Prosecution Insights
Last updated: August 15, 2026
Application No. 17/805,629

SYSTEMS AND METHODS FOR DETECTING UNAUTHORIZED ONLINE TRANSACTIONS

Non-Final OA §101
Filed
Jun 06, 2022
Priority
May 23, 2022 — EU 22386031.3
Examiner
GAW, MARK H
Art Unit
3693
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Gen Digital Inc.
OA Round
7 (Non-Final)
50%
Grant Probability
Moderate
7-8
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 50% of resolved cases
50%
Career Allowance Rate
149 granted / 299 resolved
-2.2% vs TC avg
Strong +60% interview lift
Without
With
+59.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 6m
Avg Prosecution
37 currently pending
Career history
338
Total Applications
across all art units

Statute-Specific Performance

§101
51.2%
+11.2% vs TC avg
§103
27.6%
-12.4% vs TC avg
§102
5.9%
-34.1% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 299 resolved cases

Office Action

§101
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 2/5/26 has been entered. Status of Claims Claims 1-5, 7-14, and 16-20 are pending in this application. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-5, 7-14, and 16-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1-5, 7-14, and 16-20 are directed to a system, method, or product, which are/is one of the statutory categories of invention. (Step 1: YES). The Examiner has identified independent method claim 1 as the claim that represents the claimed invention for analysis and is similar to independent system claim 10 and product claim 17. Claim 1 recites the limitations of method of identifying unauthorized device by comparing reported transaction against tracked-online transaction and then updating a user’s preferences database for potential use in detecting deviation. These limitations, under their broadest reasonable interpretation, cover performance of the limitation as certain methods of organizing human activity. Collecting online financial activities (“network telemetry”) tracked by user’s device; identifying financial activities by detecting patterns of network requests (that occur after credit card information is inserted on a web) that are triggered by online financial activities; receiving financial activity report; filtering either recurring-transaction OR card-not-present transactions; correlating reported financial activity to online financial activity tracked by the device; creating correlation record; detecting uncorrelated activity to detect unauthorized device; and taking security related action (including automatically confirming fraud and taking preventative action prior to issuing an alert), – specifically, the claim recites “collecting network telemetry data corresponding to network traffic of one or more authorized devices including at least a first authorized device including a first telemetry tracker and a second authorized device including a second telemetry tracker, wherein the network telemetry data is collected from at least the first telemetry tracker and the second telemetry tracker; identifying, from the collected network telemetry data, one or more financial activities on the one or more authorized devices including requests that occur after credit card information is inserted on a web form to create patterns of network requests that are triggered by online financial activities; receiving data of one or more reported financial activities; filtering… from the one or more reported financial activities, at least one of automated recurring transactions or transactions that do not correspond to card-not-present transactions; correlating… the one or more reported financial activities to the identified one or more online financial activities using fuzzy matching between the one or more reported financial activities and the identified one or more online financial activities occurring in a similar time period, wherein the fuzzy matching relies on correlations between multiple users making similar transactions to detect common patterns; creating, in a data structure, correlation records based on the correlation; detecting… based on the correlation records in the data structure, uncorrelated activity of the one or more reported financial activities to detect an unauthorized device; identifying… based on the detecting, that at least one of the reported financial activities was initiated by the unauthorized device; and performing… in response to the identification, a security action for the at least one of the reported financial activities that was initiated by the unauthorized device, wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert”, recites a fundamental economic practice, directed to mitigating risk. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation as a fundamental economic practice or commercial or legal interactions, then it falls within the “Certain Methods of Organizing Human Activity” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. The “at least one processor”, “network telemetry”, “authorized devices”, “a first authorized device”, “a first telemetry tracker”, “a second authorized device”, “a second telemetry tracker”, “network telemetry data”, “a data structure”, “fuzzy matching”, and “unauthorized device”, in claim 1; the additional technical element of “system”, and “physical memory”, in claim 10; and the additional technical element of “non-transitory computer-readable medium” in claim 17, are just applying generic computer components to the recited abstract limitations. The recitation of generic computer components in a claim does not necessarily preclude that claim from reciting an abstract idea. Claims 10 and 17 are also abstract for similar reasons. (Step 2A-Prong 1: YES. The claims recite an abstract idea) This judicial exception is not integrated into a practical application. In particular, the claims recite the additional elements of: a computer such as at least one processor, authorized devices, unauthorized device, a first authorized device, a second authorized device, , and system; a storage unit such as physical memory, and non-transitory computer-readable medium; data and data types such as network telemetry data and a data structure; and software module and algorithm such as fuzzy matching, a first telemetry tracker, and a second telemetry tracker. The computer hardware/software is/are recited at a high-level of generality (i.e., as a generic processor performing a generic computer function) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, these additional elements, when considered separately and as an ordered combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea and are at a high level of generality. Therefore, claims 1, 10 and 17 are directed to an abstract idea without a practical application. (Step 2A-Prong 2: NO. The additional claimed elements are not integrated into a practical application) The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when considered separately and as an ordered combination, they do not add significantly more (also known as an “inventive concept”) to the exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a computer hardware amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Accordingly, these additional elements, do not change the outcome of the analysis, when considered separately and as an ordered combination. Thus, claims 1, 10 and 17 are not patent eligible. (Step 2B: NO. The claims do not provide significantly more) Dependent claims further define the abstract idea that is present in their respective independent claims 1, 10 and 17 and thus correspond to Certain Methods of Organizing Human Activity and hence are abstract for the reasons presented above. Dependent claims 2, 11, and 18 disclose that one or more card-not-present financial transactions of an account and the one or more online financial activities correspond to one or more web-based financial transactions tracked in network telemetry on at least one of the one or more of the authorized devices that are authorized to perform online purchases using the account, which explains a process and description at a high level – both are abstract ideas. Dependent claims 3, 12, and 19 disclose that reported financial activities correspond to one or more new accounts appearing on a credit report of a user and the one or more online financial activities correspond to one or more account opening activities tracked in network telemetry on at least one of the one or more authorized devices that are authorized to open new accounts on behalf of the user, which explains