Prosecution Insights
Last updated: August 17, 2026
Application No. 18/159,226

Systems, Methods, and Apparatuses For Network Entity Tracking

Non-Final OA §101§103
Filed
Jan 25, 2023
Priority
Jan 26, 2022 — provisional 63/303,338
Examiner
SHIFERAW, ELENI A
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Comcast Cable Communications LLC
OA Round
3 (Non-Final)
38%
Grant Probability
At Risk
3-4
OA Rounds
8m
Est. Remaining
76%
With Interview

Examiner Intelligence

Grants only 38% of cases
38%
Career Allowance Rate
51 granted / 134 resolved
-19.9% vs TC avg
Strong +38% interview lift
Without
With
+37.8%
Interview Lift
resolved cases with interview
Typical timeline
4y 3m
Avg Prosecution
8 currently pending
Career history
143
Total Applications
across all art units

Statute-Specific Performance

§101
17.0%
-23.0% vs TC avg
§103
49.9%
+9.9% vs TC avg
§102
18.1%
-21.9% vs TC avg
§112
9.2%
-30.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 134 resolved cases

Office Action

§101 §103
DETAILED ACTION This Non Final Office action is in response to Request for continued Examination filed on 4/9/26. The claims 1 – 20 are pending. Claims 1, 8 and 15 are amended. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17€, was filed in this application after final action. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant’s submission filed on 4/9/26 has been entered. Response to Amendments and/or Arguments Response to Applicant’s arguments under 101: Applicant argues that amended claims 1, 8, and 15 do not recite a judicial exception because the claims cannot practically be performed in the human mind, and that the recitation of storing a record in a persistent cache integrates any alleged abstract idea into a practical application. Applicant’s arguments are not persuasive. The claims are still directed to a mental process and to collecting, analyzing and reporting information. The claims as amended continue to recite steps of: ‘determining associations between identifiers based on network log data,’ ‘determining whether a network entity is associated with malicious network activity’, ‘and sending a notification message …’. These limitations remain directed to the identification, evaluation, and communication of information. Such activities are longstanding forms of observation, analysis and judgement that fall squarely within the recognized categories of abstract ideas, including mental process and certain methods of organizing human activity. Although applicant emphasizes that the determinations are based on network log data and that records are stored in a persistent cache, the claims do not recite any specific technological improvement to the computers, networks, log processing mechanisms, or cache architecture themselves. Instead, the claims recite using generic computer components to carry out data gathering, storage, analysis, and notification functions at a high level of abstraction. The recited ‘persistent cache’ does not integrate the abstract idea into a practical application. Applicant argues that the addition of “storing, within a persistent cache, a record indicating a current association between the first temporary ID and the first static ID” supplies a concrete technological improvement. Argument is not persuasive. The claims do not recite any particular cache architecture, cache management technique, cache invalidation protocol, data structure specialization, or improved processing efficiency resulting from the claimed cache. The “persistent cache” is recited merely as a generic data store for keeping a record of an association. Storing information in a cache is an ancillary data storage activity and, on this record, amounts to insignificant extra-solution activity and data gathering or storage. The claims do not recite a technical solution to a technical problem in computer functionality. Rather, they recite using known computer components to record and retrieve identifier associations in the context of network security analysis. That is insufficient to integrate the abstract idea into a practical application. The claims still do not recite “significantly more” Applicant contends that the claims improve network entity tracking technology because they persistently maintain identifier associations and thereby improve malicious activity detection. However, the claims themselves do not recite the purported improvement with sufficient technical specificity. The claims merely state the intended result: storing an association, determining another association later and concluding malicious activity. A mere automation of an abstract idea using generic computer components does not supply an inventive concept. Accordingly, the additional elements, considered individually and as an ordered combination are insufficient to amount to significantly more than the abstract idea itself. Regarding argument claims are not performable “in the mind” Applicant argues that the claimed operations cannot be practically performed in the human mind because they involve network log data and persistent cache storage. However, the relevant inquiry is not whether every element must be literally performed mentally, but whether the claim as a whole is directed to an abstract idea and whether any additional element add significantly more. The determining steps are functional in nature and broadly recite evaluating identifiers and relationships. The use of network data and storage in memory does not by itself, convert the claims