Prosecution Insights
Last updated: August 15, 2026
Application No. 19/211,005

METHOD FOR EXPOSURE MANAGEMENT AND AN EXPOSURE MANAGEMENT SYSTEM

Non-Final OA §101§103
Filed
May 16, 2025
Priority
May 20, 2024 — EU 24176841.5
Examiner
WALIULLAH, MOHAMMED
Art Unit
Tech Center
Assignee
Withsecure Corporation
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
635 granted / 732 resolved
+26.7% vs TC avg
Moderate +11% lift
Without
With
+10.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
31 currently pending
Career history
751
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
62.3%
+22.3% vs TC avg
§102
4.8%
-35.2% vs TC avg
§112
12.0%
-28.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 732 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-15 were amended, and claims 16-19 were added as new claims by preliminary amendments. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. The claimed invention as in claim 14 is addressed to “A computer program comprising instructions which, when executed by a computer " that can be interpreted as referring to lines of programming within a computer system, rather than referring to the program product or medium as a physical object. Accordingly, the claim becomes nothing more than sets of software instructions which are "software per se". “Software per se” is non-statutory under 35 USC 101 because it is merely a set instructions without any defined tangible output or tangible result being produced. The requirement for tangible result under 35 USC 101 is defined in State Street Bank & Trust Co. v. Signature Financial Group Inc., 149 F.3d 1368, 47USPQ2d 1596 (Fed. Cir. 1998) Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3, 5-16 are rejected under 35 U.S.C. 103 as being unpatentable over Cohen et al(US 20050193430 A1:IDS supplied) in view of Engelberg et al(US 20230076372 A1). With regards to claim 1, Cohen discloses, An exposure management method in a network including at least one host, including one or more of an endpoint and a server, a security agent being installed to the at least one host (FIG 2 and associated text; [0057] FIG. 2 is a block diagram depicting components of a system in accordance with one embodiment of the present invention. As shown, the system includes a server computer 141 comprising server software, …. The system also includes a client computer 156, comprising client software, including one or more information discovery agents 158, a network…), the method comprising: requesting and/or receiving a list of vulnerabilities and/or misconfigurations of one or more of (i) the at least one host in the network and (ii) the network (FIG 1, 100 and associated text; [0027] A method of detecting and analyzing risks in a computer network in accordance with embodiments of the present invention is shown in FIG. 1. First, certain information about the network is collected. Raw network vulnerabilities are gathered by gone or more information discovery agents, step 100. In some embodiments, these information discovery agents may be manufactured and supplied by third parties such as Internet Scanner or System Scanner by Internet Security Systems, CyberCop Scanner by Network Associates, and Nessus Scanner by the Nessus Project.); running an attack path simulation for one or more of the at least one host of the network and the network (FIG 1 120 and associated text; [0037] The system then simulates attacks through the network topology from each start point to each end point by performing attack simulations, step 120. In some embodiments, all attacks from any starting point are simulated without guidance to a certain end point. Attack simulation is the process of creating attack simulation attack graphs for a given network identifying possible attacks through attack paths of the graph.); in a case in which an entry attack vector to a host is found with the attack path simulation, determining and/or creating at least one attack path related to the host based on the received list of vulnerabilities and/or misconfigurations (FIG 1 125 and associated text; [0052] Results of the attack simulation are stored in memory and used to generate a list of possible attacks on the network, step 125. Once the list of possible attacks is generated, the system then calculates the corresponding consequences of each possible attack, step 130. The attack route for each possible attack has a start point and an end point. Intermediate points of an attack route are end points of previous iterations of the attack route and also considered. As such, all network nodes which an attacker can compromise may be associated with end points, regardless of whether they are intermediate points of an attack route or ultimate end points of the final route.); forming an attack path map based on the attack path simulation ([0030] This topology model of actual vulnerabilities and corresponding network and services information is used by the system to detect and analyze risks posed by attackers. The system creates attack scenarios from the topology model to show potential attack paths which might be used by an attacker to exploit the network. An attack scenario can be presented in the form of an attack graph or other graph-based presentation forms. In some embodiments, attack graphs, graph nodes and edges describe all action routes in a given network. In some embodiments, data representing the attack graph for a network is stored in an array data structure. In some embodiments, an attack graph is presented as a layered graph in which nodes in odd layers represent