a process and description at a high level – both are abstract ideas. Dependent claims 4 and 13 disclose that tracking the one or more online financial activities on at least one of the authorized devices that is authorized to perform the online financial activities, which is a description/explanation of the process at a high level and an abstract idea. Dependent claims 5 and 14 disclose that identifying the one or more reported financial activities, which is a description/explanation of the process at a high level and an abstract idea. Dependent claim 20 discloses that filtering, from the one or more reported financial activities, at least one of automated recurring transactions or transactions that do not correspond to card-not-present transactions, which is a description/explanation of the process at a high level and an abstract idea. Dependent claims 7 and 16 disclose that performing the security action includes issuing an alert after taking the preventative action, which is a description/explanation of the process at a high level and an abstract idea. Dependent claim 8 discloses that issuing the alert includes at least one of generating an alert in response to the identifying or issuing a potential fraud alert generated based on a fraud detection analysis of the one or more reported financial activities, which is a description/explanation of the process at a high level and an abstract idea. Dependent claim 9 discloses that taking the preventative action includes at least one of placing a hold on an account or performing an automated credit freeze, which is a description/explanation of the process at a high level and an abstract idea. Thus, the dependent claims do not include any additional elements that integrate the abstract idea into a practical application or are sufficient to amount to significantly more than the judicial exception when considered both individually and as an ordered combination. Therefore, the dependent claims are directed to an abstract idea. Thus, the claims 1-5, 7-14, and 16-20 are not patent-eligible. Response to Arguments Applicant's arguments filed 2/5/26 have been fully considered but they are not persuasive. In response to applicant's argument that: “35 U.S.C. § 101… Applicant has amended each independent claim to clarify a technical solution to a technical problem, tying the claims to elements that achieve certain technical benefits, as outlined in the as-filed specification,” the examiner respectfully disagrees. In comparison to the prior version, the added elements (see underlined) and deleted elements (if any, struck out with a line) are essentially: (1) “identifying, from the collected network telemetry data, one or more financial activities on the one or more authorized devices including requests that occur after credit card information is inserted on a web form to create ”; and (2) “wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert”. These changes are not sufficient to overcome the 35 U.S.C. § 101 rejections because: for 101 analysis purpose, this is just stating (corresponding to the numberings above): an explanation of what data can include (i.e., those occur after credit card is inserted on a web form), this is just data definition – an abstract idea; and an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea. These are abstract ideas. There is nothing technical about it. In response to applicant's argument that: “The amended claims also recite identifying financial activities by detecting requests that occur after credit card information is inserted on a web form, and creating patterns that enable purchase detection even when telemetry is collected without browser-extension visibility. This provides a specific improvement in how the system recognizes transactions in network traffic,” the examiner respectfully disagrees. Gathering information after credit card information is inserted on a web form is a business idea. This is not technological innovation. It is not patentable. In response to applicant's argument that: “The claims further recite targeted filtering to enable telemetry correlation, including filtering automated recurring transactions and transactions that do not correspond to card-not present transactions… the claims recite fuzzy matching that relies on correlations to detect common patterns, which can eliminate spurious correlations,” the examiner respectfully disagrees. This is just data processing according to a business goals. As stated in the prior office action (regarding the filtering process): “This is a business process (removing recurring transactions and card-not-present transactions) carried out by “generic computer”. There is no technological improvement”. In response to applicant's argument that: “amended claims recite automatic fraud confirmation and preventative Action,” the examiner respectfully disagrees. Again, this is just an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea. In response to applicant's argument that: “practical application… The present claims do so by reciting a specific improvement to network fraud detection and security,” the examiner respectfully disagrees. There is no technological improvement. Processing data to detect a pattern is not a technological improvement. The examiner has also determined that this judicial exception is not integrated into a practical application. In particular, the claims’ technical elements (e.g., the at least one processor, authorized devices, unauthorized device, a first authorized device, a second authorized device, etc.) when considered separately and as an ordered combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea and are at a high level of generality. See Claim Rejections - 35 USC § 101 above. In response to applicant's argument that: “example, amended claim 1 recites "performing, by the at least one processor in response to the identification, a security action for the at least one of the reported financial activities that was initiated by the unauthorized device, wherein the security action includes automatically confirming fraud and taking preventative action prior to issuing an alert," which can achieve fraud confirmation more rapidly and avoid the delays of requiring customer interaction,” the examiner respectfully disagrees. Again, this is just an explanation of what security action can included (i.e., confirming fraud and taking preventative action), this is a procedure – another abstract idea. In response to applicant's argument that: “technological mechanisms that improve the functioning of the computer-network security system and endpoint telemetry processing (e.g., pattern-based purchase recognition without full browser visibility, multi-user correlation techniques that eliminate spurious matches, automated confirmation workflows,” the examiner respectfully disagrees. Again, processing multiple data points to detect a pattern is not a technological improvement. In response to applicant's argument that: “significantly more… The claim recites a non-conventional, non-generic arrangement of components and operations (e.g., multi-layer telemetry capture (browser/VPN), post-credit-card-form request patterning, a fuzzy matching technique that can eliminate spurious correlations, correlation records driving automated actions) that are all expressly disclosed as improvements to computer operation and security workflows,” the examiner respectfully disagrees. The decision to capture browser and VPN data is a business decision. Similarly, the post-credit-card-form requesting timing is also a business decision. There is simply no technological innovation. The fuzzy matching technique is mentioned at a high level. As stated in the prior office action: “Applying an algorithm (fuzzy matching) by using generic computer is not patentable under 35 U.S.C. § 101”. The examiner has determined that the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when considered separately and as an ordered combination, they do not add significantly more (also known as an “inventive concept”) to the exception. See Claim Rejections - 35 USC § 101 above. The additional element of using a computer hardware amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MARK H GAW whose telephone number is (571)270-0268. The examiner can normally be reached Mon-Fri: 9am -5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mike Anderson can be reached on 571 270-0508. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MARK H GAW/Examiner, Art Unit 3693
Read full office action

