Notice of Pre-AIA or AIA Status
This Final communication is in response to Application No. 19/412,835 filed 12/08/2025, and claims priority to 63/728,802 filed on 12/06/2024. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendments filed 6/10/2026 have been entered. They provide amendments to claims 1-17 and cancel claims 18-20. Claims 21-23 have been added. Claims 1-17 and 21-23 are pending. The amendments have overcome drawing objections, the 112b and 101 rejections.
Response to Arguments
Applicant’s arguments with respect to claim 1-17 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-7, and 16-17, 21-23 are rejected under 35 U.S.C. 103 as being unpatentable over Peters (US 2024/0414194 A1) in view of Puzanov (US 2024/0303259 A1) and Saha (US 2022/0201014 A1).
Regarding claim 1, Peters teaches:
A computer-implemented method for accelerated cybersecurity threat detection, the computer-implemented method comprising: ([0007] “In one embodiment, a method for detecting a cybersecurity threat and automatically generating cybersecurity threat intelligence for mitigating the cybersecurity threat includes identifying a cybersecurity threat based on one or more streams of event data from one or more external data sources associated with a subscriber;”)
at a remote cybersecurity service implemented by a network of distributed computers: ([0038] “Additionally, the security alert machine learning system 114 may be implemented by the one or more computing servers, a distributed network of computers (e.g., a cloud network), computer processors, and the like of the system 100.”)
generating, by one or more computers of the remote cybersecurity service, a cybersecurity alert classification of a plurality of cybersecurity alert classifications based on cybersecurity alert data associated with a subscriber to the remote cybersecurity service; ([0014] “implementing a threat classification machine learning model that predicts a threat classification label for the cybersecurity threat that indicates a type of cybersecurity threat from among a plurality of distinct possible types of cybersecurity threats based on an input of vectors of the extracted cybersecurity threat feature data.”)
accessing, from a memory storing a plurality of cybersecurity investigation instructions, a classification-indexed investigation set of instructions based on the generated cybersecurity alert classification, wherein the classification-indexed investigation set of instructions form a directed acyclic graph; ([0073] “In a second implementation, in response to obtaining or receiving a copy of validated security alert data, S220 may function to map the validated security alert directly to a corpus of investigation instructions or investigation instructions/scripts, that when executed, automatically perform one or more investigative actions for resolving the validated security alert.”)
responsive to the investigation executor module receiving the directed acyclic graph as input, forming, by the investigation executor module, a corpus of evidence by accessing one or more sources of evidence based on executing the classification-indexed investigation set of instructions; ([0074] “S230, which includes executing one or more automated investigation workflows and composing a corpus of investigation data, may function to implement one or more automated security alert investigations that source and build one or more corpora of investigation data and identifies and/or extracts threat intelligence data from the one or more corpora of investigation data.”)
producing, via a natural-language generation module executed by the one or more processors, a machine-generated summary comprising (i) a description of the investigation evidence accessed, (ii) the plurality of Q&A pairs generated, and (iii) the investigative conclusion, together with one or more system-generated recommended response actions associated with the cybersecurity alert data. ([0091] “As a non-limiting example, S240 may function to merge or populate one or more portions of a corpus of investigation data and/or cybersecurity intelligence data into one or more sections of a cybersecurity threat reporting template or reporting document. In such embodiments, S240 may function to intelligently format the cybersecurity threat intelligence data and/or investigation analysis data into one or more data structures that may be presented or otherwise, displayed via the investigation reporting document.”)
