Prosecution Insights
Last updated: August 18, 2026
Application No. 19/170,441

SYSTEM AND METHOD FOR BUILDING AN ATTACK FLOW GRAPH

Non-Final OA §103
Filed
Apr 04, 2025
Priority
Apr 05, 2024 — provisional 63/575,506
Examiner
HUSSEIN, HASSAN A
Art Unit
Tech Center
Assignee
Accenture Global Solutions Limited
OA Round
1 (Non-Final)
59%
Grant Probability
Moderate
1-2
OA Rounds
1y 8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
81 granted / 138 resolved
-1.3% vs TC avg
Strong +53% interview lift
Without
With
+53.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
29 currently pending
Career history
172
Total Applications
across all art units

Statute-Specific Performance

§101
4.8%
-35.2% vs TC avg
§103
71.6%
+31.6% vs TC avg
§102
2.8%
-37.2% vs TC avg
§112
14.4%
-25.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 138 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This office action is in response to the application filed on 04/04/2025. In which, claims 1-19 are pending and being considered, claims 1, 10 and 19 are independent, claims 1-19 are rejected. Information Disclosure Statement The information disclosure statement (IDS) submitted on 09/17/2019 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Specification Applicant is reminded of the proper language and format for an abstract of the disclosure. The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details. The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided. The abstract of the disclosure is objected to because “disclosed” is stated on line 1 of the Abstract. A corrected abstract of the disclosure is required and must be presented on a separate sheet, apart from any other text. See MPEP § 608.01(b). Claim Objections Claim 2-3, 5-6, 11 and 14-15 are objected to because of the following informalities: In regards to Claims 2, 5, 6, 11, 14, and 15, the applicant recites the limitation “LLM”, this is a typographical error as abbreviation should be fully recited first before abbreviation. Examiner suggest amending the claims to read “large language model (LLM)” similar to claim 4. Appropriate correction is required. In regards to Claim 3, the applicant recites the limitation “TTP”, this is a typographical error as abbreviation should be fully recited first before abbreviation. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 7-8, 10, 16-17 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”) and Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”) further in view of Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) In regards to Claim 1, Craig teaches a computer-implemented method comprising: receiving, by a processor, a cyber-attack report from a user device; (Par. (0007); processor receiving cyber incident reports)), (Par. (0024, 0027); from a user device (user corresponding to threats and attacks apart of incident report) extracting, by the processor, one or more attack actions from the cyber- attack report; (Par. (0007); processor extracting action from cyber attack report (extracting keywords from cyber incident report)), (Par. (0038, 0042); one or more actions (keywords corresponding to anomalous behavior determined associated with system attack)) extracting, by the processor, one or more attack assets from the cyber- attack report; (Par. (0042-0045, 0047); extraction engine and extraction subsystem with processor extracting assets from cyber incident report)) determining, by the processor, one or more conditions and one or more operators associated with the one or more attack actions and the one or more attack assets; (Par. (0025, 0038); determining, by the processor (determining by the system with processor) one or more conditions and one or more operators (compromise of anomalous behavior with keywords corresponding to operating system) associated with the one or more attack actions and the one or more attack assets (operator behavior is determined when anomaly is detected corresponding to asset) ((Par. (0060); determining one or more operators and the one or more assets (incident reporting a router and examining all routers and assets with router that may be affected)) Craig does not explicitly teach generating, by the processor, a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators; generating, by the processor, an attack flow graph, wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and storing, by the processor, the attack flow graph in an attack flow knowledgebase. Wherein Soliman teaches generating, by the processor, a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators; (Par. (0036-0037, 0060); generating subgraph using one or more attacks (subgraph generated corresponding to attacks) the one or more conditions and the one or more operators (attack and subgraph based on nodes in compromised state with condition)), (Par. (0004); processor with subgraph) (Par. (0031-0033, 0036-0037); generating subgraph using one or more attack assets (subgraph developed based