Prosecution Insights
Last updated: October 02, 2026
Application No. 17/380,738

CLASSIFICATION OF MOUSE DYNAMICS DATA USING UNIFORM RESOURCE LOCATOR CATEGORY MAPPING

Final Rejection §103
Filed
Jul 20, 2021
Examiner
LAU, KAITLYN RENEE
Art Unit
2148
Tech Center
2100 — Computer Architecture & Software
Assignee
International Business Machines Corporation
OA Round
6 (Final)
60%
Grant Probability
Moderate
7-8
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 60% of resolved cases
60%
Career Allowance Rate
6 granted / 10 resolved
+5.0% vs TC avg
Strong +67% interview lift
Without
With
+66.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
27 currently pending
Career history
40
Total Applications
across all art units

Statute-Specific Performance

§101
28.8%
-11.2% vs TC avg
§103
34.3%
-5.7% vs TC avg
§102
14.3%
-25.7% vs TC avg
§112
21.9%
-18.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 10 resolved cases

Office Action

§103
DETAILED ACTION This action is in response to the amendment filed 07/20/2026. Claims 1, 3-8, 10-15, 17-20 and 24-26 are pending and have been examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claim 8 objected to because of the following informalities: Regarding claim 8 the Examiner respectfully notes that claim 8 is a method claim and the limitation of “responsive to the decision indicating the session is not legitimate, automatically initiating at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically blocking the session and automatically inspecting the session” is a contingent limitation and therefore under the broadest reasonable interpretation these limitation may not be performed (“The broadest reasonable interpretation of a method (or process) claim having contingent limitations requires only those steps that must be performed and does not include steps that are not required to be performed because the condition(s) precedent are not met.” MPEP 2111.04(II)). Accordingly the Examiner recommends the Applicant positively recite that the session is not legitimate to avoid a contingent interpretation of these limitations. Appropriate correction is required. Applicant is advised that should claims 7, 13, and 20 be found allowable, claims 24-26 will be objected to under 37 CFR 1.75 as being a substantial duplicate thereof. When two claims in an application are duplicates or else are so close in content that they both cover the same thing, despite a slight difference in wording, it is proper after allowing one claim to object to the other as being a substantial duplicate of the allowed claim. See MPEP § 608.01(m). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1, 3, 8, 10-11, 15, and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Benkreira et al. (US 20210319527) ("Benkreira"), in view of Smith and Ng, "Web Page Clustering Using a Self-Organizing Map of User Navigation Patterns" (“Smith”) in further view of Kilic et al. (“Bogazici mouse dynamics dataset”) (hereafter referred to as Kilic). Regarding Claim 1, Benkreira teaches A system for classifying mouse dynamics data of a session using a trained classification model and providing a decision regarding legitimacy of the session, comprising a processor to (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025) where “the system (e.g., using computing resource 414 processor 520, memory 530, storage component 540, input component 550, output component 560, communication interface 570, and or the like) may transit an indication of a recommended action to be performed by the server device with respect to the application form and the client device based on the fraud score, as described above”.): receive mouse dynamics data of the session to be analyzed (Benkreira Fig. 6, 620, Receive, from the server device, behavior information that indicates user behavior associated with inputting data into the application form using the client device wherein “the behavior information may indicate at least one of:…mouse dynamics used to input the data into the one or more fields or to navigate between fields of the application form, a technique used to navigate between fields of the application form, a technique used to scroll between different portions of the application form on the client device.” (Benkreira, page 22, paragraph 0087)), group the mouse dynamics data into a plurality of groups (Benkreira, page 19, paragraph 0055, “the trained machine learning model may classify (e.g. cluster) the new observation in a cluster [group] as shown by reference number 320” wherein “the set of observations may include data gathered from user interacting with and/or user input” (Benkreira, page 16, paragraph 0038)), separately extract, for each of the plurality of… categories, a distinct set of mouse dynamics, (Benkreira, Paragraph 0039, "As shown by reference number 210, a feature set may be derived from the set of observations. The feature set may include a set of variable types. A variable type may be referred to as a feature….In some implementations, the machine learning system may determine features (e.g., variables types) for a feature set based on input received from a server device, such as by extracting or generating a name for a column… and/or the like" where “For example, the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) wherein the features are clustered (Benkreira page 19, paragraph 0055), then the features are extracted from each cluster for each feature set. Examiner further notes that the observations are the mouse dynamics.). input the mouse dynamics features into the trained classification model, wherein the trained classification is configured to operate on the mouse dynamics features of each of the plurality of …categories (Benkreira, Paragraph 0003, "provide the device information and the behavior information as a feature set that is input to a machine learning model”); receive an output score from the trained classification model (Benkreira, Paragraph 0003, “receive output from the machine learning model”), wherein the output score represents a legitimacy of the session (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315.”where “the fraud platform may determine a fraud score based on the device information and the behavior information. A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score.); specify, using a policy, the decision regarding legitimacy based on the output score of the session and whether the output score exceeds a threshold wherein the decision is a classification of the session as legitimate, not legitimate or an outlier (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation, such as to send another authentication challenge to verify identity. Additionally, or alternatively, the machine learning system may perform an automated action and/or may cause an automated action to be performed (e.g., by instructing another device to perform the automated action) such as to send a more difficult authentication challenge” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score. Examiner further notes that by exceeding the threshold, the fraud score is classified as having a high likelihood of fraud. Examiner notes that classifying as not legitimate is having a likelihood of fraud.). responsive to the decision indicating the session is not legitimate, automatically initiating at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically blocking the session and automatically inspecting the session (Benkreira, page 15, paragraph 0028, "Recommended actions may include approving an application associated with the application form, rejecting the application associated with the application form, requesting additional information from the client device, sending an authentication challenge ( e.g., a knowledge-based authentication (KBA) question, a video review action, a biometric step-up action, and/or the like), and/or the like. The recommended action may be used to obtain additional information on whether to authenticate the user and/or gain more information on whether the transaction is fraudulent" where " the client device may transmit, to an operator device, the video review based on the unsuccessful completion of the KBA challenge. The operator device may determine whether the video review is sufficient to authenticate the user and/or