DETAILED ACTION
In a communication received on 26 May 2026, the applicants amended claims 1, 7, 9, 15, and 17 and canceled claims 5, 6, 13, and 14, and added new claims 21-24.
Claims 1-4, 7-12 and 15-24 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1, 9 and 17 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-4, 7-12 and 15-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jeyakumar et al. (US 2020/0344251 A1) in view of Reyderman (US 2022/0147714 A1), and further in view of Jakobsson et al. (US 2021/0234870 A1).
With respect to claim 1, Jeyakumar discloses: a method comprising: analyzing an email sent from a sending device and a sender address sent to a receiving device (i.e., the platform examines a routed incoming email and identifies its sender address, recipient, headers, and body content. in Jeyakumar, ¶0136);
identifying, from a key-value database storing aggregated historical co-occurrence counts of sender attribute combinations observed over a sliding time window, a first specialized misuse model and a second specialized misuse model associated with the sending device, wherein the first specialized misuse model is configured to detect misuse of directly-extracted sender metadata attributes and the second specialized misuse model is configured to detect misuse of NLP-extracted sender body-content attributes (i.e., date-range counts of historical attribute combinations are stored in Redis, while entity-selected, specialized analysis modules separately evaluate primary and secondary attributes in Jeyakumar, ¶0187; ¶0184; ¶0097);
applying the first specialized misuse model to determine a first probability value associated with the first sender attribute that conveys a likelihood that the first sender attribute is a first misused sender attribute (i.e., an entity-specific detector quantifies deviation of directly extracted sender behavior from its baseline and may output an attack probability representing metadata misuse. in Jeyakumar, ¶0102; ¶0099);
applying the second specialized misuse model to determine a second probability value associated with the second sender attribute that conveys the likelihood that the second sender attribute is a second misused sender attribute, wherein: (i.e., employee-signature and body-style features feed impersonation models whose analysis modules output attack probabilities or likelihood scores. in Jeyakumar, ¶0179; ¶0099)
and the first specialized misuse model and the second specialized misuse model are executing at least partly in parallel within a Cognitive Anti-Phishing Engine (CAPE) (i.e., specialized primary- and secondary-attribute extractors and attack-analysis modules execute with temporal overlap in the threat-detection platform in Jeyakumar, ¶0118; ¶0119);
determining, by an aggregating classifier and using the first probability value and the second probability value, an overall probability value associated with a likelihood of classifying the email as having at least one misused sender attribute to enable identifying at least misuse of the sender address to a sender's signature extracted from body content of the email via the NLP process (i.e., a master detector combines outputs from multiple attack-specific modules into a final email classification using sender-address history and signature-based impersonation signals in Jeyakumar, ¶0103; ¶0089; ¶0179); and
in response to the overall probability value exceeding a configurable threshold , causing an action that prevents at least forwarding the email to the receiving device. (i.e., adjustable score thresholds classify the email, and serial delivery withholds any email classified as an attack in Jeyakumar, ¶0147; ¶0116).
Jeyakumar discloses direct email-metadata attributes and body-signature impersonation models (¶0088; ¶0179). Jeyakumar do(es) not explicitly disclose the following. Reyderman, in order to improve recognition speed of sender specific meta data based on automated signature-block extraction (¶0024), discloses:
extracting at least a first sender attribute and a second sender attribute from the email, wherein the first sender attribute is directly extracted from metadata of the email and the second sender attribute is extracted from body content of the email using a Natural Language Processing (NLP) process, the second sender attribute comprising at least one of a sender signature or an email closing (i.e., an NLP/ML pipeline locates a signature block in email body text, validates signature-line language patterns, and extracts structured signature attributes in Reyderman, ¶0009; ¶0023).
Based on Jeyakumar in view of Reyderman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Reyderman to improve upon those of Jeyakumar in order to improve recognition speed of sender specific meta data based on automated signature-block extraction .
