Prosecution Insights
Last updated: August 15, 2026
Application No. 17/859,854

CYBER SECURITY SANDBOX ENVIRONMENT

Final Rejection §102§112
Filed
Jul 07, 2022
Priority
Jul 07, 2021 — provisional 63/219,026
Examiner
DAVIS, ZACHARY A
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
4 (Final)
54%
Grant Probability
Moderate
5-6
OA Rounds
4m
Est. Remaining
76%
With Interview

Examiner Intelligence

Grants 54% of resolved cases
54%
Career Allowance Rate
273 granted / 508 resolved
-4.3% vs TC avg
Strong +22% interview lift
Without
With
+21.9%
Interview Lift
resolved cases with interview
Typical timeline
4y 5m
Avg Prosecution
35 currently pending
Career history
568
Total Applications
across all art units

Statute-Specific Performance

§101
12.3%
-27.7% vs TC avg
§103
30.8%
-9.2% vs TC avg
§102
15.9%
-24.1% vs TC avg
§112
38.6%
-1.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 508 resolved cases

Office Action

§102 §112
DETAILED ACTION A response was received on 19 February 2026. By this response, Claims 1-9, 11-13, 15, 17, and 18 have been amended. Claim 10 has been canceled. No new claims have been added. Claims 1-9 and 11-20 are currently pending in the present application. Response to Arguments Applicant's arguments filed 19 February 2026 have been fully considered but they are not persuasive. Regarding the rejection of Claims 1-20 under 35 U.S.C. 102(a)(1) as anticipated by Benjamin, US Patent 7784099, and with particular reference to independent Claim 1, Applicant argues that Benjamin does not teach creating a clone cyber security appliance from a reference appliance, where the clone appliance includes a clone of one or more machine learning architectures and a clone of one or more machine learning algorithms in which the cloned architectures are configured to update weights applied to learning of the cloned algorithms differently than the architectures of the reference appliance, and that Benjamin instead teaches machine learning-based virtual security appliances creating virtual copies of networks and appliances, deploying in sandboxed environments, simulating attacks, and reporting results (page 10 of the present response, no particular evidence cited). However, Applicant does not clearly explain how the machine learning in Benjamin is asserted to be different from the claimed machine learning. The virtual copy of the machine and of the network (for example, see column 13, line 51-column 14, line 7, and column 9, line 62-column 10, line 9, virtual copies of machines; virtual copy of network) correspond to the claimed clone appliance and clone network, respectively. Further, as detailed below, there is not clear written description of applying weights differently. Applicant further argues that Benjamin “does not teach an explicit mechanism in which an ML model… continues to update weights that clearly occurs during deployment as it is tested” (page 10 of the present response) but does not argue what particular mechanism is required by the claim. The claim merely requires the function of updating weights during deployment but no explicit mechanism for such updating. In this context, Benjamin does disclose the clone of the model/algorithm learning new rules, corresponding to the claimed updating of the weights (see column 11, lines 40-62; see also column 6, lines 29-41, real-time response, and column 12, line 47-column 13, line 33, describing the particular machine learning model). Further, in response to applicant's argument that the references fail to show certain features of the invention (pages 10-11 of the present response), it is noted that the features upon which applicant relies (i.e., the clone creator orchestrates instantiation of multiple concurrent sandboxed clone networks that operate independently) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Applicant also argues that the same arguments are applicable to Claims 11 and 20 (page 11 of the present response); in response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., the cloned machine learning architectures are configured to update weights applied to the cloned algorithms differently than the architectures of the reference appliance; a model in a clone appliance continues to update weights; the clone creator orchestrates instantiation of multiple concurrent sandboxed clone networks that operate independently) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Independent Claim 11 does not recite the features argued with respect to Claim 1, and Claim 20 similarly does not recite those features due to its reference to Claim 11. Therefore, for the reasons detailed above, the Examiner maintains the rejections as set forth below. Specification The specification is objected to as failing to provide proper antecedent basis for the claimed subject matter. See 37 CFR 1.75(d)(1) and MPEP § 608.01(o). Correction of the following is required: Independent Claim 1 has been amended to recite “the cloned one or more machine learning architectures are configured to update weights applied to machine learning of the cloned one or more machine learning algorithms differently than the one or more machine learning architectures of the reference cyber security appliance”. There appears to be no mention in the specification of updating weights differently. Therefore, there is not clearly proper antecedent basis for the claimed subject matter in the specification. For further detail, see below with respect to the rejection under 35 U.S.C. 112(a) for failure to comply with the written description requirement. Claim Objections The objection of Claims 2, 3, and 7 for informalities are withdrawn in light of the amendments thereto. The objections to Claims 1, 4, and 