Peters does not teach:
generating, for a plurality of investigative questions associated with the classification-indexed investigation set of instructions, a corresponding model-generated answer that forms a question-and-answer (Q&A) pair by applying an automated analysis model to the corpus of evidence;
wherein the classification-indexed investigation set of instructions form a directed acyclic graph;
receiving the directed acyclic graph at an investigation executor module, different from an investigation planner module that generated the directed acyclic graph;
implementing a feature-extraction that encodes each investigative question of the plurality of investigation questions and the corresponding model-generated answer into a machine-readable feature value, the feature-extraction being configured to transform evidence signals into feature vectors consumable by a weak-supervision predictive model;
extracting, from a plurality of Q&A pairs, a feature set comprising feature values representing answers generated for the plurality of investigative questions;
applying, to the feature set, the weak-supervision predictive model stored in the memory and executable by one or more processors, the weak-supervision predictive model being configured to compute, for each investigative question of the plurality of investigative questions, a probabilistic output indicating whether investigation evidence from the corpus of evidence supports an affirmative or negative answer to that investigative question;
determining, based on probabilistic outputs generated by the weak-supervision predictive model, an investigative conclusion for at least one of the classification-indexed investigation set of instructions or for the cybersecurity alert data as a whole; and
However, Puzanov does teach some of these:
generating, for a plurality of investigative questions associated with the classification-indexed investigation set of instructions, a corresponding model-generated answer that forms a question-and-answer (Q&A) pair by applying an automated analysis model to the corpus of evidence; ([0029] “In step 203, each question is automatically answered using question answering language models with respect to each document”)
implementing a feature-extraction that encodes each investigative question of the plurality of investigation questions and the corresponding model-generated answer into a machine-readable feature value, the feature-extraction being configured to transform evidence signals into feature vectors consumable by a weak-supervision predictive model; ([0034] “Here, the questions serve as features and the vector of answers would be a feature vector.”)
extracting, from a plurality of Q&A pairs, a feature set comprising feature values representing answers generated for the plurality of investigative questions; ([0029] “a feature vector is generated with answers as features for each document “)
applying, to the feature set, the weak-supervision predictive model stored in the memory and executable by one or more processors, the weak-supervision predictive model being configured to compute, for each investigative question of the plurality of investigative questions, a probabilistic output indicating whether investigation evidence from the corpus of evidence supports an affirmative or negative answer to that investigative question; ([0052] “With reference now to the decision engine 504, at each step the engine 504 considers the sentence sections from the NLP module 502, the suggested classification probabilities for them generated by the threat modeling classifier and the remaining questions.”)
determining, based on probabilistic outputs generated by the weak-supervision predictive model, an investigative conclusion for at least one of the classification-indexed investigation set of instructions or for the cybersecurity alert data as a whole; and ([0052]-[0053] “The decision engine 404 suggests the next step in terms of section text and zero or more questions. Zero questions means that the decision is final, while any number of questions means more exploration is possible. Note that the classification is available at any iteration, and it would get more accurate as more questions are asked.”)
Peters and Puzanov are considered analogous art to the claimed invention because they are in the same field of endeavor being cybersecurity treat modeling. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the classification modeling of Peters with the question answering system of Puzanov and combine those into the report by Peters. One would want to do this to imitate a human analyst (Puzanov [0007]).
Saha teaches:
wherein the classification-indexed investigation set of instructions form a directed acyclic graph; ([0114] “ Once novel exploits have been predicted, defense DAGs are constructed at step 52 to defend an IoT system or CPS against prior known attacks and the predicted novel exploits. In this security measures section 26, the primary endeavor is to defend an IoT system or CPS against all known attacks and the novel exploits predicted at an optimal cost. Defense-in-depth and multi-level security (MLS) are the most appropriate schemes to adopt in such a scenario. Defense-in-depth refers to employing multiple defense strategies against a single weakness and is one of the seven properties of highly secure devices. MLS categorizes data/resources into one of the following security levels: Top Secret, Secret, Restricted, and Unclassified.
receiving the directed acyclic graph at an investigation executor module, different from an investigation planner module that generated the directed acyclic graph ([0124] “To defend against such attacks, a Core Root of Trust for Measurement is required along with a Trusted Platform Module (TPM) or a Hardware Security Module. These are generally present at a level lower than the kernel and sometimes referred to as the Trusted Computing Base (TCB). In FIG. 15, the BOOTROM serves as the TCB. The defense procedure involves a series of hierarchical and chained hash checks of binary files and secret keys stored in the Platform Configuration Register (PCR) of the TPM.”).
Peters, Puzanov and Saha are considered analogous art to the claimed invention because they are in the same field of endeavor being cybersecurity treat modeling. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the classification modeling of Peters with the question answering system of Puzanov and combine those into the report by Peters while using the DAG to represent threats of Saha. One would want to use a DAG to easily be able to identify new threats (Saha [0011]).