accept the application" (Benkreira, page 16, paragraph 0035) and "Operator device 440 includes one or more devices capable of receiving, generating, storing, processing, and/or providing information, such as information described herein. For example, operator device 440 may include a laptop computer, a tablet computer, a desktop computer, a server device, a group of server devices, or a similar type of device, associated with a merchant, a financial institution, and/or the like. In some implementations, operator device 440 may receive information from and/or transmit information to server device 430 and/or fraud platform 410" (Benkreira, page 20, paragraph 0070). Examiner notes that rejecting the application is automatically blocking the session. Examiner further notes that sending an authentication challenge and/or the like is automatically inspecting the session.) Benkreira does not teach, but Smith does teach process the mouse dynamics data by partitioning a website corresponding to the plurality of uniform resource locators (URLs) into a plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to aa plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); map each URL visited in the session to at least one URL category of the plurality of URL categories in order to generate a URL category mapping (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes mapping each URL visited in the session to at least one URL category is clustering the transactions into similarity groups. Examiner further notes that the clusters are the URL categories and the category mapping is the SOM.); group the…data into a plurality of groups using the URL category mapping, wherein each of the plurality of groups relates to one of the at least one URL category (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph).Examiner notes that the SOM is being considered as a category mapping) the plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to a plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); wherein the mouse dynamics features contain information about how a user interacts with each of the plurality of URL categories (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns. The K-means algorithm is outlined in Fig. 2. Within each processed transaction group, we use the column totals as the activity of the transaction group. This is illustrated in Table 2, where the cluster depicted contains 2679 transactions, including transaction numbers 5, 6, and 8012. Instead of having transactions as features, we now have transaction groups as features. The URLs are now described by the relative interests or activities of each of the transaction groups.” (Smith, page 250, 2nd -3rd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph). Examiner notes that the transaction groups are features.); Benkreira and Smith are considered analogous because they are in the same field of machine learning where they both collect and organize data to be trained. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira to use a URL category mapping to group the behavior data. Doing so would “successfully reduce[] the number of dimensions of the data” (Smith, page 250, paragraph 6) and “add more value to information retriev[ed]” (Smith, page 246, fifth paragraph). Benkreira and Smith do not teach, but Kilic does teach Wherein the mouse dynamics data comprises, for each of a plurality of uniform resource locators (URLs) that are visited, an action identifier, a timestamp, an x-coordinate and a y-coordinate (Kilic, page 2, last 3 paragraphs, “This dataset includes mouse behavior data which is collected from 24 different participants….Collected data has 7 columns: action type, timestamp, mouse cursor X location, mouse cursor Y location, clicked button (None if it is not a click), click state (Move, Pressed or Released) and foremost application window name respectively. Dataset columns are listed with detailed descriptions in Table 1. For all users, browsing (Google Chrome, Mozilla Firefox, Safari, etc.) is the most time spent action by far with 51 percent. Development applications (VMWare, Docker, PyCharm, etc.) are second with 19 percent, Office applications (MS Word, MS Excel, LibreOffice, etc.) are third with 17 percent, filesystem applications (System Preferences, OS programs, setup files, etc.) are fourth by 11 percent, and finally, entertainment applications (Spotify, Discord, video games, etc.) are fifth by 2 percent.” Examiner notes that the action identifier is the action type and the plurality of URLs are the browsers and applications used.) Benkreira, Smith, and Kilic are considered analogous because they are in the same field of mouse, behavior, and user data where they collect and organize data to be trained on. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith to use an action identifier, X coordinate, Y coordinate, and time stamp in the mouse dynamics data. Doing so would be advantageous because “this dataset is highly suitable for testing the under-development procedures against the insider threat, remote unauthorised access, and physical access” (Kilic, abstract). Regarding Claim 3, Benkreira in view of Smith and Kilic teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira further teaches wherein the trained classification model is trained using the mouse dynamics features extracted from a plurality of training sessions (Benkreira, Paragraph 0038 "a machine learning model may be trained using a set of observations. The set of observations may be obtained and/or input from historical data, such as data gathered during one or more processes described herein” where "a device may include one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to:…provide the device information and the behavior information as a feature set that is input to a machine learning model” (Benkreira, Paragraph 0003) wherein the “processes” correspond to training sessions and the “observations” correspond to the mouse dynamics.). Regarding Claim 8, Benkreira teaches A computer-implemented method for classifying mouse dynamics data of a session using a trained classification model and providing a decision regarding legitimacy of the session, comprising (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025) where “the system (e.g., using computing resource 414 processor 520, memory 530, storage component 540, input component 550, output component 560, communication interface 570, and or the like) may transit an indication of a recommended action to be performed by the server device with respect to the application form and the client device based on the fraud score, as described above”.): Receiving… mouse dynamics data of the session to be analyzed (Benkreira Fig. 6, 620, Receive, from the server device, behavior information that indicates user behavior associated with inputting data into the application form using the client device wherein “the behavior information may indicate at least one of:…mouse dynamics used to input the data into the one or more fields or to navigate between fields of the application form, a technique used to navigate between fields of the application form, a technique used to scroll between different portions of the application form on the client device.” (Benkreira, page 22, paragraph 0087)), Via a processor (Benkreira, page 21, paragraph 0078, “Device 500 may perform one or more processes described herein. Device 500 may perform these processes based on processor 520 executing software instructions stored by a non-transitory computer readable medium, such as memory 530 and/or storage component 540.”) Grouping… the mouse dynamics data into a plurality of groups (Benkreira, page 19, paragraph 0055, “the trained machine learning model may classify (e.g. cluster) the new observation in a cluster [group] as shown by reference number 320” wherein “the set of observations may include data gathered from user interacting with and/or user input” (Benkreira, page 16, paragraph 0038)), separately extracting…, for each of the plurality of… categories, a distinct set of mouse dynamics, (Benkreira, Paragraph 0039, "As shown by reference number 210, a feature set may be derived from the set of observations. The feature set may include a set of variable types. A variable type may be referred