Prosecution Insights
Last updated: October 04, 2026
Application No. 19/112,493

METHOD FOR MEASURING SECURITY OPERATION CENTER

Non-Final OA §101§103§112
Filed
Mar 17, 2025
Priority
Sep 23, 2022 — nonprovisional of PCTTR2022051036
Examiner
GRACIA, GARY S
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Binalyze Yazilim A S
OA Round
1 (Non-Final)
72%
Grant Probability
Favorable
1-2
OA Rounds
1y 10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
408 granted / 571 resolved
+13.5% vs TC avg
Strong +48% interview lift
Without
With
+48.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
24 currently pending
Career history
590
Total Applications
across all art units

Statute-Specific Performance

§101
11.9%
-28.1% vs TC avg
§103
65.8%
+25.8% vs TC avg
§102
11.2%
-28.8% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 571 resolved cases

Office Action

§101 §103 §112
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restrictions 2. NO restrictions warranted at initial time of filing for patent. Information Disclosure Statement 3. The information disclosure statement (IDS) submitted on 03/17/2025, the submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Oath/Declaration 4. Applicant’s Oath was filed on 03/17/2025. Drawings 5. Applicant’s drawings filed on 03/17/2025 has been inspected and is in compliance with MPEP 608.01. Specification 6. Applicant’s specification filed on 03/17/2025 has been inspected and is in compliance with MPEP 608.02. Claim Objections 7. Claim 1 is objected to because of the following informalities: Claim 1, the claim in line 6 recites " wherein multiple forensic snapshots pertaining to the baseline operational state of at least multiple assets are created based on predetermined characteristics of the device " The phrase " baseline operational state of at least multiple assets " as recited in the claim lacks antecedent bases. Examiner respectfully suggests the applicant to correct and rewrite it e.g. as " wherein multiple forensic snapshots pertaining to [[[the]] baseline operational state of at least multiple assets is created based on predetermined characteristics of the device " Appropriate correction is required. Claims 2-7 discloses “A method” which should state the method of claim 1. Appropriate correction is required. Remarks 8. Examiner request Applicant review relevant prior art under the conclusion of this office action. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 9. Claim 1 recites a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file" which renders the claim indefinite because the phrase "but not limited to" introduces an open-ended and ambiguous scope without any reasonable certainty. The phrase "but not limited to" as recited fails to define the boundaries what is being claimed, as it implies the claim can encompass elements outside of what is actually written. Under MPEP 2171, claims must precisely define what is protected. "But not limited to" leaves the reader guessing what else might be covered. Clarification is required. 11. Claims 3 and 4 may be generally narrative and indefinite, failing to conform with current U.S. practice. They appear to be a literal translation into English from a foreign document and are replete with grammatical and idiomatic errors. Claims 3 and 4 state said multiple categories said multiple analysis entities are rated in are more than two and wherein said multiple categories said multiple analysis entities are rated in are four. However, it is unclear as to who said categories and multiple analysis entities are rated in two or four. Clarification is required. 12. Claim 4 recites the limitation "the device". However, claim 4 contains no earlier recitation or limitation of a device and it is unclear as to what element the limitation was making reference. There is insufficient antecedent basis for this limitation in the claim thereby rendering the claim indefinite. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(f): The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked 13. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as "configured to" or "so that"; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. 14. Claims 1-7 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Step one: Are the claims at issue directed to a statutory category? Yes. The claims recites a series of steps i.e., forensic artifact collection, wherein multiple forensic snapshots pertaining to the baseline operational state of at least multiple assets are created based on predetermined characteristics of the device that may be based on properties of that specific asset or its use case, compromise indicator injection, wherein said multiple forensic snapshots are injected with indicators of compromise associated with at least one type of infiltration of at least one asset, representing a potential compromise or an attack scenario, investigation rating, wherein said at least multiple analysis entities are rated in multiple categories based on their performance for identifying injected forensic snapshots and associating said forensic snapshots with types of malicious activity, readiness-based grouping, wherein said at least multiple analysis entities that are rated in multiple categories are grouped based on predetermined standards for a security operation center Step 2A – Prong 1: Is a Judicial Exception recited? Yes. The claim recites the limitation of collecting forensic information about a device, injecting comprising indicators, investigative rating of entities, and readiness group of entities. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, the claim encompasses a user observing collecting forensic information, injecting indicators, rating entities and grouping them by the process of thinking and observing a device in his/her mind. The mere nominal recitation of a generic device does not take the claim limitation out of the mental processes grouping. Thus, the claim recites a mental process. