DETAILED ACTION
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
2. Claims 1-20 are pending. Claims 1, 12 and 17 are independent.
3 The IDS submitted on 1/6/2025 has been considered.
Claim Rejections - 35 USC § 103
4. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
6. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Noel (US PG Pub. 2017/0289187) in view of Park (US PG Pub. 2019/0158309).
As regarding claim 1, Noel discloses A computer-implemented method comprising:
normalizing, by at least one processor, cyber information received for a plurality of cyberspace entities [para. 24; normalizing data ingested from sensors];
generating, by the at least one processor, one or more cyber-graphs based on relationships between two or more of the plurality of cyberspace entities [FIG. 2, para. 26-28 and 30; generating graphs illustrated in FIG. 2];
receiving, by the at least one processor, a cyber-threat inquiry of the cyber-graphs [para. 36-38; receiving a user query];
configuring the one or more cyber-graphs as nodes represented by the plurality of cyberspace entities and edges represented by relationships between the plurality of cyberspace entities [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes];
further configuring the nodes to represent mission-dependent operations for an organization mission and further linking to network service nodes used by the mission-dependent operations [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes]; and
rendering on a geographical map the one or more cyber-graphs that represent impacts on a plurality of the mission-dependent operations for an organization mission suspected to be compromised by a cyber-threat actor [para. 27 and 42-48; providing cyber-graphs including asset components that are vulnerable to attacks].
Noel does not explicitly disclose rendering on a geographical map, based on a location of the cyber-threat inquiry, the one or more cyber-graphs; however, Park discloses it [para. 352; inquiring the space graph based on a location of the query].
It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Noel’s system to further comprise the missing claim features, as disclosed by Park, as one of a plurality attributes associated with an object entity that are used to query other attributes associated with the object entity.
As regarding claim 2, Noel further discloses The method of claim 1, further comprising: aggregating the cyber-graphs into an active knowledge database [para. 23-28].
As regarding claim 3, Noel further discloses The method of claim 2, the generating the cyber-graphs further comprising: selecting the cyber-graphs related to the cyber-threat inquiry from the active knowledge database [para. 41-55].
As regarding claim 4, Noel and Park further discloses The method of claim 1, further comprising: generating the cyber-threat inquiry by converting a natural language inquiry to a formal query language [Noel para. 44 and Park para. 61, 68 and 351].
As regarding claim 5, Park further discloses The method of claim 1, further comprising: receiving location information associated with the plurality of cyberspace entities [para. 352].
As regarding claim 6, Park further discloses The method of claim 5, further comprising: filtering the location information associated with the plurality of cyberspace entities to match the location to a corresponding operational environment [para. 301].
As regarding claim 7, Park further discloses The method of claim 1, the normalizing further comprising: capturing the cyber information from streaming data [para. 22].
As regarding claim 8, Noel further discloses The method of claim 1, further comprising: linking to virtual machine nodes that are dependent on the network service nodes [para. 28-30].
As regarding claim 9, Noel further discloses The method of claim 1, further comprising: linking to deployment platform nodes that are dependent on the network service nodes [para. 28-30].
As regarding claim 10, Noel further discloses The method of claim 1, wherein the cyber information includes any of: network infrastructure, security posture, cyber threats, or operational dependencies [para. 20].
As regarding claim 11, Noel further discloses The method of claim 1, wherein the plurality of cyberspace entities are represented as Internet Protocol (IP) addresses for virtual machines [para. 39 and 59].
