DETAILED ACTION
This action is in response to new application titled “SYSTEMS AND METHODS FOR ASSESSING EXPOSURE EXPLOITABILITY IN ADVANCED CYBERATTACK SCENARIOS” filed 2/27/2025. Claims 1-43 were received for consideration.
Priority
Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). The certified copy has been received.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 2/27/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1-7, 11-19, 22-28, 32-40 and 43 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Mullaney (US 2022/0286475).
With respect to claim 1 Mullaney teaches a method, performed by a device, comprising:
generating, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and
performing one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 2 Mullaney teaches the method of claim 1, wherein performing the one or more actions based on the set of vulnerability scores comprises: transmitting a report of the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 3 Mullaney teaches the method of claim 1, wherein performing the one or more actions based on the set of vulnerability scores comprises: performing a remediation based at least in part on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 4 Mullaney teaches the method of claim 1, wherein the vulnerabilities are classified by common vulnerabilities and exposures (CVEs) (see Mullaney paragraph 0046 i.e. As indicated above, a CAN may evaluate a vulnerability of its own product, assign a CVE ID and associated metadata to the vulnerability when the vulnerability is disclosed to the public. A Common Vulnerability Scoring System (CVSS) is an open framework for communicating characteristics and severity of software vulnerabilities. A set of CVSS metrics may be published as part of the metadata associated with a CVE. These metrics may be calculated by the CNA that first registers the vulnerability and published with the initial CVE disclosure).
With respect to claim 5 Mullaney teaches the method of claim 1, further comprising: extracting a raw dataset from the threat-related information; and generating the dataset based on the raw dataset extracted from the threat-related information (see Mullaney paragraph 0113-0117 i.e. In block 620, the vulnerability metrics generator may receive a trained vulnerability metrics generation model, e.g., from a vulnerability metrics generation model trainer. The vulnerability metrics generation model may be trained on a training dataset to generate one or more target vulnerability vectors of a target vulnerability. The training dataset has been described above, and thus is not repeated here. In an aspect, the target vulnerability may not be any one of the one or more training vulnerabilities of the training dataset. In other words, the target vulnerability may be a previously unseen vulnerability. In block 630, the vulnerability metrics generator may generate one or more target vulnerability vectors based on the target vulnerability description).
With respect to claim 6 Mullaney teaches the method of claim 1, wherein generating, by the one or more classifiers, the set of vulnerability scores comprises: generating, by a first classifier, a first set of partial scores based on the descriptions of the vulnerabilities; generating, by a second classifier, a second set of partial scores based on the sets of vulnerability parameters associated with the vulnerabilities; and generating, by an ensemble classifier, the set of vulnerability scores based on the first set of partial scores and the second set of partial scores (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector and paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector).
With respect to claim 7 Mullaney teaches the method of claim 6, wherein generating, by the first classifier, the first set of partial scores comprises: obtaining a set of embeddings of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the embeddings (see Mullaney paragraph 0112 i.e. FIG. 6 illustrates a flow chart of an example method 600 for generating vulnerability metrics. The method 600 may be performed by a vulnerability metrics generator. In an aspect, the vulnerability management system 150, 250 may also perform vulnerability metrics generation model trainer functions. In block 610, the vulnerability metrics generator may receive a target vulnerability description of a target vulnerability. The target vulnerability description may comprise a textual description).
With respect to claim 11 Mullaney teaches the method of claim 6, wherein the sets of vulnerability parameters include: a set of exploit maturities; a set of severities; a set of risk factors; a set of exploit prediction scoring system (EPSS) percentiles; or any combination thereof (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 12 Mullaney teaches the method of claim 11, wherein generating, by the second classifier, the second set of partial scores comprises: generating the second set of partial scores based on one or more of the sets of vulnerability parameters (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector and paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector).
