Prosecution Insights
Last updated: October 04, 2026
Application No. 17/161,497

KERNEL BASED EXPLOITATION DETECTION AND PREVENTION USING GRAMMATICALLY STRUCTURED RULES

Non-Final OA §103
Filed
Jan 28, 2021
Examiner
POPHAM, JEFFREY D
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Malwarebytes Corporate Holdco Inc.
OA Round
8 (Non-Final)
38%
Grant Probability
At Risk
8-9
OA Rounds
0m
Est. Remaining
62%
With Interview

Examiner Intelligence

Grants only 38% of cases
38%
Career Allowance Rate
179 granted / 474 resolved
-20.2% vs TC avg
Strong +24% interview lift
Without
With
+24.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 7m
Avg Prosecution
25 currently pending
Career history
508
Total Applications
across all art units

Statute-Specific Performance

§101
14.7%
-25.3% vs TC avg
§103
47.6%
+7.6% vs TC avg
§102
14.4%
-25.6% vs TC avg
§112
21.1%
-18.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 474 resolved cases

Office Action

§103
Remarks Claims 1, 3-10, and 13-20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 8/24/2026 has been entered. Response to Arguments Applicant's arguments filed 8/24/2026 have been fully considered but they are not persuasive. With respect to Applicant’s allegations on pages 11-13, the Examiner notes with appreciation Applicant’s admission that “Paithane discloses that its hook framework intercepts API calls associated with activity of the interpreter … affirmatively attribute the intercepted call to a source … such as the interpreter…”. As noted in Paithane, the interpreter can be part of the kernel. For example, Paithane discloses that the interpreter is in the kernel in various portions (e.g., column 11, lines 21-23: “in operation alongside the interpreter 272, a kernel driver 274 is loaded into the kernel 266.” Figure 2 clearly shows interpreter 272 and kernel driver 274 within kernel 266, for example. Thus, one of the sources discussed as being the source of the call within Paithane actually is within the kernel in at least some embodiments thereof. Thus, Paithane clearly discloses “an execution call issued by the operating kernel to cause execution by the computer processor”. With respect to Applicant’s allegations regarding Lopez-Chicheri, in response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 4-6, 10, 13-15, and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Paithane (U.S. Patent 10,033,747) in view of Lopez-Chicheri (U.S. Patent 9,754,105). Regarding Claim 1, Paithane discloses a method for preventing exploitation of a computer processor, the method comprising: Receiving, from a monitoring module executing on an operating kernel, a triggering action on the operating kernel that includes an execution call issued by the operating kernel to cause execution by the computer processor, the triggering action received before execution of the triggering action on the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures; triggering action, such as anomalous API call, out of order API call, specified API call, other non-API calls, activities, acquiring of information based thereon, characteristics, features, objects, metadata, state information, etc., as examples, from hooks, instrumentation, hook framework, instrumentation framework, etc., in kernel, for example. Moreover, it is noted that Paithane disclose that the host OS may be monitored, in addition to the guest OSes (e.g., column 12, lines 17-21). Therefore, Paithane includes disclosure of a host OS being monitored as well as the guest OSes. Additionally, Paithane discloses that the interpreter is in the kernel in various portions (e.g., column 11, lines 21-23: “in operation alongside the interpreter 272, a kernel driver 274 is loaded into the kernel 266.” Figure 2 clearly shows interpreter 272 and kernel driver 274 within kernel 266, for example. Moreover, the interpreter can make the calls. For example, column 4, lines 53-56 states “intercepting of anomalous activities by the interpreter through any of the interception point frameworks, followed by confirmation that the activities appear to have been initiated by the interpreter.”); Responsive to receiving the triggering action and before executing the triggering action, accessing an evidence set comprising information describing execution of the triggering action and a plurality of related actions corresponding to the triggering action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures; triggering action, such as anomalous API call, out of order API call, specified API call, other non-API calls, activities, acquiring of information based thereon, characteristics, features, objects, metadata, state information, etc., as examples); Generating, using the evidence set for the triggering action and before executing the triggering action on the operating kernel, an execution hierarchy defining hierarchical relationships between the triggering action and the plurality of related actions (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 8, lines 45-60; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, line 1 to Column 17, line 30; Column 17, line 51 to Column 18, line 27; and associated figures; calling hierarchy, sequence of calls, call stack, call trace, etc., as examples); Accessing a rule list comprising a plurality of grammatically structured rules configured to identify whether the triggering action is an exploitation action for the operating kernel when applied to the execution hierarchy for the triggering action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; any rules, such