Prosecution Insights
Last updated: August 06, 2026
Application No. 19/075,530

Methods and Systems for Forecasting Subsequent Computer System Log Events Based on Analysis of Historical Log Data

Non-Final OA §103
Filed
Mar 10, 2025
Priority
Mar 15, 2024 — provisional 63/566,103
Examiner
HOLLISTER, JAMES ROSS
Art Unit
Tech Center
Assignee
Pre Security Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
168 granted / 222 resolved
+15.7% vs TC avg
Strong +25% interview lift
Without
With
+24.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
7 currently pending
Career history
235
Total Applications
across all art units

Statute-Specific Performance

§101
18.7%
-21.3% vs TC avg
§103
53.9%
+13.9% vs TC avg
§102
10.5%
-29.5% vs TC avg
§112
11.0%
-29.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 222 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Summary This action is a responsive to the application filed on 3/10/2025. Claims 1-20 are pending and have been examined. Claims 1-20 are rejected. Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description: 314, 400. Corrected drawing sheets in compliance with 37 CFR 1.121(d), or amendment to the specification to add the reference character(s) in the description in compliance with 37 CFR 1.121(b) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-8, 11-13, 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Weber et al. (US 20230038671 A1) and further in view of Pickman et al. (US 20250117486 A1). As to claim 1, Weber et al. teaches A computer implemented method of intelligently predicting cybersecurity events for preemptive cybersecurity defense mechanisms, comprising: receiving cybersecurity alert log data from a plurality of sources, the cybersecurity alert log data being from a plurality of time-sequenced events (See ¶¶ [0074], [0076], [0080], Teaches that S210, which includes identifying alerts and/or events, may function to identify inbound alerts and/or events collected from one or more data sources. In one or more preferred embodiments, the system 100 and/or the method 200 may identify inbound alerts and/or events by collecting and/or receiving alert and/or event data from one or more data sources in real-time or near real-time to initiate fast-processing of the inbounds alerts and/or events (e.g., recently identified cybersecurity alerts, recently identified cybersecurity events, etc.).); transforming the cybersecurity alert log data from the plurality of sources using natural language processing into multi-dimensional alert signatures, the multi- dimensional alert signatures standardizing the cybersecurity alert log data from the plurality of sources (See ¶¶ [0022], [0043], [0046], [0057], [0059]-[0060] Teaches that In one or more embodiments, an n-dimensional space may include one or more vector representations generated based on distinct alert data, one or more vector representations generated based on distinct event data, and/or one or more vector representations generated based on both event data and alert data associated with the event data. Therefore, for ease of description in the remainder of this disclosure a vector representation mapped to an alert space (e.g., n-dimensional space) may generally be referred to and treated as an “alert vector,” “an alert vector representation,” “an alert hash signature,” “a cybersecurity hash signature,” or “an alert embedding” irrespective of if the alert vector representation was generated based on alert data, event data, or a combination of both alert and event data. In one or more embodiments, S205 may function to construct an n-dimensional space (hereafter referred to as an “alert space”) in a variety of modes based on a preferred deployment (or utilization) of a system 100 and/or the method 200. For instance, in one embodiment, S205 may function to construct a global alert space based on identifying corpora of alert/event data from a plurality of distinct subscribers. In such embodiments, a global alert space may be constructed that may include historical alert data or historical event data from a plurality of distinct subscribers in a single alert space (or repository). In other words, each of the alert vector representations stored in and/or mapped to the global alert space may be used as a primary evaluation source for recently identified inbound alerts or recently identified events from a plurality of subscribers (e.g., the global alert space may be subscriber agnostic when evaluating for historical alert vectors substantially similar to a target alert vector).); sorting the multi-dimensional alert signatures into a plurality of cosine similarity buckets (See ¶¶ [0055-56], [0060-61], [0105], Teaches that the artifact-similarity search module 150 may function to receive, as input, the distinct vector representation corresponding to the inbound cybersecurity artifact and construct an artifact-similarity search query that may include the distinct vector representation as a search parameter. In one or more embodiments, the artifact-similarity search query, when executed, may be used to search one or more vectorization databases (or alert spaces) 155 to identify one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 that may be homogenous, substantially similar or equivalent to the distinct vector representation corresponding to the inbound cybersecurity artifact, if any. In one or more embodiments, the artifact-similarity handling engine 160 may function to receive the distinct vector representation corresponding to the inbound cybersecurity artifact and/or the one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 to generate one or more proposed handling actions (e.g., one or more mitigation or disposal actions) for the inbound cybersecurity artifact, as described in more detail herein.); vectorizing the plurality of cosine similarity buckets into vectorized buckets of numerical values (See ¶¶ [0092]-[0093], Teaches that In a first implementation, an alert hash value or an alert hash signature may be generated for an abridged alert digest associated with a target inbound alert based on using a MinHash hashing algorithm. In such implementation, the MinHash hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of integers or bits of a fixed length vector size (e.g., 128/256, etc.). In one or more embodiments of the first implementation, via a cybersecurity event hashing algorithm, S220 may function to compute one or more hash value for each token of the (abridged) alert digest. For instance, in a non-limiting example, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a MinHash hashing algorithm to generate an alert hash signature (with bit width), such as, [0, 1, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or a distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through a MinHash hashing algorithm (e.g., cybersecurity hashing algorithm). In a second implementation, an alert hash value or alert hash signature may be generated based on using a token-frequency hashing algorithm. In such implementation, the token-frequency hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of bits or integers of a fixed length vector size (e.g., 128/256) based on token frequency. For instance, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a token-frequency hashing algorithm to generate an alert hash signature, such as, [0, 0, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through the token-frequency hashing algorithm.); storing the vectorized buckets in a vector database with corresponding metadata (See ¶ [0070], Teaches that the one or more alert spaces may