Prosecution Insights
Last updated: August 17, 2026
Application No. 18/198,244

CONTROL FLOW INTEGRITY MONITORING FOR APPLICATIONS RUNNING ON PLATFORMS

Non-Final OA §103§112
Filed
May 16, 2023
Priority
Jul 22, 2022 — provisional 63/391,518 +1 more
Examiner
WHEATON, BRADFORD F
Art Unit
2193
Tech Center
2100 — Computer Architecture & Software
Assignee
Cisco Technology Inc.
OA Round
3 (Non-Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
7m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
240 granted / 390 resolved
+6.5% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
22 currently pending
Career history
416
Total Applications
across all art units

Statute-Specific Performance

§101
18.3%
-21.7% vs TC avg
§103
68.6%
+28.6% vs TC avg
§102
2.1%
-37.9% vs TC avg
§112
8.8%
-31.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 390 resolved cases

Office Action

§103 §112
DETAILED ACTION Claims 1-5, 7-8, 10-12 and 14-24 are pending in the current application. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 3/19/26 has been entered. Response to Arguments Applicant’s arguments, see Remarks, filed 3/19/26, with respect to the rejection of claim 1 under 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new grounds of rejection is made in view of Malin (Pub. No. US 2019/0386917 A1) [0074] lines 1-16 and [0075] lines 1-13 that shows the ability to revert back to a previous/different learning/observation phase from the current phase of monitoring analysis when changes produces during this second phase generates results with accuracy/confidence score that falls outside the determine threshold where the threshold accuracy can be determined a plurality of different ways thus viewed as based on a first or second threshold condition, which in light of the teachings of Zawadowskiy [0036] lines 1-13, [0037] lines 1-9, [0058] lines 2-5, [0059] lines 1-13, [0068] lines 1-7 and [0070] lines 1-10 showing as part of monitoring if the given executing application is compliant with the finite state machine associated with control flow thus viewed when not compliant there has be a modification/change to the executing application and thus together show being able to determine to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the confidence score to fall below the first threshold or a second threshold. It is noted here that independent claims 8 and 15 have been amended differently from claim 1 but argued that rejected for the amended features of claim 1 thus the response to the amended language of claim 1 with full rejection for the other independent claims 8 and 15 seen below as for why they were rejected. Claim Objections Claim 5 is objected to because of the following informalities: It recites “a second threshold” however viewed as a type based on the amendments to the parent claim and should recite “the second threshold”. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 15-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 15 recites the limitation "…to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the score to fall below a threshold" in lines 21-23. There is insufficient antecedent basis for the monitoring phase limitation in the claim and also unclear if the “a threshold” limitation is a refence to the same “a threshold” limitation in line 20 or different though interpreted as the same for claim analysis appropriate correction is required. Claims 16-20 depend from claim 15 and do not overcome this issue and thus rejected under the same reasoning. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 15-16 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy et al. (Pub. No. US 2020/0004954 A1), in view of Copty et al. (Pub. No. US 2018/0232523 A1) in view of Katkoori et al. (Pub. No. US 2023/0020547 A1), and further in view of Malin (Pub. No. US 2019/0386917 A1). As to claim 1, Zawadowskiy discloses a method for monitoring a computing system, comprising: determining an observation phase for observing execution of processes on the computing system, wherein the processes executed during the observation phase include valid transfers that are allowed to be executed (Zawadowskiy [0036] lines 1-13, [0037] lines 1-9, [0058] lines 2-5, [0059] lines 1-13, [0068] lines 1-7 and [0070] lines 1-10; which shows that during a learning phase/viewed as the observation phase, where during the learning phase the program is executed and all possible transitions are learned/observed from the executing program/process viewed as including valid/secure transfers, viewed as ones that are allowed to be executed); determining telemetry, during the observation phase, representing execution of the processes (Zawadowskiy [0070] lines 1-8; which shows as part of the generation/building of the finite state machine, viewed as a type of control flow graph, for the application being able to use and thus have determine associated enhanced security telemetry data and as done as part of the generation/building/learning phase viewed as being done in the observation phase); generating a control flow directed graph representing execution sequences of an application based on the telemetry (Zawadowskiy [0070] lines 1-10; which shows the specifics of a finite state machine for an executing program to be generated/built, viewed as generating/build the control flow graph, that represent execution sequence of an application program and is built/generated based on telemetry data to learn/cover all possible transitions/paths of the program/application viewed as the goal for completely generated graph/model); monitoring, using the control flow directed graph, transfers of instruction pointers at the computing system (Zawadowskiy [0036] lines 1-6, [0037] lines 1-9, [0064] lines 1-4 and [0070] lines 1-17; which shows being able to monitor the instruction points of the executing application with its ability to monitor for specific instruction pointer with the control flow graph/finite state machine to identify if they are invalid); and determining an invalid transfer based at least in part on the control flow directed graph (Zawadowskiy [0025] lines 1-15, [0036] lines 1-6, [0037] lines 1-9, [0064] lines 1-4 and [0070] lines 1-17; which shows that after the generation of the control flow graph/finite state machine where the program is executed a monitored later it is evaluated against the learned control flow graph/finite state machine information to determine an invalid instruction pointer, viewed as an invalid transfer); performing a remediation action associated with the invalid transfer (Zawadowskiy [0025] lines 9-15, [0046] lines 1-23 and [0064] lines 4-15; which shows based on a determination/detection of an invalid/mismatch transfer and performing actions responses such as stop, raise interrupts, raise alarms/alerts/indications of the issue viewed as a type of performing a remediation actions associated with the detected invalid/not consistent information) Zawadowskiy does not specifically disclose determining an observed number of the processes observed in the observation phase and represented in the control flow graph; determining a confidence score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application. However, Copty discloses determining an observed number of the processes observed in the observation phase and represented in the control flow graph; determining a confidence score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application (Copty [0059] lines 1-17 and [0086] lines 1-12; which shows being able to determine a coverage metric associated with a model, including control flow graph representation of execution, where the determined coverage metric can be a plurality of things including percentage of the instruction of the program invoked during execution, viewed as all/total number of path that can be made in light of path coverage of the control flow graph/ the coverage of all the execution paths according to the CFG, viewed as the determined/observed number of processes represented in the generated control flow graph in light of the all the instruction executed by the program/application as a percentage, and viewed as a type of confidence score/coverage goal value associated with the control flow graph, where the teachings of Zawadowskiy above discloses the specifics of the goal for coverage of the graph/model being one that all paths/transitions are learned/covered by the model viewed as the goal). