Prosecution Insights
Last updated: August 18, 2026
Application No. 19/082,063

ATTACK ANALYSIS DEVICE, ATTACK ANALYSIS METHOD, AND STORAGE MEDIUM THEREOF

Non-Final OA §102§103§112
Filed
Mar 17, 2025
Priority
Sep 30, 2022 — JP 2022-157432 +3 more
Examiner
MIAN, MOHAMMAD YOU A
Art Unit
Tech Center
Assignee
Denso Corporation
OA Round
1 (Non-Final)
66%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 66% — above average
66%
Career Allowance Rate
187 granted / 284 resolved
+5.8% vs TC avg
Strong +33% interview lift
Without
With
+32.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
21 currently pending
Career history
304
Total Applications
across all art units

Statute-Specific Performance

§101
6.6%
-33.4% vs TC avg
§103
61.5%
+21.5% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 284 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1- 26 are pending for examination. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “a log acquisition unit”, “an indicator acquisition unit”, “an attack anomaly relation information storage unit”, “an attack estimation unit”, “an output unit”, “a situation estimation unit” couple with functional language “acquiring”, “storing”, “estimating”, “outputting” in claims 1-8, 10, 12, 14, and 17-21. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. A review of the specification shows that the following appears to be the corresponding structure described in the specification for the 35 U.S.C. 112(f) or pre-AIA 35 USC. 112, sixth paragraph limitation: Fig. 10 illustrates and para. 0162 discloses a log acquisition unit 111, indicator acquisition unit 112, attack anomaly relation information storage unit 115, attack estimation unit 116, output unit 118, situation estimation unit 113. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 11 and 21-26 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by US 2023/0283617 (Tasaki et al.). Regarding Claim 1, Tasaki teaches an attack analysis device analyzing an attack on an electronic control system mounted on a mobile object ([¶ 0007] An attack analysis device according to one aspect of the present disclosure includes: an obtainer that obtains in-vehicle network information …and anomaly detection information indicating a result of detecting an anomaly …an attack path estimator that, …estimates an attack path in an attack on the in-vehicle network…; and an outputter that outputs the attack path), the attack analysis device comprising: a log acquisition unit acquiring a security log indicating (i) an anomaly detected in the electronic control system and (ii) a location within the electronic control system where the anomaly is detected ([0067] As illustrated in FIG. 2, in-vehicle network 20 is configured including a plurality of external communication interfaces, a plurality of control Electronic Control Units (ECUs), and integrated ECU. [¶ 0081] Security master generates anomaly detection information indicating an anomaly detection result detected in at least one node [i.e., location within the electronic control system where the anomaly is detected] in in-vehicle network when Intrusion Detection System (IDS) …has detected an anomaly. [¶ 0084], the anomaly detection list is a table which, for each node included in in-vehicle network, associates a classification of the node, a timestamp …whether or not an anomaly has been detected by the IDS which detects anomalies for that node, and an anomaly detection score); an indicator acquisition unit acquiring an indicator indicating an internal state or an external state of the mobile object when the anomaly occurs ([¶ 0046] …the obtainer may further obtain an external communication event history [i.e., an external state of the mobile object] indicating a history of communication events between the in-vehicle network and outside the in-vehicle network, and a vehicle control event history [i.e., an internal state] indicating a history of vehicle control events by a vehicle in which the in-vehicle network is installed. [¶ 0100], vehicle control event history is a table which, for each vehicle control event that has occurred, associates the date and time …an ECU ID identifying ECU which caused that vehicle control event to occur… [¶ 0094] …external communication event history is a table which, for each external communication event that occurs, associates the date and time …an external communication IF ID identifying external communication IF which communicated with the exterior in that external communication event, and an external communication event risk); an attack anomaly relation information storage unit storing attack anomaly relation information indicating a relation among (i) predicted attack information indicating an attack predicted to be received by the electronic control system, (ii) predicted anomaly information indicating an anomaly predicted to occur when the electronic control system receives the predicted attack, and (iii) predicted anomaly location information indicating a location within the electronic control system where the predicted anomaly occurs ( [¶ 0112] attack path estimator estimates an attack path, including the entry point and the attack target, in the attack on in-vehicle network [i.e., predicted attack information]. [¶ 0116] Upon …obtaining the anomaly detection information, …generates the attack path estimation result table [i.e., implicitly storing] based on the anomaly detection information obtained…. Then, …successively updates and manages the generated attack path estimation result table. [¶ 0118], the attack path estimation result table is a table which…associates the following: …whether or not an anomaly