as de-obfuscation rules, white lists, black lists, abnormal calls, specified calls, call sequences, verifying call hierarchies, etc., as examples); Determining the triggering action is an exploitation action for the operating kernel by applying each grammatically structured rule in the accessed rule list to the execution hierarchy (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; identifying malicious action/activity, for example, by applying the above, for example); and Responsive to determining that the triggering action is an exploitation action and before execution of the exploitation action by the operating kernel, performing a prevention action to prevent execution of the exploitation action called by the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; report/alert when malicious, for example); But may not explicitly disclose stopping the operating kernel from executing the triggering action on the operating kernel. Lopez-Chicheri, however, discloses that the prevention action comprises stopping the operating kernel from executing the triggering action on the operating kernel (Exemplary Citations: for example, Abstract, Column 2, lines 44-49; Column 3, line 57 to Column 4, line 5; Column 4, lines 25-67; Column 5, line 58 to Column 6, line 45; Column 7, line 56 to Column 10, line 11; and associated figures; determining if calls, requesting applications, etc., exhibit malicious behavior/parameters, and then allowing or denying requested call based on the above, and terminating the application if malicious as well, for example. It is noted that Paithane already discloses that the triggering actions are from the kernel and for the kernel to execute. Moreover, Lopez-Chicheri also discloses stopping the kernel from executing API calls, such as API calls to kernel32.dll (e.g., Kernel32.dll CreateProcessW API), for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the exploitation prevention techniques of Lopez-Chicheri into the attack detection system of Paithane in order to allow the system to stop malicious actions from ever being executed, to provide for termination of malicious applications, allow the system to detect malicious actions regardless of the data or patterns involved, to beneficially detect malicious characteristics by analyzing a memory address associated with an API call and determining if the memory location lacks execute access, and/or to increase security in the system. Regarding Claim 19, Claim 19 is a medium claim that corresponds to method claim 1 and is rejected for the same reasons. Regarding Claim 20, Claim 20 is a system claim that corresponds to method claim 1 and is rejected for the same reasons. Regarding Claim 4, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that performing the prevention action to prevent execution of the exploitation action by the operating kernel further comprises: Generating a notification indicating the triggering action is the exploitation action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; report/alert when malicious, for example); and Displaying the notification on a display of a system comprising the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; report/alert when malicious, for example). Regarding Claim 5, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that performing the prevention action to prevent execution of the exploitation action by the operating kernel further comprises: Transmitting, to a security management server, a report that both indicates the triggering action is the exploitation action and comprises the evidence set and the execution hierarchy for the triggering action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; report/alert when malicious, for example). Regarding Claim 6, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that applying each grammatically structured rule further comprises: For each grammatically structured rule in the rule list (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; if a certain action is found, it may be suspicious/malicious, if the action is malicious, an attack is detected, etc., for example): Accessing a conditional statement in the grammatically structured rule configured to identify one or more exploitation actions in the execution hierarchy (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; if a certain action is found, it may be suspicious/malicious, if the action is malicious, an attack is detected, etc., for example); and Evaluating the conditional statement against the execution hierarchy to determine whether one or more actions in the execution hierarchy are exploitation actions (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; if a certain action is found, it may be suspicious/malicious, if the action is malicious, an attack is detected, etc., for example); Wherein the conditional statement is indicated by its location within a grammatical structure of the grammatically structured rule (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; if a certain action is found, it may be suspicious/malicious, if the action is malicious, an attack is detected, etc., for example). Regarding Claim 10, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that the rule list is configured to identify a plurality of exploitation actions (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures); and Each grammatically structured rule of the rule list is configured to identify one or more exploitation actions of the plurality of exploitation actions in the rule list (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures). Regarding