on alerts that signal conditions of vulnerabilities, exploits of assets (user accounts)), (Par. (0042-0044); one or more attack assets (user account with customer name, attributes etc.)) generating, by the processor, an attack flow graph, (Par. (0054-0056, 0058); first attack subgraph corresponding to subgraph)), (Par. (0004); processor with attack graph)) wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and (Par. (0054-0056); attack graph based on attack subgraph)) (Par. (0049); attack graph based on report (incident used in attack graph)), (Par. (0053-0056); an attack flow schema (attack graph based on set of correlations)), (Examine Note: In the instant application the specification states on Par. (0050) that attack flow schema is define as structure framework or blueprint that represents relationships and types, therefore it will be broadly and reasonable interpreted that relationships or correlations associated with attack graph is an attack flow schema)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of collecting, monitoring and countering cyber security attacks by alerting and combatting false-positives by creating graphs to determine maliciousness with metrics and set of correlations provided to the system. (Soliman Par. (0003-0005)) Craig and Soliman do not explicitly teach storing, by the processor, the attack flow graph in an attack flow knowledgebase. Wherein Ungureanu teaches storing, by the processor, the attack flow graph in an attack flow knowledgebase. (Par. (0031, 0020); attack graph stored in attack flow knowledgebase (graph database)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Soliman to incorporate the teaching of Ungureanu to utilize the above feature because of the analogous concept of detecting security attacks in systems and attack graphs, with the motivation of creating attack graphs to represent prior knowledge of vulnerabilities with possible paths to prevent risk. (Ungureanu Par. (0002)) In regards to Claim 7, the combination Craig, Soliman and Ungureanu teach the method of claim 1, Soliman further teaches wherein generating the attack flow graph comprises, adding properties for each of node of graph, (Par. (0036-0037); attack graph with node that has properties of pre-post condition, states and edges that represent the node) wherein the properties are added based on the attack flow schema and using the cyber- attack report. (Par. (0036-0037); properties of pre-post condition, states and edges that represent node are based on attack flow schema (correlations determined from alerts and graph)), (Par. (0049); attack flow schema and using the cyber- attack report. (correlation using incidents with attack graph)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Ungureanu to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of determining whether a node is in a compromised state by representation on the attack graph to identify pre and post conditions of exploit. (Soliman Par. (0036-0037)) In regards to Claim 8, the combination Craig, Soliman and Ungureanu teach the method of claim 1, Soliman further teaches wherein the attack flow graph is generated in a structured format. (Figure 2A, 2D; structure of attack graph and In Figure 2A with format userX > 10.0.0.1 and Figure 2D with alert graph), (Par. (0034-0035, 0046-0047 graph with edges and correlation formats)), (Par. (0022); structed format (JSON)), (Examiner note: In the instant application the specification states on Par. (0050) that structured format may be any known formats as well as JSON format therefore it will be broadly and reasonably interpreted in light of the specification that a graph with edges and particular format of the graph meets the claimed limitation.)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Ungureanu to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of identifying based on the graph format representation of attacks for analysis and further investigation to detect maliciousness and alert and create responses in the system by identifying correlations in the graph. (Soliman Par. (0014 and 0057)) In regards to Claim 10, Craig teaches a system comprising: (Par. (0007); system) at least one memory configured to store machine-executable instructions; and (Par. (0079); memory) at least one processor communicatively coupled with the at least one memory, and configured to execute the machine-executable instructions to perform operations comprising: (Par. (0078-0079); processor with memory and computer-readable medium) receiving a cyber-attack report from a user device; (Par. (0007); processor receiving cyber incident reports)), (Par. (0024, 0027); from a user device (user corresponding to threats and attacks apart of incident report) extracting one or more attack actions from the cyber-attack report; (Par. (0007); processor extracting action from cyber attack report (extracting keywords from cyber incident report)), (Par. (0038, 0042); one or more actions (keywords corresponding to anomalous behavior determined associated with system attack)) extracting one or more attack assets from the cyber-attack report; (Par. (0042-0045, 0047); extraction engine and extraction subsystem extracting assets from cyber incident report)) determining one or more conditions and one or more operators associated with the one or more attack actions and the one or more attack assets; (Par. (0025, 0038); determining, by the processor (determining by the system with processor) one or more conditions and one or more operators (compromise of anomalous behavior with keywords corresponding to operating system) associated with the one or more attack actions and the one or more attack assets (operator behavior is determined when anomaly is detected corresponding to asset) ((Par. (0060); determining one or more operators and the one or more assets (incident reporting a router and examining all routers and assets with router that may be affected)) Craig does not explicitly teach generating a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators; generating an attack flow graph, wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and storing the attack flow graph in an attack flow knowledgebase. Wherein Soliman teaches generating a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators; (Par. (0036-0037, 0060); generating subgraph using one or more attacks (subgraph generated corresponding to attacks) the one or more conditions and the one or more operators (attack and subgraph based on nodes in compromised state with condition)), (Par. (0004); processor with subgraph) (Par. (0031-0033, 0036-0037); generating subgraph using one or more attack assets (subgraph developed based on alerts that signal conditions of vulnerabilities, exploits of assets (user accounts)), (Par. (0042-0044); one or more attack assets (user account with customer name, attributes etc.)) generating an attack flow graph, (Par. (0054-0056, 0058); first attack subgraph corresponding to subgraph)), (Par. (0004); processor with attack graph) wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and (Par. (0054-0056); attack graph based on attack subgraph)) (Par. (0049); attack graph based on report (incident used in attack graph)), (Par. (0053-0056); an attack flow schema (attack graph based on set of correlations)), (Examine Note: In the instant application the specification states on Par. (0050) that attack flow schema is define as structure framework or blueprint that represents relationships and types, therefore it will be broadly and reasonable interpreted that relationships or correlations associated with attack graph is an attack flow schema)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of collecting, monitoring and countering cyber security attacks by alerting and combatting false-positives by creating graphs to determine maliciousness with metrics and set of correlations provided to the system. (Soliman Par. (0003-0005)) Craig and Soliman do not explicitly teach storing the attack flow graph in an attack flow knowledgebase. Wherein Ungureanu teaches storing the attack flow graph in an attack flow knowledgebase. (Par. (0031, 0020); attack graph stored in attack flow knowledgebase (graph database)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Soliman to incorporate the teaching of Ungureanu to utilize the above feature because of the analogous concept of detecting security attacks in systems and attack graphs, with the motivation of creating attack graphs to represent prior knowledge of vulnerabilities with possible paths to prevent risk. (Ungureanu Par. (0002)) In regards to Claim 16, the combination Craig, Soliman and Ungureanu teach the system of claim 10, Soliman further teaches wherein generating the attack flow graph comprises, adding properties for each of node of the graph, (Par. (0036-0037); attack graph with node that has properties of pre-post condition, states and edges that represent the node) wherein the properties are added based on the attack flow schema and using the cyber-attack report. (Par. (0036-0037); properties of pre-post condition, states and edges that represent node are based on attack flow schema (correlations determined from alerts and graph)), (Par. (0049); attack flow schema and using the cyber- attack report. (correlation using incidents with attack graph)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Ungureanu to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of determining whether a node is in a compromised state by representation on the attack graph to identify pre and post conditions of exploit. (Soliman Par. (0036-0037)) In regards to Claim 17, the combination Craig, Soliman and Ungureanu teach the system of claim 10, Soliman further teaches wherein the attack flow graph is generated in a structured format. (Figure 2A, 2D; structure of attack graph and In Figure 2A with format userX > 10.0.0.1 and Figure 2D with alert graph), (Par. (0034-0035, 0046-0047 graph with edges and correlation formats)), (Par. (0022); structed format (JSON)), (Examiner note: In the instant application the specification states on Par. (0050) that structured format may be any known formats as well as JSON format therefore it will be broadly and reasonably interpreted in light of the specification that a graph with edges and particular format of the graph meets the claimed limitation.)