Prosecution Insights
Last updated: August 18, 2026
Application No. 18/207,058

ANALYSES AND AGGREGATION OF DOMAIN BEHAVIOR FOR EMAIL THREAT DETECTION BY A CYBER SECURITY SYSTEM

Final Rejection §103§112
Filed
Jun 07, 2023
Priority
Jun 09, 2022 — provisional 63/350,781 +1 more
Examiner
CELANI, NICHOLAS P
Art Unit
2449
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
4 (Final)
46%
Grant Probability
Moderate
5-6
OA Rounds
0m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
213 granted / 463 resolved
-12.0% vs TC avg
Strong +42% interview lift
Without
With
+42.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
37 currently pending
Career history
501
Total Applications
across all art units

Statute-Specific Performance

§101
15.8%
-24.2% vs TC avg
§103
51.0%
+11.0% vs TC avg
§102
3.1%
-36.9% vs TC avg
§112
25.5%
-14.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 463 resolved cases

Office Action

§103 §112
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following claim(s) is/are pending in this office action: 1-19 The following claim(s) is/are amended: 1, 9, 16 The following claim(s) is/are cancelled: - The following claim(s) is/are new: - Claim(s) 1-19 is/are rejected. This rejection is FINAL. Response to Arguments Applicant’s arguments filed in the amendment filed 7/1/2026, have been fully considered but are moot in view of new grounds of rejection. The reasons set forth below. Applicant’s Invention as Claimed Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claim(s) 1-19 is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Claim 1 is representative and claims “in response to the email module detecting the email is directed a source email address falsely identifying the domain as part of the source email address.” The limitation makes no sense. Examiner construes the language based on the included Remarks (see Remarks, 2/6/2026) as calling back to the functionality of the email module. Claim limitation “email module,” “autonomous response module,” and “inoculation module” invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. Claims 1 and 9 claim modules configured to perform functions and therefore invoke means plus without the specification disclosing an algorithm of sufficient specificity for performing the function. Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. The above cited rejections are merely exemplary. The Applicant(s) are respectfully requested to correct all similar errors. Claims not specifically mentioned are rejected by virtue of their dependency. Claim Rejections - 35 USC § 103 A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-19 are rejected under 35 U.S.C. 103 as being unpatentable over Dreller (US Pub. 2014/0082726) in view of Gilliam (US Pat. 11,277,375) and further in view of Adams (US Pub. 2018/0007064). With respect to Claim 1, Dreller teaches a cyber security appliance to protect a domain associated with an organization or user, comprising: (Fig. 1, paras. 5, 29-32; system classifies incoming mail and uses a phishing/spoofing detection engine to determine if an email is malicious.) One or more processors; and a non-transitory storage medium accessible by the one or more processors, the non-transitory storage medium comprises (para. 26; processor and hard disk.) an email module communicatively coupled to the communication module, the email module comprises email report analysis logic configured to analyze content within an email authentication report received via the one or more input/output (I/O) ports to detect an email suspected of being malicious (I/O ports will be taught later. para. 29-31; classification server parses parts of messages such as FROM DOMAIN and SENDING IP ADDRESS to classify messages as possibly being suspicious or having authentication problems. para. 32-35; phish detection engine receives the data from the classifier and other data to analyze messages from domains not owned by a customer. The engine provides results to alerting and reporting servers to notify of possible security events. Fig. 3, paras. 40-49; Classifier runs multiple checks including DMARC analysis.) when the email is directed to a computing device operating outside of the domain and a source email address of the email falsely identifying the domain as part of the source email address; (para. 32; analysis of message from domains not owned by a customer. Paras. 8-9; DMARC is used to authenticate that a message is from a particular domain it claims to be from. Para. 50; system considers both domain and non-domain phishing. Paras. 51-52; system searches for messages from outside corporation that may use corporate lookalike messages.) based on a frequency of emails that fail authentication (para. 34; system takes action based on the number of suspicious messages over a threshold in a defined time period, which is a frequency.) But Dreller does not explicitly teach a communication module including one or more input/output (I/O) ports. Gilliam, however, teaches a communication module including one or more input/output (I/O) ports, (Fig. 4, col. 4, ln. 62 to col. 5, ln. 13 and col. 6, lns. 4-20; network interface to allow computer to communicate with other devices such as a wireless data port. See also Dreller, Fig. 1, para. 26; devices communicating in a networked system, which suggests a communication module with input/output. Para. 36; data source inputs.) an autonomous response module communicatively coupled to the email module, the autonomous response module is configured, in response to the email module detecting the email is directed a source email address falsely identifying the domain as part of the source email address to cause a first set of autonomous actions to mitigate one or more emails directed to the computing device or falsely identifying the domain from dissemination over a network; and (col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains. See also Dreller, para. 26; method is performed automatically in real time without delay. para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the appliance of Dreller with the I/O ports of Gilliam in order to communicate over a network and to allow for facilitating contact of owners or updating of SPF records. But modified Dreller does not explicitly teach an inoculation module configured to perform a DOS. Adams, however, does teach an inoculation module communicatively coupled to the email module, the inoculation module is configured, in response to the email module detecting the email is directed from a source email address falsely identifying the domain as part of the source email address to further cause a second set of autonomous actions, wherein the second set of autonomous actions includes one or more offensive actions including issuance of a Denial of Service (DOS) attack on a malicious server from which the email originated in response to the email module identifying the malicious server sending the email falsely identifying the domain. (para. 106; security server identifies a malicious server and initiates a DOS attack on it to cause it to crash.