5 are NOT withdrawn in light of the additional informalities noted below. Claims 1 and 11 are objected to because of the following informalities: In Claim 1, line 5, it appears that a colon should be inserted after “configured to”. In Claim 4, line 5, in the phrase “the set of IP packet traffic”, it appears that “set of” should be deleted for clear antecedent basis to the IP packet traffic in Claim 1. In Claim 5, line 5, in the phrase “the set of IP packet traffic”, it appears that “set of” should be deleted for clear antecedent basis to the IP packet traffic in Claim 1. In Claim 11, line 3, it appears that a colon should be inserted after “configured to”. In Claim 11, line 8, it appears that “is configured” should read “are configured” for agreement with the plural subject “architectures”. In Claim 11, line 19, it appears that the comma at the end of item 3 after “appliance” should be replaced with a semicolon. Appropriate correction is required. Claim Rejections - 35 USC § 112 The rejection of Claim 15 under 35 U.S.C. 112(a) for failure to comply with the written description requirement is withdrawn in light of the amendments to the claim. The rejection of Claim 10 under 35 U.S.C. 112(b) as indefinite is moot in light of the cancellation of the claim. The rejection of Claims 1-9 and 11-20 under 35 U.S.C. 112(b) as indefinite is NOT withdrawn, because not all issues have been addressed and/or because the amendments have raised new issues, as detailed below. The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-9 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Independent Claim 1 has been amended to recite “the cloned one or more machine learning architectures are configured to update weights applied to machine learning of the cloned one or more machine learning algorithms differently than the one or more machine learning architectures of the reference cyber security appliance”. Although there is general discussion of updating weights (for example, see paragraphs 0039 and 0059 of the present specification), there appears to be no mention in these paragraphs or elsewhere in the specification of updating weights in different ways. Further, Applicant has not pointed out where in the specification the amended claims are supported. See also MPEP § 2163.04. Therefore, there is not clearly sufficient written description of the claimed subject matter in the specification. Claims 2-9 are rejected due to their dependence on rejected Claim 1. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-9 and 11-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites “the clone creator is configured to” in lines 4-5. It is not clear how this independent clause relates grammatically to the remainder of the claim, although it appears that this may be intended as a “wherein” clause or similar. The claim further recites “the clone of the one or more architectures is configured to continue” in lines 9-10. It is not clear how this independent clause relates grammatically to the remainder of the claim, although it appears that this may be intended as a “wherein” clause or similar. The claim additionally recites “a reference cyber security appliance” in lines 18-19. It is not clear whether this is intended to refer to the same reference appliance as recited in line 7 or a distinct reference appliance. The claim also recites “the one or more architectures” in lines 20-21. It is not clear whether this is intended to refer to the cloned architecture s or the reference architectures. The claim further recites “a clone of the one or more machine learning architectures” in line 23. It is not clear whether this is intended to refer to the same clone created in line 6 or a distinct clone. The above ambiguities render the claim indefinite. Claim 2 recites “a data store” in line 6. It is not clear whether this data store is an element of the claimed apparatus. Claim 3 recites “a data store” in line 8. It is not clear whether this data store is an element of the claimed apparatus. Claim 6 recites “the one or more virtual machines are protected” in lines 2-3. It is not grammatically clear how this independent clause relates to the remainder of the claim, although it appears that this may be intended as a “wherein” clause or similar. Claim 11 recites a “method for automated cloning of one or more machine learning algorithms” in line 1. However, it appears that the result of the method is not the automated generation of a clone, but rather the configuration of certain structures or other aspects. The claim further recites “the one or more machine learning architectures” in line 4. There is insufficient antecedent basis for this limitation in the claim. The claim additionally recites “corresponding one or more machine learning algorithms” in line 5. It is not clear whether this is intended to refer to the algorithms recited in line 1 or distinct algorithms. The claim further recites “one or more machine learning architectures” in line 29. It is not clear whether this is intended to refer to the same architectures recited in line 4. The claim additionally recites “the one or more machine learning algorithm events” in lines 29-30. There is insufficient antecedent basis in the claims for this limitation. The above ambiguities render the claim indefinite. Claim 12 recites “the first snapshot includes” in lines 4-5. It is not grammatically clear how this independent clause relates to the remainder of the claim, although it appears that this may be intended as a “wherein” clause or similar. Claim 13 recites “that includes (a) a memory of the disk image and (b) settings” in line 5. It is not clear what the subject of this phrase is intended to be; that is, it is not clear what includes the memory and settings, the snapshot or the disk image. Claim 19 recites “an actual cyber threat attack” in lines 3-4. It is not clear what is meant by the term “actual” in this context, because the specification appears to recite simulated attacks. Claim 20 recites “software that, when executed by one or more processors, configure a clone creator” in lines 2-3. The verb “configure” does not agree with the subject “software” which should take a singular verb. Claims not specifically referred to above are rejected due to their dependence on a rejected base claim. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-9 and 11-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Benjamin, US Patent 7784099. In reference to Claim 1, Benjamin discloses an apparatus that includes processing units and media including clone creator software which, when executed, is configured to create a clone of one or more machine learning architectures and corresponding algorithms from a reference cyber security appliance that includes architectures using the algorithms configured to update weights applied to the machine learning (see column 6, line 29-column 8, line 67, generally describing learning systems; see also column 12, line 47-column 13, line 33); create a clone network from a reference network that includes a set of devices, accounts, and packet traffic, where the clone network is created in a virtual machine environment and includes devices corresponding to the devices in the reference network and copies of the accounts and traffic (column 13, line 51-column 14, line 7; see also column 9, line 62-column 10, line 9, virtual copy of network, and column 14, lines 24-40, virtual network is set of virtual machines); create a clone cyber security appliance from the reference appliance, where the clone appliance includes the architectures using the algorithms from the reference appliance which are configured to update the weights applied to the machine learning differently (column 13, line 51-column 14, line 7; see also column 11, lines 40-62, learning new rules, corresponding to updating the weights in a different manner; see also column 6, lines 29-41, real-time response, and column 12, line 47-column 13, line 33, describing the particular machine learning model); and test one or more cyber attacks on the clone network by subjecting the clone network to the cyber attacks such that the traffic in the reference network is not affected by the cyber attacks in the clone network, where the clone network is created in a virtual machine environment (column 13, line 51-column 14, line 7, and column 9, line 62-column 10, line 9, executing attacks or activities in simulated copy of network); where the apparatus also includes a user interface to convey results of the attacks on the clone network and analysis by the clone appliance using events recorded during the attacks (column 10, line 60-column 11, line 5, displaying vulnerability analysis). In reference to Claims 2 and 3, Benjamin further discloses making the clone network and appliance by taking snapshots of disk images and settings being cloned and storing the clone network and appliance (see column 15, line 53-column 16, line 2, virtual images of machines on network). In reference to Claims 4-6, Benjamin further discloses sandbox environments populated with virtual machines to implement the clone network (see column 10, lines 38-45, virtual machines) and a threat creator to implement the attacks in the virtual machines (column 13, line 51-column 14, line 7). In reference to Claims 7-9, Benjamin further discloses a data management module to record and display events including information indicating malicious activity, compromised accounts or devices, and actions taken by the clone or reference appliance (column 10, line 60-column 11, line 5, interface displaying vulnerability analysis). Claims 11-19 are directed to methods corresponding to the functionality of the apparatus of Claims 1-9 and are rejected by a similar rationale, mutatis mutandis. Claim 20 is directed to a software implementation of the method of Claim 11, and is rejected by a similar rationale. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Zachary A Davis whose telephone number is (571)272-3870. The examiner can normally be reached Monday-Friday, 9:00am-5:30pm, Eastern Time. Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal D Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Zachary A. Davis/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Show 2 earlier events
Apr 16, 2025
Response Filed
Jun 10, 2025
Final Rejection mailed — §102, §112
Jul 31, 2025
Response after Non-Final Action
Sep 10, 2025
Request for Continued Examination
Sep 18, 2025
Response after Non-Final Action
Oct 22, 2025
Non-Final Rejection mailed — §102, §112
Feb 19, 2026
Response Filed
Jul 29, 2026
Final Rejection mailed — §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12676750
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12676751
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12659750
ULTRA-WIDEBAND UNLOCK DEVICE
3y 8m to grant Granted Jun 16, 2026
Patent 12592929
TECHNIQUE FOR COMPUTING A BLOCK IN A BLOCKCHAIN NETWORK
4y 9m to grant Granted Mar 31, 2026
Patent 12566840
Systems And Methods For Creating Trustworthy Orchestration Instructions Within A Containerized Computing Environment For Validation Within An Alternate Computing Environment
3y 7m to grant Granted Mar 03, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
54%
Grant Probability
76%
With Interview (+21.9%)
4y 5m (~4m remaining)
Median Time to Grant
High
PTA Risk
Based on 508 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month