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Ungureanu to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of identifying based on the graph format representation of attacks for analysis and further investigation to detect maliciousness and alert and create responses in the system by identifying correlations in the graph. (Soliman Par. (0014 and 0057)) In regards to Claim 19, Craig teaches at least one non-transitory computer-readable media comprising machine- executable instructions stored thereon, which, when executed by at least one processor of at least one computing device, cause the at least one computing device to perform operations comprising: (Par. (0078-0079, 0082); computer readable medium with processor and memory and storage devices)), (Par. (0033, 0060); device)) receiving a cyber-attack report from a user device; (Par. (0007); processor receiving cyber incident reports)), (Par. (0024, 0027); from a user device (user corresponding to threats and attacks apart of incident report) extracting one or more attack actions from the cyber-attack report; (Par. (0007); processor extracting action from cyber attack report (extracting keywords from cyber incident report)), (Par. (0038, 0042); one or more actions (keywords corresponding to anomalous behavior determined associated with system attack)) extracting one or more attack assets from the cyber-attack report; (Par. (0042-0045, 0047); extraction engine and extraction subsystem extracting assets from cyber incident report)) determining one or more conditions and one or more operators associated with the one or more attack actions and the one or more attack assets; (Par. (0025, 0038); determining, by the processor (determining by the system with processor) one or more conditions and one or more operators (compromise of anomalous behavior with keywords corresponding to operating system) associated with the one or more attack actions and the one or more attack assets (operator behavior is determined when anomaly is detected corresponding to asset) ((Par. (0060); determining one or more operators and the one or more assets (incident reporting a router and examining all routers and assets with router that may be affected)) Craig does not explicitly teach generating a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators; generating an attack flow graph, wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and storing the attack flow graph in an attack flow knowledgebase. Wherein Soliman teaches generating a subgraph using the one or more attack actions, the one or more attack assets, the one or more conditions and the one or more operators (Par. (0036-0037, 0060); generating subgraph using one or more attacks (subgraph generated corresponding to attacks) the one or more conditions and the one or more operators (attack and subgraph based on nodes in compromised state with condition)), (Par. (0004); processor with subgraph) (Par. (0031-0033, 0036-0037); generating subgraph using one or more attack assets (subgraph developed based on alerts that signal conditions of vulnerabilities, exploits of assets (user accounts)), (Par. (0042-0044); one or more attack assets (user account with customer name, attributes etc.)) generating an attack flow graph, (Par. (0054-0056, 0058); first attack subgraph corresponding to subgraph)), (Par. (0004); processor with attack graph) wherein the attack flow graph is generated based on the subgraph, the cyber-attack report and an attack flow schema; and (Par. (0054-0056); attack graph based on attack subgraph)) (Par. (0049); attack graph based on report (incident used in attack graph)), (Par. (0053-0056); an attack flow schema (attack graph based on set of correlations)), (Examine Note: In the instant application the specification states on Par. (0050) that attack flow schema is define as structure framework or blueprint that represents relationships and types, therefore it will be broadly and reasonable interpreted that relationships or correlations associated with attack graph is an attack flow schema)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig to incorporate the teaching of Soliman to utilize the above feature because of the analogous concept of detecting security attacks in systems, with the motivation of collecting, monitoring and countering cyber security attacks by alerting and combatting false-positives by creating graphs to determine maliciousness with metrics and set of correlations provided to the system. (Soliman Par. (0003-0005)) Craig