be an alert database in which each distinct intelligent text sequence (e.g., each abridged alert digest, each abridged event digest, etc.) for each piece of alert data or event data of one or more corpora of alert data may be associated with an alert hash signature and/or an alert embedding value that may be digitally stored in the alert database and electronically accessible to a system (e.g., the system 100 implementing the method 200). That is, in some embodiments, each (distinct) piece of alert or event data of the one or more corpora of alert/event data may be associated with both a corresponding hash signature and a corresponding embedding value. In such embodiments, any suitable search technique, such as regular expression with or without Boolean logic, k-nearest neighbors (kNN), approximate nearest neighbors (ANN) may be implemented for performing alert similarity detection.). However, it does not expressly teach the details of training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model; validating the predicting cybersecurity events model using testing datasets; dynamically updating the predicting cybersecurity events model based on the validating; and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model. Pickman et al., from analogous art, teaches training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); validating the predicting cybersecurity events model using testing datasets (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); dynamically updating the predicting cybersecurity events model based on the validating (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model (See ¶ [0140], Teaches that The AI classifiers can be part of the assessment component, which scores the outputs of the analyzer module. Again, as for the other AI classifiers discussed, the AI classifier can be coded to take in multiple pieces of information about an entity, object, and/or thing and based on its training and then output a prediction about the entity, object, or thing. Given one or more inputs, the AI classifier model will try to predict the value of one or more outcomes. The AI classifiers cooperate with the range of data analysis processes that produce features for the AI classifiers. The various techniques cooperating here allow anomaly detection and assessment of a cyber threat level posed by a given anomaly; but more importantly, an overall cyber threat level posed by a series/chain of correlated anomalies under analysis.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into Weber et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 2, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. Weber et al. further teaches wherein the transforming the cybersecurity alert log data from the plurality of sources applies a predefined template for generating the multi- dimensional alert signatures (See ¶¶ [0022], [0043], [0046], [0057], [0059]-[0060] Teaches that In one or more embodiments, an n-dimensional space may include one or more vector representations generated based on distinct alert data, one or more vector representations generated based on distinct event data, and/or one or more vector representations generated based on both event data and alert data associated with the event data.). As to claim 3, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the predicting cybersecurity events for preemptive cyber defense executes a cosine similarity analysis on the vectorized buckets of numerical values with the corresponding metadata. Pickman et al., from analogous art, teaches wherein the predicting cybersecurity events for preemptive cyber defense executes a cosine similarity analysis on the vectorized buckets of numerical values with the corresponding metadata (See ¶ [0252], Teaches that The vector embeddings derived from the text data observed over a specified time period may be stored in a memory accessible to the query worker so that the query worker can look up/identify (at block 1914) which cluster, of the set of clusters, the received portion of text data belongs to. The train worker updates the set of clusters that are used by the query worker to identify which cluster a particular portion of text data can be considered to belong to. The searching may be based on a similarity search such as a cosine similarity search or hierarchical navigable smallest world (HNSW) searching performed on the vector embeddings associated with the user. HNSW searching may be more efficient at identifying which cluster a particular portion of text belongs to.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 4, the combination of Weber et al. and Pickman et al. teaches the method according to claim 3 above. However, it does not expressly teach the details of wherein the cosine similarity analysis generates a plurality of cybersecurity alert log categories. Pickman et al., from analogous art, teaches wherein the cosine similarity analysis generates a plurality of cybersecurity alert log categories (See ¶¶ [0091], [0252] Teaches that trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats. Later, when in deployment in a domain/network being protected by the cyber security appliance 100, the AI model trained on cyber threats can determine whether a potentially unknown threat has been detected via a number of techniques including an overlap of some of the same characteristics and attributes in that category of cyber threats. The AI model may use unsupervised learning when deployed to better learn newer and updated characteristics of cyberattacks. The vector embeddings derived from the text data observed over a specified time period may be stored in a memory accessible to the query worker so that the query worker can look up/identify (at block 1914) which cluster, of the set of clusters, the received portion of text data belongs to. The train worker updates the set of clusters that are used by the query worker to identify which cluster a particular portion of text data can be considered to belong to. The searching may be based on a similarity search such as a cosine similarity search or hierarchical navigable smallest world (HNSW) searching performed on the vector embeddings associated with the user. HNSW searching may be more efficient at identifying which cluster a particular portion of text belongs to.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 5, the combination of Weber et al. and Pickman et al. teaches the method according to claim 4 above. However, it does not expressly teach further comprising categorizing the plurality of cybersecurity alert log categories, using a machine learning engine, into predefined cybersecurity threat categories. Pickman et al., from analogous art, teaches further comprising categorizing the plurality of cybersecurity alert log categories, using a machine learning engine, into predefined cybersecurity threat categories (See ¶ [0255], Teaches that a behavior metric such as an anomaly score (indicative of how anomalous the data appears to be compared to a previous pattern of life for the user) or a rarity score (indicative of how rare the data appears to be compared to a previous pattern of life for the user) can be created based on changes in behavior associated with the user that have been observed over time. For example, two periods of time (that may or may not overlap) may be compared to determine whether or not there has been a change in the text types associated with a particular user. A threshold may be specified (e.g., by a security team or otherwise specified by the cyber security system) whereby if a certain number or relative ratio of counts of one or more types of text (i.e., one or more clusters) are observed for a particular user, this can be flagged to the security team for further analysis, or even to an autonomous response engine to form an appropriate automated response. For example, if a user performing a customer service function sends emails including a financial report, this could be immediately flagged. However, such emails may not be unusual for a user such as a finance director, and so such emails may not be flagged.