to as a feature….In some implementations, the machine learning system may determine features (e.g., variables types) for a feature set based on input received from a server device, such as by extracting or generating a name for a column… and/or the like" where “For example, the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) wherein the features are clustered (Benkreira page 19, paragraph 0055), then the features are extracted from each cluster for each feature set. Examiner further notes that the observations are the mouse dynamics.). inputting… the mouse dynamics features into the trained classification model, wherein the trained classification is configured to operate on the mouse dynamics features of each of the plurality of …categories (Benkreira, Paragraph 0003, "provide the device information and the behavior information as a feature set that is input to a machine learning model”); Receiving… an output score from the trained classification model (Benkreira, Paragraph 0003, “receive output from the machine learning model”), wherein the output score represents a legitimacy of the session (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315.”where “the fraud platform may determine a fraud score based on the device information and the behavior information. A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score.); specifying… using a policy, the decision regarding legitimacy based on the output score of the session and whether the output score exceeds a threshold wherein the decision is a classification of the session as legitimate, not legitimate or an outlier (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation, such as to send another authentication challenge to verify identity. Additionally, or alternatively, the machine learning system may perform an automated action and/or may cause an automated action to be performed (e.g., by instructing another device to perform the automated action) such as to send a more difficult authentication challenge” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score. Examiner further notes that by exceeding the threshold, the fraud score is classified as having a high likelihood of fraud. Examiner notes that classifying as not legitimate is having a likelihood of fraud.). responsive to the decision indicating the session is not legitimate, automatically initiating at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically blocking the session and automatically inspecting the session (Benkreira, page 15, paragraph 0028, "Recommended actions may include approving an application associated with the application form, rejecting the application associated with the application form, requesting additional information from the client device, sending an authentication challenge ( e.g., a knowledge-based authentication (KBA) question, a video review action, a biometric step-up action, and/or the like), and/or the like. The recommended action may be used to obtain additional information on whether to authenticate the user and/or gain more information on whether the transaction is fraudulent" where " the client device may transmit, to an operator device, the video review based on the unsuccessful completion of the KBA challenge. The operator device may determine whether the video review is sufficient to authenticate the user and/or accept the application" (Benkreira, page 16, paragraph 0035) and "Operator device 440 includes one or more devices capable of receiving, generating, storing, processing, and/or providing information, such as information described herein. For example, operator device 440 may include a laptop computer, a tablet computer, a desktop computer, a server device, a group of server devices, or a similar type of device, associated with a merchant, a financial institution, and/or the like. In some implementations, operator device 440 may receive information from and/or transmit information to server device 430 and/or fraud platform 410" (Benkreira, page 20, paragraph 0070). Examiner notes that rejecting the application is automatically blocking the session. Examiner further notes that sending an authentication challenge and/or the like is automatically inspecting the session.) Benkreira does not teach, but Smith does teach processing… the mouse dynamics data by partitioning a website corresponding to the plurality of uniform resource locators (URLs) into a plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to aa plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); mapping… each URL visited in the session to at least one URL category of the plurality of URL categories in order to generate a URL category mapping (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes mapping each URL visited in the session to at least one URL category is clustering the transactions into similarity groups. Examiner further notes that the clusters are the URL categories and the category mapping is the SOM.); grouping… the…data into a plurality of groups using the URL category mapping, wherein each of the plurality of groups relates to one of the at least one URL category (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph).Examiner notes that the SOM is being considered as a category mapping) the plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to a plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); wherein the mouse dynamics features contain information about how a user interacts with each of the plurality of URL categories (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns. The K-means algorithm is outlined in Fig. 2. Within each processed transaction group, we use the column totals as the activity of the transaction group. This is illustrated in Table 2, where the cluster depicted contains 2679 transactions, including transaction numbers 5, 6, and 8012. Instead of having transactions as features, we now have transaction groups as features. The URLs are now described by the relative interests or activities of each of the transaction groups.” (Smith, page 250, 2nd -3rd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph). Examiner notes that the transaction groups are features.); Benkreira and Smith are considered analogous because they are in the same field of machine learning where they both collect and organize data to be trained. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira to use a URL category mapping to group the behavior data. Doing so would “successfully reduce[] the number of dimensions of the data” (Smith, page 250, paragraph 6) and “add more value to information retriev[ed]” (Smith, page 246, fifth paragraph). Benkreira and Smith do not teach, but Kilic does teach Wherein the mouse dynamics data comprises, for each of a plurality of uniform resource locators (URLs) that are visited, an action identifier, a timestamp, an x-coordinate and a y-coordinate (Kilic, page 2, last 3 paragraphs, “This dataset includes mouse behavior data which is collected from 24 different participants….Collected data has 7 columns: action type, timestamp, mouse cursor X location, mouse cursor Y location, clicked button (None if it is not a click), click state (Move, Pressed or Released) and foremost application window name respectively. Dataset columns are listed with detailed descriptions in Table 1. For all users, browsing (Google Chrome, Mozilla Firefox, Safari, etc.) is the most time spent action by far with 51 percent. Development applications (VMWare, Docker, PyCharm, etc.) are second with 19 percent, Office applications (MS Word, MS Excel, LibreOffice, etc.) are third with 17 percent, filesystem applications (System Preferences, OS programs, setup files, etc.) are fourth by 11 percent, and finally, entertainment applications (Spotify, Discord, video games, etc.) are fifth by 2 percent.” Examiner notes that the action identifier is the action type and the plurality of URLs are the browsers and applications used.) Benkreira, Smith, and Kilic are considered analogous because they are in the same field of mouse, behavior, and user data where they collect and organize data to be trained on. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith to use an action identifier, X coordinate, Y coordinate, and time stamp in the mouse dynamics data. Doing so would be advantageous because “this dataset is highly suitable for testing the under-development procedures against the insider threat, remote unauthorised access, and physical access” (Kilic, abstract). Regarding Claim 10, Benkreira in view of Smith and Kilic teaches the computer-implemented method of claim 8 (and thus the rejection of claim 8 is incorporated). Benkreira further teaches further comprising training a classification model to generate the trained classification model (Benkreira, page 16, paragraph 0037, “FIG. 2 is a diagram illustrating an example 200 of training a machine learning model. The machine learning model described herein may be performed using a machine learning system”) receiving…mouse dynamics data for a plurality of sessions (Benkreira Fig. 6, 620, Receive, from the server device, behavior information that indicates user behavior associated with inputting data into the application form using the client device wherein “the behavior information may indicate at least one of:…mouse dynamics used to input the data into the one or more fields or to navigate between fields of the application form, a technique used to navigate between fields of the application form, a technique used to scroll between different portions of the application form on the client device.” (Benkreira, page 22, paragraph 0087) and “process [session] 600 may include additional implementations, such as any single implementation or any combination of implementations described below and/or in connection with one or more other processes [sessions] described elsewhere herein” (Benkreira, page 22, paragraph 0086)) merging, via the processor, all of the mouse dynamics features (Benkreira, page 16, paragraph 0040, "the machine learning system may pre-process and/or perform dimensionality reduction to reduce the feature set and/or combine features of the feature set to a minimum feature set” wherein “as shown by reference number 210, a feature set may be derived from the set of observations [clusters]”(Benkreira, page 16, paragraph 0038) where “For example, the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) and there are multiple clusters (Benkreira, Fig 3, 320).), and training, via the processor, the classification model based on the merged groups of mouse dynamics features (Benkreira, page 16, paragraph 0040 "a machine learning model may be trained on the minimum feature set" where “For example, the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040)). Benkreira does not teach, but Smith does teach receiving…the URL category mapping (Smith, page 249, second paragraph, "we want to map the web documents into a two-dimensional space, where the locations will indicate the similarity between documents, as indicated by the navigation patterns"). Benkreira and Smith are considered analogous because they are in the same field of machine learning where they both collect and organize data to be trained. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira to use a URL category mapping to group the behavior data. Doing so would “successfully reduce[] the number of dimensions of the data” (Smith, page 250, paragraph 6) and “add more value to information retriev[ed]” (Smith, page 246, fifth paragraph). Regarding Claim 11, Benkreira in view of Smith and Kilic teaches the computer-implemented method of claim 8 (and thus the rejection of claim 8 is incorporated). Benkreira further teaches receiving…mouse dynamics data for a plurality of sessions (Benkreira Fig. 6, 620, Receive, from the server device, behavior information that indicates user behavior associated with inputting data into the application form using the client device wherein “the behavior information may indicate at least one of:…mouse dynamics used to input the data into the one or more fields or to navigate between fields of the application form, a technique used to navigate between fields of the application form, a technique used to scroll between different portions of the application form on the client device.” (Benkreira, page 22, paragraph 0087) and “process [session] 600 may include additional implementations, such as any single implementation or any combination of implementations described below and/or in connection with one or more other processes [sessions] described elsewhere herein” (Benkreira, page 22, paragraph 0086)) and training, via the processor, a machine learning model for each of the mouse dynamics features (Benkreira page 18, paragraph 0048, “In some implementations, the machine learning system may independently train the machine learning model k times, with each individual group being used as a hold-out group once and being used as a training group k-1 times” wherein “observations in the training set 220 may be split into k groups (e.g., in order or at random)” (Benkreira page 18, paragraph 0048) where "a device may include one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to:…provide the device information and the behavior information as a feature set that is input to a machine learning model” (Benkreira, Paragraph 0003) and “the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) ), wherein the trained classification model comprises an ensemble of the trained machine learning models (Benkreira, page 17, paragraph 0047, "the machine learning system may train multiple machine learning model to generate a set of model parameters for each machine learning model, where each machine learning model corresponds to a different combination of a machine learning algorithm and a hyperparameter set 240 for that machine learning algorithm"). Regarding Claim 15, Benkreira teaches A computer program product for classifying mouse dynamics data of a session using a trained classification model and providing a decision regarding legitimacy of the session, the computer program product comprising a computer-readable storage medium having program code embodied therewith, wherein the computer-readable storage medium is not a transitory signal per se, the program code executable by a processor (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025) where “the system (e.g., using computing resource 414 processor 520, memory 530, storage component 540, input component 550, output component 560, communication interface 570, and or the like) may transit an indication of a recommended action to be performed by the server device with respect to the application form and the client device based on the fraud score, as described above” where “Device 500 may perform one or more processes described herein. Device 500 may perform these processes based on processor 520 executing software instructions stored by a non-transitory computer-readable medium, such as memory 530 and/or storage component 540” (Benkreira, page 21, paragraph 0078).) receive mouse dynamics data of the session to be analyzed (Benkreira Fig. 6, 620, Receive, from the server device, behavior information that indicates user behavior associated with inputting data into the application form using the client device wherein “the behavior information may indicate at least one of:…mouse dynamics used to input the data into the one or more fields or to navigate between fields of the application form, a technique used to navigate between fields of the application form, a technique used to scroll between different portions of the application form on the client device.” (Benkreira, page 22, paragraph 0087)), group the mouse dynamics data into a plurality of groups (Benkreira, page 19, paragraph 0055, “the trained machine learning model may classify (e.g. cluster) the new observation in a cluster [group] as shown by reference number 320” wherein “the set of observations may include data gathered from user interacting with and/or user input” (Benkreira, page 16, paragraph 0038)), separately extract, for each of the plurality of… categories, a distinct set of mouse dynamics, (Benkreira, Paragraph 0039, "As shown by reference number 210, a feature set may be derived from the set of observations. The feature set may include a set of variable types. A variable type may be referred to as a feature….In some implementations, the machine learning system may determine features (e.g., variables types) for a feature set based on input received from a server device, such as by extracting