As regarding claim 12, Noel discloses A system, comprising:
a memory [para. 73]; and
at least one processor coupled to the memory and configured [para. 71 and 73] to:
normalize, by at least one processor, cyber information received for a plurality of cyberspace entities [para. 24; normalizing data ingested from sensors];
generate, by the at least one processor, one or more cyber-graphs based on relationships between two or more of the plurality of cyberspace entities [FIG. 2, para. 26-28 and 30; generating graphs illustrated in FIG. 2];
receive, by the at least one processor, a cyber-threat inquiry of the cyber-graphs [para. 36-38; receiving a user query];
configure the one or more cyber-graphs as nodes represented by the plurality of cyberspace entities and edges represented by relationships between the plurality of cyberspace entities [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes];
further configure the nodes to represent mission-dependent operations for an organization mission and further link to network service nodes used by the mission-dependent operations [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes]; and
render on a geographical map the one or more cyber-graphs that represent impacts on a plurality of the mission-dependent operations for an organization mission suspected to be compromised by a cyber-threat actor [para. 27 and 42-48; providing cyber-graphs including asset components that are vulnerable to attacks].
Noel does not explicitly disclose rendering on a geographical map, based on a location of the cyber-threat inquiry, the one or more cyber-graphs; however, Park discloses it [para. 352; inquiring the space graph based on a location of the query].
It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Noel’s system to further comprise the missing claim features, as disclosed by Park, as one of a plurality attributes associated with an object entity that are used to query other attributes associated with the object entity.
As regarding claim 13, Noel further discloses The system of claim 12, the at least one processor further configured to: aggregate the cyber-graphs into an active knowledge database [para. 23-28].
As regarding claim 14, Noel further discloses The system of claim 12, the at least one processor further configured to: select the one or more cyber-graphs related to the location of the cyber-threat inquiry from the active knowledge database [para. 41-55].
As regarding claim 15, Noel further discloses The system of claim 12, wherein the cyber information includes any of network infrastructure, security posture, cyber threats, or mission dependencies [para. 20].
As regarding claim 16, Noel further discloses The system of claim 12, wherein the plurality of cyberspace entities are represented as Internet Protocol (IP) addresses for virtual machines [para. 39 and 59].
As regarding claim 17, Noel discloses A non-transitory computer-readable device having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:
normalizing, by at least one processor, cyber information received for a plurality of cyberspace entities [para. 24; normalizing data ingested from sensors];
generating, by the at least one processor, one or more cyber-graphs based on relationships between two or more of the plurality of cyberspace entities [FIG. 2, para. 26-28 and 30; generating graphs illustrated in FIG. 2];
receiving, by the at least one processor, a cyber-threat inquiry of the cyber-graphs [para. 36-38; receiving a user query];
configuring the one or more cyber-graphs as nodes represented by the plurality of cyberspace entities and edges represented by relationships between the plurality of cyberspace entities [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes];
further configuring the nodes to represent mission-dependent operations for an organization mission and further linking to network service nodes used by the mission-dependent operations [para. 26-28, 30, 41 and 42; generating graphs including nodes represented various entities and edges represented relationships between nodes]; and
rendering on a geographical map the one or more cyber-graphs that represent impacts on a plurality of the mission-dependent operations for an organization mission suspected to be compromised by a cyber-threat actor [para. 27 and 42-48; providing cyber-graphs including asset components that are vulnerable to attacks].
Noel does not explicitly disclose rendering on a geographical map, based on a location of the cyber-threat inquiry, the one or more cyber-graphs; however, Park discloses it [para. 352; inquiring the space graph based on a location of the query].
It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Noel’s system to further comprise the missing claim features, as disclosed by Park, as one of a plurality attributes associated with an object entity that are used to query other attributes associated with the object entity.
As regarding claim 18, Noel further discloses The non-transitory computer-readable device of claim 17, the operations further comprising: aggregating the cyber-graphs into an active knowledge database [para. 23-28].
As regarding claim 19, Noel further discloses The non-transitory computer-readable device of claim 17, the operations further comprising: selecting the one or more cyber-graphs related to the location of the cyber-threat inquiry from the active knowledge database [para. 41-55].
As regarding claim 20, Noel further discloses The non-transitory computer-readable device of claim 17, wherein the plurality of cyberspace entities are represented as Internet Protocol (IP) addresses for virtual machines [para. 39 and 59].
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to THONG P TRUONG whose telephone number is (571)270-7905. The examiner can normally be reached on M-F 8:30AM - 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 57127267986798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/THONG TRUONG/
Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433