Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 6 and 13 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 6 and 13 declare “the information” however in independent claims 1 and 8 have already declared “license information” and “vulnerability information” making the antecedent basis unclear.
Examiner believes that “the information” in claims 6 and 13 should be declared as “the vulnerability information” and has interpreted the claims this way for the sake of examination.
Appropriate correction or clarification is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over United States Patent Application Publication No. US 2016/0300065 A1 (Bang) in view of United States Patent Application Publication No. US 2024/0314020 A1 (Gong et al.)
As Per Claim 1: Bang Teaches: A method for generating a vulnerability report for a product, the method comprising:
- obtaining, by a server, a set of parameters corresponding to the product associated with a user device, wherein the set of parameters comprises a product name, a pre-installed product version,
- analysing, by the server, a database to determine one of a presence or an absence of vulnerability information associated with the product within the database, wherein the vulnerability information comprises one or more issues associated with a current product version and each of a set of existing product versions of the product;
(Bang, Paragraph [0023], “The functions of program assessment module 140 and vulnerability optimization module 150 may be performed by any suitable combination of one or more servers or other components at one or more locations. In the embodiment where the modules are servers, the servers may be public or private servers, and each server may be a virtual or physical server. The server may include one or more servers at the same or at remote locations. Program assessment module 140 and vulnerability optimization module 150 may also include any suitable component that functions as a server. In some embodiments, workstation 130 may be integrated with program assessment module 140 and vulnerability optimization module 150 or they may operate as part of the same device or devices.”).
(Bang, Paragraph [0003], “In accordance with the present disclosure, in one embodiment, a system for identifying and tracking application vulnerabilities includes an interface, a processor, and a memory. The interface is operable to receive a plurality of applications from one or more business units, each of the plurality of applications including source code. A process is communicatively coupled to the interface and is operable to identify a vulnerability associated with the source code of each of the plurality of applications. A memory is communicatively coupled to the interface and the processor and operable to store the vulnerability and the source code associated with the vulnerability in a vulnerability database. The processor is further operable to create a vulnerability tag for the vulnerability. The memory may store the vulnerability tag in a reporting database.”).
(Bang, Paragraph [0013], “To identify and track the vulnerabilities, a vulnerability optimization module may interface with the vulnerability database. The vulnerability optimization module may tag each vulnerability with information including the vulnerability's name, the application (and version) containing the vulnerability, the business unit running the application, the date that the vulnerability was discovered and tagged, and a review status indicating the severity of the vulnerability. The vulnerability optimization module may synchronize with the vulnerability database at regular intervals (e.g., every twenty-four hours, once a week, once a month) to determine whether any new vulnerabilities have been added to the vulnerability database. To prevent redundancies in the reporting database, vulnerability optimization module may use the tagging function to determine whether a vulnerability added to the vulnerability database is a pre-existing vulnerability discovered during a previous scan, or whether a new version of an application still contains the same vulnerability. In this manner, the tagging program can differentiate between vulnerabilities that have not been corrected and vulnerabilities that may have been missed during an application update. Accordingly, the vulnerability optimization module may provide analytics regarding the applications run by the enterprise's business units.”).
- in response to analysing, extracting, by the server, the vulnerability information for the product, upon determining the presence of the vulnerability information;
- validating, by the server, each of the set of parameters based on the vulnerability information extracted for the product; and
(Bang, Paragraph [0015], “In the illustrated embodiment, business units 122a-n send a plurality of applications 102 to program assessment module 140 to be analyzed for vulnerabilities. Program assessment module 140 may identify vulnerabilities in the plurality of applications 102 and store identified vulnerabilities 104 in vulnerability database 149. Program assessment module 140 may send identified vulnerabilities 104 to workstation 130 for a specialist to analyze. Utilizing workstation 130, the specialist may analyze the source code pertaining to identified vulnerabilities 104. The specialist may determine that identified vulnerability 104 is a false-positive and indicate to program assessment module 140 that the identified vulnerability 104 should be removed from vulnerability database 149. Alternatively, the specialist may confirm identified vulnerability 104 and indicate to program assessment module 140 that the vulnerability needs remediation.”).
- generating, by the server, a vulnerability report corresponding to the product in a pre-defined format based on the validating, wherein the vulnerability report comprises information associated with the current product version and each of the set of existing product versions.
