DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to communication filed on 05/13/2025.
Status of claims in the instant application:
Claims 1-20 are pending.
Priority
This application is a CON of 18/219,549 filed on 07/07/2023 now Pat US 12326943 B2 which is a CON of 17/004,392 filed on 08/27/2020 now PAT 11,709,944 which claims benefit of 62/893,350 filed on 08/29/2019.
Information Disclosure Statement
Information Disclosure Statements (IDS) filed on 05/13/2025 and 05/14/2025 have been considered, and a signed copies of the IDS forms have been attached to this office action.
Drawings
Drawings filed on 05/13/2025 have been inspected, and it’s in compliance with MPEP 608.02.
Specification
Specification filed on 05/13/2025 has been inspected and it’s in compliance with MPEP 608.01.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f):
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f). The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) because the claim limitations use a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are:
Claim 1: “An apparatus, comprising: an intelligent-adversary simulator is configured to construct a graph of a virtualized instance of a network …”; “intelligent-adversary simulator is configured to calculate one or more paths of least resistance …”; “a formatting module is configured to generate the report with the identified critical devices connecting to …”; “intelligent-adversary simulator is configured to calculate the paths of least resistance from the virtualized instance of the source device through to other virtualized instances of components …”
Claim 2: “intelligent-adversary simulator is configured to create the graph …”
Claim 3: “intelligent-adversary simulator is configured to search and query …”;
Claim 4: “intelligent-adversary simulator is configured to create the virtualized version of the network and its network devices …”
Claim 5: “intelligent-adversary simulator is configured to simulate the compromise of a spread of the cyber threat …”
Claim 6: “intelligent-adversary simulator is configured to construct the graph …”; “intelligent-adversary simulator is configured to model a compromise …”
Claim 7: “intelligent-adversary simulator is configured to integrate within a cyber security appliance and …”
Claim 8: “a profile manager module configured to communicate and cooperate …”
Claim 9: “a profile manager module is configured to maintain a profile tag for each device …”
Claim 10: “intelligent-adversary simulator is configured to search and query …”.
Because these claim limitations are being interpreted under 35 U.S.C. 112(f), they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
Examiner has investigated the disclosure (specification, drawing …) and finds the following for the place holder terms identified above, in the published instant application (US 20250272412 A1):
Para [0006]: A formatting module can generate the report with the identified critical devices connecting to the virtualized instance of the network that should have the priority to allocate security resources to them. One or more processing units can execute software instructions associated with the intelligent-adversary simulator, the formatting module, and other modules, and AI models in the cyber security appliance. Likewise, one or more non-transitory storage mediums can store at least software associated with the intelligent-adversary simulator, modules, and AI models in the cyber security appliance.
Para [0117]: A computing system can be, wholly or partially, part of one or more of the server or client computing devices in accordance with some embodiments. Components of the computing system can include, but are not limited to, a processing unit having one or more processing cores, a system memory, and a system bus that couples various system components including the system memory to the processing unit.
Based on at-least the above description in the specification, Examiner interprets that the various claimed modules, units and simulators are implemented by a combination of hardware and software elements. The software elements are stored in memory (hardware) that are executed by the processing unit (hardware) that are in communication to the memory.
If applicant does not intend to have these limitations interpreted under 35 U.S.C. 112(f), applicant may: (1) amend the claim limitations to avoid them being interpreted under 35 U.S.C. 112(f) (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitations recite sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 3 and 13 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 3 recites the limitation “the one or more Al models in the cyber security appliance, already know about the network, and its components, under analysis to create the graph of the virtualize instance of the network, where the graph of the virtualize instance of the network is created with two or more of 1) known characteristics of the network itself, 2) pathway connections between devices on that network, 3) security features and credentials of devices and/or their associated users, and 4) behavioural characteristics of the devices and/or their associated users connecting to that network, which all of this information is obtained from what was already know about the network from the cyber security appliance”.