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The limitation of collecting forensic information about a device, injecting comprising indicators, investigative rating of entities, and readiness group of entities. As drafted, the limitations are a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting nothing in the claim element precludes the step from practically being performed in the mind. The step in the context of this claim encompasses the user performing the steps using a physical written paper and their mind. Thus, the claim recites a mental process. Step 2A – Prong 2: Are the claims integrated into a practical application recited? No. The claim recites four elements: collecting forensic information about a device, injecting comprising indicators, investigative rating of entities, and readiness group of entities. The forensic artifact collection, compromise indicator injection, investigation rating, and readiness-grouping are recited at a high level of generality (i.e., as a general means of collecting forensic information about a device, injecting comprising indicators, investigative rating of entities, and readiness group of entities for use in the series of steps), and amounts to mere data gathering, which is a form of insignificant extra-solution activity. The method that performs the collecting, injecting, rating, and grouping steps are also recited at a high level of generality, and merely automates the collecting, injecting, rating, and grouping steps. Each of the additional limitations is no more than mere instructions to apply the exception using a generic computer component (processor). The combination of these additional elements is no more than mere instructions to apply the exception using a generic computer component (processor). Accordingly, even in combination, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to the abstract idea. Step 2b: Does the claims provide an inventive concept? No. As discussed with respect to Step 2A Prong Two, the additional elements in the claim amount to no more than mere instructions to apply the exception using a generic computer component. The same analysis applies here in 2B, i.e., mere instructions to apply an exception on a generic computer cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. Under the 2019 PEG, a conclusion that an additional element is insignificant extra-solution activity in Step 2A should be re-evaluated in Step 2B. Here, the collecting, injecting, rating, and grouping steps were considered to be extra-solution activity in Step 2A, and thus it is re-evaluated in Step 2B to determine if it is more than what is well-understood, routine, conventional activity in the field. The background of the example does not provide any indication that the processor is anything other than a generic, off-the-shelf computer component, and the Symantec, TLI, and OIP Techs. court decisions cited in MPEP 2106.05(d)(II) indicate that mere collection or receipt of data over a network is a well‐understood, routine, and conventional function when it is claimed in a merely generic manner (as it is here). Accordingly, a conclusion that the collecting step is well-understood, routine, conventional activity is supported under Berkheimer Option 2. For these reasons, there is no inventive concept in the claim, and thus it is ineligible. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 15. Claims 1-7 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20180255077 hereinafter Paine in view of U.S. Patent No. 10135862 hereinafter McClintock As per claim 1, Paine discloses: A method of digital forensics investigation suitable for a security operation center said operation center being configured to monitor at least one information network comprising at least multiple assets (para 0033 “Systems and methods are provided for collection and aggregation of raw statistical data from system access endpoints to identify typical behavior of approved users and subsequently determine behavior changes indicating endpoint compromise.”), comprising steps of; forensic artifact collection, wherein multiple forensic snapshots pertaining to the baseline operational state of at least multiple assets are created based on predetermined characteristics of the device that may be based on properties of that specific asset or its use case (para 0036 “Each of the collector engines includes a service and an agent operating on a corresponding system endpoint of the system endpoints. The service is configured to take a first snapshot of the corresponding system endpoint. The first snapshot includes event activity information associated with the system endpoint. The agent is configured to take a second snapshot of the corresponding system endpoint. The second snapshot includes behavioral activity information associated with the corresponding system endpoint. The system further includes an aggregator engine configured to aggregate the first snapshot and the second snapshot from each of the system endpoints into an aggregated snapshot. The system further includes one or more analytics engines configured to: generate and store baseline profiles associated with the system endpoints based on a previously received aggregated snapshot, receive the aggregated snapshot from the aggregator engine, determine deviation values for each of the system endpoints based on the received aggregated snapshot and the stored baseline profiles, and generate, for each of the system endpoints, a cumulative risk value based on the deviation values.”), said snapshot being selectable from a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file (Fig. 8, para 0033 “ Captured data is then securely sent to a cloud-based analysis platform to determine an approved user's behavioral profile (or fingerprint) that encompasses individual metrics, activity sequences, and comparative (historical) data.. (text formats)” para 0078 “Centralized SIEM systems may detect parts of the activity (such as GeoIP connections or scanning of the internal network) from event logs produced by the operating system or monitoring of centralized network switch equipment.”), Paine does not disclose: at least multiple analysis entities said operation center being configured to monitor at least one information network comprising at least multiple assets, compromise indicator injection, wherein