states of services (i.e. known information), nodes in even layers represent actions, and edges connect the nodes.); Cohen does not exclusively but Engelberg teaches, verifying each of the determined and/or created at least one attack path of the attack path map by the at least one agent in the attack path, by verifying by the security agent that an attack or a part of the attack can be carried out as simulated ([0072] MulVAL uses a datalog solver on the program specification to check whether there exists an attack path from the input facts to a target goal. It does this by iteratively applying the derivation rules on facts until either reaching a target goal (a path exists) or reaching a fixed point, from which no new fact can be derived. In this case, no attack path to the target exists and the system is considered to be secure.); and removing one or more of the attacks and the attack paths from the attack path map which are one or more of attacks and paths that are determined by the security agent to be prevented, such that the one or more of the attacks and the paths that are determined to be prevented cannot be carried out as simulated ([0127] During execution of analytics, one or more remediation actions can be identified that have the highest impact in reducing risk, while minimizing cost. For example, a remediation action can be applied to the augmented process-aware AAG to evaluate an impact that the remediation action has on risk in view of its cost. With reference to FIG. 6B, the first remediation action can be applied to the augmented process-aware AAG 600′ by removing the fact node 602 (first fact). As a result, the first rule cannot be executed and the first impact cannot be realized. In view of this, a first risk value (R.sub.1) can be determined. In this example, it can be determined that R.sub.base is greater than R.sub.1. A difference value can be provided as ΔR.sub.base-1 (i.e., R.sub.base−R.sub.1). The augmented process-aware AAG 600′ can be reset to include the fact node 602, the rule node 606, and the impact node 608, and the first remediation action can be applied to the augmented process-aware AAG 600′ by removing the fact node 604 (second fact).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Cohen’s method with teaching of Engelberg in order to identify the most vulnerable components within a computer network and can be used to evaluate fixes of vulnerabilities that the AAG reveals (e.g., by fixing a limited number of issues, any adversary attack on the computer network, or on certain components in the computer network can be stopped (Engelberg[0005];) . With regards to claim 2, Cohen further discloses, wherein the receiving the list of vulnerabilities and/or misconfigurations comprises receiving a list of detected known vulnerabilities found by a vulnerability management service (027] A method of detecting and analyzing risks in a computer network in accordance with embodiments of the present invention is shown in FIG. 1. First, certain information about the network is collected. Raw network vulnerabilities are gathered by gone or more information discovery agents, step 100. In some embodiments, these information discovery agents may be manufactured and supplied by third parties such as Internet Scanner or System Scanner by Internet Security Systems, CyberCop Scanner by Network Associates, and Nessus Scanner by the Nessus Project.). With regards to claim 3, Cohen further discloses, wherein the at least one security agent verifies attacks, vulnerability exploits, and misconfigurations of the attack path simulation that are usable ([0028] Information discovery agents also gather network topology and services information, or configuration of security measures such as access control lists from routers, firewalls, or other devices, step 105. In some embodiments, the network topology, services, and vulnerability information may alternatively be provided in whole or in part by XML data or other data as specified by a user.). With regards to claim 5-6, Cohen further discloses, wherein a simulated attack path is deleted from the attack path map in a case in which a part of the at least one attack path is not utilizable by malicious actors based on the verification by the security agent; wherein an attack path is kept in the attack path map in a case in which all steps and/or parts of the attack path are verified by the security agent to be implementable and/or usable by a malicious actor (0029] By comparing the raw vulnerabilities with information about the network topology and the network services, the system combines vulnerabilities with logic to determine actual vulnerabilities which might be exploited by an attacker, step 110. A vulnerabilities rule set containing logic (which logic can generally include any kind of logic or methodology, including predicate logic or first-order logic, used for organization or presentation of facts, effects, conditions or other information associated with vulnerabilities) specifies combinations of raw vulnerabilities that represent actual vulnerabilities when combined with various network topologies and network services (herein, the term "network information" generally includes network topology information, network service information, or both). A model of the network is thus created detailing the network topology and the actual atomic vulnerabilities present at each network node. As such, "raw vulnerability," as used herein, generally includes theoretical atomic vulnerabilities associated with network nodes as such