DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is response to communication: response to amendments/arguments filed on 12/08/2025
Claims 1-8, 10-18, 20-28, and 30 are currently pending in this application. Claims 9, 19, and 29 have been cancelled.
The IDS filed on 02/06/2026, 03/25/2026, 04/01/2026, 04/22/2026, 05/11/2026, 05/27/2026, 06/11/2026, 06/25/2026, 07/02/2026, and 07/15/2026 have been considered.
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/20/2026 has been entered.
Response to Arguments
Applicant’s arguments have been fully considered but are moot in view of the new grounds of rejection. See amended rejection below.
Claim Rejections - 35 USC § 112
The prior 112 rejections have been withdrawn in response to applicant’s amendments/arguments.
Claim Rejections - 35 USC § 101
The prior 101 rejections have been withdrawn in response to applicant’s amendments/arguments.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-4, 8, 10-14, 18, 20-24, 28, and 30 are rejected under 35 U.S.C. 103 as unpatentable over Malhotra US Patent Application Publication 2021/0014256 (Malhotra), in view of Engle et al. US Patent Application Publication 2020/0389482 (Engle)
As per claim 1, Malhotra teaches a computer-implemented method, executed on a computing device, comprising: receiving an alert concerning an event within a computer platform (paragraph 29 with notification of potential cyber security threat); autonomously defining an investigation/remediation plan for addressing the event within the computer platform based upon one or more available resources (paragraph 33-34 with determining if remediation action exists with ai threat detection module); autonomously determining an efficacy level for the investiagatoin/remediation plan (abstract, paragraph 36, and throughout with determining that a remediation action exists); autonomously effectuating a remedial action based, at least in part upon the determined efficacy level (abstract, paragraph 36, and throughout with resolving the cyber security threat).
Malhotra does not explicitly teach wherein autonomously executing the investigation/remediation plan to address the event within the computer platform, including determining if the investigation/remediation plan to address the event within the computer platform executed properly. However, this would have been obvious. For example, see Engle (paragraph 68 with testing and validating efficacy of remedial control). Engle further shows the obviousness of escalating the event for additional remediation when the efficacy level is below a threshold (paragraph 68, wherein after remedial action is performed, validation component tests and validate efficacy by reapplying evaluation component to determine whether same/alternative are present in remediated network architecture; see paragraph 63 with evaluation component with determining risk to system; see paragraph 62 wherein remedial actions are taken if risk is above threshold; see further paragraph 68 wherein remedial control is evaluated and continually tested, thereby ensuring the cybersecurity network and ensuring residual risk is maintained within the organizations determined risk appetite)
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of Engle with Malhotra. One of ordinary skill in the art would have been motivated to perform such an addition to increase security by allowing a system to continually assess, monitor, and remediate cyber attacks in real time (paragraph 2 of Engle).
As per claim 2, Malhotra teaches wherein the alert concerns a network entity on the computer platform (abstract, paragraphs 34, 35, and throughout with alert concerning the application server).
As per claim 3, Malhotra teaches wherein the network entity includes one or more of: a network device; a computing device; a network user; a service; a container; a pod; and a virtual machine (paragraph 34-35 with application server/network device/computing device).
As per claim 4, Malhotra teaches wherein autonomously effectuating a remedial action based, at least in part, upon the determined efficacy level includes one or more of: defining the event as having been addressed; and escalating the event for additional remediation (paragraph 35 with fixing or patching vulnerability, rolling back previously-executed transactions, etc).
As per claim 8, Malhotra teaches wherein the investigation/remediation plan defines: one or more operations to be performed to address the event; and one or more tools to be utilized to address the event, wherein the one or more tools to be utilized are selected from the list of available tools (Malhotra paragraph 34 with list of remediation actions, and choosing the remediation action that will remediate the event).
As per claim 10, as best understood by the Examiner, Malhotra teaches wherein autonomously executing the investigation/remediation plan to address the event within the computer platform further includes: defining an updated plan if the investigation/remediation plan did not execute properly, wherein the updated plan is based, at least in part, upon the investigation/remediation plan (paragraph 36, wherein if no remediation action exists, a remediation parameters are generated and configured to generate a remediation package).
Claim 11 is rejected using the same basis of arguments used to reject claim 1 above.
Claim 12 is rejected using the same basis of arguments used to reject claim 2 above.
Claim 13 is rejected using the same basis of arguments used to reject claim 3 above.
Claim 14 is rejected using the same basis of arguments used to reject claim 4 above.
Claim 18 is rejected using the same basis of arguments used to reject claim 8 above.
Claim 20 is rejected using the same basis of arguments used to reject claim 10 above.
Claim 21 is rejected using the same basis of arguments used to reject claim 1 above.
Claim 22 is rejected using the same basis of arguments used to reject claim 2 above.
Claim 23 is rejected using the same basis of arguments used to reject claim 3 above.
Claim 24 is rejected using the same basis of arguments used to reject claim 4 above.
Claim 28 is rejected using the same basis of arguments used to reject claim 8 above.
Claim 30 is rejected using the same basis of arguments used to reject claim 10 above.
Claim(s) 5-7, 15-17, and 25-27 are rejected under 35 U.S.C. 103 as being unpatentable over the Malhotra combination as applied above, in view of Boyer et al. US Patent Application Publication 2024/0045990 (Boyer)
As per claim 5, Malhotra as modified teaches wherein autonomously defining an investigation/remediation plan for addressing the event within the computer platform based upon one or more available resources includes: defining one or more human-readable operations; and processing the one or more human-readable operations to generate one or more machine readable operations (paragraph 34 and throughout with source code). However, Malhotra as modifed does not explicitly teaching utilizing a large language model LLM to generate machine-readable operations. However, this would have been obvious. For example, see Boyer (paragraph 58 with utilizing LLM in a cyber security user interface).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of the Malhotra combination with Boyer. One of ordinary skill in the art would have been motivated to perform such an addition to facilitate communication between the system and users (paragraph 58).
As per claim 6, Malhotra as modified does not explicitly teach wherein the alert defines a rule that was broken by the event within the computer system. However, utilizing rules to determine malicious activity is well known in the art. For example, see Boyer (paragraphs 138-40 with utilizing rule to determine malicious activity).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of Boyer with the Malhotra combination. One of ordinary skill in the art would have been motivated to perform such an addition to increase efficiency by reducing the time taken for human-led investigations (paragraph 37).
As per claim 7, Malhotra as modified teaches wherein the one or more available resources includes one or more of: information concerning a broken rule; a list of available tools; a customer context; and guidance concern how the broken rule was applied (Malhotra paragraph 34 with indicia of threat and database of remediation actions).
Claim 15 is rejected using the same basis of arguments used to reject claim 5 above.
Claim 16 is rejected using the same basis of arguments used to reject claim 6 above.
Claim 17 is rejected using the same basis of arguments used to reject claim 7 above.
Claim 25 is rejected using the same basis of arguments used to reject claim 5 above.
Claim 26 is rejected using the same basis of arguments used to reject claim 6 above. Claim 27 is rejected using the same basis of arguments used to reject claim 7 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON KAI YIN GEE whose telephone number is (571)272-6431. The examiner can normally be reached on Monday-Friday 8:30-5:00 PST Pacific.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/JASON K GEE/Primary Examiner, Art Unit 2495