(Bang, Paragraph [0016], “Vulnerability optimization module 150 may then analyze and tag identified vulnerabilities 104 in vulnerability database 149. Vulnerability optimization module 150 may then store tagged vulnerabilities 157 in reporting database 159. Reporting database 159 may then develop analytics and track identified vulnerabilities 104 in vulnerability database 149. For example, vulnerability optimization module 150 may generate and transmit vulnerability report 106 to business units 122a-n based on tagged vulnerabilities 157. Vulnerability report 106 may be customized to include specific information regarding identified vulnerabilities 104 affecting the applications administered by individual business units (e.g., business unit 122a), or it may be generalized to produce information regarding identified vulnerabilities 104 affecting the entire enterprise.”).
Bang does not explicitly teach the following limitation:
- parameters including a license information, and user device configurations;
However Gong et al. in analogous art does teach the above limitation:
(Gong et al.,Paragraph [0022], “The system 10 is one example of an enterprise network. The system 10 may involve multiple enterprise networks. The network/computing equipment and software 102(1)-102(N) are resources or assets of an enterprise (the terms “assets” and “resources” are used interchangeably herein). The network/computing equipment and software 102(1)-102(N) may include any type of network devices or network nodes such as controllers, access points, gateways, switches, routers, hubs, bridges, gateways, modems, firewalls, intrusion protection devices/software, repeaters, servers, and so on. The network/computing equipment and software 102(1)-102(N) may further include endpoint or user devices such as a personal computer, laptop, tablet, and so on. The network/computing equipment and software 102(1)-102(N) may include virtual nodes such as virtual machines, containers, point of delivery (POD), and software such as system software (operating systems), firmware, security software such as firewalls, and other software products. The network/computing equipment and software 102(1)-102(N) may be in a form of software products that reside in an enterprise network and/or in one or more cloud(s). Associated with the network/computing equipment and software 102(1)-102(N) is configuration data representing various configurations, such as enabled and disabled features. The network/computing equipment and software 102(1)-102(N), located at the enterprise sites 110(1)-110(N), represent information technology (IT) environment of an enterprise.”).
(Gong et al.,Paragraph [0030], “Moreover, each device or group of devices may encounter various issues. In one example embodiment, these issues involve network related problems or potential problems. Network related problems may involve an outage, a latency problem, a connectivity problem, a malfunction of the network device or software thereon, and/or incompatibility or configuration related problems. In one example embodiment, issues may involve defects, obsolescence, configurations, workarounds, network patches, network information, etc. Issues may relate to warranties, licenses, or may be informational notices e.g., for a particular configuration or upgrade.”).
(Gong et al.,Paragraph [0042], “In addition to the inventory data 220, the network hierarchical summary and recommendation service 120 also obtains plurality of notifications 230a-j from various data sources (knowledge base). The notifications 230a-j may include information about a particular network device (such as a first network device 212a). For example, a notification may be a security alert, a bug notice, a defect notice, a security vulnerability report, etc. As another example, a notification may be a warranty coverage notice (e.g., support license for a specific network device is about to expire) or a configuration notice (e.g., devices executing software version A need to be upgraded to the software version B or a patch C needs to be installed).”).
It would have been an obvious interchangeable variation readily implemented with expectations of success to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Gong et al. into the method of Bang as information such as a license information and user device configurations are well established parameters that fit right into Bang’s nonlimiting list of details that can be collected and are known to be used for the same purpose.
As Per Claim 2: The rejection of claim 1 is incorporated and further Bang teaches:
- the database comprises vulnerability information associated with a plurality of products, and wherein the database is updated with the vulnerability information before release of each product version of each of the plurality of products.
(Bang, Paragraph [0019], “Business units 122a-n may utilize one or more applications to conduct their operations. To ensure that the applications are designed and functioning properly, business units 122a-n may use program assessment module 140 to scan their applications for potential vulnerabilities. For example, an enterprise may require business unit 122a to scan every application and every new version of the application used by business unit 122a. Business unit 122a may scan their active applications periodically (i.e., every month, forty-five days, six months, year) to take advantage of any updates to vulnerability identifier program 148.”).
