Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is responsive to: an original application filed on 27 February 2025 with acknowledgement that this application is a continuation of a provisional application filed on 28 February 2024.
2. Claims 1-20 are currently pending. Claims 1, 12, and 20, are independent claims.
Claim Rejections – 35 USC § 103
3. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4. Claims 1, 3, 8-12, 14, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Martinez et al. U.S. Patent Application Publication No. 2014/0137257 (hereinafter ‘257) in view of Crabtree et al. U.S. Patent Application Publication No. 2021/0167175 (hereinafter ‘175).
As to independent claim 1, “A method comprising: receiving operational technology (OT) environment data describing a plurality of assets belonging to an OT network environment comprising one or more OT networks, the OT environment data comprising network data and asset data” is taught in ‘257 Abstract and paragraphs 10-11;
“wherein the method is performed by one or more processors” is shown in ‘257 Abstract;Although ‘257 teaches in paragraphs 8 and 243-250 the primary product of the VARM (Vulnerability Assessment and Risk Management) process is an assessment report that includes threat/risk analysis and risk mitigation since the terms ‘generating a network replica’ and ‘attack simulation model’ are not used it could be argued the following is not explicitly taught in ‘257:
“generating a network replica of the OT network environment based on the network data and the asset data, the network replica comprising a structured representation of the plurality of assets, communication pathways between the plurality of assets, security controls implemented in the OT network environment, and vulnerabilities” however ‘175 teaches “In the embodiments described herein, one or more directed graphs are used create system models 2610 to model both the operational technology (OT) and information technology (IT) system and the interactions between them…” in paragraph 108;
“applying an attack simulation model to the network replica and threat data describing a plurality of threats capable of compromising OT network environments, the attack simulation model configured to simulate attacks by the plurality of threats on the network replica and generate simulated attack data describing a set of simulated attack paths corresponding to one or more threats; and providing one or more risk reduction recommendations based on the simulated attack data” however ‘175 teaches “use the system information to initiate iterative simulation of cyberattack strategy sequence, each iteration comprising a simulated attack on a model of the network under test and a simulated defense against the simulated attack” in paragraphs 6-7 and 113;
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of a system, method, and apparatus for assessing risk of one or more assets within an operational technology infrastructure taught in ‘257 to include a means to generate a replica of the OT network environment and apply an attack simulation. One of ordinary skill in the art would have been motivated to perform such a modification because networked systems are highly complex and vulnerable to attack from a myriad of constantly-evolving attack strategies. A system and method are needed for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements, see ‘175 paragraphs 3-4.
As to dependent claim 3, “The method of claim 1: wherein the OT environment data received includes business data; and wherein generating the network replica is based on the business data” is taught in ‘175 paragraph 78.
As to dependent claim 8, “The method of claim 1, further comprising: generating an updated network replica based on one or more changes to the OT network environment; applying the attack simulation model to the updated network replica and the threat data to generate updated simulated attack data; and providing one or more additional risk reduction recommendations based on the updated simulated attack data” is shown in ‘175 paragraphs 120 and 126.
As to dependent claim 9, “The method of claim 8, wherein generating the updated network replica is performed in response to detecting the one or more changes to the OT network environment based on the OT environment data received” is disclosed in ‘175 paragraphs 120 and 126.
As to dependent claim 10, “The method of claim 1, further comprising: generating updated threat data based on one or more changes to the threat data; applying the attack simulation model to the network replica and the updated threat data to generate updated simulated attack data; and providing one or more additional risk reduction recommendations based on the updated simulated attack data” is taught in ‘175 paragraphs 96, 119, and 128.
As to dependent claim 11, “The method of claim 1, further comprising: generating the one or more risk reduction recommendations by applying an attack analysis language model to the simulated attack data” is shown in ‘175 paragraph 113.
As to independent claim 12, this claim is directed to a non-transitory computer-readable medium storing instructions that execute the method of claim 1; therefore, it is rejected along similar rationale.
As to dependent claims 14 and 16-19, these claims contain substantially similar subject matter as claims 3 and 8-11; therefore, they are rejected along similar rationale.
As to independent claim 20, this claim is directed to the system executing the method of claim 1; therefore, it is rejected along similar rationale.
