Prosecution Insights
Last updated: August 17, 2026
Application No. 17/364,691

ENFORCING JAVASCRIPT FOR MITB DETECTION

Non-Final OA §103§112
Filed
Jun 30, 2021
Examiner
HABTEGEORGIS, MATTHIAS
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Fortinet Inc.
OA Round
7 (Non-Final)
78%
Grant Probability
Favorable
7-8
OA Rounds
0m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
90 granted / 115 resolved
+20.3% vs TC avg
Strong +18% interview lift
Without
With
+17.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
23 currently pending
Career history
139
Total Applications
across all art units

Statute-Specific Performance

§101
4.8%
-35.2% vs TC avg
§103
64.1%
+24.1% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
18.4%
-21.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 115 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/13/2026 has been entered. Response to Arguments Applicant’s arguments, see Remarks, filed 09/25/2025, with respect to the rejection(s) of independent claims 1, 7 and 8 under 35 USC § 112(b) have been fully considered, and are persuasive. Therefore, the rejection of the claims under 35 USC § 112(b) that stems from the 112(f) interpretation has been withdrawn. However, the antecedent issues were not fully addressed by the Applicant, and the amendments have also introduced new antecedent issues as indicated in this office action, and thus the rejection of the claims under 35 USC § 112(b) is maintained. With respect to the rejection(s) of independent claims 1, 7 and 8 under 35 USC § 103, on page 13/14 of the Remarks, the Applicant’s argument is moot because of the new ground of rejection based on a newly found prior art, Liberman, US 2003/0028801. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-2, 5-6 and 8 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites the limitation "the remote web page" in lines 36-37. There is insufficient antecedent basis for the "the remote web page” in the claim. The Examiner suggests to amend claim 1 by replacing the limitation “detect an outgoing request for a web page” in lines 16-17 with “detect an outgoing request for a confidential web page”, and also each instance of the “remote web page” in the claim by “confidential web page” to maintain consistency with claims 7 and 8. Claims 2 and 5 recite the limitation "the confidential web page" in lines 3-4 and 1-2, respectively. There is insufficient antecedent basis for the "the confidential web page” in the claims. Claim 6 recites the limitation "a second confidential web page" in line 2. There is insufficient antecedent basis for the "a second confidential web page” since it implies there was “a first confidential web page” prior to the claimed "a second confidential web page” in the claim. Claim 8 recites the limitation "the plurality of clients," in line 11. There is insufficient antecedent basis for the "the plurality of clients" in the claim. Claim 1 recites the limitation "wherein the JavaScript restriction module," in line 31. There is insufficient antecedent basis for the "the JavaScript restriction module," in the claim. Claim 1 recites the limitation "wherein the JavaScript enablement module receives …" in line 44. There is insufficient antecedent basis for the "the JavaScript enablement module," in the claim. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2 and 7-8 are rejected under 35 U.S.C. 103 as being unpatentable over USPAT No. 10721269 B1 to Talmor et al. (hereinafter “Talmor”), US-PGPUB No. 2003/0028801 A1 to Liberman et al. (hereinafter “Liberman”), and further in view of US-PGPUB No. 2008/0175377 A1 to Merrill Regarding claim 1: Talmor discloses: A network device (col 3, line 7: “… a network traffic management device 110 …”, see Fig. 2) on an enterprise network (see Fig. 1, LAN 104) that connects with a plurality of clients (see Fig. 1, Client Devices 106) over a Wi-Fi network (see Fig. 1, Network 108, col.3, lines 54-57: “… network 108 may include local area networks (LANs), … and other types and numbers of network types.”), […], the network device comprising: a processor (see Fig. 2, device Processor 200); a network interface (see Fig. 2, Network Interface 204) communicatively coupled to the processor (see Fig. 2, device Processor 200 coupled to Network Interface 204) and to the enterprise network (see Fig. 1, LAN 104 coupled to Device 110 which incorporates Network Interface 204) and to the Internet (col 3, lines 44-45: “Network 108 comprises a publicly accessible network, such as the Internet …”), wherein the plurality of clients locally execute JavaScript (col 8, lines 12-13: “… requesting client devices 106 process the challenges (e.g., JavaScript)”); and a memory (see Fig. 2, Device Memory 218), communicatively coupled to the processor (see Fig. 2, Device Memory 218 coupled to Device Processor 200) and storing modules executable by the processor (see Fig. 2, Device Memory 218 storing Security Module 210) that, when executed by the processor cause the the network device to: detect an outgoing request for a web page (col 7, line 9: “client requests destined for particular servers,”) from the enterprise network by a specific client of the plurality of clients (see Fig. 3, block 300, Receive Request for Server, col 10, lines 54-55: “… device 110 may receive a request for access to the server 102 from a client device such as the client device 106 …”, see Fig. 3, step 300), and in response, transmit an HTML code snippet downstream (see Fig. 3, Return Request to Client Device with Java Script, step 308) to a browser running on the specific client (col 3, lines 35-36: “… client devices 106 run Web browsers …”) to determine whether JavaScript is enabled or disabled locally at the specific client (see Fig. 3, decision block 310, “YES” branch (JavaScript enabled), “NO” branch (JavaScript not enabled)); responsive to