Jeyakumar discloses date-ranged counts of attribute combinations in Redis (¶0184; ¶0187). Jeyakumar and Reyderman do(es) not explicitly disclose the following. Jakobsson, in order to improve probabilistic detection by using combination statistics reveal how likely multiple message aspects are to appear together (¶0042), discloses: the first probability value and the second probability value are each calculated using (i) a count of messages historically observed with a particular sender attribute value and (ii) a reference attribute value and a total count of messages historically observed with the reference attribute value (i.e., sender-history records store observation counts and use those historical observations to calculate conditional or Bayesian likelihoods for combinations of message aspects in Jakobsson, ¶0041; ¶0055).
Based on Jeyakumar in view of Reyderman, and further in view of Jakobsson, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Jakobsson to improve upon those of Jeyakumar in order to improve probabilistic detection by using combination statistics reveal how likely multiple message aspects are to appear together.
With respect to claim 2, Jeyakumar discloses: the method of claim 1, further comprising: assigning the action based on classifying of the email to the receiving device comprising at least one of indicating the email is suspicious, preventing delivery of the email, or authorizing delivery of the email (i.e., classification can mark an email suspicious and govern delivery, junking, deletion, notification, restoration, or withholding in Jeyakumar, ¶0212; ¶0104; ¶0116).
With respect to claim 3, Jeyakumar discloses: the method of claim 1, further comprising: identifying one or more detectors for detecting data of the first sender attribute (i.e., specialized primary-attribute extractors obtain directly extracted sender and header-metadata attributes in Jeyakumar, ¶0088; ¶0118); and
using data detected of the first sender attribute for computing the first probability value that conveys the likelihood that the first sender attribute is misused (i.e., detected sender-attribute deviations are fed to attack detectors that generate probability or other attack outputs in Jeyakumar, ¶0102; ¶0099).
With respect to claim 4, Jeyakumar discloses: the method of claim 1, further comprising: identifying one or more detectors for detecting data of the second sender attribute (i.e., specialized secondary-attribute extractors and NLP body analysis obtain sender-related body information for analysis in Jeyakumar, ¶0118; ¶0137); and
using data detected of the second sender attribute for computing the second probability value that conveys the likelihood that the second sender attribute is misused (i.e., detected signature and body-style data is supplied to impersonation models whose modules can produce probability or likelihood outputs in Jeyakumar, ¶0179; ¶0099).
With respect to claim 7, Jakobsson discloses: the method of claim 1, further comprising: determining the likelihood of a first misuse sender attribute for computing a conditional probability based on detection of the first sender attribute from an email and probability data stored in a database (i.e., detected header or content information is compared with stored sender-history statistics to determine a conditional likelihood of aberration or misuse in Jakobsson, ¶0054; ¶0055).
With respect to claim 8, Jakobsson discloses: the method of claim 7, further comprising: determining the likelihood of a second misuse sender attribute for computing a conditional probability based on detection of the second sender attribute from email and probability data stored in a database (i.e., a detected message signature is evaluated against stored sender-history observations through a conditional or Bayesian risk computation in Jakobsson, ¶0072; ¶0055).
With respect to claim 9, the limitation(s) of claim 9 are similar to those of claim(s) 1. Therefore, claim 9 is rejected with the same reasoning as claim(s) 1.
Jeyakumar further discloses: a system comprising: one or more processors (i.e., the processing system includes one or more central processing units in Jeyakumar, ¶0220); and
one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: (i.e., machine-readable, nonvolatile storage holds instructions that processors execute to perform the disclosed operations in Jeyakumar, ¶0222; ¶0223)
in a synchronous real-time processing path: identifying a first sender-specific misuse model and a second sender-specific misuse model associated with the sending device from a database storing aggregated historical co-occurrence counts of sender attribute combinations, wherein the first sender-specific misuse model is specialized to detect misuse of directly-extracted metadata attributes and the second sender-specific misuse model is specialized to detect misuse of NLP-extracted body-content attributes; (i.e., a real-time scorer uses entity-specific analysis modules with Redis-stored attribute-combination counts and specialized primary and secondary attribute extraction in Jeyakumar, ¶0185; ¶0099; ¶0187; ¶0118)
in an asynchronous batch processing path performed in parallel with the synchronous real-time processing path, periodically updating the aggregated historical counts in the database based on sender attributes extracted from a plurality of previously processed emails (i.e., batch processing generates or updates data for real-time email scoring, while signatures are periodically ingested and historical activity is aggregated for model input in Jeyakumar, ¶0180; ¶0189); and
in response to identifying the email with at least one misused sender attribute, causing an action that prevents at least forwarding the email to the receiving device (i.e., an email is delivered only after it is determined not to be an attack; attack remediation includes junking, hiding, or deleting it in Jeyakumar, ¶0116; ¶0104).