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 Zawadowskiy as modified by Copty do not specifically disclose determining to transition from the observation phase into a monitoring phase based at least in part on the confidence score satisfying a first threshold. However, Katkoori disclose determining to transition from the observation phase into a monitoring phase based at least in part on the confidence score satisfying a first threshold (Katkoori [0003] lines 1-16 and [0049] lines 1-7; which shows that after an analysis/observation phase is performed that is used to build an approximate control flow graph it transitions into an enforcement/monitoring phase of the control flow graph, where in light of the teachings of Copty and Zawadoskiy above showing the generation and determination and improvement of coverage associated with a control flow graph associated with a coverage goal/completeness/finished where the completeness/all can be viewed as the goal/finish/threshold for the confidence score associated with the control flow graph and can together be viewed as showing determining to transition from the observation phase into a monitoring phase based at least in part on the confidence score satisfying a first threshold) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Katkoori showing the specifics of after the generation of a control flow graph applying and enforcing the generated control flow graph into the control flow graph generation of Zawadowskiy as modified by Copty for the purpose of improving security by leveraging the generated control flow graph against control flow attacks, as taught by Katkoori [0003] lines 1-16. Zawadowskiy as modified by Copty and Katkoori do not specifically disclose determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the confidence score to fall below the first threshold or a second threshold However, Malin discloses determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the confidence score to fall below the first threshold or a second threshold (Malin [0074] lines 1-16 and [0075] lines 1-13; which shows the ability to revert back to a previous/different learning/observation phase from the current phase of monitoring analysis when changes produces during this second phase generates results with accuracy/confidence score that falls outside the determine threshold where the threshold for accuracy/confidence can be determined a plurality of different ways, viewed as a first or second threshold where it is seen in the teachings of Zawadowskiy above being able to determine an invalid transfer, viewed as a type of indication of a change/difference in the application from the monitored application information and thus together would show discloses determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the confidence score to fall below the first threshold or a second threshold). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Malin showing the ability to switch and revert between different phases associated with analysis based on associated score into the monitoring application flow analysis of Zawadowskiy as modified by Copty and Katkoori for the purpose of being able in increase the accuracy of the model with additional information, as taught by Malin [0071] lines 1-10 and [0075] lines 1-13 As to claim 2, Zawadowskiy does not specifically disclose, however, Copty disclose wherein determining the confidence score comprises determining a proportion of the processes represented in the control flow directed graph and wherein determining the monitoring phase is in response to the confidence score being above a threshold (Copty [0059] lines 1-17 and [0086] lines 1-12; which shows being able to determine a coverage metric/confidence score associated with a model, including control flow graph representation of execution, where the determined coverage metric can be a plurality of things including percentage/proportion of the instruction of the program invoked during execution, viewed as all/total number of path that can be made in light of path coverage of the control flow graph/ the coverage of all the execution paths according to the CFG, viewed as the determined/observed proportion/percentage of processes of the application represented/included in the CFG where the coverage metrics can also include a coverage goal/target/threshold type value, that in light of the teachings of Katkoori above showing the specifics of the transition from an observation/monitoring phase to an enforcement/active monitoring phase once the associated CFG is built generated and where the teachings of Zawadowskiy above showing the graph/model is generated to cover all possible transition/execution paths of the software and thus together can show determining the confidence score comprises determining a proportion of the processes represented in the control flow directed graph and wherein determining the monitoring phase is in response to the confidence score being able a threshold) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 As to claim 3, Zawadowskiy discloses wherein generating the control flow directed graph is based on observed transfers during the observation phase, wherein the observed transfers during the observation phase are considered valid transfers (Zawadowskiy [0070] lines 1-10; which shows that during a learning phase/observation phase all a program is executed and all possible transitions/transfers learned/observed to create/generate the control flow graph/finite state machine where these are the transactions used later for comparison and thus viewed as the valid transfers/transitions). As to claim 15, Zawadowskiy discloses one or more non-transitory computer-readable media storing computer- readable instructions that, when executed by one or more processors, cause the one or more processors to: determine an observation phase for observing execution of processes by the one or more processors, wherein the processes executed during the observation phase include valid transfers that are allowed to be executed (Zawadowskiy [0036] lines 1-13, [0037] lines 1-9, [0058] lines 2-5, [0059] lines 1-13, [0068] lines 1-7 and [0070] lines 1-10; which shows that during a learning phase/viewed as the observation phase, where during the learning phase the program is executed and all possible transitions are learned/observed from the executing program/process viewed as including valid/secure transfers, viewed as ones that are allowed to be executed); determine