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 6, the combination of Weber et al. and Pickman et al. teaches the method according to claim 5 above. Weber et al. further teaches wherein the metadata comprises: cybersecurity alert log data metadata, the cybersecurity alert log data metadata being from the cybersecurity alert log data from the plurality of sources, and multi-dimensional alert signatures metadata, the multi-dimensional alert signatures metadata being from the multi-dimensional alert signatures (See ¶ [0070], Teaches that the one or more alert spaces may be an alert database in which each distinct intelligent text sequence (e.g., each abridged alert digest, each abridged event digest, etc.) for each piece of alert data or event data of one or more corpora of alert data may be associated with an alert hash signature and/or an alert embedding value that may be digitally stored in the alert database and electronically accessible to a system (e.g., the system 100 implementing the method 200). That is, in some embodiments, each (distinct) piece of alert or event data of the one or more corpora of alert/event data may be associated with both a corresponding hash signature and a corresponding embedding value. In such embodiments, any suitable search technique, such as regular expression with or without Boolean logic, k-nearest neighbors (kNN), approximate nearest neighbors (ANN) may be implemented for performing alert similarity detection.). As to claim 7, the combination of Weber et al. and Pickman et al. teaches the method according to claim 6 above. Weber et al. further teaches wherein the cybersecurity alert log data metadata comprises event timestamps of the time-sequenced events (See ¶ [0089], Teaches that In the same or another non-limiting example, an inbound alert may include time stamp metadata and file path metadata such as “2021 Dec. 13T00:45:31+00:00/users/john/documents/projects” and, in some embodiments, S220 may function to not include the time stamp metadata feature and/or generalize or abstract the file path metadata (in the abridged alert digest) as “/users/<user>/documents/projects.” It shall be noted that abstracting or generalizing non-informative alert metadata features may prevent misidentifying similar (or homogenous) alert representations of the one or more alert spaces contributed to overly specific alert metadata features included in the abridged alert digest (e.g., text-based cybersecurity event digest).). As to claim 8, the combination of Weber et al. and Pickman et al. teaches the method according to claim 7 above. Weber et al. further teaches further comprising temporal sequencing the plurality of cybersecurity alert log categories using the event timestamps of the time-sequenced events, the temporal sequencing the plurality of cybersecurity alert log categories generating a historical pattern of cyber cybersecurity incidents for the predicting cybersecurity events model (See ¶¶ [0071]-[0073], Teaches that each distinct hash signature generated for each piece of alert and/or event data may be associated with a decay value that may change or reduce over time according to a decay rate. Accordingly, in such embodiments, the decay rate may reduce the evidentiary value of a given hash signature within an alert space as time passes. For instance, a first (cybersecurity) hash signature (in an alert space) may have a decay value greater (e.g., decaying faster) than a second (cybersecurity) hash signature (in the same alert space), as the first hash signature may have appeared in the alert space earlier in time than the second hash signature. ). As to claim 11, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach wherein the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model generates a probability score for each predicted cybersecurity event. Pickman et al., from analogous art, teaches wherein the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model generates a probability score for each predicted cybersecurity event (See ¶¶ [0136]-[0137], Teaches that The assessment module with the AI classifiers cooperates with the one or more AI models trained on possible cyber threats in order to assign a numerical assessment of a given cyber threat hypothesis that was found likely to be supported by the analyzer module with the one or more data analysis processes, via the abnormal behavior, the suspicious activity, or the collection of system data points. The assessment module with the AI classifiers output can be a score (ranked number system, probability, etc.) that a given identified process is likely a malicious process. The assessment module with the AI classifiers can be configured to assign a numerical assessment, such as a probability, of a given cyber threat hypothesis that is supported and a threat level posed by that cyber threat hypothesis which was found likely to be supported by the analyzer module, which includes the abnormal behavior or suspicious activity as well as one or more of the collection of system data points, with the one or more AI models trained on possible cyber threats.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 12, the combination of Weber et al. and Pickman et al. teaches the method according to claim 11 above. However, it does not expressly teach further comprising ranking predicted cybersecurity events using the probability score for each predicted cybersecurity event, the ranking prioritizing the predicted cybersecurity events based on a likelihood of occurrence of each of the predicted cybersecurity events. Pickman et al., from analogous art, teaches further comprising ranking predicted cybersecurity events using the probability score for each predicted cybersecurity event, the ranking prioritizing the predicted cybersecurity events based on a likelihood of occurrence of each of the predicted cybersecurity events (See ¶¶ [0136]-[0137], Teaches that The assessment module with the AI classifiers cooperates with the one or more AI models trained on possible cyber threats in order to assign a numerical assessment of a given cyber threat hypothesis that was found likely to be supported by the analyzer module with the one or more data analysis processes, via the abnormal behavior, the suspicious activity, or the collection of system data points. The assessment module with the AI classifiers output can be a score (ranked number system, probability, etc.) that a given identified process is likely a malicious process. The assessment module with the AI classifiers can be configured to assign a numerical assessment, such as a probability, of a given cyber threat hypothesis that is supported and a threat level posed by that cyber threat hypothesis which was found likely to be supported by the analyzer module, which includes the abnormal behavior or suspicious activity as well as one or more of the collection of system data points, with the one or more AI models trained on possible cyber threats.