has been detected by the IDS which detects anomalies for that node; the anomaly detection score output from the IDS which detects anomalies for that node [i.e., an predicted anomaly information indicating an anomaly predicted to occur] estimation result indicating an anomaly state of that node… estimated by entry point estimator when that node is external communication IF, or an estimation result indicating an anomaly state of that node, estimated by attack target estimator when that node is ECU 22 [i.e., predicted anomaly location information]; a risk indicating the entry point risk of that node, calculated … when that node is communication IF., or the attack target risk of that node, calculated by attack target estimator .when that node is ECU 22; an attack path indicating whether that node corresponds to the attack path estimated by attack path estimator); an attack estimation unit estimating the attack received by the electronic control system based on (i) the security log, (ii) the attack anomaly relation information, and (iii) the indicator ([¶ 0108] Based on the in-vehicle network information, the anomaly detection information, and the external communication event history obtained by obtainer, entry point estimator estimates an entry point indicating external communication IF that is the point of intrusion into in-vehicle network in the attack on in-vehicle network. [¶ 0110] Based on the in-vehicle network information, the anomaly detection information, and the vehicle control event history obtained by obtainer, attack target estimator estimates an attack target indicating ECU which is the target of the attack on in-vehicle network. [¶ 0112] Based on the in-vehicle network information and the anomaly detection information obtained by obtainer, attack path estimator estimates an attack path, including the entry point and the attack target, in the attack on in-vehicle network [¶ 0096], vehicle control event list stored by vehicle control event manager); and an output unit outputting attack information indicating the estimated attack ([¶ 0126] Outputter 13 outputs the attack path estimated by attack path estimator …display controller 18, which outputs a display control signal including the attack path). Regarding Claim 11, Tasaki teaches The attack analysis device according to claim 1, wherein the indicator includes the security log acquired by the log acquisition unit ([¶ 0103], when IDS included in in-vehicle network detects an anomaly, security master 27 generates the anomaly detection information [i.e., security log] and transmits the generated anomaly detection information to attack analysis device along with the in-vehicle network information, the vehicle control event history, and the external communication event history). Regarding Claim 21, the claim limitations are identical and/or equivalent in scope to claim 1, therefore, rejected under the same rationale as claim 1. Tasaki further teaches …a situation acquisition unit acquiring a situation of the mobile object estimated based on an indicator indicating an internal state or an external state of the mobile object when the anomaly occurs… ([¶ 0046] the obtainer may further obtain an external communication event history indicating a history of communication events [i.e., situation based on external state] between the in-vehicle network and outside the in-vehicle network, and a vehicle control event history indicating a history of vehicle control events [i.e., situation based on internal state] by a vehicle in which the in-vehicle network is installed), as also required by the claim 21,. Regarding Claim 22, Tasaki teaches the attack analysis device according to claim 1, wherein the attack analysis device is located outside the mobile object (Fig. 1 illustrates the Attack analysis device 10 located outside of the vehicle 30. [¶ 0232], attack analysis device 10 as being realized by monitoring server 40 located outside in-vehicle network 20). Regarding Claim 23, Tasaki teaches the attack analysis device according to claim 1, wherein the attack analysis device is mounted on the mobile object ([¶ 0232], it is not necessary for attack analysis device 10 to be realized in a device outside in-vehicle network 20. For example, it is conceivable for attack analysis device 10 to be realized by an integrated ECU included in in-vehicle network 20). Regarding Claim 24, the claim limitations are identical and/or equivalent in scope to claim 1, therefore, rejected under the same rationale as claim 1. Regarding Claim 25, the claim limitations are identical and/or equivalent in scope to claim 1, therefore, rejected under the same rationale as claim 1. Tasaki also teaches a non-transitory tangible storage medium storing an attack analysis program to be executed by at least one processor… (¶ 0238) as required by claim 25. Regarding Claim 26, Tasaki teaches the attack analysis device according to claim 1, wherein the indicator, which indicates the internal state or the external state of the mobile object, is not included in the security log ([¶ 0089] Vehicle control event manager 28 …manages an external communication event history [i.e., external state], which indicates a history of communication events between in-vehicle network 20 and the exterior, and a vehicle control event history [i.e., internal state], which indicates a history of vehicle control events performed by vehicle 30. [¶ 0081] Security master 27 generates anomaly detection information [i.e., security log] indicating an anomaly detection result detected in at least one node in in-vehicle network 20 when IDS 23 included in in-vehicle network 20 has detected an anomaly. Note: these three data structures are explicitly disclosed as separately generated, separately transmitted, and separately stored). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2, 5, 6, 10 and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of US 2019/0306180 (Dyakin et al.) Regarding Claim 2, Tasaki teaches the attack analysis device according to claim 1, further comprising …the attack estimation unit estimates the attack received by the electronic control system based on … the security log and the attack anomaly relation information ([¶ 0108] Based on the in-vehicle network information, the anomaly detection information, and the external communication event history obtained by obtainer, entry point estimator estimates an entry point indicating external communication IF that is the point of intrusion into in-vehicle network in the attack on in-vehicle network. [¶ 0110] Based on the in-vehicle network information, the anomaly detection information, and the vehicle control event history obtained by obtainer, attack target estimator estimates an attack target indicating ECU which is the target of the attack on in-vehicle network. [¶ 0112] Based on the in-vehicle network information and the anomaly detection information obtained by obtainer, attack path estimator estimates an attack path, including the entry point and the attack target, in the attack on in-vehicle network). Tasaki does not explicitly teach, however, Dyakin teaches a situation estimation unit estimating, based on the indicator, a situation of the mobile object corresponding to the indicator, wherein the attack estimation unit estimates the attack received by the electronic control system based on the situation of the mobile object ([¶ 0087], the rule may contain the condition of movement of the automobile. That is, if the automobile is in motion and the above-indicated CAN messages arrive, the condition for application of the rule will be fulfilled, but if the automobile is not moving, the rule will not be applied, since in the second case the receiving of such messages does not indicate the exploiting of a vulnerability and a computer attack. [¶ 0112], the at least condition of the rule specifies presence of a defined group of messages in the log during a period of time associated with movement of the vehicle. the rule is applied responsive to determining that the vehicle is in motion, and the rule is not applied responsive to determining that the vehicle is not moving. Thus, Dyakin teaches estimating attack based on vehicle situation (i.e., moving vs. stationary)). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Dyakin's rule for estimating attack based on operating situation of the vehicle into Tasaki’s attack estimation process because such incorporation would have improved attack estimation accuracy by distinguishing legitimate operating conditions from actual cyberattacks, thereby reducing erroneous attack determinations. Regarding Claim 5, Tasaki teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit uses a part of the attack anomaly relation information, which includes a location within the electronic control system estimated to be related to the attack under the situation of the mobile object as the predicted anomaly location information or the predicted attack information ([¶ 0044], an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point indicating an external communication interface that is a point of intrusion into the in-vehicle network in the attack and an attack target indicating a control ECU [i.e. location within the electronic control system estimated to be related to the attack] that is a target of the attack. [¶ 0046], estimates the entry point based on the in-vehicle network information, the anomaly detection information, and the external communication event history; and an attack target estimator that estimates the attack target based on the in-vehicle network information, the anomaly detection information, and the vehicle control event history. [¶ 0048], the entry point estimator may calculate an entry point risk …the attack target estimator may calculate an attack target risk …and estimates the attack target based on each attack target risk calculated). Regarding Claim 6, Tasaki teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit uses a part of the attack anomaly relation information, which includes an anomaly estimated to be related to the attack under the situation of the mobile object as the predicted anomaly information ([¶ 0007], an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point …and an attack target. [¶ 0046], …an external communication event history indicating a history of communication events between the in-vehicle network and outside the in-vehicle network, and a vehicle control event history indicating a history of vehicle control events by a vehicle in which the in-vehicle network is installed. The attack analysis device may further include: an entry point estimator that estimates the entry point based on the in-vehicle network information, the anomaly detection information, and the external communication event history; and an attack target estimator that estimates the attack target based on the in-vehicle network information, the anomaly detection information, and the vehicle control event history [i.e., situation of the mobile object]. The attack path estimator may estimate the attack path based on the entry point estimated by the entry point estimator and the attack target estimated by the attack target estimator). Regarding Claim 10, Tasaki teaches the attack analysis device according to claim 2, wherein the