Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 04/04/2025 was filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Objections
Regarding claims 1 and 17, Claims 1 and 17 are objected to because of the following informalities: The claims first recite “a semantically harmonized representation” and later recite “harmonized data”. Although the intended relationship may be inferable, consistent terminology should be used. Appropriate correction is required.
Regarding claim 5, Claim 5 is objected to because of the following informalities: The claim recite “per segment” which is imprecise and the relationship between claimed segments and the recited zone, region or application groups is not clearly stated. Examiner suggest to amend the claim to “wherein the risk posture is divided into a plurality of segments, each segment corresponding to a respective zone, region, or application group, and wherein a respective exposure score is computed for each segment”. Appropriate correction is required.
Regarding claim 7, Claim 7 is objected to because of the following informalities: The phrase recites “wherein the continuously evaluating includes continuous scanning” is grammatically awkward. Applicant is required to amend the claim to identify the underlying operation more clearly. Examiner suggest to amend the claim to “wherein the continuously evaluating the semantically harmonized representation comprises includes continuous scanning the computing environment for threats, misconfigurations, and vulnerabilities”. Appropriate correction is required.
Regarding claim 9, Claim 9 is objected to because of the following informalities: The phrase “attack likelihood” should read “an attack likelihood”. Appropriate correction is required.
Regarding claim 10, Claim 10 is objected to because of the following informalities: The phrase “new threat signatures” is informal relative to the claimed updating operation. It is unclear whether the claim intends newly received signatures, newly generated signatures or newly identified signatures. Applicant is required to amend the phrase to more precisely reflect the indented operations. Appropriate correction is required.
Regarding claim 12, Claim 12 is objected to because of the following informalities: The phrase “generating an uber node representing each asset.” Could grammatically be interpreted as generating one Uber node that collectively represents every asset. Applicant is required to clarify that a respective uber node is generated for each deduplicated asset. Examiner suggest to amend the claim to “generating, for each deduplicated asset, a respective uber node representing the deduplicated asset”. Appropriate correction is required.
Regarding claim 14, Claim 14 is objected to because of the following informalities: The phrase “CMDB update” may infer either to updating a CMDB record or updating the CMDB software or system itself. Applicant is required to replace “CMDB update” with “updating a CMDB records for exposed asset”. Appropriate correction is required.
Regarding claim 17, Claim 17 is objected to because of the following informalities: The phrase “one or more processors and memory” should read ““one or more processors and a memory”. Appropriate correction is required.
Regarding claim 18, Claim 18 is objected to because of the following informalities: The phrase “cause the one or more processors to: ingest vulnerability data from a plurality of scanners and threat intelligence sources, and correlating the vulnerability data with asset inventory and contextual telemetry” should read ““cause the one or more processors to ingest vulnerability data from a plurality of scanners and threat intelligence sources, and corelate the vulnerability data with asset inventory and contextual telemetry”. The colon following “to” is unnecessary and the verb are not grammatically parallel. Appropriate correction is required.
Regarding claims 19 and 20 , Claims 19 and 20 are objected to because of the following informalities: The colon following “to” is unnecessary where only a single operation follows. Thus, claim 19 should recite “cause the one or more processors to generate a topological map…” and claim 20 should recite “cause the one or more processors to generate exposure reports and visual dashboards …”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 3, 9, and 10 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 3 recites “ exposure data includes detection of external-facing assets lacking authentication, use of insecure protocols, or misconfigured firewall rules” . The phrase “exposure data” lacks antecedent basis. Claim 1 recites “cybersecurity data”, “ingested data”, “harmonized data”, “potential exposures”, and “exposure metrics” , but does not previously introduce “exposure data”. Thus, it is unclear whether exposure date refers to cybersecurity data, ingested data, harmonized data, potential exposures, and exposure metrics. Dependent claims are also rejected for inheriting the deficiencies set forth above for independent claims. Appropriate correction is required.
Claim 9 recites “wherein prioritization of remediation is based on attack likelihood computed using threat intelligence, exploitability, and exposure window duration”. Neither claim 9 nor its parent claims expressly recites an act of “prioritizing remediation”. Claim 1 recites triggering automated remediation workflows based on policy defined thresholds, but does not expressly recite prioritizing the remediation workflows. Additionally, the phrase “exposure window duration” does not identify the beginning and ending events defining the claimed duration. It is unclear whether the duration refers to a period since an exposure was initially detected, a period during which an asset is externally accessible or a period before remediation occurs. Examiner suggest applicant to clarify the scope of the claim. Dependent claims are also rejected for inheriting the deficiencies set forth above for independent claims. Appropriate correction is required.
Claim 10 recites “updating risk posture metrics”, whereas claim 1 recites “a risk posture” generated by aggregating “exposure metrics”. It is unclear whether the claimed “risk posture metrics” are the previously recited exposure matrices, separate metrics generated from the exposure metrics or metrics representing the resulting risk posture. Claim 10 further recites that the metrics are updated “at defined intervals based on telemetry, scan frequency, and new threat signatures”. It is unclear whether telemetry , scan frequency and threat signatures determine the timing of the defined intervals or instead provide substantive data used to update the metric values. In particular, “scan frequency” itself identifies a frequency, while telemetry and threat signatures identify data rather than an interval. Examiner suggest applicant to clarify the scope of the claim. Dependent claims are also rejected for inheriting the deficiencies set forth above for independent claims. Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-11, 13, 15, and 17-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Independent claims 1, and 17:
Step1:
Claims 1 is drawn to “a method”, and claim 17 is drawn to “a system”, therefore each of these claim groups falls under one of four categories of statutory subject matter (process/method, machines/products/apparatus, manufactures, and compositions of matter).