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 13, the combination of Weber et al. and Pickman et al. teaches the method according to claim 12 above. However, it does not expressly teach wherein the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model comprises generating a cybersecurity report for an entity, the cybersecurity report for the entity being based on the ranking the predicted cybersecurity events. Pickman et al., from analogous art, teaches wherein the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model comprises generating a cybersecurity report for an entity, the cybersecurity report for the entity being based on the ranking the predicted cybersecurity events (See ¶¶ [0136]-[0137], Teaches that The assessment module with the AI classifiers cooperates with the one or more AI models trained on possible cyber threats in order to assign a numerical assessment of a given cyber threat hypothesis that was found likely to be supported by the analyzer module with the one or more data analysis processes, via the abnormal behavior, the suspicious activity, or the collection of system data points. The assessment module with the AI classifiers output can be a score (ranked number system, probability, etc.) that a given identified process is likely a malicious process. The assessment module with the AI classifiers can be configured to assign a numerical assessment, such as a probability, of a given cyber threat hypothesis that is supported and a threat level posed by that cyber threat hypothesis which was found likely to be supported by the analyzer module, which includes the abnormal behavior or suspicious activity as well as one or more of the collection of system data points, with the one or more AI models trained on possible cyber threats.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 15, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach further comprising automatically responding to a predicted cybersecurity event using a security orchestration, automation and response platform, the predicted cybersecurity event being based on the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model. Pickman et al., from analogous art, teaches further comprising automatically responding to a predicted cybersecurity event using a security orchestration, automation and response platform, the predicted cybersecurity event being based on the predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model (See ¶¶ [0083]-[0084], Teaches that In an example, the autonomous response engine uses its intelligence to cooperate with a cyber threat prediction engine and its Artificial Intelligence-based simulations to choose and initiate an initial set of one or more mitigation actions indicated as a preferred targeted initial response to the detected cyber threat by autonomously initiating those mitigation actions to defend against the detected cyber threat, rather than a human taking an action. The autonomous response engine, rather than the human taking the action, is configured to autonomously cause the one or more mitigation actions to be taken to contain the cyber threat when a threat risk parameter from an assessment module in the detection engine is equal to or above an actionable threshold. Example mitigation actions can include 1) the autonomous response engine monitoring and sending signals to a potentially compromised node to restrict communications of the potentially compromised node to merely normal recipients and types of communications according to the Artificial Intelligence model trained to model the normal pattern of life for each node in the protected system, 2) the autonomous response engine trained on how to isolate a compromised node as well as to take mitigation acts with other nodes that have a direct nexus to the compromised node..). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 16, Weber et al. teaches A system for intelligently predicting cybersecurity events for preemptive cybersecurity defense mechanisms, comprising: at least one processor; and a memory storing processor-executable instructions, wherein the at least one processor is configured to implement the following operations upon executing the processor-executable instructions: receiving cybersecurity alert log data from a plurality of sources, the cybersecurity alert log data being from a plurality of time-sequenced events (See ¶¶ [0074], [0076], [0080], Teaches that S210, which includes identifying alerts and/or events, may function to identify inbound alerts and/or events collected from one or more data sources. In one or more preferred embodiments, the system 100 and/or the method 200 may identify inbound alerts and/or events by collecting and/or receiving alert and/or event data from one or more data sources in real-time or near real-time to initiate fast-processing of the inbounds alerts and/or events (e.g., recently identified cybersecurity alerts, recently identified cybersecurity events, etc.).); transforming the cybersecurity alert log data from the plurality of sources using natural language processing into multi-dimensional alert signatures, the multi-dimensional alert signatures standardizing the cybersecurity alert log data from the plurality of sources (See ¶¶ [0022], [0043], [0046], [0057], [0059]-[0060] Teaches that In one or more embodiments, an n-dimensional space may include one or more vector representations generated based on distinct alert data, one or more vector representations generated based on distinct event data, and/or one or more vector representations generated based on both event data and alert data associated with the event data. Therefore, for ease of description in the remainder of this disclosure a vector representation mapped to an alert space (e.g., n-dimensional space) may generally be referred to and treated as an “alert vector,” “an alert vector representation,” “an alert hash signature,” “a cybersecurity hash signature,” or “an alert embedding” irrespective of if the alert vector representation was generated based on alert data, event data, or a combination of both alert and event data. In one or more embodiments, S205 may function to construct an n-dimensional space (hereafter referred to as an “alert space”) in a variety of modes based on a preferred deployment (or utilization) of a system 100 and/or the method 200. For instance, in one embodiment, S205 may function to construct a global alert space based on identifying corpora of alert/event data from a plurality of distinct subscribers. In such embodiments, a global alert space may be constructed that may include historical alert data or historical event data from a plurality of distinct subscribers in a single alert space (or repository). In other words, each of the alert vector representations stored in and/or mapped to the global alert space may be used as a primary evaluation source for recently identified inbound alerts or recently identified events from a plurality of subscribers (e.g., the global alert space may be subscriber agnostic when evaluating for historical alert vectors substantially similar to a target alert vector).); sorting the multi-dimensional alert signatures into a plurality of cosine similarity buckets (See ¶¶ [0055-56], [0060-61], [0105], Teaches that the artifact-similarity search module 150 may function to receive, as input, the distinct vector representation corresponding to the inbound cybersecurity artifact and construct an artifact-similarity search query that may include the distinct vector representation as a search parameter. In one or more embodiments, the artifact-similarity search query, when executed, may be used to search one or more vectorization databases (or