Examiner clarifies that the use of “and/or” in the same claim limitation, as in the claimed invention, makes the claim language ambiguous/indefinite’; “and” requires both the terms (devices and users); however “or” requires only one the terms. So the use of “and/or” results in contradictory requirements, and hence claim 3 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 13 also has similar issue as claim 3, and hence rejected for similar reason.
Appropriate corrections required.
*** Note: For examination purposes examiner interprets claims to recite only “and” instead of “and/or”.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. US 11709944 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are just broader version of claims of the issued patent US 11709944 B2 that make the claims of the instant application obvious. The differences in wording are just obvious variations.
Instant Application
Reference Patent (11709944)
1. An apparatus, comprising: an intelligent-adversary simulator is configured to construct a graph of a virtualized instance of a network including i) devices connecting to the virtualized instance of the network as well as ii) connections and pathways through the virtualized instance of the network, where the virtualized instance of the network is based on an actual network under analysis, where the graph of the virtualized instance of the network is constructed in order to run a simulated cyber-attack scenario on the virtualized instance of the network in order to identify one or more critical devices connecting to the virtualized instance of the network from a security standpoint, and then put this information into a generated report; and thus, help prioritize which critical devices connecting to the virtualized instance of the network should have a priority to allocate security resources to them based on the simulated cyber-attack scenario, where, during a simulation, the intelligent-adversary simulator is configured to calculate one or more paths of least resistance for a cyber threat in the cyber-attack scenario to compromise 1) a virtualized instance of a source device, originally compromised by the cyber threat, 2) through to other virtualized instances of components of the virtualized network, 3) until reaching an end goal of the cyber-attack scenario in the virtualized network, all based on historic knowledge of connectivity and behaviour patterns of users and devices within the actual network under analysis, a formatting module is configured to generate the report with the identified critical devices connecting to the virtualized instance of the network that should have the priority to allocate security resources to them, one or more processing units are configured to execute software instructions associated with the intelligent-adversary simulator and the formatting module, and one or more non-transitory storage mediums are configured to store at least software associated with the intelligent-adversary simulator, and where the intelligent-adversary simulator is configured to calculate the paths of least resistance from the virtualized instance of the source device through to other virtualized instances of components of the virtualized network until reaching an end goal of the cyber-attack scenario; but not calculate every theoretically possible path from the virtualized instance of the source device to the end goal of the cyber-attack scenario, each time a hop is made from one device in the virtualized network to another device in the virtualized network in order to reduce an amount of computing cycles needed by the one or more processing units as well as an amount of memory storage needed in the one or more non-transitory storage mediums.
1. An apparatus, comprising: one or more memory storage devices; one or more processors, coupled to the one or more memory storage devices, the one or more processors configured to cause: an intelligent-adversary simulator configured to construct a graph of a virtualized instance of a network including: i) devices connecting to the virtualized instance of the network and ii) connections and pathways through the virtualized instance of the network; wherein the virtualized instance of the network is based on an actual network under analysis, wherein the graph of the virtualized instance of the network is constructed to run a simulated cyber-attack scenario on the virtualized instance of the network to identify one or more critical devices connecting to the virtualized instance of the network from a security standpoint; wherein information constructed from the graph is configured to generate a report; wherein the critical devices connecting to the virtualized instance of the network are configured to have priority to allocate security resources, at least based on information from the report and based on the simulated cyber-attack scenario; and wherein, during a simulation, the intelligent-adversary simulator is configured to calculate one or more paths of least resistance for a cyber threat in the cyber-attack scenario to compromise 1) a virtualized instance of a source device, previously compromised by the cyber threat, 2) through to other virtualized instances of components of the virtualized network, 3) until reaching an end goal of the cyber-attack scenario in the virtualized network, all of the above instances being based on historic knowledge of connectivity and behaviour patterns of users and devices within the actual network under analysis; a formatting module configured to generate the report with the identified critical devices connecting to the virtualized instance of the network that should have the priority to allocate security resources; one or more processing units configured to execute software instructions associated with the intelligent-adversary simulator and the formatting module; one or more non-transitory storage mediums configured to store at least software associated with the intelligent-adversary simulator; and wherein the intelligent-adversary simulator is configured to calculate the paths of least resistance from the virtualized instance of the source device through to other virtualized instances of components of the virtualized network until reaching an end goal of the cyber-attack scenario without calculating every theoretically lengthy or difficult possible path to compromise the virtualized instances of components of the virtualized network from the virtualized instance of the source device in the end goal of the cyber-attack scenario to reduce the amount of computing cycles needed by the one or more processing units and an amount of memory storage needed in the one or more non-transitory storage mediums thereby reducing the number of times a hop is made from one device in the virtualized network to another device in the virtualized network.
2. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to create the graph of the virtualized network, with its nets and subnets, where two or more of the devices connecting to the virtualized network are assigned with different weighting resistances to malicious compromise from the cyber threat being simulated in the cyber-attack scenario during the simulation.
2. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to create the graph of the virtualized network, the graph including nets and subnets, wherein two or more of the devices connecting to the virtualized network are assigned with different weighting resistances to malicious compromises from the cyber threat being simulated in the cyber-attack scenario during the simulation.
3. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to search and query, two or more of i) a data store, ii) modules, and iii) one or more Artificial Intelligence (AI) models making up a cyber security appliance protecting the actual network under analysis from cyber threats, on what, i) the data store, ii) the modules, and iii) the one or more AI models in the cyber security appliance, already know about the network, and its components, under analysis to create the graph of the virtualize instance of the network, where the graph of the virtualize instance of the network is created with two or more of 1) known characteristics of the network itself, 2) pathway connections between devices on that network, 3) security features and credentials of devices and/or their associated users, and 4) behavioural characteristics of the devices and/or their associated users connecting to that network, which all of this information is obtained from what was already know about the network from the cyber security appliance.
3. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to search and query two or more of i) a data store, ii) modules, and iii) one or more Artificial Intelligence (AI) models making up a cyber security appliance protecting the actual network under analysis from cyber threats, on what, i) the data store, ii) the modules, and iii) the one or more AI models in the cyber security appliance, already know about the network, and its components, under analysis to create the graph of the virtualize instance of the network, wherein the graph of the virtualize instance of the network is created with two or more of 1) known characteristics of the network itself, 2) pathway connections between devices on that network, 3) security features and credentials of devices and/or their associated users, and 4) behavioural characteristics of the devices and/or their associated users connecting to that network, which all of this information is obtained from what was already know about the network from the cyber security appliance.
4. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to create the virtualized version of the network and its network devices; and thus, does not degrade or compromise the actual network, or its actual network devices, under analysis when running the simulation, and where the virtualized network, and its network components connecting to the network, being tested during the simulation are up to date and accurate for a time the actual network under analysis is being tested and simulated because the intelligent-adversary simulator is configured to obtain actual network data collected by two or more of 1) modules, 2) a data store, and 3) one or more AI models of a cyber security appliance protecting the actual network under analysis from cyber threats.
4. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to create the virtualized version of the network and its network devices thereby does not degrade or compromise the actual network, or its actual network devices, under analysis when running the simulation, and wherein the virtualized network, and its network components connecting to the network, being tested during the simulation are up to date and accurate for a time the actual network under analysis is being tested and simulated because the intelligent-adversary simulator is configured to obtain actual network data collected by two or more of 1) modules, 2) a data store, and 3) one or more AI models of a cyber security appliance protecting the actual network under analysis from cyber threats.
5. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to simulate the compromise of a spread of the cyber threat being simulated in the simulated cyber-attack scenario on connections between the devices connected to the virtualized network, and where the intelligent-adversary simulator is configured to then perform a calculation on an ease of transmission of the cyber threat between those devices, including key network devices.
5. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to simulate the compromise of a spread of the cyber threat being simulated in the simulated cyber-attack scenario on connections between the devices connected to the virtualized network, and wherein the intelligent-adversary simulator is configured to then perform a calculation on an ease of transmission of the cyber threat between those devices, including key network devices.
6. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to construct the graph of the virtualized version of the network from knowledge known and stored by modules, a data store, and one or more AI models of a cyber security appliance protecting an actual network under analysis, where the knowledge known and stored is obtained at least from ingested traffic from the actual network under analysis, and where the intelligent-adversary simulator is configured to model a compromise by the cyber threat through the virtualized version of the network based upon how likely it would be for the cyber-attack to spread to achieve either of 1) a programmable end goal of that cyber-attack scenario set by a user, or 2) set by default an end goal scripted into the selected cyber-attack scenario.
6. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to construct the graph of the virtualized version of the network from knowledge known and stored by modules, a data store, and one or more AI models of a cyber security appliance protecting an actual network under analysis, wherein the knowledge known and stored is obtained at least from ingested traffic from the actual network under analysis, and wherein the intelligent-adversary simulator is configured to model a compromise by the cyber threat through the virtualized version of the network based upon how likely it would be for the cyber-attack to spread to achieve either of 1) a programmable end goal of that cyber-attack scenario set by a user, or 2) set by default an end goal scripted into the selected cyber-attack scenario.
7. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to integrate within a cyber security appliance and cooperate with components within the cyber security appliance installed and protecting the network from cyber threats by making use of outputs, data collected, and functionality from two or more of a data store, other modules, and one or more AI models already existing in the cyber security appliance, and where the comprise of the source device is an infection spread to and from the source device in the virtualized instance of the network under analysis, where a likelihood of the compromise is tailored and accurate to an actual device being simulated because the cyber-attack scenario is based upon security credentials and behaviour characteristics from actual traffic data fed to the modules, data store, and AI models of the cyber security appliance.
7. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to integrate within a cyber security appliance and cooperate with components within the cyber security appliance installed and protecting the network from cyber threats by using outputs, data collected, and functionality from two or more of a data store, other modules, and one or more AI models already existing in the cyber security appliance, and wherein the comprise of the source device is an infection spread to and from the source device in the virtualized instance of the network under analysis, wherein a likelihood of the compromise is tailored and accurate to an actual device being simulated because the cyber-attack scenario is based upon security credentials and behaviour characteristics from actual traffic data fed to the modules, data store, and AI models of the cyber security appliance.
8. The apparatus of claim 1, further comprising: a profile manager module configured to communicate and cooperate with the intelligent-adversary simulator, where the profile manager module is configured to maintain a profile tag on all of the devices connecting to the actual network under analysis based on their behaviour and security characteristics and then supply the profile tag for the devices connecting to the virtualized instance of the network when the construction of the graph occurs.
8. The apparatus of claim 1, further comprising: a profile manager module configured to communicate and cooperate with the intelligent-adversary simulator, wherein the profile manager module is configured to maintain a profile tag on all of the devices connecting to the actual network under analysis based on their behaviour and security characteristics and supply, when the construction of the graph occurs, the profile tag for the devices connecting to the virtualized instance of the network.
9. The apparatus of claim 1, further comprising: wherein a profile manager module is configured to maintain a profile tag for each device before the simulation is carried out; and thus, eliminates a need to search and query for known data about each device being simulated during the simulation, and where the profile manager module is configured to maintain the profile tag on each device based on their behaviour as detected by a network module cooperating with network probes ingesting traffic data for network devices and network users in the network under analysis as well as cooperation and analysis with the AI models modelling a normal pattern of life for entities in that network under analysis.
9. The apparatus of claim 1, further comprising: wherein a profile manager module is configured to maintain a profile tag for each device before the simulation is carried out thereby eliminating a need to search and query for known data about each device being simulated during the simulation, and wherein the profile manager module is configured to maintain the profile tag on each device based on their behaviour as detected by a network module cooperating with network probes ingesting traffic data for network devices and network users in the network under analysis as well as cooperation and analysis with the AI models modelling a normal pattern of life for entities in that network under analysis.
