Prosecution Insights
Last updated: October 02, 2026
Application No. 18/207,061

Unifying of the network device entity and the user entity for better cyber security modeling along with ingesting firewall rules to determine pathways through a network

Non-Final OA §103
Filed
Jun 07, 2023
Priority
Jun 09, 2022 — provisional 63/350,781 +1 more
Examiner
GREENE, JOSEPH L
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
3 (Non-Final)
63%
Grant Probability
Moderate
3-4
OA Rounds
7m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 63% of resolved cases
63%
Career Allowance Rate
358 granted / 569 resolved
+4.9% vs TC avg
Strong +36% interview lift
Without
With
+35.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
31 currently pending
Career history
607
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
62.2%
+22.2% vs TC avg
§102
10.3%
-29.7% vs TC avg
§112
7.9%
-32.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 569 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 1. Claims 1, 3-11, 13-20 are currently pending in this application. Claims 1, 3, 11, and 13 are amended as filed on 05/27/2026. Claims 2 and 12 are canceled as filed on 05/27/2026. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3-6, 8-11, 13-16, and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Akella et al. (Pre-Grant Publication No. US 2021/0281582 A1), hereinafter Akella, in view of Crabtree et al. (Pre-Grant Publication No. US 2022/0078210 A1), hereinafter Crabtree. 2. With respect to claim 1, Akella taught an apparatus, comprising: a device linking service configured to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device (0052 & 0097, where the different access sources are taught, at least, by the wired vs wireless connection) that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network (0184, where the different MAC address teaches the different identifiers), where the device linking service is configured to create a unified network device identifier for the different device identifiers from the different sources of access into the network (0097), where the device linking service is configured to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine (0007) and where any instructions for the device linking service and the prediction engine are stored in an executable format on one or more non-transitory computer readable mediums, which are executable by one or more processors (0181 & 0049); wherein the device linking service is configured to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network (0052, where the fingerprint is the meta identifier as it contains the MAC address and, at least, ownership information in accordance with 0096), where the device linking service is configured to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network (0070), and where the cyber security appliance is configured to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat (0052, where the patterns are associated with the image ensembles: 0008, which is associated with the fingerprints: 0249). However, Akella did not explicitly state that the prediction engine is configured to run a simulation of attack paths for the network attack paths for the network by at least generating a virtual network represented by a graph of nodes representing devices within the network and simulating how a cyberattack could progress within the network based on at least a normal behavior of the devices and a current operational state of each of the devices associated with the nodes. On the other hand, Crabtree did teach that the prediction engine is configured to run a simulation of attack paths for the network attack paths for the network by at least generating a virtual network represented by a graph of nodes representing devices within the network and simulating how a cyberattack could progress within the network based on at least a normal behavior of the devices and a current operational state of each of the devices associated with the nodes (0023, where a graph, in computer science, is an abstract data structure that consists of a set of vertices/nodes that connect pairs of vertices/nodes. A graph is not inherently displayed visually to a human user and, in this case, is represented by the organized virtual node connections that are received and produced by the simulation engine). Both of the systems of Akella and Crabtree are directed towards provided attack prevention tools and therefore, it would have been obvious to a person having ordinary skill in the art, at the time of the effective filing of the invention, to modify the teachings of Akella, to utilize simulating an attack path, as taught by Crabtree, in order to provide a more detailed protection to coincide with a device’s modeled behavior. 3. With respect to claim 11, Akella taught a non-transitory computer readable medium configured to store instructions in an executable format in the non-transitory computer readable medium, which when executed by one or more processors cause operations (0181 & 0049), comprising: providing a device linking service to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network (0052 & 0097), providing the device linking service to create a unified network device identifier for the different device identifiers from the different sources of access into the network (0184), and providing the device linking service to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine (0007); providing the device linking service is configured to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network (0052, where the fingerprint is the meta identifier as it contains the MAC address and, at least, ownership information in accordance with 0096), where the device linking service is configured to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network (0070), and where the cyber security appliance is configured to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat (0052, where the patterns are associated with the image ensembles: 0008, which is associated with the fingerprints: 0249). However, Akella did not explicitly state that the prediction engine is configured to run a simulation of attack paths for the network attack paths for the network by at least generating a virtual network represented by a graph of nodes