alert spaces) 155 to identify one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 that may be homogenous, substantially similar or equivalent to the distinct vector representation corresponding to the inbound cybersecurity artifact, if any. In one or more embodiments, the artifact-similarity handling engine 160 may function to receive the distinct vector representation corresponding to the inbound cybersecurity artifact and/or the one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 to generate one or more proposed handling actions (e.g., one or more mitigation or disposal actions) for the inbound cybersecurity artifact, as described in more detail herein.); vectorizing the plurality of cosine similarity buckets into vectorized buckets of numerical values (See ¶¶ [0092]-[0093], Teaches that In a first implementation, an alert hash value or an alert hash signature may be generated for an abridged alert digest associated with a target inbound alert based on using a MinHash hashing algorithm. In such implementation, the MinHash hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of integers or bits of a fixed length vector size (e.g., 128/256, etc.). In one or more embodiments of the first implementation, via a cybersecurity event hashing algorithm, S220 may function to compute one or more hash value for each token of the (abridged) alert digest. For instance, in a non-limiting example, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a MinHash hashing algorithm to generate an alert hash signature (with bit width), such as, [0, 1, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or a distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through a MinHash hashing algorithm (e.g., cybersecurity hashing algorithm). In a second implementation, an alert hash value or alert hash signature may be generated based on using a token-frequency hashing algorithm. In such implementation, the token-frequency hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of bits or integers of a fixed length vector size (e.g., 128/256) based on token frequency. For instance, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a token-frequency hashing algorithm to generate an alert hash signature, such as, [0, 0, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through the token-frequency hashing algorithm.); storing the vectorized buckets in a vector database with corresponding metadata (See ¶ [0070], Teaches that the one or more alert spaces may be an alert database in which each distinct intelligent text sequence (e.g., each abridged alert digest, each abridged event digest, etc.) for each piece of alert data or event data of one or more corpora of alert data may be associated with an alert hash signature and/or an alert embedding value that may be digitally stored in the alert database and electronically accessible to a system (e.g., the system 100 implementing the method 200). That is, in some embodiments, each (distinct) piece of alert or event data of the one or more corpora of alert/event data may be associated with both a corresponding hash signature and a corresponding embedding value. In such embodiments, any suitable search technique, such as regular expression with or without Boolean logic, k-nearest neighbors (kNN), approximate nearest neighbors (ANN) may be implemented for performing alert similarity detection.). However, it does not expressly teach the details of training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model; validating the predicting cybersecurity events model using testing datasets; dynamically updating the predicting cybersecurity events model based on the validating; and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model. Pickman et al., from analogous art, teaches training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); validating the predicting cybersecurity events model using testing datasets (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); dynamically updating the predicting cybersecurity events model based on the validating (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model (See ¶ [0140], Teaches that The AI classifiers can be part of the assessment component, which scores the outputs of the analyzer module. Again, as for the other AI classifiers discussed, the AI classifier can be coded to take in multiple pieces of information about an entity, object, and/or thing and based on its training and then output a prediction about the entity, object, or thing. Given one or more inputs, the AI classifier model will try to predict the value of one or more outcomes. The AI classifiers cooperate with the range of data analysis processes that produce features for the AI classifiers. The various techniques cooperating here allow anomaly detection and assessment of a cyber threat level posed by a given anomaly; but more importantly, an overall cyber threat level posed by a series/chain of correlated anomalies under analysis.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into Weber et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 17, the combination of Weber et al. and Pickman et al. teaches the system according to claim 16 above. However, it does not expressly teach the details of wherein the predicting cybersecurity events for preemptive cyber defense executes a cosine similarity analysis on the vectorized buckets of numerical values with the corresponding metadata. Pickman et al., from analogous art, teaches wherein the predicting cybersecurity events for preemptive cyber defense executes a cosine similarity analysis on the vectorized buckets of numerical values with the corresponding metadata (See ¶ [0252], Teaches that The vector embeddings derived from the text data observed over a specified time period may be stored in a memory accessible to the query worker so that the query worker can look up/identify (at block 1914) which cluster, of the set of clusters, the received portion of text data belongs to. The train worker updates the set of clusters that are used by the query worker to identify which cluster a particular portion of text data can be considered to belong to. The searching may be based on a similarity search such as a cosine similarity search or hierarchical navigable smallest world (HNSW) searching performed on the vector embeddings associated with the user. HNSW searching may be more efficient at identifying which cluster a particular portion of text belongs to.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 18, the combination of Weber et al. and Pickman et al. teaches the system according to claim 17 above. However, it does not expressly teach the details of wherein the cosine similarity analysis generates a plurality of cybersecurity alert log categories. Pickman et al., from analogous art, teaches wherein the cosine similarity analysis generates a plurality of cybersecurity alert log categories (See ¶¶ [0091], [0252] Teaches that trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats. Later, when in deployment in a domain/network being protected by the cyber security appliance 100, the AI model trained on cyber threats can determine whether a potentially unknown threat has been detected via a number of techniques including an overlap of some of the same characteristics and attributes in that category of cyber threats. The AI model may use unsupervised learning when deployed to better learn newer and updated characteristics of cyberattacks. The vector embeddings derived from the text data observed over a specified time period may be stored in a memory accessible to the query worker so that the query worker can look up/identify (at block 1914) which cluster, of the set of clusters, the received portion of text data belongs to. The train worker updates the set of clusters that are used by the query worker to identify which cluster a particular portion of text data can be considered to belong to. The searching may be based on a similarity search such as a cosine similarity search or hierarchical navigable smallest world (HNSW) searching performed on the vector embeddings associated with the user. HNSW searching may be more efficient at identifying which cluster a particular portion of text belongs to.