(Bang, Paragraph [0025], “Program assessment interface 142 may be used to receive a plurality of applications 102 from one or more business units 122a-n. Program assessment interface 142 may also transmit the source code of identified vulnerabilities 104 to workstation 130 so that a specialist may further inspect the source code to determine if there is any malicious code. In certain embodiments, program assessment interface 142 may aid vulnerability optimization interface 152 in searching vulnerability database 149. For example, in certain embodiments, program assessment interface 142 may send a notification to vulnerability optimization module 150 that a new vulnerability was identified and needs to be tagged by vulnerability optimization module 150.”).
As Per Claim 3: The rejection of claim 1 is incorporated and further Bang and Gong et al. do not explicitly teach:
- the one or more issues comprises issues associated with components, ports, platforms, web services, an End of Life (EOL) of associated third party components, and an EOL of the product.
However Examiner is giving Official Notice that this is just a list of standard known types of vulnerability vectors and issues it would have been an obvious interchangeable variation readily implemented with expectations of success to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the listing of these particular vulnerability vectors and issues in the details of the vulnerabilities as performed in Bang and Gong et al..
As Per Claim 4: The rejection of claim 1 is incorporated and further Bang teaches:
- upon determining the absence of the vulnerability information associated with the product within the database,
- scanning, by the server, the product based on at least one vulnerability scanning technique;
- identifying, by the server, the vulnerability information for the product in response to the scanning; and
- updating, by the server, the database based on the vulnerability information determined for the product.
(Bang, Paragraph [0013], “To identify and track the vulnerabilities, a vulnerability optimization module may interface with the vulnerability database. The vulnerability optimization module may tag each vulnerability with information including the vulnerability's name, the application (and version) containing the vulnerability, the business unit running the application, the date that the vulnerability was discovered and tagged, and a review status indicating the severity of the vulnerability. The vulnerability optimization module may synchronize with the vulnerability database at regular intervals (e.g., every twenty-four hours, once a week, once a month) to determine whether any new vulnerabilities have been added to the vulnerability database. To prevent redundancies in the reporting database, vulnerability optimization module may use the tagging function to determine whether a vulnerability added to the vulnerability database is a pre-existing vulnerability discovered during a previous scan, or whether a new version of an application still contains the same vulnerability. In this manner, the tagging program can differentiate between vulnerabilities that have not been corrected and vulnerabilities that may have been missed during an application update. Accordingly, the vulnerability optimization module may provide analytics regarding the applications run by the enterprise's business units.”).
(Bang, Paragraph [0019], “Business units 122a-n may utilize one or more applications to conduct their operations. To ensure that the applications are designed and functioning properly, business units 122a-n may use program assessment module 140 to scan their applications for potential vulnerabilities. For example, an enterprise may require business unit 122a to scan every application and every new version of the application used by business unit 122a. Business unit 122a may scan their active applications periodically (i.e., every month, forty-five days, six months, year) to take advantage of any updates to vulnerability identifier program 148.”).
As Per Claim 5: The rejection of claim 4 is incorporated and further Bang and Gong et al. do not explicitly teach:
- the at least one vulnerability scanning technique comprises a Black Duck scanning technique, a Nessus scanning technique, a Nexpose scanning technique, a Webapp scanning technique, and a penetration testing technique.
However Examiner is giving Official Notice that this is just a list of known scanning techniques. It would have been an obvious interchangeable variation readily implemented with expectations of success to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate specific scanning techniques into the general scanning performed in Bang and Gong et al.
As Per Claim 6: The rejection of claim 1 is incorporated and further Bang teaches:
- the information comprises an impact, a remediated product version, false positives,
(Bang, Paragraph [0015], “In the illustrated embodiment, business units 122a-n send a plurality of applications 102 to program assessment module 140 to be analyzed for vulnerabilities. Program assessment module 140 may identify vulnerabilities in the plurality of applications 102 and store identified vulnerabilities 104 in vulnerability database 149. Program assessment module 140 may send identified vulnerabilities 104 to workstation 130 for a specialist to analyze. Utilizing workstation 130, the specialist may analyze the source code pertaining to identified vulnerabilities 104. The specialist may determine that identified vulnerability 104 is a false-positive and indicate to program assessment module 140 that the identified vulnerability 104 should be removed from vulnerability database 149. Alternatively, the specialist may confirm identified vulnerability 104 and indicate to program assessment module 140 that the vulnerability needs remediation.”).