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the appliance of modified Dreller with the DOS attack in order to protect the system by crashing the malicious device. With respect to Claim 2, modified Dreller teaches the cyber security appliance of claim 1, and Gilliam also teaches wherein the email module further comprises email authentication set-up logic configured to notify and assist domain administrators in response to the email report analysis logic identifying potential Domain Name System (DNS) sever misconfiguration based on the content of the email authentication report. (col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains or performing SPF updating. See also Dreller, para. 36; report output for an authentication problem contains DKIM and SPF results that a customer will find useful to understand authentication problems on their mail servers. Fig. 6, paras. 64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication including rDNS hostname.) The same motivation to combine as the independent claim applies here. With respect to Claim 3, modified Dreller teaches the cyber security appliance of claim 2, and Dreller also teaches wherein the email authentication report corresponds to a Domain-based Message Authentication, Reporting and Conformance (DMARC) aggregate report includes content associated with emails that utilize the domain as part of its source address. (paras. 8-9; DMARC aggregate report) With respect to Claim 4, modified Dreller teaches the cyber security appliance of claim 3, and Dreller also teaches wherein the DMARC aggregate report includes content that identifies an email failing at least one of a plurality of authentications to categorize the email as malicious, the plurality of authentications include a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain and a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email has not been modified during transit.( paras. 8, 30, 41; SPF and DKIM results. paras. 29-31, 36; messages marked as suspicious. para. 41; DKIM and SPF results. Para. 48; Forwarder check by sending DKIM result to DMARC aggregate data. Paras. 8-9; DMARC combines DKIM and SPF check with an identifier alignment check. Paras. 45-46; authentication check that includes FROM, MFROM and DKIM alignment. Para. 9; SPF deals with authorization use of domains in email.) With respect to Claim 5, modified Dreller teaches the cyber security appliance of claim 4, and Dreller also teaches wherein the plurality of authentications include DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address. (Paras. 8-9; DMARC combines DKIM and SPF check with an identifier alignment check. Para. 46; FROM, MFROM and DKIM domains are compared to check alignment.) With respect to Claim 6, modified Dreller teaches the cyber security appliance of claim 4, and Gilliam also teaches wherein the autonomous response module configured to provide data to be rendered on a display to assist a domain administrator in configuring a DMARC record that adjusts the DMARC authentication or a SPF record that adjusts the SPF authentication. (col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains or performing SPF updating. See also Dreller, para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) The same motivation to combine as the independent claim applies here. With respect to Claim 7, modified Dreller teaches the cyber security appliance of claim 1, and Dreller also teaches wherein the inoculation is further configured to the second set of autonomous actions including one or more defensive actions including issuance of an alert. (para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) With respect to Claim 8, modified Dreller teaches the cyber security appliance of claim 1, and Dreller also teaches communicatively coupled to a global domain intelligence data store to provide results of the analysis of the content within the email authentication report along with the content of the email authentication report to assist in reconfiguration of a plurality of email authentications conducted during transmission of the email and global tracking of behavior of a source of the suspected malicious email. (Examiner asserts the language after “to assist in” is not entitled to patentable weight. Regardless, Examiner cites Dreller to teach. para. 13, 41, 51, 85; message attributes including body content are stored and used in reports. Para. 54; reports to third parties such as ISPs. Para. 34; alerting and reporting happens in real-time.) With respect to Claim 9, Dreller teaches implemented within a cyber security appliance, a non-transitory storage medium configured to store instructions in a format that, when executed by a processor, (para. 26; processor and hard disk.) identifies malicious spoofing and phishing emails to protect a domain associated with an organization or user, the non-transitory storage medium comprising: (Fig. 1, paras. 5, 29-32; system classifies incoming mail and uses a phishing/spoofing detection engine to determine if an email is malicious.) an email module including email report analysis logic is configured to, when executed by the processor, analyze content within an email authentication report (para. 29-31; classification server parses parts of messages such as FROM DOMAIN and SENDING IP ADDRESS to classify messages as possibly being suspicious or having authentication problems. para. 32-35; phish detection engine receives the data from the classifier and other data to analyze messages from domains not owned by a customer. The engine provides results to alerting and reporting servers to notify of possible security events. Fig. 3, paras. 