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 19, the combination of Weber et al. and Pickman et al. teaches the system according to claim 18 above. However, it does not expressly teach further comprising categorizing the plurality of cybersecurity alert log categories, using a machine learning engine, into predefined cybersecurity threat categories. Pickman et al., from analogous art, teaches further comprising categorizing the plurality of cybersecurity alert log categories, using a machine learning engine, into predefined cybersecurity threat categories (See ¶ [0255], Teaches that a behavior metric such as an anomaly score (indicative of how anomalous the data appears to be compared to a previous pattern of life for the user) or a rarity score (indicative of how rare the data appears to be compared to a previous pattern of life for the user) can be created based on changes in behavior associated with the user that have been observed over time. For example, two periods of time (that may or may not overlap) may be compared to determine whether or not there has been a change in the text types associated with a particular user. A threshold may be specified (e.g., by a security team or otherwise specified by the cyber security system) whereby if a certain number or relative ratio of counts of one or more types of text (i.e., one or more clusters) are observed for a particular user, this can be flagged to the security team for further analysis, or even to an autonomous response engine to form an appropriate automated response. For example, if a user performing a customer service function sends emails including a financial report, this could be immediately flagged. However, such emails may not be unusual for a user such as a finance director, and so such emails may not be flagged.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into the combination of Weber et al. and Pickman et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). As to claim 20, Weber et al. teaches A non-transitory computer-readable storage medium having embodied thereon instructions, which when executed by at least one processor, perform operations of a method comprising: receiving cybersecurity alert log data from a plurality of sources, the cybersecurity alert log data being from a plurality of time-sequenced events (See ¶¶ [0074], [0076], [0080], Teaches that S210, which includes identifying alerts and/or events, may function to identify inbound alerts and/or events collected from one or more data sources. In one or more preferred embodiments, the system 100 and/or the method 200 may identify inbound alerts and/or events by collecting and/or receiving alert and/or event data from one or more data sources in real-time or near real-time to initiate fast-processing of the inbounds alerts and/or events (e.g., recently identified cybersecurity alerts, recently identified cybersecurity events, etc.).); transforming the cybersecurity alert log data from the plurality of sources using natural language processing into multi-dimensional alert signatures, the multi- dimensional alert signatures standardizing the cybersecurity alert log data from the plurality of sources (See ¶¶ [0022], [0043], [0046], [0057], [0059]-[0060] Teaches that In one or more embodiments, an n-dimensional space may include one or more vector representations generated based on distinct alert data, one or more vector representations generated based on distinct event data, and/or one or more vector representations generated based on both event data and alert data associated with the event data. Therefore, for ease of description in the remainder of this disclosure a vector representation mapped to an alert space (e.g., n-dimensional space) may generally be referred to and treated as an “alert vector,” “an alert vector representation,” “an alert hash signature,” “a cybersecurity hash signature,” or “an alert embedding” irrespective of if the alert vector representation was generated based on alert data, event data, or a combination of both alert and event data. In one or more embodiments, S205 may function to construct an n-dimensional space (hereafter referred to as an “alert space”) in a variety of modes based on a preferred deployment (or utilization) of a system 100 and/or the method 200. For instance, in one embodiment, S205 may function to construct a global alert space based on identifying corpora of alert/event data from a plurality of distinct subscribers. In such embodiments, a global alert space may be constructed that may include historical alert data or historical event data from a plurality of distinct subscribers in a single alert space (or repository). In other words, each of the alert vector representations stored in and/or mapped to the global alert space may be used as a primary evaluation source for recently identified inbound alerts or recently identified events from a plurality of subscribers (e.g., the global alert space may be subscriber agnostic when evaluating for historical alert vectors substantially similar to a target alert vector).); sorting the multi-dimensional alert signatures into a plurality of cosine similarity buckets (See ¶¶ [0055-56], [0060-61], [0105], Teaches that the artifact-similarity search module 150 may function to receive, as input, the distinct vector representation corresponding to the inbound cybersecurity artifact and construct an artifact-similarity search query that may include the distinct vector representation as a search parameter. In one or more embodiments, the artifact-similarity search query, when executed, may be used to search one or more vectorization databases (or alert spaces) 155 to identify one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 that may be homogenous, substantially similar or equivalent to the distinct vector representation corresponding to the inbound cybersecurity artifact, if any. In one or more embodiments, the artifact-similarity handling engine 160 may function to receive the distinct vector representation corresponding to the inbound cybersecurity artifact and/or the one or more (probable) vector signatures or vector representations of the one or more vectorization databases (or alert spaces) 155 to generate one or more proposed handling actions (e.g., one or more mitigation or disposal actions) for the inbound cybersecurity artifact, as described in more detail herein.); vectorizing the plurality of cosine similarity buckets into vectorized buckets of numerical values (See ¶¶ [0092]-[0093], Teaches that In a first implementation, an alert hash value or an alert hash signature may be generated for an abridged alert digest associated with a target inbound alert based on using a MinHash hashing algorithm. In such implementation, the MinHash hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of integers or bits of a fixed length vector size (e.g., 128/256, etc.). In one or more embodiments of the first implementation, via a cybersecurity event