Step 2A, Prong 1:
Claims 1, and 17 are directed to a judicially recognized exception of an abstract idea without significantly more. Each of claims 1, and 17recites limitations “ingesting cybersecurity data from a plurality of heterogeneous sources into a data fabric, wherein the sources comprise cybersecurity monitoring systems, cloud service providers, configuration management databases (CMDBs), and endpoint telemetry feeds”, “normalizing and correlating the ingested data into a semantically harmonized representation using a security knowledge graph implemented in the data fabric, the representation comprising entities including users, devices, applications, vulnerabilities, misconfigurations, or policies”, “continuously evaluating harmonized data in the security knowledge graph to detect potential exposures based on predefined controls and graph traversal logic”, “generating a risk posture by aggregating exposure metrics associated with entities in the security knowledge graph, wherein the risk posture is dynamically updated in response to newly ingested data” and “triggering automated remediation workflows based on policy-defined thresholds, wherein the workflows are executed in response to detected exposures to reduce an attack surface of the computing environment” that under its broadest reasonable interpretation, enumerates abstract ideas and a mental process. Other than reciting a generic “one or more processors” (Claim 17), nothing in the claims preclude the steps from practically being performed in the human mind. For example, other than the “computer processors” language, the claims encompass a user visually and manually collect and organize cybersecurity information, evaluate the information according to predetermined criteria to identify exposure and risk, and determine whether responsive action should be initiated. The mere nominal recitation of a generic computer component (computer processor) to automate the mental concepts does not take the claim limitations out of the as such, the steps of corelating, evaluating, comparing with controls or thresholds, aggregating metrics, identifying exposures, and determining responsive actions are nothing more than abstract mental concepts (See MPEP 2106.04(a)(2)(I)(III)).
Step 2A, Prong 2:
Claim 1 does not recite any additional elements/or steps that would integrate the abstract idea into a practical application. However, claim 17 recites additional element “memory” to store computer program instructions and “one or more processors” to execute the computer program instructions. The computer memory and the computer processor are recited at a high level of generality (i.e., as generic computer components performing generic computer functions to store and to process data respectively). These generic computer functions are no more than mere instructions to apply the exception using generic computer components. The combination of these additional elements does not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea (MPEP 2106.05(f)).
Step 2B:
The additional elements “memory” to store computer program instructions and “one or more processors” to execute the computer program instructions are no more than generic, off-the-shelf computer components, and the Symantec, TLI, OIP Techs, and Versata court decisions cited in MPEP 2106.05(d)(II) indicate that mere collection/receipt of data over a network and/or storing and retrieving information in memory are well-understood, routine, and conventional functions when it is claimed in a merely generic manner as well as other additional elements heterogeneous cybersecurity data sources, a data fabric, a security knowledge graph, graph traversal logic, continuous or dynamic computer processing, automated workflow triggering, reports and dashboards individually and in combination does not integrate the identified abstract idea into practical application. The claims do not recite a particular graph structure, data normalization mechanism, traversal algorithm, improved computer architecture or specific technical remediation action Instead these elements generally perform data gathering, generic computer processing information organization and presentation of results, (See MPEP 2106.05(d)(II)(IV)). As such, claims 1, and 17 are not patent eligible.
Dependent claims 2-11, 13, 15, and 18-20:
Step 1:
Claims 2-11, 13, and 15 are drawn to “a method” and 18-20 are drawn to “system” therefore each of these claims falls under one of four categories of statutory subject matter (process/method, machines/products/apparatus, manufactures, and compositions of matter).
Steps 2A-2B:
Dependent claims 2-11, 13, 15, and 18-20 are also ineligible for the same reasons given with respect to claims 1 and 17. Claims 2-11, 13, 15, and 18-20 recite further abstract mental concept of further define the cybersecurity information collected, the condition being detected, the factors used to calculate or prioritize risk, the frequency or evaluation and reports, maps, dashboards, and inventories displaying the analytical results (MPEP 2106.04(a)(2)(I)). Claims 2-13 and 15-19 fail to recite any additional elements/steps that might integrates the abstract idea into a practical application. As such, claims 2-13 and 15-19 are not patent eligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-8, 10,11, 13-15, and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree (US 20220232040 A1) in view of Gill (US 20150281287 A1).
Regarding claim 1, Crabtree teaches a method for continuous exposure management in a computing environment (Crabtree, continuously monitor, process and explore incoming data for subtle changes or diffuse informational threads 353 and generate cyber-physical systems graphing 354 as part of the advanced cyber decision platform's common capabilities, [0091]), comprising:
ingesting cybersecurity data from a plurality of heterogeneous sources into a data fabric, wherein the sources comprise cybersecurity monitoring systems, cloud service providers, configuration management databases (CMDBs), and endpoint telemetry feeds (Crabtree, Much of the business data analyzed by the system both from sources within the confines of the client business, and from cloud based sources (i.e., cloud service providers),, also enter the system through the cloud interface 110, data being passed to the connector module 135 which may possess the API routines 135a needed to accept and convert the external data and then pass the normalized information to other analysis and transformation components of the system, the directed computational graph module 155, high volume web crawler module 115, multidimensional time series database (MDTSDB) 120 and the graph stack service 145. The directed computational graph module 155 retrieves one or more streams of data from a plurality of sources, which includes, but is in no way not limited to, a plurality of physical sensors, network service providers, web based questionnaires and surveys, monitoring of electronic infrastructure, crowd sourcing campaigns, and human input device information, [0080] Input network data which may include network flow patterns 321, the origin and destination of each piece of measurable network traffic 322, system logs from servers and workstations on the network 323, endpoint data 323(i.e., a endpoint telemetry feeds), any security event log data from servers or available security information and event (SIEM) systems 324, external threat intelligence feeds 324a (i.e., cybersecurity monitoring systems), , identity or assessment context 325, external network health or cybersecurity feeds 326, Kerberos domain controller or ACTIVE DIRECTORY™ server logs or instrumentation 327 and business unit performance related data 328, among many other possible data types for which the invention was designed to analyze and integrate, may pass into 315 the advanced cyber decision platform 310 for analysis as part of its cyber security function. These multiple types of data from a plurality of sources may be transformed for analysis 311, [0091] an advanced cyber decision platform may monitor all information about a network 1801, including (but not limited to) device telemetry data, log files, connections and network events, deployed software versions, or contextual user activity information. This information is incorporated into a CPG 1802 to maintain an up-to-date model of the network in real-time, [0137] some aspects may make use of one or more security systems 36 and configuration systems 35., (i.e., configuration management databases (CMDBs)) ) [Examiner interprets that system teaching integrated architecture connecting heterogenous sources transforming /normalizing data, and making the information available to graph and analytical services as limitation above];