40-49; Classifier runs multiple checks including DMARC analysis.) received from an Internet Service Provider (ISP) (para. 32; analysis of message from domains not owned by a customer. Paras. 8-9; DMARC is used to authenticate that a message is from a particular domain it claims to be from. Para. 50; system considers both domain and non-domain phishing. Paras. 51-52; system searches for messages from outside corporation that may use corporate lookalike messages. Para. 30, 60, 69; data is from ISPs. To the extent that some functionality is performed by the classifier server it would have been obvious to one of ordinary skill prior to the effective filing date to move the reporting functionality of the classifier server to the ISP because it is a simple substitution for predictable results in that the ownership of the server does not affect its functionality.) to detect an email suspected of being malicious upon failure of an authentication process that detects when the email is directed to a computing device operating outside of the domain and a source address of the email falsely identifies the domain as part of the source email address; (para. 32; analysis of message from domains not owned by a customer. Paras. 8-9; DMARC is used to authenticate that a message is from a particular domain it claims to be from. Para. 50; system considers both domain and non-domain phishing. Paras. 51-52; system searches for messages from outside corporation that may use corporate lookalike messages.) based on a frequency of emails that fail authentication (para. 34; system takes action based on the number of suspicious messages over a threshold in a defined time period, which is a frequency.) But Dreller does not explicitly teach an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to, when executed by the processor, cause a first set of autonomous actions to mitigate one or more emails directed to the computing device or falsely identifying the domain from dissemination over a network. Gilliam, however, does teach and an autonomous response module communicatively coupled to the email module, the autonomous response module is configured to, when executed by the processor, cause a first set of autonomous actions to mitigate one or more emails directed to the computing device or falsely identifying the domain from dissemination over a network; and (col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains. See also Dreller, para. 26; method is performed automatically in real time without delay. para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the appliance of Dreller with the autonomous response module of Gilliam in order to contact owners of invalid domains to provide a fast and accurate method of determining validity. (Gilliam, col. 2, lns. 32-54) But modified Dreller does not explicitly teach an inoculation module configured to perform a DOS. Adams, however, does teach an inoculation module communicatively coupled to the email module, the inoculation module is configured to, when executed by the processor and in response to the email module detecting the email is directed from a source email address falsely identifying the domain as part of the source email address cause a second set of autonomous actions, wherein the second set of autonomous actions includes one or more offensive actions including issuance of a Denial of Service (DOS) attack on a malicious server from which the email originated. (para. 106; security server identifies a malicious server and initiates a DOS attack on it to cause it to crash.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the appliance of modified Dreller with the DOS attack in order to protect the system by crashing the malicious device. With respect to Claims 10-15, they are substantially similar to Claims 2-7, respectively, and are rejected in the same manner, the same art and reasoning applying. With respect to Claim 16, Dreller teaches a method for a cyber security appliance to protect a domain associated with an organization or user, comprising: (Fig. 1, paras. 5, 29-32; system classifies incoming mail and uses a phishing/spoofing detection engine to determine if an email is malicious.) analyzing content within an email authentication report received from a resource external to the domain (para. 29-31; classification server parses parts of messages such as FROM DOMAIN and SENDING IP ADDRESS to classify messages as possibly being suspicious or having authentication problems. para. 32-35; phish detection engine receives the data from the classifier and other data to analyze messages from domains not owned by a customer. The engine provides results to alerting and reporting servers to notify of possible security events. Fig. 3, paras. 40-49; Classifier runs multiple checks including DMARC analysis.) to determine whether an email, observed as using the domain as part of its source email address, has failed at least one of a plurality of email authentication processes, (para. 32; analysis of message from domains not owned by a customer. Paras. 8-9; DMARC is used to authenticate that a message is from a particular domain it claims to be from. Para. 50; system considers both domain and non-domain phishing. Paras. 51-52; system searches for messages from outside corporation that may use corporate lookalike messages.) wherein the plurality of email authentication processes include (i) a first authentication process configured to confirm that the email is being sent from a mail server authorized to send emails on behalf of the domain, (paras. 8, 30, 41; SPF result. Applicant also admits this functionality preexisted, see Spec, Background, para. 5; SPF) (ii) a second authentication process configured to confirm that the content of the email has not been modified during transit, (paras. 