hashing algorithm, S220 may function to compute one or more hash value for each token of the (abridged) alert digest. For instance, in a non-limiting example, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a MinHash hashing algorithm to generate an alert hash signature (with bit width), such as, [0, 1, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or a distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through a MinHash hashing algorithm (e.g., cybersecurity hashing algorithm). In a second implementation, an alert hash value or alert hash signature may be generated based on using a token-frequency hashing algorithm. In such implementation, the token-frequency hashing algorithm may function to approximate a target abridged alert digest associated with an inbound alert as a vector of bits or integers of a fixed length vector size (e.g., 128/256) based on token frequency. For instance, an abridged alert digest of an inbound alert, such as, “7744 US android_emm_uem company.com comcast cable communications inc isp users company.com us” may be passed through a token-frequency hashing algorithm to generate an alert hash signature, such as, [0, 0, 1, 0, 1, . . . , 1, 1]. It shall be noted that a distinct hash value or distinct hash signature may be generated for each abridged alert digest of each inbound alert by passing each abridged alert digest through the token-frequency hashing algorithm.); storing the vectorized buckets in a vector database with corresponding metadata (See ¶ [0070], Teaches that the one or more alert spaces may be an alert database in which each distinct intelligent text sequence (e.g., each abridged alert digest, each abridged event digest, etc.) for each piece of alert data or event data of one or more corpora of alert data may be associated with an alert hash signature and/or an alert embedding value that may be digitally stored in the alert database and electronically accessible to a system (e.g., the system 100 implementing the method 200). That is, in some embodiments, each (distinct) piece of alert or event data of the one or more corpora of alert/event data may be associated with both a corresponding hash signature and a corresponding embedding value. In such embodiments, any suitable search technique, such as regular expression with or without Boolean logic, k-nearest neighbors (kNN), approximate nearest neighbors (ANN) may be implemented for performing alert similarity detection.). However, it does not expressly teach the details of training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model; validating the predicting cybersecurity events model using testing datasets; dynamically updating the predicting cybersecurity events model based on the validating; and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model. Pickman et al., from analogous art, teaches training datasets using the vectorized buckets of the numerical values, the training datasets generating a predicting cybersecurity events model (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); validating the predicting cybersecurity events model using testing datasets (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); dynamically updating the predicting cybersecurity events model based on the validating (See ¶ [0091], Teaches that an initial training of the Artificial Intelligence model trained on cyber threats can occur using unsupervised learning and/or supervised learning on characteristics and attributes of known potential cyber threats including malware, insider threats, and other kinds of cyber threats that can occur within that domain. Each Artificial Intelligence can be programmed and configured with the background information to understand and handle particulars, including different types of data, protocols used, types of devices, user accounts, etc. of the system being protected. The Artificial Intelligence pre-deployment can all be trained on the specific machine learning task that they will perform when put into deployment. For example, the AI model, such as AI model(s) 160 or example (hereinafter “AI model(s) 160”), trained on identifying a specific cyber threat learns at least both in the pre-deployment training i) the characteristics and attributes of known potential cyber threats as well as ii) a set of characteristics and attributes of each category of potential cyber threats and their weights assigned on how indicative certain characteristics and attributes correlate to potential cyber threats of that category of threats. In this example, one of the AI model(s) 160 trained on identifying a specific cyber threat can be trained with machine learning such as Linear Regression, Regression Trees, Non-Linear Regression, Bayesian Linear Regression, Deep learning, etc. to learn and understand the characteristics and attributes in that category of cyber threats.); and predicting cybersecurity events for preemptive cyber defense mechanisms using the predicting cybersecurity events model (See ¶ [0140], Teaches that The AI classifiers can be part of the assessment component, which scores the outputs of the analyzer module. Again, as for the other AI classifiers discussed, the AI classifier can be coded to take in multiple pieces of information about an entity, object, and/or thing and based on its training and then output a prediction about the entity, object, or thing. Given one or more inputs, the AI classifier model will try to predict the value of one or more outcomes. The AI classifiers cooperate with the range of data analysis processes that produce features for the AI classifiers. The various techniques cooperating here allow anomaly detection and assessment of a cyber threat level posed by a given anomaly; but more importantly, an overall cyber threat level posed by a series/chain of correlated anomalies under analysis.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Pickman et al. into Weber et al. in order to protect a system, such as one or more networks/domains under analysis, from cyber threats (See Pickman et al. ¶ [0048]). Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Weber et al. (US 20230038671 A1) and Pickman et al. (US 20250117486 A1) and further in view of DICHIU et al. (US 20200186544 A1). As to claim 9, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of further comprising arranging the vectorized buckets of numerical values into a temporal sequence based on timestamp metadata to establish a chronological pattern of cybersecurity events. DICHIU et al., from analogous art, teaches further comprising arranging the vectorized buckets of numerical values into a temporal sequence based on timestamp metadata to establish a chronological pattern of cybersecurity events (See ¶¶ [0066], Teaches that An exemplary sequence of steps implementing training of an event encoder is illustrated in FIG. 9. A step 222 retrieves a set of event records from event corpus 18 and identifies an event sequence 25 according to event timestamps and according to a source of the respective events (i.e., client systems where the respective events have occurred). In a skip-gram embodiment, a step 224 then executes event encoder 70a to produce an embedding-space representation of event E0 (event vector 28c in FIG. 8-A). In a step 226, profiling engine 60 executes event decoder 76a to produce a set of predictions or “guesses” for events preceding and/or following central event E0 within sequence 25. A step 228 compares each predicted context event with the respective actual context event Ei (i≠0) of sequence 25, thus determining a numerical prediction error. The