Prosecution Insights
Last updated: September 17, 2026
Application No. 19/056,199

SYSTEM AND METHOD FOR OPTIMIZING RESPONSES TO CYBER ATTACKS

Final Rejection §103§112
Filed
Feb 18, 2025
Priority
Feb 29, 2024 — provisional 63/559,648
Examiner
BROCKINGTON III, WILLIAM S
Art Unit
3623
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Cyberactive Technologies LLC
OA Round
2 (Final)
42%
Grant Probability
Moderate
3-4
OA Rounds
2y 4m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 42% of resolved cases
42%
Career Allowance Rate
214 granted / 508 resolved
-9.9% vs TC avg
Strong +55% interview lift
Without
With
+54.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
45 currently pending
Career history
546
Total Applications
across all art units

Statute-Specific Performance

§101
33.1%
-6.9% vs TC avg
§103
36.0%
-4.0% vs TC avg
§102
2.9%
-37.1% vs TC avg
§112
26.0%
-14.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 508 resolved cases

Office Action

§103 §112
DETAILED ACTION The following is a Final Office Action on the Merits in response to communications filed June 18, 2026. Claims 1–14 are amended; claims 15–20 are canceled; and claims 21–22 are newly added. Claims 1–14 and 21–22 are currently pending. Response to Amendment/Argument Applicant’s Response is sufficient to overcome the previous objection to claim 14 for informalities. Accordingly, the previous objection to claim 14 is withdrawn. Applicant’s Response is sufficient to overcome the previous rejection of claims 1–20 under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Accordingly, the previous rejection of claims 1–20 under 35 U.S.C. 112(b) is withdrawn. However, Applicant’s Response necessitates new grounds of rejection under 35 U.S.C. 112(b), and Examiner directs Applicant to the relevant explanation below. Applicant’s Response is sufficient to overcome the previous rejection of claims 1–20 under 35 U.S.C. 101 as being directed to non-statutory subject matter. More particularly, the additional elements of claims 1 and 8, including the elements to “execute the selected response on a group of assets, wherein the selected response includes at least one of isolating an endpoint device or restricting access to a server device”, integrate the abstract idea into a practical application under Step 2A Prong Two because the additional elements embody an improvement to other technology. Accordingly, the previous rejection of claims 1–20 under 35 U.S.C. 101 is withdrawn. With respect to the previous rejections under 35 U.S.C. 102(a)(1) and 35 U.S.C. 103, Applicant’s remarks have been fully considered but are moot in view of the updated grounds of rejection asserted below. Claim Rejections - 35 USC § 112(b) The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 21–22 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 21 recites “the cyber-attack loss” and “the business disruption loss” in the element to “calculate” and further recites “the node type”, “the infrastructure nodes”, and “the calculated risk level” in the element beginning “automatically”. There is insufficient antecedent basis for these limitations in the claim. For purposes of examination, claim 21 is interpreted as reciting functionality to “calculate a combined loss level based on the loss caused by the at least one cyber-attack loss caused by business disruptions network when [[the]] a node type corresponds to a network user profile to restrict server access, and (ii) isolate the at least one infrastructure node to disconnect network communication paths when the node type corresponds to a firewall, thereby limiting lateral risk propagation across [[the]] infrastructure nodes, when the combined loss level exceeds the response threshold”. In view of the above, claim 21 is rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Claim 22, which depends from claim 21, inherits the deficiencies described above. As a result, claim 22 is similarly rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Claim 22 recites “the group of assets” in line 4. There is insufficient antecedent basis for “the group of assets” in the claim. For purposes of examination, claim 22 is interpreted as reciting “[[the]] a group of assets”. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1–4, 6, 8–11, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Paté-Cornell et al. (Paté-Cornell, M-Elisabeth, and Marshall A. Kuypers. "A probabilistic analysis of cyber risks." IEEE Transactions on Engineering Management 70.1 (2021): 3-13.) in view of Engelberg et al. (U.S. 2022/0263855). Claims 1 and 8: Paté-Cornell discloses a system to: determine a loss caused by at least one cyber-attack using a probability distribution of potential losses per incident (See pg. 6, col. 1, wherein impacts include direct costs associated with cybersecurity incidents, and wherein probabilistic distributions are determined for each attack type, frequency, and impact); determine a loss caused by business disruptions resulting from responses to the at least one cyber-attack using a probability distribution of losses due to business disruptions (See pg. 6, col. 1, wherein impacts include business interruption costs associated with cybersecurity incidents, and wherein probabilistic distributions are determined for each attack type, frequency, and impact); and select a response to the at least one cyber-attack to minimize total combined losses determined from the loss caused by the at least one cyber-attack and the loss caused by business disruptions (See pg. 6, col. 2, wherein countermeasures are selected based on risk-reduction benefits). Paté-Cornell does not