situation estimation unit estimates whether a cause of the anomaly indicated by the security log is a cyberattack ([¶ 0003], analyze cyber-attacks (also called simply “attacks” hereinafter) on in-vehicle networks installed in vehicles. [¶ 0091], external communication event list is a table which, for each of external communication events indicating communication events between in-vehicle network and the exterior, associates a classification of the external communication event, a risk and a sub-risk indicating a degree of risk of a cyber-attack stemming from that external communication event, and a prioritized path, which is a comment regarding that external communication event. Here, the “risk” and “sub-risk” are both scores which increase in value as the degree of risk of a cyber-attack increases), in response to the cause of the anomaly being different from the cyberattack, the situation estimation unit determines the security log is a false positive log, and the attack estimation unit does not estimate the attack using the security log determined as the false positive log ([¶ 0152] If IDS has not detected an anomaly, entry point estimator estimates the anomaly state of the selected external communication IF to be “false detection”, and calculates the entry point risk for that external communication IF as “2”. [¶ 0156] If IDS has not detected an anomaly, entry point estimator estimates the anomaly state of the selected external communication IF to be “no attack (event present)”, and calculates the entry point risk for that external communication IF as “1”). Regarding Claim 14, Tasaki teaches the attack analysis device according to claim 2, wherein the situation estimation unit estimates an entry point candidate, which is a candidate of an entry point from where the attack entered, based on the indicator, and when estimating the attack received by the electronic control system, the attack estimation unit uses a part of the attack anomaly relation information, which includes the entry point candidate as the predicted attack information ([¶ 0044], an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point indicating an external communication interface that is a point of intrusion into the in-vehicle network in the attack. [¶ 0046], an entry point estimator that estimates the entry point based on the in-vehicle network information…and the external communication event history. [¶ 0108], entry point estimator calculates an entry point risk, which indicates a confidence level of that external communication IF being an entry point, and estimates the entry point based on each of the calculated entry point risks). Regarding Claim 15, Tasaki does not explicitly teach, however Dyakin teaches the attack analysis device according to claim 14, wherein the indicator is a speed of the mobile object ([¶ 0025] Sensors and setpoint generators configured to detect operating conditions (e.g. engine speed) and setpoint values (e.g. switch position). [¶ 0061], As a rule, the majority of ECU ignore messages if the speed of the automobile exceeds 7-15 km/h, and therefore such a computer attack is possible during slow movement of the automobile. [¶ 0096], a significant change in speed of the MT during a short interval of time may be considered to be an anomaly). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Dyakin's teachings of using vehicle-state information, such as vehicle speed, as an indicator into Tasaki’s anomaly-detection system because such incorporation would have predictably reduce false positives and improve anomaly classification by allowing Tasaki to determine whether a detected anomaly is plausible given the vehicle’s operating condition. Regarding Claim 16, Tasaki teaches The attack analysis device according to claim 14, wherein the indicator includes at least one of (i) a location of the mobile object ([¶ 0112], Based on the in-vehicle network information and the anomaly detection information obtained…, attack path estimator estimates an attack path, including the entry point and the attack target [i.e., location of the mobile object], in the attack on in-vehicle network, (ii) an ambient temperature of the mobile object, or (iii) time related information ([¶ 0084], the anomaly detection list is a table which, for each node included in in-vehicle network, …a timestamp indicating the date and time at which an anomaly was detected by the IDS which detects anomalies for that node). Claims 3, 4, 7 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin, and further in view of US 2016/0381068 (Galula et al.). Regarding Claim 3, Tasaki in view of Dyakin do not explicitly teach, however, Galula teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit does not use a part of the attack anomaly relation information, which includes a location within the electronic control system estimated to be not related to the attack under the situation of the mobile object as the predicted anomaly location information or the predicted attack information ([Fig. 5, ¶¶ 0127-0128], Table 590 shown an exemplary set of contexts. …As shown the description column 592, a context may be related to a vehicle's state or operation (e.g., engine is running, vehicle is accelerating), a context may be related to an in-vehicle network (e.g., an intrusion to the network was detected) and a context may be related to nodes attached to an in-vehicle network (e.g., a fault in, or malfunction of, a node or component attached to the in-vehicle network detected. … an anomaly may be detected or identified according to, or based on, a context that may be a complex context. … Logic in an security enforcement unit (SEU) may prioritize contexts when needed, or select a portion of a complex or combined context value. For example, an SEU may ignore the portion of a context that indicates that the infotainment system is on (e.g., the context includes “C” as shown in table 590) when processing a message received from a sensor that monitors and reports engine oil pressure). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Galula's selective context approach into Tasaki’s attack estimation process because such incorporation would predictably improve Tasaki’s anomaly-detection accuracy by allowing the system to ignore portions of vehicle context that do not affect the anomaly determination while using only the context value that do. Regarding Claim 4, Tasaki in view of Dyakin do not explicitly teach, however, Galula teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit does not use a part of the attack anomaly relation information, which includes an anomaly estimated to be not related to the attack under the situation of the mobile object as the predicted anomaly information ([¶ 0128], Logic in an security enforcement unit (SEU) may prioritize contexts when needed, or select a portion of a complex or combined context value. For example, an SEU may ignore the portion of a context that indicates that the infotainment system is on (e.g., the context includes “C” as shown in table 590) when processing a message received from a sensor that monitors and reports engine oil pressure). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Galula's selective context approach into Tasaki’s attack estimation process because such incorporation would predictably improve Tasaki’s anomaly-detection accuracy by allowing the system to ignore portions of vehicle context that do not affect the anomaly determination while using only the context value that do. Regarding Claim 7, Tasaki teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit uses a part of the attack anomaly relation information, which includes a location within the electronic control system…or the predicted anomaly location information after applying weighting to the part of the attack anomaly relation information ([¶ 0007], an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point …and an attack target [i.e., a location within the electronic control system]. [¶ 0048], he entry point estimator …calculate an entry point risk indicating a confidence level of each of the plurality of …the entry point, …and …calculate an attack target risk indicating a confidence level of each of the plurality of control ECUs being the attack target, and estimates the attack target based on each attack target risk calculated. Note: These risk values are weights applied to anomaly-location information). Tasaki in view of Dyakin do not explicitly teach, however, Galula teaches estimated to be not related to the attack under the situation of the mobile object as the predicted anomaly information ([¶ 0128], Logic in an SEU 40 may prioritize contexts …or select a portion of a complex or combined context value. … may ignore the portion of a context that indicates that the infotainment system is on …when processing a message received from a sensor that monitors and reports engine oil pressure). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Tasaki’s weighted use of anomaly-location information with Galula’s teachings of situation-based relevance determination so that the attack estimation unit uses only the weighted portion of the attack anomaly relation information, including anomaly-location information that is not fully related under the current situation but still contributes with reduced weight. The combination yields predictable results by improving robustness of attack estimation through weighting rather than discarding partially relevant anomaly-location information. Regarding Claim 8, Tasaki teaches the attack analysis device according to claim 2, wherein, when estimating the attack received by the electronic control system, the attack estimation unit uses a part of the attack anomaly relation information, which includes an anomaly …as the predicted anomaly information after applying weighting to the part of the attack anomaly relation information ([¶ 0007], an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network. [¶ 0084], the anomaly detection list is a table which, for each node included in in-vehicle network, associates …whether or not an anomaly has been detected by the IDS which detects anomalies for that node, and an anomaly detection score output from the IDS which detects anomalies for that node. [¶ 0048], he entry point estimator …calculate an entry point risk indicating a confidence level of each of the plurality of …the entry point, …and …calculate an attack target risk indicating a confidence level of each of the plurality of control ECUs being the attack target, and estimates the attack target based on each attack target risk calculated. Note: These risk values are weights applied to anomaly-related information). Tasaki in view of Dyakin do not explicitly teach, however, Galula teaches estimated to be not related to the attack under the situation of the mobile object ([¶ 0128], Logic in an SEU 40 may prioritize contexts …or select a portion of a complex or combined context value. … may ignore the portion of a context that indicates that the infotainment system is on …when processing a message received from a sensor that monitors and reports engine oil pressure). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Tasaki’s weighted use of anomaly-location information with Galula’s teachings of situation-based relevance determination so that the attack estimation unit uses only the weighted portion of the attack anomaly relation information, including anomaly-location information that is not fully related under the current situation but still contributes with reduced weight. The combination yields predictable results by improving robustness of attack estimation through weighting rather than discarding partially relevant anomaly-location information. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin and Galula, and further in view of WO 2023067257 (Vivet et al.). Regarding Claim 9, Tasking in view of Dyakin and Galula do not explicitly teach, however, Vivet teaches the attack analysis device according to claim 8, wherein the weighting is performed by multiplying a coefficient set within a range of 0 ≤ coefficient < 1 ([Para. 1-2 on Page 3], the adjusted speed being determined …the difference being weighted by a weighting coefficient depending on the relevance indicator …the relevance indicator being between 0 and 1, the weighting coefficient being between 0 and a maximum value, the weighting coefficient being equal to its maximum value when the relevance indicator is between 0 and a determined value less than 1). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Vivet’s teaching of applying a weighting coefficient constrained to a range ≥ 0 and < 1 into Tasaki’s attack-estimation system because Tasaki already relies on risk-based weighting of anomaly information, and Vivet provides well-defined, mathematically stable weighting scheme that predictably suppresses low-confident or unreliable anomaly input. Claims 12 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin, and further in view of US 2014/0350779 (Yasue). Regarding Claim 12, Tasaki teaches the attack analysis device according to claim 2, wherein the situation estimation unit estimates, as the situation of the mobile object, a situation of a vehicle based on the indicator ([¶¶ 0170-0172], attack target estimator 15 obtains the in-vehicle network information, the anomaly detection information, and the vehicle control event history obtained by obtainer 11, … and checks whether a vehicle control event has been produced by the selected ECU 22), the situation of the vehicle includes an operation state of the vehicle or a driving condition of the vehicle, the situation estimation unit estimates power supply states of one or more electronic control devices included in the electronic control system from the situation of the vehicle, and when estimating the attack received by the electronic control system, based on the estimated…states, the attack estimation unit does not use a part of the attack anomaly relation information, which includes a location within the electronic control system estimated to be not related to the attack as the predicted anomaly location information or the predicted attack information (([¶ 0173], attack target estimator 15 estimates the anomaly state of the selected ECU 22 to be “anomaly detected (attack risk: high)”, and calculates the attack target risk for that ECU 22) [¶ 0198], attack path estimator 12 …estimates the attack path candidate, …which has the highest number of IDSs 23 that detected an anomaly, as the attack path. [¶ 0223], display controller 18 …checks whether there is IDS 23 which is not included in the attack path but which has detected an anomaly). However, Tasaki in view Dyakin do not teach, however, Yasue teaches the situation of the vehicle includes an operation state of the vehicle or a driving condition of the vehicle, the situation estimation unit estimates power supply states of one or more electronic control devices included in the electronic control system from the situation of the vehicle, and when estimating the attack received by the electronic control system, based on the estimated power supply states, the attack estimation unit does not use a part of the attack anomaly relation information, which includes a location within the electronic control system estimated to be not related to the attack as the predicted anomaly location information or the predicted attack information ([¶¶ 0010, 0012], The anomaly diagnosis system is to perform an anomaly diagnosis in an in-vehicle network where a plurality of electronic control units are connected to mutually communicate. The anomaly diagnosis system includes a power supply portion, a voltage detection portion, an integration section, and a diagnosis section. …the voltage detection portion is to detect a power supply voltage in the subject electronic control unit repeatedly while the subject electronic control unit perform an operation. …the diagnosis section is to perform an anomaly diagnosis based on the respective integrated values calculated with respect to the plurality of electronic control units. … the integration section calculates the integrated value by substituting a corresponding value for the variation value at an activation time when the subject electronic control unit is activated, the corresponding value corresponding to the power supply voltage detected by the voltage detection portion at the activation time when the subject electronic control unit is activated; and the diagnosis section performs the anomaly diagnosis using only the integrated values each being greater than zero. … when the ECU is activated and starts an operation, the integrated value certainly turns into a value greater than zero. The diagnosis section performs an anomaly diagnosis using only the integrated values each being greater than zero. an integrated value with respect to an ECU that is not activated or not operating is held at