into a patent eligible technological improvement. Therefore the 101 rejection is maintained. Response to Applicant’s arguments under 103 Arguments are moot in view of new ground of rejection using additional reference Shah US 20230126313 A1. Applicant’s argument on the motivation statement is unpersuasive. Applicant argues that Bengtson and Furukawa do not teach a current association between a temporary ID and a static ID in a persistent cache. However, the obviousness analysis does not require an identical literal disclosure of the claim language in one reference. The proper inquiry is whether the claimed invention as a whole would have been obvious in view of the combined teachings. Bengtson provides the log based security correlation and suspicious credential-network address behavior, and Furukawa provides the use of multiple network related identifiers and security analysis based on threat and abnormality. A person of ordinary skill in the art would have found it obvious to combine these teachings to maintain and reuse known identifier associations in a memory resident or cache based data structure for efficient threat detection. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-5, 8, 11, 12, 15, 16, and 18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 8, and 15 are directed to an abstract idea. Analyzing network log data to determine temporal association between identifiers and network entities, determining that an entity is associated with malicious activity and reporting the result. The claims do not integrate the abstract idea into a practical application because they do not recite a specific technological improvement, particular machine, transformation or meaningful technical implementation beyond generic computer storage and notification. The additional elements, individually and as an ordered combination, amount to generic computer implementation using conventional network logs, UUIDs, persistent cache storage, and notification messaging. Therefore, claims 1, 8, 15 are ineligible under 35 USC 101. Claims 2, 11 and 16 further recite that the first time period is a prior time period and/or that the second time period is a current time period. These additional limitations merely specify the temporal relationship between data associations used in the abstract analysis. They do not add technological mechanism for processing network data, do not improve the operation of a computer or network, and do not apply the abstract idea using a particular machine beyond generic computing components. Rather, the limitations simply define when the recited identifier associations occur as part of the claimed mental process of evaluating network log data and determining malicious activity. Accordingly, these limitations do not integrate the abstract idea into a practical application under step 2A, prong 2, and considered individually or in combination with the remaining claim elements, amount only to well understood, routine, and conventional data analysis activity under step 2B. Therefore, claims 2, 11 and 16 are patent ineligible. Dependent claims 3-5, 8, 12, 15, and 18, further do not add limitations sufficient to integrate the abstract idea into a practical application or provide significant more. Therefore claims 1-5, 8, 11, 12, 15, 16, and 18 are patent ineligible under 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bengtson et al (US 2019/0349369 A1), hereinafter Bengtson in view of Furukawa US PG Pubs. 20210367957 and further in view of Shah et al. US 20230126313 A1, herein after Shah. Regarding Claim 1¸ Bengtson discloses “A method comprising: determining, based on network log data, that a first temporary identifier (ID) and a first static ID are associated during a first time period” (Para. 0029 describes a data log analyzer, which is used to analyze log data including network addresses and credentials (i.e., temporary ID). Para. 0033 describes how the data log includes instance identifiers and static, public-facing IP addresses (i.e., static IDs)); “wherein the first static ID uniquely identifies a first network entity” (Para. 0060 describes how temporary network addresses may be converted to static, public-facing network addresses. It is well-known in the art that an IP address may represent a network entity, which could be anything from a user device or server to a network switch or printer); “determining, based on the network log data, that the first temporary ID is associated with a second network entity during a second time period” (Para. 0060 describes how a temporary address (i.e., example of a temporary ID) may be associated with the public-facing network address. Figure 5B shows a time diagram of the determination and association process embodied in the instant application); “determining, based on the first temporary ID being associated with the first static ID during the first time period” (Para. 0060 and Figure 5B show that a server instance may be initialized with either static or temporary credentials, where these credentials may be a network address in an exemplary embodiment of the instant application); “and based on the first temporary ID being associated with the second network entity during the second time period, that the second network entity is associated with malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information); “and sending, to a computing device, a notification message” (Para. 0010 describes how, upon determination of malicious activity, a variety of