With respect to claim 13 Mullaney teaches the method of claim 12, wherein each of the exploit maturities is assigned a value of high, functional, or proof of concept (POC), and wherein the second set of partial scores is based at least in part on scaled exploit maturity scores associated with the exploit maturities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 14 Mullaney teaches the method of claim 12, wherein each of the severities is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled severity scores associated with the severities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 15 Mullaney teaches the method of claim 12, wherein each of the risk factors is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled risk factor scores associated with the risk factors (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 16 Mullaney teaches the method of claim 12, wherein the second set of partial scores is based at least in part on scaled EPSS scores associated with the EPSS percentiles (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 17 Mullaney teaches the method of claim 12, wherein the second set of partial scores is based at least in part on indications of whether the vulnerabilities are remotely exploitable (see Mullaney paragraph 0032 i.e. On the other hand, the uncredentialed audits may generally include network-based scans that involve communicating packets or messages to the appropriate asset(s) 130 and observing responses thereto in order to identify certain vulnerabilities (e.g., that a particular asset 130 accepts spoofed packets that may expose a vulnerability that can be exploited to close established connections).
With respect to claim 18 Mullaney teaches the method of claim 6, wherein generating, by the ensemble classifier, the set of vulnerability scores comprises: summing the first set of partial scores and the second set of partial scores to obtain the set of vulnerability scores (see Mullaney paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector).
With respect to claim 19 Mullaney teaches the method of claim 6, wherein generating, by the ensemble classifier, the set of vulnerability scores comprises: generating a weighted sum of the first set of partial scores that are weighted by a first weight and the second set of partial scores that are weighted by a second weight to obtain the set of vulnerability scores (see Mullaney paragraph 0122 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions).
With respect to claim 22 Mullaney teaches a device, comprising: one or more memories; and one or more processors communicatively coupled to the one or more memories, the one or more processors, either alone or in combination, configured to:
generate, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and
perform one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 23 Mullaney teaches the device of claim 22, wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: transmit a report of the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 24 Mullaney teaches the device of claim 22, wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: perform a remediation based at least in part on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
With respect to claim 25 Mullaney teaches the device of claim 22, wherein the vulnerabilities are classified by common vulnerabilities and exposures (CVEs) (see Mullaney paragraph 0046 i.e. As indicated above, a CAN may evaluate a vulnerability of its own product, assign a CVE ID and associated metadata to the vulnerability when the vulnerability is disclosed to the public. A Common Vulnerability Scoring System (CVSS) is an open framework for communicating characteristics and severity of software vulnerabilities. A set of CVSS metrics may be published as part of the metadata associated with a CVE. These metrics may be calculated by the CNA that first registers the vulnerability and published with the initial CVE disclosure).
With respect to claim 26 Mullaney teaches the device of claim 22, wherein the one or more processors, either alone or in combination, are further configured to: extract a raw dataset from the threat-related information; and generate the dataset based on the raw dataset extracted from the threat-related information (see Mullaney paragraph 0113-0117 i.e. In block 620, the vulnerability metrics generator may receive a trained vulnerability metrics generation model, e.g., from a vulnerability metrics generation model trainer. The vulnerability metrics generation model may be trained on a training dataset to generate one or more target vulnerability vectors of a target vulnerability. The training dataset has been described above, and thus is not repeated here. In an aspect, the target vulnerability may not be any one of the one or more training vulnerabilities of the training dataset. In other words, the target vulnerability may be a previously unseen vulnerability. In block 630, the vulnerability metrics generator may generate one or more target vulnerability vectors based on the target vulnerability description).
With respect to claim 27 Mullaney teaches the device of claim 22, wherein the one or more processors configured to generate, by the one or more classifiers, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: generate, by a first classifier, a first set of partial scores based on the descriptions of the vulnerabilities; generate, by a second classifier, a second set of partial scores based on the sets of vulnerability parameters associated with the vulnerabilities; and generate, by an ensemble classifier, the set of vulnerability scores based on the first set of partial scores and the second set of partial scores (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector).
With respect to claim 28 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the first classifier, the first set of partial scores comprise the one or more processors, either alone or in combination, configured to: obtain a set of embeddings of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the embeddings (see Mullaney paragraph 0112 i.e. FIG. 6 illustrates a flow chart of an example method 600 for generating vulnerability metrics. The method 600 may be performed by a vulnerability metrics generator. In an aspect, the vulnerability management system 150, 250 may also perform vulnerability metrics generation model trainer functions. In block 610, the vulnerability metrics generator may receive a target vulnerability description of a target vulnerability. The target vulnerability description may comprise a textual description).