zero; thus, any integrated value with respect to the ECU that is not activated is not used in the anomaly diagnosis. Yasue further teaches “when the vehicle is under the stop state”, “when the vehicle is parked or the ignition switch is turned off”, “ in a situation where only part of ECUs are activated whereas the other ECUs are under the sleep mode”, “some ECUs among all the ECUs are not activated”, therefore, it would be understood that Yasue considered vehicle operational condition [i.e., stop state, turned off] and estimating power supply state [i.e., ECU in sleep mode, activated]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Yasue’s teaching of ignoring information related to power state of ECU into Tasaki’s attack-estimation system because such incorporation would have predictably reduce false positives and prevent from considering misleading anomaly sources, thereby improving accuracy. Regarding Claim 13, Tasaki in view of Dyakin do not explicitly teach, however, Yasue teaches the attack analysis device according to claim 12, wherein the indicator includes at least one of (i) a vehicle speed, (ii) an operation mode, (iii) number of occupants, (iv) a battery voltage, (v) a battery charge state, or (vi) a shift position ( [¶¶ 0022, 0030], when the vehicle is parked or the ignition switch is turned off …when the vehicle is under the stop state, [i.e., an operation mode], Yasue also teaches [¶¶ 0010, 0022], the voltage detection portion is to detect a power supply voltage [i.e., battery voltage] in the subject electronic control unit repeatedly while the subject electronic control unit perform an operation, …the ECU 11 is provided to receive the electric power supply directly from an in-vehicle battery 18 which may be referred to as a power supply portion or source). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Yasue’s teaching of considering vehicle’s operating state (running or stop) and the ECU power supply voltage into Tasaki’s attack-estimation system because such incorporation would have allowed distinguish genuine attack behavior from normal vehicle behavior, thereby improving accuracy. Claims 17 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin, and further in view of US 2016/0239661 (Kawauchi). Regarding Claim 17, Tasaki in view of Dyakin do not explicitly teach, however, Kawauchi teaches the attack analysis device according to claim 2, wherein the situation estimation unit estimates whether a cause of the anomaly indicated by the security log is a cyberattack based on a frequency at which the security log is generated as the indicator, when the cause of the anomaly is not the cyberattack, the situation estimation unit determines that the security log is a false positive log, and when estimating the attack received by the electronic control system, the attack estimation unit applies weighting to a part of the attack anomaly relation information, which corresponds to the anomaly indicated by the security log at the location of the electronic control system corresponding to the security log determined as the false positive log, and then uses the weighted attack anomaly relation information to estimate the attack ([¶ 0455], the attack likelihood value is automatically determined based on the event occurrence frequency of the normal state. [¶ 0331] Hence, an effect is obtained that occurrence of the attack can be notified to the user only when a series of events similar to the behavior of an attacker occur. As a result, false detection can be reduced. [¶ 0166] the attack occurrence determining part updates the value of the accumulated attack likelihood by adding the value [i.e., applies weighting] of the attack likelihood …to the value of the accumulated attack likelihood of the attack activity status information [¶ 0167] the attack occurrence determining part compares the value of the accumulated attack likelihood updated with the attack determination threshold. [¶ 0168] If the value of the accumulated attack likelihood is larger than the attack determination threshold, then the attack occurrence determining part notifies the user of an occurrence of an attack). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kawauchi’s teaching of determining attack occurrence when an attack-likelihood value exceeds a threshold into Tasaki’s attack-estimation system because Tasaki already computes risk score for entry point and attack targets, but does not specify a concrete decision threshold, Kawauchi provides well-defined likelihood-based trigger that makes Tasaki’s attack-occurrence determination more objective, predictable, and easier to calibrate. Regarding Claim 18, Tasaki in view of Dyakin do not explicitly teach, however, Kawauchi teaches the attack analysis device according to claim 2, wherein the situation estimation unit estimates whether a cause of the anomaly indicated by the security log is a cyberattack based on a frequency at which the security log is generated as the indicator, when the cause of the anomaly is not the cyberattack, the situation estimation unit determines that the security log is a false positive log, and the attack estimation unit does not estimate the attack using the security log determined as the false positive log ([¶ 0455], the attack likelihood value is automatically determined based on the event occurrence frequency of the normal state. [¶ 0331] Hence, an effect is obtained that occurrence of the attack can be notified to the user only when a series of events similar to the behavior of an attacker occur. As a result, false detection can be reduced. [¶ 0166] the attack occurrence determining part updates the value of the accumulated attack likelihood by adding the value [i.e., applies weighting] of the attack likelihood …to the value of the accumulated attack likelihood of the attack activity status information [¶ 0167] the attack occurrence determining part compares the value of the accumulated attack likelihood updated with the attack determination threshold. [¶ 0168] If the value of the accumulated attack likelihood is larger than the attack determination threshold, then the attack occurrence determining part notifies the user of an occurrence of an attack). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Kawauchi’s teaching of determining attack likelihood value based on the event occurrence frequency into Tasaki’s attack-estimation system because such incorporation would have predictably improve Tasaki’s ability to distinguish persistence malicious behavior from isolated benign events. Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin, and further in view of US 11757931 (Sodja et al.). Regarding Claim 19, Tasaki in view of Dyakin do not explicitly teach, however, Sodja teaches the attack analysis device according to claim 17, wherein the situation estimation unit estimates whether a cause of the anomaly indicated by the security log is a misoperation made by a user to the mobile object based on a frequency at which the security log is generated as the indicator, and when the cause of the anomaly is the misoperation made by the user, the situation estimation unit determines that the security log is the false positive log ([C.2:L.65 – C.3:L.25] recognize that observation of a sudden, relatively large count of particular types of events associated with network connections, while infrequent in some environments, does not necessarily imply that a machine is under attack [i.e. false positive]. For example, a script that performs the following actions would appear to be suspicious when evaluating a time series of counts of failed logins. However, such an example is most likely not malicious: uses an expired password retries login attempts every N-minutes with different usernames over a public IP address within a range owned by the enterprise. …the context of failed logins and inbound connections can be useful in discriminating between true positive (TP) and false positive (FP) brute force attacks. Sodja teaches sudden spikes in failed login events [i.e., user misoperation] do not always mean a machine is being hacked, considered it as false positive). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Sodja’s teaching of frequency-based log analysis to determine low-frequency user attempt not an attack into Tasaki’s attack-estimation system because such incorporation would have reduced wasted administrative effort and misclassifying benign log generation event as attack. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Tasaki in view of Dyakin and Sodja, and further in view of US 10972498 (Keohane et al.). Regarding Claim 20, Tasaki in view of Dyakin do not explicitly teach, however, as aforementioned in claim 19, Sodja teaches estimates that the cause of the anomaly indicated by the security log is the misoperation made by the user (see, rejection of claim 19), Tasaki in view of Dyakin and Sodja do not explicitly teach, but Keohane teaches when the frequency at which the security log is generated is lower than a reference frequency, …indicated …misoperation made by the user ([C.5:L.24-28], determines a frequency of access attempts ..compares the determined frequency of access attempts to a first pre-defined threshold. [C.7:L.37-47] In response to determining that the frequency of access attempts made to the account is less than the first threshold …continues to determine a frequency of access attempts made to the account. …determines that the frequency of access attempts made to the account exceeds the first threshold, …identifies the access attempts as a brute force attack). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate Sodja and Keohane’s teaching of frequency-based log analysis to determine low-frequency user attempt not an attack into Tasaki’s attack-estimation system because such incorporation would have reduced wasted administrative effort and misclassifying benign log generation event as attack. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD YOUSUF A MIAN whose telephone number is (571)272-9206. The examiner can normally be reached Monday-Friday 9am-5:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ARIO ETIENNE can be reached at 571-272-4001. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOHAMMAD YOUSUF A. MIAN/ Examiner, Art Unit 2457 /ARIO ETIENNE/ Supervisory Patent Examiner, Art Unit 2457
Read full office action

Prosecution Timeline

Mar 17, 2025
Application Filed
Jul 16, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706736
PREPARATION OF A CONTROL DEVICE FOR SECURE COMMUNICATION
3y 8m to grant Granted Aug 11, 2026
Patent 12682051
CONTROL SYSTEM HAVING ISOLATED USER COMPUTING UNIT AND CONTROL METHOD THEREFOR
3y 2m to grant Granted Jul 14, 2026
Patent 12676860
SYSTEM AND METHOD FOR ADVERTISING SUPPLICANTS IN A NETWORK
2y 11m to grant Granted Jul 07, 2026
Patent 12651522
PATTERN AGENT FOR COMPUTER-AIDED DISPATCH SYSTEMS
6y 1m to grant Granted Jun 09, 2026
Patent 12647320
DISTRIBUTED NETWORK CONFIGURATION METHOD AND APPARATUS, INTELLIGENT TERMINAL, AND COMPUTER READABLE STORAGE MEDIUM
3y 0m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
66%
Grant Probability
99%
With Interview (+32.9%)
3y 2m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 284 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month