said multiple forensic snapshots are injected with indicators of compromise associated with at least one type of infiltration of at least one asset, representing a potential compromise or an attack scenario, investigation rating, wherein said at least multiple analysis entities are rated in multiple categories based on their performance for identifying injected forensic snapshots and associating said forensic snapshots with types of malicious activity, readiness-based grouping, wherein said at least multiple analysis entities that are rated in multiple categories are grouped based on predetermined standards for a security operation center McClintock discloses: at least multiple analysis entities said operation center being configured to monitor at least one information network comprising at least multiple assets (Col. 2 Lines 13-22 “The intrusion detection system is configured to recognize this indicator of compromise and raise alarms or enable defenses. An incident response system can process the alarms and notify security administrators. A security incident response testing service can measure the response times of the security administrators, and the testing service can also assess the actions taken by the security administrators for effectiveness. Further, the testing service can assess the effect of any automated defenses.”) compromise indicator injection, wherein said multiple forensic snapshots are injected with indicators of compromise associated with at least one type of infiltration of at least one asset, (Col. 4 Lines 53-57 “To this end, the security incident response testing service 109 automatically injects known indicators of compromise into a stream of events destined for processing by the intrusion detection system 112.” Col. 5 Lines 65 – Col. 6 Lines 5 “The event data 236 includes a stream of event data generated by the network monitoring system 221. The security incident response testing service 109 may insert fake events into the event data 236. The fabricated indicator of compromise log 239 may document the injection of fabricated events into the event data 236 by the security incident response testing service 109.”) representing a potential compromise or an attack scenario (Col. 2 Lines 36-46 “From these inputs, the security incident response testing service 109 generates an updated event stream 103b in order to test the security incident response of the organization. In the updated event stream, a fabricated indicator of compromise has been added, which corresponds to the known indicator of compromise 106. In this non-limiting example, the security incident response testing service 109 adds a fake event to the event stream 103b indicating that a particular host on the network (“host 8”) has installed a file with a signature corresponding to the signature of the known indicator of compromise 106.”) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Paine to include compromise indicator injection, wherein said multiple forensic snapshots are injected with indicators of compromise associated with at least one type of infiltration of at least one asset, representing a potential compromise or an attack scenario, as taught by McClintock. The motivation would have been to assess the effectiveness of the security incident response of the organization to a fabricated indicator of compromise. Paine in view of McClintock does not disclose: investigation rating, wherein said at least multiple analysis entities are rated in multiple categories based on their performance for identifying injected forensic snapshots and associating said forensic snapshots with types of malicious activity, readiness-based grouping, wherein said at least multiple analysis entities that are rated in multiple categories are grouped based on predetermined standards for a security operation center Gabay discloses: investigation rating, wherein said at least multiple analysis entities are rated in multiple categories based on their performance for identifying injected forensic snapshots and associating said forensic snapshots with types of malicious activity (para 0105 “ For example, the grade can be calculated utilizing the timestamps so that the faster the security analyst 130 performed the expected actions—the higher the grade is (optionally assuming that the action is the expected action). Another example is that the security analyst 130 can be required to perform the action within a certain time (e.g. within five seconds, within thirty seconds, within one minute, within five minutes, within half an hour, etc.) in order to get a score associated with the specific expected action (assuming that a given expected action needs to be completed within ten seconds, the security analyst 130 can receive a score associated with this action if he performs the given expected action within ten seconds), and the timestamp can be used to determine if the security analyst 130 performed the given expected action on time.”), readiness-based grouping, wherein said at least multiple analysis entities that are rated in multiple categories are grouped based on predetermined standards for a security operation center (para 0171 “In some cases, additionally or alternatively, the assessment system 140 can be configured to obtain information of actions performed by one or more of the security analysts 130 on the SIRS 120 and/or on one or more of the TRITS 160, and the grade can be calculated based on comparison of such actions with expected actions provided by a user authorized to determine such expected actions for the organization (e.g. a SOC manager of the organization). In some cases, the assessment system 140 can be configured to associate each action made by each security analyst 130 with a respective timestamp, and in such cases, the grade can be further calculated based on the timestamps.” The various categories of timestamps create various groups of analysts based on timestamps that are governed by the SOC manager of the organization) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Paine in view of McClintock to include investigation rating, wherein said at least multiple analysis entities