Prosecution Insights
Last updated: October 01, 2026
Application No. 17/887,081

EVENT INJECTION FOR ANALYSIS OF HARDWARE NETWORK STACK BEHAVIOR

Final Rejection §103
Filed
Aug 12, 2022
Examiner
SANDHU, NEVENA ZECEVIC
Art Unit
2474
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
2 (Final)
74%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
80%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
151 granted / 204 resolved
+16.0% vs TC avg
Moderate +6% lift
Without
With
+6.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
25 currently pending
Career history
233
Total Applications
across all art units

Statute-Specific Performance

§101
3.1%
-36.9% vs TC avg
§103
68.8%
+28.8% vs TC avg
§102
9.7%
-30.3% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 204 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments 2. Applicant’s arguments, filed on May 5, 2026, regarding rejection of claims 1-20, as amended, under 35 U.S.C. 103 have been considered but are moot because the arguments do not apply to any combination of the references being used in the current rejection. Examiner has applied Yao ‘443 (US 2005/0246443), Brandeburg ‘678 (US 2016/0191678), and Rothstein ‘879 (US 9,660,879) to clearly teach the amended limitations in claims 1-20. Claim Rejections - 35 USC § 103 3. The following is a quotation of 35 U.S.C. 103, which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 4. Claims 1 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Li (Li et al., "IMap: Fast and Scalable In-Network Scanning with Programmable Switches", In Proceedings of the 19th USENIX Symposium on Networked Systems Design and Implementation, April 4, 2022, pp.667-681, “Li”), in view of Nguyen ‘755 (US 2013/0346755, “Nguyen ‘755”), further in view of Yao ‘443 (US 2005/0246443, “Yao ‘443”), and further in view of Zhang ‘870 (US 2022/0200870, “Zhang ‘870”). Regarding claim 1, Li discloses a method comprising: configuring a programmable network device to: inject events into the network traffic (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; an IMap programmable switch receives parameters parsed from configuration information, and uses these parameters to generate probe packets it sends to scan the network; thus, the IMap programmable switch is configured to inject probe packets into network traffic; IMap programmable switch reads on a programmable network device; probe packets read on events); the mirrored traffic including the injected events (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; an IMap programmable switch generates probe packets, and sends the probe packets to scan the network; thus, the network traffic includes injected probe packets); the analysis results reflecting behavior of the network stack functionality in response to the injected events (FIG. 1, Abstract, Introduction, Section 3.2; scanning of the network includes sending the probe packets and receiving response packets, where scanning results are used to understand network behavior in response to the probe packets); and outputting the analysis results (FIG. 1, Abstract, Introduction, Section 3.2; scanning results are written into a database). However, Li does not specifically disclose receive network traffic comprising packets communicated between two or more hosts having network adapters. Nguyen ‘755 teaches receive network traffic comprising packets communicated between two or more hosts having network adapters (FIGS. 1 and 4, para 16-20, 144, 147, and 152-153; a source node sends data packets to a target node, via a topology of intermediate nodes IN1-IN12; a node is implemented as a computer connected to a network through a network adapter; thus, an IN receives packets communicated between the source node and the target node, where nodes have network adapters); wherein the injected events include modifications to individual packets communicated between the two or more hosts (FIG. 1, para 16-20; intermediate node IN6 adds corrupt packets to the packets communicated between the source node and the target node, negatively affecting the target node’s ability to reconstruct the data consisting of packets sent by the source node). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to combine Li’s method comprising configuring a programmable network device to inject events into network traffic, to include Nguyen ‘755’s corrupt packets. The motivation for doing so would have been to address a problem of traditional digital signature schemes failing in situations where a digital signature on arbitrarily combined packets needs verification (Nguyen ‘755, para 3). Although Li in combination with Nguyen ‘755 discloses receive network traffic comprising packets communicated between two or more hosts having network adapters, Li in combination with Nguyen ‘755 does not specifically disclose hosts having network adapters that perform network stack functionality in hardware. Yao ‘443 teaches hosts having network adapters that perform network stack functionality in hardware (FIG. 1, para 12-14; a host system includes a network interface card (NIC), where the NIC includes a network adapter that implements a network stack in hardware). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li and Nguyen ‘755, to include Yao ‘443’s network adapter that implements a network stack in hardware. The motivation for doing so would have been to provide support for Internet Small Computer Systems Interface (iSCSI) operations, such that the TCP/IP stack implemented in hardware of the NIC is used for the iSCSI operations (Yao ‘443, para 1-2 and 31). Although Li in combination with Nguyen ‘755 and Yao ‘443 discloses the mirrored traffic including the injected events, Li in combination with Nguyen ‘755 and Yao ‘443 does not specifically disclose obtaining mirrored traffic provided by the programmable network device, analyzing the mirrored traffic to obtain analysis results. Zhang ‘870 teaches obtaining mirrored traffic provided by the programmable network device, analyzing the mirrored traffic to obtain analysis results (FIG. 1, para 44-45; a data source device mirrors traffic, and sends the mirrored traffic to an analysis device; the analysis device parses the traffic and obtains flow statistical information). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, and Yao ‘443, to include Zhang ‘870’s data source device that mirrors traffic. The motivation for doing so would have been to resolve the problem of poor accuracy of prediction technology (Zhang ‘870, para 8-9). Regarding claim 5, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. Further, Li teaches further comprising: populating a configuration file with event parameters for the events; and sending the configuration file to the programmable network device, the programmable network device being configured to read the configuration file and inject the events according to the event parameters (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; configuration information is sent to the IMap programmable switch; the IMap programmable switch receives the configuration information, and uses parameters parsed from the configuration information to generate and send probe packets to scan the network). 5. Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Brandeburg ‘678 (US 2016/0191678, “Brandeburg ‘678”). Regarding claim 2, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. Further, Nguyen ‘755 teaches wherein the injected events include corrupting a packet, the corrupting resulting in a corrupted packet that is sent to a second host (FIG. 1, para 16-20; intermediate node IN6 adds corrupt packets to the packets communicated between the source node and the target node). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to further include Nguyen ‘755’s corrupt packets. The motivation for doing so would have been to address a problem of traditional digital signature schemes failing in situations where a digital signature on arbitrarily combined packets needs verification (Nguyen ‘755, para 3). Although Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses wherein the injected events include corrupting a packet, the corrupting resulting in a corrupted packet that is sent to a second host, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose corrupting a particular packet received from a first host. Brandeburg ‘678 teaches corrupting a particular packet received from a first host (FIG. 1, para 14-16; a remote computing device segments data into segmented network packets, and transmits the segmented network packets containing data segments to a computing device; the process of segmentation at the remote computing device corrupts a segmented network packet; the computing device receives the segmented network packet, and determines that the segmented network packet is corrupted; thus, a particular packet is corrupted and received from the remote computing device). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Brandeburg ‘678’s segmented network packet that is corrupted. The motivation for doing so would have been to address a problem of errors introduced into the network packet from hardware offload operations (Brandeburg ‘678, para 1-2). 6. Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Rothstein ‘879 (US 9,660,879, “Rothstein ‘879”). Regarding claim 3, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the injected events include dropping a particular packet received from a first host, the dropping resulting in a dropped packet that is not sent to a second host. Rothstein ‘879 teaches wherein the injected events include dropping a particular packet received from a first host, the dropping resulting in a dropped packet that is not sent to a second host (FIGS. 4-5, col. 5:1-6, col. 20:38-44, and col. 24:16-32; a network monitoring computer (NMC) is arranged to actively forward received network packets to another NMC responsible for processing the received network packets; packet forwarding is adaptive; when the forwarding is not necessary, the forwarding NMC is signaled to start discarding received packets and not to forward them). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Rothstein ‘879’s discarded received packets that are not forwarded. The motivation for doing so would have been to address a difficulty of determining correlations or other information from monitoring data that includes duplicative data (Rothstein ‘879, col. 1:59-67 and col. 2:1-28). 7. Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Janakiraman ‘785 (US 2004/0196785, “Janakiraman ‘785”). Regarding claim 4, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. Further, Nguyen ‘755 teaches packet that is received from a first host (FIG. 1, para 16-20; a source node sends data packets to a target node, via a topology of intermediate nodes IN1-IN12). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to further include Nguyen ‘755’s node that is implemented as a computer connected to a network through a network adapter. The motivation for doing so would have been to address a problem of traditional digital signature schemes failing in situations where a digital signature on arbitrarily combined packets needs verification (Nguyen ‘755, para 3). Although Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses packet that is received from a first host, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the injected events include adding an explicit congestion notification mark to a particular packet and sending the particular packet having the explicit congestion notification mark to a second host. Janakiraman ‘785 teaches wherein the injected events include adding an explicit congestion notification mark to a particular packet and sending the particular packet having the explicit congestion notification mark to a second host (para 26; a data packet is sent to a receiving node, where the data packet includes congestion notification marker). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Janakiraman ‘785’s data packet that includes congestion notification marker. The motivation for doing so would have been to provide a congestion notification process for use in a communication network (Janakiraman ‘785, para 6-8). 8. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Rothenberger (Rothenberger et al., "ReDMArk: Bypassing ROMA Security Mechanisms", In Proceedings of the 30th USENIX Security Symposium, August 11, 2021, pp. 4277-4292, “Rothenberger”). Regarding claim 6, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 5, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the configuration file identifies a particular queue pair for which the programmable network device is to inject a particular event. Rothenberger teaches wherein the configuration file identifies a particular queue pair for which the programmable network device is to inject a particular event (Section 2.1, Section 5.1, lines 1-25; a packet is injected based on a queue pair number (QPN)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined method of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Rothenberger’s packet that is injected based on a queue pair number. The motivation for doing so would have been to consider potential mitigation techniques to secure remote direct memory access (RDMA) (Rothenberger, Introduction). 9. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, further in view of Rothenberger, and further in view of Sarangapani ‘769 (US 9,705,769, “Sarangapani ‘769”). Regarding claim 7, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothenberger discloses all the limitations with respect to claim 6, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothenberger does not specifically disclose wherein the configuration file identifies a particular packet sequence number of a particular packet in which to inject the particular event. Sarangapani ‘769 teaches wherein the configuration file identifies a particular packet sequence number of a particular packet in which to inject the particular event (col. 13:23-33; a sequence number identifies a relative position of a packet in a sequence of packets). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothenberger, to include Sarangapani ‘769’s sequence number that identifies a relative position of a packet in a sequence of packets. The motivation for doing so would have been to improve network efficiency and design the network in a more latency-sensitive manner (RDMA) (Sarangapani ‘769, col. 4:5-12). 10. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, further in view of Rothenberger, further in view of Sarangapani ‘769, and further in view of Youn ‘830 (US 2025/0167830, “Youn ‘830”). Regarding claim 8, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, Rothenberger, and Sarangapani ‘769 discloses all the limitations with respect to claim 7, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870, Rothenberger, and Sarangapani ‘769 does not specifically disclose wherein the configuration file identifies a particular event type of the particular event. In a similar field of endeavor, Youn ‘830 teaches wherein the configuration file identifies a particular event type of the particular event (para 511; a header includes packet type indication). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the system of Li, Nguyen ‘755, Yao ‘443, Zhang ‘870, Rothenberger, and Sarangapani ‘769, to include Youn ‘830’s header that includes packet type indication. The motivation for doing so would have been to provide a negotiation method and device for fast frequency shift keying (FSK) (Youn ‘830, para 6-7). 11. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, further in view of Rothenberger, further in view of Sarangapani ‘769, further in view of Youn ‘830, and further in view of Lee ‘909 (US 2019/0181909, “Lee ‘909”). Regarding claim 9, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, Rothenberger, Sarangapani ‘769, and Youn ‘830 discloses all the limitations with respect to claim 8, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, Rothenberger, Sarangapani ‘769, and Youn ‘830 does not specifically disclose wherein the configuration file identifies an iteration number specifying a transmission round in which the particular event is to be injected by the programmable network device. Lee ‘909 teaches wherein the configuration file identifies an iteration number specifying a transmission round in which the particular event is to be injected by the programmable network device (para 84; parameter “Retry count” indicates the number of retransmissions of a packet). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the system of Li, Nguyen ‘755, Yao ‘443, Zhang ‘870, Rothenberger, Sarangapani ‘769, and Youn ‘830, to include Lee ‘909’s “Retry count” parameter. The motivation for doing so would have been to address a problem of slow frequency hopping resulting in occasional collisions when another wireless device is introduced into the environment (Lee ‘909, para 2). 12. Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Kulshreshtha ‘592 (US 2016/0359592, “Kulshreshtha ‘592”). Regarding claim 10, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the analysis results reflect retransmission latency. Kulshreshtha ‘592 teaches wherein the analysis results reflect retransmission latency (para 79; a monitoring device determines retransmission latency). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Kulshreshtha ‘592’s monitoring device that determines retransmission latency. The motivation for doing so would have been to address difficult to identify node topologies, data path flow, and/or path characteristics for devices and/or networks within data center networks (Kulshreshtha ‘592, para 3). 13. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Lee ‘909. Regarding claim 11, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the analysis results reflect timeout values and retry counts. Lee ‘909 teaches wherein the analysis results reflect timeout values and retry counts (para 52 and 84; pre-determined timeout time; parameter “Retry count” that indicates the number of retransmissions of a packet). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the system of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Lee ‘909’s “Retry count” parameter. The motivation for doing so would have been to address a problem of slow frequency hopping resulting in occasional collisions when another wireless device is introduced into the environment (Lee ‘909, para 2). 14. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Janakiraman ‘785. Regarding claim 12, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 discloses all the limitations with respect to claim 1, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the analysis results reflect congestion notification behavior. Janakiraman ‘785 teaches wherein the analysis results reflect congestion notification behavior (para 26; a data packet is sent, where the data packet includes congestion notification marker). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Janakiraman ‘785’s data packet that includes congestion notification marker. The motivation for doing so would have been to provide a congestion notification process for use in a communication network (Janakiraman ‘785, para 6-8). 15. Claims 13-14 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, and further in view of Zhang ‘870. Regarding claim 13, Li discloses a programmable network device (FIG. 1, Abstract; IMap programmable switch that performs network scanning) comprising: a plurality of ports (FIG. 1, Abstract, Section 4.1; the IMap programmable switch includes multiple ports); and a programmable logic circuit (FIG. 1, Abstract, Section 2.2; the IMap programmable switch includes programmable ASICs) configured to: receive event parameters of events to inject into network traffic connected to two or more of the ports; inject the events into the network traffic (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; the IMap programmable switch includes multiple ports; the IMap programmable switch receives parameters parsed from configuration information, and uses these parameters to generate probe packets it sends to scan the network; thus, the IMap programmable switch receives parameters of probe packets to inject into network traffic, using multiple ports); packets received at a first port (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; the IMap programmable switch generates probe packets, and sends the probe packets to survey all ports of the network; thus, packets are received at ports); transmit the network traffic having the injected events via a second port (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; the IMap programmable switch includes multiple ports; the IMap programmable switch receives parameters parsed from configuration information, and uses these parameters to generate probe packets it sends to scan the network; thus, the IMap programmable switch sends probe packets in the network via ports). Although Li discloses receive event parameters of events to inject into network traffic connected to two or more of the ports; inject the events into the network traffic, Li does not specifically disclose network traffic communicated between two or more network adapters. Further, although Li discloses packets received at a first port, Li does not specifically disclose wherein the events include modifications to individual packets received from a first network adapter. Furthermore, although Li discloses transmit the network traffic having the injected events via a second port, Li does not specifically disclose transmit the network traffic to a second network adapter. Nguyen ‘755 teaches network traffic communicated between two or more network adapters (FIGS. 1 and 4, para 16-20, 144, 147, and 152-153; a source node sends data packets to a target node, via a topology of intermediate nodes IN1-IN12; a node is implemented as a computer connected to a network through a network adapter; thus, an IN receives packets communicated between the source node and the target node, where nodes have network adapters); wherein the events include modifications to individual packets received from a first network adapter (FIG. 1, para 16-20; intermediate node IN6 adds corrupt packets to the packets communicated between the source node and the target node, negatively affecting the target node’s ability to reconstruct the data consisting of packets sent by the source node). transmit the network traffic to a second network adapter (FIGS. 1 and 4, para 16-20, 144, 147, and 152-153; a source node sends data packets to a target node, via a topology of intermediate nodes IN1-IN12; a node is implemented as a computer connected to a network through a network adapter; thus, a node sends packets to another node, where nodes have network adapters). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to combine Li’s programmable network device that injects events into network traffic, to include Nguyen ‘755’s corrupt packets. The motivation for doing so would have been to address a problem of traditional digital signature schemes failing in situations where a digital signature on arbitrarily combined packets needs verification (Nguyen ‘755, para 3). However, Li in combination with Nguyen ‘755 does not specifically disclose mirror the network traffic to one or more other devices for subsequent analysis. Zhang ‘870 teaches mirror the network traffic to one or more other devices for subsequent analysis (FIG. 1, para 44-45; a data source device mirrors traffic, and sends the mirrored traffic to an analysis device; the analysis device parses the traffic and obtains flow statistical information). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined programmable network device of Li and Nguyen ‘755, to include Zhang ‘870’s data source device that mirrors traffic. The motivation for doing so would have been to resolve the problem of poor accuracy of prediction technology (Zhang ‘870, para 8-9). Regarding claim 14, Li in combination with Nguyen ‘755 and Zhang ‘870 discloses all the limitations with respect to claim 13, as outlined above. Further, Li teaches wherein the programmable logic circuit is configured to populate a match-action table to inject the events based at least on the event parameters (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; the IMap programmable switch receives parameters parsed from configuration information, and updates a Probe IP Range (PIPR) table to inject probe packets into network traffic). Regarding claim 17, Li in combination with Nguyen ‘755 and Zhang ‘870 discloses all the limitations with respect to claim 13, as outlined above. Further, Li teaches wherein the event parameters are received in a configuration file and the programmable logic circuit is configured to parse the configuration file to extract the event parameters from the configuration file (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; the IMap programmable switch receives configuration information, and uses parameters parsed from the configuration information to generate and send probe packets to scan the network). 16. Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Zhang ‘870, and further in view of Rothstein ‘879. Regarding claim 15, Li in combination with Nguyen ‘755 and Zhang ‘870 discloses all the limitations with respect to claim 13, as outlined above. However, Li in combination with Nguyen ‘755 and Zhang ‘870 does not specifically disclose wherein the injected events include at least one of a packet corruption event that corrupts at least one packet communicated between a first host having the first network adapter and a second host having the second network adapter, a packet drop event that drops at least one packet sent by the first host and addressed to the second host, or an explicit congestion notification event that adds an explicit congestion notification mark to at least one packet communicated between the first host and the second host. Rothstein ‘879 teaches wherein the injected events include at least one of a packet corruption event that corrupts at least one packet communicated between a first host having the first network adapter and a second host having the second network adapter, a packet drop event that drops at least one packet sent by the first host and addressed to the second host (FIGS. 4-5, col. 5:1-6, col. 20:38-44, and col. 24:16-32; a network monitoring computer (NMC) is arranged to actively forward received network packets to another NMC responsible for processing the received network packets; packet forwarding is adaptive; when the forwarding is not necessary, the forwarding NMC is signaled to start discarding received packets and not to forward them; examiner notes the use of alternative language; for rejection purposes, only one of the alternative limitations must be disclosed by prior art), or an explicit congestion notification event that adds an explicit congestion notification mark to at least one packet communicated between the first host and the second host. Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined programmable network device of Li, Nguyen ‘755, and Zhang ‘870, to include Rothstein ‘879’s discarded received packets that are not forwarded. The motivation for doing so would have been to address a difficulty of determining correlations or other information from monitoring data that includes duplicative data (Rothstein ‘879, col. 1:59-67 and col. 2:1-28). 17. Claim 16 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Zhang ‘870, and further in view of Rothenberger. Regarding claim 16, Li in combination with Nguyen ‘755 and Zhang ‘870 discloses all the limitations with respect to claim 13, as outlined above. However, Li in combination with Nguyen ‘755 and Zhang ‘870 does not specifically disclose wherein the programmable logic circuit is configured to inject the events for a particular queue pair specified by the event parameters. Rothenberger teaches wherein the programmable logic circuit is configured to inject the events for a particular queue pair specified by the event parameters (Section 2.1, Section 5.1, lines 1-25; a packet is injected based on a queue pair number (QPN)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined programmable network device of Li, Nguyen ‘755, and Zhang ‘870, to include Rothenberger’s packet that is injected based on a queue pair number. The motivation for doing so would have been to consider potential mitigation techniques to secure remote direct memory access (RDMA) (Rothenberger, Introduction). 18. Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, and further in view of Rothstein ‘879. Regarding claim 18, Li discloses a system (Introduction, Section 4.1; a switch includes a CPU) comprising: a processor (Introduction, Section 4.1; CPU included in the switch); and configure a programmable network device to inject events into network traffic (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; an IMap programmable switch receives parameters parsed from configuration information, and uses these parameters to generate probe packets it sends to scan the network; thus, the IMap programmable switch is configured to inject probe packets into network traffic; IMap programmable switch reads on a programmable network device; probe packets read on events); the mirrored traffic including the injected events (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; an IMap programmable switch generates probe packets, and sends the probe packets to scan the network; thus, the network traffic includes injected probe packets); the analysis results reflecting behavior of the network stack functionality in response to the injected events (FIG. 1, Abstract, Introduction, Section 3.2; scanning of the network includes sending the probe packets and receiving response packets, where scanning results are used to understand network behavior in response to the probe packets); and output the analysis results (FIG. 1, Abstract, Introduction, Section 3.2; scanning results are written into a database). However, Li does not specifically disclose a storage medium storing instructions which, when executed by the processor, cause the system to. Further, although Li discloses configure a programmable network device to inject events into network traffic, Li does not specifically disclose network traffic communicated between a first host and a second host having network adapters. Nguyen ‘755 teaches a storage medium storing instructions which, when executed by the processor, cause the system to (FIG. 4, para 144-148; computer 410 includes a memory storing instructions executable by a processor): network traffic communicated between a first host and a second host having network adapters (FIGS. 1 and 4, para 16-20, 144, 147, and 152-153; a source node sends data packets to a target node, via a topology of intermediate nodes IN1-IN12; a node is implemented as a computer connected to a network through a network adapter; thus, packets are communicated between the source node and the target node, where nodes have network adapters). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to combine Li’s system that configures a programmable network device to inject events into network traffic, to include Nguyen ‘755’s node that is implemented as a computer connected to a network through a network adapter. The motivation for doing so would have been to address a problem of traditional digital signature schemes failing in situations where a digital signature on arbitrarily combined packets needs verification (Nguyen ‘755, para 3). Although Li in combination with Nguyen ‘755 discloses network traffic communicated between a first host and a second host having network adapters, Li in combination with Nguyen ‘755 does not specifically disclose host having network adapters that perform network stack functionality in hardware. Yao ‘443 teaches host having network adapters that perform network stack functionality in hardware (FIG. 1, para 12-14; a host system includes a network interface card (NIC), where the NIC includes a network adapter that implements a network stack in hardware). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li and Nguyen ‘755, to include Yao ‘443’s network adapter that implements a network stack in hardware. The motivation for doing so would have been to provide support for Internet Small Computer Systems Interface (iSCSI) operations, such that the TCP/IP stack implemented in hardware of the NIC is used for the iSCSI operations (Yao ‘443, para 1-2 and 31). However, Li in combination with Nguyen ‘755 and Yao ‘443 does not specifically disclose obtain mirrored traffic provided by the programmable network device; analyze the mirrored traffic to obtain analysis results. Zhang ‘870 teaches obtain mirrored traffic provided by the programmable network device; analyze the mirrored traffic to obtain analysis results (FIG. 1, para 44-45; a data source device mirrors traffic, and sends the mirrored traffic to an analysis device; the analysis device parses the traffic and obtains flow statistical information). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, and Yao ‘443, to include Zhang ‘870’s data source device that mirrors traffic. The motivation for doing so would have been to resolve the problem of poor accuracy of prediction technology (Zhang ‘870, para 8-9). However, Li in combination with Nguyen ‘755, Yao ‘443, and Zhang ‘870 does not specifically disclose wherein the injected events involve at least one of a modifying or dropping a particular packet sent by the first host and addressed to the second host. Rothstein ‘879 teaches wherein the injected events involve at least one of a modifying or dropping a particular packet sent by the first host and addressed to the second host (FIGS. 4-5, col. 5:1-6, col. 20:38-44, and col. 24:16-32; a network monitoring computer (NMC) is arranged to actively forward received network packets to another NMC responsible for processing the received network packets; packet forwarding is adaptive; when the forwarding is not necessary, the forwarding NMC is signaled to start discarding received packets and not to forward them; examiner notes the use of alternative language; for rejection purposes, only one of the alternative limitations must be disclosed by prior art). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, and Zhang ‘870, to include Rothstein ‘879’s discarded received packets that are not forwarded. The motivation for doing so would have been to address a difficulty of determining correlations or other information from monitoring data that includes duplicative data (Rothstein ‘879, col. 1:59-67 and col. 2:1-28). 19. Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, further in view of Rothstein ‘879, and further in view of McLean ‘212 (US 2024/0284212, “McLean ‘212”). Regarding claim 19, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879 discloses all the limitations with respect to claim 18, as outlined above. However, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879 does not specifically disclose wherein the outputting of the results comprises displaying one or more graphical user interfaces that convey at least one of retransmission latency, timeout values, retry counts, or congestion notification behavior. McLean ‘212 teaches wherein the outputting of the results comprises displaying one or more graphical user interfaces that convey at least one of retransmission latency, timeout values, retry counts, or congestion notification behavior (para 144 and 164; congestion is a radio coverage issue; the affected geographic area is displayed on a graphical user interface (GUI); examiner notes the use of alternative language; for rejection purposes, only one of the alternative limitations must be disclosed by prior art). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879, to include McLean ‘212’s geographic area that is affected by congestion, and is displayed on a GUI. The motivation for doing so would have been to address a need for a data processing, storage and analysis system for storing large amounts of radio network measurement data that results from the testing or measurement or monitoring of multiple heterogeneous radio communications networks, and for the temporal querying, visualization and analysis of that data by both technically-skilled and lay users (McLean ‘212, para 29). 20. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Li, in view of Nguyen ‘755, further in view of Yao ‘443, further in view of Zhang ‘870, further in view of Rothstein ‘879, and further in view of Wylie ‘966 (US 2020/0021966, “Wylie ‘966”). Regarding claim 20, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879 discloses all the limitations with respect to claim 18, as outlined above. Further, Li teaches wherein the instructions, when executed by the processor, cause the system to: configure the programmable network device to inject the particular events according to the particular event parameters (FIG. 1, Abstract, Introduction, Section 3, Section 4.1; an IMap programmable switch receives parameters parsed from configuration information, and uses these parameters to generate probe packets it sends to scan the network; thus, the IMap programmable switch is configured to inject probe packets into network traffic; IMap programmable switch reads on a programmable network device; probe packets read on events). However, Li in combination with Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879 does not specifically disclose display a graphical user interface having elements for specifying event parameters; receive user input directed to the elements of the graphical user interface, the user input identifying particular event parameters for particular events. In a similar field of endeavor, Wylie ‘966 teaches display a graphical user interface having elements for specifying event parameters (FIG. 8C, para 48 and 92; live event fields are displayed on the mobile device’s graphical user interface (GUI)); receive user input directed to the elements of the graphical user interface, the user input identifying particular event parameters for particular events (FIG. 8C, para 48 and 92; the user selects a live event using the displayed field). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to add features to the combined system of Li, Nguyen ‘755, Yao ‘443, Zhang ‘870, and Rothstein ‘879, to include Wylie ‘966’s live event fields that are displayed on the mobile device’s GUI. The motivation for doing so would have been to address challenges in setting up a WiFi network to handle all the devices that would need to connect to it during an event (Wylie ‘966, para 3-8). Conclusion Internet Communication Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, https://www.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only. (1) Central Fax which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.0. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NEVENA SANDHU whose telephone number is (571) 272-0679. The examiner can normally be reached on Monday-Thursday 9AM-5PM EST, Friday variable. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Michael Thier can be reached on (571)272-2832. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NEVENA ZECEVIC SANDHU/Examiner, Art Unit 2474 /BENJAMIN H ELLIOTT IV/Primary Examiner, Art Unit 2474
Read full office action

Prosecution Timeline

Aug 12, 2022
Application Filed
Jan 09, 2026
Non-Final Rejection mailed — §103
Apr 06, 2026
Applicant Interview (Telephonic)
Apr 07, 2026
Examiner Interview Summary
May 05, 2026
Response Filed
Jul 15, 2026
Final Rejection mailed — §103
Sep 15, 2026
Examiner Interview Summary
Sep 15, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739071
COMMUNICATION APPARATUS AND METHOD THEREOF
4y 9m to grant Granted Sep 15, 2026
Patent 12739793
METHOD FOR RESOURCE SELECTION, AND APPARATUS, AND USER EQUIPMENT USING THE SAME
2y 11m to grant Granted Sep 15, 2026
Patent 12720379
SYSTEMS AND METHODS FOR PERFORMING CELL CHANGE TO A TARGET CELL SUBJECT TO CLEAR CHANNEL ASSESSMENT
4y 9m to grant Granted Aug 25, 2026
Patent 12712695
COMMUNICATION METHOD AND APPARATUS FOR REDUCING A RETRANSMISSION PROCESS DELAY
3y 9m to grant Granted Aug 18, 2026
Patent 12684576
TERMINAL AND COMMUNICATION METHOD
3y 11m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
74%
Grant Probability
80%
With Interview (+6.5%)
2y 10m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 204 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month