(Bang, Paragraph [0022], “Program assessment module 140 and vulnerability optimization module 150 represent any suitable components that facilitate identifying and tracking application vulnerabilities. Program assessment module 140 and vulnerability optimization module 150 may also be any suitable components that generate and facilitate the identification, tagging, and reporting of application vulnerabilities and their remediation. Program assessment module 140 and vulnerability optimization module 150 may include a network server, remote server, mainframe, host computer, workstation, web server, personal computer, file server, or any other suitable device operable to communicate with other devices and process data. In some embodiments, program assessment module 140 and vulnerability optimization module 150 may execute any suitable operating system such as IBM's zSeries/Operating System (z/OS), MS-DOS, PC-DOS, MAC-OS, WINDOWS, UNIX, OpenVMS, Linux, or any other appropriate operating systems, including future operating systems.”).
(Bang, Paragraph [0030], “Vulnerability optimization processor 154 communicatively couples interface 152 and memory 156 and controls the operation of vulnerability optimization module 150. Vulnerability optimization processor 154 may execute tagging program 158 to analyze identified vulnerabilities 104 stored in vulnerability database 149. Tagging program 158 may scan identified vulnerabilities 104, generate a tagged vulnerability 157 based on the identified vulnerability 104, and store tagged vulnerability 157 in reporting database 159. In certain embodiments, tagged vulnerability 157 comprises a plurality of information regarding identified vulnerability 104 that is useful to the tracking and remediation of identified vulnerability 104.”).
(Bang, Paragraph [0031], “In an example embodiment, vulnerability optimization processor 154 executes tagging program 158 and scans vulnerability database 149 to create a tagged vulnerability 157 for each identified vulnerability 104. A tagged vulnerability 157 may comprise information including, but is not limited to, a vulnerability identifier, an application identifier, a review version, a status date, an implementation date, a review status, a remediation date, vendor identifier, and a business group identifier. Tagging program 158 may tag vulnerabilities stored in vulnerability database 149 using one or more of the foregoing categories when used by vulnerability optimization processor 154. Vulnerability optimization processor 154 may store tagged vulnerabilities 157 in vulnerability database 156.”).
Bang and Gong et al. do not explicitly teach:
- the information comprising a common vulnerability exposure (CVE) list, and a download link.
However Examiner is giving Official Notice CVE and a download link would be normal information to have in the present environment It would have been an obvious interchangeable variation readily implemented with expectations of success to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the normal available tools in to the method of Bang and Gong et al.
As Per Claim 7: The rejection of claim 1 is incorporated and further Bang teaches:
- transmitting, by the server, the vulnerability report to the user device; and
- rendering, via a Graphical User Interface (GUI) of the user device, the vulnerability report to a user.
(Bang, Paragraph [0016], “Vulnerability optimization module 150 may then analyze and tag identified vulnerabilities 104 in vulnerability database 149. Vulnerability optimization module 150 may then store tagged vulnerabilities 157 in reporting database 159. Reporting database 159 may then develop analytics and track identified vulnerabilities 104 in vulnerability database 149. For example, vulnerability optimization module 150 may generate and transmit vulnerability report 106 to business units 122a-n based on tagged vulnerabilities 157. Vulnerability report 106 may be customized to include specific information regarding identified vulnerabilities 104 affecting the applications administered by individual business units (e.g., business unit 122a), or it may be generalized to produce information regarding identified vulnerabilities 104 affecting the entire enterprise.”).
(Bang, Paragraph [0008], “FIG. 2 is a screenshot illustrating an embodiment of a vulnerability report including charted data;”).
As Per Claims 8-14: Claims 8-14 are substantially a restatement of the method of claims 1-7 as a system and are rejected under substantially the same reasoning.
As Per Claims 15-17: Claims 15-17 are substantially a restatement of the method of claims 1, 4, and 7 as a non-transitory computer-readable medium and are rejected under substantially the same reasoning.
Additional Prior Art
United States Patent Application Publication No.: US 2021/0034602 A1 (LEVACHER et al.) and United States Patent No.: US 10,401,810 B2 (Guthrie et al.) provide additional teaching in assessing and managing vulnerability exposure.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN A KAPLAN whose telephone number is (571)270-3170. The examiner can normally be reached 9:00 a.m. - 5:00 p.m..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kambiz Zand can be reached at (571)272-3811. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BENJAMIN A KAPLAN/Examiner, Art Unit 2434