Prosecution Insights
Last updated: July 28, 2026
Application No. 18/072,238

AUTOMATIC GENERATION OF ATTACK PATTERNS FOR THREAT DETECTION

Final Rejection §103
Filed
Nov 30, 2022
Priority
May 13, 2022 — provisional 63/341,754 +1 more
Examiner
PHAM, PHUC H
Art Unit
2408
Tech Center
2400 — Computer Networks
Assignee
Forescout Technologies Inc.
OA Round
4 (Final)
89%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
158 granted / 177 resolved
+31.3% vs TC avg
Strong +19% interview lift
Without
With
+18.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
9 currently pending
Career history
195
Total Applications
across all art units

Statute-Specific Performance

§101
2.0%
-38.0% vs TC avg
§103
91.9%
+51.9% vs TC avg
§102
1.3%
-38.7% vs TC avg
§112
2.8%
-37.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 177 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The office action is in response to communication filed on January 08, 2026. Status of claims within the present application: Claims 1 – 20 are pending. Claims 1, 8, and 15are amended. Response to Amendment Applicant’s arguments with respect to independent claims 1, 8, and 15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 8, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over US 11658999 B2 to Peters et al., (hereinafter, “Peters”) in view of US 20230252136 A1 to Kim. Regarding claim 1, Peters teaches a method comprising: obtaining cyber threat intelligence (CTI) data comprising a plurality of methodologies used by a cyber threat, including extracting, from the CTI data, the plurality of methodologies as techniques, tactics, and procedures (TTPs); [Peters, col. 8 lines 9 – 19 discloses a method for automatically deriving actionable cybersecurity threat intelligence and mitigating cybersecurity threats via automated security investigations includes aggregating event data and identifying cybersecurity threat events and/or cybersecurity alerts S210, identifying and/or initializing an automated investigation workflow and one or more automated investigation tasks S220, executing the automated investigation workflow and the one or more automated investigation tasks S230, and automatically returning investigation data and deriving cybersecurity threat intelligence data S240. Col. 2 lines 23 – 30 discloses identifying the cybersecurity threat includes: extracting threat feature data from the corpus of investigation data, wherein the corpus of investigation data comprises a subset of data from the one or more streams of event data; evaluating the threat feature data against one or more threat identifying heuristics; and computing whether the threat feature data satisfy criteria of the one or more threat identifying heuristics. Col. 2 lines 32 – 39 discloses extracting threat feature data from the corpus of investigation data, wherein the corpus of investigation data comprises a subset of data from the one or more streams of event data; converting the threat feature data to a set of threat feature vectors; and predicting, by one or more cybersecurity threat machine learning models, a threat classification of one of the cybersecurity threat or not a cybersecurity threat based on an input of the set of threat feature vectors.] mapping, by a processing device, the TTPs used by the cyber threat to a plurality of network-detectable events associated with the TTPs; [Peters, col. 2 lines 42 – 47 discloses identifying a reference mapping between each of a plurality of distinct cybersecurity threat types and a plurality of distinct automated threat intelligence workflows; and identifying the one or more automated threat intelligence workflows for the cybersecurity threat based on evaluating the cybersecurity threat type against the reference mapping. Col. 8 lines 21 – 28 discloses S210, which includes sourcing security alert data/event data and identifying likely security alerts, may function to collect or receive event data and raw security alert data from one or more distinct sources of data. In one or more embodiments, the event data and/or security alert data may include, but should not be limited to, one or more of vendor alert data, continuous telemetry data, subscriber data, investigative data, other data, and/or the like.] and providing an indication of a potential network threat based on the attack pattern [Peters, col. 18 lines 36 – 48 discloses the cybersecurity threat intelligence data for a target validated security alert may include an indication of one or more of a root cause of the validated security alert, an identification of a state (e.g., active or dynamic threat) of the validated security alert, and/or a cybersecurity threat severity of the validated security alert. Accordingly, based on the evaluation of the cybersecurity threat intelligence data and/or reports, S250 may function selectively prescribe one of a plurality of distinct threat mitigation and/or threat handling routes to a given validated security alert that enables one or more of an escalation for handling the validated security alert or immediately executing a disposal or triage of the validated security alert.], but Peters does not teach generating