DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 have been examined.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 8/27/26 is being considered by the examiner.
Response to Arguments
Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 11-13 and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. U.S. 2024/0143788 (hereinafter Chen) in view of Raghavendran et al. U.S. 11,436,127 (hereinafter Raghavendran).
As per claim 1, 11 and 16, Chen discloses a method/system for certifying a level of security vulnerability of a software application from a developer prior to acquisition of the software application by an organization (Chen: Abstract: perform risk assessment of applications), the method/system comprising non-transitory storage device, processor and software security management application to perform the steps of:
selecting a security vulnerability test to be performed on the software application (Chen: [0073]-[0075] and [0080]: determine tests to be performed based on security requirements);
selecting an additional test to be performed on the software application (Chen: [0075]: update, remove or add security requirement over time);
setting, an acceptable level of security vulnerability for the software application as determined by the security vulnerability test (Chen: [0027]: allowance indicator; [0084]: determine scope of evaluation);
selecting a tester to perform the security vulnerability test (Chen: [0087]-[0092]);
the tester performing the security vulnerability test on the software application (Chen: [0082]-[0092]: testing computer evaluates software based on security test requirements);
the tester providing to the developer a full test report of results of the testing including a determined level of security vulnerability of the software application (Chen: [0025]: security evaluation report containing specific tests and rules); and
when the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, the tester providing a certification report including verification that the security vulnerability test was performed and that the determined level of security vulnerability is equal to or is less than the acceptable level of security vulnerability, the certification report excluding disclosure of any security vulnerabilities discovered during performance of the security vulnerability test (Chen: [0026] and [0051]: security evaluation summary include brief statement of the main outcome of a security evaluation to indicate whether a development computer can proceed with distributing the evaluated software modules).
Chen discloses that developer can submit request to have software/application evaluated. Chen does not explicitly disclose submitting software certification request by organization or software acquirer to be evaluated by third party tester that is distinct from both the developer and the organization, and providing a list of the security vulnerability test to be performed, information to be included in a full test report to the developer and information to be included in a certification report to the organization. However, Raghavendran discloses automated validation and authentication of software module wherein consumer of a software requests an independent third party testing entity to validate a software module from a producer of the software module (Raghavendran: Abstract; col. 2 lines 25-52: requesting independent third party tester to validate software based on various criteria, including security requirement; Fig. 6 and col. 6 line 54 – col. 7 line 26: operations performed by testing entity based on software module and parameters/attributes requested by consumer and producer). It would have been obvious to one having ordinary skill in the art to combine the teachings of Raghavendran and Chen because they are in the same field of endeavor of software/application testing. The motivation to combine would be to offer neutral attestation/certification of software applications instead of reliance on developer’s self-attestation of compliance.
As per claim 2, 12 and 17, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified further discloses wherein the full test report includes details of all security vulnerabilities discovered during performance of the security vulnerability test (Chen: [0022]: pre-release report that provides rich feedback to application developer to make application more secure, reliable, efficient and performant; [0025]: security evaluation report shows how application performed in security assessment; Raghavendran: col. 7 lines 15-26).
As per claim 3, 13 and 18, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified further discloses wherein the security vulnerability test is a dynamic application security test or an interactive application security test (Chen: [0086]-[0090]).
Claims 4-10, 14, 15, 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Raghavendran and further in view of Dongle et al. U.S. 2025/0139252 (hereinafter Dongle).
As per claim 4, 14 and 19, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified does not explicitly disclose when the determined level of security vulnerability exceeds the acceptable level of security vulnerability, the developer makes at least one change to the software application and the method returns to the step of the tester performing the security vulnerability test. However, Dongle discloses providing vulnerability test result to developer to further improve the application for retesting (Dongle: Figs. 3-4; [0081]-[0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities.
As per claim 5, 15 and 20, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified does not explicitly disclose a step of selecting an additional test to be performed on the software application by the tester, the additional test being one of unit testing, dynamic application security testing, interactive application security testing, regression testing, integration testing, user acceptance testing, and performance testing. However, Dongle discloses performing additional vulnerability tests and iteratively improve and retest (Dongle: [0083]; [0090]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities.
As per claim 6, Chen as modified discloses the method according to Claim 5. Chen as modified does not explicitly disclose when the results of the testing indicate that the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, performing the additional test on the software application and including results of the additional test in the full test report. However, Dongle discloses performing additional vulnerability tests and iteratively improve and retest (Dongle: Figs. 3-4; [0081]-0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities.
As per claim 7, Chen as modified discloses the method according to Claim 1. Chen as modified does not explicitly disclose a step of selecting additional tests to be performed on the software application by the tester and, when the results of the testing indicate that the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, performing the additional tests on the software application and including results of the additional tests in the full test report (Dongle: Figs. 3-4; [0081]-0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities to meet required security level.
As per claim 8, Chen as modified discloses the method according to Claim 7. Chen as modified further discloses including after each of the additional tests is performed checking whether all of the additional tests were performed (Dongle: Figs. 3-4; [0081]-0084]). Same rationale applies here as above in rejecting claim 7.
As per claim 9, Chen as modified discloses the method according to Claim 7. Chen as modified further discloses when the results of the testing for each of the additional tests indicate that a determined level of security vulnerability equals or is less than an acceptable level of security vulnerability, including results of the additional test in the full test report and selecting another of the additional tests to be performed (Dongle: Figs. 3-4; [0081]-[0084]; [0090]). Same rationale applies here as above in rejecting claim 7.
As per claim 10, Chen as modified discloses the method according to Claim 9. Chen as modified further discloses wherein the certification report includes verification that the additional tests were performed and that the software application equals or is less than the acceptable level of security vulnerability for each of the additional tests (Chen: Figs. 3-4; [0081]-[0084]; [0090]). Same rationale applies here as above in rejecting claim 7 for iteratively testing and correct application vulnerability.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Kabir et al. U.S. 12,561,448 discloses method for simulating application breaches.
Gupta U.S. 9,268,672 discloses automated test case generation for applications using third party application tester.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHIN-HON (ERIC) CHEN/ Primary Examiner, Art Unit 2431