Prosecution Insights
Last updated: October 04, 2026
Application No. 19/065,189

SYSTEMS AND METHODS FOR ASSESSING EXPOSURE EXPLOITABILITY IN ADVANCED CYBERATTACK SCENARIOS

Non-Final OA §102§103
Filed
Feb 27, 2025
Examiner
ALMEIDA, DEVIN E
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Tenable Inc.
OA Round
1 (Non-Final)
72%
Grant Probability
Favorable
1-2
OA Rounds
2y 0m
Est. Remaining
83%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
440 granted / 615 resolved
+13.5% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
22 currently pending
Career history
636
Total Applications
across all art units

Statute-Specific Performance

§101
7.3%
-32.7% vs TC avg
§103
55.7%
+15.7% vs TC avg
§102
23.4%
-16.6% vs TC avg
§112
7.6%
-32.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 615 resolved cases

Office Action

§102 §103
DETAILED ACTION This action is in response to new application titled “SYSTEMS AND METHODS FOR ASSESSING EXPOSURE EXPLOITABILITY IN ADVANCED CYBERATTACK SCENARIOS” filed 2/27/2025. Claims 1-43 were received for consideration. Priority Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). The certified copy has been received. Information Disclosure Statement The information disclosure statement (IDS) submitted on 2/27/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-7, 11-19, 22-28, 32-40 and 43 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Mullaney (US 2022/0286475). With respect to claim 1 Mullaney teaches a method, performed by a device, comprising: generating, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and performing one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 2 Mullaney teaches the method of claim 1, wherein performing the one or more actions based on the set of vulnerability scores comprises: transmitting a report of the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 3 Mullaney teaches the method of claim 1, wherein performing the one or more actions based on the set of vulnerability scores comprises: performing a remediation based at least in part on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 4 Mullaney teaches the method of claim 1, wherein the vulnerabilities are classified by common vulnerabilities and exposures (CVEs) (see Mullaney paragraph 0046 i.e. As indicated above, a CAN may evaluate a vulnerability of its own product, assign a CVE ID and associated metadata to the vulnerability when the vulnerability is disclosed to the public. A Common Vulnerability Scoring System (CVSS) is an open framework for communicating characteristics and severity of software vulnerabilities. A set of CVSS metrics may be published as part of the metadata associated with a CVE. These metrics may be calculated by the CNA that first registers the vulnerability and published with the initial CVE disclosure). With respect to claim 5 Mullaney teaches the method of claim 1, further comprising: extracting a raw dataset from the threat-related information; and generating the dataset based on the raw dataset extracted from the threat-related information (see Mullaney paragraph 0113-0117 i.e. In block 620, the vulnerability metrics generator may receive a trained vulnerability metrics generation model, e.g., from a vulnerability metrics generation model trainer. The vulnerability metrics generation model may be trained on a training dataset to generate one or more target vulnerability vectors of a target vulnerability. The training dataset has been described above, and thus is not repeated here. In an aspect, the target vulnerability may not be any one of the one or more training vulnerabilities of the training dataset. In other words, the target vulnerability may be a previously unseen vulnerability. In block 630, the vulnerability metrics generator may generate one or more target vulnerability vectors based on the target vulnerability description). With respect to claim 6 Mullaney teaches the method of claim 1, wherein generating, by the one or more classifiers, the set of vulnerability scores comprises: generating, by a first classifier, a first set of partial scores based on the descriptions of the vulnerabilities; generating, by a second classifier, a second set of partial scores based on the sets of vulnerability parameters associated with the vulnerabilities; and generating, by an ensemble classifier, the set of vulnerability scores based on the first set of partial scores and the second set of partial scores (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector and paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector). With respect to claim 7 Mullaney teaches the method of claim 6, wherein generating, by the first classifier, the first set of partial scores comprises: obtaining a set of embeddings of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the embeddings (see Mullaney paragraph 0112 i.e. FIG. 6 illustrates a flow chart of an example method 600 for generating vulnerability metrics. The method 600 may be performed by a vulnerability metrics generator. In an aspect, the vulnerability management system 150, 250 may also perform vulnerability metrics generation model trainer functions. In block 610, the vulnerability metrics generator may receive a target vulnerability description of a target vulnerability. The target vulnerability description may comprise a textual description). With respect to claim 11 Mullaney teaches the method of claim 6, wherein the sets of vulnerability parameters include: a set of exploit maturities; a set of severities; a set of risk factors; a set of exploit prediction scoring system (EPSS) percentiles; or any combination thereof (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 12 Mullaney teaches the method of claim 11, wherein generating, by the second classifier, the second set of partial scores comprises: generating the second set of partial scores based on one or more of the sets of vulnerability parameters (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector and paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector). With respect to claim 13 Mullaney teaches the method of claim 12, wherein each of the exploit maturities is assigned a value of high, functional, or proof of concept (POC), and wherein the second set of partial scores is based at least in part on scaled exploit maturity scores associated with the exploit maturities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 14 Mullaney teaches the method of claim 12, wherein each of the severities is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled severity scores associated with the