10. The apparatus of claim 1, further comprising: where the intelligent-adversary simulator is configured to search and query i) ingested network traffic data as well as ii) analysis on that network traffic data from one or more AI models within the cyber security appliance, where the intelligent-adversary simulator has access to and obtains a wealth of actual network data from the network under analysis from the data store and the AI models of normal pattern of life for entities in the network under analysis, which means paths of least resistance through possible routes in this network can be computed during the simulation even when a first possible route of least resistance 1) is not previously known or 2) has not been identified by a human before to determine a spread of the cyber threat from device-to-device.
10. The apparatus of claim 1, further comprising: wherein the intelligent-adversary simulator is configured to search and query i) ingested network traffic data as well as ii) analysis on that network traffic data from one or more AI models within the cyber security appliance, wherein the intelligent-adversary simulator has access to and obtains actual network data from the network under analysis from the data store and the AI models of normal pattern of life for entities in the network under analysis, wherein the paths of least resistance through possible routes in this network can be computed during the simulation even when a first possible route of least resistance 1) is not previously known or 2) has not been identified by a human before to determine a spread of the cyber threat from device-to-device.
Claims 11-20 of the instant application are method claims that are parallel to apparatus claim 1-10, and they are also rejected over claims 11-20 of the reference patent 11709944.
Claims 1-20 of the instant application are also rejected over claims 1-17 of the reference patent US 12326943 B2 under non-statutory double patenting.
Allowable Subject Matter
Claims 1-20 are allowed over prior arts of record.
As allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a).
Applicants response must address the double patenting rejections, 112 rejections and other issue identified, including interpretation of claims under 112(f).
Reasons for allowance will be furnished upon allowance.
Pertinent Prior Arts
The following prior arts made of record and not relied upon are considered pertinent to applicant's disclosure.
US 20160205122 A1; Bassett: Bassett discloses An improved method for analyzing computer network security has been developed. The method first establishes multiple nodes, where each node represents an actor, an event, a condition, or an attribute related to the network security. Next, an estimate is created for each node that reflects the ease of realizing the event, condition, or attribute of the node. Attack paths are identified that represent a linkage of nodes that reach a condition of compromise of network security. Next, edge probabilities are calculated for the attack paths. The edge probabilities are based on the estimates for each node along the attack path. Next, an attack graph is generated that identifies the easiest conditions of compromise of network security and the attack paths to achieving those conditions. Finally, attacks are detected with physical sensors on the network, that predict the events and conditions. When an attack is detected, security alerts are generated in response to the attacks.
US 20180295154 A1; Crabtree et al.: Crabtree discloses a system for mitigation of cyberattacks employing an advanced cyber decision platform comprising a time series data store, a directed computational graph module, an action outcome simulation module, and observation and state estimation module, wherein the state of a network is monitored and used to produce a cyber-physical graph representing network resources, simulated network events are produced and monitored, and the network events and their effects are analyzed to produce security recommendations.
US 20210021629 A1; Dani et al.: Dani discloses methods and systems for generating an attack path based on user and system risk profiles are presented. The method comprises determining user information associated with a computing device; determining system exploitability information of the computing device; determining system criticality information of the computing device; determining a risk profile for the computing device based on the user information, the system exploitability information, and the system criticality information; and generating an attack path based on the risk profile. The attack path indicates a route through which an attacker accesses the computing device. The system exploitability information indicates one or more of: the vulnerability associated with the computing device, an exposure window associated with the computing device, and a protection window associated with the computing device. The system criticality information indicates one or more: assets associated with the computing device and services associated with the computing device.
Dani discloses that the vulnerability information may be used to simulate attack execution operations (e.g., red teaming/pentesting attack scenarios) in order to better understand vulnerable points within one's IT infrastructure. In some cases, the vulnerability information (e.g., comprised in the risk profile discussed below) may facilitate automatically selecting the most vulnerable or most lucrative assets (e.g., computing device, hardware and/or software resources) within a given computing system/device. In other cases, the data obtained from the vulnerability information may be “ingested” or processed by other systems (e.g., Artificial Intelligence software, machine learning resources, Qualys Breach and Attack Simulation system, etc.) in order to develop more robust computer security systems, tools, and security models. The systems discussed in this disclosure are able to determine computer security vulnerability information for a user, and/or organization, and/or a computing device associated the user and/or the organization and are subsequently used to generate attack paths.