normalizing and correlating the ingested data into a semantically harmonized representation using a security knowledge graph implemented in the data fabric, the representation comprising entities including users, devices, applications, vulnerabilities, misconfigurations, or policies (Crabtree, information is obtained about the client network 1907 and the client organization's operations, which is used to construct a cyber-physical graph 1902 representing the relationships between devices, users, resources, and processes in the organization, and contextualizing cybersecurity information with physical and logical relationships that represent the flow of data and access to data within the organization, [0101] A cyber-physical graph, in its most basic form, is a knowledge graph representing the network devices comprising an organization's network infrastructure as nodes (also called vertices) in the graph and the physical or logical connections between them as edges between the nodes…. The cyber-physical graph may be expanded to include network information and processes such as data flow, security protocols and procedures, and software versions and patch information. A cyber-security graph may be further expanded to include internal process information such as business processes, loss information, and legal requirements and documents; external information such as domain and IP information, data breach information; and generated information such as open port information from external network scans, and vulnerabilities and avenues of attack. Thus, a cyber-physical graph may be used to represent a complete picture of an organization's infrastructure and operations, [0114] connector module 135 which may possess the API routines 135a needed to accept and convert the external data and then pass the normalized information to other analysis and transformation components of the system, [0081] The natural language processor 2504 uses the information extracted from the structured data as training data to search, identify, and tag the unstructured data, thereby converting it to structured data, [0124] The newly structured data (created from unstructured data) are sent to the database 2507, where they are combined into one or more data stores for querying. .. The databases may then be processed by a graphical representation service 2508, which transforms data into graphical representations for relational analysis, [0125]) [Examiner interprets that system normalizing external data, converting structured and unstructured data into common structured forms, combining data, corelating data, and transforming it into graphical representation as limitation above];
continuously evaluating harmonized data in the security knowledge graph to detect potential exposures based on predefined controls and graph traversal logic (Crabtree, A data to rule mapper 1904 is used to retrieve laws, policies, and other rules from an authority database 1903 and compare reconnaissance data received from the reconnaissance engine 1906 and stored in the reconnaissance data storage 1905 against the rules in order to determine whether and to what extent the data received indicates a violation of the rules, [0100] a comprehensive set of data containing all identified or suspected vulnerabilities associated with all levels of the software supply chain is created. A comprehensive cybersecurity threat assessment based on the totality of vulnerabilities from all levels of the software supply chain may be performed by processing the cyber-physical graph by running graph analysis algorithms such as shortest path algorithms, minimum cost/maximum flow algorithms, strongly connected node algorithms, etc., to identify the probabilities of success of cyberattacks through a given vulnerability and the impact of a successful cyberattack, [0117] his system not only analyzes static code features, but dynamically updates on a periodic or continuous basis to capture cybersecurity risks associated with dynamic effects in the software supply chain…. The cyber-physical graph is then re-analyzed to identify new or changed vulnerability paths in the software supply chain, [0118] the combined data of the CPG and the known vulnerabilities may then be analyzed 1203 to identify the relationships between known vulnerabilities and risks exposed by components of the infrastructure, [0131]) [Examiner interprets that system continuously or periodically updating graph, reanalyzing of the updated graph, detecting vulnerabilities and exposed infrastructure, applying policies and rules, shortest path flow, and connected node algorithms as limitation above];
generating a risk posture by aggregating exposure metrics associated with entities in the security knowledge graph, wherein the risk posture is dynamically updated in response to newly ingested data (Crabtree, run one or more graph-processing algorithms on the cyber-physical graph to determine one or more paths of vulnerability in the software supply chain and a probability of occurrence for each path; and generate a cybersecurity score for the software application based on the vulnerabilities in the software supply chain, [0032] The cybersecurity profile 1918 is sent to the scoring engine 1910 along with event and loss data 1914 and context data 1909 for the scoring engine 1910 to develop a score and/or rating for the organization that takes into consideration both the cybersecurity profile 1918, context, and other information., [0101] Patches, updates, deprecations, changes to EULAs and other licenses, are monitored and updated as they occur, and changes to the software supply chain are propagated through the cyber-physical graph. The cyber-physical graph is then re-analyzed to identify new or changed vulnerability paths in the software supply chain, [0118] a baseline score can be used to measure an overall level of risk for a network infrastructure,[0131] When a new vulnerability is discovered, a blast radius score may be assessed 1803 and the network's resiliency score may be updated 1804 as needed, [0137]) [Examiner interprets that a cybersecurity profile, cybersecurity score, rating, baseline risk score, blast radius score or resiliency score as risk posture and system dynamically updating graph and associated scores when new events or vulnerabilities are ingested as limitation above]; and
triggering automated remediation workflows, wherein the workflows are executed in response to detected exposures to reduce an attack surface of the computing environment (Crabtree, A data to rule mapper 1904 is used to retrieve laws, policies, and other rules from an authority database 1903 and compare reconnaissance data received from the reconnaissance engine 1906 and stored in the reconnaissance data storage 1905 against the rules in order to determine whether and to what extent the data received indicates a violation of the rules. Machine learning models 1901 may be used to identify patterns and trends in any aspect of the system, but in this case are being used to identify patterns and trends in the data which would help the data to rule mapper 1904 determine whether and to what extent certain data indicate a violation of certain rules, [0100] Vulnerabilities exceeding certain parameters can be established to trigger warnings, alarms, and alerts to notify administrators of cybersecurity threat/risk levels that exceed the established parameters, and identify precisely which components in the supply chain are causing the threat/risk, so those components can be addressed (e.g., by removing that component, service, etc., from the software application or eliminating its use by the software application), [0118] These anomalous behaviors may then be used 804 to analyze potential angles of attack and then produce 805 security suggestions based on this second-level analysis and predictions generated by an action outcome simulation module 125 to determine the likely effects of the change. The suggested behaviors may then be automatically implemented 806 as needed, [0126] A security alert may then be produced 1805 to notify an administrator of the vulnerability and its impact, and a proposed patch may be presented 1806 along with the predicted effects of the patch on the vulnerability's blast radius and the overall network resiliency score, [0137]);
