Prosecution Insights
Last updated: October 02, 2026
Application No. 18/229,062

ADVANCED THREAT PREVENTION

Final Rejection §103§112
Filed
Aug 01, 2023
Examiner
ALI, AFAQ
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
4 (Final)
90%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
128 granted / 143 resolved
+31.5% vs TC avg
Moderate +12% lift
Without
With
+11.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
27 currently pending
Career history
177
Total Applications
across all art units

Statute-Specific Performance

§101
9.7%
-30.3% vs TC avg
§103
51.5%
+11.5% vs TC avg
§102
4.5%
-35.5% vs TC avg
§112
22.1%
-17.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 143 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action Claims 1, 2, and 6-15 have been amended Claims 3-5 have been cancelled Claims 16-23 are added new Claims 1, 2, and 6-23 are pending Response to Arguments Applicant’s arguments filed on 06/24/2026 have been fully considered. With respect to the double patenting rejection for claims 1, 14, and 15, with respect to U.S. Patent No. US 12294609 B2 and the double patenting rejection for claims 1, 14, and 15 with respect to co-pending Application No. 19/353,404. The rejections have been overcome due to Applicant filing an approved terminal disclaimer. With respect to the USC 103 rejection Applicant has argued that DENG-HEWLETT-LOMAN fail to teach of “portion of the monitored network traffic should be tagged by the data appliance as potential Cobalt Strike activity for further evaluation at … wherein the remote service has more available computing resources than the data appliance, and … transmit a single copy of the tagged traffic to the remote service for analysis;” Examiner respectfully disagrees. DENG teaches of “portion of the monitored network traffic should be tagged by the data appliance as potential [Cobalt Strike] activity for further evaluation at ([DENG, para. 0078] “At stage 2, DP adaptor 202 a forwards the incoming packets associated with that file to packet data storage and protocol adaptor 210 b of EIPAT 210 (e.g., which includes a persistent storage component 210 f as shown in FIG. 2C). For example, packets can be accumulated into a block, and then the block can be uploaded to the cloud security services”) ([DENG, para. 0079] “Packet data storage and protocol adaptor 210 b identifies the protocol, applies the appropriate protocol decoder to assemble the file from packets, and then forwards the whole file”) ([DENG, para. 0080] “At stage 4, the whole file is sent to security services 222 for performing a plurality of types of analysis on the assembled files”) the claim language of portion of network traffic being tagged is taught by DENG as seen in the following citations above. Incoming packets associated with a file are accumulated into a block, this is analogous to tagging a portion of traffic. Only the packets that are associated with a file are accumulated. Therefore, DENG teaches this limitation. As for potential Cobalt Strike activity Examiner is relying on LOMAN to teach Cobalt strike activity. As for the limitation of “wherein the remote service has more available computing resources than the data appliance, and” DENG also teaches this as seen in the following citation ([DENG, para. 0031] “ firewall 102 forwards a downloaded file to a cloud security service 108 (e.g., a commercially available cloud-based security service, such as the WildFire′ cloud-based malware analysis environment that is a commercially available cloud security service provided by Palo Alto Networks, Inc., which includes automated security analysis of malware samples as well as security expert analysis, or a similar solution provided by another vendor can be utilized), such as via the Internet, and cloud security service 108 then performs content inspection on the downloaded file.”). The remote service as recited in a DENG is a cloud security service that is able to perform malware analysis. The cloud security service has more resources than the data appliance of DENG. Therefore, DENG also teaches this limitation. As for the limitation “transmit a single copy of the tagged traffic to the remote service for analysis;” DENG also teaches this ([DENG, para. 0078] “In an example implementation, the CTD component is implemented as a security platform OS task (e.g., pan_task (an agent on the DP)), which can copy the selective payloads to shared memory and then another agent (DP adaptor) can send those payloads to the cloud using the gRPC protocol.”). Therefore, DENG-HEWLETT-LOMAN teach all limitations of claim 1. Similar arguments apply for parallel independent claims 14 and 15. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation is: “a remote service for further evaluation” in claims 1 and 15 “… remote service is configured to” in claims 8, 16, and 17. Because this claim limitation(s) is being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it is being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. See specification para. 0027, 0028 for hardware support for remote service See specification para. 0095, 0099, and 0100 for functional support for remote service If applicant does not intend to have this limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION. —The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 16 and 17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 16 and 17 recite of the limitation “The system”. There is no antecedent basis for this limitation. For the purpose of examination, Examiner is interpreting this limitation as “The data appliance”. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 7, 8, 10, 13-17, 20, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over DENG (US-20220070223-A1) in view of HEWLETT (US-20210021611-A1), and further in view of LOMAN (US-20240211597-A1), hereinafter DENG-HEWLETT-LOMAN. Regarding claim 1, DENG teaches “A data appliance, comprising: a processor configured to: parse monitored network traffic associated with a session and determine, using a prefilter, that a portion of the monitored network traffic should be tagged by the data appliance as potential [Cobalt Strike] activity for further evaluation at a remote service, ([DENG, para. 0034] “a system/method/computer program product for a security platform with external inline processing of assembled selected traffic includes monitoring network traffic of a session at a security platform; selecting a subset of the monitored network traffic associated with the session to send to a cloud-based security service for analysis based on a security policy, wherein the selected subset of the monitored network traffic is proxied to the cloud-based security service”) ([DENG, para. 0092] “the disclosed architecture for a security platform with external inline processing of assembled selected traffic … The selective L7 proxy for suspicious sections of the monitored network traffic provides for enhanced security.”) ([DENG, para. 0038] “the security platform can selectively forward part of the traffic associated with a session to another processing unit (e.g., an external processing unit).”) ([DENG, para. 0071] “a policy configuration, action related 210 d (e.g., security rules/policies, which can be configured to handle different types of content/files (file type) using EIPAT 210 and/or security services 222 (such as a policy on which file types to send to which cloud-based security services”) ([DENG, para. 0078] “At stage 2, DP adaptor 202 a forwards the incoming packets associated with that file to packet data storage and protocol adaptor 210 b of EIPAT 210 (e.g., which includes a persistent storage component 210 f as shown in FIG. 2C). For example, packets can be accumulated into a block, and then the block can be uploaded to the cloud security services”) ([DENG, para. 0079] “Packet data storage and protocol adaptor 210 b identifies the protocol, applies the appropriate protocol decoder to assemble the file from packets, and then forwards the whole file”) ([DENG, para. 0080] “At stage 4, the whole file is sent to security services 222 for performing a plurality of types of analysis on the assembled files”) wherein the remote service has more available computing resources than the data appliance … ([DENG, para. 0031] “ firewall 102 forwards a downloaded file to a cloud security service 108 (e.g., a commercially available cloud-based security service, such as the WildFire′ cloud-based malware analysis environment that is a commercially available cloud security service provided by Palo Alto Networks, Inc., which includes automated security analysis of malware samples as well as security expert analysis, or a similar solution provided by another vendor can be utilized), such as via the Internet, and cloud security service 108 then performs content inspection on the downloaded file.”) transmit a single copy of the tagged traffic to the remote service for analysis; ([DENG, para. 0078] “In an example implementation, the CTD component is implemented as a security platform OS task (e.g., pan_task (an agent on the DP)), which can copy the selective payloads to shared memory and then another agent (DP adaptor) can send those payloads to the cloud using the gRPC protocol.”) receive, from the remote service, a verdict indicating that the session is malicious … , and take a remedial action in response; and ([DENG, para. 0034] “receiving, from the cloud-based security service, results of the analysis based on the security policy, and perform a responsive action based on the results of the analysis based on the security policy.”) ([DENG, para. 0065] “In the event an application is determined to be malicious, data appliances can be configured to automatically block the file download based on the analysis result. Further, a signature can be generated for the malware and distributed (e.g., to data appliances such as security platform 202) to automatically block future file transfer requests to download the file determined to be malicious.”) a memory coupled to the processor and configured to provide the processor with instructions. ([DENG, para. 0013] “The invention can be implemented in numerous ways, including as a process; an apparatus; a system; a composition of matter; a computer