activities may be performed, such as preventing the second server instance from performing various tasks, or raising an alert to entities of the network); “wherein the notification message indicates the second network entity is associated with malicious network activity” (Para. 0058 describes how limits to the second server instance and network address (i.e., IDs of the second network entity) may be placed upon detection of malicious activity). Bengtson fails to explicitly teach, however Furukawa teaches the first static ID...is a different type of identifier than the first temporary (see par. 43; unique network name (static ID) and IP address (temporary) of the judgement log; see further pars. 60-62; where threat and abnormality is measured/identified using data including the unique network name and IP address from judgement log). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to have modified Bengtson to incorporate the teachings of Furukawa to accurately analyze threats and abnormalities (see pars. 67-68 and figs. 4, 8, & 16). The combination of Bengtson and Furukawa fails to explicitly teach storing, within a persistent cache, a record indicating a current association between identifiers. However, Shah teaches storing, within a persistent cache, a record indicating a current association between the first temporary ID and the first static ID (see pars. 51, 77-80 & 78: Shah teaches storing within a Redis cache, a record reflecting a current association between a device identifier and corresponding client side /AP side data. …discusses a network management system (NMS) -client side data for a particular client device with a device identifier …and uses a Redis cache to perform a UUID re-lookup when the client’s SSID changes.). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Bengtson in view of Furukawa by incorporating the cache based identifier correlation techniques of Shah, because doing so would have improved the efficiency and reliability of storing, updating, and retrieving current association information for network related identifiers; and improve lookup speed and correlation accuracy in a network monitoring environment. Regarding Claim 8, Bengtson discloses “A method comprising: determining, based on network log data, that a first temporary identifier (ID) and a first static ID are associated during a first time period” (Para. 0029 describes a data log analyzer, which is used to analyze log data including network addresses and credentials (i.e., temporary ID). Para. 0033 describes how the data log includes instance identifiers and static, public-facing IP addresses (i.e., static IDs)); “wherein the first static ID is associated with a first network entity” (Para. 0060 describes how temporary network addresses may be converted to static, public-facing network addresses. It is well-known in the art that an IP address represents a network entity, which could be anything from a user device or server to a network switch or printer); “determining, based on the network log data, that the first temporary ID is associated with a second network entity during a second time period” (Para. 0060 describes how a temporary address (i.e., example of a temporary ID) may be associated with the public-facing network address. Figure 5B shows a time diagram of the determination and association process embodied in the instant application); “determining, based on historical network activity data associated with a second static ID,” (The Abstract describes how a second server instance, implied to be a second network entity, may use network addresses that may be valid within the network (i.e., potential temporary ID)); “and based on the network log data, that the second network entity is associated with malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information); “and sending, to a computing device, a notification message” (Para. 0010 describes how, upon determination of malicious activity, a variety of activities may be performed, such as preventing the second server instance from performing various tasks, or raising an alert to entities of the network); “wherein the notification message indicates the second network entity is associated with malicious network activity” (Para. 0058 describes how limits to the second server instance and network address (i.e., IDs of the second network entity) may be placed upon detection of malicious activity). Bengtson fails to explicitly teach, however Furukawa teaches the first static ID...is a different type of identifier than the first temporary (see par. 43; unique network name (static ID) and IP address (temporary) of the judgement log; see further pars. 60-62; where threat and abnormality is measured/identified using data including the unique network name and IP address from judgement log). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to have modified Bengtson to incorporate the teachings of Furukawa to accurately analyze threats and abnormalities (see pars. 67-68 and figs. 4, 8, & 16). The combination of Bengtson and Furukawa fails to explicitly teach storing, within a persistent cache, a record indicating a current association between identifiers. However, Shah teaches storing, within a persistent cache, a record indicating a current association between the first temporary ID and the first static ID (see pars. 51, 77-80 & 78: Shah teaches storing within a Redis cache, a record reflecting a current association between a device identifier and corresponding client side /AP side data. …discusses a network management system (NMS) -client side data for a particular client device with a device identifier …and uses a Redis cache to perform a UUID re-lookup when the client’s SSID changes.). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Bengtson in view of Furukawa by incorporating the cache based identifier correlation techniques of Shah, because doing so would have improved the efficiency and reliability of storing, updating, and retrieving current association information for network related identifiers; and improve lookup speed and correlation accuracy in a network monitoring environment. Regarding Claim 15¸ Bengtson discloses “A method comprising: determining, based on network log data indicating a first temporary identifier (ID) is associated with a first static ID during a first time period” (Para. 0029 describes a data log analyzer, which is used to analyze log data including network addresses and credentials (i.e., temporary ID). Para. 0033 describes how the data log includes instance identifiers and static, public-facing IP addresses (i.e., static IDs)); “and based on the network log data indicating the first temporary ID is associated with a second static ID during a second time period” (Para. 0060 describes how a temporary address (i.e., example of a temporary ID) may be associated with the public-facing network address. Figure 5B shows a time diagram of the determination and association process embodied in the instant application); “that a network entity uniquely identified by the second static ID is associated with malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information); “and sending, to a computing device, a notification message” (Para. 0010 describes how, upon determination of malicious activity, a variety of activities may be performed, such as preventing the second server instance from performing various tasks, or raising an alert to entities of the network); “wherein the notification message indicates the network entity is associated with the malicious network activity” (Para. 0058 describes how limits to the second server instance and network address (i.e., IDs of the second network entity) may be placed upon detection of malicious activity). Bengtson fails to explicitly teach, however Furukawa teaches the first static ID...is a different type of identifier than the first temporary (see par. 43; unique network name (static ID) and IP address (temporary) of the judgement log; see further pars. 60-62; where threat and abnormality is measured/identified using data including the unique network name and IP address from judgement log). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to have modified Bengtson to incorporate the teachings of Furukawa to accurately analyze threats and abnormalities (see pars. 67-68 and figs. 4, 8, & 16). The combination of Bengtson and Furukawa fails to explicitly teach storing, within a persistent cache, a record indicating a current association between identifiers. However, Shah teaches storing, within a persistent cache, a record indicating a current association between the first temporary ID and the first static ID (see pars. 51, 77-80 & 78: Shah teaches storing within a Redis cache, a record reflecting a current association between a device identifier and corresponding client side /AP side data. …discusses a network management system (NMS) -client side data for a particular client device with a device identifier …and uses a Redis cache to perform a UUID re-lookup when the client’s SSID changes.). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Bengtson in view of Furukawa by incorporating the cache based identifier correlation techniques of Shah, because doing so would have improved the efficiency and reliability of storing, updating, and retrieving current association information for network related identifiers; and improve lookup speed and correlation accuracy in a network monitoring environment. Regarding Claim 2, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 1, wherein the first time period comprises a prior time period, and wherein the second time period comprises a current time period” (Figure 5B shows a time diagram of events occurring within the system environment. Each time marker, represented by T0-T5, represents a time point where each event occurs. If T0 is a past time period, then T1-T5 represents a current time period, depending when each event is observed or occurs). Regarding Claim 3, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 1, wherein determining that the second network entity is associated with the malicious network activity comprises: determining, based on the first temporary ID being associated with the first static ID during the first time period” (Para. 0029 describes a data log analyzer, which is used to analyze log data including network addresses and credentials (i.e., temporary ID). Para. 0033 describes how the data log includes instance identifiers and static, public-facing IP addresses (i.e., static IDs)); “and based on the first temporary ID being associated with the second network entity during the second time period” (Para. 0060 describes how a temporary address (i.e., example of a temporary ID) may be associated with the public-facing network address. Figure 5B shows a time diagram of the determination and association process embodied in the instant application); “that a second static ID that uniquely identifies the second network entity is associated