DETAILED ACTION
This office action is in response to the application filed on 01/03/2025. Claims 1-20 are pending and are examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Applicant’s benefit claim is hereby acknowledged of the U.S patent application No. 18/614,345, filed on March 22, 2024, which is a Continuation of U.S. Application No. 18/204,250, filed on May 31, 2023, which claims priority to U.S. Provisional Application No. 63/457,671, filed April 6, 2023, and U.S. Provisional Application No. 63/347,389, filed May 31, 2022, each of which are incorporated herein by reference in their entireties and for all purposes.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 01/03/2025, 03/07/2025, 04/08/2025, 07/03/2025, 12/09/2025, 03/17/2026, 05/14/2026 and 07/10/2026, were filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b)
(B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 1 recites the term, “the at least one entity”, in the limitations “(ii) data corresponding to one or more offerings or one or more transactions between the at least one entity and one or more third-parties, or (iii) one or more security incidents corresponding with the at least one entity”. There is insufficient antecedent basis for this term in the claims.
Regarding independent claim 1, the limitations "generate, for one or more AI agentic approaches of the plurality of agentic approaches, one or more of: a resource utilization estimate or a performance estimate, wherein the resource utilization estimate represents an anticipated resource consumption of each AI agentic approach and the performance estimate represents a value of an expected output from each AI agentic approach”, “execute, based on the one or more of the resource utilization estimate or the performance estimate for each AI agentic approach, a particular AI agentic approach of the plurality of agentic approaches” and “record, via a distributed ledger, (1) the particular AI agentic approach and (2) the resource utilization estimate or the performance estimate.", recited in the indicated claim are unclear which renders the claim indefinite.
The claim as a whole recites multiple alternative features and processes, and under the broadest reasonable interpretation of the claim language, the multiple alternative features and processes recited in the claim are leading to different interpretations of the scope of the claimed invention, which rends the real scope of the invention unclear and therefore renders the claim indefinite.
Same reasoning applies to independents claims 11 and 20 and therefore they are rejected under 35 U.S.C. 112(b).
Regarding dependent claims 2-10 and 12-19, the dependent claims are rejected under 35 U.S.C. 112(b) based on their dependency from the rejected claims 1 and 11 respectively.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-4, 9, 11-14 and 19-20, are rejected under AIA 35 U.S.C. 102(a) (1) as being unpatentable over Pearcy et al. (U.S. Pub. No. 2015/0,074,750 A1, referred to as Pearcy).
Regarding claims 1, 11 and 20, Pearcy teaches:
A method, comprising:
receiving or identifying, by one or more processing circuits, at least one of (i) one or more remediation actions, security capabilities (Pearcy: Fig. 4A and Fig. 4B; ¶ 0057- ¶ 0058, “Managing and visualizing relationships between security events and policies can also be driven from a policy-centric context. For example, as shown in the example of FIG. 4B, a plurality of security policies can be identified 430 ”), or assets of at least one entity, (ii) data corresponding to one or more offerings or one or more transactions between the at least one entity and one or more third-parties, or (iii) one or more security incidents corresponding with the at least one entity;
generating, by the one or more processing circuits, at least one graphical user interface (GUI) comprising a plurality of interactive items, wherein the plurality of interactive items comprise: one or more first interactive items configured to cause the one or more processing circuits, responsive to a first interaction with the one or more first interactive items, to determine or update the one or more remediation actions, security capabilities, or assets (Pearcy: Fig. 4A and Fig. 4B; ¶ 0057- ¶ 0058, “GUI presentation generated 435 that includes a policy-centric graphical representation of the policies. (In some instances, the identified security policies and graphical representations can correspond to the identified (e.g., 420) subset of security policies and generated (e.g., 425) graphical representation, as well as from interactions with an event-centric context, as in the example of FIG. 4A)”);
one or more second interactive items configured to cause the one or more processing circuits, responsive to a second interaction with the one or more second interactive items, to present the one or more offerings or perform the one or more transactions; or one or more third interactive items configured to cause the one or more processing circuits, responsive to a third interaction with the one or more third interactive items, to initiate at least one of the one or more remediation actions or present incident data corresponding with the one or more security incidents; and
providing, by the one or more processing circuits, the GUI to an entity computing system of the at least one entity (Pearcy: Fig. 3A- Fig. 3I; Fig. 4A and Fig. 4B; ¶ 0057- ¶ 0058, “A user can interact with the graphical representations, for instance, to identify (e.g., at 440) a subset of one or more policies represented in the GUI presentation. Such user interactions can serve to identify 445 a subset of detected security events corresponding to (e.g., triggered by violations of or in connection with) the one or more policies. Further, a graphical representation of the identified security events can be generated 450 (and integrated with the generated GUI presentation) to reflect and represent the security events.”) or a third-party computing system of the one or more third-parties.
Regarding claim 11, Pearcy further teaches:
A system, comprising: one or more processing circuits (Pearcy: ¶ 0062, “The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources. The terms “data processing apparatus,” “processor,” “processing device,” and “computing device” can encompass all kinds of apparatus, devices, and machines for processing data”).