With respect to claim 32 Mullaney teaches the device of claim 27, wherein the sets of vulnerability parameters include: a set of exploit maturities; a set of severities; a set of risk factors; a set of exploit prediction scoring system (EPSS) percentiles; or any combination thereof (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 33 Mullaney teaches the device of claim 32, wherein the one or more processors configured to generate, by the second classifier, the second set of partial scores comprise the one or more processors, either alone or in combination, configured to: generate the second set of partial scores based on one or more of the sets of vulnerability parameters (see Mullaney paragraph 0122-0123 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions. In block 650, the vulnerability metrics generator may determine a confidence level for each target vulnerability vector).
With respect to claim 34 Mullaney teaches the device of claim 33, wherein each of the exploit maturities is assigned a value of high, functional, or proof of concept (POC), and wherein the second set of partial scores is based at least in part on scaled exploit maturity scores associated with the exploit maturities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 35 Mullaney teaches the device of claim 33, wherein each of the severities is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled severity scores associated with the severities (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 36 Mullaney teaches the device of claim 33, wherein each of the risk factors is assigned a value of critical, high, or medium, and wherein the second set of partial scores is based at least in part on scaled risk factor scores associated with the risk factors (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 37 Mullaney teaches the device of claim 33, wherein the second set of partial scores is based at least in part on scaled EPSS scores associated with the EPSS percentiles (See Mullaney paragraph 0108 i.e. FIG. 5 illustrates a flow chart of an exemplary process that may be performed, e.g., by the vulnerability metrics generation model trainer, to implement block 320. In block 510, the vulnerability metrics generation model trainer may train the vulnerability metrics generation model to associate the one or more training vulnerability metrics and corresponding vulnerability metric values to the extracted training features of the training dataset. For example, one association may be made between a metric:value combination “AV:N” (attack vector (AV) metric with value network (N)) with the extracted training features. Another association may be made between a metric:value combination “AC:H” (attack complexity (AC) metric with value high (H)) with the extracted training features. A third association may be made between a metric:value combination “AV:L” (attack vector (AV) metric with value network (N)).
With respect to claim 38 Mullaney teaches the device of claim 33, wherein the second set of partial scores is based at least in part on indications of whether the vulnerabilities are remotely exploitable (see Mullaney paragraph 0032 i.e. On the other hand, the uncredentialed audits may generally include network-based scans that involve communicating packets or messages to the appropriate asset(s) 130 and observing responses thereto in order to identify certain vulnerabilities (e.g., that a particular asset 130 accepts spoofed packets that may expose a vulnerability that can be exploited to close established connections).
With respect to claim 39 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the ensemble classifier, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: sum the first set of partial scores and the second set of partial scores to obtain the set of vulnerability scores see Mullaney paragraph 0119 i.e. In block 820, the vulnerability metrics generator may combine the separately determined target vulnerability metrics and their corresponding metric values for each target vulnerability vector).
With respect to claim 40 Mullaney teaches the device of claim 27, wherein the one or more processors configured to generate, by the ensemble classifier, the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: generate a weighted sum of the first set of partial scores that are weighted by a first weight and the second set of partial scores that are weighted by a second weight to obtain the set of vulnerability scores (see Mullaney paragraph 0122 i.e. In block 640, the vulnerability metrics generator may generate one or more target vulnerability scores of the target vulnerability based on the one or more target vulnerability vectors. In an aspect, each target vulnerability score may be generated using a scoring calculator of the vulnerability version corresponding to that target vulnerability score. Again, when multiple target vulnerability scores are generated, they may be vulnerability scores of multiple vulnerability scoring versions).