with anomalous behavior” (The Abstract describes how a second server instance, implied to be a second network entity, may use network addresses that may be valid within the network (i.e., potential temporary ID)); “and determining, based on the second static ID being associated with the anomalous behavior, that the second network entity is associated with the malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information). Regarding Claim 4, Bengtson, Furukawa and Shah teach the method, Bengtson further “The method of claim 1, wherein determining that the second network entity is associated with the malicious network activity comprises determining, based on the network log data, that the second network entity was associated with a second static ID, uniquely identifying the second network entity, during the first time period” (The Abstract describes how a second server instance, with a different network address, may request a network service during a time period. A network address may identify a network entity); “wherein the first time period is prior to the second time period” (Figure 5B shows a time diagram of events occurring within the system environment. Each time marker, represented by T0-T5, represents a time point where each event occurs. If T0 is a past time period, then T1-T5 represents a current time period, depending when each event is observed or occurs). Regarding Claim 5, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 1, wherein determining that the second network entity is associated with malicious network activity comprises: determining a second static ID that uniquely identifies the second network entity” (The Abstract describes how a second server instance, implied to be a second network entity, may use network addresses that may be valid within the network (i.e., potential temporary ID)); “and determining, based on historical network activity data associated with the second static ID, and based on the network log data, that the second network entity is associated with malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information). Regarding Claim 6, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 1, wherein the first temporary ID comprises an IP address, a domain name (DN), a fully qualified domain name (FQDN), a MAC address, a username, or an email address” (Para. 0002 describes examples of credentials, such as usernames and passwords). Regarding Claim 7, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 1, wherein the first static ID comprises a universally-unique identifier (UUID)” (Para. 0050 describes the use of static IP addresses, where the information may be regional or global. IP addresses, as known in the art, are used for uniquely identifying a network entity). Regarding Claim 9, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein the first static ID uniquely identifies the first network entity, and wherein the second static ID uniquely identifies the second network entity” (Para. 0060 describes how temporary network addresses may be converted to static, public-facing network addresses. It is well-known in the art that an IP address represents a network entity, which could be anything from a user device or server to a network switch or printer. The Abstract describes how a second server instance, implied to be a second network entity, may use network addresses that may be valid within the network (i.e., potential temporary ID)). Regarding Claim 10, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein the historical network activity data is indicative of the second network entity being associated with the second static ID during the first time period” (The Abstract describes how a second server instance, implied to be a second network entity, may use network addresses that may be valid within the network (i.e., potential temporary ID)). Regarding Claim 11¸ Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein the first time period is prior to the second time period” (Figure 5B shows a time diagram of events occurring within the system environment. Each time marker, represented by T0-T5, represents a time point where each event occurs. If T0 is a past time period, then T1-T5 represents a current time period, depending when each event is observed or occurs). Regarding Claim 12, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein determining that the second network entity is associated with the malicious network activity comprises: determining, based on the first temporary ID being associated with the first static ID during the first time period” (Para. 0029 describes a data log analyzer, which is used to analyze log data including network addresses and credentials (i.e., temporary ID). Para. 0033 describes how the data log includes instance identifiers and static, public-facing IP addresses (i.e., static IDs)); “and based on the first temporary ID being associated with the second network entity during the second time period, that the second static ID is associated with anomalous behavior” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information); “and determining, based on the second static ID being associated with the anomalous behavior, that the second network entity is associated with the malicious network activity (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information). Regarding Claim 13, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein the first temporary ID comprises an IP address, a domain name (DN), a fully qualified