Although, Crabtree teaches configuration systems 35., (i.e., configuration management databases (CMDBs) and triggering warning and alerts, [0118], automatically implementing suggested behaviors [0126],and combining distinct passages from separate embodiments may support obviousness, but Crabtree it does not explicitly teach:
Ingesting data from configuration management databases (CMDBs); triggering automated remediation workflows based on policy-defined thresholds
However, Gill teaches:
Ingesting data from configuration management databases (CMDBs) (Gill, Alert enterprise system 100 contains a connector framework that provides an open and pre-defined set of data connectors (connector types) to gather data for each solution through the data controller, [0103] alert enterprise system 100 can pull-in control results from security automation like vulnerability scanners, CMDBs, SIEMs, Integrated Security Managers (e.g. Symantec ESM and McAfee ePolicy Orchestrator) and DLP systems. Combining the test results from security automation tools that check for security gaps and vulnerabilities with control results from evaluation of business processes risk delivers the most comprehensive view of risk and compliance across the organization., [0557]);
triggering automated remediation workflows based on policy-defined thresholds (Gill, take automated remedial action, [0196] a risk engine 622 that manages the correlation of user access and activity events with a risk/rule library. Alert enterprise system 100 may be configured to automatically initiate a workflow action when potential security and compliance risk are detected, [0215] a policy engine that follows a pre-defined business process workflow for manual as well as automated completion of tasks of the organization, [0124] Each workflow has a set of conditions on which the workflow is initiated, [0129] Remediation scripts associated with the alerts can be pre-configured to execute at a specified time or trigger based on a particular event, [0484]).
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree to include a concept of Ingesting data from configuration management databases (CMDBs); triggering automated remediation workflows based on policy-defined thresholds as taught by Gill for the purpose of performing threat and fraud detection, risk analysis and remediation, active policy enforcement and continuous monitoring, [Gill: 0016] and automatically initiating a workflow action when potential security and compliance risk are detected, [Gill:0215].
Regarding claim 2, Crabtree and Gill teaches the method of claim 1, further comprising ingesting vulnerability data from a plurality of scanners and threat intelligence sources, and correlating the vulnerability data with asset inventory and contextual telemetry (Crabtree, When performing a port scan, web crawler 115 may employ a variety of software suitable for the task, such as Nmap, ZMap, or masscan, [0086] Input network data which may include network flow patterns 321, the origin and destination of each piece of measurable network traffic 322, system logs from servers and workstations on the network 323, endpoint data 323a, any security event log data from servers or available security information and event (SIEM) systems 324, external threat intelligence feeds 324a, identity or assessment context 325, external network health or cybersecurity feeds 326, ..which the invention was designed to analyze and integrate, may pass into 315 the advanced cyber decision platform 310 for analysis as part of its cyber security function. These multiple types of data from a plurality of sources may be transformed for analysis 311,[0091] the combined data of the CPG and the known vulnerabilities may then be analyzed 1203 to identify the relationships between known vulnerabilities and risks exposed by components of the infrastructure. This produces a combined CPG 1204 that incorporates both the internal risk level of network resources, user accounts, and devices as well as the actual risk level based on the analysis of known vulnerabilities and security risks, [0131] an advanced cyber decision platform may monitor all information about a network 1801, including (but not limited to) device telemetry data, log files, connections and network events, deployed software versions, or contextual user activity information. This information is incorporated into a CPG 1802 to maintain an up-to-date model of the network in real-time., [0137] Third party search tools 1915 for domain and IP address searching tasks 2011 include, for example, DNSDumpster, Spiderfoot HX, Shodan, VirusTotal, Dig, Censys, ViewDNS, and CheckDMARC, among others. These tools may be used to obtain reconnaissance data about an organization's server IPs, software, geolocation; open ports, patch/setting vulnerabilities; data hosting services, among other data 2031, [0138]) [Examiner interprets that system constructing cyber physical graph representing the organization asset and correlation of known vulnerabilities and infrastructure components as limitation above].
Regarding claim 4, Crabtree and Gill teaches the method of claim 1, further comprising generating a topological map of the attack surface using the security knowledge graph, showing relationships between assets, identities, and vulnerabilities (Crabtree, MDTSDB 120 and graph stack 145 may be used to produce a hybrid graph/time-series database using the analyzed data, forming a graph of Internet-accessible organization resources and their evolving state information over time, [0087] cyber-physical graph showing a software supply chain represented as a directed graph with identification of the sources of specific software components and possible vulnerabilities. A cyber-physical graph represents the relationships between entities associated with an organization, for example, devices, users, resources, groups, and computing services, the relationships between the entities defining relationships and processes in an organization's infrastructure, thereby contextualizing security information with physical and logical relationships that represent the flow of data and access to data within the organization including, in particular, network security protocols and procedures, A cyber-physical graph, in its most basic form, is a knowledge graph representing the network devices comprising an organization's network infrastructure as nodes (also called vertices) in the graph and the physical or logical connections between them as edges between the nodes. The cyber-physical graph may be expanded to include network information and processes such as data flow, security protocols and procedures, and software versions and patch information. Further, human users and their access privileges to devices and assets may be included. A cyber-security graph may be further expanded to include internal process information such as business processes, loss information, and legal requirements and documents; external information such as domain and IP information, data breach information; and generated information such as open port information from external network scans, and vulnerabilities and avenues of attack. Thus, a cyber-physical graph may be used to represent a complete picture of an organization's infrastructure and operations, [0114]) [Examiner interprets that system generating graph visualization that shows assets such as servers, devices, resources, applications, and services, identities such as users and accounts, physical and logical relationships, vulnerabilities, and avenues of attack as limitation above].