prediction error, which may be interpreted as a cost function or an objective function, may be calculated according to any method known in the art of artificial intelligence. Such calculations may comprise determining a distance, for instance a Levenshtein, Euclidean, or cosine distance between the predicted and actual events. Some embodiments determine an objective function according to a cross entropy measure. In a step 230, profiling engine may adjust parameters of encoder 70a in the direction of minimizing the calculated prediction error. Some exemplary algorithms used for training include backpropagation using a gradient descent, simulated annealing, and genetic algorithms, among others. Some embodiments then repeat steps 222-230 until a termination condition is satisfied, for instance until the average prediction error over event corpus 18 drops below a pre-determined threshold. In another embodiment, training proceeds for a pre-determined amount of time, or for a pre-determined count of iterations. A skilled artisan will know that the sequence of steps illustrated in FIG. 9 is equally suited to a bag-of words embodiment (FIG. 8-B), with minor adaptations). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of DICHIU et al. into the combination of Weber et al. and Pickman et al. in order to automatically detect and/or prevent unauthorized intrusion and other malicious activities (See DICHIU et al. ¶ [0004]). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Weber et al. (US 20230038671 A1) and Pickman et al. (US 20250117486 A1) and further in view of McLean (US 20210273958 A1). As to claim 10, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the predicting cybersecurity events model comprises a Long Short-Term Memory (LSTM) neural network configured to analyze time- sequenced data for predicting future cybersecurity events. McLean, from analogous art, teaches wherein the predicting cybersecurity events model comprises a Long Short-Term Memory (LSTM) neural network configured to analyze time- sequenced data for predicting future cybersecurity events (See ¶¶ [0116], [0118], Teaches that The RNN detector may implement a bidirectional long short-term memory LSTM) recurrent neural network or the like, where such detector may accept an input of a parent chain and may output a vector of approximation of that chain for each possible chain that has been previously observed. Accordingly, such RNN detector may be used to provide relatively slow analysis and determinations but may detect very subtle anomalies that may analyze more details of how each process of that process chain is interacting with other processes and/or resources on that device. It should be understood that the third stage anomaly detector 513 may use one or more neural network processes/algorithms, including, but not limited to, deep learning neural network algorithms, feed forward neural networks, convolutional neural network (CNN), RNNs, perceptron algorithm, multilayer perceptrons (MLP) algorithms, back-propagation algorithms, stochastic gradient descent algorithms, Hopfield network algorithms, radial basis function network (RBFN) algorithms, LSTMs networks, stacked auto-encoders, deep Boltzmann machine (DBM), deep belief networks (DBN), as well as multiple type of transformer algorithms, and any other similar processes.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of McLean into the combination of Weber et al. and Pickman et al. in order to detect one or more potential cyber threats on an endpoint computing device (See McLean ¶ [0007]). Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Weber et al. (US 20230038671 A1) and Pickman et al. (US 20250117486 A1) and further in view of Razi et al. (US 20230222208 A1). As to claim 14, the combination of Weber et al. and Pickman et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the validating the predicting cybersecurity events model using testing datasets executes the predicting cybersecurity events model using a code execution sandbox, the code execution sandbox testing the predicting cybersecurity events model. Razi et al., from analogous art, teaches wherein the validating the predicting cybersecurity events model using testing datasets executes the predicting cybersecurity events model using a code execution sandbox, the code execution sandbox testing the predicting cybersecurity events model (See ¶ [0023], Teaches that In one embodiment, the sandbox engine 110 models runtime behavior of files using a graph network as shown in FIG. 3, for example. Parameters of GCN are adjusted from thousands of samples. Cross entropy loss is minimized to achieve the link prediction objective. The dotted lines show negative sample edges, where a link between nodes does not exist. In processes 500 and 600 of FIGS. 5 and 6, respectively, solid lines show steps required for both runtime link prediction and offline training, while the dotted lines show steps needed for offline training. Turning to FIG. 5, link prediction training phase of thousands of samples are used to adjust parameters of a GCN. Cross entropy loss is minimized in FIG. 6 to achieve the link prediction objective. Untagged files are received 510, and graphically received 520 for GCN recursive processing 530. In FIG. 6, a training set 610 is tagged as anomaly or normal 620. To do so, files are executed in a sandbox and behavior logs are modeled by graph. GCN is applied to get node embeddings of each graph. A dot product to node embeddings is applied to get link scores. Each score is compared against a preset threshold value to determine low-score links. Finally, low-score links are tagged as anomaly.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Razi et al. into the combination of Weber et al. and Pickman et al. in order to provide a safe and monitored environment to observe runtime behavior of software samples (See Razi et al. ¶ [0002]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. HEIMANN et al. (US 20200258004 A1) teaches To analyze cybersecurity threats, an analysis module of a processor may receive log data from at least one network node. The analysis module may identify at least one statistical outlier within the log data. The analysis module may determine that the at least one statistical outlier represents a cybersecurity threat by applying at least one machine learning algorithm to the at least one statistical outlier. Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Hollister whose telephone number is (571)270-3152. The examiner can normally be reached Mon - Fri 7:30 am - 4:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. James Hollister /J.R.H./Examiner, Art Unit 2499 7/11/26 /PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Mar 10, 2025
Application Filed
Jul 17, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701007
System, Method, and Computer Program Product for Third-Party Authorization
1y 9m to grant Granted Aug 04, 2026
Patent 12688276
SHARING CONTAINER DATA INSIDE A TENANT'S POD UNDER DIFFERENT TRUSTED EXECUTION ENVIRONMENTS (TEES)
3y 11m to grant Granted Jul 21, 2026
Patent 12689520
MULTI-PART TRANSACTION INTEGRITY PROTECTION AND ENCRYPTION
3y 0m to grant Granted Jul 21, 2026
Patent 12664285
Asset Grouping Rules for Vulnerability Detection and Management in IT Systems
3y 8m to grant Granted Jun 23, 2026
Patent 12657282
INFERENCE WITH INLINE REAL-TIME ML MODELS IN APPLICATIONS
2y 9m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+24.6%)
2y 7m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 222 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month