Prosecution Insights
Last updated: October 02, 2026
Application No. 18/219,552

MALICIOUS SITE DETECTION FOR A CYBER THREAT RESPONSE SYSTEM

Non-Final OA §103§DP
Filed
Jul 07, 2023
Priority
Feb 20, 2018 — provisional 62/632,623 +3 more
Examiner
CHAO, MICHAEL W
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
3 (Non-Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
389 granted / 555 resolved
+12.1% vs TC avg
Strong +40% interview lift
Without
With
+39.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
16 currently pending
Career history
588
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
45.4%
+5.4% vs TC avg
§102
15.0%
-25.0% vs TC avg
§112
20.1%
-19.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 555 resolved cases

Office Action

§103 §DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is in response to the claims filed 12/22/2025. Claims 21-41 are pending. Claims 21 (a machine), 33 (a method), and 41 (a non-transitory CRM) are independent. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 12/22/2025 has been entered. Claim Objections Claims 22, 27-29, 38, and 39 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. As discussed herein below, independent claims 21, 33, and 41 are rejected in view of Kumar et al., US 2019/0104154 (filed 2017-10), in view of Oliver, US 2008/0131006 (published 2008), and Waterson et al., US 2012/0023566 (filed 2009). Claims 22, 27-29, 38, and 39 were previously found obvious in view of Kumar et al., US 2019/0104154 (filed 2017-10), in view of Oliver, US 2008/0131006 (published 2008), and Flament et al., US 2019/0019020 (filed 2018-07). It would not have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to further modify the combination of Kumar, Oliver, and Waterson with Flament to further modify the text detection of Kumar, Oliver, and Waterson. Therefore, Claims 22, 28, and 38, along with their dependents 29 and 39 are objected to as allowable but dependent upon a rejected base claim. Response to Arguments Applicant’s remarks on pages 11-36 of the remarks addressing the 112(a) rejection and pages 37-41 addressing the 112(b) rejection are moot as the amendment of 12/22/2025, removing the “determine whether the transformed segment includes a key text-like feature” as performed after the division and transformation steps obviates the 112(a) and 112(b) rejections. On page 45 of the remarks Applicant asserts that “Oliver explicitly states that the character blocks are created only after determining that regions have a reasonable probability of containing characters…. Claim 21 has claim limitations requires the opposite sequence of: Divide image to create segments -> transform the segments -> then analysis performed on key text-like features in the transformed segments.” This argument is not persuasive. Applicant’s argument equates “analysis performed on key text-like features” with detecting the key text-like features. Both Kumar and Oliver perform analysis after segmentation. For example, Kumar segments in ¶ 59 and analyzes in ¶ 60 and Oliver ¶ 44 segments an image and analyzes the segment in ¶ 45 (see also ¶ 12). Intuitively, analysis will always follow segmentation as the purpose of segmentation is to enable an analysis. The difference between the cited art and Applicant’s specification is how the text-like features are located. Such detail is not presently claims in independent claims 21, 33, and 41. However, note that Applicant’s method of detecting text-like features via machine learning (claim 22) is noted as allowable as discussed above. Applicant’s remarks on page 46 regarding Applicant’s preferred interpretation of the claimed phrase “fixed rendered size” is not persuasive. None of display resolution, screen dimensions, or scaling is claimed and this argument is moot. Applicant’s remark on page 47 that the vector of Kumar is not a plurality of distinct claimed elements is not persuasive. As stated by Kumar ¶ 59: “The plurality of keypoint descriptors describing the keypoints detected within a screenshot is stored in a vector, referred to herein as a “feature vector.”” See also ¶¶ 68-69. Applicant’s remark on page 48: “step i) Explicitly Requires Dividing the Entire Image Before Steps ii) and iii)….” is not persuasive. Here, Applicant seems to be asserting that the claim terminology: “i) divide an entire image into a plurality of segments” requires that each portion of the image is placed into at least one segment. In other words, the argument is that the sum total of segments include every portion of the “entire image”. There is no basis in Applicant’s specification for this assertion. Applicant’s specification, describing the segmentation via the segmentation module states in ¶ 30: “The segmentation module applying the machine learning algorithm identifies areas of key features along with their coordinates on the image of the page, (e.g. in the visual appearance of the site) as rendered on the end user's computing