Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-9 and 11-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claim 1 recites “receiving … first information associated with a procedure …” (mental step - observation), “transforming the first information… ” (mental step - evaluation and/or mathematical calculation), “determining … a first plurality of features including a first average reconciliation ratio and a first indication of whether the security policy is accurate…” (mental step - mathematical calculation), “determining … a first probability …” (mental step - mathematical calculation, “determining whether the first probability is greater than a threshold value” (mental step - mathematical calculation), “… determining … a recommendation to implement one or more actions …” (mental step - judgement), along with claims 11 and 20 reciting similar limitations. This judicial exception is not integrated into a practical application because the claims do not recite any further limitations that either apply, rely on, or utilize the abstract idea in a manner that imposes meaningful limit on the abstract idea itself. For example, there’s no further recitation(s) of an improvement to a computer function or to a technology or technical field. The claims do recite utilizing numerous machine learning models that were previously trained on various information, however the usage of these machine learning models is similar to the usage of a calculator in that they’re merely a tool utilized by the abstract idea rather than integrated into the abstract idea itself. Further, the training aspects of these respective machine learning models does not actively occur as a function of the abstract idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because claims 1-9 and 11-20 fail to recite any additional elements that would amount to significantly more than the abstract idea itself. For example, claim 11 recites a “system comprising at least one processor; and at least one memory”, which are equivalent to typical components used for storing (and retrieving) information in memory, and thus are recognized as being well-understood, routine, and conventional computer functions (Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015); OIP Techs., 788 F.3d at 1363, 115 USPQ2d at 1092-93). The examiner also takes Official Notice regarding the claimed “system comprising at least one processor; and at least one memory” as being well-known and conventional in the computer arts. Therefore, the above identified abstract idea recited within claims 1, 11, and 20, when considered individually and in combination with the above recited well-known, conventional components, fails to recite subject matter that would constate as significantly more than the abstract idea itself.
Further, dependent claims 2-9 and 12-19 also fail to recite any further limitations that would either recite a non-abstract idea, further integrate the above identified abstract idea into a practical application, or recite anything considered as significantly more than the abstract idea itself. Thus, these claims are also rejected for the same reasons as applied to respective claims 1, 11, and 20 above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3, 9, 11-13 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in further view of “Hwang” (US 2020/0293970).
Regarding Claim 1:
Kudale teaches:
A method comprising:
receiving, from an external entity, first information associated with a procedure (Col. 9,lines 20-25, “At 322, the cyber risk analysis engine 104 may generate an input feature space by collecting data from a plurality of computer sources. For instance, the input feature space may include data associated with a computing system or set of computing systems of an organization for which a cyber security insurance policy is being underwritten”), wherein the procedure includes a control representing a security policy (Col. 9, lines 36-44, “For example, the cyber risk analysis engine 104 may collect data from endpoints indicating operations and attributes (e.g., inside-out data) pertaining to cyber security, data from external sources indicating attempted or actual data breaches (e.g., outside-in data), or other data (lost cost, dark intelligence, business interruption, regulatory, etc.). For example, for inside-out data, a user may grant access on a computer to internal operations, services used, etc”);
transforming the first information into first transformed information (Col. 9, lines 54-57, “… the cyber risk analysis engine 104 may use direct data and/or may derive features based on the received data. For instance, the cyber risk analysis engine 104 may generate analytics and/or augment data to generate the feature space”);
determining, using a first machine learning model (Figure 5B, element 524), a first plurality of features including a first average reconciliation ratio and a first indication of whether the security policy is accurate, based on the first transformed information (Col. 12, lines 11-33, “In some implementations, the cyber risk analysis engine 104 may input the inputs 522 into the similarity model 524, which may perform data imputation and/or comparisons with other similar computing systems or organizations. For example, the similarity model 524 may use a statistical approach to determine data proxy when components of the data are insufficient or missing for a computing system or organization in question… In some implementations, the similarity model 524 may find the top k similar organizations or computing systems to that being analyzed, for example, for purposes of data imputation, size comparison, or relative positioning (e.g., for a relative weighting or score of a risk factor in the context of an industry)”; i.e., compare multiple input data sets to determine a number of discrepancies and missing data to reconcile in addition to selecting the most accurate representation of organizational (policy) data), …
