Prosecution Insights
Last updated: October 04, 2026
Application No. 16/939,973

THREAT MITIGATION SYSTEM AND METHOD

Final Rejection §103§112
Filed
Jul 27, 2020
Priority
Jul 26, 2019 — provisional 62/879,105 +1 more
Examiner
SAVENKOV, VADIM
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
ReliaQuest Holdings LLC
OA Round
10 (Final)
61%
Grant Probability
Moderate
11-12
OA Rounds
0m
Est. Remaining
81%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
193 granted / 318 resolved
+2.7% vs TC avg
Strong +20% interview lift
Without
With
+20.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
27 currently pending
Career history
374
Total Applications
across all art units

Statute-Specific Performance

§101
10.6%
-29.4% vs TC avg
§103
53.7%
+13.7% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
17.3%
-22.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 318 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The 4/3/2026 and 7/20/2026 IDS documents have been considered by the examiner. Response to Amendment / Arguments Regarding claims objected to for minor informalities: Applicant’s amendment is considered to have overcome the applied objection. Therefore, the objection has been withdrawn. Regarding claims rejected under 35 USC 112(b): Applicant’s amendment is considered to have overcome the applied rejection. Therefore, the rejection has been withdrawn. Regarding claims rejected under 35 USC 103: Applicant's arguments have been fully considered but they are not persuasive. Applicant argues that the Petersen-Doppke-Roturier combination does not disclose the amended claim limitation “enabling the third party to gather artifacts concerning an object within the inspection window, the artifacts including one or more of raw data, screen shots, graphics, notes authored by the third party, annotations made by the third party, audio recordings, and video recordings.” In response, it is noted that at least FIG. 19 and 27 of Petersen concern a form of the claimed “inspection window.” As per Col. 25, Ll. 26-40 and Col. 30, Ll. 59-Col. 31, Ll. 8 of Petersen, a popup window is presented responsive to clicking events / alarms from the GUI. Each respective popup window includes log data and its own graphical interface. As per at least Col. 29, Ll. 8-16 of Petersen, users can utilize the GUI to drill down into raw log data. The popup window 444 of FIG. 23 includes such raw log messages (i.e., Col. 31, Ll. 2-3 of Petersen). The popup of FIG. 19 likewise includes log data and log data – user fields. It is additionally noted that “raw data” is claimed at a high level of generality, and is otherwise unspecified. Therefore, data such as the IP addresses in FIG. 19 of Petersen may be considered “raw data.” Likewise, essentially any graphic within the GUI may be considered as “graphics.” It is also noted that the popup window of at least FIG. 19 of Petersen includes functionality for the user to add and remove information that can be interpreted as the claimed “notes authored by the third party” (e.g., “New” / “Unassociate” in “Knowledge Base Web References”). Finally, it is noted that the claim is drawn to “enabling the third party to gather artifacts concerning an object within the inspection window,” which is different from actually performing the gathering inside the inspection window exclusively. Instead, this language merely requires that the third party is enabled to gather objects that are associated with the object. This can include any action taken outside of the inspection window so long as it relates to the object. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-5, 7, 10-14, 16, 19-23, and 25 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Independent claim 1 recites “enabling the third party to gather artifacts concerning an object within the inspection window,” which renders the claim as failing to comply with the enablement requirement because the instant specification does not disclose all ways of “enabling” a user “to gather artifacts concerning an object” as per the claimed level of generality. In this case, the claim language is drawn to essentially any and all ways of “enabling” and “gather[ing].” This could include the user merely taking a mental note and gathering information in memory, gathering information from APIs and databases, gathering information by means of interpersonal communication or physical mail, and so forth. Additionally, “enabling” can include merely presenting the information, providing a means of machine interaction, and could even refer to post-solution activity since it is not clear whether the gathering actually takes place within the scope of the claim. While one of ordinary skill in the art would recognize multiple common solutions for gathering and presenting data (e.g., the APIs and displaying gathered data using a trivial GUI), they would not have a ready solution for all ways of “enabling… to gather” as claimed. Instead, this would require undue experimentation beyond the disclosure of the instant specification. Independent claims 10 and 19 recite substantially similar claim language and are therefore rejected under the same analysis as above. The dependent claims do not rectify the above-identified issues and are therefore likewise rejected with their respective parent claims. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-5, 7, 10-14, 16, 19-23, and 25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. recites “enabling the third party to gather artifacts concerning an object within the inspection window,” which renders the claim indefinite because it is not clear whether this refers to post-solution activity outside of the scope of the claim. It is not clear whether this limitation is merely intended as an intended use of the “inspection window” further displaying certain artifacts, or if it is referring to a positive gathering step. In the case of the latter, it is noted that the gathering may take place outside of the claim scope (e.g., at a future date and time without otherwise making use of the claimed invention) since it merely requires gathering artifacts “concerning an object within the inspection window” rather than performing any actions within the inspection window as part of the claim steps. Therefore, a person of ordinary skill in the art could not interpret the metes and bounds of the claim so as to understand how to avoid infringement. Independent claims 10 and 19 recite substantially similar claim language and are therefore rejected under the same analysis as above. The dependent claims do not rectify the above-identified issues and are therefore likewise rejected with their respective parent claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 4-5, 7, 10-11, 13-14, 16, 19-20, 22-23, and 25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Petersen (US 9,384,112 B2) in view of Doppke (US 10,567,415 B2) and Roturier (US 10,418,036 B1). Regarding claim 1, Petersen discloses: A computer-implemented method, executed on a computing device, comprising: monitoring, by one or more security-relevant subsystems, respective activity of the one or more security-relevant subsystems with respect to a computing platform to identify suspect activity within the computing platform, wherein the one or more security-relevant subsystems include one or more of CDN (Content Delivery Network) systems; DAM (Database Activity Monitoring) systems; UBA (User Behavior Analytics) systems; MDM (Mobile Device Management) systems; IAM (Identity and Access Management) systems; DNS (Domain Name Server) systems, antivirus systems, operating systems, data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform; detecting the security event within the computing platform based upon the identified suspect activity; Refer to at least Col. 1, Ll. 64-Col. 2, Ll. 5, Col. 9, Ll. 61-67, and Col. 13, Ll. 19-27 of Petersen with respect to sources such as firewalls, intrusion detection systems, security devices, and so forth. detecting the security event within the computing platform based upon the identified suspect activity; Refer to at least Col. 25, Ll. 1-14 and Ll. 54-67 of Petersen with respect to identifying suspect activity as security events. rendering a threat mitigation user interface that identifies objects within a computing platform in response to the security event, Refer to at least Col. 10, Ll. 1-41 of Petersen with respect to log messages and events. At least Ll. 31-41 discuss examples such as improper logins, attacks, errors, and so forth. Refer to at least FIG. 17-18, FIG. 23, and Col. 24, Ll. 50-65 of Petersen with respect to an exemplary dashboard / GUI for viewing the logs / events. including gathering objects within the computing platform in response to the security event from a plurality of sources associated with the computing platform, thus defining objects within the computing platform, Refer to at least Col. 13, Ll. 19-24, Col. 25, Ll. 56-67, Col. 26, Ll. 44-67, and Col. 33, Ll. 28-35 of Petersen with respect to collecting logs from one or more log sources as they concern alarms. enabling a third-party (the instant specification, e.g., [00113] and [00153] defines a third party as comprising a user / owner / operator) to select one or more objects within the threat mitigation user interface when conducting an investigation of the security event, thus defining one or more selected objects; Refer to at least Col. 28, Ll. 67-Col. 29, Ll. 4 and Col. 25, Ll. 28-36 of Petersen with respect to a user being able to “drill down” information by, e.g., clicking on the information within the GUI. rendering an inspection window that defines object information concerning the one or more selected objects, this defining one or more objects reviewed by the third party; and Refer to at least FIG. 19, FIG. 27-31, Col. 25, Ll. 26-40, and Col. 30, Ll. 27-Col. 31, Ll. 67 of Petersen with respect to, e.g., launching a pop-up window with more information responsive to the drilling down. rendering an action list that defines targeted actions based, at least in part, upon the object information; Refer to at least FIG. 28, Col. 7, Ll. 51-53, Col. 30, Ll. 55-59, and Col. 31, Ll. 21-67 of Petersen with respect to a drop-down menu presenting a number of actions that may be taken to the