Regarding claim 5, Crabtree and Gill teaches the method of claim 1, wherein the risk posture is segmented by zone, region, or application group, and exposure scores are computed per segment (Gill, Geo spatial services: An embodiment provides a geo spatial service that is manifested as a subsystem that helps in tracking down the risk to a particular geographical location. This module provides the inside view of what exactly is happening at the site where the risk is detected. In an embodiment, such subsystem is actively used in the subsystem, AlertAction, which may be specifically designed for drilling down the location where risk is reported. This service may be actively used for risk monitoring and remediation that provides geospatial remediation of cross-enterprise threats, cross-application and cross-subsystem threats, serious acts of sabotage, terrorism, fraud and theft, etc. such geo spatial services co-relates seemingly innocent events and activities to detect real threats and risks and generates powerful alerting and automatic remedial action strategies for decisive action, [0128] Geospatial capabilities automatically pin-point the location of the incident and provide drill-down capability for optimum response, [0464] Enterprise level solution with ability to report by organizations, processes, areas etc and encourage collaboration among business users, [0538] Users having access to critical zones, [0587]) Same motivation applies as claim 1.
Regarding claim 6, Crabtree and Gill teaches the method of claim 1, further comprising generating exposure reports and visual dashboards showing trends over time and surfacing emerging high-risk asset clusters (Crabtree, value at risk (VAR) modeling and simulation 341, anticipatory vs. reactive cost estimations of different types of data breaches to establish priorities 342, work factor analysis 343 and cyber event discovery rate 344 as part of the system's risk analytics capabilities; and the ability to format and deliver customized reports and dashboards 351, perform generalized, ad hoc data analytics on demand 352, continuously monitor, process and explore incoming data for subtle changes or diffuse informational threads 353 and generate cyber-physical systems graphing 354 as part of the advanced cyber decision platform's common capabilities, [0091] customize reports and dashboards to specific audiences, [0092] Machine learning models 1901 may be used to identify patterns and trends in any aspect of the system, [0100] To provide proactive security recommendations through a simulation module 125, simulated intrusions may be run 904 to identify potential blast radius calculations for a variety of attacks and to determine 905 high risk accounts or resources so that security may be improved in those key areas rather than focusing on reactive solutions, [0128] This information may be received continuously, passively collecting events and monitoring activity over time while feeding 1002 collected information into a graphing service 145 for use in producing time-series graphs 1003 of states and changes over time, This collated time-series data may then be used to produce a visualization 1004 of changes over time, [0129]) [Examiner interprets that system producing reports, visual dashboards, timeseries graphs, trends and changes overtime, identifying high risk accounts and resources, using machine learning for identifying pattern and trends as limitation above].
Regarding claim 7, Crabtree and Gill teaches the method of claim 1, wherein the continuously evaluating includes continuous scanning for threats, misconfigurations, and vulnerabilities across the computing environment (Crabtree, perform generalized, ad hoc data analytics on demand 352, continuously monitor, process and explore incoming data for subtle changes or diffuse informational threads 353 and generate cyber-physical systems graphing 354 as part of the advanced cyber decision platform's common capabilities… detect presence of malware 366, and perform one time or continuous vulnerability scanning depending on client directives 367, [0091] dynamically updates on a periodic or continuous basis to capture cybersecurity risks associated with dynamic effects in the software supply chain, [0118] dynamic network and rogue device discovery, according to one aspect. According to the aspect, an advanced cyber decision platform may continuously monitor a network in real-time 1601, detecting any changes as they occur. When a new connection is detected 1602, a CPG may be updated 1603 with the new connection information, which may then be compared against the network's resiliency score 1604 to examine for potential risk. The blast radius metric for any other devices involved in the connection may also be checked 1605, to examine the context of the connection for risk potential (for example, an unknown connection to an internal data server with sensitive information may be considered a much higher risk than an unknown connection to an externally-facing web server), [0135] advanced cyber decision platform may monitor all information about a network 1801, including (but not limited to) device telemetry data, log files, connections and network events, deployed software versions, or contextual user activity information. This information is incorporated into a CPG 1802 to maintain an up-to-date model of the network in real-time, [0137]) [Examiner interprets that system continuously monitoring and scanning vulnerability across organizational network infrastructures as limitation above].
Regarding claim 8, Crabtree and Gill teaches the method of claim 7, further comprising identifying high-risk exposure paths based on graph traversal between vulnerable assets and sensitive data stores on the security knowledge graph (Crabtree, run one or more graph-processing algorithms on the cyber-physical graph to determine one or more paths of vulnerability in the software supply chain and a probability of occurrence for each path, [0032] A comprehensive cybersecurity threat assessment based on the totality of vulnerabilities from all levels of the software supply chain may be performed by processing the cyber-physical graph by running graph analysis algorithms such as shortest path algorithms, minimum cost/maximum flow algorithms, strongly connected node algorithms, etc., to identify the probabilities of success of cyberattacks through a given vulnerability and the impact of a successful cyberattack, [0117] impact assessment of an attack may be measured using a DCG 155 to analyze a user account and identify its access capabilities 901 (for example, what files, directories, devices or domains an account may have access to). This may then be used to generate 902 an impact assessment score for the account, representing the potential risk should that account be compromised, In the event of an incident, the impact assessment score for any compromised accounts may be used to produce a “blast radius” calculation 903, identifying exactly what resources are at risk as a result of the intrusion and where security personnel should focus their attention, [0128] to contextualize impact assessment scores within the infrastructure (for example, so that it may be predicted what systems or resources might be at risk for any given credential attack), [0134]) [Examiner interprets that system identifying high risk vulnerability or attack paths using graph traversal by accessing files directories, devices, resources, and data within the graph as limitation above].