vulnerabilities would exist without consideration of effects of network information on such vulnerability. Furthermore, "actual vulnerability," as used herein, generally includes atomic vulnerabilities associated with network nodes considering effects of network information on such vulnerability. It is further to be noted that "raw vulnerability," as used herein, includes "filtered raw vulnerability" as described herein). With regards to claim 7, Cohen further discloses, wherein the verifying that the attack or the part of the attack can be carried out comprises at least one of the following: verifying whether there is suitable network connection from a host to next part of the attack path, verifying whether necessary preconditions for privilege escalation are in place, verifying whether the host has credentials which are accessible to a malicious actor, verifying whether a user would be able to write or execute files in a predefined location, verifying whether a vulnerable application has been executed at the host, verifying whether there are vulnerabilities suitable for lateral movement on other hosts, verifying domain level privilege escalation, and verifying available credentials that would be required to escalate attack further on an internal server ([0047] The attack simulation then commences in line 3 from a specified attack starting point. In lines 4-7, the system then loops through a moving front-line algorithm by repeatedly evaluating the constraints for every state/graph node that has not yet been reached. If the constraint is met and an attacker is thus able to obtain access associated with the graph node, an edge to the graph node is added from every graph node that enabled the constraint. The moving front-line algorithm continues adding edges to new graph nodes until no more states/graph nodes can be reached at which point the process terminates. In some embodiments, edges can connect graph nodes that represent states in the same host, for example, in the case of an exploitation of privilege escalation vulnerability.). With regards to claim 8, Cohen further discloses, wherein the security agent uses at least one of the following information when verifying the attack path: a target network layout, routing rules, firewall rules, local user privileges, browser stored credentials, cloud credentials, Application Programming Interface (API) keys, registry configurations, file write permissions, a list of services that are running which listen on external network interfaces, and cryptographic authentication keys ([0028] Information discovery agents also gather network topology and services information, or configuration of security measures such as access control lists from routers, firewalls, or other devices, step 105. In some embodiments, the network topology, services, and vulnerability information may alternatively be provided in whole or in part by XML data or other data as specified by a user.). With regards to claim 9, Cohen in view of Engelberg discloses, wherein the entry attack vector comprises one or more of: remote code execution in publicly visible service, a phishing opportunity due to a user having a vulnerable client or player software installed, and a client software application by which the user can execute an application by clicking (Engelberg [0081] In some examples, impact vectors are specified by domain experts and are embedded within the ontology per impact type (e.g., denial of service (DoS) has a high impact on availability). In some examples, each asset (represented as a node that represents an asset), has an asset identifier, which enables mapping to the asset (e.g., rules are mapped to assets based on asset identifiers according to outgoing impacts).). With regards to claim 10, Cohen further discloses, wherein the server of the network manages verification of the attack path by instructing the security agent at the at least one host to verify its part of an attack path ([0059] The collection manager 144 is responsible for coordinating network data collection performed by the discovery agents 158. The control manager 144 activates the agents, distils information received by the agents according to rules stored in the rules database 172 and the configuration database 174, and updates the network and services database 160 with changes and information received from the discovery agents 158.). Claim 11 is device(server) claim performs substantially similar steps of method claim 1 also rejected accordingly. Claim 12 is a system claim corresponding system claim 12, also rejected accordingly. Claim 13 is a system claim corresponding method claim 1, also rejected accordingly. Claim 14 is a product claim corresponding system claim 13, also rejected accordingly. Claim 15 is a medium claim corresponding system claim 13, also rejected accordingly. With regards to claim 16, Examiner taking official notice that “wherein the running the attack path simulation occurs at one or more of a backend system and at the at least one server” is not an inventive step and well known in the art. Claim(s) 4 are rejected under 35 U.S.C. 103 as being unpatentable over Cohen et al(US 20050193430 A1:IDS supplied) in view of Engelberg et al(US 20230076372 A1) and further in view of Aloisio et al(US 10749890 B1:IDS supplied). With regards to claim 9, Cohen in view of Engelberg do not but Aloisio discloses, wherein the verifying the at least one attack path with the security agent comprises sending instructions to the security agent in the at least one host where a next potential step in