determining, using a second machine learning model (Figure 5B, element 532; Col. 14, lines 56-61, “The artificial intelligence models of the risk factors model(s), along with the other models herein, allow a large number of features and data to be analyzed to determine the quantified risk factors scores that may be used to underwrite insurance, correct cyber security risks, or perform other operations”), a first probability that the first transformed information does not satisfy the plurality of criteria, based on the first plurality of features (Col. 10, lines 17-34, “At 328, the cyber risk analysis engine 104 may determine a severity of at least one of the one or more data-security breach incidents and the one or more events using a third computer model. In some implementations, the cyber risk analysis engine 104 may use a severity model, as described in reference to FIG. 5B to determine a severity of an incident and/or event, for example, based on an output of the incident predictive model, an output of the event recognition, and/or the input feature space. At 330, the cyber risk analysis engine 104 may generate risk factor score(s) indicating a computer security risk of certain computer security aspect of computing system based on determined severity. For instance, the factor scores may be based on the determined severity of the data-security breach incident(s) and/or the event(s). Each of the risk factor scores may indicate a computer security risk of a certain computer security aspect of the computing system, as described above”), …
determining whether the first probability is greater than a threshold value (Col. 10, lines 41-45, “At 332, the cyber risk analysis engine 104 may perform an action based one or more of the risk factor scores. For example, the action may include performing a corrective action on the computing system to address the computer security risk”); and
upon determining that the first probability is greater than the threshold value, determining … a recommendation to implement one or more actions associated with the control, based on the first probability (Col. 10, lines 45-51, “For instance, the particular risk factor and its associated score may determine an area of risk and/or its severity. For example, the cyber risk analysis engine 104 may tighten network security settings in response to a high (e.g., satisfying a threshold) risk that there will be an incident or event breaching a firewall, although other implementations are possible”), …
Kudale does not disclose:
… wherein the first machine learning model was trained using data representing the procedure, a plurality of criteria associated with the control, and historical audit data;
… wherein the second machine learning model was trained using at least the historical audit data;
… using a third machine learning model, a recommendation to implement one or more actions associated with the control …
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control.
Sharieh teaches:
… wherein the first machine learning model was trained using data representing the procedure, a plurality of criteria associated with the control, and historical audit data (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance and audit events and evidence data…”);
… wherein the second machine learning model was trained using at least the historical audit data (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using … audit events …”);
…
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance … and evidence data…”);.
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale’s cybersecurity risk assessment system by enhancing Kudale’s assessment steps to utilize machine learning models trained utilizing one or more of procedure data, evidence data corresponding to a control, and historical audit data, as taught by Sharieh, in order to enhance accuracy of risk and compliance data.
The motivation is to more accurately provide risk and compliance data in order to demonstrate proper compliance with regulatory requirements for a risk assessment system by training multiple machine learning models using data that represents several factors associated with risk and compliance (Sharieh, ¶0029). Further, running multiple models may enhance the speed of the system to reach an overall result while simultaneously reducing the potential impact of an inaccurate model (Sharieh, ¶0074).
Kudale in view of Sharieh does not disclose:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control …
Hwang teaches:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control (¶0055, “The training model (420) with the generated policy (412) is leveraged together with the data stored at (432) to orchestrate a series of compliance actions that can be employed while minimizing risk (440). As described in detail in FIG. 1, the generated policy, e.g. sequence of actions, is used to orchestrate one or more compliance actions to take while minimizing risk. The orchestrated compliance actions are represented as an ordered list of recommended actions, e.g. sequence of actions”) …
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh’s process of providing a recommendation to utilize a machine learning model, as taught by Hwang, in order to provide dynamic recommendations in a manner that increases reward while minimizing risk.
The motivation is to utilize a machine learning model to provide a list of recommended compliance actions such that the actions can be dynamically provided in an optimized manner that increases reward while minimizing risk to attain a desired level of compliance of an assessed system (Hwang, ¶0055).
Regarding Claim 3:
The method of claim 1, wherein Kudale in view of Sharieh in further view of Hwang further teaches the first plurality of features further includes an indication of whether the first transformed information includes sensitive information (Kudale, Figure 2, element 218; Col. 6, lines 32-35, “Continuous or periodic scans from dark web chatter indicating domain and email-domain breaches, plain text exposure of email-ids, and/or exposed sensitive information 216”).