5. Claims 2, 7, and 13, are rejected under 35 U.S.C. 103 as being unpatentable over Martinez et al. U.S. Patent Application Publication No. 2014/0137257 (hereinafter ‘257) in view of Crabtree et al. U.S. Patent Application Publication No. 2021/0167175 (hereinafter ‘175) in further view of Fellow et al. U.S. Patent Application Publication No. 2019/0260781 (hereinafter ‘781).
As to dependent claim 2, the following is not explicitly taught in ‘257 and ‘175: “The method of claim 1, wherein the OT network environment is a production OT network environment; and wherein the OT environment data is received from the production OT network environment” however ‘781 teaches “the GUI allows a viewer to confirm the detected cyber threat in view of what is happening in the OT network…as malfunctions or misconfigurations in the production process can be viewed” in paragraph 36.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of a system, method, and apparatus for assessing risk of one or more assets within an operational technology infrastructure taught in ‘257 and ‘175 to include a means to evaluate an OT network environment that is a production OT network. One of ordinary skill in the art would have been motivated to perform such a modification because Operational Technology (OT) systems, such as Industrial Control Systems (ICS) are critical to major manufacturing and critical infrastructure misconfigurations, malfunctions, and cyber threats are incredibly costly improvements are needed see ‘781 paragraphs 4-5.
As to dependent claim 7, “The method of claim 1, wherein the method is performed on one or more computing devices located within the OT network environment” is taught in ‘781 paragraph 24, note “The one or modules may be situated within the network”.
As to dependent claim 13, this claim contains substantially similar subject matter as claim 2; therefore, it is rejected along similar rationale.
6. Claims 4, 6, and 15, are rejected under 35 U.S.C. 103 as being unpatentable over Martinez et al. U.S. Patent Application Publication No. 2014/0137257 (hereinafter ‘257) in view of Crabtree et al. U.S. Patent Application Publication No. 2021/0167175 (hereinafter ‘175) in further view of Sellars et al. U.S. Patent Application Publication No. 2024/0406210 (hereinafter ‘210).
As to dependent claim 4, the following is not explicitly taught in ‘257 and ‘175 “The method of claim 1, further comprising: wherein the OT environment data received includes security data generated by one or more OT security vendors; and wherein generating the network replica is based on the security data” however ‘210 teaches “The cyber-attack simulator 105 in conducting simulations can use the cyber threat analyst module with external data input (e.g., crowdstrike)…3rd party vendors, antivirus and-based testing antivirus in paragraph 2014.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of a system, method, and apparatus for assessing risk of one or more assets within an operational technology infrastructure taught in ‘257 and ‘175 to include a means to utilize OT security vendors. One of ordinary skill in the art would have been motivated to perform such a modification because cybersecurity attack have become a pervasive problems for enterprises improvements are needed over the conventional cybersecurity products see paragraph 4.
As to dependent claim 6, “The method of claim 1, wherein the network replica comprises a graph database that includes the structured representation of substantially all assets belonging to the OT network environment” is taught in ‘210 paragraph 97.
As to dependent claim 15, this claim contains substantially similar subject matter as claim 4; therefore, it is rejected along similar rationale.
7. Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Martinez et al. U.S. Patent Application Publication No. 2014/0137257 (hereinafter ‘257) in view of Crabtree et al. U.S. Patent Application Publication No. 2021/0167175 (hereinafter ‘175) in further view of Mehrotra et al. U.S. Patent Application Publication No. 2022/010082 (hereinafter ‘182).
As to dependent claim 5, the following is not explicitly taught in ‘257 and ‘175 “The method of claim 1, further comprising: maintaining a threat database comprising the plurality of threats based on threat intelligence data received from one or more threat intelligence data sources” however ‘182 teaches “At process block 146, a destination for the received data may be determined based on analyzing the data, metadata included with the data, or both. For example, in the case of the edge computing device 86 receiving the data 102B, the edge computing device 86 may determine whether to provide the received data to the database” in paragraph 83.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of a system, method, and apparatus for assessing risk of one or more assets within an operational technology infrastructure taught in ‘257 and ‘175 to include a means to maintain a threat database. One of ordinary skill in the art would have been motivated to perform such a modification because asset-related to data management with the plurality of services from various entities creates a need for ease of use for technicians see paragraphs 1-3.
Conclusion
8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ELLEN C TRAN whose telephone number is (571) 272-3842. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeff Pwu can be reached at 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
__________________________________________________________
/ELLEN TRAN/Primary Examiner, Art Unit 2433 24 July 2026