Jeyakumar discloses direct email-metadata attributes and body-signature impersonation models (¶0088; ¶0179). Jeyakumar do(es) not explicitly disclose the following. Reyderman, in order to improve recognition speed of sender specific meta data based on automated signature-block extraction (¶0024), discloses:
extracting at least a first sender attribute and a second sender attribute from the email, wherein the first sender attribute comprises directly-extracted metadata of the email including at least one of a sender domain, sender address, or displayed text, and the second sender attribute is extracted from body content of the email using a Natural Language Processing (NLP) process and comprises at least one of a sender signature or an email closing (i.e., an NLP/ML pipeline locates a signature block in email body text, validates signature-line language patterns, and extracts structured signature attributes in Reyderman, ¶0009; ¶0023).
Based on Jeyakumar in view of Reyderman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Reyderman to improve upon those of Jeyakumar in order to improve recognition speed of sender specific meta data based on automated signature-block extraction.
With respect to claim 10, the limitation(s) of claim 10 are similar to those of claim(s) 2. Therefore, claim 10 is rejected with the same reasoning as claim(s) 2.
With respect to claim 11, the limitation(s) of claim 11 are similar to those of claim(s) 3. Therefore, claim 11 is rejected with the same reasoning as claim(s) 3.
With respect to claim 12, the limitation(s) of claim 12 are similar to those of claim(s) 4. Therefore, claim 12 is rejected with the same reasoning as claim(s) 4.
With respect to claim 15, the limitation(s) of claim 15 are similar to those of claim(s) 7. Therefore, claim 15 is rejected with the same reasoning as claim(s) 7.
With respect to claim 16, the limitation(s) of claim 16 are similar to those of claim(s) 8. Therefore, claim 16 is rejected with the same reasoning as claim(s) 8.
With respect to claim 17, the limitation(s) of claim 17 are similar to those of claim(s) 1 and 9. Therefore, claim 17 is rejected with the same reasoning as claim(s) 1 and 9.
With respect to claim 18, the limitation(s) of claim 18 are similar to those of claim(s) 2. Therefore, claim 18 is rejected with the same reasoning as claim(s) 2.
With respect to claim 19, the limitation(s) of claim 19 are similar to those of claim(s) 3. Therefore, claim 19 is rejected with the same reasoning as claim(s) 3.
With respect to claim 20, the limitation(s) of claim 20 are similar to those of claim(s) 4. Therefore, claim 20 is rejected with the same reasoning as claim(s) 4.
With respect to claim 21, Jeyakumar discloses: the method of claim 1, further comprising: importing, into the key-value database, one or more sender-specific misuse models previously built for a first corporate email domain for use in identifying misuse of sender attributes in emails associated with a second corporate email domain different from the first corporate email domain (i.e., profiles may be federated across customers, allowing knowledge learned for one enterprise to benefit other enterprises through federated and enterprise-specific models in Jeyakumar, ¶0086; ¶0160; ¶0204),
wherein the imported sender-specific misuse models enable the first specialized misuse model and the second specialized misuse model to leverage aggregated historical co-occurrence counts observed across a plurality of corporate domains to improve detection of sender attribute misuse for senders (i.e., sender communication statistics can span a universe of customers, and federated models are combined with enterprise-specific models to broaden detection in Jeyakumar, ¶0089; ¶0204).
With respect to claim 22, Jeyakumar discloses: the method of claim 1, further comprising: updating the key-value database with the aggregated historical co-occurrence counts by extracting and normalizing a subset of sender attribute data from each of a plurality of processed emails comprising at least the sender domain, sender address, and sender signature (i.e., raw event attributes are converted to an internal schema and mapped into date-range combination counts, while sender-address and body-signature features are tracked in Jeyakumar, ¶0183; ¶0184; ¶0179), and
storing the sender attribute data in the key-value database (i.e., processed risk events and their attribute-combination signatures are persisted in Redis and queried for combination counts in Jeyakumar, ¶0187),
wherein the updating is performed as a batched aggregate operation (i.e., batch processing updates data used for real-time scoring, with periodic signature ingestion and historical aggregation supplying model inputs in Jeyakumar, ¶0180; ¶0189).
