other limitations of claims 1 and 11.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHENG-FENG HUANG whose telephone number is (571)272-6186. The examiner can normally be reached Monday-Friday: 9 am - 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHENG-FENG HUANG/Primary Examiner, Art Unit 2497