Regarding claim 2, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Peters further teaches:
accessing the classification-indexed investigation set of instructions comprises retrieving, from a classification-to-investigation index stored in the memory, a machine-readable investigation-step specification associated with the cybersecurity alert classification, the machine-readable investigation-step specification defining a sequence of evidence-access operations and corresponding investigative questions. ([0073] “In a second implementation, in response to obtaining or receiving a copy of validated security alert data, S220 may function to map the validated security alert directly to a corpus of investigation instructions or investigation instructions/scripts, that when executed, automatically perform one or more investigative actions for resolving the validated security alert. In this second implementation, S220 may function to implement an investigation reference source, such as a reference table or any suitable data structure, that electronically maps or links each of a plurality of distinct security alerts or distinct cybersecurity threat types to a set or a corpus of investigation instructions that may be specifically tailored for mitigating and/or resolving the associated security alert. Thus, in some embodiments, for each distinct (validated) security alert, a differentiated set of investigation instructions may be executed to generate investigation data and/or investigation responses for each distinct security alert.”)
Regarding claim 3, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Puzanov further teaches:
generating the corresponding model-generated answer for each investigative question comprises executing a question-conditioned inference model that receives, as input, (i) a representation of the investigative question and (ii) a bounded subset of the corpus of evidence, and outputs an answer token or answer confidence value forming the Q&A pair. ([0037] “Regarding the question answering oracle 303, the question answering oracle 303 supports the human level understanding of the content. The oracle's purpose is to answer the questions from the question bank with respect to one or more documents. The solution does not rely on a single oracle, but rather picks the most appropriate oracle for the question. Some of the question types that the oracles can support are extractive—where the oracle would accept a context and question and find the relevant answer in the context or generative—where the oracle would generate a free text answer by looking at a context and a question.”)
Regarding claim 4, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Puzanov further teaches:
applying the weak-supervision predictive model comprises combining the feature values of the feature set using a plurality of labeling functions or heuristics encoded in the weak-supervision predictive model, each labeling function being configured to evaluate correlations among the feature values to generate the probabilistic outputs for the investigative questions. ([0054] “The decision engine 504 can be as simple as a rule-based system of a complex artificial intelligence (AI) agent. Due to the various number of parameters such as different labels, various questions, costs and computation times, the inventors suggest training a Reinforcement Learning (RL)-based agent. The agent would automatically consider all parameters with respect to a target function and would generate the best matching action.”))
Regarding claim 5, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Peters further teaches:
invoking, after generating the cybersecurity alert classification, an autonomous artificial-intelligence agent evaluate the corpus of evidence and intermediate Q&A pairs and to determine whether additional evidence is required to complete an investigation of the cybersecurity alert data. ([0076] “In such embodiments, S230 may function to identify one or more sources of the validated security alert data, such as a third-party security vendor or security service, and may function to generate one or more investigation queries to the one or more sources requesting additional security alert information and/or details relating to the validated security alert.”)
Regarding claim 6, Peters in view of Puzanov and Saha teaches claim 5 as outlined above. Peters further teaches:
in response to the autonomous artificial-intelligence agent determining that the additional evidence is required, expanding the corpus of evidence by the autonomous artificial-intelligence agent autonomously accessing one or more supplemental evidence sources via a plurality of threat-intelligence or telemetry-access tools exposed through an application programming interface. ([0076] “That is, in this embodiment, S230 the one or more sources of data used in defining or identifying a validated security alert may be identified as targets of the one or more investigative tasks and/or investigative actions of the given automated investigation workflow. In one or more embodiments, S230 may function to construct or generate the one or more investigation queries to the one or more sources based on the one or more investigation scripts or rules that may define data criteria and/or data requirements for a given cybersecurity threat type of the validated security alert. For instance, if a cybersecurity threat type includes a suspicious login, one or more of the investigation scripts or rules may define API call parameters for configuring an API call for sourcing data relating to an agent identifier and/or IP address associated with the suspected suspicious login.”)
Regarding claim 7, Peters in view of Puzanov and Saha teaches claim 5 as outlined above. Puzanov further teaches:
wherein the autonomous artificial-intelligence agent generates one or more additional investigative questions not included in the classification-indexed investigation set of instructions, and wherein generating the corresponding model-generated answer further comprises applying the automated analysis model to the corpus of evidence to produce question-and-answer (Q&A) pairs corresponding to the one or more additional investigative questions. ([0028]-[0029] “In step 202, a bank of questions is composed from various sources such as the subject matter experts, posture status, and/or data-driven questions. In step 203, each question is automatically answered using question answering language models with respect to each document, and a feature vector is generated with answers as features for each document in step 104” combining the question answer pair generation of Puzanov when Peters system adds more data. )
Regarding claim 16, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Puzanov further teaches:
generating the question-and-answer (Q&A) pairs further comprises executing a question-evaluation pipeline, the question-evaluation pipeline including: evidence-selection logic configured to retrieve, from one or more evidence sources, investigation evidence associated with a designated investigation step; a model-execution stage that applies an analytical model to the retrieved investigation evidence using the investigative question as a conditioning parameter to generate a model-generated answer; and a feature-encoding stage that converts the investigative question and the model-generated answer into a structured Q&A feature suitable for downstream probabilistic reasoning by the weak-supervision predictive model. (Figure 2. Shows their pipeline for generating answers to questions.)