the at least one attack path is, and/or which steps are verified as long as the steps of the attack path are usable by a malicious actor (col 8 line 3-15; Specifically, the analytic server may follow the logic of the attack tree model by traversing the attack tree model from bottom up and determine if the logging information, alerts and events data satisfy the operating conditions of the nodes. From the bottom up, child nodes are lower-level operating conditions of an attack, at least one of the child nodes must be satisfied to make the direct parent node true, the parent node may represent higher-level operating condition; when the root is satisfied (e.g., the highest level operating condition is satisfied), the attack is complete. The analytic server may perform automated evaluations and computations over the attack tree model, testing on-line to see whether particulate vulnerabilities are present or known-weak configurations or libraries are in use. In addition, by correlating information from multiple sources, the analytic server may be able to learn context for alerts and distinguish likely false alarms, as well as true, but unimportant, alerts. Thus, the analytic server may reduce false positives and cognitive load the false positives may cause.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Cohen in view of Engelberg’s method with teaching of Aloisio in order to provide ranking and prioritizing attack indicators so that their time may be more efficiently spent on the most important threats (Aloisio Col 2 line 20-30;) . Claim(s) 17 are rejected under 35 U.S.C. 103 as being unpatentable over Cohen et al(US 20050193430 A1:IDS supplied) in view of Engelberg et al(US 20230076372 A1) and further in view of Kras et al(US 20190005428 A1). With regards to claim 17, Cohen in view of Engelberg do not but Kras discloses, wherein the entry attack vector comprises information which indicates that an installed application has been used for phishing ([0097]; In some embodiments, the phishing emails may request that the user perform a certain action, such as clicking on a link, providing sensitive information by replying to the email, or transferring money to an account owned by the attacker and then sending a reply email to confirm that the money has been transferred. A common attack vector used by phishing mails is to get users to click on links in an email or to click on links delivered in documents attached to phishing). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Cohen in view of Engelberg’s method with teaching of Kras in order to determines a configuration for each of a baseline simulated phishing campaign, electronic based training of users of the entity for security awareness and one or more subsequent simulated phishing campaigns (Kras Abstract) . Claim(s) 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over Cohen et al(US 20050193430 A1:IDS supplied) in view of Engelberg et al(US 20230076372 A1) and further in view of NEWMAN et al(WO 2024228181 A1). With regards to claim 18, Cohen in view of Engelberg do not but NEWMAN discloses, wherein the information comprises one or more of Endpoint Detection and Response (EDR)/Managed Detection and Response (MDR)-system information and process execution logs (NEWMAN [068] In the Detection & response mode, once a new attack vector is detected, the engineers may create a new "trigger" and "action" for the detected attack vector. For example, a trigger may be: how the EDR may detect the new attack vector in real-time, and the action may be the operation that the EDR needs to take to mitigate the attack.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Cohen in view of Engelberg’s method with teaching of NEWMAN in order to detect and respond to one or more systematical exceptional events in a network of computerized devices(NEMAN Abstract). With regards to claim 19, Cohen in view of Engelberg and NEWMAN discloses, wherein the client software application by which the user can execute the application by clicking includes an email client, a web browser, and an instant messaging client (NEWMAN [019] For example, wherein the threat comprises at least one of a malware attack, a ransomware attack, installing spyware and performing hacking.). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20190190955 A1 Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMED WALIULLAH whose telephone number is (571)270-7987. The examiner can normally be reached 8.30 to 430 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 1-571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOHAMMED WALIULLAH/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

May 16, 2025
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705390
PRIVACY-AWARE DATA TRANSFORMATIONS
3y 8m to grant Granted Aug 11, 2026
Patent 12695610
BLOCKCHAIN DATA PROCESSING METHOD AND APPARATUS, COMPUTER DEVICE, MEDIUM, AND PRODUCT
2y 7m to grant Granted Jul 28, 2026
Patent 12695613
DATA COMMUNICATION SYSTEM, CENTER DEVICE, MASTER DEVICE, STORAGE MEDIUM STORING ENCRYPTION PROGRAM, AND STORAGE MEDIUM STORING DECRYPTION PROGRAM
2y 4m to grant Granted Jul 28, 2026
Patent 12683763
COMPUTER-BASED SYSTEMS CONFIGURED TO SELECT A MONITORED DATA SEGMENTATION AND METHODS OF USE THEREOF
2y 6m to grant Granted Jul 14, 2026
Patent 12682081
KEY DEPRECATION WITHOUT CERTIFICATE REVOCATION
2y 6m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
98%
With Interview (+10.9%)
2y 4m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 732 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month