program product embodied on a computer readable storage medium; and/or a processor, such as a processor configured to execute instructions stored on and/or provided by a memory coupled to the processor.”). However, DENG fails to teach “potential Cobalt Strike activity … wherein the determination is made based at least in part on determining at the data appliance that:(1) a response payload starts with a magic byte matching a list of file types implicated in Cobalt Strike activity; (2) a content length in a response header is within a prespecified range implicated by Cobalt Strike activity; and (3) a pattern associated with Cobalt Strike activity is matched within a first portion of a response body; … a verdict indicating that the session is associated with malicious Cobalt Strike activity”. In analogous teaching HEWLETT teaches “wherein the determination is made based at least in part on determining at the data appliance that:(1) a response payload starts with a magic byte matching a list of file types implicated in … activity; ([HEWLETT, para. 0038] “The compromised client device can then be instructed to perform tasks (e.g., cryptocurrency mining, or participating in denial of service attacks) and to report information to an external entity, such as command and control (C&C) server 150, as well as to receive instructions from C&C server 150, as applicable.”) ([HEWLETT, para. 0082] “Process 600 begins at 602 when an indication is received by appliance 102 that a file is being transmitted as part of a session. As one example of the processing performed at 602, for a given session, an associated protocol decoder can call or otherwise make use of an appropriate file-specific decoder when the start of a file is detected by the protocol decoder. As explained above, the filetype is determined (e.g., by decoder 402) and associated with the session”) ([HEWLETT, para. 0072] “a given filetype is specified within the file's header (e.g., as a magic number appearing in the first seven bytes of the file itself). In such a scenario, threat engine 244 can select an appropriate model corresponding to the specified file type … As one example, JavaScript would have a filetype of “textfile.” To identify filetypes such as JavaScript, decoder 402 can be used to perform deterministic finite state automaton (DFA) pattern matching and apply heuristics (e.g., identifying <script> and other indicators that the file is JavaScript). The determined filetype and/or selected classification model are saved in the session state.”) ([HEWLETT, para. 0085] “In various embodiments, appliance 102 is configured to share its verdicts (whether benign verdicts, malicious verdicts, or both) with security platform 122. When security platform 122 completes its independent analysis of the file, it can use the verdict reported by appliance 102 for a variety of purposes, including assessing the performance of the model that formed the verdict.”) ([HEWLETT, para. 0041] “A variety of actions can be taken by data appliance 102 if no signature for an attachment is found, in various embodiments.”) ([HEWLETT, para. 0042] “As a third example, data appliance 102 can be configured to provide the file (e.g., malware 130) to security platform 122 for static/dynamic analysis, to determine whether it is malicious and/or to otherwise classify it.”) (2) a content length in a response header is within a prespecified range implicated by … activity; and ([HEWLETT, para. 0066] “in various embodiments, decoder 402 can use other information (e.g., file size as reported in a header) to determine when feature extraction of a file should end (e.g., the overlay section begins) and execution using an appropriate model should be commenced.”) ([HEWLETT, para. 0078] “classification model can be built using both n-gram (e.g., 8-gram) and non n-gram features. One example of a non n-gram feature is the purported size of the file (which can be read as a value out of a packet containing the file's header). Any file data appearing after the purported end of the file (e.g., as based on the file size specified in the header) is referred to as an overlay. In addition to serving as a feature, the purported file length can be used as a proxy for how long the file is expected to be.”) (3) a pattern associated with … activity is matched within a first portion of a response body ([HEWLETT, para. 0069] “As session packets corresponding to a file are received by threat engine 244, threat pattern matcher 408 parses the packets for matches against strings in a table (e.g., by performing regular expression and/or exact string matches). A list of matches (e.g., with each instance of a match identified by a corresponding pattern ID) and at what offset each match occurred is generated. Actions on those matches are taken in the order of the offset (e.g., from lower to higher). For a given match (i.e., corresponding to a particular pattern ID), a set of one or more actions to take is specified (e.g., via an action table that maps actions to pattern IDs).”) ([HEWLETT, para. 0083] “it can also determine whether any 8-grams in the packet match 8-grams