8, 30, 41; DKIM result. Applicant also admits this functionality preexisted, see Spec, Background, para. 7; DKIM) and (iii) a third authentication process configured to detect misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address; (para. 8; DMARC checks for alignment between FROM header, mail from, and the DKIM domain. Paras. 29-31; DMARC forensic and aggregate data) determining whether the email corresponds to a suspected malicious email upon the email failing at least one of the plurality of email authentication processes; (para. 29-31; classification server parses parts of messages such as FROM DOMAIN and SENDING IP ADDRESS to classify messages as possibly being suspicious or having authentication problems. para. 32-35; phish detection engine receives the data from the classifier and other data to analyze messages from domains not owned by a customer. The engine provides results to alerting and reporting servers to notify of possible security events. Fig. 3, paras. 40-49; Classifier runs multiple checks including DMARC analysis.) based on a frequency of emails that fail authentication (para. 34; system takes action based on the number of suspicious messages over a threshold in a defined time period, which is a frequency.) But Dreller does not explicitly teach and performing a first set of autonomous actions to mitigate continued dissemination of emails over a network by a malicious actor originating the suspected malicious email. Gilliam, however, does teach and performing a first set of autonomous actions to mitigate continued dissemination of emails over a network by a malicious actor originating the suspected malicious email. (col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains. See also Dreller, para. 26; method is performed automatically in real time without delay. para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of Dreller with the actions of Gilliam in order to improve security by validating emails and responding to threats. But modified Dreller does not explicitly teach performing a DOS. Adams, however, does teach performing a second set of autonomous actions to further mitigate continued dissemination over the network in response to detecting the email is directed from a source email address falsely identifying the domain as part of the source email address, wherein the second set of autonomous actions includes one or more offensive actions including issuance of a Denial of Service (DOS) attack on a malicious server from which the email originated. (para. 106; security server identifies a malicious server and initiates a DOS attack on it to cause it to crash.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Dreller with the DOS attack in order to protect the system by crashing the malicious device. With respect to Claim 17, modified Dreller teaches the method of claim 16, and Dreller also teaches wherein the first set of autonomous actions include (i) one or more defensive actions including issuance of an alert across to multiple cyber security appliances across multiple domains including the domain or (ii) one or more offensive actions including issuance of a Denial of Service (DoS) attack on a malicious server from which the suspected malicious email originated. (para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action.) With respect to Claim 18, modified Dreller teaches the method of claim 16, and Dreller also teaches wherein the first email authentication process corresponds to a Sender Policy Framework (SPF) authentication that confirms that the email is being sent from a mail server authorized to send emails on behalf of the domain, (paras. 8, 30, 41; SPF result. Applicant also admits this functionality preexisted, see Spec, Background, para. 5; SPF) the second email authentication process corresponds to a DomainKeys Identified Mail (DKIM) authentication that confirms that the content of the email have not been modified during transit, (paras. 8, 30, 41; DKIM result. Applicant also admits this functionality preexisted, see Spec, Background, para. 7; DKIM) and the third email authentication process corresponds to a DMARC authentication that detects whether a misalignment between an actual email address of an email sender and the source email address included within a From header field of the email identifying the domain as part of the source email address. (para. 8; DMARC checks for alignment between FROM header, mail from, and the DKIM domain. Paras. 29-31; DMARC forensic and aggregate data) With respect to Claim 19, modified Dreller teaches the method of claim 16, and Gilliam also teaches further comprising: provide results of an analysis of the content within the email authentication report along with the content of the email authentication report to a global domain intelligence data store to (i) provide real-time access of the results and the content to an administrator to assist in reconfiguration of one or more of the plurality of email authentication processes and (ii) enable global tracking of behavior of the email sender of the suspected malicious email. (Examiner asserts that anything beyond providing the results to a global data store is not entitled to patentable weight. Regardless, Examiner cites Gilliam, col. 2, lns. 32-54 and col. 3, ln. 58 to col. 4, ln. 5; system uses GUI to present report on SPF validity to admin that includes reasons why domains are invalid and allow actions that facilitate contacting owners of invalid domains. See also Dreller, para. 26; method is performed automatically in real time without delay. para. 54; system sends out alerts and reports to clients, ISPs, mailbox providers and security take down vendors. Figs. 4, 6, paras. 