Prosecution Insights
Last updated: August 06, 2026
Application No. 18/156,937

DETECTING OF BUSINESS EMAIL COMPROMISE

Final Rejection §103
Filed
Jan 19, 2023
Priority
Jan 26, 2016 — provisional 62/287,378 +2 more
Examiner
CHEN, SHIN HON
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Zapfraud Inc.
OA Round
4 (Final)
86%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
698 granted / 807 resolved
+28.5% vs TC avg
Moderate +13% lift
Without
With
+13.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
25 currently pending
Career history
836
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
43.6%
+3.6% vs TC avg
§102
25.7%
-14.3% vs TC avg
§112
4.0%
-36.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 807 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-3, 5, 7-10, 12-18 and 20-24 have been examined. Response to Arguments Applicant's arguments filed 6/17/26 have been fully considered but they are not persuasive. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Specifically, as explained in the previous office action, Osipkov discloses use of address book which contains display name and email address to identify whether sender is trusted. Although Osipkov does not explicitly disclose determining whether email poses risk when display name is same but e-mail address is different (Osipkov: [0022]: automated process to determine whether the message is desired or unwanted, identify properties of the message including name of the sender; [0024]: message sent from verified sender who are identified in an address book of the user, the email address book maintained by the system to determine whether sender is trusted party), Dreller teaches common phishing email that contains trusted display name but suspicious e-mail address (Dreller: [0051]-[0052]: search display name and determine non-domain phishing to identify legitimate display name with phishing address). Lastly, Starink is relied upon for protective measure of replacing suspicious content when email is determined to pose risk (Starink: [0031]-[0032]; [0047]: replace the URL with an alternate link to a trusted resource) while the determining step is disclosed by combination of Osipkov and Dreller. Therefore, Applicant’s argument is not persuasive in light of above explanation. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5, 7, 10, 13-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Osipkov U.S. 2012/0246725 (hereinafter Osipkov) in view of Dreller et al. U.S. 2014/0082726 (hereinafter Dreller) and further in view of Starink U.S. 2015/0381653 (hereinafter Starink). As per claim 1 and 14, Osipkov discloses a system/method for detection of email risk, comprising: a processor configured to: maintain data associated with a second party indicating that a first party is considered trsuted by the second party, wherein the data includes a display name and email address of the first party in at least one of whitelist or an address book associated with the second party (Osipkov: [0022]: automated process to determine whether the message is desired or unwanted, identify properties of the message including name of the sender; [0024]: message sent from verified sender who are identified in an address book of the user, the email address book maintained by the system to determine whether sender is trusted party); receive a message addressed to the second party from a third party (Osipkov: [0019]: receive message addressed to the user); determine that the message poses a risk in response to determining that a display name of the first party matches a display name of the third party (Osipkov: [0022]-[0024]: determine if name of the sender is in the address book); responsive to determining that the message poses a risk, automatically perform a security action comprising at least one of marking the message up with a warning or quarantining the message (Osipkov: [0007]: exclude the message; [0021]: quarantining the message). and a memory coupled to the processor and configured to provide the processor with instructions. Osipkov discloses determining name of the sender to determine whether sender is verified sender (Osipkov: [0024]). Osipkov does not explicitly disclose determining display name of sender is same as trusted sender, but an email address of the third party and an email address of the first party are different. However, Dreller discloses identifying phishing email that are purporting to be from trusted domain but are actually from another domain not owned by the legitimate domain (Dreller: [0051]-[0052]: search display name and determine non-domain phishing to identify legitimate display name with phishing address). It would have been obvious to one having ordinary skill in the art to identify suspicious email with legitimate display name but suspicious domain address because Osipkov and Dreller are analogous art. The motivation to combine would be to filter out seemingly legitimate email based on additional analysis of metadata. Osipkov discloses identifying link contained in email communication (Osikpov: [0021]: evaluate content of messages in order to differentiate unwanted messaged from desirable messages… examine content associated with a message, such as attached files and hyperlinks). Osipkov does not explicitly disclose responsive to determining that the message comprises a hyperlink, cause a proxying of loading of content associated with the hyperlink so that a request from the second party for the content associated with the hyperlink is received by a proxy (Starink: [0031]-[0032]; [0047]: replace the URL with an alternate link to a trusted resource). It would have been obvious to one having ordinary skill in the art to replace suspicious link contained in email with proxy link to trusted resource because they are analogous art. The motivation would be to protect user from accessing malicious content. As per claim 2 and 15, Osipkov as modified discloses the limitations of claims 1 and 14 respectively. Osipkov as modified further discloses wherein a request associated with the hyperlink causes the system to: determine whether a site associated