detecting that JavaScript has been locally disabled at the specific client (see Fig. 3, decision block 310, the “NO” branch (JavaScript not enabled, JavaScript Disabled), see also col 8, lines 56-62: “Many client devices that may perform attacks, such as denial of service or brute force attacks, may not be capable of processing the JavaScript in the request and therefore will not send a response to the network device 110. Thus, client devices that … have JavaScript disabled … may not be served by the application server 102.”), restrict subsequent local communication from the specific client (col 11, lines 8-10: “If no response is received, the network traffic management device 110 ends the routine without requesting access to the server 102 (312).”, see Fig. 3, step 312, END), wherein the JavaScript restriction module, responsive to detecting that JavaScript has been locally disabled (see Fig. 3, decision block 310, “NO” branch (JavaScript not enabled)), requires enabling of JavaScript to continue to the remote web page (col 11, lines 8-10: “If no response is received, the network traffic management device 110 ends the routine without requesting access to the server 102 (312).”), and responsive to detecting that JavaScript has not been disabled, allowing the request for the (col 11, lines 6-8: “If the response is received, the network traffic management device 110 may send the request to the server 102 (306).”, see Fig. 3, step 306, Send Request to Server); and [wherein the JavaScript enablement module] receives an indication that JavaScript has been enabled at the specific client (col 11, lines 37-50: “… the network traffic management device 110 selects a JavaScript challenge code (408).… The execution of the challenge results in a cookie being included in a response to the network traffic management device 110. The response with the cookie is received by the network traffic management device 110 (412) (implies the JavaScript challenge code was executed by the specific network device which indicates JavaScript is enabled on the specific network device).”), and in response, transmits the remote web page to the browser running on the specific client (col 11, lines 54-59: “Once the response is received, the network traffic management device 110 may compare the data in the cookie … with the expected results of the computational challenge to determine if the result is correct (414). If the result is correct, the request is sent to the server 102.”). However, Talmor does not explicitly disclose the following limitation taught by Rosenthal: send an alert message to the specific client, the message requesting automatic enablement of JavaScript, prior to allowing access to the remote web page (Liberman, ¶27-28: “when a user requests access to a particular document available on a web page, for which copy protection is required, the program will operate so as to first check whether or not the user's browser is and has JavaScript enabled. … If the user's browser does not have JavaScript enabled, then the program may send an HTML message to the user, such as "Please enable JavaScript". The program may prevent the particular document from being accessed until JavaScript is enabled by automatically redirecting it to the origin page. Therefore, if users do not enable JavaScript on their browsers, they will not be allowed to view the requested document.”), It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of Talmor to incorporate the functionality of the program to first check whether or not a user's browser is and has JavaScript enabled prior to providing access to a particular document available on a web page, and send an HTML message to the user to enable JavaScript when it is determined that the browser does not have JavaScript enabled, as disclosed by Liberman, such modification would enable the system to disable appropriate client-side browser/platform functionality, for example, by using Javascript to disable the right mouse button on PCs users will be prevented from accessing the right mouse button menu that includes functions such as "select all", "view source", and "print" options (as taught in paragraph [0029] by Liberman). The combination of Talmor and Liberman does not explicitly disclose the following limitation taught by Merrill: […] for detecting and remediating local web browser Man-in-the Browser (MITB) security breaches (Merrill, ¶74: “… detect man-in-the-browser attacks and deny fraudulently manipulated transactions.”) wherein a MITB browser extension is executing on the browser in an attempt to compromise data of the browser (Merrill, ¶74: “… The rogue browser extension changes transaction information in an attempt to re-route funds to an unauthorized third party. … detect man-in-the-browser attacks and deny fraudulently manipulated transactions.”), It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Talmor and Liberman to incorporate the functionality of the method to implement a browser plug-in to append a digital signature for a submitted transaction to verify the integrity of the transaction, as disclosed by Merrill, into the security module of Talmor, such modification would allow the system (the security module of Talmor) to detect man-in-the-browser attacks from rogue browser extensions and implement proper mitigation actions. Regarding claim 2: The combination of Talmor, Liberman and Merrill discloses: The network device of claim 1, further comprising wherein JavaScript is transmitted to the browser of the specific network device based on the confidential web page (Talmor, ¶31: “Challenge insertion could be turned on and off for specific server resources, such as … particular URIs … automatically …”). Regarding claim 7: Claim 7 substantially recites the same limitations as claim 1 in the form of a method implementing the corresponding