Regarding claim 17, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Puzanov further teaches:
generating the corresponding model-generated answers further comprises executing, by the one or more processors, a non-transitory computer-implemented question-analysis engine configured to automatically transform heterogeneous cybersecurity evidence inputs into structured feature values by applying a machine-learning model conditioned on predetermined investigative questions, thereby generating Q&A feature data that is not derivable through mere inspection of the investigation evidence. ([0037] “Regarding the question answering oracle 303, the question answering oracle 303 supports the human level understanding of the content. The oracle's purpose is to answer the questions from the question bank with respect to one or more documents. The solution does not rely on a single oracle, but rather picks the most appropriate oracle for the question. Some of the question types that the oracles can support are extractive—where the oracle would accept a context and question and find the relevant answer in the context or generative—where the oracle would generate a free text answer by looking at a context and a question.”)
Regarding claim 21, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Saha further teaches:
the directed acyclic graph at least indicates an execution order for a first plurality of investigation instructions and a second plurality of investigation instructions, and forming the corpus of evidence includes: ([0114] “Defense-in-depth and multi-level security (MLS) are the most appropriate schemes to adopt in such a scenario. Defense-in-depth refers to employing multiple defense strategies against a single weakness and is one of the seven properties of highly secure devices.”)
detecting, based on the execution order of the directed acyclic graph, that the second plurality of investigation instructions depend on an execution of the first plurality of investigation instructions, and based on detecting that the second plurality of investigation instructions depend on the execution of the first plurality of investigation instructions: executing, in parallel, the first plurality of investigation instructions to asynchronously obtain a plurality of prerequisite evidence, and once the plurality of prerequisite evidence is obtained, executing the second plurality of investigation instructions based on determining that the plurality of prerequisite evidence is available. ([0116] “The aggregated attack DAG includes multiple categories of attacks that are weaved together. These broad attack categories include but are not limited to buffer overflow attacks, access control and privilege escalation attacks, malware execution, cryptographic and network security flaws, and boot-stage attacks. Defense mechanisms can be systematically developed for each of these attack categories in the form of defense DAGs. Defense DAGs mirror the corresponding attack subgraphs and make execution of the key basic blocks of the attack sequence infeasible. This ensures that no path from a head node to a leaf node in the attack DAG can be traversed in the presence of the suggested defense measures.” And [0117] “Many attacks have multiple defense strategies that can protect against them. The more defense mechanisms that are enforced, the costlier the overall defense strategy becomes. MLS helps to optimize this cost. The less sensitive resources (those belonging to the Restricted level) have basic defense measures against all attacks. Moving up the hierarchy, the Secret and Top Secret levels have more layers of security. This ensures that securing the less sensitive resources is not as costly as securing the more sensitive resources.”)
Regarding claim 22, Peters in view of Puzanov and Saha teaches claim 21 as outlined above. Peters further teaches:
once the plurality of prerequisite evidence is obtained: detecting a type of activity associated with the plurality of prerequisite evidence, responsive to detecting that the type of activity associated with the plurality of prerequisite evidence is benign activity, terminating execution of the second plurality of investigation instructions early to conserve computing resources, and responsive to detecting that the type of activity associated with the plurality of prerequisite evidence is indeterminate activity, continuing executing the second plurality of investigation instructions based on the plurality of prerequisite evidence. ([0095] “S250, which includes identifying a routing for disposing of a cybersecurity threat, may function to identifying a threat mitigation route or a threat disposal route based on the cybersecurity intelligence data. In a preferred embodiment, a system and/or service implementing the method 200 may include a plurality of distinct threat mitigation and/or threat disposal routes for handling and/or remediating a validated security alert or cybersecurity threat. In one or more embodiments, the plurality of distinct threat mitigation and/or threat disposal routes may include, but should not be limited to, a first route for escalating the validated security alert to a confirmed state of malicious attack or incident, a second route for informing a subscriber regarding a threat risk state of the validated security alert, and a third route for de-escalating the validated security alert to a determined state of non-malicious thereby informing a termination state for a validated security alert. In one or more embodiments, a state and/or a determined route for a given validated security alert may be represented and/or provided via a security threat mitigation user interface. It shall be recognized that the routes may include any suitable number or type of routes that be different than the above-mentioned routes.”)