Claim 13, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses identifying an application class for the triggering action and wherein only grammatically structured rules corresponding to the application class are applied to the triggering action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; choosing configuration based on application type, interpreter type, object type, script type, or the like, as examples); and Lopez-Chicheri discloses identifying an application class for the triggering action and wherein only grammatically structured rules corresponding to the application class are applied to the triggering action (Exemplary Citations: for example, Column 5, lines 29-47, all citations above, and associated figures; application profiles and/or group profiles identifying what is to be analyzed, for example). Regarding Claim 14, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses monitoring, in real time, a plurality of execution calls by the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures); and Responsive to an execution call of the plurality of execution calls having a verification call type, defining the execution call as the triggering action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures; triggering actions described above are to be verified and, thus, have a verification call type, for example). Regarding Claim 15, Paithane as modified by Lopez-Chicheri discloses the method of claim 14, in addition, Paithane discloses executing one or more actions corresponding to one or more of the plurality of execution calls by the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures); Storing the one or more actions in a datastore (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures; storing information about calls, for example); and Wherein accessing the evidence set for the triggering action comprises accessing one or more of the stored actions in the datastore as the plurality of related actions (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures; accessing information about calls, for example). Regarding Claim 17, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that accessing the evidence set further comprises reading one or more execution images from a datastore (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures). Regarding Claim 18, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that the evidence set comprises information for previously terminated actions executed by the operating kernel (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 9, lines 31-47; Column 10, lines 7-32; Column 11, line 21 to Column 12, line 6; Column 12, line 17 to Column 13, line 10; Column 14, line 63 to Column 15, line 32; Column 16, lines 1-50, Column 17, lines 1-30; Column 17, line 51 to Column 18, line 27; and associated figures). Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Paithane in view of Lopez-Chicheri and Sridhara (U.S. Patent Application Publication 2016/0337390). Regarding Claim 3, Paithane as modified by Lopez-Chicheri does not explicitly disclose that performing the prevention action to prevent execution of the exploitation action by the operating kernel further comprises migrating one or more files associated with the triggering action into a quarantine such that the triggering action cannot be executed by the operating kernel. Sridhara, however, discloses that performing the prevention action to prevent execution of the exploitation action by the operating kernel further comprises migrating one or more files associated with the triggering action into a quarantine such that the triggering action cannot be executed by the operating kernel (Exemplary Citations: for example, Abstract, Paragraph 39 and associated figures). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the real-time whitelisting and malicious response techniques of Sridhara into the attack detection system of Paithane as modified by Lopez-Chicheri in order to allow the system to quarantine malicious entities, allow for whitelist updating, and/or to increase security in the system. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Paithane in view of Lopez-Chicheri and Fulp (U.S. Patent Application Publication 2006/0248580). Regarding Claim 7, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that performing the prevention action to prevent execution of the exploitation action by the operating kernel further comprises: Accessing an action statement in a grammatically structured rule in the rule list that determined the triggering action was the exploitation action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; each rule designates what occurs when the rule is triggered, for example); Applying the action statement as the prevention action (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures); and Wherein the action statement is indicated by its location within a grammatical structure of the grammatically structured rule (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 26; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures; all rules are structured such that the computer can determine what each portion of the rule is, so that the action will be distinctly set apart from the rest (e.g., conditionals for the rule), for example). Fulp also discloses that the action statement is indicated by its location within a grammatical structure of the grammatically structured rule (Exemplary Citations: for example, Figures 5A, 5B, 6B, 7B, and associated written description; Tables 1, 2, and