user. enabling the third party to gather artifacts concerning an object within the inspection window, the artifacts including one or more of raw data, screen shots, graphics, notes authored by the third party, annotations made by the third party, audio recordings, and video recordings; Refer to at least FIG. 19, 27, Col. 25, Ll. 26-40, and Col. 30, Ll. 59-Col. 31, LL. 8 of Petersen with respect to, e.g., log data (including raw log data), user interface graphics, and notes (e.g., adding or unassociating knowledge base web references). monitoring the one or more objects reviewed by the third party when conducting the investigation of the security event. Refer to at least Col. 33, Ll. 16-Col. 34, Ll. 4 of Petersen with respect to allowing an administrator to monitor for, e.g., specific data transfers and to automatically collect associated information. The administrator can use any user interfaces or dashboards for monitoring. Although Petersen discloses presenting a number of actions that might be taken, it is not clear whether it discloses: suggesting additional actions to be taken by the third party concerning the investigation of the security event, the additional actions including one or more of additional objects to be reviewed by the third party when conducting the investigation of the security event and additional artifacts to be gathered by the third party when investigating the security event. Petersen further does not fully specify: wherein the object information includes one or more of: total quantity of data provided to a destination IP address; and a list of all devices within the computing platform that have provided data to the destination IP address; wherein gathering objects includes: receiving a unified query concerning a plurality of the one or more security-relevant subsystems and distributing at least a portion of the unified query to each of the plurality of the one or more security-relevant subsystems, resulting in distribution of a plurality of queries to the one or more security-relevant subsystems. However, Petersen in view of Doppke discloses: wherein the object information includes one or more of: total quantity of data provided to a destination IP address; and Refer to at least FIG. 3-4A, Col. 4, Ll. 51-54, Col. 5, Ll. 10-17, Col. 7, Ll. 16-46, Col. 8, Ll. 14-32, and Col. 9, Ll. 7-34 of Doppke with respect to traffic volume metrics and user selections for the threat monitoring GUI, where the user selections can include “destination IP address; one or more traffic characteristics, such as volume or other metrics; and one or more policy characteristics.” Further, “[t]he graphic display is based on the user selections that were received, such as to display data associated with a selected time window, a selected protected host 104 or external host 106 or group of hosts.” Finally, the “volumetric data can be associated with total traffic flow in either direction, inbound or outbound, to or from the protected network 108, or can be associated with particular protected hosts 104 or external hosts 114 or groups of such hosts.” a list of all devices within the computing platform that have provided data to the destination IP address; suggesting additional actions to be taken by the third party concerning the investigation of the security event, the additional actions including one or more of additional objects to be reviewed by the third party when conducting the investigation of the security event and additional artifacts to be gathered by the third party when investigating the security event. Refer to at least 446 in FIG. 4C and Col. 13, Ll. 16-32 of Doppke with respect to a menu bar with interactive display elements that can be activated to perform a variety of tasks. The tasks include viewing additional alerts and events. The teachings of Doppke likewise concern graphical user interfaces for network security monitoring and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Petersen to further implement additional visualizations and GUI elements (e.g., a visualization of total traffic for a selectable destination IP address) for at least the purpose discussed in Col. 1, Ll. 51-63 of Doppke (i.e., helping analysts with improved tools to better present information conducive to recognition of relationships and associations concerning network traffic). Petersen-Doppke does not disclose: wherein gathering objects includes: receiving a unified query concerning a plurality of the one or more security-relevant subsystems and distributing at least a portion of the unified query to each of the plurality of the one or more security-relevant subsystems, resulting in distribution of a plurality of queries to the one or more security-relevant subsystems. However, Petersen-Doppke in view of Roturier discloses: wherein gathering objects includes: receiving a unified query concerning a plurality of the one or more security-relevant subsystems and distributing at least a portion of the unified query to each of the plurality of the one or more security-relevant subsystems, resulting in distribution of a plurality of queries to the one or more security-relevant