Regarding Claim 9:
The method of claim 1, wherein Kudale in view of Sharieh in further view of Hwang further teaches transforming the first information into the first transformed information includes at least standardizing the first information (Kudale, Col. 6, lines 40-43, “For the dark intelligence cyber risk factor ζ, feature engineering may involve text mining of dark web scans to transform textual information to numeric features”; Col. 6, lines 61-64, “The cyber risk analysis engine 104 may weight industry compliance data using relevance to a computing system's/organization's industry vertical and transformed into normalized features to train a compliance model”).
Regarding Claim 11:
Kudale teaches:
A system comprising:
at least one processor; and
at least one memory having programming instructions stored thereon, which, when executed by the at least one processor, cause the system to perform operations comprising:
receiving, from an external entity, information associated with a procedure (Col. 9,lines 20-25, “At 322, the cyber risk analysis engine 104 may generate an input feature space by collecting data from a plurality of computer sources. For instance, the input feature space may include data associated with a computing system or set of computing systems of an organization for which a cyber security insurance policy is being underwritten”), wherein the procedure includes a control representing a security policy Col. 9, lines 36-44, “For example, the cyber risk analysis engine 104 may collect data from endpoints indicating operations and attributes (e.g., inside-out data) pertaining to cyber security, data from external sources indicating attempted or actual data breaches (e.g., outside-in data), or other data (lost cost, dark intelligence, business interruption, regulatory, etc.). For example, for inside-out data, a user may grant access on a computer to internal operations, services used, etc”);
transforming the first information into transformed information (Col. 9, lines 54-57, “… the cyber risk analysis engine 104 may use direct data and/or may derive features based on the received data. For instance, the cyber risk analysis engine 104 may generate analytics and/or augment data to generate the feature space”);
determining, using a first machine learning model (Figure 5B, element 524), a plurality of features including a first average reconciliation ratio, based on the transformed information (Col. 12, lines 11-33, “In some implementations, the cyber risk analysis engine 104 may input the inputs 522 into the similarity model 524, which may perform data imputation and/or comparisons with other similar computing systems or organizations. For example, the similarity model 524 may use a statistical approach to determine data proxy when components of the data are insufficient or missing for a computing system or organization in question… In some implementations, the similarity model 524 may find the top k similar organizations or computing systems to that being analyzed, for example, for purposes of data imputation, size comparison, or relative positioning (e.g., for a relative weighting or score of a risk factor in the context of an industry)”; i.e., compare multiple input data sets to determine a number of discrepancies and missing data to reconcile in addition to selecting the most accurate representation of organizational (policy) data), …
determining, using a second machine learning model (Figure 5B, element 532; Col. 14, lines 56-61, “The artificial intelligence models of the risk factors model(s), along with the other models herein, allow a large number of features and data to be analyzed to determine the quantified risk factors scores that may be used to underwrite insurance, correct cyber security risks, or perform other operations”), a probability that the transformed information does not satisfy the plurality of criteria, based on the plurality of features (Col. 10, lines 17-34, “At 328, the cyber risk analysis engine 104 may determine a severity of at least one of the one or more data-security breach incidents and the one or more events using a third computer model. In some implementations, the cyber risk analysis engine 104 may use a severity model, as described in reference to FIG. 5B to determine a severity of an incident and/or event, for example, based on an output of the incident predictive model, an output of the event recognition, and/or the input feature space. At 330, the cyber risk analysis engine 104 may generate risk factor score(s) indicating a computer security risk of certain computer security aspect of computing system based on determined severity. For instance, the factor scores may be based on the determined severity of the data-security breach incident(s) and/or the event(s). Each of the risk factor scores may indicate a computer security risk of a certain computer security aspect of the computing system, as described above”), …
determining … a recommendation to implement one or more actions associated with the control, based on the probability (Col. 10, lines 45-51, “For instance, the particular risk factor and its associated score may determine an area of risk and/or its severity. For example, the cyber risk analysis engine 104 may tighten network security settings in response to a high (e.g., satisfying a threshold) risk that there will be an incident or event breaching a firewall, although other implementations are possible”), …
Kudale does not disclose:
… wherein the first machine learning model was trained using data representing the procedure and a plurality of criteria associated with the control;
… wherein the second machine learning model was trained using at least the historical audit data;
… using a third machine learning model, a recommendation to implement one or more actions associated with the control …
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control.
Sharieh teaches:
… wherein the first machine learning model was trained using data representing the procedure and a plurality of criteria associated with the control (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance … and evidence data…”);
… wherein the second machine learning model was trained using at least the historical audit data (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using … audit events …”);
…
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance … and evidence data…”);.