representing devices within the network and simulating how a cyberattack could progress within the network based on at least a normal behavior of the devices and a current operational state of each of the devices associated with the nodes, and providing the device linking service to then link the unified network device identifier with a user in the network. On the other hand, Crabtree did teach that the prediction engine is configured to run a simulation of attack paths for the network attack paths for the network by at least generating a virtual network represented by a graph of nodes representing devices within the network and simulating how a cyberattack could progress within the network based on at least a normal behavior of the devices and a current operational state of each of the devices associated with the nodes (0023, where a graph, in computer science, is an abstract data structure that consists of a set of vertices/nodes that connect pairs of vertices/nodes. A graph is not inherently displayed visually to a human user and, in this case, is represented by the organized virtual node connections that are received and produced by the simulation engine), and providing the device linking service to then link the unified network device identifier with a user in the network (0103). Both of the systems of Akella and Crabtree are directed towards provided attack prevention tools and therefore, it would have been obvious to a person having ordinary skill in the art, at the time of the effective filing of the invention, to modify the teachings of Akella, to utilize simulating an attack path, as taught by Crabtree, in order to provide a more detailed protection to coincide with a device’s modeled behavior. 4. As for claims 3 and 13, they are rejected on the same basis as claims 2 and 12 (respectively). In addition, Akella taught where the cyber security appliance is configured to have an autonomous response module to autonomously respond to mitigate the cyber threat as well as to cooperate with the prediction engine in order to determine how to properly autonomously respond to a cyber-attack by the cyber threat based upon simulations run in the prediction engine modelling the attack paths into and through the network (0063). 5. As for claims 4 and 14, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Akella taught where the device linking service is configured to cooperate with a firewall configuration ingester and the prediction engine, where the prediction engine is configured to monitor traffic into the network in order to map all of the paths into and through the network taken by the monitored traffic, where the firewall configuration ingester is configured to ingest firewall rules to determine theoretically possible paths through the network in accordance with the firewall rules and a mapping of nodes of the network, and where the prediction engine is configured to combine all of the paths into and through the network taken by the monitored traffic with the possible paths through the network theoretically possible in accordance with the firewall rules from the firewall configuration ingester in light of the unified network device identifier with a user entity in the network from the device linking service to determine possible attack paths when running the simulation of attack paths for the network that the cyber threat may take (0083, where the firewall and simulations can be further seen in 0118). 6. As for claims 5 and 15, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Akella taught where the device linking service is configured to passively monitor the data streams from different sources having access into the network as well as to actively query third party platforms to gather and ingest device data, user data, and activity data from multiple third party vendors and then analyze the ingested data, and then pass the ingested data into the prediction engine to perform the simulation of attack paths for the network that the cyber threat may take (0080-0081, where the third-party vendors can be seen in Crabtree: 0115, wherein the sources within the confines of the business teaches the local network and the external cloud based sources outside of the client business teaches the external third party vendor sources under BRI. See also: 0118). 7. As for claims 6 and 16, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Akella taught where the device linking service is configured to maintain data from the data streams in their generic format as well as put relevant data into a uniform analysis format in a central data store via translation and mapping and then using the central data store to store the relevant data for the uniform analysis format (0231, the tensor format). 8. As for claims 8 and 18, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Crabtree taught where the device linking service is configured to aggregate network presence information about a user of the network and their different user accounts on different third-party applications served from third-party platforms external to the network, who is then also associated with this particular individual physical network device (0115, where the web is crawled). 9. As for claims 9 and 19, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Crabtree taught further comprising: a firewall configuration ingester configured to cooperate with the device linking service, where the firewall configuration ingester is configured to examine rules of firewall configurations and their settings to model changes in these rules over time to detect unusual rules over time to the firewall configurations that cause new attack path modelling routes into the network (0107). 10. As for claims 10 and 20, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Akella taught further comprising: a firewall configuration ingester configured to cooperate with the device linking service and the prediction engine, where the firewall configuration ingester is configured to examine firewall rules implemented by a firewall to identify routes into the network allowed by a current firewall rules and supply the prediction engine with a set of possible routes that a cyber-attack by the cyber threat may take into the network and permitted reasons into the network (0109). Claim(s) 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Akella, in view of Crabtree, and in further view of MAJKOWSKI et al. (Pre-Grant Publication No. US 2021/0306371 A1), hereinafter Majkowski. 