DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to the application filed on 05/13/2025.
Claims 1-20 are currently pending in this application.
No information disclosure statement (IDS) has been filed.
Examiner’s Note
Applicants are suggested to include information from figure 3 with related text into the claims to provide a better condition for an allowance.
Claim Objections
Claims 2-10, 13 and 17 are objected to because of the following informalities:
the claims 2-10 recite “The system of claim 1 (or 4 or 5) …”, which appears to be “The cybersecurity threat detection and mitigation system of claim 1 (or 4 or 5) …”;
the claim 13 recites “The method of claim 1, further comprising …”, which appears to be “The method of claim 11, further comprising …”;
the claim 17 recites “The system of claim 1, wherein refining the AI model comprises …”, which appears to be “The method of claim 11, wherein refining the AI model comprises …”.
Appropriate corrections are required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(B) CONCLUSION. —The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which applicant regards as the invention.
Claim 1 (claim 11 includes similar limitations) recites:
“… refining an AI model with corpus of historical security data that represents security events that occurred across a computer network, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events …”, however, it is not clear (1) whether refining the AI model is performed with the queries and actions or not – or it is not clear to define a boundary of the limitations; (2) whether the security analysts has access to the computer network because the security events are occurred in the computer network – or omitting necessary step/component that causes the limitations unclear; (3) whether the security events indicate normal daily actions or a routine system changes – or omitting necessary step/component that causes the limitations unclear;
“… analyzing, by the AI model, the real-time telemetry data … to identify a potential security threat … using multi-dimensional vector representation that encode threat characteristics, network behaviors, and mitigation effectiveness in interconnected subspaces …”, however, it is not clear (1) whether the AI model is a part of the cybersecurity threat detection and mitigation system or not (note: the system refines the AI model); (2) whether claimed information, “multi-dimensional vector representation that encode threat characteristics, network behaviors, and mitigation effectiveness in interconnected subspaces”, are parts of the AI model, the system or the real-time telemetry data – or omitting necessary step/component that causes the limitations unclear;
“… performing, by the AI model, an assessment of risk to the computer network for the potential security threat; and … the potential security threat is an actual security threat, triggering a security alert …”, however, it is not clear (1) whether performing the assessment of risk to the computer network has any thing related to the real-time telemetry data or not – or omitting necessary step/component that causes the limitations unclear; (2) whether the assessment of risk is performed for the potential security threat or for the actual security threat – or it is not clear to define a boundary of the limitations; (3) whether the security alert is triggered at the system or not.
Claims 2-10 and 12-20 depend from the claim 1 or 11, and are analyzed and rejected accordingly.
Claims 2 and 12 recite “… dynamically adjusting a threshold value based on network conditions and threat intelligence feeds … time-decay functions for aging intelligence …”, however, it is not clear (1) whether the threshold value is the value/number of the network conditions and the threat intelligence feeds; (2) how to define the threat intelligence feeds (e.g., the feeds provided by an intelligence feed model, etc.); (3) whether the aging intelligence is aging of the threat intelligence feeds or the AI model – it is not clear to define a boundary of the limitation/terms.
Claims 4-6 and 14-16 recite:
“… predicting, by the AI model, at least one query for investigating the actual security threat by translating detection signals into investigation pathways …”, however, it is not clear (1) whether “at least one query” has any relationship with the analyzed real-time telemetry data or not – omitting necessary step/component which causes the limitations unclear; (2) how to translate the signals to the pathways (e.g., the pathways, in which the signals are detected, etc.);
“… providing the predicted … for presentation to a security analyst through a user interface …”, however, it is not clear (1) whether the “security analyst” is one of the “security analysts” of the claim 1 (or 11) or not; (2) whether the user interface is a part of the cybersecurity threat detection and mitigation system or not (if not, whether the presenting on the user interface is an intended use or not – not limiting weight).
Claims 7 and 17 recite “… restructuring a vector index for the multi-dimensional vector representations”, however, it is not clear whether a previous vector index is restructured to a new vector index using the multi-dimensional vector representations of the claim 1 or not – omitting necessary step/component which causes the limitations unclear.
Claims 8 and 18 recite “… prioritizing the security alert, based on (1) a potential impact of the potential security threat … (ii) a detection confidence … and (iii) the potential lateral movement paths available to the threat actor …”, however, it is not clear (1) whether the security alert is based on the actual security threat of the claim 1 or the potential impact of the potential security threat; (2) the terms, “the potential lateral movement paths” and “the threat actor”, have antecedent basis issues (not defining “potential lateral movement paths” and “a threat actor” before.