and Soliman do not explicitly teach storing the attack flow graph in an attack flow knowledgebase. Wherein Ungureanu teaches storing the attack flow graph in an attack flow knowledgebase. (Par. (0031, 0020); attack graph stored in attack flow knowledgebase (graph database)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig and Soliman to incorporate the teaching of Ungureanu to utilize the above feature because of the analogous concept of detecting security attacks in systems and attack graphs, with the motivation of creating attack graphs to represent prior knowledge of vulnerabilities with possible paths to prevent risk. (Ungureanu Par. (0002)) Claim(s) 2 and 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”), Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”) and Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) further in view of Singh et al. (U.S Pub. No. 20250045411, hereinafter referred to as “Singh”) In regards to Claim 2, the combination of Craig, Soliman and Ungureanu teach the method of claim 1, Craig further teaches the computer-implemented method of claim 1, wherein the one or more attack actions are extracted from the cyber-attack report using one of a first machine learning model and (Par. (0007); processor extracting action from cyber attack report (extracting keywords from cyber incident report)), (Par. (0059-0060); deep machine learning subsystem with models corresponding to extracting from incident reports)), (Par. (0006-0007); deep machine learning with extraction of actions)) Craig, Soliman and Ungureanu do not explicitly teach a first finetuned LLM. Wherein Singh teaches a first finetuned LLM. (Par. (0029); LLM retrieving from threat report a threat prompt with and assessment), (Par. (0006); actions are extracted (threat prompt with threats and vulnerabilities identified)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Singh to utilize the above feature because of the analogous concept of detecting security attacks in systems and graphing, with the motivation of using threat models to allow administrators to understand security vulnerabilities and potential threats. As well as using large language models to create automation and enhance security assessments to mitigate threats. (Singh Par. (0002-0003 and 0005-0006)) In regards to Claim 11, the combination of Craig, Soliman and Ungureanu teach the system of claim 10, Craig further teaches the system of claim 10, wherein the one or more attack actions are extracted from the cyber-attack report using one of a first machine learning model and (Par. (0007); processor extracting action from cyber attack report (extracting keywords from cyber incident report)), (Par. (0059-0060); deep machine learning subsystem with models corresponding to extracting from incident reports)), (Par. (0006-0007); deep machine learning with extraction of actions)) Craig, Soliman and Ungureanu do not explicitly teach a first finetuned LLM. Wherein Singh teaches a first finetuned LLM. (Par. (0029); LLM retrieving from threat report a threat prompt with and assessment), (Par. (0006); actions are extracted (threat prompt with threats and vulnerabilities identified)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Singh to utilize the above feature because of the analogous concept of detecting security attacks in systems and graphing, with the motivation of using threat models to allow administrators to understand security vulnerabilities and potential threats. As well as using large language models to create automation and enhance security assessments to mitigate threats. (Singh Par. (0002-0003 and 0005-0006)) Claim(s) 3 and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”), Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”) and Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) further in view of Kim et al. (U.S Pub. No. 20230048076, hereinafter referred to as “Kim”) In regards to Claim 3, the combination of Craig, Soliman and Ungureanu do not explicitly teach assigning a MITRE identifier for each of the one or more attack actions using a TTP framework. Wherein Kim teaches assigning a MITRE identifier for each of the one or more attack actions using a TTP framework. (Par. (0333-0335, 0565); MITRE identifier with TTP assigned on database)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Kim to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of using identifiers to identify possible attacks, threats and create analysis to detect malware more effectively to filter though fake information and eliminate confusion. (Kim Par. (0003-0009, 0016, 0168, 0565)) In regards to Claim 12, the combination of Craig, Soliman and Ungureanu do not explicitly teach assigning a MITRE identifier for each of the one or more attack actions using a tactics, techniques, and procedures (TTP) framework. Wherein Kim teaches assigning a MITRE identifier for each of the one or more attack actions using a tactics, techniques, and