56-60, 63-64, 67; system provides information to help identify which servers or IPs are failing SPF and DKIM authentication and identify malicious messages including how other systems handled the message and providing the ability to take action. Para. 34; alerting and reporting happens in real-time.) The same motivation to combine as the independent claim applies here. Remarks Applicant argues at Remarks, pgs. 9-10 that the amendment to the claims that includes the word “from” fixes the ambiguity in the claim meaning. Examiner agrees but Applicant only makes the change in one of the two occurrences, as both the autonomous response module and the inoculation module include the language and only the inoculation language is modified. Consequently, Examiner must maintain the ground of rejection for now. Applicant argues at Remarks, pgs. 10-20 that the email, autonomous response, and inoculation modules as claimed do not invoke 112f. The limitations invoke 112f, so Examiner will maintain the construction. With perhaps one exception, Applicant does not argue that the claims are definite under 112b if the claims are in means-plus, so Examiner will maintain the 112b in view of f. There is a lot to unpack here, so Examiner begins with the proper standard. Applicant states that “The Examiner needs to understand that a presumption of 35 US 112(f) interpretation only exists when the term ‘means for’ or ‘step for’ is used in a claim.” Examiner understands that the claims here do not use means-for and agrees that this creates a rebuttable presumption that the limitations do not invoke 112f. Whether the presumption is overcome is controlled by MPEP 2181. In the middle of Remarks, pg. 11, Applicant asserts that “to rebut this presumption, the Examiner must demonstrate:” three things. Examiner disagrees that the three things listed on pg. 11 are what Examiner must demonstrate. At Remarks, pgs. 12-13, Applicant states that “The PTO directs Examiners to apply 35 USC 112(f) to a claim limitation if it meets all of the following 3-prong analysis.” This three prong analysis is correct, as it appears to be taken directly from MPEP 2181(I). It is not clear to Examiner why Applicant asserts a 3 point analysis on pg. 11 and, almost immediately after, asserts a different 3 prong analysis on pg. 12. Regardless, Examiner follows the MPEP and the pg. 12 3-prong analysis is the correct one. We begin with the first prong (Prong A) – “the claim limitation uses the term ‘means’ or ‘step’ or a term used as a substitute for ‘means’ that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function.” (Remarks, pg. 12, MPEP 2181(I)) At Remarks, pg. 11, Applicant quotes from MPEP 2181, “Note that there is no fixed list of generic placeholders that will always result in 35 USC 112(f) interpretation…” Examiner notes that the immediately preceding sentence in the MPEP states “The following is a list of non-structural generic placeholders that may invoke 35 USC 112(f): …’module for’…’component for’…” Therefore the MPEP explicitly states that “module” may be a non-structural term that functions as a generic placeholder that stands in for “means.” At Remarks, pgs. 11-12, Applicant cites Williamson v. Citrix Online, 792 F.3d 1339. Examiner agrees that Williamson is extremely relevant to the instant issue. In Williamson the court considered a distributed learning system implemented by networked computers, i.e., also a computer-implemented invention. Claim 8 in Williamson was directed to “A system for conducting distributed learning among a plurality of computer systems coupled to a network, the system comprising:…a distributed learning server remote from [other devices] and coupled to the [other devices] and comprising:…a distributed learning control module for receiving communications transmitted between the [other devices] and for relaying the communications to an intended receiving computer system and for coordinating the operation of the streaming data module.” Therefore the “module” in Williamson was also related to a computing device. The court found that “This [limitation], as lengthy as it is, is nonetheless in a format consistent with traditional means-plus-function claim limitations. It replaces the word ‘means’ with the word ‘module’ and recites three functions performed by the ‘distributed learning control module.’ ‘Module’ is a well-known nonce word that can operate as a substitute for ‘means’ in the context of 112, para. 6. As the district court found, ‘module’ is a simply a generic description for software or hardware that performs a specified function.” The court went on to find that the claimed distributed learning control module invokes 112f. MPEP 2181(I)(A) considers Williamson, and states that “the Federal Circuit determined that the word ‘module’ does not provide any indication of structure because it sets forth the same black box recitation of structure for providing the same specified function as if the term ‘means’ had been used.” At Remarks, pg. 15, Applicant acknowledges the Williamson holding is against Applicant’s position and attempts to distinguish from Williamson based on the passage of time. Consequently, Applicant’s argument that “The Office Action…makes a conclusory assertion that the [module terms] are merely generic placeholders” is unpersuasive, as the claims are similar to those in Williamson and the Court’s logic applies. MPEP 2181(I)(A) expressly identifies a module for as a nonce term that can fulfill Prong A of the analysis. We next move to Prong B – “the term ‘means’ or ‘step’ or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g. “means for”) or another linking word or phrase, such as “configured to” or “so that.” The email module “comprises logic configured to: [perform functions].” The autonomous response module “is configured…to [perform functions].” The inoculation module…is configured…to [perform functions].” Applicant does not appear to dispute that the elements include functional recitations. Rather, Applicant argues at Remarks, pg. 13 that “The Office Action does not provide any reasoning or analysis demonstrating that the claim terms are purely functional and lack structure.” But that is not the standard. Prong B does not require the terms be “purely functional,” rather it requires the generic placeholder from Prong A to be “modified by functional language.” The modules are modified by functional language. Prong C requires “the term ‘means’ or ‘step’ or the generic placeholder is not modified by sufficient structure, material or acts for performing the claimed function.” To the extent that the above argument implicates Prong C because it complains that the Office Action does not demonstrate the terms “lack structure,” that is not the standard. Rather the standard is “sufficient structure [] for performing the claimed function.” Here Examiner needs to pause because Applicant’s argument veers off the rails a bit. Applicant asserts at Remarks, pgs. 13-14 that “support for the terms and structure can be found throughout the specification.” Applicant cites multiple paragraphs in the Specification and reproduces Spec, paras. 