expressly disclose the remaining claim elements. Engelberg discloses a system comprising a computer including a processor and a memory, the memory including instructions such that the processor is programmed to perform operations (See paragraph 11); and execute the selected response on a group of assets, wherein the selected response includes at least one of isolating an endpoint device or restricting access to a server device (See paragraphs 58–59 and 61–62, wherein remediation options are executed to reduce the attack surface by limiting lateral movements of an attack). Paté-Cornell discloses a system directed to assessing and managing cybersecurity incidents. Engelberg discloses a system directed to prioritizing cyber risk remediations. Each reference discloses a system directed to analyzing and managing cyber threats. The technique of executing responses is applicable to the system of Paté-Cornell as they each share characteristics and capabilities; namely, they are directed to analyzing and managing cyber threats. One of ordinary skill in the art would have recognized that applying the known technique of Engelberg would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Engelberg to the teachings of Paté-Cornell would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate cyber threat analysis and management into similar systems. Further, applying response execution to Paté-Cornell would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow more detailed analysis and more reliable results. Claims 2 and 9: Paté-Cornell discloses the system of claim 1 wherein the system is configured to execute a simulation engine utilizing a plurality of Monte Carlo simulations to repeatedly calculate a total combined loss value for a plurality of distinct combinations of the at least one cyber-attack, the group of assets, and candidate responses to the at least one cyber-attack. (See pg. 6, col. 1, in view of pg. 6, col. 2, wherein the risk curve is calculated using a Monte Carlo simulation, and wherein the simulation is repeatedly run based on parameter changes derived from countermeasures). Paté-Cornell does not expressly disclose the remaining claim elements. Engelberg discloses a processor (See citations above). One of ordinary skill in the art would have recognized that applying the known technique of Engelberg would have yielded predictable results and resulted in an improved system for the same reasons as stated above with respect to claim 1. Claims 3 and 10: Paté-Cornell discloses the system of claim 1 wherein the probability distribution of potential losses per incident is constructed utilizing at least one of a lognormal distribution, a Poisson distribution, a negative binomial distribution, a beta distribution, a gamma distribution, a uniform distribution, or an exponential distribution (See pg. 6, col. 2, wherein probability distributions are modeled using a Poisson process). Claims 4 and 11: Paté-Cornell discloses the system of claim 1, wherein the probability distribution of losses due to business disruptions incorporates model parameters quantifying at least one of a duration of critical system downtime, a potential loss in revenue per unit of operational unavailability, a cost associated with temporary operational workarounds, a loss in employee productivity, or service level agreement (SLA) penalties (See pg. 6, col. 1, wherein the probability distributions are modeled based on a disruption of operations, unavailability of services, or loss of internal productivity). Claims 6 and 13: Paté-Cornell does not expressly disclose the elements of claims 6 and 13. Engelberg discloses wherein the processor is further programmed to maintain an organizational asset inventory data structure mapping the group of assets to multiple possible response playbooks, wherein individual assets are categorized within the organizational asset inventory data structure by a plurality of static attributes comprising device type, operating system, patch-level security status, network connection type, and operational criticality rank (See paragraph 59, in view of paragraphs 48–49 and 61–62, wherein remediation action recommendations are generated for each issue using a service and/or security knowledge base, wherein issues are clustered and evaluated according to each feature, wherein the system updates over time, and wherein Examiner submits that the listed attributes are afforded limited patentable weight as nonfunctional descriptive material because the listed attributes do not patentably limit the functionality to maintain a data structure; see also paragraphs 130–132). One of ordinary skill in the art would have recognized that applying the known technique of Engelberg would have yielded predictable results and resulted in an improved system for the same reasons as stated above with respect to claim 1. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Paté-Cornell et al. (Paté-Cornell, M-Elisabeth, and Marshall A. Kuypers. "A probabilistic analysis of cyber risks." IEEE Transactions on Engineering Management 70.1 (2021): 3-13.) in view of Engelberg et al. (U.S. 2022/0263855), and in further view of Almukaynizi et al. (U.S. 2022/0004630) and Hu et al. (CN 118011814). Claims 7 and 14: As disclosed above, Paté-Cornell and Engelberg disclose the elements of claim 1. Although Engelberg discloses an artificial intelligence model (See paragraph 34) and mapping vulnerabilities and remediation options (See paragraph 55), Paté-Cornell and Engelberg do not expressly disclose the remaining claim elements. Almukaynizi discloses functionality to extract technical attack features from an unclassified zero-day exploit signature and match the technical attack features against a known attack profile to determine a matching mitigation response (See paragraphs 50–53 and 55, wherein models selection enables optimal vulnerability analysis, and wherein new attack information is compared to known vulnerability data to identify attacks). As disclosed above, Paté-Cornell discloses a system directed to assessing and managing cybersecurity incidents, and Engelberg discloses a system directed to prioritizing cyber risk remediations. Almukaynizi discloses a system directed to assessing cyber threats. Each reference discloses a system directed to analyzing and managing cyber threats. The technique of utilizing feature matching is applicable to the systems of Paté-Cornell and Engelberg as they each share characteristics and capabilities; namely, they are directed to analyzing and managing cyber threats. One of ordinary skill in the art would have recognized that applying the known technique of Almukaynizi would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Almukaynizi to the teachings of Paté-Cornell and Engelberg would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate cyber threat analysis and management into similar systems. Further, applying feature matching to Paté-Cornell and Engelberg would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow more detailed analysis and more reliable results. Paté-Cornell, Engelberg, and Almukaynizi do not expressly disclose the remaining claim elements. Hu discloses at least one of a random forest with dynamic weighting, a Deep Q-Network, a Siamese neural network, or a one-shot learning with prototypical network to match the technical attack features against a known attack profile to determine a matching mitigation response (See pg. 3, wherein “the intelligent attack detection identification module uses the real-time and historical network data to continuously adjust and update the detection algorithm so as to adapt to the newly appeared attack mode and strategy, and uses the large data analysis and cloud computing resource to improve the capability of processing the large-scale network data, and the learning and adapting speed of the algorithm. Further, the machine learning algorithm is based on the improved random forest algorithm,” and wherein the random forest algorithm uses weighted feature selection; see also pg. 3, wherein worm attack identification utilizes a signature database of known work and abnormal flow behavior analysis). As disclosed above, Paté-Cornell discloses a system directed to assessing and managing cybersecurity incidents, Engelberg discloses a system directed to prioritizing cyber risk remediations, and Almukaynizi discloses a system directed to assessing cyber threats. Hu discloses a system directed to network security monitoring and management. Each reference discloses a system directed to analyzing and managing cyber threats. The technique of utilizing a random forest algorithm is applicable to the systems of Paté-Cornell, Engelberg, and Almukaynizi as they each share characteristics and capabilities; namely, they are directed to analyzing and managing cyber threats. One of ordinary skill in the art would have recognized that applying the known technique of Hu would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Hu to the teachings of Paté-Cornell, Engelberg, and Almukaynizi would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate cyber threat analysis and management into similar systems. Further, applying a random forest algorithm to Paté-Cornell, Engelberg, and Almukaynizi would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow more detailed analysis and more reliable results. Conclusion The following prior art is made of record and not relied upon but is considered pertinent to applicant's disclosure: Osman (U.S. 2025/0225461) discloses a system directed to assessing and managing cybersecurity risks, including cybersecurity and business impacts; and Hasan et al. (Hasan, Kamrul, et al. "Towards optimal cyber defense remediation in cyber physical systems by balancing operational resilience and strategic risk." MILCOM 2019-2019 IEEE Military Communications Conference (MILCOM). IEEE, 2019.). Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM S BROCKINGTON III whose telephone number is (571)270-3400. The examiner can normally be reached M-F, 8am-5pm, EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rutao Wu can be reached at 571-272-6045. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WILLIAM S BROCKINGTON III/Primary Examiner, Art Unit 3623
Read full office action

Prosecution Timeline

Feb 18, 2025
Application Filed
May 06, 2026
Non-Final Rejection mailed — §103, §112
Jun 02, 2026
Examiner Interview Summary
Jun 02, 2026
Applicant Interview (Telephonic)
Jun 18, 2026
Response Filed
Aug 17, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737709
SYSTEMS AND METHODS FOR MONITORING INFORMATION SECURITY EFFECTIVENESS
2y 5m to grant Granted Sep 15, 2026
Patent 12737711
Methodology for managing personnel engagement
2y 3m to grant Granted Sep 15, 2026
Patent 12725120
SYSTEM AND METHOD FOR DETERMINING A DUMP LOCATION FOR A VEHICLE
1y 6m to grant Granted Sep 01, 2026
Patent 12711519
DYNAMIC WEB CONTENT INSERTION
3y 3m to grant Granted Aug 18, 2026
Patent 12694418
Survey Administration System and Methods
1y 6m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
42%
Grant Probability
97%
With Interview (+54.8%)
3y 11m (~2y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 508 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month