subsystems. Refer to at least the abstract, FIG. 3, Col. 5, Ll. 30-34, Col. 5, Ll. 47-Col. 6, Ll. 2, and Col. 9, Ll. 23-34 of Roturier with respect to a unified conversational agent query by a client being used to generate search queries to a plurality of incident analysis systems. The teachings of Roturier likewise concern graphical user interfaces for computer security monitoring, and are considered to be within the same the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Petersen-Doppke to further implement unified conversational agent functionality for user queries for at least the reasons specified in Col. 1, Ll. 37-59 and Col. 4, Ll. 54-Col. 5, Ll. 8 of Roturier (i.e., making it easier for users to look up information from disparate security incident analysis systems having different APIs and syntax, thereby improving an analyst’s security workflow). Regarding claim 2, it is rejected for substantially the same reasons as claim 1 above (i.e., the citations concerning a pop-up window). Regarding claim 4, Petersen-Doppke-Roturier discloses: The computer-implemented method of claim 1 further comprising: enabling the third-party to select a portion of the object information rendered within the inspection window, thus defining a selected portion. Refer to at least FIG. 19, FIG. 27, FIG. 29-30, and Col. 25, Ll. 26-40, and Col. 30, Ll. 27-Col. 31, Ll. 67 of Petersen with respect to GUI elements within the pop-up windows and additionally being able to drill down within the pop-up windows; with respect to a second pop-up window responsive to edits within the first. Regarding claim 5, it is rejected for substantially the same reasons as claim 4 above (i.e., the citations). Regarding claim 7, Petersen-Doppke-Roturier discloses: The computer-implemented method of claim 6 wherein detecting the security event within the computing platform based upon identified suspect activity includes: monitoring a plurality of sources to identify suspect activity within the computing platform. Refer to at least Col. 12, Ll. 67-Col. 13, Ll. 27 with respect to collecting log data from a variety of sources. Regarding independent claim 10, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations). Regarding claims 11, 13-14, and 16, they are substantially similar to claims 2 and 4-7 above, and are therefore likewise rejected. Regarding independent claim 19, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations). Regarding claims 20, 22-23, and 25, they are substantially similar to claims 2 and 4-7 above, and are therefore likewise rejected. Claim(s) 3, 12, and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Petersen-Doppke-Roturier as applied to claims 1-2, 4-5, 7, 10-11, 13-14, 16, 19-20, 22-23, and 25 above, and further in view of Van Brink (US 2015/0207804 A1). Regarding claim 3, Petersen-Doppke-Roturier does not specify: wherein the inspection window is a slide out inspection window. However, Petersen-Doppke-Roturier in view of Van Brink discloses: wherein the inspection window is a slide out inspection window. Refer to at least FIG. 2, [0036], and [0057] of Van Brink with respect to a slide-out window element. The teachings of Petersen-Doppke-Roturier and the relied-upon teachings of Van Brink concern graphical user interfaces for security and are considered to be combinable. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Petersen-Doppke-Roturier such that its pop-up windows may be implemented via a slide-out element because the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., see [0057] of Van Brink stating the equivalence between use of a pop-up window or a slide-out element). Further, an advantage of using a slide-out element may have been to more efficiently utilize screen space (e.g., the user would not have to deal with finding, opening, and closing pop-ups). Regarding claims 12 and 21, they are substantially similar to claim 3 above, and are therefore likewise rejected. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432 /V.S/Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 19 earlier events
Jun 25, 2025
Response Filed
Oct 07, 2025
Final Rejection mailed — §103, §112
Dec 03, 2025
Response after Non-Final Action
Dec 22, 2025
Request for Continued Examination
Jan 08, 2026
Response after Non-Final Action
Feb 23, 2026
Non-Final Rejection mailed — §103, §112
May 26, 2026
Response Filed
Aug 26, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12639449
SYSTEM AND METHOD FOR SCANNING CONTAINERS FOR VULNERABILITIES
2y 4m to grant Granted May 26, 2026
Patent 12632534
ACCESSING SECURE SYSTEM RESOURCES BY LOW PRIVILEGE PROCESSES
7y 12m to grant Granted May 19, 2026
Patent 12613999
DETECTING ELECTRONIC SYSTEM MODIFICATION
6y 10m to grant Granted Apr 28, 2026
Patent 12608482
DETERMINING A SECURITY SCORE IN BINARY SOFTWARE CODE
6y 5m to grant Granted Apr 21, 2026
Patent 12608501
Privacy-Preserving Log Analysis
5y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

11-12
Expected OA Rounds
61%
Grant Probability
81%
With Interview (+20.3%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 318 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month