with the hyperlink is associated with risk; and based on the determination whether the site associated with the hyperlink is associated with risk, cause a warning to be displayed or redirection to be made (Osipkov: [0021]; Starink: [0031]-[0032]). Same rationale applies here as above in rejecting claims 1 and 14. As per claim 3 and 16, Osipkov as modified discloses the limitations of claims 2 and 15 respectively. Osipkov as modified further discloses determining whether the site associated with the hyperlink is associated with risk before the request associated with the hyperlink is received (Osipkov: [0021]: examine content before user accesses the link; Starink: [0031]-[0032]; [0047]: once a link has been found to be associated with a potentially malicious resource, the modifier module may be executed to replace the link with an alternate link/proxy link). Same rationale applies here as above in rejecting claim 1. As per claim 5 and 18, Osipkov as modified discloses the limitations of claims 1 and 14 respectively. Osipkov as modified further discloses in response to receiving a request associated with the hyperlink, and based on a result of the verification, causing a warning to be displayed or a redirection to be made (Starink: [0086]-[0094]). It would have been obvious to one having ordinary skill in the art to redirect user to intermediary node for additional security analysis because the references are analogous art involving detection of malicious email communications. The motivation to combine would be to track and monitor communication behaviors associated with unknown resources prior to determining whether it’s malicious or safe. As per claim 7, Osipkov as modified discloses the system of claim 1. Osipkov as modified further discloses wherein the security action comprises at least one of: initiating a multi-factor authentication verification, modifying the display name of the message, transmitting a notification or a warning to an address associated with the second party, collecting information comprising at least one of an IP address, a cookie, and browser version information, and transmitting a confirmation request to an address associated with the first party, the confirmation request comprising at least a portion of the message (Osipkov: [0021]-[0022]; Dreller: [0054]; Starink: [0057]). It would have been obvious to one having ordinary skill in the art to take various security measures in response to detection of suspicious/malicious communication as well known in the art. As per claim 10, Osipkov as modified discloses the system of claim 1. Vitaldevara as modified further discloses wherein the risk determination is further based at least in part on at least one of: an indication of spoofing, an indication of account takeover, a presence of a reply-to address, a geographic inconsistency, detection of a new signature file, detection of a new display name, detection of high-risk email content, detection of an abnormal delivery path, and based on analysis of attachments (Vitaldevara: [0016]-[0018]). As per claim 13 and 20, Osipkov discloses a system/method for determining whether an electronic message is deceptive, comprising: 13. A system for determining whether an electronic message is deceptive, comprising: a processor configured to: automatically determine whether a first party is considered trusted by a second party, based on accessing data associated with a second party including at least one of a whitelist or an address book (Osipkov: [0022]: automated process to determine whether the message is desired or unwanted, identify properties of the message including name of the sender; [0024]: message sent from verified sender who are identified in an address book of the user); receive a message addressed to the second party from a third party (Osipkov: [0019]: receive message addressed to the user); determine if the received message poses a risk by determining that a display name of the first party in the data and a display name of third party in the message are the same (Osipkov: [0022]-[0024]: determine if name of the sender is in the address book); responsive to a determination that the first party is not considered trusted by the second party, determine that the message is not deceptive (Osipkov: [0021]); responsive to the message being found deceptive, automatically perform a security action comprising at least one of marking the message up with a warning or quarantining the message (Osipkov: [0007]: exclude the message; [0021]: quarantining the message); and responsive to the message being found not deceptive and not comprising a hyperlink, deliver the message to the second party (Osipkov: [0024]: deliver message to user by placing in the messages in “trusted mail” folder). and a memory coupled to the processor and configured to provide the processor with instructions. Osipkov discloses determining name of the sender to determine whether sender is verified sender (Osipkov: [0024]). Osipkov does not explicitly disclose determining display name of sender is same as trusted sender, but an email address of the third party and an email address of the first party are different; responsive to the first party is considered trusted by the second party, and the received message is determined to pose a risk, determine that the message is deceptive. However, Dreller discloses identifying phishing email that are purporting to be from trusted domain but are actually from another domain not owned by the legitimate domain (Dreller: [0051]-[0052]: search display name and determine non-domain phishing to identify legitimate display name with phishing address). It would have been obvious to one having ordinary skill in the art to identify suspicious email with legitimate display name but suspicious domain address because Osipkov and Dreller are analogous art. The motivation to combine would be to filter out seemingly legitimate email based on additional analysis of metadata. Osipkov discloses identifying link contained in email communication (Osikpov: [0021]: evaluate content of messages in order to differentiate unwanted