functionalities, therefore it is rejected by the same rationale. Regarding claim 8: Talmor discloses: A non-transitory computer-readable media (col 6, lines 27-29: “Device memory 218 comprises computer readable media, namely computer readable or processor readable storage media …”) in a network device (col 3, line 7: “… a network traffic management device 110 …”, see Fig. 2) on an enterprise network (see Fig. 1, LAN 104) that connects with a plurality of stations (see Fig. 1, client devices 106) over a Wi-Fi network (see Fig. 1, Network 108, col.3, line 44-col.4, line 7) for sensitive data transfers (col 7, line 9: “client requests destined for particular servers,”, col 4, lines 3-6: “… the network 108 … data may travel between client devices 106, Web application servers 102 and network traffic management device 110, …”), when executed by a processor (see Fig. 2, device Processor 200), performs a method (see the method of Fig. 3) […], the method comprising the steps of: In addition to the above limitations, claim 8 substantially recites the same limitations as claim 1 in the form of a non-transitory computer-readable media for an artificial intelligence model-based data delivery for low battery stations co-existing with high-bandwidth stations within the plurality of stations, therefore it is rejected by the same rationale. Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Talmor, Liberman, Merrill, and further in view of US-PGPUB No. 2002/0108050 A1 to Raley et al. (hereinafter “Raley”) Regarding claim 5: The combination of Talmor, Liberman and Merrill discloses the network device of claim 1, but does not explicitly disclose the following limitation taught by Raley discloses: wherein the confidential web page comprises a log in page (Raley, ¶80-83: “… client computer 230 … requests document 222 from distributor server 220 … distributor server 220 then informs client computer 230 that document 222 is protected and client computer 230 needs to have security module 237 to render document 222 … transaction aggregator 160 requests and collects various user information …The method of FIG. 11 permits a user to log on to a new Web site to initiate a transaction.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Talmor, Liberman and Merrill to incorporate the capability of the server to store web pages having a plurality of protected documents, and the functionality of the management module to prohibit access to the protected documents when the UI module is not installed, or limit access to only documents specified as being freely distributable, as disclosed by Raley, into the security module of Talmor, such modification would allow the system (the security module of Talmor) to control the distribution of electronic documents over the Web. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Talmor, Liberman, Merrill, and further in view of USPAT No. 8613089 B1 to Holloway et al. (hereinafter “Holloway”) Regarding claim 6: The combination of Talmor, Liberman and Merrill discloses the network device of claim 1, but does not explicitly disclose the following limitation taught by Holloway: wherein a second request (Holloway, col 25, line 10: “… a subsequent request …”) for a second confidential web page is detected, and the network device bypasses an additionally JavaScript enablement check for the second request during a predetermined period of time (Holloway, col 25, lines 10-15: “If a subsequent request is received at the proxy server prior to the time expiring, then the same challenge will be presented to the visitor without testing whether the answer was correct. After the time period of the cache (5860 milliseconds) has expired, the proxy server begins to accept answers to the challenge.”, see Fig. 11, client-side script 1110). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Talmor, Liberman and Merrill to incorporate the functionality of the proxy server to receive a request that includes a client-side script code, and cache the request for a predetermined number of milliseconds based on a number of specified milliseconds in the code, as disclosed by Holloway, such modification would allow the system to avoid frequent computation of challenges during each request, thus improving efficiency of the system . Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MATTHIAS HABTEGEORGIS whose telephone number is (571)272-1916. The examiner can normally be reached M-F 8am-5pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William R. Korzuch can be reached on (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MATTHIAS HABTEGEORGIS/Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Show 9 earlier events
Feb 28, 2025
Request for Continued Examination
Mar 06, 2025
Response after Non-Final Action
Mar 25, 2025
Non-Final Rejection mailed — §103, §112
Sep 25, 2025
Response Filed
Jan 13, 2026
Final Rejection mailed — §103, §112
May 13, 2026
Request for Continued Examination
May 23, 2026
Response after Non-Final Action
Jun 16, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706939
Prioritizing Vulnerability Based on Application Security Context
3y 7m to grant Granted Aug 11, 2026
Patent 12671714
LIMITING THE ABILITY OF RANSOMWARE TO SPREAD WITHIN A DATA CENTER
3y 2m to grant Granted Jun 30, 2026
Patent 12671700
METHOD FOR TRACING PATH OF ATTACK ON SMART CONTRACT ON BLOCKCHAIN
2y 9m to grant Granted Jun 30, 2026
Patent 12659297
APPARATUS AND METHOD FOR INTRUSION DETECTION AND PREVENTION OF CYBER THREAT INTELLIGENCE
2y 8m to grant Granted Jun 16, 2026
Patent 12652296
SYSTEM, METHOD, AND COMPUTER PROGRAM FOR APPLICATION PROGRAMMING INTERFACE (API) SECURITY
2y 1m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
78%
Grant Probability
96%
With Interview (+17.6%)
3y 0m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 115 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month