procedures (TTP) framework. (Par. (0333-0335, 0565); MITRE identifier with TTP assigned on database)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Kim to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of using identifiers to identify possible attacks, threats and create analysis to detect malware more effectively to filter though fake information and eliminate confusion. (Kim Par. (0003-0009, 0016, 0168, 0565)) Claim(s) 5 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”), Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”), Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) and Bishop et al. (U.S Pub. No. 20230252158, hereinafter referred to as “Bishop”) further in view of Gallagher et al. (U.S Pub. No. 20250245092, hereinafter referred to as “Gallagher”) In regards to Claim 5, the combination of Craig, Soliman and Ungureanu do not explicitly teach wherein the one or more attack assets are extracted from the cyber-attack report using one of a third machine learning model and a third finetuned LLM. Wherein Bishop teaches wherein the one or more attack assets are extracted from the cyber-attack report using one of a third machine learning model and (Par. (0027, 0032); extracting from cyber attack reports (entries) assets (software applications with new threat) using third machine learning models (plurality of threat models 118-118n of machine learning models)), (Figure 1 labels 1181-118n; third model (plurality of threat models)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Bishop to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of creating threat modeling to identify assets such as software application and possible security threats to allow counter measures to be in place and using models to update and enhance investigation with new susceptible threats. (Bishop Par. (0002)) Craig, Soliman, Ungureanu and Bishop do not explicitly teach a third finetuned LLM. Wherein Gallagher teaches a third finetuned LLM. (Par. (0102); third LLM), (Par. (0015, 0083-0085, 0094; LLM amongst plurality of LLMs extracting assets (data) from cyber attack report (incident record)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman, Ungureanu and Bishop to incorporate the teaching of Gallagher to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of using large language models to crate alerts, records and monitoring malfunction and remediation strategies to allow uptime in system. (Gallagher Par. (0006 and 0012)) In regards to Claim 14, the combination of Craig, Soliman and Ungureanu do not explicitly teach wherein the one or more attack assets are extracted from the cyber-attack report using one of a third machine learning model and a third finetuned LLM. Wherein Bishop teaches wherein the one or more attack assets are extracted from the cyber-attack report using one of a third machine learning model and (Par. (0027, 0032); extracting from cyber attack reports (entries) assets (software applications with new threat) using third machine learning models (plurality of threat models 118-118n of machine learning models)), (Figure 1 labels 1181-118n; third model (plurality of threat models)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Bishop to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of creating threat modeling to identify assets such as software application and possible security threats to allow counter measures to be in place and using models to update and enhance investigation with new susceptible threats. (Bishop Par. (0002)) Craig, Soliman, Ungureanu and Bishop do not explicitly teach a third finetuned LLM. Wherein Gallagher teaches a third finetuned LLM. (Par. (0102); third LLM), (Par. (0015, 0083-0085, 0094; LLM amongst plurality of LLMs extracting assets (data) from cyber attack report (incident record)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman, Ungureanu and Bishop to incorporate the teaching of Gallagher to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of using large language models to crate alerts, records and monitoring malfunction and remediation strategies to allow uptime in system. (Gallagher Par. (0006 and 0012)) Claim(s) 6 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”), Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”), Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) and Bishop et al. (U.S Pub. No. 20230252158, hereinafter referred to as “Bishop”) further in view of Crume et al. (U.S Pub. No. 20250265446, hereinafter referred to as “Crume”) In regards to Claim 6, the combination of Craig, Soliman and Ungureanu do not explicitly teach wherein the one or more conditions and the one or more operators associated with the one or more attack actions and the one or more attack assets are determined using one of a fourth machine learning model and a fourth finetuned LLM. Wherein Bishop teaches wherein the one or more conditions and the one or more operators associated with the one or more attack actions and the