telemetry, during the observation phase, representing execution of the processes (Zawadowskiy [0070] lines 1-8; which shows as part of the generation/building of the finite state machine, viewed as a type of control flow graph, for the application being able to use and thus have determine associated enhanced security telemetry data and as done as part of the generation/building/learning phase viewed as being done in the observation phase); generate a control flow directed graph representing execution sequences of an application based on the telemetry (Zawadowskiy [0070] lines 1-8; which shows the specifics of a finite state machine for an executing program to be generated/built, viewed as generating/build the control flow graph, that represent execution sequence of an application program and is built/generated based on telemetry data where the model/graph is able represent all paths/transitions of the program/application when complete viewed as complete coverage goal); convey the control flow directed graph to a computing device for monitoring execution of processes by the computing device based at least in part on the control flow directed graph (Zawadowskiy [0025] lines 1-15, [0036] lines 1-6, [0037] lines 1-9, [0042] lines 1-18, [0064] lines 1-4 and [0070] lines 1-17; which shows being using, and thus viewed as having been conveyed, the generated control flow graph to monitor the instruction points of the executing application with its ability to monitor for specific instruction pointer with the control flow graph/finite state machine to identify if they are invalid). Zawadowskiy does not specifically disclose determine an observed number of the processes observed in the observation phase and represented in the control flow graph; determine a score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application. However, Copty discloses determine an observed number of the processes observed in the observation phase and represented in the control flow graph; determine a score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application (Copty [0059] lines 1-17 and [0086] lines 1-12; which shows being able to determine a coverage metric associated with a model, including control flow graph representation of execution, where the determined coverage metric can be a plurality of things including percentage of the instruction of the program invoked during execution, viewed as all/total number of path that can be made in light of path coverage of the control flow graph/ the coverage of all the execution paths according to the CFG, viewed as the determined/observed number of processes represented in the generated control flow graph in light of the all the instruction executed by the program/application as a percentage, and viewed as a type of confidence score/coverage goal value associated with the control flow graph, where the teachings of Zawadowskiy above shows the specifics of the coverage goal for the generated model/graph being complete cover all execution and transitions learned and incorporated of the program). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 Zawadowskiy as modified by Copty do not specifically disclose that the convey the control flow graph to a computer device for monitoring is based at least in part on the control flow graph and in response to the score being above a threshold. However, Katkoori disclose the specifics of the convey the control flow graph to a computer device for monitoring is based at least in part on the control flow graph and in response to the score being above a threshold (Katkoori [0003] lines 1-16, [0004] lines 1-4 and [0049] lines 1-7; which shows that after an analysis phase is performed that is used to build an approximate control flow graph it transitions/conveys into an enforcement/monitoring phase on a system/platform for the execution of software, viewed as a computer device, of the control flow graph after a trusted control flow graph is built/generated, where in light of the teachings of Copty above showing the generation and determination and improvement of coverage/trust score/value associated with a control flow graph associated with a coverage goal/completeness/finished and the teachings of Zawadowskiy showing the generation of the graph/model that covers all possible transitions/executions of the program thus determined/generating thus with determine complete coverage threshold value and thus together can be viewed as showing the specifics of the convey the control flow graph to a computer device for monitoring is based at least in part on the control flow graph and in response to the score being above a threshold) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Katkoori showing the specifics of after the generation of a control flow graph applying and enforcing the generated control flow graph into the control flow graph generation of Zawadowskiy as modified by Copty for the purpose of improving security by leveraging the generated control flow graph against control flow attacks, as taught by Katkoori [0003] lines 1-16. Zawadowskiy as modified by Copty and Katkoori do not specifically disclose determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the score to fall below a threshold However, Malin discloses determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the score to fall below a threshold (Malin [0074] lines 1-16 and [0075] lines 1-13; which shows the ability to revert back to a previous/different learning/observation phase from the current phase of monitoring analysis when changes produces during this second phase generates results with accuracy/confidence score that falls outside the determine threshold where the threshold for accuracy/confidence can be determined a plurality of different ways, viewed as a threshold where it is seen in the teachings of Zawadowskiy above being able to determine an invalid transfer, viewed as a type of indication of a difference/change in the application from the monitored application information and thus together would show discloses determining to transition from the monitoring phase back to the observation phase based at least in part on a modification to the application causing the score to fall below a threshold). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Malin showing the ability to switch and revert between different phases associated with analysis based on associated score into the monitoring application flow analysis of Zawadowskiy as modified by Copty and Katkoori for the purpose of being able in increase the accuracy of the model with additional information, as taught by Malin [0071] lines 1-10 and [0075] lines 1-13 As to claim 16, Zawadowskiy does not specifically disclose, however, Copty discloses wherein the instructions to generate the control flow directed graph comprise further instructions to determine completion of the observation phase based at least in part on the control flow directed graph representing at least a threshold portion of application processes (Copty [0059] lines 1-17 and [0086] lines 1-12; which shows being able to determine a coverage metric/confidence score associated with a model, including control flow graph representation of execution, where the determined coverage metric can be a plurality of things including percentage/proportion of the instruction of the program invoked during execution, viewed as all/total number of path that can be made in light of path coverage of the control flow graph/ the coverage of all the execution paths according to the CFG, viewed as the determined/observed proportion/percentage of processes of the application represented/included in the CFG where the coverage metrics can also include a coverage goal/target/threshold type value, that in light of the teachings of where the teachings of Zawadowskiy above showing the graph/model is generated to cover all possible transition/execution paths of the software, viewed as the set goal/threshold and thus together can show wherein the instructions to generate the control flow directed graph comprise further instructions to determine completion of the observation phase based at least in part on the control flow directed graph representing at least a threshold portion of application processes). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 As to claim 19 it is comparable to claim 2 above and rejected under the same reasoning. Claims 4 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claims 1 and 15 above, and further in view of Sasikumar et al. (Patent No. US 8,407,322 B1). As to claims 4 and 18, Zawadowskiy as modified by Copty, Katkoori and Malin do not specifically disclose wherein determining the telemetry, during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry. However, Sasikumar discloses wherein determining the telemetry, during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry (Sasikumar Col. 9 lines 40-45 and Col. 12 lines 10-36; which shows the ability for software code being able to identify and divide the code into specific code blocks, for different workload/logical operations performed where the different code block are assigned to different to different computer devices for performing and processing their assigned information and the ability to share and aggregate their individual determined information together, which in light of the teachings of Zawadowskiy above for the observation/analysis phase of execution code to determine/identify associated telemetry data and thus together show during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Sasikumar showing the specific of dividing code into separate code blocks for analysis into the software analysis of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of increasing the adaptability of the system by being able facilitate the determination and execution of divided code blocks on a plurality of different computing devices, as taught by Sasikumar Col. 1 lines 36-44 and Col. 9 lines 40-45. Claims 5 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claims 1 and 15 above, and further in view of Magi et al. (Patent No. US 11, 809,535 B2). As to claims 5 and 17, Zawadowskiy as modified by Copty, Katkoori and Malin does not specifically disclose wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase. However, Magi discloses wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase (Magi Col. 12 lines 54- Col. 13 line 14 and Col. 14 lines 48- 67 and claim 1; which shows being able to have multiple levels set for a threshold that can be used to trigger specific action performance where the different levels for threshold use can be based on further received conditions, seen specifically as other measured values of confidence that can be used together with the first measured confidence score value to trigger the same specific action, where the threshold confidence levels can be different and thus viewed as being lower, and together with the specific teachings of Katkoori and Copty above showing the specific of how coverage metric/confidence score and associated goal can be used to show the trigger switch between an observation/analysis phase and a monitoring/enforcement phase that together are viewed as showing wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Magi showing the specific of using a plurality of thresholds for analysis of information given different criteria provided into the software analysis of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of increasing the adaptability of the system by being having adjustable threshold condition based on additional factors used to make decisions, as taught by Magi Col. 4 lines 11-21. Claims 7 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claim 1 above, and further in view of Neill (Patent No. US 11,018,959 B1). As to claim 7, Zawadowskiy discloses wherein the monitoring phase is performed using a hardware device of the computing system and wherein determining the invalid transfer is based at least in part on identifying an instruction sequence in the CPU telemetry that is not present in the control flow directed graph (Zawadowskiy [0025] lines 1-15, [0036] lines 1-6, [0037] lines 1-9, [0064] lines 1-4 and [0070] lines 1-17; which show being able to use the determine telemetry data tied to the CPU still in the monitoring phase to determine/identify when there is different/unexpected telemetry data viewed as invalid and as the telemetry data can be tied to specific instruction pointers viewed as being able to identify an invalid instruction sequence that does not match the finite state machine/control flow graph information where the specifics of CPU telemetry is seen specifically disclosed in Neill below). Zawadowskiy as modified by Copty, Katkoori and Malin do not specifically disclose wherein the telemetry comprises central processing unit (CPU) telemetry, and wherein generating the control flow directed graph comprises normalizing the CPU telemetry into a control flow directed graph representation. However, Neill discloses wherein the telemetry comprises central processing unit (CPU) telemetry, and wherein generating the control flow directed graph comprises normalizing the CPU telemetry into a control flow directed graph representation (Neill Col. 2 lines 48-54 and Col. 9 lines 44-60; which shows being able to collect/monitor telemetry data from a plurality of different sources that can include processor/CPU sources and thus CPU telemetry and being to normalize that collected telemetry data for later, which in light of the teachings of Zawadowskiy above showing the specifics of using the telemetry data to build the finite state machine/control flow graph can together be viewed as wherein the telemetry comprises central processing unit (CPU) telemetry, and wherein generating the control flow directed graph comprises normalizing the CPU telemetry into a control flow directed graph representation). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Neill showing normalizing collected telemetry data into the software analysis with telemetry data of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of improving data consistency by normalizing the used data, at taught by Neill Col. 7 lines 2-7 and Col. 9 lines 44-60. Claims 8 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy et al. (Pub. No. US 2020/0004954 A1), in view of Copty et al. (Pub. No. US 2018/0232523 A1) in view of Katkoori et al. (Pub. No. US 2023/0020547 A1),. As to claim 8, Zawadowskiy discloses a system comprising: one or more processors; and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising (Zawadowskiy [0058] lines 2-5 and [0059] lines 1-13); determining an observation phase for observing execution of processes on the computing system, wherein the processes executed during the observation phase include valid transfers that are allowed to be executed (Zawadowskiy [0036] lines 1-13, [0037] lines 1-9, [0058] lines 2-5, [0059] lines 1-13, [0068] lines 1-7 and [0070] lines 1-10; which shows that during a learning phase/viewed as the observation phase, where during the learning phase the program is executed and all possible transitions are learned/observed from the executing program/process viewed as including valid/secure transfers, viewed as ones that are allowed to be executed); determining telemetry, during the observation phase, representing execution of the processes (Zawadowskiy [0070] lines 1-8; which shows as part of the generation/building of the finite state machine, viewed as a type of control flow graph, for the application being able to use and thus have determine associated enhanced security telemetry data and as done as part of the generation/building/learning phase viewed as being done in the observation phase); generating a control flow directed graph representing execution sequences of an application based on the telemetry (Zawadowskiy [0070] lines 1-10; which shows the specifics of a finite state machine for an executing program to be generated/built, viewed as generating/build the control flow graph, that represent execution sequence of an application program and is built/generated based on telemetry data to learn/cover all possible transitions/paths of the program/application viewed as the goal for completely generated graph/model); monitoring, using the control flow directed graph, transfers of instruction pointers at the computing system (Zawadowskiy [0036] lines 1-6, [0037] lines 1-9, [0064] lines 1-4 and [0070] lines 1-17; which shows being able to monitor the instruction points of the executing application with its ability to monitor for specific instruction pointer with the control flow graph/finite state machine to identify if they are invalid); and determining an invalid transfer based at least in part on the control flow directed graph (Zawadowskiy [0025] lines 1-15, [0036] lines 1-6, [0037] lines 1-9, [0064] lines 1-4 and [0070] lines 1-17; which shows that after the generation of the control flow graph/finite state machine where the program is executed a monitored later it is evaluated against the learned control flow graph/finite state machine information to determine an invalid instruction pointer, viewed as an invalid transfer); performing a remediation action associated with the invalid transfer (Zawadowskiy [0025] lines 9-15, [0046] lines 1-23 and [0064] lines 4-15; which shows based on a determination/detection of an invalid/mismatch transfer and performing actions responses such as stop, raise interrupts, raise alarms/alerts/indications of the issue viewed as a type of performing a remediation actions associated with the detected invalid/not consistent information) Zawadowskiy does not specifically disclose determining an observed number of the processes observed in the observation phase and represented in the control flow graph; determining a confidence score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application; receiving from an operator, a threshold confidence score. However, Copty discloses determining an observed number of the processes observed in the observation phase and represented in the control flow graph; determining a confidence score associated with the control flow directed graph by comparing the observed number of the processes that were observed in the observation phase as compared to a total number of total processes associated with the application; receiving from an operator, a threshold confidence score (Copty [0052] lines 30-33, [0059] lines 1-17 and [0086] lines 1-12; which shows being able to determine a coverage metric associated with a model, including control flow graph representation of execution, where the determined coverage metric can be a plurality of things including percentage of the instruction of the program invoked during execution, viewed as all/total number of path that can be made in light of path coverage of the control flow graph/ the coverage of all the execution paths according to the CFG, viewed as the determined/observed number of processes represented in the generated control flow graph in light of the all the instruction executed by the program/application as a percentage, and viewed as a type of confidence score/coverage goal value associated with the control flow graph, and shows the ability to modify the confidence level threshold, viewed as threshold confidence score, based on information received from of information resources, viewed as operators where the teachings of Zawadowskiy above discloses the specifics of the goal for coverage of the graph/model being one that all paths/transitions are learned/covered by the model viewed as the goal). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 Zawadowskiy as modified by Copty do not specifically disclose determining to transition from the observation phase into a monitoring phase based at least in part on the control flow directed graph and the confidence score, wherein determining to transition into the monitoring phase comprises determining that the confidence score satisfies the threshold confidence score satisfying a first threshold. However, Katkoori disclose determining to transition from the observation phase into a monitoring phase based at least in part on the control flow directed graph and the confidence score, wherein determining to transition into the monitoring phase comprises determining that the confidence score satisfies the threshold confidence score satisfying a first threshold (Katkoori [0003] lines 1-16 and [0049] lines 1-7; which shows that after an analysis/observation phase is performed that is used to build an approximate control flow graph it transitions into an enforcement/monitoring phase of the control flow graph, where in light of the teachings of Copty and Zawadoskiy above showing the generation and determination and improvement of coverage associated with a control flow graph associated with a coverage goal/completeness/finished where the completeness/all can be viewed as the goal/finish/threshold for the confidence score associated with the control flow graph and can together be viewed as showing based at least on the control flow graph and associated confidence score at/satisfying threshold determining to transition from the observation phase into a monitoring phase based at least in part on the confidence score satisfying the threshold) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Katkoori showing the specifics of after the generation of a control flow graph applying and enforcing the generated control flow graph into the control flow graph generation of Zawadowskiy as modified by Copty for the purpose of improving security by leveraging the generated control flow graph against control flow attacks, as taught by Katkoori [0003] lines 1-16. As to claim 11, Zawadowskiy discloses wherein generating the control flow directed graph is based on observed transfers during the observation phase, wherein the observed transfers during the observation phase are considered valid transfers (Zawadowskiy [0070] lines 1-10; which shows that during a learning phase/observation phase all a program is executed and all possible transitions/transfers learned/observed to create/generate the control flow graph/finite state machine where these are the transactions used later for comparison and thus viewed as the valid transfers/transitions). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty and Katkoori as applied to claim 8 above, and further in view of Sasikumar et al. (Patent No. US 8,407,322 B1). As to claim 10 Zawadowskiy as modified by Copty and Katkoori do not specifically disclose wherein determining the telemetry, during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry. However, Sasikumar discloses wherein determining the telemetry, during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry (Sasikumar Col. 9 lines 40-45 and Col. 12 lines 10-36; which shows the ability for software code being able to identify and divide the code into specific code blocks, for different workload/logical operations performed where the different code block are assigned to different to different computer devices for performing and processing their assigned information and the ability to share and aggregate their individual determined information together, which in light of the teachings of Zawadowskiy above for the observation/analysis phase of execution code to determine/identify associated telemetry data and thus together show during the observation phase, comprises: dividing underlying code associated with the processes into a plurality of workloads; assigning the plurality of workloads to two or more computing devices associated with the computing system for observation; and aggregating observation data from the two or more computing devices, the observation data representing the telemetry). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Sasikumar showing the specific of dividing code into separate code blocks for analysis into the software analysis of Zawadowskiy as modified by Copty and Katkoori for the purpose of increasing the adaptability of the system by being able facilitate the determination and execution of divided code blocks on a plurality of different computing devices, as taught by Sasikumar Col. 1 lines 36-44 and Col. 9 lines 40-45. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty and Katkoori as applied to claim 8 above, and further in view of Magi et al. (Patent No. US 11, 809,535 B2). As to claim 12 Zawadowskiy as modified by Copty and Katkoori does not specifically disclose wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase. However, Magi discloses wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase (Magi Col. 12 lines 54- Col. 13 line 14 and Col. 14 lines 48- 67 and claim 1; which shows being able to have multiple levels set for a threshold that can be used to trigger specific action performance where the different levels for threshold use can be based on further received conditions, seen specifically as other measured values of confidence that can be used together with the first measured confidence score value to trigger the same specific action, where the threshold confidence levels can be different and thus viewed as being lower, and together with the specific teachings of Katkoori and Copty above showing the specific of how coverage metric/confidence score and associated goal can be used to show the trigger switch between an observation/analysis phase and a monitoring/enforcement phase that together are viewed as showing wherein determining the confidence score comprises: determining a first threshold for the confidence score, wherein the first threshold is used for determining the monitoring phase; and determining a second threshold for the confidence score, the second threshold lower than the first threshold, wherein the second threshold is based at least in part on receiving one or more policy allowance conditions associated with determining the monitoring phase). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Magi showing the specific of using a plurality of thresholds for analysis of information given different criteria provided into the software analysis of Zawadowskiy as modified by Copty and Katkoori for the purpose of increasing the adaptability of the system by being having adjustable threshold condition based on additional factors used to make decisions, as taught by Magi Col. 4 lines 11-21. Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty and Katkoori as applied to claim 8 above, and further in view of Pulla et al. (Patent No. US 8,682,985 B2). As to claim 14, Zawadowskiy as modified by Copty and Katkoori do not specifically disclose wherein the one or more processors comprise one or more processors across organizational boundaries; and determining the telemetry comprises aggregating observation data from the one or more processors, the observation data representing the telemetry However, Pulla discloses wherein the one or more processors comprise one or more processors across organizational boundaries (Pulla Col. 3 lines 11-17 and line 57-Col. 4 line 3, Col. 9 lines 40-48 and Col. 12 lines 23-34; which shows an environment for cross boundary tracking of information, where computer devices including processors can be on both sides of an organizational boundary); and determining the telemetry comprises aggregating observation data from the one or more processors, the observation data representing the telemetry (Pulla Col. 3 lines 11-17 and line 57-Col. 4 line 3, Col. 9 lines 40-48 and Col. 12 lines 23-34; which shows an environment for cross boundary tracking of information, where the collected/determined/tracked data is aggregated together, that in light of the teachings of Zawadowskiy above is viewed as including tracked/observation data representing the telemetry). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Pulla showing normalizing collected telemetry data into the software analysis with telemetry data of Zawadowskiy as modified by Copty and Katkoori for the purpose of increase effective use of tracking and monitoring system by being able to track and monitor data from a plurality of organizations, as taught by Pulla Col. 1 lines 21-27 and Col. 3 lines 11-17. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claim 15 above, and further in view of Pulla et al. (Patent No. US 8,682,985 B2). As to claim 20, Zawadowskiy as modified Copty, Katkoori and Malin do not specifically disclose, however, Pulla discloses wherein: the one or more processors comprise one or more processors across organizational boundaries; and determining the telemetry comprises aggregating observation data from the one or more processors, the observation data representing the telemetry (Pulla Col. 3 lines 11-17 and line 57-Col. 4 line 3, Col. 9 lines 40-48 and Col. 12 lines 23-34; which shows an environment for cross boundary tracking of information, where computer devices including processors can be on both sides of an organizational boundary and for the cross boundary environment being able to track information, where the collected/determined/tracked data is aggregated together, that in light of the teachings of Zawadowskiy above is viewed as including tracked/observation data representing the telemetry). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Pulla showing normalizing collected telemetry data into the software analysis with telemetry data of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of increase effective use of tracking and monitoring system by being able to track and monitor data from a plurality of organizations, as taught by Pulla Col. 1 lines 21-27 and Col. 3 lines 11-17. Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claim 1 above, and further in view of Magi et al. (Patent No. US 11, 809,535 B2) and Salaegheh et al. (Pub. No. US 2017/0206350 A1) As to claim 21, Zawadowskiy as modified by Copty, Katkoori and Malin do not specifically disclose wherein determining the confidence score comprises: receiving one or more policy allowance conditions associated with one or more unobserved transfers not represented in the control flow directed graph; wherein determining to transition from the observation phase to the monitoring phase is based on the confidence score meeting the second threshold in response to the one or more policy allowance conditions being satisfied, such that the monitoring phase is entered prior to the confidence score reaching the first threshold. However Magi disclose wherein determining to transition from the observation phase to the monitoring phase is based on the confidence score meeting the second threshold in response to the one or more policy allowance conditions being satisfied, such that the monitoring phase is entered prior to the confidence score reaching the first threshold (Magi Col. 12 lines 54- Col. 13 line 14 and Col. 14 lines 48- 67 and claim 1; which shows being able to have multiple levels set for a threshold that can be used to trigger specific action performance where the different levels for threshold use can be based on further received conditions, seen specifically as other measured values of confidence thus have a plurality of thresholds at different levels and thus some that are reached before/at different points than other thresholds where at the generic level the policy allowance condition being satisfied can be viewed as its own second threshold, but the specifics of the policy allowance condition being specifically disclosed in Salajegheh below, and together with the specific teachings of Katkoori and Copty above showing the specific of how coverage metric/confidence score and associated goal/threshold can be used to show the trigger switch between an observation/analysis phase and a monitoring/enforcement phase that together are viewed as showing determining to transition from the observation phase to the monitoring phase is based on the confidence score meeting the second threshold in response to the one or more policy allowance conditions being satisfied, such that the monitoring phase is entered prior to the confidence score reaching the first threshold). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Magi showing the specific of using a plurality of thresholds for analysis of information given different criteria provided into the software analysis of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of increasing the adaptability of the system by being having adjustable threshold condition based on additional factors used to make decisions, as taught by Magi Col. 4 lines 11-21. Zawadowskiy as modified by Copty, Katkoori, Malin and Magi do not specifically disclose wherein determining the confidence score comprises: receiving one or more policy allowance conditions associated with one or more unobserved transfers not represented in the control flow directed graph However, Salaegheh disclose wherein determining the confidence score comprises: receiving one or more policy allowance conditions associated with one or more unobserved transfers not represented in the control flow directed graph (Salajegheh [0044] lines 1-16, [0048] lines 1-8, [0051] lines 1-11 and [0054] lines 5-20; which shows being able to determine for an unused path/transition associated with a control flow graph is reached and determine/calculate a risk summary associated with that path/transition, where the risk summary can be an evaluated expression that can be determined true/false and used to trigger an action based on determination, viewed as a type of risk score/allowance condition for previously unused/unobserved transfers, viewed as transfer not represented in the control flow directed graph information) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Salaegheh showing the specifics of determining information for a new previously unobserved path transfers and if triggers specific action, into the analysis based on control flow graph information of Zawadowskiy as modified by Copty, Katkoori, Malin and Magi for the purpose of improving performance so execution does not can determine risk associated with new paths encountered and alert if determined issue for the execution of the path, as taught by Salaegheh [0048] lines 1-8. Claim 23 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claim 1 above, and further in view of Sasikumar et al. (Patent No. US 8,407,322 B1) and Hu et al. (Pub. No. US 2021/0349723 A1) As to claim 23, Zawadowskiy as modified by Copty, Katkoori and Malin do not specifically disclose wherein determining the telemetry during the observation phase comprises: identifying a binary of the application associated with the processes; dividing the binary into a plurality of code segments based on control flow boundaries within the binary; assigning each of the plurality of code segments to a respective computing node of a plurality of computing nodes for observation; and aggregating observation data from each of the respective computing nodes, the observation data representing observed control flow transitions for the assigned code segments of the respective computing node, wherein the aggregated observation data comprises the telemetry. However, Sasikumar discloses wherein determining the telemetry during the observation phase comprises: assigning each of the plurality of code segments to a respective computing node of a plurality of computing nodes for observation; and aggregating observation data from each of the respective computing nodes, the observation data representing observed control flow transitions for the assigned code segments of the respective computing node, wherein the aggregated observation data comprises the telemetry (Sasikumar Col. 9 lines 40-45 and Col. 12 lines 10-36; which shows the ability for software code being able to identify and divide the code into specific code blocks where the different code block are assigned to different to different computer devices, viewed as computing nodes for performing and processing their assigned information and the ability to share and aggregate their individual determined information together, which in light of the teachings of Zawadowskiy above for the observation/analysis/learning phase of execution code to determine/identify associated telemetry data that can includes associated transitions and thus together view show wherein determining the telemetry during the observation phase comprises: assigning each of the plurality of code segments to a respective computing node of a plurality of computing nodes for observation; and aggregating observation data from each of the respective computing nodes, the observation data representing observed control flow transitions for the assigned code segments of the respective computing node, wherein the aggregated observation data comprises the telemetry). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Sasikumar showing the specific of dividing code into separate code blocks for analysis into the software analysis of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of increasing the adaptability of the system by being able facilitate the determination and execution of divided code blocks on a plurality of different computing devices, as taught by Sasikumar Col. 1 lines 36-44 and Col. 9 lines 40-45. Zawadowskiy as modified by Copty, Katkoori, Malin and Sasikumar do not specifically disclose the specifics of identifying a binary of the application associated with the processes; dividing the binary into a plurality of code segments based on control flow boundaries within the binary. However, Hu discloses the specifics of identifying a binary of the application associated with the processes; dividing the binary into a plurality of code segments based on control flow boundaries within the binary (Hu [0024] lines 1-10; which show disassembly methods for the determined/identified binary file for the program, viewed as the binary of the application associated with this process and being able to disassembly/divide the binary into a plurality of elements/code segments as it follows the control flow edge/boundary thus viewed as the segments being divided based on the control flow boundaries/edges within the binary). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Hu showing the specifics of control flow analysis through disassembly of the binary along control flow edge traversal, into the control flow observation and analysis of Zawadowskiy as modified by Copty, Katkoori, Malin and Sasikumar for the purpose of improving control flow analysis to help identify and eliminate false positive in the analysis, as taught by Hu [0024] lines 1-3. Claim 24 is rejected under 35 U.S.C. 103 as being unpatentable over Zawadowskiy, Copty, Katkoori and Malin as applied to claim 1 above, and further in view of Salaegheh et al. (Pub. No. US 2017/0206350 A1) As to claim 24, Zawadowskiy does not specifically disclose, however, Copty discloses inputting each of the one or more unobserved transfers into a machine learning model, wherein the machine learning model is trained to evaluate a risk associated with control flow transfers based at least in part on transfers represented in the control flow directed graph (Copty [0059] lines 1-17, [0098] lines 1-18 and [0107] lines 1-19; which shows that input provided to a machine learning model and used to determine associated risk classification associated with the input where the input to the machine learning model elements can be based on input associated with path information associated with the control flow graph, where the specifics of overserved transfer/paths as input into a risk analysis system are seen specifically disclose below in the teachings of Salaegheh) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Copty showing the specifics of determine a coverage based on control flow graph and total application information, into the software analysis of Zawadowskiy for the purpose of improving generated control flow graph coverage model so that further/additional paths are determined and covered and included in the control flow graph and increase its coverage and thus increase the overall accuracy of the generated control flow graph, as taught by Copty [0059] lines1-4 and [0087] lines 1-5 Zawadowskiy as modified by Copty, Katkoori and Malin do not specifically disclose identifying one or more unobserved transfers not represented in the control flow directed graph during the monitoring phase; evaluate a risk associated with control flow transfers based at least in part on transfers represented in the control flow directed graph; and determining a risk score for each of the one or more unobserved transfers based on an output of the machine learning model; wherein performing the remediation action is further based on the risk score for the unobserved transfer. However, Salajegheh discloses identifying one or more unobserved transfers not represented in the control flow directed graph during the monitoring phase; evaluate a risk associated with control flow transfers based at least in part on transfers represented in the control flow directed graph; and determining a risk score for each of the one or more unobserved transfers based on an output of the machine learning model; wherein performing the remediation action is further based on the risk score for the unobserved transfer (Salajegheh [0044] lines 1-16, [0048] lines 1-8, [0051] lines 1-11 and [0054] lines 5-20; which shows being able to determine for an unused path/transition associated with a control flow graph is reached, viewed as identified a new/unobserved transfer associated with the control flow graph and determine/calculate a risk summary associated with that path/transition, where the risk summary can be an evaluated expression that can be determined true/false and used to trigger an action based on determination, viewed as a type of output of evaluation of risk and an associated risk score/value for previously unused/unobserved/new transfers, viewed as transfer not represented in the control flow directed graph information, that in light of the teachings of Copty above showing the use of machine learning model to evaluate risk associated with control flow graph can be viewed as the showing the machine learning model output of the risk score/summary information where based on the risk summary/score calculated/determined for the current path can trigger an alert, viewed as type of remediation action where additional detail on remediation actions are seen specifically disclosed in the teachings of Zawadowskiy above ) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Salaegheh showing the specifics of determining information for a new previously unobserved path transfers and if triggers specific action, into the analysis based on control flow graph information of Zawadowskiy as modified by Copty, Katkoori and Malin for the purpose of improving performance so execution does not can determine risk associated with new paths encountered and alert if determined issue for the execution of the path, as taught by Salaegheh [0048] lines 1-8. Allowable Subject Matter Claim 22 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRADFORD F WHEATON whose telephone number is (571)270-1779. The examiner can normally be reached Monday-Friday 8:00-5:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Chat Do can be reached at 571-272-3721. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRADFORD F WHEATON/Examiner, Art Unit 2193
Read full office action

Prosecution Timeline

Show 2 earlier events
Sep 15, 2025
Interview Requested
Sep 24, 2025
Applicant Interview (Telephonic)
Sep 29, 2025
Examiner Interview Summary
Sep 29, 2025
Response Filed
Dec 19, 2025
Final Rejection mailed — §103, §112
Mar 19, 2026
Request for Continued Examination
Mar 24, 2026
Response after Non-Final Action
May 27, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705160
MANAGING COMPUTING RESOURCE CONSUMPTION OF SOFTWARE APPLICATIONS USING CONTROL GROUPS TO FACILITATE SAFETY COMPLIANCE
2y 8m to grant Granted Aug 11, 2026
Patent 12699769
DYNAMIC RUNTIME MICRO-SEGMENTATION OF INTERPRETED LANGUAGES
3y 2m to grant Granted Aug 04, 2026
Patent 12688021
PROCESSOR CONTROLLED PROGRAMMABLE LOGIC DEVICE MODIFICATION
6y 7m to grant Granted Jul 21, 2026
Patent 12688014
GENERATING APPLICATIONS FOR VARIOUS PLATFORMS BY USE OF A NO CODE ENVIRONMENT
3y 5m to grant Granted Jul 21, 2026
Patent 12688029
COMMUNICATION APPARATUS FOR WIRELESSLY COMMUNICATING WITH ANOTHER APPARATUS, INFORMATION PROCESSING METHOD, AND PROGRAM
3y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
73%
With Interview (+11.2%)
3y 11m (~7m remaining)
Median Time to Grant
High
PTA Risk
Based on 390 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month