Regarding claim 20, Pearcy further teaches:
A non-transitory computer readable medium (CRM) comprising one or more instructions stored thereon (Pearcy: ¶ 0062, “The operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources. The terms “data processing apparatus,” “processor,” “processing device,” and “computing device” can encompass all kinds of apparatus, devices, and machines for processing data”).
Regarding claims 2 and 12, Pearcy teaches all the features of claims 1 and 11, as outlined above.
Pearcy further teaches:
wherein the plurality of interactive items correspond with at least one of a meeting, a vendor dashboard, a customer dashboard, a product offering, a posture stream, a real-time threat or incident, or a metric, (Pearcy: ¶ 0058, “GUI presentation generated 435 that includes a policy-centric graphical representation of the policies. (In some instances, the identified security policies and graphical representations can correspond to the identified (e.g., 420) subset of security policies and generated (e.g., 425) graphical representation, as well as from interactions with an event-centric context, as in the example of FIG. 4A). A user can interact with the graphical representations, for instance, to identify (e.g., at 440) a subset of one or more policies represented in the GUI presentation. Such user interactions can serve to identify 445 a subset of detected security events corresponding to (e.g., triggered by violations of or in connection with) the one or more policies.”).
Regarding claims 3 and 13, Pearcy teaches all the features of claims 2 and 12, as outlined above.
Pearcy further teaches:
wherein determining or updating the one or more remediation actions, security capabilities, or assets comprises: initiating or updating, by the one or more processing circuits, responsive to the first interaction or the third interaction, the at least one of the meeting, the vendor dashboard, the customer dashboard, the product offering, the posture stream, the real-time threat or incident, or the metric (Pearcy: ¶ 0058, “GUI presentation generated 435 that includes a policy-centric graphical representation of the policies. (In some instances, the identified security policies and graphical representations can correspond to the identified (e.g., 420) subset of security policies and generated (e.g., 425) graphical representation, as well as from interactions with an event-centric context, as in the example of FIG. 4A). A user can interact with the graphical representations, for instance, to identify (e.g., at 440) a subset of one or more policies represented in the GUI presentation. Such user interactions can serve to identify 445 a subset of detected security events corresponding to (e.g., triggered by violations of or in connection with) the one or more policies.”).
Regarding claims 4 and 14, Pearcy teaches all the features of claims 3 and 13, as outlined above.
Pearcy further teaches:
wherein initiating or updating the at least one of the meeting, the vendor dashboard, the customer dashboard, the product offering, the posture stream, the real-time threat or incident, or the metric comprises: transmitting, by the one or more processing circuits, one or more notifications or alerts corresponding to the at least one of the meeting, the vendor dashboard, the customer dashboard, the product offering, the posture stream, the real-time threat or incident, or the metric; or
transmitting, by the one or more processing circuits, at least one request corresponding with the at least one of the meeting, the vendor dashboard, the customer dashboard, the product offering, the posture stream, the real-time threat or incident, or the metric (Pearcy: ¶ 0049- ¶ 0056, “While some of the previous examples involve a user's interactions with a particular bubble-type data representation to further subsequent analytics tasks, other GUI windows and data representation types can be available to a user. Indeed, in some instances, a user can switch, replace, or otherwise change the type of a previously presented data representation, for instance, to analyze data from a new or otherwise different perspective. For instance, as shown in the example of FIG. 3F, a user can elect to minimize an initially presented bubble-type or other type of data representation (e.g., 308) and request or cause the generation of an alternate data representation from which to proceed and analyze security events (or policy)”).
Regarding claims 9 and 19, Pearcy teaches all the features of claims 1 and 11, as outlined above.
Pearcy further teaches:
wherein initiating the one or more remediation actions or presenting the incident data comprises: identifying, by the one or more processing circuits, at least one status of the one or more security incidents; and displaying, by the one or more processing circuits, the at least one status using at least one item of the one or more third interactive items of the GUI (Pearcy: Fig. 4A and Fig. 4B; ¶ 0057- ¶ 0058, “FIGS. 4A-4B are simplified flowcharts 400 a, 400 b illustrating example techniques for integrating management of security events and security policies. For example, in FIG. 4A, a plurality of security events can be identified 405 within a system, such as security events that have been, or are being detected by one or more security tools deployed within a system. A GUI presentation, such as a GUI associated with a security tool management or analytics application, can be generated 410 to include a graphical representation of the identified security events and related data.”).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was.
Claims 6, 8, 16 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Pearcy, in view of Murphy et al. (U.S Pub No. 2022/0,164,440 A1, referred to as Murphy).
Regarding claims 6 and 16, Pearcy teaches all the features of claims 1 and 11, as outlined above.