146, 152. The citations are not relevant to this part of the analysis. Prong C is directed to the claim language. The specification is only relevant if the specification defines a claim term in some structural way, because the specification can set a non-plain-meaning definition for a claim term. But the analysis is directed to the claim, not to the specification. In this case, the specification does not define the terms “email module,” “autonomous response module,” or “inoculation module” and the cited paras. 146, 152 do not even mention them. Because the specification does not define a module as meaning some structural thing, the description that, e.g., “Some portion of this description are presented in algorithms…These algorithms can be written in a number of different software programming language such as Python, C, C++…” is simply not relevant for whether the claim is invoking 112f. In a more relevant vein, Applicant next argues the plain meaning of “module” is now structural. Applicant attaches some documents and argues at Remarks, pgs. 14-15 that “Perhaps in 2015 when Williamson v. Citrix Online was decided the term ‘module’ was not a well-known structure to one skilled in the art of computer technology…but Applicant submits definitions that evidence that a ‘module’ does not in 2026 have a well understood structural meaning in the computer technology field.” This argument is relevant to the question but fails on both legal and factual grounds. The instant application claims priority to two provisional applications filed 6/9/2022 and 8/8/2022. The instant application was filed 6/7/2023. Claims are not construed as of their examination date, claims are construed as of their effective filing date. (MPEP 2111.01(III)) Consequently, the question is not what claim terms means in 2026 but what they meant in either 2022 or 2023. Applicant’s undated citations which appear to be from current day accesses are not evidence of the meaning of the term in 2023. Regardless, Examiner gives consideration to the citations because even if they were appropriately dated they would not prove the terms are structural. As an initial point, Applicant only asserts that “module” has a structural meaning, but the claim terms are “email module” “autonomous response module” and “inoculation module.” Applicant’s evidence is unpersuasive inasmuch as Applicant has to show that “email module” has a “sufficiently definite meaning as a name for structure” and Applicant presents at least one reference that distinguishes amongst types of modules. Setting that to the side, Applicant’s references confirm that module is a functional description rather than a structural one. PCMag states “A software module (program module) comes in the form of a file and typically handles a specific task within a larger software system.” “Typically handles a specific task within a larger software system” is a functional, not structural, definition. Examiner does not believe “file” to be a structural term either, but to the extent it could be it is not what the art understood to be a structure for “module” because Applicant’s other citations do not identify modules as files. Wikitionary, conversely to PCMag, states a module is “a section of a program; a subroutine or group of subroutines,” rather than a file. TechTarget similarly states “In computer software, a module is an extension to a main program dedicated to a specific function.” This again is a functional rather than structural definition. Modular Electronics also defines modules functionally: “each doing a specific job.” Modular Electronics gives examples of “a sensor module, a transistor module, a buzzer module,” which seem to prove the functional definition of the term. The description is not referring to a specific structure but rather, much like Williamson, is referring to a “black box recitation of structure for providing the same specified function as if the term ‘means’ had been used.” i.e. a sensor module is not a particular structure, but is instead any hardware configuration that ultimately performs the function of sensing. Examiner further notes that the citations refer to other non-structural terms in defining what a module is. For example, PCMag states a module is “A self-contained hardware or software component that interacts with a larger system…Hardware modules are units….” Wikitionary defines a module as “A self-contained component of a system” Techtarget states “A module is a distinct assembly of components that can be easily added, removed or replaced in a larger system.” In short, the evidence is improperly dated, the argument and evidence is not directed to the claim terms, and the evidence fails to show that even the broader term “module” has a known structural definition in the art. Notably, in ten pages of argument Applicant never identifies what the structural definition of a module is or explains why the four cited documents Applicant presents all define the term in materially different ways. If “module” had a known structural meaning to the art four references should not be in conflict as to what structure is encompassed by the term. Rather, the references seem to show that to the extent module describes something it describes an identifiable purpose-specific part of a whole. That is a functional definition. Applicant next reverts (Remarks, pg. 16) to the argument that “even if a claim term appears functional it does not invoke 112(f) unless it is purely functional without any structural connotation.” Again, this is not the standard. Applicant then cites paragraphs of the specification and asserts “the Office Action interpretation ignores the context of the claims.” But unclaimed context of claim terms is not relevant for a Prong A analysis unless the specification defines the term as something other than the plain meaning. “The