device. The segmentation module forms a bounding box around each of these key features.” There is no description of any segment, or bounding box, without a “key feature”. This is exemplified throughout Applicant’s figures by highlighting only parts of the image including key features, see Figure 6 with illustrated bounding boxes. Applicant’s system functions identically to the systems of Kumar and Oliver who locate areas of interest within a larger image. Examiner reiterates that there is no description or illustration of any segment that does not include a text-like feature or “key feature”. Thus, it is reasonable to interpret the claimed “divide an entire image” as locating selected segments of the image, as done in Kumar ¶ 59 and Oliver ¶ 44. Although Applicant further states on page 49 of the remarks “The Examiner’s Mapping Ignores “Entire Image” and Substitutes Selective Regions”; Applicant has no written description or illustration showing any segment that does not include a ‘selective region’. Applicant’s further remarks are not persuasive for the reasons noted above. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 21, 22, 33, and 41 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 and 1 of U.S. Patent No. 11,716,347. Although the claims at issue are not identical, they are not patentably distinct from each other because: As to pending claims 21, 22, 33, and 41, claim 1 of ‘347 comprises a majority of the limitations with the exception of the OCR aspect, which is shown in claim 7. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 21, 23-26, 30, 32-37, 40, and 41 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kumar et al., US 2019/0104154 (filed 2017-10), in view of Oliver, US 2008/0131006 (published 2008), and Waterson et al., US 2012/0023566 (filed 2009). As to claims 21, 33, and 41, Kumar discloses a machine/method/non-transitory CRM comprising: one or more processors; and (See Kumar Fig. 4) a non-transitory memory storage device accessible by the one or more processors, the non-transitory memory storage device comprises (“FIG. 4 is an exemplary embodiment of a logical representation of the phishing detection and analysis system of FIG. 1. The phishing detection and analysis system (PDAS) 400, in an embodiment, may be stored on a non-transitory computer-readable storage medium of an endpoint device” Kumar ¶ 71) a phishing site detector (“Embodiments of systems and methods for detecting phishing attacks are described.” Kumar ¶ 11) configured to i) divide an entire image into a plurality of segments, (“the feature generation logic 106 is responsible for: (1) detecting keypoints within the screenshot, (2) generating keypoint descriptors based on the detected keypoints,” Kumar ¶ 47) ii) transform one or more of the segments of the plurality of segments into a fixed rendered size to generate a plurality of transformed segments, (“The feature generation logic 106 uses computer vision techniques to detect keypoints within the screenshot. The feature generation logic 106 extracts blocks of pixels from the screenshot having a predetermined size, e.g., a 16×16 block, that includes the keypoint.” Kumar ¶ 59. “Known keypoint detection techniques such as rule sets that detect keypoints based on pixel density. Scale-Invariant Feature Transform (SIFT)” Kumar ¶ 17) and iii) then analyze each of the plurality of transformed segments (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training.” Kumar ¶ 60) … transformed segment; (“the keypoints can be selected so as to capture the common branding, and design elements of a webpage family” Kumar ¶ 20. “The plurality of keypoint descriptors describing the keypoints detected within a screenshot is stored in a vector, referred to herein as a “feature vector.” … The feature vector is then provided to the classifier 112.”) a signature creator configured to create a plurality of digital signatures, each digital signature, corresponding to one of the plurality of transformed segments including a corresponding key text-like feature, which is at least indicative of a visual appearance of the corresponding key text-like feature; and (“Each block of pixels is then used to generate a keypoint descriptor for the keypoint included within the block of pixels as discussed above. The plurality of keypoint descriptors describing the keypoints detected within a screenshot is stored in a vector, referred to herein as a “feature vector.”” Kumar ¶ 59. Also ¶¶ 67-69) an Artificial-Intelligence (AI) model (“As an overview the training process involves receipt of a list of URLs for use the detection of phishing websites. The list of URLs may be based on internal analytics, a third-party source, or the like. The URLs included in the list of URLs may be either known, benign websites (e.g., those that are often used in carrying out phishing attacks) and/or known phishing websites.” Kumar ¶ 44) configured to compare i) the plurality of digital signatures associated with a plurality of key text-like features detected in the image from an unknown site under analysis to (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training. Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) ii) digital signatures associated with a second plurality of text-like features from a plurality of known bad phishing sites (“known phishing websites.” Kumar ¶ 44) to output a likelihood of maliciousness of the unknown site under analysis. (“a first confidence may correspond to the Bank of America webpage, a second confidence may correspond to the Wells Fargo webpage, etc., with each confidence indicating the likelihood that the subject webpage is attempting to mimic the webpage corresponding to the webpage family. Continuing the example, the first confidence indicates the likelihood that the subject webpage is attempting to mimic the Bank of America webpage” Kumar ¶ 60) Kumar does not disclose “divide… transform… then analyze” … by performing an optical character recognition operation on a key text-like feature in a particular Oliver discloses: Divide… transform (“The OCR module may split the image into several character-blocks that each has a reasonable probability of containing a character (e.g., an ASCII character). The OCR module may form a sequence of blocks that represent a candidate match for the search term and estimate the probability of a match between the sequence of blocks and the search term.” Oliver ¶ 12. “The antispam engine 320 finds a section in the image 323 that is suitably similar to the selected expression 322 (step 802).” Oliver ¶ 44) Then analyze (“The OCR module may be configured to output whether or not the search term is found in the image and, if applicable, the location of the search term in the image.” Oliver ¶ 12. “The antispam engine 320 builds a text string directly (i.e., without first converting the image to text by OCR, for example) from the section of the image and then scores the text string against the selected expression to determine the closeness of the selected expression 322 to the found section (step 803).” Oliver ¶ 45. “For anti-phishing applications, links to phishing sites may be included in the expressions 322. In that case, the antispam engine 320 may be configured to determine if an image included in an email has text content matching a link to a phishing site” Oliver ¶ 47) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar with Oliver, by utilizing OCR splitting and searching in the system of Oliver to either, detect the keypoints for text or to extract text to match to fishing websites after the keypoints are detected. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Kumar with Oliver in order to detect malicious or phishing text that has been obfuscated or is otherwise difficult for machine vision to process, see Oliver Figures. Kumar in view of Oliver does not disclose: by performing an optical character recognition operation on a key text-like feature in a particular Waterson discloses: by performing an optical character recognition operation on a key text-like feature in a particular (“As well as extracting tokens from text, the plug in tool extracts tokens in another manner. It first takes an image of the retrieved page and then performs optical character recognition on it along with the title of the page, step 1002. This turns the page image into a set of characters, from which tokens can be extracted. Again a token probability is obtained for each extracted token, step 1003, and from those the page probability is found, step 1004. Using this method may extract tokens that would not otherwise be found from text alone. The plug in tool then determines which page probability is the largest, the one determined from OCR extracted tokens, or the one taken from text extracted tokens, step 1008. If the selected page probability is larger than a threshold, the plug in determines the page as being a fraudulent page, step 1009.” Waterson ¶ 95) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar in view of Oliver with Waterson by incorporating an OCR functionality to characterize the keypoints. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar in view of Oliver with Waterson in order to obtain token characteristics from images for comparison in phishing website detection that detects commonality despite changing fonts and colors or other image alterations that may avoid the machine vision of Kumar. As to claims 23 and 34, Kumar in view of Oliver and Waterson, as combined in claim 21, discloses the machine/method/CRM of claims 21 and 33 and further discloses: The cyber security appliance of claim 21, wherein the phishing site detector further comprises a categorizing module to analyze at least a first transformed segment of the plurality of transformed segments of the image determined to have a first key text-like feature by at least i) conducting the optical character recognition operation on