Claims 10 and 20 recite “… automatically assigning the ticket to an appropriate security team based on a threat classification and team expertise”, however, it is not clear (1) whether “a threat classification” has any relationship with the actual security threat or the real-time telemetry data of the claim 1 or 11 – omitting necessary step/component which causes the limitations unclear.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1, 3-7, 9-11, 13-17, 19 and 20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by McCarson (US 12,088,599 B1).
As per claim 1, McCarson teaches a cybersecurity threat detection and mitigation system [see the abstract], comprising: at least one processor; and memory storing instructions that, when executed by the at least one processor, cause the system to perform operations [see col. 22, lines 27-39] comprising:
refining an artificial intelligence (Al) model with a corpus of historical security data that represents security events that occurred across a computer network, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events [figs. 1, 2, 7, 8; col. 3, lines 25-43; col. 10, lines 1-36; col. 11, lines 53-61; col. 12, lines 53-67; col. 13, lines 1-36; col. 19, lines 1-20 of McCarson teaches refining (e.g., refined over time) an artificial intelligence (Al) model with a corpus of historical security data (e.g., the historical performance for the threats) that represents security events that occurred across a computer network, queries that were submitted by security analysts (e.g., various predictive analytics models/modules or analytics engine 830 etc.) in response to the security events, and actions that were performed for mitigating (e.g., the mitigation techniques) the security events (e.g., the information stored/provided by the context-aware artificial intelligence database 850, etc.)];
collecting real-time telemetry data that corresponds to behavior and performance of the computer network; providing the real-time telemetry data to the AI model; analyzing, by the AI model, the real-time telemetry data in conjunction with the historical security data to identify a potential security threat to the computer network using multi-dimensional vector representations that encode threat characteristics, network behaviors, and mitigation effectiveness in interconnected subspaces [figs. 8, 9, 13; col. 4, lines 12-31; col. 18, lines 13-30; col. 19, lines 21-61; col. 22, lines 14-26 of McCarson teaches collecting real-time telemetry data that corresponds to behavior and performance of the computer network; providing the real-time telemetry data to the AI model (e.g., the analytics engine with AI, the real-time security AI agent or machine learning model); analyzing, by the AI model, the real-time telemetry data in conjunction with the historical security data (e.g., historical analysis of known events) to identify a potential security threat to the computer network using multi-dimensional vector (e.g., the attack vectors) representations that encode threat characteristics (e.g., classifying patterns, etc.), network behaviors (e.g., attack behaviors, etc.), and mitigation effectiveness (e.g., effectiveness of the attacks or improved defenses, etc.) in interconnected subspaces (e.g., the AI monitored honeypots, virtual honeypots, etc.];
performing, by the AI model, an assessment of risk to the computer network for the potential security threat; and when the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, triggering a security alert that corresponds to the actual security threat [figs. 8, 9; col. 3, lines 25-43; col. 19, lines 21-61; col. 21, lines 8-19; col. 24, lines 10-15 of McCarson teaches performing, by the AI model, an assessment of risk to the computer network for the potential security threat (e.g., performed to assess the extent, maturity, complexity and potential origin of the attacks, etc.); and when the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, triggering a security alert (e.g., providing alerts for detected threats or suspicious activity) that corresponds to the actual security threat].
As per claim 3, McCarson teaches the system of claim 1.
McCarson further teaches when the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, determining, by the AI model, at least one automated mitigation action based on a type of the actual security threat; and initiating the at least one automated mitigation action [col. 15, lines 56-67; col. 21, lines 8-19, 55-59; col. 23, lines 53-61 of McCarson teaches when the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, determining, by the AI model, at least one automated mitigation action based on a type of the actual security threat; and initiating the at least one automated mitigation action(e.g., actions carried out autonomously or autonomous defensive action)].
As per claim 4, McCarson teaches the system of claim 1.
McCarson further teaches predicting, by the AI model, at least one query for investigating the actual security threat by translating detection signals into investigation pathways; and providing the predicted at least one query for presentation to a security analyst through a user interface with supporting evidence and confidence scores for each predicted query [figs. 9, 10; col. 15, lines 45-67; col. 16, lines 1-16; col. 18, lines 1-30 of McCarson teaches predicting, by the AI model, at least one query for investigating the actual security threat by translating detection signals into investigation pathways (e.g., through the various models, RLHF, etc.); and providing the predicted at least one query for presentation to a security analyst through a user interface (e.g., the question/answer forums in the RLHF) with supporting evidence (e.g., the output of the model) and confidence scores (e.g., the additional value) for each predicted query].
As per claim 5, McCarson teaches the system of claim 4.