standard is whether the words of the claim are understood by persons of ordinary skill in the art to have a sufficient definite meaning as the name for structure.” (MPEP 2181(I)(A)) Regardless, the citations to the specification are functional descriptions – they describe what is the result of use of undescribed black box elements. Applicant incorrectly describes the citations as “structural interactions” but they are functional actions taken by the modules. “The leg is affixed to the underside of the table” is a structural description. “The email module, further cooperating with AI model(s), may be configured to conduct analytics on the content of the DMARC reports” (Remarks, pg. 16 citing Spec, para. 51) is the functional result of the use of undescribed structure. The description on its face embraces any structure that causes the result of (“configured to”) cooperatively conducting analytics. At Remarks, pg. 17, Applicant argues “Applicant’s specification specifically does describe various structures associated with the structure of [the modules].” Applicant points to paragraph 152 stating that algorithms can be written in particular programming languages. The paragraph does not define any of the module terms, so it does not change the meaning of those claim terms as generic placeholders to a person of ordinary skill in the art. The paragraph does not prevent the claims from using functional language to modify the generic placeholders. The paragraph does not include in the claim sufficient structure for achieving the specified functions in the claim. Applicant next cites to Fig. 1A. The same response applies. Applicant next turns to “disclosure of an algorithm as discussed in Aristocrat” at Remarks, pg. 18. The argument is irrelevant to whether the claim invokes means-plus. The discussion in Aristocrat deals with, once a claim term invokes means plus, if there sufficient description in the specification or is the means-plus term indefinite. Applicant conflates two distinct issues at different steps of the analysis process. Regardless, to the extent this can be construed as an argument against the indefiniteness of the claims, the quoted section of the instant specification that a person of ordinary skill could use undescribed algorithms in order to achieve the claimed result is not sufficient to render the claim terms definite. The specification must disclose an algorithm of sufficient structure for performing the functionality. Paragraphs 141-152 do not disclose algorithms for performing the claimed functions, they merely state that such algorithms could be made. Regardless, this argument is not relevant to whether the claims invoke 112f. This tech center, which deals with computer-implemented inventions, routinely construes “modules” as being nonce terms that invoke 112(f) when the other two prongs are met. The claim terms meet the three prongs of MPEP 2181. The claims invoke 112(f). To the extent some of Remarks, pgs. 10-20 can be construed as an argument that the 112(f) terms are definite, they are unpersuasive because Applicant fails to point to algorithms that transform a general purpose computer into a special purpose computer for achieving the claimed functions. Examiner maintains the construction of the terms in 112(f) and maintains the 112(b) in view of f. Turning to the 103 rejection, Applicant argues the new claim feature which is taught above. Applicant further argues at Remarks, pg. 21 that the prior art teaches away. For there to be a teaching away the prior art must criticize, discredit or otherwise discourage the solution claimed. Applicant argues that Adams “explicitly restricts the initiation of a DoS attack to known malicious servers…Adams relies on a static blacklist to ensure that destructive offensive actions are not accidentally launched against innocent or legitimate network infrastructure.” There is no cited evidentiary support for the argument that Adams was concerned about “accidentally” launching an attack “against innocent or legitimate network infrastructure.” And even if there was the reference would not render the claims nonobvious because the nature of the teaching is highly relevant. There is no suggestion that a DoS attack against a suspected malicious actor as opposed to a certain malicious actor would not work, i.e. one does not have to be guilty for a DoS attack to succeed. Thus even if Adams were concerned about DoS attacks against innocent targets that does not mean a person of ordinary skill would find it nonobvious to utilize a DoS attack against one whom they suspect is malicious. In other words, even if Adams were exceedingly concerned with harming innocents a person of ordinary skill is not obligated to adopt Adams’ conscience. A person of ordinary skill would have been motivated to stop someone they suspect might be malicious, not just someone they were absolutely certain is malicious. At Remarks, pg. 22, Applicant points to a Dreller disclosure that emails frequently fail authentication checks for benign reasons. Applicant states “Dreller categorizes these benign failures separately under an ‘Automatic Forwarding’ category specifically to prevent improper corrective actions.” Applicant next reasons that “the resulting system would indiscriminately launch offensive cyberattacks against legitimate ISPs and forwarding servers.” Applicant views this as “highly risky” and “would cause catastrophic collateral damage.” Applicant states “a POSTIA would not be motivated to substitute the safe, blacklist-triggered DoS attack of Adams with the authentication trigger of Dreller.” Applicant again makes several analytical mistakes, both legal and factual. First, Dreller is the primary reference, so the question is not whether one would substitute a blacklist for the Dreller authentication check. The question is whether one who performs the authentication check in Dreller was motivated to take additional actions beyond the remedial actions taken in Dreller, i.e., If one determines an email is suspected of being malicious would one only alert about it, or might they take action like facilitating contact (Gilliam) or fighting back (Adams). The secondary references evidence