With respect to claim 23, Jeyakumar discloses: the method of claim 1, further comprising: applying the first specialized misuse model and the second specialized misuse model to additionally identify, from the aggregated historical co-occurrence counts in the key-value database, frequent senders whose sender attributes are observed in combination across a plurality of previously processed emails (i.e., sender and domain frequencies plus Redis counts of attribute combinations identify recurrent communication patterns across prior emails in Jeyakumar, ¶0089; ¶0187); and
in response to identifying a frequent sender, causing the email to bypass one or more misuse detection operations (i.e., a past-benign surely-safe model load-sheds further analysis, while Redis supports a whitelist of signatures determined not to be threats in Jeyakumar, ¶0069; ¶0187),
wherein the key-value database serves both to detect sender attribute misuse in suspicious emails and to filter benign email traffic from frequent legitimate senders using a unified set of aggregated historical co-occurrence counts (i.e., the Redis database supports both safe-signature whitelisting and attribute-combination counts, while historical safe activity supplies model inputs in Jeyakumar, ¶0187; ¶0189).
Claim(s) 24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jeyakumar et al. (US 2020/0344251 A1) in view of Reyderman (US 2022/0147714 A1) and Jakobsson et al. (US 2021/0234870 A1), and further in view of LaRosa et al. (US 2017/0251006 A1).
With respect to claim 24, Jeyakumar discloses: the method of claim 1, further comprising: generating, based on the overall probability value relative to the configurable threshold, a verdict selected from a plurality of distinct verdict categories (i.e., adjustable score thresholds sort possible threats into multiple distinct classifications, including borderline, suspicious, and bad in Jeyakumar, ¶0133; ¶0147)
comprising at least: a rare sender verdict indicating that the sender address has lower than a first threshold amount of co-occurrence history in the key-value database to establish a sender-specific baseline (i.e., sender-frequency and prior-seen statistics establish behavioral history, and mail from a previously unseen sender address is treated as a potential threat. in Jeyakumar, ¶0089; ¶0196);
a rare sender domain verdict indicating that the sender domain has lower than a second threshold amount of co-occurrence history in the key-value database (i.e., domain frequencies and prior-seen status are evaluated so unsafe or potentially unsafe domains can be identified more quickly. in Jeyakumar, ¶0089; ¶0197);
wherein each distinct verdict category causes a different action to be performed with respect to forwarding the email to the receiving device (i.e., classifications drive different remediation measures affecting delivery, including inbox delivery, junking, hiding, deletion, notification, or restoration in Jeyakumar, ¶0104; ¶0116).
Jeyakumar discloses historical attribute combinations and NLP/body-signature impersonation modeling (¶0139; ¶0179). Jeyakumar, Reyderman, and Jakobsson do(es) not explicitly disclose the following. LaRosa, in order to improve detection of impersonation by combining communication-relationship analysis with learned linguistic patterns (¶0048), discloses: and a sender signature impersonation verdict indicating that the sender's signature extracted from the body content of the email via the NLP process is statistically inconsistent with the sender address based on the aggregated historical co-occurrence counts (i.e., message endings and signature blocks are profiled per sender, and a normalized deviation score measures departure from that sender's usual signature block in LaRosa, ¶0093; ¶0107).
Based on Jeyakumar in view of Reyderman and Jakobsson, and further in view of LaRosa, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of LaRosa to improve upon those of Jeyakumar in order to improve detection of impersonation by combining communication-relationship analysis with learned linguistic patterns.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHERMAN L LIN whose telephone number is (571)270-7446. The examiner can normally be reached Monday through Friday 9:00 AM - 5:00 PM (Eastern).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon Hwang can be reached on 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sherman Lin
8/26/2026
/S. L./Examiner, Art Unit 2447
/JOON H HWANG/Supervisory Patent Examiner, Art Unit 2447