an attack pattern for the cyber threat, wherein the attack pattern comprises the plurality of detectable events associated with the plurality of methodologies; detecting an occurrence of the plurality of network-detectable events of the attack pattern; However, Kim does teach generating an attack pattern for the cyber threat, [Kim, para. 100 discloses Malicious activity analysis information related to the input file is generated. Para. 105 discloses the analysis information in this step may include correlation analysis information capable of estimating a correlation for attack activity or an attacker by correlating analysis information previously stored in relation to the file or generated analysis information with each other.] wherein the attack pattern comprises the plurality of detectable events mapped from the TTPs and associated with the plurality of methodologies; [Kim, para. 99 discloses when an input file is transmitted through a mobile network, network transmission packet recombination technology, etc. is used for packets transmitted through network traffic, so that, when the input file is suspicious mobile malware, the file may be saved. The packet recombination technology recombines a series of packets corresponding to one piece of executable code in the collected network traffic, and when a file transmitted by the recombined packets is suspicious mobile malware, this file is saved. Para. 189 discloses the in-depth analysis may identify attack activity based on the extracted disassembled code or the data format converted into the predetermined format. Para. 190 discloses in the disassembled code, the opcode is a part of a machine language command that specifies an operation to be performed. In terms of cybersecurity, the opcode that causes attack activity or attack technique (TTP) may have a significantly similar value or format for each attack activity. Therefore, by analyzing the opcode and the ASM code, specific attack activity may be distinguished.] detecting an occurrence of the plurality of network-detectable events of the attack pattern; [Kim, para. 204 discloses analysis may include a step of identifying an attacker causing similar attack activity using the disassembled code and the AI-based machine learning result (S2440). Similarly, a specific example of attacker identification will be described later. Para. 205 discloses include taint analysis capable of determining whether there is attack activity through memory analysis of the system at a specific point in time even in the case of fileless malware. Para. 206 discloses The in-depth analysis is based on processing the disassembled code of the executable file, and identification of the attack technique or attacker, or taint analysis accordingly may be selectively performed.] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Kim’s system with Peters’s system, with a motivation for static analysis information, dynamic analysis information, in-depth analysis information, correlation analysis information, etc. for a single file may be integrated and analyzed for accurate attack technique and attacker identification. Integrated analysis removes an overlap between pieces of analysis information, and common information between pieces of analysis information may be used to increase accuracy. [Kim, para. 107] Regarding claims 8 and 15, they recite features similar to features within claim 1, therefore, they are rejected in a similar manner. Claims 2 – 7, 9 – 14, and 16 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over US 11658999 B2 to Peters et al., (hereinafter, “Peters”) in view of US 20230252136 A1 to Kim in further view of US 20230247048 A1 to Samosseiko et al., (hereinafter, “Samosseiko”). As per claim 2, modified Peters teaches the method of claim 1, further comprising: determining a subset of the plurality of methodologies that are detectable within a network; [Peters, col. 2 lines 24 – 30 discloses extracting threat feature data from the corpus of investigation data, wherein the corpus of investigation data comprises a subset of data from the one or more streams of event data; evaluating the threat feature data against one or more threat identifying heuristics; and computing whether the threat feature data satisfy criteria of the one or more threat identifying heuristics.] wherein generating the attack pattern for the cyber threat comprises generating the attack pattern to comprise the plurality of network-detectable events associated with the subset of the plurality of methodologies. [Peters, col. 17 lines 29 – 46 discloses automatically create cybersecurity threat intelligence collateral (“threat intelligence collateral”) for handling a given validated security alert. In one or more embodiments, S240 may function to automatically create threat intelligence collateral based on cybersecurity threat intelligence data. In such embodiments, executing one or more investigative tasks, may function to automatically perform an integrating of select cybersecurity intelligence data into one or more pre-fabricated pieces of collateral. As a non-limiting example, S240 may function to merge or populate one or more