McCarson further teaches:
receiving, through the user interface, a selection of the at least one query; executing the at least one query, and returning a result based on the executing for presentation through the user interface [col. 14, lines 42-49; col. 24, lines 21-27 of McCarson teaches receiving, through the user interface, a selection of the at least one query (e.g., selection of the hypothesis object); executing the at least one query, and returning a result based on the executing for presentation through the user interface (e.g., the reinforcement learning from human feedback, RLHF)];
providing, to the AI model, query selection data that indicates that the at least one question was selected; receiving, through the user interface, a feedback response from the security analyst indicative of effectiveness of mitigation actions taken in response to the query results [figs. 9, 10; col. 17, lines 5-15; col. 18, lines 12-30; col. 19, lines 40-61; col. 24, lines 21-27 of McCarson teaches providing, to the AI model (e.g., the NPL models or LLM model), query selection data that indicates that the at least one question was selected; receiving, through the user interface, a feedback response from the security analyst indicative of effectiveness of mitigation actions taken in response to the query results (e.g., the human feedback is provided to align the output of the LLM)]; and
incrementally refining the AI model based on the query selection data and the effectiveness of mitigation actions taken in response to the query results through Reinforcement Learning from Human Feedback (RLHF) [figs. 9, 10; col. 16, lines 61-67; col. 17, lines 1-15; col. 18, lines 12-30; col. 19, lines 40-61; col. 24, lines 21-27 of McCarson teaches incrementally refining the AI model (e.g., refining the hypothesis adaptively over time) based on the query selection data and the effectiveness of mitigation actions taken in response to the query results through Reinforcement Learning from Human Feedback (RLHF) (e.g., the RLHF 902 of fig. 9)].
As per claim 6, McCarson teaches the system of claim 5.
McCarson further teaches incrementally refining the AI model with a dual feedback loop combining the Reinforcement Learning from Human Feedback (RLHF) with Reinforcement Learning from AI Feedback (RLAIF) [figs. 9, 10; col. 3, lines 25-43; col. 16, lines 61-67; col. 17, lines 1-58; col. 18, lines 4-30; col. 24, lines 21-27 of McCarson teaches incrementally refining the AI model with a dual feedback loop combining the Reinforcement Learning from Human Feedback (RLHF) (e.g., the RLHF 902 of fig. 9) with Reinforcement Learning from AI Feedback (RLAIF) (e.g., reinforcement from the various models of analytics engine 830 or the various reinforcement learning methods that could either be AI-driven or HITM-driven to validate)].
As per claim 7, McCarson teaches the system of claim 1.
McCarson further teaches wherein refining the AI model comprises automatically restructuring a vector index for the multi-dimensional vector representations [col. 19, lines 21-39 of McCarson teaches wherein refining the AI model comprises automatically restructuring (e.g., from the source of the attack to the attack behaviors) a vector index for the multi-dimensional vector representations (e.g., the attack vectors)].
As per claim 9, McCarson teaches the system of claim 1.
McCarson further teaches wherein collecting the real-time telemetry data comprises: receiving the real-time telemetry data through multiple different security threat feeds, each security threat feed having a different data format; and outputting the real-time data in a common schema with standardized metadata tagging for cross-correlation across different data sources [figs. 2, 7; col. 5, lines 30-65; col. 9, lines 43-65; col. 13, lines 10-22 of McCarson teaches receiving the real-time telemetry data through multiple different security threat feeds, each security threat feed having a different data format; and outputting the real-time data in a common schema with standardized metadata tagging (e.g., assigning metadata to the pre-processed data) for cross-correlation across different data sources].
As per claim 10, McCarson teaches the system of claim 1.
McCarson further teaches in response to the security alert being an indicator of attack, issuing a ticket that corresponds to the actual security threat, by a ticketing system that is integrated with the cybersecurity threat detection and mitigation system; and automatically assigning the ticket to an appropriate security team based on a threat classification and team expertise [figs. 2, 7, 8; col. 11, lines 43-67; col. 13, lines 1-9; col. 14, lines 50-67 of McCarson teaches in response to the security alert being an indicator of attack, issuing a ticket that corresponds to the actual security threat, by a ticketing system that is integrated with the cybersecurity threat detection and mitigation system; and automatically assigning the ticket to an appropriate security team (e.g., storing within probationary database for further correlations refinement) based on a threat classification (e.g., characterized leading indicator) and team expertise (e.g., the additional computation cybles)].
Claims 11, 13-17, 19 and 20 are method claims that correspond to the system claims 1, 3-7, 9 and 10, and are analyzed and rejected accordingly – see the claim objections to the claims 13 and 17.
Allowable Subject Matter
Claims 2, 8, 12 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims, and amended to overcome the 112(b) rejections (if any) stated above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAUNG T LWIN whose telephone number is (571)270-7845. The examiner can normally be reached on Monday - Friday 10:00 am - 6:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MAUNG T LWIN/Primary Examiner, Art Unit 2495