Regarding claim 23, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Peters further teaches:
the one or more system-generated recommended response actions associated with the cybersecurity alert data includes blocking an IP address and isolating a target device, and ([0072] “For instance, if a cybersecurity threat type includes a suspicious login, one or more of the investigation criteria or investigative queries for this cybersecurity threat type may include a request for a source IP address of the suspicious login. In such example, during an evaluation of the investigative data, the method 200 may function to extract from the investigative data informative or probative pieces of data including a source IP address associated with the suspicious login.”)
the method further comprises: displaying, via a graphical user interface, one or more interactive controls implementing the one or more system-generated recommended response actions, and blocking the IP address and isolating the target device based on the subscriber interacting with the one or more interactive controls of the graphical user interface. ([0043] “The security mitigation user interface 130 may function to enable an analyst or an administrator to perform, in a parallel manner, monitoring, investigations, and reporting of security events, incidents, and/or resolutions to subscribers to the system 100 and/or service implementing the system 100. In some embodiments, an operation of the security user interface 130 may be transparently accessible to subscribers, such that one or more actions in monitoring, investigation, and reporting security threats or security incidents may be surfaced in real-time to a user interface accessible, via the Internet or the like, to a subscribing entity.”)
Claims 8-11 are rejected under 35 U.S.C. 103 as being unpatentable over Peters in view of Puzanov, Saha and Case (US 2020/0380369 A1)
Regarding claim 8, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. None of Peters, Puzanov nor Saha teach:
applying the weak-supervision predictive model further comprises performing an incremental weight-learning process in which weight parameters associated with feature values derived from the classification-indexed investigation set of instructions remain fixed, while weight parameters associated with feature values corresponding to one or more additional investigative questions generated by an autonomous artificial-intelligence agent are learned or updated during inference.
However, Case does:
applying the weak-supervision predictive model further comprises performing an incremental weight-learning process in which weight parameters associated with feature values derived from the classification-indexed investigation set of instructions remain fixed, while weight parameters associated with feature values corresponding to one or more additional investigative questions generated by an autonomous artificial-intelligence agent are learned or updated during inference. ([0059] “ In at least one embodiment, second pipeline iteration 302 illustrates a step (batch) of training that comprises: loading input data; partial/sparse weight updating by non-gradient term(s); forward propagation; backwards propagation; and partial/sparse weight updating by gradient term(s). In at least one embodiment, a system training a neural network performs second pipeline iteration 302.” Here they are only training some of the weights and some of the weights are being fixed.)
Peters, Puzanov, Saha and Case are considered analogous art to the claimed invention because they are in the same field of endeavor being machine learning. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the classification modeling of Peters with the question answering system of Puzanov with the machine learning training approach of Case. One would want to do this to improve computational efficiency (Case [0041]).
Regarding claim 9, Peters in view of Puzanov, Saha and Case teaches claim 8 as outlined above. Case further teaches:
performing the incremental weight-learning process comprises executing, during the inference, a real-time fine-tuning cycle in which the weak-supervision predictive model updates weight values associated with feature values corresponding to dynamically generated investigative questions, thereby generating updated probabilistic outputs for one or more investigative questions. ([0046] “In at least one embodiment, updated weight information 110 is used to train a neural network 112 at a t-kth step of training. In at least one embodiment, neural network 112 is a feedforward artificial neural network.”)
Regarding claim 10, Peters in view of Puzanov, Saha and Case teaches claim 8 as outlined above. Case further teaches:
the incremental weight-learning process further comprises generating a refined inference result by re-evaluating the feature set using the updated weight values, the refined inference result being more accurate than an initial inference result produced prior to the incremental weight-learning process. ([0086] “In at least one embodiment, training framework 904 trains untrained neural network 906 until untrained neural network 906 achieves a desired accuracy. In at least one embodiment, trained neural network 908 can then be deployed to implement any number of machine learning operations.”)