With respect to claim 43 Mullaney teaches a non-transitory computer-readable medium storing computer-executable instructions that, when executed by a device, cause the device to:
generate, by one or more classifiers, a set of vulnerability scores based on a dataset that is obtained based on threat-related information referencing vulnerabilities, wherein the dataset includes descriptions of the vulnerabilities and sets of vulnerability parameters associated with the vulnerabilities (see Mullaney paragraph 0049-0050 i.e. In an aspect, this may be accomplished by training a supervised Machine Learning model to produce a vulnerability metric (e.g., CVSS metric) based on a vulnerability's description. Since a description of the vulnerability is required to publish a CVE, it can be assured that a description will always be available for a vulnerability once a CVE has been published. As this is a supervised Machine Learning algorithm, a corpus of existing descriptions from the US NVD may be used train the model. The proposed technique may automatically generate a vulnerability metric including a vector and score (e.g., CVSS vector and score) based on a description as supplied by a non-authoritative scoring entity (e.g., software vendor). In many instances, software vendors do not produce their own CVSS metrics, or do produce their own metrics that are ultimately inconsistent with metrics that have been previously produced by the defacto source of truth for vulnerability data, the US NVD. With the proposed technique, using previously created descriptions and vulnerability metrics, a previously unseen vulnerability description may be taken to produce a new vulnerability metric); and
perform one or more actions based on the set of vulnerability scores (see Mullaney paragraph 0040 i.e. in response to obtaining the snapshot of the network 200, the active scanners 210 and/or cloud scanners 270 may then report the information describing the snapshot to the vulnerability management system 250, which may use the information to remediate and otherwise manage the vulnerabilities and assets in the network and paragraph 0042-0044).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 8-10 and 29-31 are rejected under 35 U.S.C. 103 as being unpatentable over Mullaney (US 2022/0286475) in view of
With respect to claim 8 Mullaney teaches the method of claim 7, but does not disclose wherein obtaining the first set of partial scores based on the embeddings comprises: obtaining a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the distances.
Zelivansky teaches wherein obtaining the first set of partial scores based on the embeddings comprises: obtaining a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtaining the first set of partial scores based on the distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Zelivansky to have measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance and text representation for measuring text similarity includes string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based as a way to update the match confidence variable of the informal vulnerability record based on prose descriptions similarity (see Zelivansky paragraph 0052).
With respect to claim 9 Mullaney in view of Zelivansky teaches the method of claim 8, wherein the first set of partial scores are based on a set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
With respect to claim 10 Mullaney in view of Zelivansky teaches the method of claim 9, but does not disclose wherein a higher partial score within the first set of partial scores corresponds to a shorter scaled distance within the set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
With respect to claim 29 Mullaney teaches the device of claim 28, but does not disclose wherein the one or more processors configured to obtain the first set of partial scores based on the embeddings comprise the one or more processors, either alone or in combination, configured to: obtain a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the distances.
Zelivansky teaches wherein the one or more processors configured to obtain the first set of partial scores based on the embeddings comprise the one or more processors, either alone or in combination, configured to: obtain a set of distances based on the embeddings, wherein each of the distances represents a difference between texts of two of the descriptions of the vulnerabilities; and obtain the first set of partial scores based on the distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
With respect to claim 30 Mullaney in view of Zelivansky teaches the device of claim 29, wherein the first set of partial scores are based on a set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
With respect to claim 31 Mullaney in view of Zelivansky teaches the device of claim 30, wherein a higher partial score within the first set of partial scores corresponds to a shorter scaled distance within the set of scaled distances (see Zelivansky paragraph 0052 i.e. operations for updating the match confidence variable of the informal vulnerability record based on prose descriptions similarity. At block 501, the system measures similarity of the prose description in the security advisory and the prose description in the informal vulnerability record. Text similarity can be measured based on text distance and text representation. The text distance includes length distance, distribution distance, and semantic distance. Text representation for measuring text similarity can be string-based, corpus-based, single-semantic text, multi-semantic text, and graph-structure-based. Examples of tools (i.e., libraries or application programming interfaces (APIs)) that can be used for measuring similarity of prose descriptions include the RxNLP Text Similarity API and the Gensim library. Implementations can pre-process the prose descriptions prior to measuring similarity (e.g., text cleaning and trimming)).
Claims 20, 21, 41 and 42 are rejected under 35 U.S.C. 103 as being unpatentable over Mullaney (US 2022/0286475) in view of Parla (US 2027/0333747).
With respect to claim 20 Mullaney teaches the method of claim 1, but does not disclose wherein performing the one or more actions based on the set of vulnerability scores comprises: determining whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores.