the first transformed segment to produce resulting text including the first key text-like feature and (“As well as extracting tokens from text, the plug in tool extracts tokens in another manner. It first takes an image of the retrieved page and then performs optical character recognition on it along with the title of the page, step 1002. This turns the page image into a set of characters, from which tokens can be extracted. Again a token probability is obtained for each extracted token, step 1003, and from those the page probability is found, step 1004. Using this method may extract tokens that would not otherwise be found from text alone. The plug in tool then determines which page probability is the largest, the one determined from OCR extracted tokens, or the one taken from text extracted tokens, step 1008. If the selected page probability is larger than a threshold, the plug in determines the page as being a fraudulent page, step 1009.” Waterson ¶ 95) ii) determining a category belonging to the first key text-like feature using both the resulting text and a visual appearance of the key text-like feature, wherein the image is from a page of an unknown site under analysis. (“when the training set includes URLs for Bank of America, Wells Fargo, First Republic, and other known banking webpages for a total of twenty (20) banking webpages in the training set, the analysis of the feature vector of the subject screenshot during the detection process may result in 20 confidences. Specifically, a first confidence may correspond to the Bank of America webpage, a second confidence may correspond to the Wells Fargo webpage, etc., with each confidence indicating the likelihood that the subject webpage is attempting to mimic the webpage corresponding to the webpage family.” Kumar ¶ 60. The category are the respective different banks.) As to claims 24, 35, Kumar in view of Oliver and Waterson discloses the machine/method/CRM of claims 23 and 34 and further discloses: wherein the page is a log-in page that harvests log-in credentials for the unknown site. (“In some embodiments, two webpage families may correspond to the same overall webpage “owner.” For example, as Bank of America may have multiple login webpages for which the “look and feel” differs, a first Bank of America login webpage may include two text boxes corresponding to an entry of a customer's username and password, while a second Bank of America login webpage may include three text boxes corresponding to an entry of a customer's email address, social security number and birthday.” Kumar ¶ 64). As to claim 25, Kumar discloses the machine/method/CRM of claim 21 and further discloses: wherein the Al model is trained to compare i) digital signatures associated with one or more key text-like features (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training. ” Kumar ¶ 60) pertaining to a first category of key text-like features from the plurality of key text-like features in the image under analysis to ii) digital signatures in the first category (“As an illustrative example, when the training set includes URLs for Bank of America, Wells Fargo, First Republic, and other known banking webpages for a total of twenty (20) banking webpages in the training set, the analysis of the feature vector of the subject screenshot during the detection process may result in 20 confidences.” Kumar ¶ 60) that are associated with one or more key text-like features from the second plurality of key text-like features that are associated with the plurality of known bad phishing sites stored in a library of digital signatures. (“Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences. Each confidence of the plurality of confidences corresponds to a separate webpage family of the URLs provided to the PDAS 400 during training (“the training set”).” Kumar ¶ 60) As to claims 26, 36, Kumar in view of Oliver and Waterson, as combined in claim 21, discloses the machine/method/CRM of claims 21 and 33 and further discloses: wherein the phishing site detector includes an autonomous response module configured to, upon determining a prescribed correlation between the digital signatures associated with one or more key text-like features from the plurality of key text-like features and the digital signatures associated with one or more key text-like features from the second plurality of key text- like features, … and generate a notice to the user that the unknown site is likely a malicious phishing site. (“When the subject URL and the subject webpage are determined to be part of a phishing attack, the reporting engine 122 generates an alert to a cybersecurity analyst, an administrator, and/or users of one or more endpoints indicating that the subject URL and subject webpage are part of a phishing attack.” Kumar ¶ 62) Kumar in view of Oliver and Waterson, as combined in claim 21, does not explicitly disclose: preclude user access to the unknown site under analysis Waterson further discloses: preclude user access to the unknown site under analysis (“If the plug in tool determines that the retrieved page is a fraudulent page, step 407, then it will reject the web page, or disable the entry fields, and/or provide a warning to the user, step 409.” Waterson ¶ 76). A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar with Waterson rejecting the webpage or disabling entry fields of a suspect phishing site. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar with Waterson in order to prevent user information from being phished in a suspected phishing site so that a user that disregards or speedily clicks through the notification of Kumar will not compromise their data. As to claim 30, Kumar discloses the machine/method/CRM of claim 21 and further discloses: wherein the trained Al model is configured to compare the plurality of digital signatures from the plurality (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training. Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) of key text-like features detected in the image (“the keypoints can be selected so as to capture the common branding, and design elements of a webpage family” Kumar ¶ 20) to the digital signatures associated with the second plurality of key text-like features (“Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) and output a result of the compare identifying a likelihood of malicious of the unknown site under analysis including the image, (“a first confidence may correspond to the Bank of America webpage, a second confidence may correspond to the Wells Fargo webpage, etc., with each confidence indicating the likelihood that the subject webpage is attempting to mimic the webpage corresponding to the webpage family. Continuing the example, the first confidence indicates the likelihood that the subject webpage is attempting to mimic the Bank of America webpage” Kumar ¶ 60) wherein each key text-like feature of the plurality of key text-like features detected in the image categorized as part of a first category is compared to a key text-like feature of the second plurality of key text-like features in the first category. (“As an illustrative example, when the training set includes URLs for Bank of America, Wells Fargo, First Republic, and other known banking webpages for a total of twenty (20) banking webpages in the training set, the analysis of the feature vector of the subject screenshot during the detection process may result in 20 confidences.” Kumar ¶ 60. Categories.) As to claim 32, Kumar discloses the machine/method/CRM of claim 21 and further discloses: wherein the access module is further configured to capture a screenshot of the page of the unknown site as the image and provide the screenshot to a segmentation module of the phishing site detector to divide the screenshot into the plurality of segments. (“the URL is provided to the content fetcher 104, which obtains a screenshot of the webpage to which the URL resolves, as discussed above with respect to the training process in accordance with FIG. 1. The content fetcher 104 then provides the screenshot of the webpage (e.g., an image file, or an identifier enabling, retrieval of the image file) to the feature generation logic 106.” Kumar ¶ 59) As to claim 37, Kumar discloses the machine/method/CRM of claim 33 and further discloses: wherein the segmentation module is further configured to detect the plurality of key text-like features in the image and determine coordinates around each key text-like feature of the plurality of key text- like features. (“A keypoint descriptor may include a set of one or more parameters that describe the keypoint such as keypoint center coordinates x and y relative to the screenshot, a scale (e.g., being a radius of a circular image region, when applicable), and/or an orientation determined by the gradient of the pixel greyscale within the keypoint.” Kumar ¶ 18). As to claim 40, Kumar discloses the machine/method/CRM of claim 21 and further discloses: wherein after the comparing of i) the plurality of digital signatures associated with the plurality of key text-like features to ii) the digital signatures associated with the second plurality of text-like features, (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training. Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) the method further comprising: outputting a result identifying a likelihood of malicious of the unknown site under analysis including the image, (“when the result of the image comparison is greater than or equal to the predefined threshold e.g., indicating a match of the two screenshots meets or exceeds the predefined threshold (yes at block 316), the method 300 determines the subject URL is a phishing URL (block 320) and subsequently generates and issues an alert (block 322). The alert may be issued to, for example, a user attempting to access the URL using an endpoint device, a network administer and/or a cybersecurity analyst.” Kumar ¶ 70) wherein each key text-like feature of the plurality of key text-like features detected in the image categorized as part of a first category is compared to a key text-like feature of the second plurality of key text-like features in the first category. (“a first confidence may correspond to the Bank of America webpage, a second confidence may correspond to the Wells Fargo webpage, etc., with each confidence indicating the likelihood that the subject webpage is attempting to mimic the webpage corresponding to the webpage family. Continuing the example, the first confidence indicates the likelihood that the subject webpage is attempting to mimic the Bank of America webpage” Kumar ¶ 60, comparison of page family categories.) Claim(s) 31 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kumar et al., US 2019/0104154 (filed 2017-10), in view of Oliver, US 2008/0131006 (published 2008), Waterson et al., US 2012/0023566 (filed 2009), and Govardhan et al., US 2019/0334947 (filed 2018-06). As to claim 31, Kumar in view of Oliver and Waterson discloses the machine/method/CRM of claim 21 and further discloses: wherein the trained Al model is configured to compare the plurality of digital signatures from the plurality (“The classifier 112 uses the feature vector of the subject screenshot as an input to the model generated during training. Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) of key text-like features detected in the image (“the keypoints can be selected so as to capture the common branding, and design elements of a webpage family” Kumar ¶ 20) to the digital signatures associated with the second plurality of key text-like features, (“Analyzing the feature vector of the subject screenshot using the model results in a plurality of confidences.” Kumar ¶ 60) Kumar does not disclose: wherein the phishing site detector includes an access module that is configured to access, when an email under analysis is checked, a link in the email to capture the image of at least a login page associated with the unknown site accessed through the link. Govardhan discloses: wherein the phishing site detector includes an access module that is configured to access, when an email under analysis is checked, (“may receive the URL via email traffic 210 (i.e., Simple Mail Transfer Protocol (SMTP))” Govardhan ¶ 22. Also ¶ 35) a link in the email to capture the image of (“First, webpage crawler 214 crawls one or more webpages of a website associated with the URL. Once webpage crawler 214 has browsed each of the one or more webpages, webpage crawler 214 captures one or more images associated with each of the one or more webpages.” Govardhan ¶ 25) at least a login page associated with the unknown site accessed through the link. (“The webpage category may include login page (for example, for email or storage)” Govardhan ¶ 28). A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Kumar in view of Oliver and Waterson with Govardhan by using the system of Kumar to scan emails with potentially malicious URLs. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Kumar in view of Oliver and Waterson with Govardhan in order to extract and classify URLs of websites which users of a system are prompted with to thereby secure the user’s in the system from malicious phishing attacks via fraudulent URLs, Govardhan ¶ 4. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892, particularly: Corcoran et al., US 10,896,357, discloses automatic key value pair extraction from document images using deep learning. Selva et al., US 11,176,443, discloses text detection from application screen images. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL W CHAO whose telephone number is (571)272-5165. The examiner can normally be reached M, W-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL W CHAO/ Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Show 5 earlier events
Mar 17, 2025
Response after Non-Final Action
Mar 17, 2025
Notice of Allowance
Aug 14, 2025
Response after Non-Final Action
Aug 23, 2025
Response after Non-Final Action
Oct 17, 2025
Response after Non-Final Action
Dec 22, 2025
Request for Continued Examination
Jan 08, 2026
Response after Non-Final Action
Jul 14, 2026
Non-Final Rejection mailed — §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744759
A NETWORK FILTER
4y 12m to grant Granted Sep 22, 2026
Patent 12732810
BROKERED SERVICE DISCOVERY AND CONNECTION MANAGEMENT
2y 0m to grant Granted Sep 08, 2026
Patent 12724908
FILE MIGRATION METHOD, ELECTRONIC DEVICE , AND STORAGE MEDIUM
2y 8m to grant Granted Sep 01, 2026
Patent 12726486
SYSTEMS AND METHODS FOR IDENTIFYING TRUSTWORTHINESS OF DATA
2y 0m to grant Granted Sep 01, 2026
Patent 12689894
BROKERED SERVICE DISCOVERY AND CONNECTION MANAGEMENT
4y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+39.7%)
3y 3m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 555 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month