11. As for claims 7 and 17, they are rejected on the same basis as claims 1 and 11 (respectively). In addition, Akella taught where the device linking service is configured to apply using a central data store to store data points organized by how the data points relate to another data point (0231). However, Akella did not explicitly state to apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network. On the other hand, Majkowski did teach apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network (0075, where this, at least, teaches the fuzzy logic limitation). Both of the systems of Akella and Majkowski are directed towards provided attack prevention tools and therefore, it would have been obvious to a person having ordinary skill in the art, at the time of the effective filing of the invention, to modify the teachings of Akella, to utilize fuzzy logic as part of the learning algorithm, as fuzzy logic was a standard programming technique for processing data. Response to Arguments Applicant's arguments filed 05/27/2026 have been fully considered but they are not persuasive. 12. The applicant argues on pages 10-11 that “Akella paragraph [0052] is merely a section heading titled "Determining Request Information," and the surrounding disclosure discusses determining request information for HTTP requests-not creating a meta entity identifier that combines a unified network device identifier with user identifiers. Akella's system tracks web request referral information between network resources. It does not teach or suggest creating a meta entity identifier from a unified network device identifier combined with one or more user identifiers associated with different device identifiers from different sources of access into the network, as recited by claim 1 as amended. Neither does Akella teach using such a meta entity identifier to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat”. However, as can be seen with the updated citations, Akella does teach the meta identifier in, at least, the fingerprint containing the MAC and Ownership information (0052 & 0096) and the cyber threat handling can be seen in 0070. 13. The applicant argues on page 10 that the “referrer data structure described in Crabtree "enables one or more of the servers to detect distributed denial-of-service attack, detect malicious bots, and/or assist in a search process." Id. Crabtree's "referrer graph" is a data structure that tracks which web resources refer to other web resources-it is fundamentally different from a graph of nodes representing physical network devices for simulating how a cyberattack could progress through a network.” However, the examiner’s previous argument is reproduced: “0023, where a graph, in computer science, is an abstract data structure that consists of a set of vertices/nodes that connect pairs of vertices/nodes. A graph is not inherently displayed visually to a human user and, in this case, is represented by the organized virtual node connections that are received and produced by the simulation engine”. Thus, the aforementioned argument is maintained as the claim does not require that the graph be represented as a graphical user interface. 14. The applicant argues on page 10-11 that “Crabtree's referrer graph tracks web request referral relationships between network resources (URLs/URIs), not the behavior or operational state of physical network devices. The Examiner's own characterization acknowledges this is merely "an abstract data structure that consists of a set of vertices/nodes that connect pairs of vertices/nodes-a generic description of a graph data structure that does not teach the specific claimed functionality of generating a virtual network represented by a graph of nodes representing devices within the network and simulating how a cyberattack could progress within the network based on at least a normal behavior of the devices and a current operational state of each of the devices associated with the nodes, as recited by claim 1 as amended. There is no teaching in Crabtree of simulating attack progression based on normal device behavior and current operational state of network devices.“ However, 0023 explicitly states that it is modelling/simulating iterations of attacks and on the network which teaches simulating attack progressions under broadest reasonable interpretation. If the applicant intends a specific definition of a simulated attack progression, then it should be amended into the claims accordingly. See also, 0110 that explicitly states that it is monitoring how an attack progresses. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSEPH L GREENE whose telephone number is (571)270-3730. The examiner can normally be reached Monday - Thursday, 10:00am - 4:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas R. Taylor can be reached at 571 272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JOSEPH L GREENE/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Show 1 earlier event
Jun 16, 2025
Non-Final Rejection mailed — §103
Sep 08, 2025
Response Filed
Sep 15, 2025
Examiner Interview (Telephonic)
Sep 25, 2025
Final Rejection mailed — §103
Apr 17, 2026
Response after Non-Final Action
May 27, 2026
Request for Continued Examination
Aug 05, 2026
Response after Non-Final Action
Aug 17, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750250
AUTOMATED ASSET PREPARATION FOR A VIRTUAL MEETING
2y 11m to grant Granted Sep 29, 2026
Patent 12743221
VEHICLE DATA STORAGE METHOD AND VEHICLE DATA STORAGE SYSTEM
3y 4m to grant Granted Sep 22, 2026
Patent 12726455
Managing Access To Cloud-Hosted Applications Using Domain Name Resolution
5y 3m to grant Granted Sep 01, 2026
Patent 12719774
MULTI-MODE HEALTH MONITORING SERVICE
3y 2m to grant Granted Aug 25, 2026
Patent 12682128
CONTROL SYSTEM WITH SECURITY MANAGEMENT DEVICE
3y 7m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
63%
Grant Probability
98%
With Interview (+35.6%)
3y 11m (~7m remaining)
Median Time to Grant
High
PTA Risk
Based on 569 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month