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale’s cybersecurity risk assessment system by enhancing Kudale’s assessment steps to utilize machine learning models trained utilizing one or more of procedure data, evidence data corresponding to a control, and historical audit data, as taught by Sharieh, in order to enhance accuracy of risk and compliance data.
The motivation is to more accurately provide risk and compliance data in order to demonstrate proper compliance with regulatory requirements for a risk assessment system by training multiple machine learning models using data that represents several factors associated with risk and compliance (Sharieh, ¶0029). Further, running multiple models may enhance the speed of the system to reach an overall result while simultaneously reducing the potential impact of an inaccurate model (Sharieh, ¶0074).
Kudale in view of Sharieh does not disclose:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control …
Hwang teaches:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control (¶0055, “The training model (420) with the generated policy (412) is leveraged together with the data stored at (432) to orchestrate a series of compliance actions that can be employed while minimizing risk (440). As described in detail in FIG. 1, the generated policy, e.g. sequence of actions, is used to orchestrate one or more compliance actions to take while minimizing risk. The orchestrated compliance actions are represented as an ordered list of recommended actions, e.g. sequence of actions”) …
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh’s process of providing a recommendation to utilize a machine learning model, as taught by Hwang, in order to provide dynamic recommendations in a manner that increases reward while minimizing risk.
The motivation is to utilize a machine learning model to provide a list of recommended compliance actions such that the actions can be dynamically provided in an optimized manner that increases reward while minimizing risk to attain a desired level of compliance of an assessed system (Hwang, ¶0055).
Regarding Claim 12:
The system of claim 11, wherein Kudale in view of Sharieh in further view of Hwang further teaches the operations further comprise:
determining whether the probability is greater than a threshold value (Kudale, Col. 10, lines 41-45, “At 332, the cyber risk analysis engine 104 may perform an action based one or more of the risk factor scores. For example, the action may include performing a corrective action on the computing system to address the computer security risk”), wherein the recommendation to implement one or more actions associated with the control is determined responsive to determining that the probability is greater than the threshold value (Kudale, Col. 10, lines 45-51, “For instance, the particular risk factor and its associated score may determine an area of risk and/or its severity. For example, the cyber risk analysis engine 104 may tighten network security settings in response to a high (e.g., satisfying a threshold) risk that there will be an incident or event breaching a firewall, although other implementations are possible”).
Regarding Claim 14:
System claim 14 corresponds to method claim 3 above and contains no further limitations. Therefore claim 14 is rejected by applying the same rationale used to reject claim 3 above.
Regarding Claim 20:
Kudale teaches:
A method comprising:
receiving, from an external entity, information associated with a procedure (Col. 9, lines 20-25, “At 322, the cyber risk analysis engine 104 may generate an input feature space by collecting data from a plurality of computer sources. For instance, the input feature space may include data associated with a computing system or set of computing systems of an organization for which a cyber security insurance policy is being underwritten”), wherein the procedure includes a control representing a security policy (Col. 9, lines 36-44, “For example, the cyber risk analysis engine 104 may collect data from endpoints indicating operations and attributes (e.g., inside-out data) pertaining to cyber security, data from external sources indicating attempted or actual data breaches (e.g., outside-in data), or other data (lost cost, dark intelligence, business interruption, regulatory, etc.). For example, for inside-out data, a user may grant access on a computer to internal operations, services used, etc”);
transforming the information into transformed information (Col. 9, lines 54-57, “… the cyber risk analysis engine 104 may use direct data and/or may derive features based on the received data. For instance, the cyber risk analysis engine 104 may generate analytics and/or augment data to generate the feature space”);
determining, using a first machine learning model (Figure 5B, element 524), a plurality of features including an average reconciliation ratio and an indication of whether the security policy is accurate, based on the transformed information (Col. 12, lines 11-33, “In some implementations, the cyber risk analysis engine 104 may input the inputs 522 into the similarity model 524, which may perform data imputation and/or comparisons with other similar computing systems or organizations. For example, the similarity model 524 may use a statistical approach to determine data proxy when components of the data are insufficient or missing for a computing system or organization in question… In some implementations, the similarity model 524 may find the top k similar organizations or computing systems to that being analyzed, for example, for purposes of data imputation, size comparison, or relative positioning (e.g., for a relative weighting or score of a risk factor in the context of an industry)”; i.e., compare multiple input data sets to determine a number of discrepancies and missing data to reconcile in addition to selecting the most accurate representation of organizational (policy) data), …
