Prosecution Insights
Last updated: October 01, 2026
Application No. 18/055,173

GENERATING AN ENRICHMENT LAYER AND POPULATING A SECURITY GRAPH BASED ON CONFIGURATION CODE OF A CLOUD COMPUTING ENVIRONMENT

Non-Final OA §101§112
Filed
Nov 14, 2022
Priority
Nov 24, 2021 — provisional 63/264,550 +3 more
Examiner
AGUILERA, TODD
Art Unit
2192
Tech Center
2100 — Computer Architecture & Software
Assignee
Wiz Inc.
OA Round
5 (Non-Final)
58%
Grant Probability
Moderate
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
293 granted / 509 resolved
+2.6% vs TC avg
Strong +58% interview lift
Without
With
+57.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 8m
Avg Prosecution
35 currently pending
Career history
547
Total Applications
across all art units

Statute-Specific Performance

§101
14.1%
-25.9% vs TC avg
§103
47.3%
+7.3% vs TC avg
§102
9.9%
-30.1% vs TC avg
§112
27.5%
-12.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 509 resolved cases

Office Action

§101 §112
DETAILED ACTION Remarks Applicant presents a request for continued examination dated 17 August 2026 in response to the 18 May 2026 final rejection (the “Previous Action”). With the request, Applicant traverses all rejections. Claims 1, 3-12 and 14-21 are pending. Claims 1, 11 and 12 are the independent claims. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 17 August 2026 has been entered. Response to Arguments Applicant traverses the § 112(a) rejections of claims 1, 3-12 and 14-21 and submits that the features of claim 1 are supported by the originally filed specification. First, Applicant points out that paragraph [0074] discloses storing values extracted from the configuration code in data fields of a code object node, that Figure 3 shows generating an edge between a code-object and an instance node and that paragraphs [0023] and [0036] discloses that a single code object can be associated with multiple workloads or machines. (Remarks, p. 1 par. 4 – p. 2 par. 2) Examiner agrees that the specification describes storing extracted values in fields of a code object node but respectfully submits that doing so “wherein each node of the plurality of nodes does not store the extracted data field” is still lacking. Applicant adds that paragraph [0049] “expressly teaches that, rather than storing the same information in each workload node, the information may be stored in a single node to which the workload nodes are connected”, that paragraph [0077] reiterates this architecture for resource nodes and that “paragraph [0026] similarly states that configuration-code data is used to populate the security graph in a compact manner that reduces graph-database storage.” (Remarks, (Remarks, p. 3 pars. 1-2, p. 3 par. 2) Examiner respectfully disagrees that these paragraphs support what is claimed and submits that unlike the data field values vales of the claims, the information in paragraphs [0049] and [0077] (i.e., “public network access” and a “cybersecurity issue”) is not extracted from any code object and is not stored in a data field of any node representing a code object. Nodes representing public network access and cybersecurity are not described as including any fields or storing any information in fields either. Applicant argues that paragraph [0049] is not limited to public network access enrichment nodes because paragraph [0074] “separately and expressly identifies the code-object node as a node that stores extracted configuration-code values.” (Remarks, p. 3 last par. – p. 4 par. 1). Examiner does not maintain that paragraph [0049] is strictly limited to public network access enrichment nodes, only that it does not support what is claimed, in combination with paragraph [0074] or otherwise. Nothing in paragraph [0074] suggests that public network access nodes are code-object nodes. Note that the difference between paragraph [0049] and what is claimed is not merely the difference between the type of node described. The public network access node of paragraph [0049] represents a characteristic not stored in the connected nodes itself and the connections between it and the connected nodes indicate that the other nodes possess that characteristic. The connections between a node representing a code object and the plurality of nodes claimed instead indicate that resources represented by the plurality of nodes were deployed based on the code object. Applicant argues that a specification may support alternative embodiments in which a value is included in or excluded from another node, that alternative features can support a negative limitation and that a disclosure can support both inclusion and exclusion of the same feature. (Remarks, p. 4 par. 2). Examiner respectfully disagrees that what is claimed is disclosed in the specification as an alternative feature to anything described. In the examiner’s view, the specification describes storing data field values in both code object nodes and instances nodes, not either in the alternative. Applicant’s arguments with respect to the remaining claims by virtue of their dependence from claim 1, similarity with claim 1 or dependence from a similar claim are unpersuasive for the same reasons. Claim Rejections – 35 U.S.C. § 112 8. The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1, 3-12 and 14-21 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. As to claim 1, the claim refers to: …storing the extracted data field value in a data field of a node representing the first code object in the graph database… …wherein each node of the plurality of nodes does not store the extracted data field value. There is insufficient support in the originally filed specification for these features. Paragraphs [0049] and [0077] appear the most relevant but while those paragraphs do describe storing information on a single node rather than each of a plurality of workload nodes, they do not disclose this single node as representing “first code object” as claimed. Per those paragraphs, the single node represents “access to a public network” or a “cybersecurity issue”, not a “first code object” from which, per the claim, the workloads are “deployed.” As to claims 3-10, the claims are dependent on claim 1 but do not cure the deficiencies of that claim. Accordingly, they are rejected for the same reasons. As to claim 11, the claim includes the same new matter as claim 1 and is rejected for the same reasons. As to claim 12, the claim includes the same new matter as claim 1 and is rejected for the same reasons. As to claims 14-21, the claims are dependent on claim 12 but do not cure the deficiencies of that claim. Accordingly, they are rejected for the same reasons. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 3-12 and 14-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception without significantly more. As to claim 1, the claim recites: [a] method for generating an enrichment layer in a security graph stored in a graph database representing a cloud computing environment, comprising: detecting in a configuration code a plurality of code objects, each of the plurality of code objects corresponding to an instance deployed in the cloud computing environment; traversing the security graph via a query to the graph database to detect a plurality of nodes, each node representing an instance deployed from a first code object of the plurality of code objects; extracting a data field value from the first code object; storing the extracted data field value in a data field of a node representing the first code object in the graph database; and connecting the representation of the node representing the first code object to each node of the plurality of nodes in the graph database, wherein each node of the plurality of nodes does not store the extracted data field value Though the claim is directed to a statutory category (Step 1), under the broadest reasonable interpretation in light of the specification the above underlined elements recite a mental process because all of the above steps are performable by the human mind with aid of pen and paper. The claim therefore recites an abstract idea. (Step 2A Prong 1). None of the additional elements integrate the judicial exception into a practical application. (Step 2A Prong 2). References to storing the graph in a graph database and traversing a graph “via query to the graph database” only amount to instructions to implement the abstract idea using a generic computer and/or generic computing components. See M.P.E.P. § 2106.05(f). Traversing a graph via a query to the graph database is also insignificant extra-solution activity because it amounts to mere data-gathering. See M.P.E.P. § 2106.05(f). Note too that while the specification may refer to reducing storage requirements of a graph, the claims do not include the components or steps that reduce those storage requirements. (See paragraphs [0049] and [0077] of the specification). Avoiding duplicate information in a graph is also not a technical improvement because doing so in a graph created by the human mind with aid of pen and paper would still be advantageous in the sense the resulting paper graph would occupy less space on paper and be less complex. See M.P.E.P. § 2106.04(d)(1). The claim thus provides no technical improvement. Looking at the claim limitations as an ordered combination yields the same conclusion as that reached when looking at the elements individually. At best, their collective function is merely to implement an abstract idea using a generic computer or generic computing components in combination with necessary extra-solution data gathering. The claim does not include additional elements that amount to significantly more than the judicial exception for substantially the same reasons discussed above with respect to a practical application. (Step 2B). Note that reevaluation of the extra-solution activity per step 2B does not indicate that this element is anything more than what is well-understood, routine and conventional in the field, at least as evidenced by the fact that commercial products such as Neo4j and Cypher include traversal of graphs via queries. (See US 2014/0278590 at pars. [0081] and [0100]). As to claims 3-10, and 21 the features of these claims do not add any additional elements integrating the abstract idea into a practical application or amounting to significantly more at least because they do not add any additional elements. The additional elements of these claims are all part of a mental process and thus only describe the abstract idea. As to claim 11, the claim recites a judicial exception without significantly more for substantially the same reasons as claim 1. The addition of a “non-transitory computer readable medium having thereon instructions for causing a processing circuitry to execute a process” amounts to nothing more than implementing the abstract idea on a generic computer. See M.P.E.P. § 2106.05(f) As to claim 12, the claim recites a judicial exception without significantly more for substantially the same reasons as claim 1. The addition of “a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to” perform the recited operations amounts to nothing more than implementing the abstract idea on a generic computer. See M.P.E.P. § 2106.05(f) As to claims 14-20, the features of these claims do not add any additional elements integrating the abstract idea into a practical application or amounting to significantly more at least because they do not add any additional elements. The elements of these claims are all part of a mental process and thus only further describe the abstract idea. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to TODD AGUILERA whose telephone number is (571)270-5186. The examiner can normally be reached M-F 11AM - 7:30PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Hyung S Sough can be reached at (571)272-6799. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TODD AGUILERA/Primary Examiner, Art Unit 2192
Read full office action

Prosecution Timeline

Show 4 earlier events
Aug 06, 2025
Request for Continued Examination
Aug 11, 2025
Response after Non-Final Action
Oct 22, 2025
Non-Final Rejection mailed — §101, §112
Jan 22, 2026
Response Filed
May 18, 2026
Final Rejection mailed — §101, §112
Aug 17, 2026
Request for Continued Examination
Aug 18, 2026
Response after Non-Final Action
Sep 10, 2026
Non-Final Rejection mailed — §101, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737174
DEVICE FIRMWARE DESCRIPTORS
3y 8m to grant Granted Sep 15, 2026
Patent 12724602
UPDATING IMAGE FILES
3y 5m to grant Granted Sep 01, 2026
Patent 12688115
DYNAMIC FUNCTIONAL TESTING TOOL
2y 9m to grant Granted Jul 21, 2026
Patent 12681720
PATCH RELEASE METHOD, SERVER, AND TERMINAL DEVICE
4y 5m to grant Granted Jul 14, 2026
Patent 12657118
AUTOMATED GENERATION OF JAVA UNIT TESTS
2y 7m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
58%
Grant Probability
99%
With Interview (+57.6%)
3y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 509 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month