are rated in multiple categories based on their performance for identifying injected forensic snapshots and associating said forensic snapshots with types of malicious activity, readiness-based grouping, wherein said at least multiple analysis entities that are rated in multiple categories are grouped based on predetermined standards for a security operation center, as taught by Gabay. The motivation would have been to on-premise cyber training to assess the effectiveness of the security incident response of security analysts within an organization. As per claim 2, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in Claim 1, wherein said multiple categories said multiple analysis entities are rated in correspond to cyberattack techniques as associated with said attack scenarios created in the compromise indicator injection step (McClintock Col. 8 Lines 42-54 “ In box 418, the security incident response testing service 109 may determine the timeliness of the response by the security administrator(s) relative to the recorded base time. For example, the security incident response testing service 109 may determine how much time elapsed between the injection of the known indicator of compromise 106 and a time when the security administrator indicated that the matter was being investigated or a later time when the security administrator indicated that the incident was a false alarm. The security incident response testing service 109 may also determine time needed for the automated functions of the intrusion detection system 112 to respond, where such automated functions are not performed at a predefined time.” Though Gabay discloses response times of security analysts wherein said multiple categories said multiple analysis entities are rated in correspond to cyberattack techniques associated with said attack scenarios created in the compromise indicator injection step. The motivation would have been to assess the effectiveness of the security incident response of the organization to a fabricated indicator of compromise.). As per claim 3, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in Claim 1, wherein said multiple categories said multiple analysis entities are rated in are more than two (Gabay discloses para 0105 “For example, the grade can be calculated utilizing the timestamps so that the faster the security analyst 130 performed the expected actions—the higher the grade is (optionally assuming that the action is the expected action). Another example is that the security analyst 130 can be required to perform the action within a certain time (e.g. within five seconds, within thirty seconds, within one minute, within five minutes, within half an hour, etc.) in order to get a score associated with the specific expected action (assuming that a given expected action needs to be completed within ten seconds, the security analyst 130 can receive a score associated with this action if he performs the given expected action within ten seconds), and the timestamp can be used to determine if the security analyst 130 performed the given expected action on time.” Though McClintock discloses categories, Gabay discloses various categories of timestamps that group the analysts by timestamps. The motivation would have been to on-premise cyber training to assess the effectiveness of the security incident response of security analysts within an organization.). As per claim 4, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in any preceding Claim 1, wherein said multiple categories said multiple analysis entities are rated in are four. (Gabay discloses para 0105 “For example, the grade can be calculated utilizing the timestamps so that the faster the security analyst 130 performed the expected actions—the higher the grade is (optionally assuming that the action is the expected action). Another example is that the security analyst 130 can be required to perform the action within a certain time (e.g. within five seconds, within thirty seconds, within one minute, within five minutes, within half an hour, etc.) in order to get a score associated with the specific expected action (assuming that a given expected action needs to be completed within ten seconds, the security analyst 130 can receive a score associated with this action if he performs the given expected action within ten seconds), and the timestamp can be used to determine if the security analyst 130 performed the given expected action on time.” Though McClintock discloses categories, Gabay discloses various categories of timestamps that group the analysts by timestamps. The motivation would have been to on-premise cyber training to assess the effectiveness of the security incident response of security analysts within an organization.). As per claim 5, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in any preceding Claim 1 wherein said method further comprises a step of training suggestion, wherein said at least multiple analysis entities that are rated in multiple categories are suggested for training based on their weaker categories that are observed to be below a predetermined threshold (McClintock Col. 9 Lines 13-29 “In box 427, the security incident response testing service 109 generates one or more response effectiveness metrics 242 (FIG. 2) assessing the response of the organization to the fabricated indicator of compromise. For example, the security incident response testing service 109 may compare the response time of the security administrator to a defined security incident SLA 245 (FIG. 2). The comparison may be a basis for scoring the response. The score may also take into account any impacts to resource availability (where large impacts would be associated with a lesser quality response), and whether expected investigative actions were performed (where omission of such actions would be associated with a lesser quality response). The score may also take into account what documentation was provided by the security administrator via the incident response system 118. The score may be a numerical score, a percentage score, a pass/fail score, or another type of score.” The response effectiveness metrics