one or more attack assets are determined using one of a fourth machine learning model and (Par. (0003-0004); machine learning models determining one or more conditions (security vulnerabilities, bad actors) and one or more assets (data stored with malware)) the one or more operators (viruses and malware operating on system with bad actors) and one or more conditions)), (Par. (0027, 0032); one or more assets (software applications with new threat) using fourth machine learning models (plurality of threat models 118-118n of machine learning models)), (Figure 1 labels 1181-118n; fourth model (plurality of threat models)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Bishop to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of creating threat modeling to identify assets such as software application and possible security threats to allow counter measures to be in place and using models to update and enhance investigation with new susceptible threats. (Bishop Par. (0002)) Craig, Soliman, Ungureanu and Bishop do not explicitly teach a fourth finetuned LLM. Wherein Crume teaches a fourth finetuned LLM. (Par. (0046, 0067-0069); fourth LLM and detecting one or more conditions (security incidents, malware security vulnerabilities etc.)), (Par. (0048); the one or more operators (conditions of a device and environment corresponding to incident with LLM), (Par. (0058-0059); the one or more assets (LLM with data in database, user ID etc.)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman, Ungureanu and Bishop to incorporate the teaching of Crume to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of determining a cybersecurity incident of an authorized party or unauthorized device to potential acquire access to private information and using large language models to determine solutions, weigh in trade off and resolution for the incident. (Crume Par. (0002-0003)) In regards to Claim 15, the combination of Craig, Soliman and Ungureanu do not explicitly teach wherein the one or more conditions and the one or more operators associated with the one or more attack actions and the one or more attack assets are determined using one of a fourth machine learning model and a fourth finetuned LLM. Wherein Bishop teaches wherein the one or more conditions and the one or more operators associated with the one or more attack actions and the one or more attack assets are determined using one of a fourth machine learning model and (Par. (0003-0004); machine learning models determining one or more conditions (security vulnerabilities, bad actors) and one or more assets (data stored with malware)) the one or more operators (viruses and malware operating on system with bad actors) and one or more conditions)), (Par. (0027, 0032); one or more assets (software applications with new threat) using fourth machine learning models (plurality of threat models 118-118n of machine learning models)), (Figure 1 labels 1181-118n; fourth model (plurality of threat models)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Bishop to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of creating threat modeling to identify assets such as software application and possible security threats to allow counter measures to be in place and using models to update and enhance investigation with new susceptible threats. (Bishop Par. (0002)) Craig, Soliman, Ungureanu and Bishop do not explicitly teach a fourth finetuned LLM. Wherein Crume teaches a fourth finetuned LLM. (Par. (0046, 0067-0069); fourth LLM and detecting one or more conditions (security incidents, malware security vulnerabilities etc.)), (Par. (0048); the one or more operators (conditions of a device and environment corresponding to incident with LLM), (Par. (0058-0059); the one or more assets (LLM with data in database, user ID etc.)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman, Ungureanu and Bishop to incorporate the teaching of Crume to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning, with the motivation of determining a cybersecurity incident of an authorized party or unauthorized device to potential acquire access to private information and using large language models to determine solutions, weigh in trade off and resolution for the incident. (Crume Par. (0002-0003)) Claim(s) 9 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Craig et al. (U.S Pub. No. 20190222593, hereinafter referred to as “Craig”), Soliman et al. (U.S Pub. No. 20240143751, hereinafter referred to as “Soliman”) and Ungureanu et al. (U.S Pub. No. 20240146755, hereinafter referred to as “Ungureanu”) further in view of Brown et al. (U.S Pub. No. 20230328094, hereinafter referred to as “Brown”) In regards to Claim 9, the combination of Craig, Soliman and Ungureanu do not explicitly teach evaluating, by the processor, the attack flow graph using a graph validator. Wherein Brown teaches evaluating, by the processor, the attack flow graph using a graph validator. (Par. (0136); attack