determining, using a second machine learning model (Figure 5B, element 532; Col. 14, lines 56-61, “The artificial intelligence models of the risk factors model(s), along with the other models herein, allow a large number of features and data to be analyzed to determine the quantified risk factors scores that may be used to underwrite insurance, correct cyber security risks, or perform other operations”), a probability that the transformed information does not satisfy the plurality of criteria, based on the plurality of features (Col. 10, lines 17-34, “At 328, the cyber risk analysis engine 104 may determine a severity of at least one of the one or more data-security breach incidents and the one or more events using a third computer model. In some implementations, the cyber risk analysis engine 104 may use a severity model, as described in reference to FIG. 5B to determine a severity of an incident and/or event, for example, based on an output of the incident predictive model, an output of the event recognition, and/or the input feature space. At 330, the cyber risk analysis engine 104 may generate risk factor score(s) indicating a computer security risk of certain computer security aspect of computing system based on determined severity. For instance, the factor scores may be based on the determined severity of the data-security breach incident(s) and/or the event(s). Each of the risk factor scores may indicate a computer security risk of a certain computer security aspect of the computing system, as described above”), …
determining whether the probability is greater than a threshold value (Col. 10, lines 41-45, “At 332, the cyber risk analysis engine 104 may perform an action based one or more of the risk factor scores. For example, the action may include performing a corrective action on the computing system to address the computer security risk”); and
upon determining that the probability is greater than the threshold value, determining, using a third machine learning model, a recommendation to implement one or more actions associated with the control, based on the probability (Col. 10, lines 45-51, “For instance, the particular risk factor and its associated score may determine an area of risk and/or its severity. For example, the cyber risk analysis engine 104 may tighten network security settings in response to a high (e.g., satisfying a threshold) risk that there will be an incident or event breaching a firewall, although other implementations are possible”), …
Kudale does not disclose:
… wherein the first machine learning model was trained using at least data representing the procedure and a plurality of criteria associated with the control;
… wherein the second machine learning model was trained using at least historical audit data;
… using a third machine learning model, a recommendation to implement one or more actions associated with the control, …
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control.
Sharieh teaches:
… wherein the first machine learning model was trained using at least data representing the procedure and a plurality of criteria associated with the control (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance … and evidence data…”);
… wherein the second machine learning model was trained using at least historical audit data (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using … audit events …”);
…
… wherein the third machine learning model was trained using at least the data representing the procedure and the plurality of criteria associated with the control (¶0063, “… selecting events that are directly related to these subsets, which may then be used for training anomaly detection ML models. In some embodiments, anomaly detection ML models may be trained using compliance … and evidence data…”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale’s cybersecurity risk assessment system by enhancing Kudale’s assessment steps to utilize machine learning models trained utilizing one or more of procedure data, evidence data corresponding to a control, and historical audit data, as taught by Sharieh, in order to enhance accuracy of risk and compliance data.
The motivation is to more accurately provide risk and compliance data in order to demonstrate proper compliance with regulatory requirements for a risk assessment system by training multiple machine learning models using data that represents several factors associated with risk and compliance (Sharieh, ¶0029). Further, running multiple models may enhance the speed of the system to reach an overall result while simultaneously reducing the potential impact of an inaccurate model (Sharieh, ¶0074).
Kudale in view of Sharieh does not disclose:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control, …
Hwang teaches:
… using a third machine learning model, a recommendation to implement one or more actions associated with the control (¶0055, “The training model (420) with the generated policy (412) is leveraged together with the data stored at (432) to orchestrate a series of compliance actions that can be employed while minimizing risk (440). As described in detail in FIG. 1, the generated policy, e.g. sequence of actions, is used to orchestrate one or more compliance actions to take while minimizing risk. The orchestrated compliance actions are represented as an ordered list of recommended actions, e.g. sequence of actions”) …
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh’s process of providing a recommendation to utilize a machine learning model, as taught by Hwang, in order to provide dynamic recommendations in a manner that increases reward while minimizing risk.
The motivation is to utilize a machine learning model to provide a list of recommended compliance actions such that the actions can be dynamically provided in an optimized manner that increases reward while minimizing risk to attain a desired level of compliance of an assessed system (Hwang, ¶0055).
Claim(s) 2 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Jacobson” (US 6735701).