includes scoring that includes a potential pass/fail option.) Gabay discloses on paragraph 0106 “ In some cases, the assessment system 140 can be configured to provide ongoing, and optionally real-time, feedback (e.g. grades, hints, indication of correctness of actions performed by the security analysts 130, etc.) to the security analysts 130, based on actions performed thereby, and expected actions that the security analysts 130 are expected to perform (e.g. as defined by a user authorized to determine such expected actions for the organization, such as a SOC manager of the organization. Para 0108 “In some cases, management server 170 can enable a user authorized to control training of the security analysts 130 of the organization (e.g. a SOC manager of the organization) to monitor progress of the security analysts 130 during the training exercise. In some cases, the management server 170 can be further configured to enable such user to provide one or more selected security analysts 130, or all security analysts 130, with instructions and/or feedback (e.g. hints, text messages, voice messages, etc.), optionally during the training exercise.” The combination of McClintock response effectiveness metrics includes scoring that includes a potential pass/fail and Gabay ongoing testing with feedback and grading would produce training suggestion, wherein said at least multiple analysis entities that are rated in multiple categories are suggested for training based on their weaker categories that are observed to be below a predetermined threshold The motivation would have been to on-premise cyber training to assess the effectiveness of the security incident response of security analysts within an organization.). As per claim 6, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in any preceding Claim 1, wherein said indicators of compromise are selected from a collection of threat groups documented according to the MITRE ATT&CK framework (McClintock Col. 3 Lines 54-65 “The indicators of compromise ingestion service 218 is executed to receive data describing known indicators of compromise from internal and/or external sources. For example, the indicators of compromise ingestion service 218 may receive periodic data feeds from other organizations using structured thread information expression (STIX), trusted automated exchange of indicator information (TAXII), and/or other formats and protocols. The indicators of compromise ingestion service 218 may choose to include or exclude various indicators of compromise provided by external sources based at least in part on predefined rules.” Though Paine discloses indicators of compromise, McClintock indicators of compromise are selected from known enterprise-level techniques, such as those of APT28. The motivation would have been to assess the effectiveness of the security incident response of the organization to a fabricated indicator of compromise.). As per claim 7, Paine in view of McClintock and Gabay discloses: A method of digital forensics investigation suitable for a security operation center as set forth in Claim 1 wherein said indicators of compromise are selected from known enterprise-level techniques, such as those of APT28. (McClintock Col. 3 Lines 54-65 “The indicators of compromise ingestion service 218 is executed to receive data describing known indicators of compromise from internal and/or external sources. For example, the indicators of compromise ingestion service 218 may receive periodic data feeds from other organizations using structured thread information expression (STIX), trusted automated exchange of indicator information (TAXII), and/or other formats and protocols. The indicators of compromise ingestion service 218 may choose to include or exclude various indicators of compromise provided by external sources based at least in part on predefined rules.” Though Paine discloses indicators of compromise, McClintock wherein said indicators of compromise are selected from a collection of threat groups documented according to the MITRE ATT&CK framework. The motivation would have been to assess the effectiveness of the security incident response of the organization to a fabricated indicator of compromise.). Conclusion 16. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent No. 10102379 discloses on Col. 1 Lines 41-51 “In an implementation, published enterprise threat detection (ETD) security notes are accessed in a computer data store. Applicability of the published ETD security notes are determined for an information technology computing (IT) landscape. A determination is made that a particular applicable ETD security note has not yet been implemented in the IT computing landscape. Aggregated impact of compromise (IoC) and state of compromise (SoC) values associated with the published ETD security note are analyzed and a computing system patching action is performed based on the aggregated IoC and SoC values.” Any inquiry concerning this communication or earlier communications from the examiner should be directed to GARY S GRACIA whose telephone number is (571)270-5192. The examiner can normally be reached Monday-Friday 9am-6pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GARY S GRACIA/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Mar 17, 2025
Application Filed
Aug 28, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750243
SYSTEMS AND METHODS FOR PRESERVING PRIVACY OF A REGISTRANT IN A DOMAIN NAME SYSTEM ("DNS")
3y 3m to grant Granted Sep 29, 2026
Patent 12748873
SYSTEMS AND METHODS FOR DATA CLASSIFICATION AND GOVERNANCE
3y 5m to grant Granted Sep 29, 2026
Patent 12743501
DEVICE, METHOD, AND SYSTEM TO DETERMINE AN ACCESS TO A TRUSTED EXECUTION ENVIRONMENT
3y 9m to grant Granted Sep 22, 2026
Patent 12737487
METHOD FOR MANAGING ACCESS TO A FILE FOR NON-VOLATILE MEMORY
1y 6m to grant Granted Sep 15, 2026
Patent 12730915
SYSTEM AND METHOD FOR AUTHENTICATION USING TOKENIZATION OF A RESOURCE PRIOR TO RESOURCE ALLOCATION
3y 3m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+48.0%)
3y 4m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 571 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month