graphs run through parameter validation), (Par. (0102); attack graph and authentication procedures), (Par. (0077); scores in attack graph are validated and evaluated (scores marked and determined to security attack and composed in attack graph)), (Part. (0042 and 0076); evaluating, by the processor, the attack flow graph (attack graph with attack vectors and scores that are determined) using a graph validator (scores in attack graph are validated)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Brown to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning and developing graphs, with the motivation of using graphs to warn system of possible cyber attacks and preventing havoc, vulnerabilities and compromise. By employing detection mechanisms a suitable way to provide defense is deployed using attack graphs and topology to create effective defenses in automation. (Brown Par. (0007-0009 and 0043)) In regards to Claim 18, the combination of Craig, Soliman and Ungureanu do not explicitly teach wherein the processor is further configured to evaluate the attack flow graph using a graph validator. Wherein Brown teaches wherein the processor is further configured to evaluate the attack flow graph using a graph validator. (Par. (0136); attack graphs run through parameter validation), (Par. (0102); attack graph and authentication procedures), (Par. (0077); scores in attack graph are validated and evaluated (scores marked and determined to security attack and composed in attack graph)), (Part. (0042 and 0076); evaluating, by the processor, the attack flow graph (attack graph with attack vectors and scores that are determined) using a graph validator (scores in attack graph are validated)) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Craig, Soliman and Ungureanu to incorporate the teaching of Brown to utilize the above feature because of the analogous concept of detecting security attacks in systems using machine learning and developing graphs, with the motivation of using graphs to warn system of possible cyber attacks and preventing havoc, vulnerabilities and compromise. By employing detection mechanisms a suitable way to provide defense is deployed using attack graphs and topology to create effective defenses in automation. (Brown Par. (0007-0009 and 0043)) Allowable Subject Matter Claims 4 and 13 objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following statement of reasons for the indication of allowable subject matter: Dependent claims 4 and 13 and their respective dependent claims, are allowable over the prior art of record including Craig, Soliman and Ungureanu and the remaining references cited by the Examiner, since the prior art, taken individually or in combination fails to particularly disclose, fairly suggest or render obvious; wherein the MITRE identifier is identified using one of a second machine learning model, a first finetuned large language model (LLM), and a semantic search on a vector database, as specified in claims 4 and 13. Relevant Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Soroush; Hamed (U.S Pub. No. 20210014264) “SYSTEM AND METHOD FOR REASONING ABOUT THE OPTIMALITY OF A CONFIGURATION PARAMETER OF A DISTRIBUTED SYSTEM”. Considered this reference because it addressed attack graphs and subgraphs based on security reports. Siracusano; Giuseppe (U.S Pub. No. 20240411994) “EXTRACTING INFORMATION FROM REPORTS USING LARGE LANGUAGE MODELS”. Considered this application because it relates to large language models and extracting from reports malware and actions associated with assets. GAMBLE; Jamie (U.S Pub. No. 20190342307) “SYSTEM AND METHOD FOR MONITORING SECURITY ATTACK CHAINS”. Considered this application because it addressed detecting of intrusion and security issues using data structures graphs and creating reports. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN A HUSSEIN whose telephone number is (571)272-3554. The examiner can normally be reached on 7:30am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HASSAN A HUSSEIN/ Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Apr 04, 2025
Application Filed
Jul 16, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701015
HTLC WITH PROOF OF ELAPSED TIME
4y 7m to grant Granted Aug 04, 2026
Patent 12689617
CRYPTOGRAPHIC METHOD FOR VERIFYING DATA
1y 2m to grant Granted Jul 21, 2026
Patent 12682075
Security Configuration Optimizer Systems and Methods
2y 3m to grant Granted Jul 14, 2026
Patent 12657341
USING MULTI-PARTY COMPUTATION AND K-ANONYMITY TECHNIQUES TO PROTECT CONFIDENTIAL INFORMATION
3y 8m to grant Granted Jun 16, 2026
Patent 12657332
SYSTEMS AND METHODS FOR FACILITATING ON-DEMAND ARTIFICIAL INTELLIGENCE MODELS FOR SANITIZING SENSITIVE DATA
3y 8m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
59%
Grant Probability
99%
With Interview (+53.0%)
3y 0m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 138 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month