Regarding Claim 2:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, …
Kudale in view of Sharieh in further view of Hwang does not disclose:
… wherein the security policy includes access restrictions associated with one or more users, and wherein the first plurality of features further includes an indication of whether the first transformed information complies with the security policy.
Jacobson teaches:
… wherein the security policy includes access restrictions associated with one or more users, and wherein the first plurality of features further includes an indication of whether the first transformed information complies with the security policy (Col. 12, lines 14-29, “Each policy is associated with a corresponding group of network policy compliance actions ranging from a mild (e.g., notifying a network user), level two (e.g. notifying the network user and a policy administrator), level three (e.g., providing a retraining module to a network user, restricting a network user's network access rights) and a level four action (e.g., restricting the network user's network access rights.) Each compliance action in the group is assigned a value related to a numeric value that may be reported from monitoring network user compliance. The numeric value assigned is based on the severity of the network policy compliance violation, i.e. the difference between the network policy compliance value and the user policy compliance value”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s system to evaluate whether access restrictions associated with users are being complied with a security policy, as taught by Jacobson, in order to consult a user policy compliance value when determining the overall compliance of a target system.
The motivation is to generate a more comprehensive compliance report for a target system by incorporating user policy compliance values in addition to network policy compliance values (Jacobson, Col. 12, lines 30-35).
Regarding Claim 13:
System claim 13 corresponds to method claim 2 above and contains no further limitations. Therefore claim 13 is rejected by applying the same rationale used to reject claim 2 above.
Claim(s) 4 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Yagnik” (US 2025/0225440).
Regarding Claim 4:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, …
Kudale in view of Sharieh in further view of Hwang does not disclose:
… wherein the first information includes information formatted in accordance with JavaScript Object Notation (JSON).
Yagnik teaches:
… wherein the first information includes information formatted in accordance with JavaScript Object Notation (JSON) (¶0062, “In some embodiments, inputs to the processing model 215 can include the data (e.g., segments 210) … for each data segment 210, the processing model 215 can output a structured JSON document”). Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s information to be structure by utilizing JSON, as taught by Yagnik, in order to ensure a commonly-used data format is utilized.
The motivation is to enhance the readability of assessment output data by ensuring the data utilizes a data structure that is human-readable and common amongst web applications, such as JSON.
Regarding Claim 15:
System claim 15 corresponds to method claim 4 above and contains no further limitations. Therefore claim 15 is rejected by applying the same rationale used to reject claim 4 above.
Claim(s) 5 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Raleigh” (US 2018/0167413).
Regarding Claim 5:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, wherein the first average reconciliation ratio represents a number of items associated with the first transformed information and reconciled during a time period (Kudale, Col. 12, lines 11-33, “In some implementations, the cyber risk analysis engine 104 may input the inputs 522 into the similarity model 524, which may perform data imputation and/or comparisons with other similar computing systems or organizations. For example, the similarity model 524 may use a statistical approach to determine data proxy when components of the data are insufficient or missing for a computing system or organization in question…”), …
Kudale in view of Sharieh in further view of Hwang does not disclose:
… divided by a total number of items that are associated with the first transformed information and that should have been reconciled during the time period.
Raleigh teaches:
… divided by a total number of items that are associated with the first transformed information and that should have been reconciled during the time period (¶0225, “In some embodiments, time period reconciliation is accomplished by aggregating a first number of device-based usage reports and a second number of network-based usage reports. In some embodiments, time period reconciliation is accomplished by maintaining a running average or running accumulation of service usage from each source”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s average reconciliation value to include a running average of usage reports received over a time period, as taught by Raleigh, in order to accomplish a reconciliation value being based on a small percentage of differences between a number of time periods.
The motivation is to reduce outlier data values by incorporating data measured across a number of time periods so that the difference in time periods is small, thus achieving an average time period reconciliation value.
Regarding Claim 16:
System claim 16 corresponds to method claim 5 above and contains no further limitations. Therefore claim 16 is rejected by applying the same rationale used to reject claim 5 above.
Claim(s) 6 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Achin” (US 12566993).
Regarding Claim 6:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, wherein the plurality of criteria includes a value representing a threshold amount of evidence (Sharieh, ¶0040, “During operation of a SaaS application, compliance controls are used to monitor and collect compliance evidence from applications running in cloud operating environments. For example, specific cloud environment (e.g. AWS, Google Cloud Platform, Microsoft Azure, or the like) compliance controls may be implemented by a SaaS application and the cloud provider (e.g. AWS) and may generate compliance evidence”), …
The motivation to reject claim 6 by applying Sharieh to Kudale is the same respective motivation applied under the rejection of claim 1 above.