Parla teaches wherein performing the one or more actions based on the set of vulnerability scores comprises: determining whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores (see Parla paragraph 0076 i.e. the threat management service 102 can take an additional step of identifying verdicts 208 of the sample of malware, in order to request remedial action from the remedial action service 110, to address the potential network threat. In some examples, a verdict can be assigned to a sample in order to indicate the nature of its activities, such as ransomware or phishing. Verdicts are derived from various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices. By assigning judgments and verdicts to samples of malware, organizations can more easily identify which threats they need to prioritize when responding to a malicious attack).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have taken an additional step of identifying verdicts of the sample of malware, in order to request remedial action from the remedial to address the potential network threat. Where the verdict assign to the sample indicate the nature of its activities, such as ransomware or phishing based on various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices, so organizations can more easily identify which threats they need to prioritize when responding to a malicious attack (see paragraph 0076).
With respect to claim 21 Mullaney teaches the method of claim 1, but does not disclose wherein performing the one or more actions based on the set of vulnerability scores comprises: presenting a prioritization of threats based on the set of vulnerability scores.
Parla teaches wherein performing the one or more actions based on the set of vulnerability scores comprises: presenting a prioritization of threats based on the set of vulnerability scores (see Parla paragraph 0079-0082 i.e. FIG. 3 illustrates an example behavioral characterization report 300 capable of indicating network threats 132 detected in a network 104 according to some aspects of the present disclosure. The behavioral characterization report 300 can include a list of titles 302 for the sample of malware, category 304 for the samples of malware, tags 308 associated with the malware, number of hits 310 detected, and an indicator score 312… he behavioral characterization report 300 can provide a prioritization of titles 302, to allow the threat intelligence service 144 of FIG. 1 to quickly prioritize responses to detected network threats 132 in order to recover from more advanced attacks).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have generated a behavioral characterization report that includes a prioritization the list of titles the sample of malware so that threats can be quickly prioritize responses to detected network threats in order to recover from more advanced attacks (See Parla paragraph 0081).
With respect to claim 41 Mullaney teaches the device of claim 22, but does not disclose wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: determine whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores.
Parla teaches wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: determine whether one or more of the vulnerabilities are indicative of advanced persistent threat (APT) exploitations, ransomware exploitations, or any combination thereof, based on the set of vulnerability scores (see Parla paragraph 0076 i.e. the threat management service 102 can take an additional step of identifying verdicts 208 of the sample of malware, in order to request remedial action from the remedial action service 110, to address the potential network threat. In some examples, a verdict can be assigned to a sample in order to indicate the nature of its activities, such as ransomware or phishing. Verdicts are derived from various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices. By assigning judgments and verdicts to samples of malware, organizations can more easily identify which threats they need to prioritize when responding to a malicious attack).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have taken an additional step of identifying verdicts of the sample of malware, in order to request remedial action from the remedial to address the potential network threat. Where the verdict assign to the sample indicate the nature of its activities, such as ransomware or phishing based on various factors, including static analysis results, dynamic analysis behaviors, and connections made between network devices, so organizations can more easily identify which threats they need to prioritize when responding to a malicious attack (see paragraph 0076).
With respect to claim 42 Mullaney teaches the device of claim 22, but does not disclose wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: present a prioritization of threats based on the set of vulnerability scores.
Parla teaches wherein the one or more processors configured to perform the one or more actions based on the set of vulnerability scores comprise the one or more processors, either alone or in combination, configured to: present a prioritization of threats based on the set of vulnerability scores (see Parla paragraph 0079-0082 i.e. FIG. 3 illustrates an example behavioral characterization report 300 capable of indicating network threats 132 detected in a network 104 according to some aspects of the present disclosure. The behavioral characterization report 300 can include a list of titles 302 for the sample of malware, category 304 for the samples of malware, tags 308 associated with the malware, number of hits 310 detected, and an indicator score 312… he behavioral characterization report 300 can provide a prioritization of titles 302, to allow the threat intelligence service 144 of FIG. 1 to quickly prioritize responses to detected network threats 132 in order to recover from more advanced attacks).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Mullaney in view of Parla to have generated a behavioral characterization report that includes a prioritization the list of titles the sample of malware so that threats can be quickly prioritize responses to detected network threats in order to recover from more advanced attacks (See Parla paragraph 0081).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEVIN E ALMEIDA whose telephone number is (571)270-1018. The examiner can normally be reached on Monday-Thursday from 7:30 A.M. to 5:00 P.M. The examiner can also be reached on alternate Fridays from 7:30 A.M. to 4:00 P.M.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Rupal Dharia, can be reached on 571-272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/DEVIN E ALMEIDA/Examiner, Art Unit 2492