or generating a name for a column… and/or the like" where “For example, the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) wherein the features are clustered (Benkreira page 19, paragraph 0055), then the features are extracted from each cluster for each feature set. Examiner further notes that the observations are the mouse dynamics.). input the mouse dynamics features into the trained classification model, wherein the trained classification is configured to operate on the mouse dynamics features of each of the plurality of …categories (Benkreira, Paragraph 0003, "provide the device information and the behavior information as a feature set that is input to a machine learning model”);receive an output score from the trained classification model (Benkreira, Paragraph 0003, “receive output from the machine learning model”), wherein the output score represents a legitimacy of the session (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315.”where “the fraud platform may determine a fraud score based on the device information and the behavior information. A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score.); specify, using a policy, the decision regarding legitimacy based on the output score of the session and whether the output score exceeds a threshold wherein the decision is a classification of the session as legitimate, not legitimate or an outlier (Benkreira, page 19, paragraph 0054, “the trained machine learning model 305 may predict a value of 90 for the target variable of “fraud score” for the new observation, as shown by reference number 315. Based on this prediction (e.g., based on the value having a particular label/classification, based on the value satisfying or failing to satisfy a threshold, and/or the like), the machine learning system may provide a recommendation, such as to send another authentication challenge to verify identity. Additionally, or alternatively, the machine learning system may perform an automated action and/or may cause an automated action to be performed (e.g., by instructing another device to perform the automated action) such as to send a more difficult authentication challenge” where “A fraud score may indicate a likelihood that the user who is associated with the behavior information or the device information is committing fraud (e.g., a high fraud score indicates a high likelihood of fraud, a low fraud score indicates a low likelihood of fraud, and/or the like)”( Benkreira, page 14, paragraph 0025). Examiner notes that the fraud score is the output score. Examiner further notes that by exceeding the threshold, the fraud score is classified as having a high likelihood of fraud. Examiner notes that classifying as not legitimate is having a likelihood of fraud.). responsive to the decision indicating the session is not legitimate, automatically initiating at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically blocking the session and automatically inspecting the session (Benkreira, page 15, paragraph 0028, "Recommended actions may include approving an application associated with the application form, rejecting the application associated with the application form, requesting additional information from the client device, sending an authentication challenge ( e.g., a knowledge-based authentication (KBA) question, a video review action, a biometric step-up action, and/or the like), and/or the like. The recommended action may be used to obtain additional information on whether to authenticate the user and/or gain more information on whether the transaction is fraudulent" where " the client device may transmit, to an operator device, the video review based on the unsuccessful completion of the KBA challenge. The operator device may determine whether the video review is sufficient to authenticate the user and/or accept the application" (Benkreira, page 16, paragraph 0035) and "Operator device 440 includes one or more devices capable of receiving, generating, storing, processing, and/or providing information, such as information described herein. For example, operator device 440 may include a laptop computer, a tablet computer, a desktop computer, a server device, a group of server devices, or a similar type of device, associated with a merchant, a financial institution, and/or the like. In some implementations, operator device 440 may receive information from and/or transmit information to server device 430 and/or fraud platform 410" (Benkreira, page 20, paragraph 0070). Examiner notes that rejecting the application is automatically blocking the session. Examiner further notes that sending an authentication challenge and/or the like is automatically inspecting the session.) Benkreira does not teach, but Smith does teach process the mouse dynamics data by partitioning a website corresponding to the plurality of uniform resource locators (URLs) into a plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to aa plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); map each URL visited in the session to at least one URL category of the plurality of URL categories in order to generate a URL category mapping (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes mapping each URL visited in the session to at least one URL category is clustering the transactions into similarity groups. Examiner further notes that the clusters are the URL categories and the category mapping is the SOM.); group the…data into a plurality of groups using the URL category mapping, wherein each of the plurality of groups relates to one of the at least one URL category (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph).Examiner notes that the SOM is being considered as a category mapping) the plurality of URL categories (Smith, page 246, last paragraph – page 247 first paragraph, “in this paper we present LOGSOM, a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns rather than according to the web content [4, 5, 8]. Instead of organizing the web-pages according to the words contained in the webpages, we keep track of the interest of the web-users, and organize the web-pages according to their interest” where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns” (Smith, page 250, 2nd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph) and where “As the web users visit the Business Systems website http://www.bs.monash.edu.au – including all of its linked web pages), they leave some footprints behind. Like many other servers, that of Business Systems saves the footprints as web server logs, which we have reformatted as shown in Fig. 1” (Smith, page 247, 2nd column, 2nd paragraph). Examiner notes that the mouse dynamics data is the user navigation patterns. The website corresponding to a plurality of URLs is the Business Systems website with linked web pages. Examiner further notes that the URL categories are the clusters based on the transactions of users.); wherein the mouse dynamics features contain information about how a user interacts with each of the plurality of URL categories (Smith, page 246, last paragraph, "a prototype system that organizes web pages on a self-organizing map (SOM) according to user navigation patterns" where “By using the K-means cluster algorithm [3], we cluster the transactions into nine groups. The number K=9 is chosen arbitrarily. In fact, we can choose any number as long as it is small enough for the data to carry sufficient information to produce a meaningful outcome. In our experiment, each 235-dimensional binary transaction vector is treated as an input vector and clustered into K=9 groups. These are essentially similarity groups, that is collections of transactions that involve similar web page access patterns. The K-means algorithm is outlined in Fig. 2. Within each processed transaction group, we use the column totals as the activity of the transaction group. This is illustrated in Table 2, where the cluster depicted contains 2679 transactions, including transaction numbers 5, 6, and 8012. Instead of having transactions as features, we now have transaction groups as features. The URLs are now described by the relative interests or activities of each of the transaction groups.” (Smith, page 250, 2nd -3rd paragraph) and “we define a transaction as a set of web pages requested by a user in a particular session (Smith, page 247, last paragraph). Examiner notes that the transaction groups are features.); Benkreira and Smith are considered analogous because they are in the same field of machine learning where they both collect and organize data to be trained. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira to use a URL category mapping to group the behavior data. Doing so would “successfully reduce[] the number of dimensions of the data” (Smith, page 250, paragraph 6) and “add more value to information retriev[ed]” (Smith, page 246, fifth paragraph). Benkreira and Smith do not teach, but Kilic does teach Wherein the mouse dynamics data comprises, for each of a plurality of uniform resource locators (URLs) that are visited, an action identifier, a timestamp, an x-coordinate and a y-coordinate (Kilic, page 2, last 3 paragraphs, “This dataset includes mouse behavior data which is collected from 24 different participants….Collected data has 7 columns: action type, timestamp, mouse cursor X location, mouse cursor Y location, clicked button (None if it is not a click), click state (Move, Pressed or Released) and foremost application window name respectively. Dataset columns are listed with detailed descriptions in Table 1. For all users, browsing (Google Chrome, Mozilla Firefox, Safari, etc.) is the most time spent action by far with 51 percent. Development applications (VMWare, Docker, PyCharm, etc.) are second with 19 percent, Office applications (MS Word, MS Excel, LibreOffice, etc.) are third with 17 percent, filesystem applications (System Preferences, OS programs, setup files, etc.) are fourth by 11 percent, and finally, entertainment applications (Spotify, Discord, video games, etc.) are fifth by 2 percent.” Examiner notes that the action identifier is the action type and the plurality of URLs are the browsers and applications used.) Benkreira, Smith, and Kilic are considered analogous because they are in the same field of mouse, behavior, and user data where they collect and organize data to be trained on. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith to use an action identifier, X coordinate, Y coordinate, and time stamp in the mouse dynamics data. Doing so would be advantageous because “this dataset is highly suitable for testing the under-development procedures against the insider threat, remote unauthorised access, and physical access” (Kilic, abstract). Claim 17 recites the computer program product of claim 15 (and thus the rejection of claim 15 is incorporated). Benkreira further teaches train a classification model based on the merged groups of mouse dynamics feature (Benkreira, page 16, paragraph 0040 "a machine learning model may be trained on the minimum feature set" wherein “as shown by reference number 210, a feature set may be derived from the set of observations [clusters]”(Benkreira, page 16, paragraph 0038) and “the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) and there are multiple clusters (Benkreira, Fig 3, 320).)). Regarding Claim 18, Benkreira in view of Smith and Kilic teaches the computer program product of claim 15 (and thus the rejection of claim 15 is incorporated). Benkreira further teaches train a classification model based on a machine learning model (Benkreira, page 16, paragraph 0037, “FIG. 2 is a diagram illustrating an example 200 of training a machine learning model. The machine learning model described herein may be performed using a machine learning system”) for each of the plurality of groups of features (Benkreira page 18, paragraph 0048, “In some implementations, the machine learning system may independently train the machine learning model k times, with each individual group being used as a hold-out group once and being used as a training group k-1 times” wherein “observations in the training set 220 may be split into k groups (e.g., in order or at random)” (Benkreira page 18, paragraph 0048) where "a device may include one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to:…provide the device information and the behavior information as a feature set that is input to a machine learning model” (Benkreira, Paragraph 0003) and “the feature set may include one or more of the following features: …mouse dynamics used to input data into one or more fields or to navigate between field of the application form” (Benkreira, page 16, paragraph 0040) ) wherein the classification model comprises an ensemble classifier (page 17, paragraph 0046, "the machine learning algorithm may include a decision tree algorithm, which may include a tree ensemble algorithm (e.g., generated using bagging and/or boosting)). Claim 4, 6-7, 12-13, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Benkreira in view of Smith and Kilic as applied to claims 1-3, 8, 10-11, 15, and 17-18 above, and further in view of Morichetta et al. (Morichetta), "CLUE: Clustering for Mining Web URLs." Regarding Claim 4, Benkreira in view of Smith and Kilic teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira in view of Smith does not teach, but Morichetta does teach, wherein the URL category mapping comprises the plurality of URLs, wherein the plurality of URLs are mapped to a unique URL category (Morichetta, page 286, paragraph 5, "URLs are grouped into well-separated and cohesive clusters" wherein “clusters clearly pinpoint specific services [categories]” (Morichetta, page 293, TABLE V)). Benkreira in view of Smith, Kilic, and Morichetta are considered analogous because both relate to grouping behavior information via machine learning. Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith and Kilic to incorporate the teachings of Morichetta and group the URLs into separate and unique groups. Doing so would “strengthen[] the potential to support the mining of URLs and of web traffic with applications to security and privacy protection fields” (Morichetta, page 287, first paragraph). Regarding Claim 6, Benkreira in view of Smith teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira in view of Smith and Kilic does not teach, but Morichetta further teaches wherein the URL category mapping is automatically generated (Morichetta, page 286, col 2, second paragraph, “we focus on the problem of automatically analyzing web traffic leveraging URLs. We design an unsupervised methodology that groups URLs in clusters according to a similarity metric”) based on data collected from an application (Morichetta, page 290, col 2, first paragraph “We let Tstat collect URLs for an entire day, generating more than 100GB of data”). Benkreira in view of Smith, Kilic and Morichetta are analogous because they are in the same field of machine learning where they both collect and organize URLs in clusters. It would have been obvious to one of ordinary skill in the art before the effective filing data of the claimed invention to have modified Benkreira in view of Smith and Kilic to automatically generate the URL category mapping based on the mouse data collected. Doing so would “avoid the overhead introduced by web crawling techniques” (Morichetta, page 286, col 2, third paragraph). Regarding Claim 7, Benkreira in view of Smith and Kilic teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira in view of Smith further teaches using a machine learning clustering on the mouse dynamics data corresponding to a plurality of sessions of various users of an application (Benkreira, Paragraph 0043 "the machine learning model may learn patterns from the set of observations without labeling or supervision, and may provide output that indicates such patterns such as by using clustering and/or association to identify related groups of items within the set of observations" wherein “the set of observations may be obtained and/or input from historical data, such as data gathered during one or more processes [sessions]” (Benkreira, page 16, paragraph 0038)). Benkreira in view of Smith and Kilic does not teach, but Morichetta does teach wherein the URL category mapping is automatically generated using a machine learning clustering (Morichetta, page 286, col 2, second paragraph, “we focus on the problem of automatically analyzing web traffic leveraging URLs. We design an unsupervised methodology that groups URLs in clusters according to a similarity