associated written description; action column, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention to incorporate the action column of Fulp into the attack detection system of Paithane as modified by Lopez-Chicheri in order to provide an explicit action/response/countermeasure column within a rule table, to allow any entity to easily determine what the action/response/countermeasure for every rule is, to allow the system to re-order rules so as to optimize the rules and security processing, and/or to increase security in the system. Claims 8, 9, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Paithane in view of Lopez-Chicheri and Yoo (U.S. Patent Application Publication 2012/0047366). Regarding Claim 8, Paithane as modified by Lopez-Chicheri does not explicitly disclose receiving a rule list from a security management server configured to generate the grammatically structured rules in the rule list. Yoo, however, discloses receiving a rule list from a security management server configured to generate the grammatically structured rules in the rule list (Exemplary Citations: for example, Paragraphs 48-50, 54-58, 106-116, 119-121, 126, 192, and associated figures; server sending encrypted update data (e.g., firewall updates, antivirus updates, etc.) to device, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the updating techniques of Yoo into the attack detection system of Paithane as modified by Lopez-Chicheri in order to ensure that security updates are encrypted, to provide additional defense against malicious entities, and/or to increase security in the system. Regarding Claim 9, Paithane as modified by Lopez-Chicheri does not explicitly disclose responsive to a security management server generating one or more additional grammatically structured rules configured to identify one or more additional exploitation actions, receiving an updated rule list from the security management server comprising the one or more additional rules. Yoo, however, discloses responsive to a security management server generating one or more additional grammatically structured rules configured to identify one or more additional exploitation actions, receiving an updated rule list from the security management server comprising the one or more additional rules (Exemplary Citations: for example, Paragraphs 48-50, 54-58, 106-116, 119-121, 126, 192, and associated figures). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the updating techniques of Yoo into the attack detection system of Paithane as modified by Lopez-Chicheri in order to ensure that security updates are encrypted, to provide additional defense against malicious entities, and/or to increase security in the system. Regarding Claim 16, Paithane as modified by Lopez-Chicheri discloses the method of claim 1, in addition, Paithane discloses that the rule list is a binary file representing the plurality of grammatically structured rules (Exemplary Citations: for example, Column 2, line 42 to Column 5, line 27; Column 5, line 63 to Column 6, line 7; Column 6, line 55 to Column 7, line 15; Column 8, lines 45-60; Column 10, line 7 to Column 13, line 10; Column 13, line 30 to Column 14, line 16; Column 14, line 63 to Column 15, line 32; Column 15, line 51 to Column 17, line 30; Column 17, line 51 to Column 18, line 53; and associated figures); But does not explicitly disclose that the binary file is an encrypted binary file. Yoo, however, discloses that the rule list is an encrypted binary file representing the plurality of grammatically structured rules (Exemplary Citations: for example, Paragraphs 48-50, 54-58, 106-116, 119-121, 126, 192, and associated figures). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the updating techniques of Yoo into the attack detection system of Paithane as modified by Lopez-Chicheri in order to ensure that security updates are encrypted, to provide additional defense against malicious entities, and/or to increase security in the system. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jeffrey D Popham whose telephone number is (571)272-7215. The examiner can normally be reached Monday through Friday 9:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey D. Popham/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 32 earlier events
Apr 03, 2025
Notice of Allowance
Apr 17, 2025
Applicant Interview (Telephonic)
Aug 04, 2025
Response after Non-Final Action
Aug 10, 2025
Response after Non-Final Action
Mar 24, 2026
Final Rejection mailed — §103
Aug 24, 2026
Request for Continued Examination
Aug 27, 2026
Response after Non-Final Action
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730884
SYSTEMS AND METHODS FOR INTELLIGENT CONFIGURATION AND DEPLOYMENT OF ALERT SUPPRESSION PARAMETERS IN A CYBERSECURITY THREAT DETECTION AND MITIGATION PLATFORM
3y 5m to grant Granted Sep 08, 2026
Patent 12671985
ACCESS AND MOBILITY MANAGEMENT FUNCTION RELOCATION DUE TO SECURITY GATEWAY OVERLOAD/FAILURE
3y 10m to grant Granted Jun 30, 2026
Patent 12481750
A METHOD OF PROCESSING TRANSACTIONS FROM AN UNTRUSTED SOURCE
5y 2m to grant Granted Nov 25, 2025
Patent 12425407
Identity And Access Management Using A Decentralized Gateway Computing System
2y 10m to grant Granted Sep 23, 2025
Patent 12380240
PROTECTING SENSITIVE DATA IN DOCUMENTS
4y 10m to grant Granted Aug 05, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

8-9
Expected OA Rounds
38%
Grant Probability
62%
With Interview (+24.0%)
4y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 474 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month