Prosecution Insights
Last updated: October 04, 2026
Application No. 18/080,562

COMPLIANCE MONITORING

Non-Final OA §103
Filed
Dec 13, 2022
Priority
Dec 19, 2016 — continuation of 10/652,278 +1 more
Examiner
BINCZAK, BRANDON MICHAEL
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Forescout Technologies Inc.
OA Round
5 (Non-Final)
39%
Grant Probability
At Risk
5-6
OA Rounds
0m
Est. Remaining
72%
With Interview

Examiner Intelligence

Grants only 39% of cases
39%
Career Allowance Rate
25 granted / 64 resolved
-18.9% vs TC avg
Strong +33% interview lift
Without
With
+33.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
28 currently pending
Career history
106
Total Applications
across all art units

Statute-Specific Performance

§101
8.2%
-31.8% vs TC avg
§103
55.8%
+15.8% vs TC avg
§102
9.7%
-30.3% vs TC avg
§112
26.2%
-13.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 64 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are pending. Claims 1, 11, and 16 are independent. Claims 1, 8, 11, 14-17, and 20 are amended. Response to Arguments Applicant’s arguments, see page(s) 7, filed 8/17/2026, with respect to the objection(s) to claim(s) 14 have been fully considered and are persuasive. The associated objection(s) to the listed claim(s) has/have been withdrawn. Applicant’s arguments, see page(s) 7, filed 8/17/2026, with respect to the rejection of claim(s) 16-20 under 35 U.S.C. 112(b) have been fully considered and are persuasive. The associated rejection(s) to the listed claim(s) has/have been withdrawn. Applicant’s arguments, see page(s) 7, filed 8/17/2026, with respect to the rejection of claim(s) 8 under 35 U.S.C. 112(d) have been fully considered and are persuasive. The associated rejection(s) to the listed claim(s) has/have been withdrawn. Applicant’s arguments, see page(s) 7-10, filed 8/17/2026, with respect to the rejection of claim(s) 1-20 under 35 U.S.C. 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of TARAZ (Doc ID US 20070124803 A1). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 8-11, 15-17, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), and further in view of WALKER et al (Doc ID US 20110167470 A1) and TARAZ (Doc ID US 20070124803 A1). Regarding claim 1: KULKARNI teaches: wherein each compliance rule of the set of compliance rules is associated with a respective weight ((19) Col 5 lines 37-39 "As illustrated in FIG. 3, Rule 1 can have a weight of 60, while Rule 12 can possess a weight of 40, for example."); performing, by the processing device, a compliance scan on the device based on the set of compliance rules ((18) Col 5 lines 13-17 "... Such compliance scoring component 220 can then examine associated logic of the rules involved ..., and generate a report of the compliance score. For example, if the score represents 100% the machine is fully compliant with the security policy."); determining a compliance level of the device based on aggregating results of the compliance scan across the set of compliance rules in accordance with the respective weight associated with each compliance rule ((20) Col 5 lines 40-43 [0085] "... a benchmark can be defined as a collection of security rules and can be scored for compliance based on weights of rules that evaluate to true. ..."); WALKER teaches the following limitation(s) not taught by KULKARNI: A method, performed by a processing device of a compliance monitoring device, comprising: determining, by the processing device, a classification of a device ([0096] "... Common policy specifications can be specific to a particular device, to all devices in a particular group, to a particular device type or device OS (e.g. Windows Mobile.TM. OS, BlackBerry Storm.TM., or Symbian.TM. OS), or to any combination of these."); Examiner notes that the reference does not recite a specific step of determining a device classification; it proceeds to choose sets of policies directed to the same device classifications, which makes the step of determining the classification implicit. accessing a set of compliance rules that are associated with the classification of the device ([0096] "... Common policy specifications can be specific to a particular device, to all devices in a particular group, to a particular device type or device OS (e.g. Windows Mobile.TM. OS, BlackBerry Storm.TM., or Symbian.TM. OS), or to any combination of these.") initiating an action based on the compliance level for the device, including initiating a patch service associated with the device, initiating an update service associated with the device, or changing network access of the device ([0078] "... Such interception and processing can be done ... to bring a mobile device 2011-2014 into compliance with required policies, to block mobile device 2011-2014 access to applications servers 2020-2022 when the mobile device 2011-2014 is not in compliance with required policies ..."); and Assigning weights to compliance rules, performing a compliance scan based on the rules, and determining a device’s compliance level based on the rules are known techniques in the art, as demonstrated by KULKARNI. Further, classifying a device, applying compliance rules associated with the classification, and taking an action on the device based on its compliance with the rules are known techniques in the art, as demonstrated by WALKER. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the weighted rules and compliance scan of KULKARNI with the device classification and compliance actions of WALKER with the motivation to apply targeted rules based on the device to which they are being applied, and to take steps to bring a device into compliance or to prevent a device not in compliance from accessing resources. This makes a system without targeted rules more streamlined. TARAZ teaches the following limitations not taught by the above combination: performing a second compliance scan on the device after the action, to determine a second compliance level of the device, wherein network access is granted to the device when the second compliance level satisfies a threshold (Fig. 3 and [0039] "If the computer has not achieved compliance sufficient to satisfy the first compliance matrix L1, the computer compliance may be checked against a second compliance matrix L2 (114) .... Remediation may be provided at any step to help bring the computer compliance score into compliance with higher level compliance matrixes." and [0028] "... base the network access decision on the score by determining whether the attaching device meets or exceeds the minimum standard level …"). Performing additional compliance scans on devices is/are known technique(s) in the art, as demonstrated by TARAZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI and WALKER with the rescan of TARAZ with the motivation to ensure that devices which were previously deficient in their compliance scanned, and then fixed, are scanned again to ensure that any changes made to the device bring the device into compliance or do not move the device out of compliance. This is a known technique which has been used to improve similar devices. Regarding claim 8: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, wherein the action is initiated based on a comparison of the compliance level of the device with a first threshold (TARAZ [0028] "Once a compliance score and authorization level have been determined, .... The policy server may base the network access decision on the score by determining whether the attaching device meets or exceeds the minimum standard level …"). Comparing a compliance score to a threshold to determine a follow-on action is a known technique in the art, as demonstrated by TARAZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the compliance score threshold of TARAZ with the motivation to withhold actions taken against devices which may be non-compliant, but not to a degree requiring immediate action. Regarding claim 9: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, wherein the classification indicates an operating system of the device (WALKER [0096] "... Common policy specifications can be specific to a particular device, to all devices in a particular group, to a particular device type or device OS (e.g. Windows Mobile.TM. OS, BlackBerry Storm.TM., or Symbian.TM. OS), or to any combination of these."). Classifying a device by its operating system (OS) is a known technique in the art, as demonstrated by WALKER. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the OS classification of WALKER with the motivation to apply compliance rules which allow or prohibit devices depending on their OS, so that devices using an unsupported or unsecure OS can be prevented from accessing resources. Regarding claim 10: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, wherein the classification indicates a functionality of the device (WALKER [0096] "... Common policy specifications can be specific to a particular device, to all devices in a particular group, to a particular device type or device OS (e.g. Windows Mobile.TM. OS, BlackBerry Storm.TM., or Symbian.TM. OS), or to any combination of these."). Classifying a device by its function is a known technique in the art, as demonstrated by WALKER. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the functionality classification of WALKER with the motivation to apply compliance rules which allow or prohibit devices depending on their functionality, so that devices meant for undesired purposes can be prevented or restricted from accessing resources. Regarding claim 11: KULKARNI teaches: A system comprising: a memory; and a processing device of a compliance monitoring system, operatively coupled to the memory, to ((41) Col 9 lines 46-50 "The computer 1012 includes a processing unit 1014, a system memory 1016, and a system bus 1018. The system bus 1018 couples ... the system memory 1016 to the processing unit 1014."): The remainder of this claim’s limitations are rejected with the same prior art mapping and justification, mutatis mutandis, as its counterpart claim 1. Regarding claims 15, 16, and 17: This claim is rejected with the same justification, mutatis mutandis, as its counterpart claims 1 and 8 above. Regarding claim 20: The combination of KULKARNI, WALKER, and TARAZ teaches: The non-transitory computer readable medium of claim 16, wherein changing the network access of the device comprises, in response to the compliance level for the device being below another threshold, granting limited network access to the device (TARAZ [0028] "The policy server may base the network access decision on the score by determining whether the attaching device meets or exceeds the minimum standard .... The result of this comparison will govern whether the user is granted ... limited network access ..."). Restricting network access to a device as an action taken in response to a compliance scan is a known technique in the art, as demonstrated by TARAZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the restricted network access of TARAZ with the motivation to control the access levels of devices based on their compliance with policies. It is obvious to restrict access to a device which has not achieved full compliance with applied policies. Claims 2, 5, 7, 12, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), WALKER et al (Doc ID US 20110167470 A1), and TARAZ (Doc ID US 20070124803 A1) as applied to claims 1, 11, and 17 above, and further in view of KOHLI et al (Doc ID US 20120102543 A1). Regarding claim 2: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, KOHLI teaches the following limitation(s) not taught by the above combination: wherein the compliance scan of the device is performed periodically ([0080] "The audit management system, for example, allows the user to specify a specific schedule start date and end date and time, a recurring schedule … etc."). Scanning a device for compliance on a periodic schedule is a known technique in the art, as demonstrated by KOHLI. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the scanning schedule of KOHLI with the motivation to ensure that devices are regularly scanned so that changes to a device which bring it out of compliance are discovered. Regarding claim 5: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, KOHLI teaches the following limitation(s) not taught by the above combination: further comprising: performing another compliance scan of the device based on a security policy ([0080] "The audit management system, for example, allows the user to specify a specific schedule start date and end date and time, a recurring schedule … etc."). Scanning a device for compliance based on a policy is a known technique in the art, as demonstrated by KOHLI. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the scanning schedule of KOHLI with the motivation to grant the user the ability to have scans performed for any reason, including adherence to a policy. Regarding claim 7: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, KOHLI teaches the following limitation(s) not taught by the above combination: wherein the compliance scan of the device is performed automatically according to a security policy ([0080] "… the audit management system allows the process of auditing to be triggered through … an event driven scheduling, etc."). Scanning a device for compliance based on a policy is a known technique in the art, as demonstrated by KOHLI. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the scanning schedule of KOHLI with the motivation to grant the user the ability to have scans performed for any reason, including adherence to a policy. Regarding claim(s) 12 and 18: The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 2 above. Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), WALKER et al (Doc ID US 20110167470 A1), and TARAZ (Doc ID US 20070124803 A1) as applied to claims 1 and 11 above, and further in view of KEOHANE et al (Doc ID US 20090077631 A1). Regarding claim 3: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, KEOHANE teaches the following limitation(s) not taught by the above combination: wherein determining the classification of the device is based on a media access control (MAC) address of the device ([0049] "… process 500 may determine the type of device using a media access control (MAC) address of the device."). Determining a device type based on its MAC address is a known technique in the art, as demonstrated by KEOHANE. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the MAC address categorization of KEOHANE with the motivation to use a well-known standard which is present on nearly every device which is able to connect to a network. Regarding claim 13: This claim is rejected with the same justification, mutatis mutandis, as its counterpart claim 3 above. Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), WALKER et al (Doc ID US 20110167470 A1), and TARAZ (Doc ID US 20070124803 A1) as applied to claims 1 and 11 above, and further in view of GUPTA et al (Doc ID US 20160359915 A1). Regarding claim 4: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, GUPTA teaches the following limitation(s) not taught by the above combination: wherein determining the classification of the device is based on traffic information associated with the device ([0050] "… Using network traffic data …, the network traffic monitoring system can determine the type of devices existing in the network …"). Identifying a network device based on its network traffic is a known technique in the art, as demonstrated by GUPTA. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the network device identification of GUPTA with the motivation to provide the system with a simple way to identify devices which are active on a network. Regarding claim 14: This claim is rejected with the same justification, mutatis mutandis, as its counterpart claim 4 above. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), WALKER et al (Doc ID US 20110167470 A1), and TARAZ (Doc ID US 20070124803 A1) as applied to claim 1 above, and further in view of WIEGLAND et al (Doc ID US 20070055752 A1). Regarding claim 6: The combination of KULKARNI, WALKER, and TARAZ teaches: The method of claim 1, WIEGLAND teaches the following limitation(s) not taught by the above combination: wherein performing the compliance scan is performed in response to detecting the device being communicatively coupled to the network ([0031] "… device 110 may provide an indication of a desire to connect to destination network 170.", [0035] "In stage 204, communication device 110 connects first to compliance network 150.", and [0036] "In stage 206, compliance network 150 checks if communication device 110 is sufficiently in compliance with the up-to-date policies of destination network 170."). Performing a compliance scan on a device that is newly connected to a network is a known technique in the art, as demonstrated by WIEGLAND. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, and TARAZ with the new device compliance scan of WIEGLAND with the motivation to ensure that new devices are scanned immediately to prevent access by device with unsafe configurations. Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over KULKARNI et al (Doc ID US 8533841 B2), WALKER et al (Doc ID US 20110167470 A1), TARAZ (Doc ID US 20070124803 A1), and KOHLI et al (Doc ID US 20120102543 A1) as applied to claim 18 above, and further in view of KEOHANE et al (Doc ID US 20090077631 A1). Regarding claim 19: The combination of KULKARNI, WALKER, TARAZ, and KOHLI teaches: The non-transitory computer readable medium of claim 18, KEOHANE teaches the following limitation(s) not taught by the above combination: wherein determining the classification of the device is based on a media access control (MAC) address of the device ([0049] "… process 500 may determine the type of device using a media access control (MAC) address of the device."). Determining a device type based on its MAC address is a known technique in the art, as demonstrated by KEOHANE. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the weighted compliance scan and remedial actions for classified devices of KULKARNI, WALKER, TARAZ, and KOHLI with the MAC address categorization of KEOHANE with the motivation to use a well-known standard which is present on nearly every device which is able to connect to a network. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703)756-4528. The examiner can normally be reached M-F 0800-1700. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRANDON BINCZAK/Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Show 14 earlier events
Mar 07, 2026
Interview Requested
Mar 12, 2026
Examiner Interview Summary
Mar 12, 2026
Applicant Interview (Telephonic)
Apr 03, 2026
Response Filed
May 15, 2026
Final Rejection mailed — §103
Aug 17, 2026
Request for Continued Examination
Aug 21, 2026
Response after Non-Final Action
Sep 03, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730897
Automation Platform for Pentest Collaboration
3y 8m to grant Granted Sep 08, 2026
Patent 12695767
PREDICTIVE BAD EVENT ALERT GENERATION
4y 2m to grant Granted Jul 28, 2026
Patent 12694091
SYSTEMS AND METHODS FOR COLLECTIVE ATTESTATION OF SPDM-ENABLED DEVICES IN AN INFORMATION HANDLING SYSTEM (IHS)
3y 4m to grant Granted Jul 28, 2026
Patent 12634133
COMPUTING SYSTEMS AND METHODS FOR PROTECTING APPLICATION PROGRAMMING INTERFACES WITH TWO-FACTOR AUTHENTICATION
3y 4m to grant Granted May 19, 2026
Patent 12470534
PARTIAL POOL CREDENTIALLING AUTHENTICATION SYSTEM
2y 6m to grant Granted Nov 11, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
39%
Grant Probability
72%
With Interview (+33.4%)
3y 1m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 64 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month