US 20200177618 A1; Hassanzadeh et al.: Hassanzadeh discloses a state graph representative of a set of action states within a network, each action state representing an attack that can be performed by an adversary within the network, determining a path stealthiness value for each attack path of a set of attack paths within the network, path stealthiness values being determined based on a mapping that maps each action state to one or more technique-tactic pairs and one or more security controls, determining a path hardness value for each attack path of the set of attack paths within the network, path hardness values being determined based on a state correlation matrix that correlates action states relative to each other, and a decay factor that represents a reduction in effort required to repeatedly perform an action of an action state, and selectively generating one or more alerts based on one or more of path stealthiness values and path hardness values.
Implementations of the present disclosure are directed to an agile security platform for enterprise-wide cyber-security. More particularly, implementations of the present disclosure are directed to an agile security platform that determines asset vulnerability of enterprise-wide assets including cyber-intelligence and discovery aspect of enterprise information technology (IT) systems, and enterprise operational technology (OT) systems, asset value, potential for asset breach, and criticality of attack paths towards target(s) including hacking analytics of enterprise IT/OT systems performed in a non-intrusive manner. In general, and as described in further detail herein, the agile security platform of the present disclosure prioritizes risks and respective remediations based on vulnerabilities of assets within an enterprise network (e.g., cyber intelligence and discovery aspect of IT/OT systems), the value of the assets, and the probability that the assets will be breached in terms of attacker's effort and security control employed in the network.
US 20190342307 A1; GAMBLE et al.: GAMBLE discloses a cybersecurity platform is described that processes collected data using a data model to identify and link anomalies and in order to identify generate security events and intrusions. The platform generates graph data structures using the security anomalies extended using additional data. The graph data structures represent links between nodes, the links being events, the nodes being machines and user accounts. The platform processes the graph data structures by combining similar nodes or grouping security events with common features to behaviour indicative of a single or multiple security events to identify chains of events which together represent an attack.
GAMBLE also discloses that the Security platform 100 can generate simulations that mimic the actions and techniques of sophisticated hackers. During these assessments, security platform 100 can configure rules linked to issues identified that were not easily detectable using conventional security tools. Security platform 100 can build models that identify security threats (e.g. via event detection 112) by analyzing volumes of network logs, user behaviour, and other relevant information. Security platform 100 can limit the number of abnormal events that trigger generation of notifications by security alerts 126 to those that are relevant from a security prospective using rules and parameters. Security platform 100 can minimize or avoid over optimizing the model to remove false positives as this can often result in a large number of false positives and potentially removed important alerts for (actual) threats. Security platform 100 can flag events generated by event detection 112 using data analytics processes and append additional context so that security alert unit 126 flags key threats for investigation and alert generation.
PAT US 10320813 B1; Ahmed et al.: Ahmed discloses that A service provider may deploy a security threat detection and mitigation platform in a multi-tenant virtualization environment that includes pluggable data collection, data analysis, and response components. The data analysis components may apply machine learning techniques to generate (based on training data sets) and refine (based on subsequently received data sets and feedback about the resulting classifications) predictors configured to detect particular types of security threats, such as denial of service attacks, botnets, scans, or remote desktop attacks. A data collection layer may collect, filter, organize, and curate network packet traffic data, network packet header data, or other information emitted by computing instances or applications executing on them, and provide the curated data as streams to the analysis layer. A response layer may automatically take action in response to threat detection (which may be overridden by an administrator) and may store classification data for subsequent analysis, feedback, and predictor refinement.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHABUB S AHMED whose telephone number is (571)272-0364. The examiner can normally be reached on 9AM-5PM EST M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached on 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MAHABUB S AHMED/Examiner, Art Unit 2434
/TESHOME HAILU/Primary Examiner, Art Unit 2434