severities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 15 Mullaney teaches the method of claim 12, wherein each of the risk factors is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled risk factor scores associated with the risk factors (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 16 Mullaney teaches the method of claim 12, wherein the second set of partial scores is based at least in part on scaled EPSS scores associated with the EPSS percentiles (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 17 Mullaney teaches the method of claim 12, wherein the second set of partial scores is based at least in part on indications of whether the vulnerabilities are remotely exploitable (see Mullaney paragraph 0032 i.e. On the other hand, the uncredentialed audits may generally include network-based scans that involve communicating packets or messages to the appropriate asset(s) 130 and observing responses thereto in order to identify certain vulnerabilities (e.g., that a particular asset 130 accepts spoofed packets that may expose a vulnerability that can be exploited to close established connections). With respect to claim 18 Mullaney teaches the method of claim 6, wherein generating, by the ensemble classifier, the set of vulnerability scores comprises: summing the first set of partial scores and the second set of partial scores to obtain the set of vulnerability scores (see Mullaney paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector). With respect to claim 19 Mullaney teaches the method of claim 6, wherein generating, by the ensemble classifier, the set of vulnerability scores comprises: generating a weighted sum of the first set of partial scores that are weighted by a first weight and the second set of partial scores that are weighted by a second weight to obtain the set of vulnerability scores (see Mullaney paragraph 0122 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions). With respect to claim 22 Mullaney teaches a device, comprising: one or more memories; and one or more processors communicatively coupled to the one or more memories, the one or more processors, either alone or in combination, configured to: generate, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and perform one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 23 Mullaney teaches the device of claim 22, wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: transmit a report of the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 24 Mullaney teaches the device of claim 22, wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: perform a remediation based at least in part on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). With respect to claim 25 Mullaney teaches the device of claim 22, wherein the vulnerabilities are classified by common vulnerabilities and exposures (CVEs) (see Mullaney paragraph 0046 i.e. As indicated above, a CAN may evaluate a vulnerability of its own product, assign a CVE ID and associated metadata to the vulnerability when the vulnerability is disclosed to the public. A Common Vulnerability Scoring System (CVSS) is an open framework for communicating characteristics and severity of software vulnerabilities. A set of CVSS metrics may be published as part of the metadata associated with a CVE. These metrics may be calculated by the CNA that first registers the vulnerability and published with the initial CVE disclosure). With respect to claim 26 Mullaney teaches the device of claim 22, wherein the one or more processors, either alone or in combination, are further configured to: extract a raw dataset from the threat-related information; and generate the dataset based on the raw dataset extracted from the threat-related information (see Mullaney paragraph 0113-0117 i.e. In block 620, the vulnerability metrics generator may receive a trained vulnerability metrics generation model, e.g., from a vulnerability metrics generation model trainer. The vulnerability metrics generation model may be trained on a training dataset to generate one or more target vulnerability vectors of a target vulnerability. The training dataset has been described above, and thus is not repeated here. In an aspect, the target vulnerability may not be any one of the one or more training vulnerabilities of the training dataset. In other words, the target vulnerability may be a previously unseen vulnerability. In block 630, the vulnerability metrics generator may generate one or more target vulnerability vectors based on the target vulnerability description). With respect to claim 27 Mullaney teaches the device of claim 22, wherein the one or more processors configured to generate, by the one or more classifiers, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: generate, by a first classifier, a first set of partial scores based on the descriptions of the vulnerabilities; generate, by a second classifier, a second set of partial scores based on the sets of vulnerability parameters associated with the vulnerabilities; and generate, by an ensemble classifier, the set of vulnerability scores based on the first set of partial scores and the second set of partial scores (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector). With respect to claim 28 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the first classifier, the first set of partial scores comprise the one or more processors, either alone or in combination, configured to: obtain a set of embeddings of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the embeddings (see Mullaney paragraph 0112 i.e. FIG. 6 illustrates a flow chart of an example method 600 for generating vulnerability metrics. The method 600 may be performed by a vulnerability metrics generator. In an aspect, the vulnerability management system 150, 250 may also perform vulnerability metrics generation model trainer functions. In block 610, the vulnerability metrics generator may receive a target vulnerability description of a target vulnerability. The target vulnerability description may comprise a textual description). With respect to claim 32 Mullaney teaches the device of claim 27, wherein the sets of vulnerability parameters include: a set of exploit maturities; a set of severities; a set of risk factors; a set of exploit prediction scoring system (EPSS) percentiles; or any combination thereof (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 33 Mullaney teaches the device of claim 32, wherein the one or more processors configured to generate, by the second classifier, the second set of partial scores comprise the one