Pearcy does not explicitly disclose, however Murphy teaches:
wherein presenting the one or more offerings comprises: displaying, by the one or more processing circuits, using the one or more second interactive items, one or more plans offered by one or more vendors (Murphy: Fig. 32; ¶ 0294- ¶ 0295, “Further and when providing 1634 suggestions to the third-party (e.g., the user/owner/operator of computing platform 60) concerning additional actions to be taken by the third-party (e.g., the user/owner/operator of computing platform 60) concerning the investigation of the security event, threat mitigation process 10 may provide 1640 suggestions to the third-party (e.g., the user/owner/operator of computing platform 60) concerning a remedial action (e.g., the execution of one or more of remedial plans 1696) to be taken by the third-party (e.g., the user/owner/operator of computing platform 60) when investigating the security event.”).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Pearcy by Murphy and provide suggestions of executing one or more remedial plans based on the result of investigating a security event to improve the security of the system. (Murphy: ¶ 0294- ¶ 0295).
Regarding claims 8 and 18, Pearcy teaches all the features of claims 1 and 11, as outlined above.
Pearcy does not explicitly disclose, however Murphy teaches:
wherein initiating the one or more remediation actions or presenting the incident data comprises: initiating or joining, by the one or more processing circuits, at least one meeting corresponding with the one or more security incidents; or identifying or displaying, by the one or more processing circuits, one or more lists of active tasks corresponding with the one or more remediation actions or the one or more security incidents (Murphy: Fig. 32; ¶ 0294- ¶ 0295, “Further and when providing 1634 suggestions to the third-party (e.g., the user/owner/operator of computing platform 60) concerning additional actions to be taken by the third-party (e.g., the user/owner/operator of computing platform 60) concerning the investigation of the security event, threat mitigation process 10 may provide 1640 suggestions to the third-party (e.g., the user/owner/operator of computing platform 60) concerning a remedial action (e.g., the execution of one or more of remedial plans 1696) to be taken by the third-party (e.g., the user/owner/operator of computing platform 60) when investigating the security event.”).
Same motivation as claims 6 and 16.
Allowable Subject Matter
Claims 5, 7, 10, 15 and 17 would be allowable if they were rewritten in independent form including all of the limitations of the base claim and any intervening claims, also should applicant overcome the claims rejections under 35 U.S.C. 112(b), set forth in this office action.
The following is an examiner’s statement of reasons for identifying allowable subject matter.
The closest prior arts made of records are, Pearcy et al. (U.S. Pub. No. 2015/0,074,750 A1, referred to as Pearcy), Murphy et al. (U.S Pub No. 2022/0,164,440 A1, referred to as Murphy) and Lin et al. (U.S Patent No. 11,503,061 B1, referred to as Lin).
Pearcy discloses a plurality of security events is detected in a computing system, each security event based on at least one policy in a plurality of security policies. Respective interactive graphical representations are presented in a graphical user interface (GUI) of either or both of the security events or security policies. The representations include interactive graphical elements representing the respective security events or security policies.
Murphy discloses method, computer program product and computing system for: a computer-implemented method is executed on a computing device and includes: obtaining object information concerning one or more initial objects within a computing platform in response to a security event; identifying an event type for the security event; and executing a response script based, at least in part, upon the event type.
Lin discloses systems and methods are provided to build a machine learned exploitability risk model that predicts, based on the characteristics of a set of machines, a normalized risk score quantifying the risk that the machines are exploitable by a set of attacks. To build the model, a training dataset is constructed by labeling characteristic data of a population of machines with exploitation test results obtained by simulating a set of attacks on the population. The model is trained using the training data to accurately predict a probability that a given set of machines is exploitable by the set of attacks. In embodiments, the model may be used to make quick assessments about how vulnerable a set of machines are to the set of attacks. In embodiments, the model may be used to compare the effectiveness of different remediation actions to protect against the set of attacks.
However, regarding claims 5 and 15, the prior art of Pearcy, Murphy and Lin when taken in the context of the claim as a whole do not disclose nor suggest, “wherein determining or updating the one or more remediation actions, security capabilities, or assets comprises: receiving, by the one or more processing circuits, at least one input corresponding with entity assets, capabilities, or environments of the at least one entity; determining, by the one or more processing circuits, a readiness of the at least one entity based on the at least one input; and displaying, by the one or more processing circuits, at least one of (i) the entity assets, capabilities, or environments or (ii) the readiness of the at least one entity.”.
Regarding claims 7 and 17, the prior art of Pearcy, Murphy and Lin when taken in the context of the claim as a whole do not disclose nor suggest, “connecting or updating, by the one or more processing circuits, at least one user account for performing or initiating at least one of the one or more offerings or the one or more transactions; and sending or receiving, by the one or more processing circuits, one or more invoices corresponding with the at least one of the one or more offerings or the one or more transactions.”.
Regarding claim 10, the prior art of Pearcy, Murphy and Lin when taken in the context of the claim as a whole do not disclose nor suggest, “wherein the plurality of interactive items correspond with one or more questionaries or applications presented using the GUI, and the method further comprising: prefilling, by the one or more processing circuits, the one or more questionaries or application.”.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: See PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN SAADOUN whose telephone number is (571)272-8408. The examiner can normally be reached Mon-Fri 9:00-5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mehrmanesh Amir can be reached at 571-2703351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HASSAN SAADOUN/ Examiner, Art Unit 2435
/AMIR MEHRMANESH/ Supervisory Patent Examiner, Art Unit 2435