Regarding claim 11, Peters in view of Puzanov, Saha and Case teaches claim 9 as outlined above. Case further teaches:
repeating the real-time fine-tuning cycle until a convergence criterion is satisfied, the convergence criterion comprising a change threshold between successive probabilistic outputs or a stability threshold for a loss function associated with the weak-supervision predictive model. ([0086] “In at least one embodiment, training framework 904 trains untrained neural network 906 until untrained neural network 906 achieves a desired accuracy. In at least one embodiment, trained neural network 908 can then be deployed to implement any number of machine learning operations.”)
Claims 12-15 are rejected under 35 U.S.C. 103 as being unpatentable over Peters in view of Puzanov, Saha and Allen (US 2016/0196497 A1)
Regarding claim 12, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. None of Peters, Puzanov nor Saha teach:
receiving, from the subscriber, one or more subscriber-generated investigative questions and corresponding subscriber-generated answers, and incorporating the one or more subscriber-generated investigative questions and the corresponding subscriber-generated answers into the plurality of Q&A pairs used to form the feature set.
However, Allen does:
receiving, from the subscriber, one or more subscriber-generated investigative questions and corresponding subscriber-generated answers, and incorporating the subscriber-generated investigative questions and answers into the plurality of Q&A pairs used to form the feature set. ([0021] “ As discussed above, each of the statements made by users in the crowdsourcing source(s) may be evaluated to generate a distribution of the reasoning criteria used by these users to provide their corresponding answers to thereby select the most often used criteria for providing underlying reasoning as to the answers generated and to generate a corresponding rule/logic/corpus statement specifying this reasoning criteria in association with a corresponding answer and question characteristics.”)
Peters, Puzanov, Saha and Allen are considered analogous art to the claimed invention because they are in the same field of endeavor being question and answering system. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the classification modeling of Peters with the question answering system of Puzanov with the user incorporated feedback of Allen. One would want to do this to generate logic for evaluating subsequent questions (Allen [0015]).
Regarding claim 13, Peters in view of Puzanov, Saha and Allen teaches claim 12 as outlined above. Allen further teaches:
applying, to each subscriber-generated investigative question, a subscriber-specified importance value selected from a set of predefined levels, and mapping the subscriber-specified importance value to a numerical weight by selecting a value from a corresponding region of a weight distribution associated with feature values of the weak-supervision predictive model. ([0022] “In some illustrative embodiments, based on the number of users providing the various criteria via the crowdsourcing sources, as determined from the distribution generated, various weights may be associated with the different criteria, e.g., those criteria most often used will have higher weights than criteria that are used less often. The weights may be used to evaluate and generate a score for the matching of the characteristics of the focus of the subsequent question to the reasoning criteria.”)
Regarding claim 14, Peters in view of Puzanov and Saha teaches claim 1 as outlined above. Allen further teaches:
generating, in parallel with the weak-supervision predictive model applied to the feature set, a baseline probabilistic output that excludes a plurality of subscriber-generated Q&A pairs, and determining whether inclusion of the plurality of subscriber-generated Q&A pairs changes at least one probabilistic output or the investigative conclusion. ([0022] “The weights may be used to evaluate and generate a score for the matching of the characteristics of the focus of the subsequent question to the reasoning criteria.”)
Regarding claim 15, Peters in view of Puzanov, Saha and Allen teaches claim 14 as outlined above. Peters further teaches:
producing, via the natural-language generation module, an influence-report segment that identifies differences between the baseline probabilistic output and the probabilistic output generated using the plurality of subscriber-generated Q&A pairs, the influence-report segment indicating whether subscriber-generated content altered a severity determination, confidence score, or recommended response action. ([0091] “As a non-limiting example, S240 may function to merge or populate one or more portions of a corpus of investigation data and/or cybersecurity intelligence data into one or more sections of a cybersecurity threat reporting template or reporting document. In such embodiments, S240 may function to intelligently format the cybersecurity threat intelligence data and/or investigation analysis data into one or more data structures that may be presented or otherwise, displayed via the investigation reporting document.” And one could combine the findings of Allen into the report of Peters)
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL P GRUSZKA whose telephone number is (571)272-5259. The examiner can normally be reached M-F 9:00 AM - 6:00 PM ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Li Zhen can be reached at (571) 272-3768. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DANIEL GRUSZKA/Examiner, Art Unit 2121
/Li B. Zhen/Supervisory Patent Examiner, Art Unit 2121