a person of ordinary skill was motivated to do more than simply alert. It is common to remediate when a problem like malicious behavior is detected. Second, Applicant misunderstands obviousness and motivation. Examiner is not required to show that every point within the claim scope is obvious, Examiner is only requires to show a single point within the claim scope is obvious. Therefore, even if everything Applicant argued with factually supported and correct, the fact that Dreller would sometimes generate false positives and there would be no motivation to attack those innocent devices does not mean that it is nonobvious to attack malicious devices. Every act taken can induce negative consequences if one thinks up a narrow enough circumstance, but the question is not whether an act is always motivated the question is whether an act is motivated for at least one example within the claim scope. By Applicant’s logic, it is nonobvious to make theft a crime because society would not be motivated in punishing a man stealing a loaf of bread to feed their starving child, or it would be nonobvious to take medicine because there is some subsection of the population for which there would be adverse reaction. Obviousness is not properly analyzed by creating hypothetical doomsday scenarios; rather a teaching away must be applicable over the entire breadth of the claim scope. Applicant’s resort to a subsection of the claim scope merely highlights that there exist other parts of the claim scope which are unaffected by the argued logic. Third, Applicant simply factually mischaracterizes the reference. Applicant apparently relies entirely upon the word “known” in Adams, para. 92 to attach an absolute standard of precision to Adams’ blacklist, but Adams does not state the mechanism by which a server is known to be malicious and blacklisted and therefore Applicant’s characterization of Adams’ accuracy is unsupported. Conversely, Applicant gives Dreller none of the goodwill that Adams gets. Applicant points to a “benign” subclass of emails that Dreller (1) knows of and (2) can identify and therefore correct for and comes to the conclusion that the use of the Dreller system to identify malicious action would lead to “indiscriminate[]” attacks. After reading that, Examiner wonders why this Office allowed Dreller a patent (US Pat. 9,143,476) on such a useless analysis system.1 Applicant then makes the leap, without citing any evidence, that “launching automated DoS attacks based on isolated email authentication failures is highly risky and would cause catastrophic collateral damage.” But, of course, the risk is relative to the certainty one attaches to malicious behavior analysis. Applicant does not explain why there is collateral damage or why it would be catastrophic. Presumably, DoS attacks which require repeated action and usually involve multiple devices acting in coordination (in their Distributed DoS subset) have no collateral damage – they always hit what they’re aiming at. The reasonable reading is, of course and inconveniently for Applicant’s argument, between the two extremes. It is unlikely that Adams’ blacklist is absolutely accurate because absolute accuracy is impossible. At most what a blacklist can say is that a given server has been known to take actions consistent with malicious behavior in the past, which has some but not conclusive probative value of the intent of the server today. It makes as much sense to be certain a server is acting maliciously because it has previously been malicious as it does to be certain a man committed a crime because he had previously been adjudicated a criminal. Similarly, while Dreller identifies at least one issue it can correct for, there are likely others that are not considered, making its usage neither “indiscriminate” nor absolutely accurate. Neither Adams, nor Dreller, nor the instant application are absolutely accurate. Absolute accuracy is not required for obviousness. A person of ordinary skill was motivated to apply known malicious detection techniques and take known remedial actions therefrom. Examiner maintains the 103 rejection. All claims remain rejected. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS P CELANI whose telephone number is (571)272-1205. The examiner can normally be reached on M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached on 571-272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NICHOLAS P CELANI/Examiner, Art Unit 2449 1 While Examiner appreciates that Applicant has a motivation to make it seem like Dreller is so inaccurate that employing it would be meaningless, Examiner notes that Applicant has never disputed Dreller teaches the email module of the claims. The email module drives the functionality of the autonomous response and inoculation modules. If a person of ordinary skill would not recognize the use in taking remedial action based on a report analysis that may or may not be faulty, it only stands to reason the instant invention would lack enablement or utility.
Read full office action

Prosecution Timeline

Show 1 earlier event
Jun 16, 2025
Non-Final Rejection mailed — §103, §112
Sep 08, 2025
Response Filed
Oct 08, 2025
Final Rejection mailed — §103, §112
Feb 06, 2026
Request for Continued Examination
Feb 21, 2026
Response after Non-Final Action
Apr 01, 2026
Non-Final Rejection mailed — §103, §112
Jul 01, 2026
Response Filed
Aug 07, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706878
ZERO-TRUST ARCHITECTURE FOR SECURE AGGREGATION IN FEDERATED LEARNING
3y 9m to grant Granted Aug 11, 2026
Patent 12695797
MEDIA COMMUNICATIONS FOR WEARABLE DEVICES
3y 1m to grant Granted Jul 28, 2026
Patent 12682092
SYSTEMS AND METHODS FOR USER DATA COLLECTION
3y 8m to grant Granted Jul 14, 2026
Patent 12647250
CIPHERTEXT CONVERSION SYSTEM, CIPHERTEXT CONVERSION METHOD, AND NON-TRANSITORY COMPUTER READABLE MEDIUM
1y 9m to grant Granted Jun 02, 2026
Patent 12634201
Detecting site locations of unknown network devices
4y 10m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
46%
Grant Probability
88%
With Interview (+42.3%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 463 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month