messaged from desirable messages… examine content associated with a message, such as attached files and hyperlinks). Osipkov does not explicitly disclose responsive to determining that the message comprises a hyperlink, cause a proxying of loading of content associated with the hyperlink so that a request from the second party for the content associated with the hyperlink is received by a proxy (Starink: [0031]-[0032]; [0047]: replace the URL with an alternate link to a trusted resource). It would have been obvious to one having ordinary skill in the art to replace suspicious link contained in email with proxy link to trusted resource because they are analogous art. The motivation would be to protect user from accessing malicious content. As per claim 17, Osipkov as modified discloses the limitations of claim 15. Osipkov as modified further discloses determining whether the site associated the hyperlink is associated with risk in response to receiving the request associated with the hyperlink (Starink: [0060]; [0077]). Same rationale applies here as above in rejecting claim 1. As per claim 24, Osipkov as modified discloses the system of claim 1. Osipkov as modified further discloses wherein the system uses a trustworthiness of the first party to the second party as indicated by the data to evaluate a trustworthiness of the message to the second party (Osipkov: [0024]-[0026]: verified senders who are identified in an address book of the user). Claims 8, 9 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Osipkov in view of Dreller and further in view of Starink and further in view of Gupta et al. U.S. 2017/0206545 (hereinafter Gupta). As per claim 8, Osipkov as modified discloses the system of claim 7. Osipkov as modified does not explicitly disclose wherein a confirmation received in response to the confirmation request comprises at least one of an entered code or a clicked link, wherein the link is included in the confirmation request. However, Gupta discloses sending confirmation request to sender to confirm that it’s from a valid e-mail address (Gupta: [0079]; [0145]). It would have been obvious to one having ordinary skill in the art to request sender to confirm validity of the e-mail because they are analogous art involving e-mail communication system where legitimacy of sender is verified. The motivation to combine would be to ensure communication from sender is from trusted party instead of from auto-generated spam message systems. As per claim 9, Osipkov as modified discloses the system of claim 8. Osipkov as modified further discloses wherein information associated with the clicked link is collected, wherein the information comprises at least one of the IP address, the cookie, and the browser version information (Gupta: [0145]: sender verification sends activation link to sender’s email). Same rationale applies here as above in rejecting claim 8. As per claim 12, Osipkov as modified discloses the system of claim 1. Osipkov as modified does not explicitly disclose wherein the security action further comprises transmitting a confirmation request to an address associated with the first party, the confirmation request comprising at least a portion of the message, wherein the message is delivered to the second party based on verification of information received in response to the confirmation request. However, Gupta discloses sending confirmation request to sender to confirm that it’s from a valid e-mail address prior to sending it to recipient (Gupta: [0079]; [0145]). It would have been obvious to one having ordinary skill in the art to request sender to confirm validity of the e-mail because they are analogous art involving e-mail communication system where legitimacy of sender is verified. The motivation to combine would be to ensure communication from sender is from trusted party instead of from auto-generated spam message systems. Claims 21-23 are rejected under 35 U.S.C. 103 as being unpatentable over Osipkov in view of Dreller and further in view of Starink and further in view of Goodman et al. U.S. 2007/0039038 (hereinafter Goodman). As per claim 21-23, Osipkov as modified discloses the limitations of claim 1. Osipkov as modified does not explicitly disclose wherein the display name of the first party matches the display name of the third party if the display name of the first party is the same, conceptually similar, or having a string distance below a threshold, as the display name of the third party. However, Goodman discloses determining display name of sender and legitimate sender by string comparison or visual similarity (Goodman: [0047]-[0049]). It would have been obvious to one having ordinary skill in the art to determine display name of sender by string comparison or visual similarity to detect suspicious display name because anti-spoofing techniques are well known in the art. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Show 2 earlier events
Sep 15, 2025
Response Filed
Oct 02, 2025
Final Rejection mailed — §103
Dec 01, 2025
Response after Non-Final Action
Jan 27, 2026
Request for Continued Examination
Feb 01, 2026
Response after Non-Final Action
Mar 19, 2026
Non-Final Rejection mailed — §103
Jun 17, 2026
Response Filed
Jul 13, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688329
INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, AND STORAGE MEDIUM
1y 12m to grant Granted Jul 21, 2026
Patent 12659165
SECURE AGGREGATION OF IOT MESSAGES
3y 0m to grant Granted Jun 16, 2026
Patent 12651046
CENTER APPARATUS, VEHICLE-SIDE SYSTEM, CONTENT PROTECTION METHOD, AND STORAGE MEDIUM STORING CONTENT PROTECTION PROGRAM
2y 4m to grant Granted Jun 09, 2026
Patent 12639098
SHARING ACCESS TO A PHYSICAL DEVICE WITH MULTIPLE VIRTUAL MACHINES
2y 7m to grant Granted May 26, 2026
Patent 12634292
PRIVATE TEMPORARY DYNAMIC SECURE NETWORKS AND FIRST RESPONDER NETWORK INTEGRATION
2y 3m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
86%
Grant Probability
99%
With Interview (+13.4%)
2y 9m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 807 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month