portions of a corpus of investigation data and/or cybersecurity intelligence data into one or more sections of a cybersecurity threat reporting template or reporting document. In such embodiments, S240 may function to intelligently format the cybersecurity threat intelligence data and/or investigation analysis data into one or more data structures that may be presented or otherwise, displayed via the investigation reporting document.] Regarding claim 3, modified Peters teaches the method of claim 1, but Peters does not teach further comprising: determining non-detectable events in the plurality of methodologies: and filtering out the non-detectable events from the plurality of methodologies, wherein the attack pattern is generated without the non-detectable events. However, Samosseiko does teach further comprising: determining non-detectable events in the plurality of methodologies: and filtering out the non-detectable events from the plurality of methodologies, wherein the attack pattern is generated without the non-detectable events. [Samosseiko, para. 82 discloses the threat management facility may be configured to adjust reporting of event data through the filter in response to a change in the filtered event stream received from the endpoint. The threat management facility may be configured to adjust reporting of event data through the filter when the filtered event stream indicates a compromised security state of the endpoint. The threat management facility may be configured to adjust reporting of event data from one or more other endpoints in response to a change in the filtered event stream received from the endpoint. The threat management facility may be configured to adjust reporting of event data through the filter when the filtered event stream indicates a compromised security state of the endpoint. The threat management facility may be configured to request additional data from the data recorder when the filtered event stream indicates a compromised security state of the endpoint. The threat management facility may be configured to request additional data from the data recorder when a security agent of the endpoint reports a security compromise independently from the filtered event stream.] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Samosseiko’s system with Peters’s system, with a motivation for when a security event is detected, the source of the security event may serve as a starting point within the event graph 500, which may then be traversed backward to identify a root cause using any number of suitable cause identification rules. The event graph 500 may then usefully be traversed forward from that root cause to identify other computing objects that are potentially tainted by the root cause so that a more complete remediation can be performed. [Samosseiko, para. 98] As per claim 4, modified Peters teaches the method of claim 3, further comprising: identifying the potential network threat as the cyber threat based on detecting the occurrence of the plurality of network-detectable events of the attack pattern. [Peters, col. 8 lines 21 – 28 discloses S210, which includes sourcing security alert data/event data and identifying likely security alerts, may function to collect or receive event data and raw security alert data from one or more distinct sources of data. In one or more embodiments, the event data and/or security alert data may include, but should not be limited to, one or more of vendor alert data, continuous telemetry data, subscriber data, investigative data, other data, and/or the like.] Regarding claim 5, modified Peters teaches the method of claim 1, but Peters does not teach wherein the attack pattern comprises a sequential order of the plurality of network-detectable events. However, Samosseiko does teach wherein the attack pattern comprises a sequential order of the plurality of network-detectable events. [Samosseiko, para. 7 discloses identifying a first set of indicators in the detections associated with use of a first malware tool on the plurality of endpoints, identifying a second set of indicators in the detections associated with use of a second malware tool on the plurality of endpoints, grouping the first and second sets of indicators by customer, identifying a progressive deployment of malware on an enterprise network for one of the customers based on a sequential use of the first malware tool and the second malware tool in a pattern indicating a malicious breach of the enterprise network; and notifying the one of the customers of a possible breach of the enterprise network based on the progressive deployment of malware. Para. 8 grouping the first and second sets of indicators by customer; identifying a progressive deployment of malware on an enterprise network for one of the customers based on a sequential use of the first malware tool and the second malware tool in a pattern indicating a malicious breach of the enterprise network; and notifying the one of the customers of a possible breach of the enterprise network based on the progressive deployment of malware.] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Samosseiko’s system with Peters’s system, with a motivation for when a security event is detected, the source of the security event may serve as a starting point within the event graph 500, which may then be traversed backward to identify a root cause using any number of suitable cause identification rules. The event graph 500 may then usefully be traversed forward from that root cause to identify other computing objects that are potentially tainted by the root cause so that a more complete remediation can be performed. [Samosseiko, para. 98] Regarding claim 6, modified Peters teaches the method of claim 1, but Peters does not teach further comprising: detecting an occurrence of a threshold number of the plurality of network-detectable events within a maximum period of time, wherein providing the indication of the potential network threat comprises providing the indication of the potential network threat based on detecting the occurrence of the threshold number of the plurality of network-detectable events within the maximum period of time. However, Samosseiko does teach further comprising: detecting an occurrence of a threshold number of the plurality of network-detectable events within a maximum period of time [Samosseiko, para. 9 discloses identifying the progressive deployment of malware may include weighting and summing scores for the first and second sets of indicators according to one or more criteria. The one or more criteria may include at a time of occurrence, a frequency of occurrence, and a number of occurrences. The detections may include malware detections from local security agents executing on the plurality of endpoints.] wherein providing the indication of the potential network threat comprises providing the indication of the potential network threat based on detecting the occurrence of the threshold number of the plurality of network-detectable events within the maximum period of time. [Samosseiko, para. 196 discloses the one or more rules or criteria may be associated with a characteristic of an indicator of breach. For example, and without limitation, the identification may be based on one or more criteria such as a time of occurrence, a frequency of occurrence, and a number of occurrences. Thus, for example, while a single deactivation of antivirus software and installation of software may be dismissed as benign, an indicator of breach may be created in response to a large number of endpoints of a customer deactivating antivirus software and installing other software or updating registry information in a short span of time. Para. 197 discloses There may also be instances where a nominal indicator of breach is benign and is, in fact, a false positive indicator. For example, a software installation across a large number of endpoints in a short amount of time may indicate a system-wide upgrade of customer software on endpoints. Thus, in some cases it may be hard to distinguish malicious patterns from benign patterns when viewed in isolation.] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Samosseiko’s system with Peters’s system, with a motivation for when a security event is detected, the source of the security event may serve as a starting point within the event graph 500, which may then be traversed backward to identify a root cause using any number of suitable cause identification rules. The event graph 500 may then usefully be traversed forward from that root cause to identify other computing objects that are potentially tainted by the root cause so that a more complete remediation can be performed. [Samosseiko, para. 98] Regarding claim 7, modified Peters teaches the method of claim 1, but Peters does not teach further comprising ranking different sets of CTI data based on a number of network mappable TTPs that are present in each of the different sets. However, Samosseiko does teach further comprising ranking different sets of CTI data based on a number of network mappable TTPs that are present in each of the different sets. [Samosseiko, para. 6 discloses the computer program product may include code that causes the one or more computing devices to perform the steps of identifying a plurality of patterns indicating a plurality of ransomware attacks staging on enterprise networks of one or more customers; scoring the plurality of ransomware attacks to provide a ranking of severity; and notifying one of the customers of a most severe one of the plurality of ransomware attacks according to the ranking] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Samosseiko’s system with Peters’s system, with a motivation for when a security event is detected, the source of the security event may serve as a starting point within the event graph 500, which may then be traversed backward to identify a root cause using any number of suitable cause identification rules. The event graph 500 may then usefully be traversed forward from that root cause to identify other computing objects that are potentially tainted by the root cause so that a more complete remediation can be performed. [Samosseiko, para. 98] Regarding claims 9 – 13, they recite features similar to features within claims 2 – 