Kudale in view of Sharieh in further view of Hwang does not disclose:
… and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the value representing the threshold amount of evidence.
Achin teaches:
… and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the value representing the threshold amount of evidence (Col. 59, lines 3-14, “In some cases, it may be desirable to produce a model that uses as few features as possible to make predictions. In these cases, the user could re-run a specific modeling technique or the search among all the modeling techniques with only the N features of greatest importance or only the features having importance values that exceed a specified threshold”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s machine learning models to consider only features satisfying an importance threshold, as taught by Achin, in order to improve the predictiveness of the models.
The motivation is to improve the predictiveness of machine learning models by utilizing only the most important features to train the models (Achin, Col. 59, lines 11-14).
Regarding Claim 17:
System claim 17 corresponds to method claim 6 above and contains no further limitations. Therefore claim 17 is rejected by applying the same rationale used to reject claim 6 above.
Claim(s) 7 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Stapleton” (US 10045218).
Regarding Claim 7:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, wherein the plurality of criteria includes a value representing a threshold number of samples (Sharieh, ¶0040, “During operation of a SaaS application, compliance controls are used to monitor and collect compliance evidence from applications running in cloud operating environments. For example, specific cloud environment (e.g. AWS, Google Cloud Platform, Microsoft Azure, or the like) compliance controls may be implemented by a SaaS application and the cloud provider (e.g. AWS) and may generate compliance evidence”), …
The motivation to reject claim 7 by applying Sharieh to Kudale is the same respective motivation applied under the rejection of claim 1 above.
Kudale in view of Sharieh in further view of Hwang does not disclose:
… and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the value representing the threshold number of samples.
Stapleton teaches:
… and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the value representing the threshold number of samples (Col. 6, lines 34-53, “An itemset is considered infrequent if the count of training samples (or “training feature vectors”) containing the itemset, referred to as its support, falls below a user-specified threshold SIGMA”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s machine learning models to prune itemsets scoring lower than a threshold, as taught by Stapleton, in order to improve the computational efficiency of the models.
The motivation is to increase the computation efficiency of machine learning models by preventing identified outliers from being utilized in the training of the models (Stapleton, Col. 6, lines 48-53).
Regarding Claim 18:
System claim 18 corresponds to method claim 7 above and contains no further limitations. Therefore claim 18 is rejected by applying the same rationale used to reject claim 7 above.
Claim(s) 8 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Kudale” (US 11870800) in view of “Sharieh” (US 2025/0131454) in view of “Hwang” (US 2020/0293970) in further view of “Bhatt” (US 2022/0036239).
Regarding Claim 8:
Kudale in view of Sharieh in further view of Hwang teaches:
The method of claim 1, …
Kudale in view of Sharieh in further view of Hwang does not disclose:
… wherein the plurality of criteria includes a maximum error rate, and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the maximum error rate.
Bhatt teaches:
… wherein the plurality of criteria includes a maximum error rate, and wherein the first plurality of features further includes a determination of whether the first transformed information satisfies the maximum error rate (¶0047, “In some examples, the foregoing process of adjusting the feature weights via training of the transformer and the discriminator may repeat until one or more of the discrimination scores are each within a threshold level of error, which may be a predefined threshold”).
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Kudale in view of Sharieh in further view of Hwang’s cybersecurity risk assessment system by enhancing Kudale in view of Sharieh in further view of Hwang’s machine learning models to only accept data inputs satisfying a maximum error threshold, as taught by Bhatt, in order to prevent the models from being trained on inaccurate data.
The motivation is to improve the efficiency and accuracy of machine learning models by ensuring that data features used to train the models are within a predefined error threshold.
Regarding Claim 19:
System claim 19 corresponds to method claim 8 above and contains no further limitations. Therefore claim 19 is rejected by applying the same rationale used to reject claim 8 above.
Allowable Subject Matter
Claim 10 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
The following is a statement of reasons for the indication of allowable subject matter: The prior art of record, when considered individually and in combination, fails to teach or suggest the subject matter recited in claim 10.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL B POTRATZ whose telephone number is (571)270-5329. The examiner can normally be reached on M-F 10 A.M. - 6 P.M. CST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached on 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DANIEL B POTRATZ/Primary Examiner, Art Unit 2491