metric”). Benkreira in view of Smith, Kilic and Morichetta are analogous because they are in the same field of machine learning where they both collect and organize URLs in clusters, It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith and Kilic to automatically generate the URL category mapping based on the mouse data collected. Doing so would “avoid the overhead introduced by web crawling techniques” (Morichetta, page 286, col 2, third paragraph). Regarding Claim 12, claim 12 recites substantially similar limitations to claim 6, and is therefore rejected under the same analysis. Regarding Claim 13, claim 13 recites substantially similar limitations to claim 7, and is therefore rejected under the same analysis Regarding Claim 19, claim 19 recites substantially similar limitations to claim 6, and is therefore rejected under the same analysis. Regarding Claim 20, claim 20 recites substantially similar limitations to claim 7, and is therefore rejected under the same analysis. Regarding Claim 24, Benkreira in view of Smith and Kilic teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira in view of Smith further teaches applying a clustering model… derived from the mouse dynamics data collected from a plurality of sessions (Benkreira, Paragraph 0043 "the machine learning model may learn patterns from the set of observations without labeling or supervision, and may provide output that indicates such patterns such as by using clustering and/or association to identify related groups of items within the set of observations" wherein “the set of observations may be obtained and/or input from historical data, such as data gathered during one or more processes [sessions]” (Benkreira, page 16, paragraph 0038)). Benkreira in view of Smith and Kilic does not teach, but Morichetta does teach wherein the generating the URL category mapping comprises applying a clustering model to characteristics of URLs (Morichetta, page 286, col 2, second paragraph, “we focus on the problem of automatically analyzing web traffic leveraging URLs. We design an unsupervised methodology that groups URLs in clusters according to a similarity metric”). Benkreira in view of Smith, Kilic and Morichetta are analogous because they are in the same field of machine learning where they both collect and organize URLs in clusters, It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Benkreira in view of Smith and Kilic to automatically generate the URL category mapping based on the mouse data collected. Doing so would “avoid the overhead introduced by web crawling techniques” (Morichetta, page 286, col 2, third paragraph). Regarding Claim 25, claim 25 recites substantially similar limitations to claim 24, and is therefore rejected under the same analysis. Regarding Claim 26, claim 26 recites substantially similar limitations to claim 24, and is therefore rejected under the same analysis Claims 5 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Benkreira in view of Smith and Kilic as applied to claims 1, 3, 8, 10-11, 15, and 17-18 above, and further in view of Luo et al. (Luo) (US 2020/0034752 A1) Regarding Claim 5, Benkreira in view of Smith and Kilic teaches the system of claim 1 (and thus the rejection of claim 1 is incorporated). Benkreira in view of Smith does not teach, but Luo does teach wherein the URL category mapping comprises a predetermined mapping (Luo, page 30, paragraph 0111, “Email classifier 114 classifies emails, such as the email 104 shown in FIG. 1, into one or more of a number of predetermined categories such as good, spam, bulk, phishing, or malware” where “initial labels may come from …URLs” (Luo, page 21, paragraph 0005)). Benkreira in view of Smith, Kilic and Luo are analogous because they are in the same field of machine learning where they both collect and organize data into clusters. It would have been obvious to one having ordinary skill in the art prior to the effective filing date of the claimed invention to have modified Benkreira in view of Smith and Kilic to use a predetermined mapping. Doing so would “creat[e] a labeled, training dataset…without use of confidential information or PII” (Luo, page 21, paragraph 0004). Regarding Claim 14, Benkreira in view of Smith and Kilic teaches the computer-implemented method of claim 8 (and thus the rejection of claim 8 is incorporated). Benkreira further teaches a threshold used to generate a decision (Benkreira, page 22, paragraph 0091, “process 600 may include determining that the fraud score satisfies a threshold, and where the recommended action may include a video review action, that requires submission of a video before a completed application form can be submitted to the server device, based on determining that the fraud score satisfies the threshold”). Benkreira in view of Smith and Kilic does not teach, but Luo does teach adjusting …during a training phase of the trained classification model (page 30, paragraph 0112, “The email classifier uses a MLM to identify a classification… the current model is run with the training dataset 118 and produces a result which is then compared with the target, for each input vector in the training dataset 118. Based on the result of the comparison and the specific learning technology being used, the parameters of the MLM are adjusted”). generate a decision by finding a limit on the false positive rate (page 27, paragraph 0080, “the confidence degrading ratio [false positive rate] of clustering edges (dotted lines) may decrease confidence by half by applying a confidence degrading ratio of 0.5 [finding a limit]. Thus, if the email 904 is labeled with 100% confidence that it is a “good” email, then the clustering edge 924 reduces that confidence level by half [generate a decision]” wherein “the edges represent inference logic that is specific to the category label (“good”) of the expansion graph 900. Thus, for the label “good” if the fingerprint 906 of the email 904 is known to be good then the email itself may be inferred to be a good email based on the edge… However, just because an email includes a good URL 910 that does not necessarily indicate the email itself is good… spam and bulk email may include URLs that are identified as good [spam and bulk emails are falsely labeled as good making the confidence degrading ratio degrade due to false positives]” (Luo, page 26, paragraph 0077)). Benkreira in view of Smith, Kilic and Luo are analogous because they are in the same field of machine learning where they both collect and organize data into clusters. It would have been obvious to one having ordinary skill in the art prior to the effective filing date of the claimed invention to have modified Benkreira in view of Smith and Kilic to fine-tune a threshold by finding a limit on a false positive rate. Doing so would “save network resources such as bandwidth, storage, and processor cycles.” (Luo, page 23, paragraph 0046). Response to Arguments Applicant’s arguments with respect to 101 on pages 9-13 and in light of the instant amendments have been fully considered and are persuasive. Specifically, the argument on pages 11-12 regarding the specific implementation shown in paragraph 0015 in light of the amendments as well as how the invention is integrated into a practical application was persuasive. The 101 rejections of the claims have been withdrawn. Examiner notes that the claims reflect the specific implementation and practical application specifically with the newly amended limitations of “wherein the mouse dynamics data comprises, for each of a plurality of uniform resource locators (URLs) that are visited, an action identifier, a timestamp, an x-coordinate and a y-coordinate” and “responsive to the decision indicating the session is not legitimate, automatically initiate at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically block the session and automatically inspect the session” in light of the claim as a whole. On page 14, Applicant argues: Applicant respectfully submits the features added to claim 1 by amendment have not been addressed by the Office Action and that Benkreira and Smith do not together teach or suggest the added features. Thus, Applicant asserts that amended claim 1 is allowable and respectfully requests that the 3 5 USC § 103 rejection of claim 1 be