or more processors, either alone or in combination, configured to: generate the second set of partial scores based on one or more of the sets of vulnerability parameters (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector). With respect to claim 34 Mullaney teaches the device of claim 33, wherein each of the exploit maturities is assigned a value of high, functional, or proof of concept (POC), and wherein the second set of partial scores is based at least in part on scaled exploit maturity scores associated with the exploit maturities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 35 Mullaney teaches the device of claim 33, wherein each of the severities is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled severity scores associated with the severities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 36 Mullaney teaches the device of claim 33, wherein each of the risk factors is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled risk factor scores associated with the risk factors (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 37 Mullaney teaches the device of claim 33, wherein the second set of partial scores is based at least in part on scaled EPSS scores associated with the EPSS percentiles (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)). With respect to claim 38 Mullaney teaches the device of claim 33, wherein the second set of partial scores is based at least in part on indications of whether the vulnerabilities are remotely exploitable (see Mullaney paragraph 0032 i.e. On the other hand, the uncredentialed audits may generally include network-based scans that involve communicating packets or messages to the appropriate asset(s) 130 and observing responses thereto in order to identify certain vulnerabilities (e.g., that a particular asset 130 accepts spoofed packets that may expose a vulnerability that can be exploited to close established connections). With respect to claim 39 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the ensemble classifier, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: sum the first set of partial scores and the second set of partial scores to obtain the set of vulnerability scores see Mullaney paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector). With respect to claim 40 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the ensemble classifier, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: generate a weighted sum of the first set of partial scores that are weighted by a first weight and the second set of partial scores that are weighted by a second weight to obtain the set of vulnerability scores (see Mullaney paragraph 0122 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions). With respect to claim 43 Mullaney teaches a non-transitory computer-readable medium storing computer-executable instructions that, when executed by a device, cause the device to: generate, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and perform one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 8-10 and 29-31 are rejected under 35 U.S.C. 103 as being unpatentable over Mullaney (US 2022/0286475) in view of With respect to claim 8 Mullaney teaches the method of claim 7, but does not disclose wherein obtaining the first set of partial scores based on the embeddings comprises: obtaining a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the distances. Zelivansky teaches wherein obtaining the first set of partial scores based on the embeddings comprises: obtaining a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Zelivansky to have measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance and text representation for measuring text similarity includes string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based as a way to update the match confidence variable of the informal vulnerability record based on prose descriptions similarity (see Zelivansky paragraph 0052). With respect to claim 9 Mullaney in view of Zelivansky teaches the method of claim 8, wherein the first set of partial scores are based on a set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). With respect to claim 10 Mullaney in view of Zelivansky teaches the method of claim 9, but does not disclose wherein a higher partial score within the first set of partial scores corresponds to a shorter scaled distance within the set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). With respect to claim 29 Mullaney teaches the device of claim 28, but does not disclose wherein the one or more processors configured to obtain the first set of partial scores based on the embeddings comprise the one or more processors, either alone or in combination, configured to: obtain a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the distances. Zelivansky teaches wherein the one or more processors configured to obtain the first set of partial scores based on the embeddings comprise the one or more processors, either alone or in combination, configured to: obtain a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). With respect to claim 30 Mullaney in view of Zelivansky teaches the device of claim 29, wherein the first set of partial scores are based on a set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). With respect to claim 31 Mullaney in view of Zelivansky teaches the device of claim 30, wherein a higher partial score within the first set of partial scores corresponds to a shorter scaled distance within the set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)). Claims 20, 21, 41 and 42 are rejected under 35 U.S.C. 103 as being unpatentable over Mullaney (US 2022/0286475) in view of Parla (US 2027/0333747). With respect to claim 20 Mullaney teaches the method of claim 1, but does not disclose wherein performing the one or more actions based on the set of vulnerability scores comprises: determining whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores. Parla teaches wherein performing the one or more actions based on the set of vulnerability scores comprises: determining whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores (see Parla paragraph 0076 i.e. the threat management service 102 can take an additional step of identifying verdicts 208 of the sample of malware, in order to request remedial action from the remedial action service 110, to address the potential network threat. In some examples, a verdict can be assigned to a sample in order to indicate the nature of its activities, such as ransomware or phishing. Verdicts are derived from various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices. By assigning judgments and verdicts to samples of malware, organizations can more easily identify which threats they need to prioritize when responding to a malicious attack). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have taken an additional step of identifying verdicts of the sample of malware, in order to request remedial action from the remedial to address the potential network threat. Where the verdict assign to the sample indicate the nature of its activities, such as ransomware or phishing based on various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices, so organizations can more easily identify which threats they need to prioritize when responding to a malicious attack (see paragraph 0076). With respect to claim 21 Mullaney teaches the method of claim 1, but does not disclose wherein performing the one or more actions based on the set of vulnerability scores comprises: presenting a prioritization of threats based on the set of vulnerability scores. Parla teaches wherein performing the one or more actions based on the set of vulnerability scores comprises: presenting a prioritization of threats based on the set of vulnerability scores (see Parla paragraph 0079-0082 i.e. FIG. 3 illustrates an example behavioral characterization report 300 capable of indicating network threats 132 detected in a network 104 according to some aspects of the present disclosure. The behavioral characterization report 300 can include a list of titles 302 for the sample of malware, category 304 for the samples of malware, tags 308 associated with the malware, number of hits 310 detected, and an indicator score 312… he behavioral characterization report 300 can provide a prioritization of titles 302, to allow the threat intelligence service 144 of FIG. 1 to quickly prioritize responses to detected network threats 132 in order to recover from more advanced attacks). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have generated a behavioral characterization report that includes a prioritization the list of titles the sample of malware so that threats can be quickly prioritize responses to detected network threats in order to recover from more advanced attacks (See Parla paragraph 0081). With respect to claim 41 Mullaney teaches the device of claim 22, but does not disclose wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: determine whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores. Parla teaches wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: determine whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores (see Parla paragraph 0076 i.e. the threat management service 102 can take an additional step of identifying verdicts 208 of the sample of malware, in order to request remedial action from the remedial action service 110, to address the potential network threat. In some examples, a verdict can be assigned to a sample in order to indicate the nature of its activities, such as ransomware or phishing. Verdicts are derived from various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices. By assigning judgments and verdicts to samples of malware, organizations can more easily identify which threats they need to prioritize when responding to a malicious attack). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have taken an additional step of identifying verdicts of the sample of malware, in order to request remedial action from the remedial to address the potential network threat. Where the verdict assign to the sample indicate the nature of its activities, such as ransomware or phishing based on various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices, so organizations can more easily identify which threats they need to prioritize when responding to a malicious attack (see paragraph 0076). With respect to claim 42 Mullaney teaches the device of claim 22, but does not disclose wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: present a prioritization of threats based on the set of vulnerability scores. Parla teaches wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: present a prioritization of threats based on the set of vulnerability scores (see Parla paragraph 0079-0082 i.e. FIG. 3 illustrates an example behavioral characterization report 300 capable of indicating network threats 132 detected in a network 104 according to some aspects of the present disclosure. The behavioral characterization report 300 can include a list of titles 302 for the sample of malware, category 304 for the samples of malware, tags 308 associated with the malware, number of hits 310 detected, and an indicator score 312… he behavioral characterization report 300 can provide a prioritization of titles 302, to allow the threat intelligence service 144 of FIG. 1 to quickly prioritize responses to detected network threats 132 in order to recover from more advanced attacks). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have generated a behavioral characterization report that includes a prioritization the list of titles the sample of malware so that threats can be quickly prioritize responses to detected network threats in order to recover from more advanced attacks (See Parla paragraph 0081). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEVIN E ALMEIDA whose telephone number is (571)270-1018. The examiner can normally be reached on Monday-Thursday from 7:30 A.M. to 5:00 P.M. The examiner can also be reached on alternate Fridays from 7:30 A.M. to 4:00 P.M. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Rupal Dharia, can be reached on 571-272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /DEVIN E ALMEIDA/Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Feb 27, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12712731
APPARATUS AND METHODS FOR PRIME FIELD MODULAR REDUCTION
2y 9m to grant Granted Aug 18, 2026
Patent 12705371
SYSTEMS FOR TIME DEPENDENT DATA ACCESS AUTHORIZATION
3y 9m to grant Granted Aug 11, 2026
Patent 12695606
FAULT-TOLERANT ACCESS TO DIGITAL ASSETS WITHOUT STORING SENSITIVE SECURITY DATA FOR DECRYPTION
3y 1m to grant Granted Jul 28, 2026
Patent 12682126
APPARATUSES, METHODS, AND SYSTEMS FOR INSTRUCTIONS TO ALLOW TRUSTED EXECUTION ENVIRONMENTS TO REACT TO ASYNCHRONOUS EXITS
5y 6m to grant Granted Jul 14, 2026
Patent 12666255
SELECTIVE USER PLANE PROTECTION IN 5G VIRTUAL RAN
3y 9m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
72%
Grant Probability
83%
With Interview (+11.2%)
3y 7m (~2y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 615 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month