Regarding claim 10, Crabtree and Gill teaches the method of claim 7, further comprising updating risk posture metrics at defined intervals based on telemetry, scan frequency, and new threat signatures (Gill, The data may be collected through relational databases, XML, RSS, PI, Excel, ERP applications (i.e. Asset management, Workforce management, Outage management, Network management, and Customer Billing), Geo and Custom data feeds. The frequency of the data updates may be modified through a design module…The data may be synchronized from the source systems to alert enterprise system 100 solutions in many ways. Some of such ways are, but are not limited to (a) batch mode—extracts the data in predefined frequency, (b) real-time connectivity from the source systems for on need basis look up for the data, and (c) event mode in both push and pull methodologies depends on the need, [0103] Scheduling: An embodiment enables a user to get information about scheduled data synchronization jobs. The user may create the jobs and schedule the jobs according to business or other particular needs and perform the desired operation accordingly, a provided interface may provide one screen hot spot to get information about the jobs scheduled for risk analysis, extractor, rule engine, mitigation, etc. For example, a user may schedule risk analysis on a weekly basis, [0123] an engine that analyzes data from diverse systems across the enterprise for rendering risk following the detection of blended threats.. Accept external feeds, e.g. iDefense Labs by VeriSign, Inc. in Sterling, Va., National Vulnerability Database (NVD), by the National Institute of Standards and Technology, United States of America, and other threat sources for correlation and risk mapping, [0157] FIG. 13 is a sample screen showing how a user may track and log privileged access for IT applications as well as physical access to facilities and critical assets, thus providing a complete risk posture across many applications. In particular, FIG. 13 shows a list of events that took place during an individual's privileged access session. High risk items are automatically identified, [0401]) [Examiner interprets that system updating risk related data at defined intervals via scheduled jobs, batch updates, event updates, and real time synchronization, telemetry maps to logs/events/security events. Scan frequency maps to scheduled extractor/risk analysis jobs and vulnerability scanner inputs, new threat signatures maps to external threat feeds such as NVD and other threat sources].
Regarding claim 11, Crabtree and Gill teaches the method of claim 1, wherein the data fabric aggregates asset metadata from security and IT management tools to construct a unified asset inventory (Crabtree, Much of the business data analyzed by the system both from sources within the confines of the client business, and from cloud based sources, also enter the system through the cloud interface 110, data being passed to the connector module 135 which may possess the API routines 135a needed to accept and convert the external data and then pass the normalized information to other analysis and transformation components of the system, [0080] Input network data which may include network flow patterns 321, the origin and destination of each piece of measurable network traffic 322, system logs from servers and workstations on the network 323, endpoint data 323a, any security event log data from servers or available security information and event (SIEM) systems 324, external threat intelligence feeds 324a, identity or assessment context 325, external network health or cybersecurity feeds 326, [0091] information is obtained about the client network 1907 and the client organization's operations, which is used to construct a cyber-physical graph 1902 representing the relationships between devices, users, resources, and processes in the organization, and contextualizing cybersecurity information with physical and logical relationships that represent the flow of data and access to data within the organization including, in particular, network security protocols and procedures, [0101] Thus, a cyber-physical graph may be used to represent a complete picture of an organization's infrastructure and operations, [0114] an advanced cyber decision platform may monitor all information about a network 1801, including (but not limited to) device telemetry data, log files, connections and network events, deployed software versions, or contextual user activity information, [0137]) [Examiner interprets that system aggregating metadata from numerous security and enterprise management information sources and constructing cyber physical graph that represents complete picture containing devices, users, software, resources, services, configurations, vulnerabilities, and relationships as limitation above].
Regarding claim 13, Crabtree and Gill teaches the method of claim 1, wherein the data fabric correlates exposure indicators with asset criticality to identify exposed or misconfigured assets (Crabtree, At the purchaser level 2250, the primary risk introduced into the supply chain is improper use of the application or improper security settings established by the purchaser 2250 or its IT department, [0112] impact assessment of an attack may be measured using a DCG 155 to analyze a user account and identify its access capabilities 901 (for example, what files, directories, devices or domains an account may have access to). This may then be used to generate 902 an impact assessment score for the account, representing the potential risk should that account be compromised, In the event of an incident, the impact assessment score for any compromised accounts may be used to produce a “blast radius” calculation 903, identifying exactly what resources are at risk as a result of the intrusion and where security personnel should focus their attention.. run 904 to identify potential blast radius calculations for a variety of attacks and to determine 905 high risk accounts or resources, [0128] the combined data of the CPG and the known vulnerabilities may then be analyzed 1203 to identify the relationships between known vulnerabilities and risks exposed by components of the infrastructure, [0131] The blast radius metric for any other devices involved in the connection may also be checked 1605, to examine the context of the connection for risk potential (for example, an unknown connection to an internal data server with sensitive information may be considered a much higher risk than an unknown connection to an externally-facing web server), [0135]) [Examiner interprets that system corelating vulnerabilities and other exposure indicators, infrastructure components to calculate impact scores, high value status, sensitivity of affected resource and combined analysis identifying assets that are exposed to known vulnerabilities and asset whose settings create security risks as limitation above].
Regarding claim 14, Crabtree and Gill teaches the method of claim 13, further comprising applying policy-driven remediation such as access restriction, ticket generation, or CMDB update for exposed assets (Gill, a risk engine 622 that manages the correlation of user access and activity events with a risk/rule library. Alert enterprise system 100 may be configured to automatically initiate a workflow action when potential security and compliance risk are detected, [0215] Customer Care and Trouble Ticket Interface Inbound calls, trouble tickets [0237-0238] Terminations: Deactivate IT Access and Physical Access immediately, [0421] provides a summary listing of all active alerts. A line level item detail view provides tasks associated with the particular alert. Remediation scripts associated with the alerts can be pre-configured to execute at a specified time or trigger based on a particular event. The line level summary of the task associated with the alert is actionable, subsystem 412 also provides the user an ability to create a new task to associate with this alert…Subsystem 412 provides the ability of the responder to initiate a lockdown of the zone to isolate the incident and to contain cascading damage, [0484]) Same motivation applies as claim 1.