6, therefore, they are rejected in a similar manner. Regarding claim 14, modified Peters teaches the system of claim 8, but Peters does not teach wherein the plurality of methodologies comprises techniques, tactics, and procedures associated with the cyber threat. However, Samosseiko does teach wherein the plurality of methodologies comprises techniques, tactics, and procedures associated with the cyber threat. [Samosseiko, para. 9 discloses the detections may include malware detections from antivirus scanners executing on the plurality of endpoints. The pattern may not indicate the malicious breach when a use of at least one of the first malware tool and the second malware tool has a second pattern indicative of non-malicious penetration testing of the enterprise network by the customer. The method may further include the step of displaying a timeline of a plurality of indicators from the first and second sets of indicators in a user interface. One or more of the plurality of indicators displayed in the user interface may be interactively linked to supporting information accessible by viewer of the user interface. The indicators may include indicia of one or more of remote machine login attempts, changes to anti-malware software, lateral movement attempts, software installations, presence of low or unknown reputation files, and attempted access to low or unknown reputation network locations.] Therefore, it would have been obvious to one of ordinary skill within the art before the effective filling date to combine Samosseiko’s system with Peters’s system, with a motivation for when a security event is detected, the source of the security event may serve as a starting point within the event graph 500, which may then be traversed backward to identify a root cause using any number of suitable cause identification rules. The event graph 500 may then usefully be traversed forward from that root cause to identify other computing objects that are potentially tainted by the root cause so that a more complete remediation can be performed. [Samosseiko, para. 98] Regarding claims 16 – 20, they recite features similar to features within claims 2 – 6, therefore, they are rejected in a similar manner. Conclusion Pertinent prior art made of record however not relied upon: US 10916351 B1 to Oh et al. “Provided is a method for classifying a cyber-attack performed in a computing device having an artificial neural network. The method comprises obtaining a plurality of features extracted from collected packets and inputting the plurality of features into the artificial neural network and using data output from the artificial neural network to determine a type of cyber-attack indicated by the collected packet.” US 20220272111 A1 to Rao et al. “In one aspect, a method for implementing a cloud-platform push for one or more known data breaches includes the step of, for each data breach of the one or more known data breaches, providing a functionality that maps one or more kill chains or Tactics, Techniques, and Procedures (TTPs) for a specified set of security dimensions. A step includes generating a security rule for each mapped kill chain or TTP based on the functionality that maps the one or more kill chains or Tactics, Techniques, and Procedures (TTPs) for a specified set of security dimensions. A step includes pushing the security rule to an enterprise so that the enterprise is aware of a vulnerability in the data breach. A step includes generating a customized posture for a Virtual private cloud (VPC) in the enterprise's cloud-based network. A step includes determining that the data breach can occur within the enterprise's cloud-based network.” Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Phuc Pham whose telephone number is (571)272-8893. The examiner can normally be reached Monday - Thursday 7:30 AM - 4:30 PM; Friday 8:00 AM - 12:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached on (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /P.P./Patent Examiner, Art Unit 2408 /LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Show 7 earlier events
Aug 18, 2025
Applicant Interview (Telephonic)
Sep 05, 2025
Request for Continued Examination
Sep 16, 2025
Response after Non-Final Action
Oct 08, 2025
Non-Final Rejection mailed — §103
Jan 08, 2026
Response Filed
Apr 21, 2026
Final Rejection mailed — §103
Jul 20, 2026
Request for Continued Examination
Jul 26, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683760
TERMINAL DEVICE, COMPUTER PROGRAM, COMMUNICATION SYSTEM, AND COMMUNICATION METHOD
3y 7m to grant Granted Jul 14, 2026
Patent 12683770
SYSTEMS AND METHODS FOR SECURE MODULAR HARDWARE BINDING
2y 11m to grant Granted Jul 14, 2026
Patent 12676746
RECOVERY USING AN ENCRYPTED FALLBACK KEY IN METADATA
2y 2m to grant Granted Jul 07, 2026
Patent 12652160
ANONYMOUS, AUTHENTICATED AND PRIVATE SATELLITE TASKING SYSTEM
3y 5m to grant Granted Jun 09, 2026
Patent 12645825
CLIENT-SIDE ENCRYPTION WITH LOW-COST INTEGRITY CHECK
3y 5m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+18.8%)
2y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 177 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month