Prosecution Timeline

Show 19 earlier events
Apr 14, 2025
Non-Final Rejection mailed — §101
Aug 12, 2025
Examiner Interview Summary
Aug 12, 2025
Applicant Interview (Telephonic)
Sep 15, 2025
Response Filed
Oct 10, 2025
Final Rejection mailed — §101
Feb 05, 2026
Request for Continued Examination
Feb 26, 2026
Response after Non-Final Action
May 06, 2026
Non-Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705623
Machine Learning System
3y 10m to grant Granted Aug 11, 2026
Patent 12688505
Machine Learning System
3y 9m to grant Granted Jul 21, 2026
Patent 12675823
CREDIT DEFAULT SWAP CLEARING
1y 10m to grant Granted Jul 07, 2026
Patent 12670492
Method, System, and Computer Program Product for Authenticating a Transaction Using Biometric Data
2y 9m to grant Granted Jun 30, 2026
Patent 12591930
TRANSACTIONALLY DETERMINISTIC HIGH SPEED FINANCIAL EXCHANGE HAVING IMPROVED, EFFICIENCY, COMMUNICATION, CUSTOMIZATION, PERFORMANCE, ACCESS, TRADING OPPORTUNITIES, CREDIT CONTROLS, AND FAULT TOLERANCE
1y 4m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
50%
Grant Probability
99%
With Interview (+59.7%)
3y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 299 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month