Regarding claim 15, Crabtree and Gill teaches the method of claim 13, wherein asset exposure is calculated based on absence of endpoint protection, deviation from policy baselines, or known misconfigurations (Crabtree, A data to rule mapper 1904 is used to retrieve laws, policies, and other rules from an authority database 1903 and compare reconnaissance data received from the reconnaissance engine 1906 and stored in the reconnaissance data storage 1905 against the rules in order to determine whether and to what extent the data received indicates a violation of the rules…A scoring engine 1910 receives the data analyses performed by the directed computational graph 1911, the output of the data to rule mapper 1904, plus event and loss data 1914 and contextual data 1909 which defines a context in which the other data are to be scored and/or rated, [0100] At the purchaser level 2250, the primary risk introduced into the supply chain is improper use of the application or improper security settings established by the purchaser 2250 or its IT department, [0112] This is enhanced with the inclusion of impact assessment information 1406 for any affected resources, and the attack is then checked against a baseline score 1407 to determine the full extent of the impact of the attack and any necessary modifications to the infrastructure or policies, [0133] open ports, patch/setting vulnerabilities, [0138]) [Examiner interprets that system comparing data against policies and rules, determining the extent of rule violations, supplying those determination to a scoring engine, baseline risk comparison, improver security settings and patch and setting vulnerabilities as limitation above].
Regarding claim 17, Claim 17 recite commensurate subject matter as claim 1. Therefore, it is rejected for the same reasons. Except the additional elements:
A system for continuous exposure management in a computing environment, comprising: one or more processors and memory storing instructions that, when executed, cause the one or more processors to (Crabtree, a computing device comprising a memory and a processor, [0032] continuously monitor, process and explore incoming data for subtle changes or diffuse informational threads 353 and generate cyber-physical systems graphing 354 as part of the advanced cyber decision platform's common capabilities, [0091])
Regarding claims 18-20, Claims 18-20 recites commensurate subject matter as claims 2, 4 and 6. Therefore, they are rejected for the same reasons
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Crabtree (US 20220232040 A1) in view of Gill (US 20150281287 A1) in further of Huang (US 20230344848 A1).
Regarding claim 3, Crabtree and Gill teaches the method of claim 1, wherein exposure data includes detection of external-facing assets lacking authentication, use of insecure protocols, or misconfigured firewall rules (Huang, Vulnerabilities may exist for any number of reasons, such as a misconfigured firewall, [0002] a conceptualization of an attack surface management problem, according to an embodiment. Server 1, server 2, server 3, and server 4 may be assets of a client domain and may be configured inside of a firewall, which an employee/trusted user of the client domain may access…. Server 6 may be a misconfigured server that is supposed to communicate with server 3 and server 4 from inside of the firewall but is mistakenly configured outside of the firewall. A malicious entity cannot communicate directly through the firewall but may infiltrate the client domain by communicating with server 5 and server 6, [0022] Entries of a report (e.g., report 401 or report 402), such as entries with private IP addresses, may be investigated using dashboard 403. Inbound traffic may not be expected to private IP addresses, which if detected, may indicate that a firewall is misconfigured and allowing traffic from a known indicator of compromise, [0074])
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree and Gill to include a concept of exposure data includes detection of external-facing assets lacking authentication, use of insecure protocols, or misconfigured firewall rules as taught by Huang for the purpose of scanning from the “outside in” by scanning the entire internet and also working with the organization to review their outward facing assets for configuration flaws, firewall rules,[Huang:0023] and detecting if a firewall is misconfigured and allowing traffic from a known indicator of compromise [Huang:0074].
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Crabtree (US 20220232040 A1) in view of Gill (US 20150281287 A1) in further of Bubshait (US 20210392153 A1) in further view of Roytman (US 20210336984 A1).
Regarding claim 9, Crabtree and Gill teaches the method of claim 7, wherein prioritization of remediation is based on attack likelihood computed using threat intelligence, exploitability (Bubshait, determining, by the computer processor, a vulnerability priority for the security vulnerabilities using the exploitability levels and organization-specific criteria. The vulnerability priority describes a sequence that the security vulnerabilities are remediated. The method further includes transmitting, by the computer processor and based on the vulnerability priority, a remediation command to a network elements among the network elements. The remediation command initiates a remediation procedure at the network element to address the security vulnerability, [0003] external vulnerability data may be publically-available data regarding known security vulnerabilities. In some embodiments, for example, external vulnerability includes Common Vulnerability Exposure (CVE) data (e.g., CVE data (161))… CVE data may include a data entry with a brief description of the security vulnerability or exposure, such that CVE data may include a CVE ID number to share data across separate network security databases. An example of the CVE ID is CVE-YYYY-NNNN, where YYYY refers to a particular year when a vulnerability is discovered, and NNNN refers to arbitrary string identifying the security vulnerability. To be qualified for a CVE entry, a vulnerability may need to be independently fixable by affected vendors without modifying internal workflows of an organization, [0021] an exploitability level may differ between organizations for the same security vulnerability based on their past cybersecurity attack history. In other words, for a specific organization, a CVE with high CVSS score may not have high remediation urgency. Likewise, a high exploitability level may indicate a strong attack possibility of a particular vulnerability to an organization, [0033]) [Examiner interprets that system prioritizing remediation based on exploitability levels generated from external vulnerability information such as CVE data (i.e., threat intelligence) and organization specific criteria where the exploitability indicates attack possibility for a vulnerability as limitation above].
