Prosecution Insights
Last updated: October 02, 2026
Application No. 19/081,996

MITIGATING SECURITY VULNERABILITIES USING LANGUAGE MODELS

Non-Final OA §102§103
Filed
Mar 17, 2025
Priority
Feb 20, 2025 — provisional 63/761,115
Examiner
DOLLY, KENDALL LYNN
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
502 granted / 572 resolved
+29.8% vs TC avg
Strong +21% interview lift
Without
With
+21.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
9 currently pending
Career history
579
Total Applications
across all art units

Statute-Specific Performance

§101
21.5%
-18.5% vs TC avg
§103
41.3%
+1.3% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
17.7%
-22.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 572 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 3/17/2025 and 6/25/2026 was filed before the mailing date of the first office action. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-3, 6, 8-10, 13, 15-17 and 19 is/are rejected under 35 U.S.C. 102(a)(1)/102(a)(2) as being anticipated by Shakarian et al (US 2020/0327237). Regarding claims 1, 8 and 15, Shakarian et al discloses a method for utilizing a language model to mitigate a network vulnerability, a system comprising: one or more processors; and one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, and One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform operations comprising [0041-0042, fig 1]: deploying the language model that is configured to respond to inputs from network operators associated with a network [0164, fig 10] (large language processing is performed such that data is scanned to identify CPE identifiers and first and second data sets (i.e., input) is received and scanned); receiving, by the language model, a first input from a network operator indicating a description of the network vulnerability [0161, 0164, fig 10] (a first data set defining vulnerabilities may be collected); receiving, by the language model, a second input including information associated with a configuration of the network [0161, 0164, fig 10] (a second data set defining configuration information is accessed and received); based at least in part on the description of the network vulnerability and the information associated with the configuration of the network, determining, by the language model, a series of actions to execute to mitigate the network vulnerability [0166, 0023] (selection of an optimal set of software changes is deployed to minimize risk); outputting, by the language model, the series of actions to execute to the network operator [0129] ( a threat based triage is performed). Regarding claims 2, 9, and 16, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Shakarian et al further discloses wherein determining the series of actions to execute further comprises: determining network devices that are affected by the network vulnerability; and determining one or more actions to execute on each of the network devices to mitigate the network vulnerability [0110-0111, 0149-0156] (the system is configured to solve an optimization problem such that overall threat is decreased). Regarding claims 3, 10, and 17, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Shakarian et al further discloses wherein the language model is a first language model and wherein determining the series of executable actions further comprises: determining a high-level configuration change to the configuration of the network that will mitigate the network vulnerability; determining a natural language description of a series of subtasks for implementing the high-level configuration change; inputting the natural language description of each subtask into a second language model; and receiving from the second language model an action to execute for each subtask, wherein each action to execute includes a network device on which to execute the action [0110-0111, 0149-0156] (optimization logic is applied in a systematic matter such that changes can be applied given software constraints). Regarding claims 6, 13, and 19, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Shakarian et al further discloses wherein the network vulnerability is Common Vulnerabilities and Exposures (CVE) report received from a CVE database [0025-0033]. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 4, 5, 7, 11, 12, 14, 18 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Shakarian et al (US 2020/0327237) in view of Lal et al (US 2024/0414190). Regarding claims 4, 11 and 18, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Lal et al further discloses wherein the natural language description of a subtask is input into the second language model multiple times and further comprising: generating, by the second language model, multiple possible actions to execute to implement the subtask; inputting a description of each of the multiple possible actions to execute into a decision tree model; and receiving from the decision tree model an optimal action to execute for the subtask [0178-0181] (when the network is being protected by an appliance a decision tree may be implemented to help to decide the countermeasures to enforce). It would have been obvious to one of ordinary skill in the art at to create the invention as claimed for the following reasons. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Shakarian et al by utilizing decision trees for optimization, for the purpose of implementing optimization of the tasks, based upon the beneficial teachings provided by Lal et al, see for example [0178-0181]. These modifications would result in ease of use and increased security, both of which are obvious benefits to the skilled artisan. Additionally, the cited references are in the field of computer security, as is the current application, and thus, are in analogous arts. Regarding claims 5 and 12, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Lal et al further discloses wherein the series of actions to execute include a series of Command Line Interface (CLI) commands for input to one or more network devices [0032]. The motivation to combine is the same as disclosed in point (13) above. Regarding claims 7, 14 and 20, Shakarian et al discloses all the limitations of independent claims 1, 8 and 15. Lal et al further discloses wherein the language model is a large language model (LLM) [0025]. The motivation to combine is the same as disclosed in point (13) above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Radford et al (US 12,682,079): discloses a system allows users to submit security vulnerabilities for systems associated with websites. The system receives, a request for submission of a security vulnerability associated with a website. The request is received via a widget displayed on a webpage of a website. A user interface is configured for receiving details of the security vulnerability. The user interface is sent for display in association with the website. Information describing the security vulnerability is received via the user interface. The information comprises a natural language description of the security vulnerability. A vulnerability tracking system is selected from a plurality of vulnerability tracking systems based on the details of the security vulnerability. The information describing the security vulnerability is routed via a secure channel to the vulnerability tracking system selected. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KENDALL DOLLY whose telephone number is (571)270-1948. The examiner can normally be reached Monday-Friday 7am-3pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KENDALL DOLLY/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Mar 17, 2025
Application Filed
Aug 19, 2026
Non-Final Rejection mailed — §102, §103
Sep 30, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737459
Detecting Fraudulent Electronic Communications
1y 11m to grant Granted Sep 15, 2026
Patent 12726471
INTERNET PROTOCOL VERSION 6-BASED MULTI-ELEMENT AUTHENTICATION ROOT SYSTEM
1y 8m to grant Granted Sep 01, 2026
Patent 12711243
Cybersecurity Vulnerability Management System and Method Thereof
1y 12m to grant Granted Aug 18, 2026
Patent 12705296
AGGREGATED DATA QUERY INTERFACE
3y 0m to grant Granted Aug 11, 2026
Patent 12705375
COLLECTION FOLDER FOR COLLECTING FILE SUBMISSIONS IN RESPONSE TO A PUBLIC FILE REQUEST
1y 11m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+21.2%)
2y 4m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 572 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month