domain name (FQDN), a MAC address, a username, or an email address” (Para. 0002 describes examples of credentials, such as usernames and passwords). Regarding Claim 14, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 8, wherein the first static ID comprises a first universally-unique identifier (UUID), and wherein the second static ID comprises a second UUID” (Para. 0050 describes the use of static IP addresses, where the information may be regional or global. IP addresses, as known in the art, are used for uniquely identifying a network entity). Regarding Claim 16, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 15, wherein the first time period comprises a prior time period, and wherein the second time period comprises a current time period” (Figure 5B shows a time diagram of events occurring within the system environment. Each time marker, represented by T0-T5, represents a time point where each event occurs. If T0 is a past time period, then T1-T5 represents a current time period, depending when each event is observed or occurs). Regarding Claim 17, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 15, wherein the first static ID uniquely identifies another network entity” (Para. 0028 describes how a set of credentials, including a network address (i.e., static ID), may be assigned to another server instance (i.e., another network entity)). Regarding Claim 18¸ Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 15, wherein determining that the network entity is associated with the malicious network activity comprises: determining, based on the first temporary ID being associated with the first static ID during the first time period, and based on the first temporary ID being associated with the second static ID during the second time period, that the network entity uniquely identified by the second static ID is associated with anomalous behavior and determining, based on the network entity uniquely identified by the second static ID being associated with the anomalous behavior, that the network entity is associated with the malicious network activity” (Para. 0025 describes how a malicious user (i.e., malicious network entity) may potentially use a set of server credentials (i.e., temporary ID) in order to gain access of a user’s account or information). Regarding Claim 19, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “19. The method of claim 15, wherein the first temporary ID comprises an IP address, a domain name (DN), a fully qualified domain name (FQDN), a MAC address, a username, or an email address associated with another network entity” (Para. 0002 describes examples of credentials, such as usernames and passwords. Usernames and passwords may be used across a variety of network entities to access a single account). Regarding Claim 20, Bengtson, Furukawa and Shah teach the method, Bengtson further discloses “The method of claim 15, wherein the first static ID comprises a universally-unique identifier (UUID) for another network entity” (Para. 0050 describes the use of static IP addresses, where the information may be regional or global. IP addresses, as known in the art, are used for uniquely identifying a network entity. IP addresses, upon expiration of a lease or at the discretion of a user, may be used for a different network identity). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The references present in PTO-892 are cited to further demonstrate the state of the art with respect to network entity and identification tracking for a variety of network entities. US 20220014451 A1: a Redis cache, a key-value mapping between overly flow tuples and source/destination virtual network identifiers, which is then used for subsequent lookups and enrichment of new underlay data flows. Persistent cache based record used to maintain the current association between flow-identifying information and virtual network identifiers. Pars. 111, 125, 113 Any inquiry concerning this communication or earlier communications from the examiner should be directed to Alexandria C Rodriguez whose telephone number is (703)756-1827. The examiner can normally be reached 08:00 - 16:00 Eastern. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached on (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Jan 25, 2023
Application Filed
Nov 27, 2024
Non-Final Rejection mailed — §101, §103
Apr 28, 2025
Response Filed
Oct 31, 2025
Final Rejection mailed — §101, §103
Dec 23, 2025
Response after Non-Final Action
Apr 09, 2026
Request for Continued Examination
Apr 19, 2026
Response after Non-Final Action
Jul 28, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 7983414
PROTECTED CRYPTOGRAPHIC CALCULATION
6y 4m to grant Granted Jul 19, 2011
Patent 7984512
INTEGRATING SECURITY BY OBSCURITY WITH ACCESS CONTROL LISTS
4y 1m to grant Granted Jul 19, 2011
Patent 7965844
SYSTEM AND METHOD FOR PROCESSING USER DATA IN AN ENCRYPTION PIPELINE
4y 3m to grant Granted Jun 21, 2011
Patent 7954164
METHOD OF COPY DETECTION AND PROTECTION USING NON-STANDARD TOC ENTRIES
6y 7m to grant Granted May 31, 2011
Patent 7954156
METHOD TO ENHANCE PLATFORM FIRMWARE SECURITY FOR LOGICAL PARTITION DATA PROCESSING SYSTEMS BY DYNAMIC RESTRICTION OF AVAILABLE EXTERNAL INTERFACES
1y 10m to grant Granted May 31, 2011
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
38%
Grant Probability
76%
With Interview (+37.8%)
4y 3m (~8m remaining)
Median Time to Grant
High
PTA Risk
Based on 134 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month