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree and Gill to include a concept of prioritization of remediation is based on attack likelihood computed using threat intelligence, exploitability as taught by Bubshait for the purpose of determining a vulnerability priority for the security vulnerabilities using the exploitability levels and organization-specific criteria and initiating a remediation procedure at the network element to address the security vulnerability based on the vulnerability priority [Bubshait:0003].
Bubshait does not explicitly teach:
prioritization of remediation is based on attack likelihood computed using exposure window duration
However, Roytman teaches:
prioritization of remediation is based on attack likelihood computed using exposure window duration (Roytman, Due to resource constraints, however, not all vulnerabilities can be remediated at the same time. Thus, remediation of vulnerabilities is typically prioritized according to different levels of risk posed by different vulnerabilities, [0006] remediating a high risk vulnerability slowly creates a time period of exposure for the enterprise following the guidance, increasing their overall risk posture , [0008] the first vulnerability data identifying a plurality of asset vulnerabilities, an amount of time between discovery of the asset vulnerabilities and resolution through remediation or exploitation in an attack, and one or more features of the asset vulnerabilities, such as a risk score or priority assigned to the asset, [0019] The risk score may additionally or alternatively comprise a computation of a likelihood that an asset vulnerability exists or that an asset vulnerability will be exploited., [0037] the server computer 130 may receive data indicating that an asset vulnerability has been discovered, such as through a ticket that is opened through a task tracking system…. The server computer 130 may compute a time between discovery of the asset vulnerability and resolution of the asset vulnerability, [0038] a time to remediate may be computed for only a subset of the first vulnerability data where the resolution of the vulnerability was the use of the vulnerability in an attack, [0046] the server computer 130 generates prioritized views of asset vulnerabilities, indicating asset vulnerabilities with a lower time to remediate as having higher priority, [0060]) [Examiner interprets that system prioritizing remediation by assigning shorter remediation timeframes to vulnerabilities based on risk/exploitation likelihood and timing data reflecting how long comparable vulnerabilities remained exposed before remediation as limitation above].
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree, Gill, and Bubshait to include a concept of prioritization of remediation is based on attack likelihood computed using threat intelligence, exploitability as taught by Roytman for the purpose of generating prioritized views of asset vulnerabilities, indicating asset vulnerabilities with a lower time to remediate as having higher priority, [0060].
Claim 12 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree (US 20220232040 A1) in view of Gill (US 20150281287 A1) in further of Kumar (US 20150381419 A1).
Regarding claim 12, Crabtree and Gill teaches the method of claim 13, further comprising triggering dynamic updates to CMDB records to resolve gaps and discrepancies in asset metadata (Kumar, a single resource may have been discovered and reported to an enterprise's configuration management system multiple times, [0005] accessing information describing one or more resources obtained from a plurality of discovery sources, identifying, via the accessed information, at least one resource that has been detected or discovered by at least two of the discovery sources; and merging the attribute values associated with the resource (from each of the discovery sources that detected the resource) into a reconciled resource object, [0006]) [Examiner interprets that system identifying records representing one resource and consolidating them as limitation above].
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree, and Gill to include a concept of deduplicating assets using a multi-source matching process and generating an uber node representing each asset as taught by Kumar for the purpose of identifying and reconciling the discovery of IT resources from multiple sources for effectively managing enterprise's resources [Kumar:0005].
Regarding claim 16, Crabtree and Gill teaches the method of claim 13, further comprising triggering dynamic updates to CMDB records to resolve gaps and discrepancies in asset metadata (Kumar, During merge phase 110, the data associated with resource objects (e.g., a resource objects' attributes) identified as being different instances of a common resource are combined into a single or reconciled resource object. This reconciled resource object is pushed into (i.e., associated with) reconciled dataset 115, [0016] database 210 comprises a configuration management database (“CMDB”) in accordance with the Information Technology Infrastructure Library (“ITIL”) standard, [0017] merge phase 110 pulls together resource object instances from different datasets that, thru identification phase 105, have been assigned the same Reconciliation ID attribute value and either modifies or creates an instance of the resource object in a resulting dataset (e.g., reconciled dataset 215), [0025] With respect to a merge group's defer if null indicator (e.g., 840 and 845), this parameter allows a user to specify what action to take when an attribute of an instance of a resource object has a “null” or “no” value. The defer if null indicator allows the user to defer to the dataset with the next weight for a given attribute if the highest weighted value is “null.” This allows a user to basically say, “I'd rather have some value than no value at all, even if the source isn't the highest weighted.”, [0031] With respect to a merge group's attribute value combination designator (e.g., 850 and 855), this parameter allows a user to assign more than one value to an attribute of a reconciled object…, [0032] a reconciled object's attribute value could be the algebraic average, weighted average or median of the values from all detected resource objects, [0033]) [Examiner interprets that reconciliation engine modifies or creates CMDB resource records based on discovered data, selecting a non-null attribute value from alternative source fills missing information where sources provide different values for the same attribute, the merge rules resolve the discrepancy by selecting or combining values as limitation above].
Therefore, it would have been obvious to PHOSITA before the effective filing date to modify the teaching of Crabtree, and Gill to include a concept of triggering dynamic updates to CMDB records to resolve gaps and discrepancies in asset metadata as taught by Kumar for the purpose of identifying and reconciling the discovery of IT resources from multiple sources for effectively managing enterprise's resources [Kumar:0005].
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 20260046294 A1: “relates to the use of event streams for recording, monitoring, and investigation of enterprise security”
US 20250379878 A1: “relates to systems and methods for anomaly detection via a detect and collect approach”
US 20210258329 A1: “relates to the field of network security, particularly to the detecting and mitigating attacks involving forged authentication objects”
US 20180295154 A1: “relates to the field of computer management, and more particularly to the field of cybersecurity and threat analytics”
US 20170289187 A1: “relates to the security vulnerability analysis of cyber networks”
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMIKSHYA POUDEL whose telephone number is (703)756-1540. The examiner can normally be reached 7:30 AM - 5PM Mon- Fri.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/S.N.P./Examiner, Art Unit 2436 /SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436