withdrawn. Regarding the Applicant’s argument that the features added to claim 1 are not taught by Benkreira and Smith, the Examiner respectfully disagrees. Specifically, a combination of Benkreira, Smith and Kilic teach all of claim 1. Benkreira, Smith, and Kilic teach the newly amended limitations of: Wherein the mouse dynamics data comprises, for each of a plurality of uniform resource locators (URLs) that are visited, an action identifier, a timestamp, an x-coordinate and a y-coordinate (Kilic, page 2, last 3 paragraphs, “This dataset includes mouse behavior data which is collected from 24 different participants….Collected data has 7 columns: action type, timestamp, mouse cursor X location, mouse cursor Y location, clicked button (None if it is not a click), click state (Move, Pressed or Released) and foremost application window name respectively. Dataset columns are listed with detailed descriptions in Table 1. For all users, browsing (Google Chrome, Mozilla Firefox, Safari, etc.) is the most time spent action by far with 51 percent. Development applications (VMWare, Docker, PyCharm, etc.) are second with 19 percent, Office applications (MS Word, MS Excel, LibreOffice, etc.) are third with 17 percent, filesystem applications (System Preferences, OS programs, setup files, etc.) are fourth by 11 percent, and finally, entertainment applications (Spotify, Discord, video games, etc.) are fifth by 2 percent.” Examiner notes that the action identifier is the action type and the plurality of URLs are the browsers and applications used.) responsive to the decision indicating the session is not legitimate, automatically initiating at least one session-handling action specified by the policy, the session-handling action selected from a group consisting of automatically blocking the session and automatically inspecting the session (Benkreira, page 15, paragraph 0028, "Recommended actions may include approving an application associated with the application form, rejecting the application associated with the application form, requesting additional information from the client device, sending an authentication challenge ( e.g., a knowledge-based authentication (KBA) question, a video review action, a biometric step-up action, and/or the like), and/or the like. The recommended action may be used to obtain additional information on whether to authenticate the user and/or gain more information on whether the transaction is fraudulent" where " the client device may transmit, to an operator device, the video review based on the unsuccessful completion of the KBA challenge. The operator device may determine whether the video review is sufficient to authenticate the user and/or accept the application" (Benkreira, page 16, paragraph 0035) and "Operator device 440 includes one or more devices capable of receiving, generating, storing, processing, and/or providing information, such as information described herein. For example, operator device 440 may include a laptop computer, a tablet computer, a desktop computer, a server device, a group of server devices, or a similar type of device, associated with a merchant, a financial institution, and/or the like. In some implementations, operator device 440 may receive information from and/or transmit information to server device 430 and/or fraud platform 410" (Benkreira, page 20, paragraph 0070). Examiner notes that rejecting the application is automatically blocking the session. Examiner further notes that sending an authentication challenge and/or the like is automatically inspecting the session.) Therefore, the prior art teaches claim 1. Examiner further points the Applicant to the above 103 rejections. On page 13, Applicant argues: Claims 8 and 15 have been amended to include substantially similar features as amended claim 1. Therefore, Applicant respectfully submits that claims 8 and 15 are allowable for the same reasons that claim I is allowable and respectfully requests that the 35 USC§ 103 rejection of claims 8 and 15 be withdrawn. Because claims 3, 10-13 and 17-23 depend upon and incorporate the limitations of claims 1, 8, and 15, Applicant contends that claims 2-3, 10-13 and 17-23 are allowable for the same reasons that claims 1, 8, and 15 are allowable. Reconsideration and withdrawal of the rejection are respectfully requested. Regarding the Applicant’s argument that claims 8 and 15 overcome the prior art, the Examiner respectfully disagrees. Specifically, claims 8 and 15 recite substantially similar limitations to claim 1, and are therefore rejected under the same analysis. Regarding the Applicant’s argument that the dependent claims are allowable at least due in part to their dependency on the independent claims, the Examiner respectfully disagrees and notes the instant rejections and response to arguments regarding the independent claims above. On page 13, Applicant argues: Claims 4, 6 and 7 depend upon and incorporate the limitations of claim 1. Applicant contends that claims 4, 6 and 7 are allowable over Benkreira in view of Smith for the same reasons that claim 1 is allowable. Morichetta does not remedy the shortcomings of Benkreira and Smith, and claims 4, 6 and 7 are allowable over the combination of references. Reconsideration and withdrawal of the rejection are respectfully requested. Regarding the Applicant’s argument that the dependent claims are allowable at least due in part to their dependency on the independent claims, the Examiner respectfully disagrees and notes the instant rejections and response to arguments regarding the independent claims above. On page 14, Applicant argues: Claims 5 and 14 depend upon and incorporate the limitations of claim 1 or claim 8. Applicant contends that claims 5 and 14 are allowable over Benkreira in view of Smith for the same reasons that claims 1 and 8 are allowable. Luo does not remedy the shortcomings of Benkreira and Smith and claims 5 and 14 are allowable over the combination of references. Reconsideration and withdrawal of the rejection are respectfully requested. Regarding the Applicant’s argument that the dependent claims are allowable at least due in part to their dependency on the independent claims, the Examiner respectfully disagrees and notes the instant rejections and response to arguments regarding the independent claims above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Solano Burns et al. (US 8,341,724 B1) also performs further inspection on suspicious sessions and either blocks the confirmed suspicious sessions or sends the session to a security management module for further analysis (Burns et al., page 13, column 7, lines 23-46). The management module provides a user interface for a human to further inspect a session (Burns et al., page 14, column 9 line 65 – column 10, line 17) Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KAITLYN R LAU whose telephone number is (571)272-1429. The examiner can normally be reached Monday - Thursday: 8:00 am - 6:00 pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Michelle Bechtold can be reached on (571) 431-0762. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /K.R.L./ Examiner, Art Unit 2148 /MICHELLE T BECHTOLD/Supervisory Patent Examiner, Art Unit 2148
Read full office action

Prosecution Timeline

Show 21 earlier events
Apr 02, 2026
Request for Continued Examination
Apr 08, 2026
Response after Non-Final Action
Jun 05, 2026
Non-Final Rejection mailed — §103
Jun 09, 2026
Interview Requested
Jun 30, 2026
Examiner Interview Summary
Jun 30, 2026
Applicant Interview (Telephonic)
Jul 20, 2026
Response Filed
Sep 18, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688298
FEATURE SELECTION FOR CYBERSECURITY THREAT DISPOSITION
4y 7m to grant Granted Jul 21, 2026
Patent 12602431
METHODS FOR PERFORMING INPUT-OUTPUT OPERATIONS IN A STORAGE SYSTEM USING ARTIFICIAL INTELLIGENCE AND DEVICES THEREOF
3y 10m to grant Granted Apr 14, 2026
Patent 12572828
METHOD FOR INDUSTRY TEXT INCREMENT AND ELECTRONIC DEVICE
4y 5m to grant Granted Mar 10, 2026
Study what changed to get past this examiner. Based on 3 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
60%
Grant Probability
99%
With Interview (+66.7%)
3y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 10 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month