provided by security platform 122. During the processing performed at 604, when an n-gram match is found, the corresponding pattern ID is used to map the condition to an action based on filetype. The action either increments a weighted counter”). Thus, given the teaching of HEWLETT, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of evaluation of potential malicious activity by HEWLETT into the teaching of a system to parse suspicious session traffic by DENG. One of ordinary skill in the art would have been motivated to do so because HEWLETT recognizes the need to mitigate malware ([HEWLETT, para. 0001] “Accordingly, there is an ongoing need for improvements to techniques for identifying and mitigating malware.”) ([HEWLETT, para. 0060] “perform is inline malware detection. In particular, and as will be described in more detail below, as a file (such as sample 130) passes through data appliance 102, machine learning techniques can be applied to perform efficient analysis of the file on data appliance”) However, DENG-HEWLETT fail to teach of “potential Cobalt Strike activity … verdict indicating that the session is associated with malicious Cobalt Strike activity”. In analogous teaching LOMAN teaches “potential Cobalt Strike activity” ([LOMAN, para. 0021] “For example, malware can initiate a malicious process that is a beacon that upon activation is configured to initiate a communication with an external entity such as, for example, a command-and-control center (C2 center) via a command-and-control channel (e.g., C2 channel). … examples of beacon include Cobalt Strike Beacon”) ([LOMAN, para. 0062] “Based on the information, the memory scan controller 214 can identify malware or code associated with a malicious process in a memory at a compute device (e.g., identify code to be a malware beacon like Cobalt Strike beacon in the example in FIG. 6, signaling to make a communication channel with a control command center), determine a type or class of malware, and/or determine a risk associated with the malware.”) ([LOMAN, para. 0086] “The process 600 includes intercepting a function call to a shared library to identify a source location associated with the function call. The example of FIG. 6 includes identifying a potentially malicious process, a Cobalt Strike beacon 673, associated with the function call.”) ([LOMAN, para. 0017] “Malware can be implemented, distributed, and/or stored via artifacts including computer files (“computer file(s)” or “file(s)”) such as text or document files (collectively, “document file(s)”) of various filetypes. Such files can be distributed or communicated via network (e.g., Internet) communications. For example, document files can include embedded, executable scripts or macros that, in some cases, can be configured to cause malicious activity” … verdict indicating that the session is associated with malicious Cobalt Strike activity” ([LOMAN, para. 0079] “At 475, the method 400 includes identifying, based on the scanning, a potentially malicious process within the range of memory addresses. In some implementations, the method 400 can further include identifying, characterizing, and/or classifying the potentially malicious process using any suitable technique (e.g., signature analysis, comparing to a black list or template of malware, using a maliciousness classifier, using machine learning models to characterize or classify potentially malicious artifacts, etc.). In some implementations, the method 400 can include performing or recommending one or more remedial measure based on the identifying”) ([LOMAN, para. 0086] “The example of FIG. 6 includes identifying a potentially malicious process, a Cobalt Strike beacon 673, associated with the function call.”) ([LOMAN, para. 0091] “the MD system can identify the malware as CS beacon 673 via instructions in the second program 679, and based on the identification instruct the processor (e.g., processor 210 of MD analysis device 201 and/or processor 310 of compute device 302) to perform an action 676 to block transfer of execution back to the first program 680 as initiated by the function call 681.”) Thus, given the teaching of LOMAN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of cobalt strike attack by LOMAN into the teaching of a system to parse suspicious session traffic by DENG-HEWLETT. One of ordinary skill in the art would have been motivated to do so because LOMAN recognizes the need to efficiently detect malicious attacks ([LOMAN, para. 0003] “a need exists for reliable methods and apparatus to identify, detect, and/or locate such difficult to detect malicious artifacts so that suitable preventative and/or remedial measures may be taken to protect hardware, data, information and/or the like.”). Regarding claim 14, this claim recites of a method claim that corresponds to system claim 1. Therefore, claim 14 is rejected in a similar manner as in the rejection of claim 1. Regarding claim 15, this claim recites of a computer program product that corresponds to system claim 1. Therefore, claim 15 is rejected in a similar manner as in the rejection of claim 1. Regarding claim 2, DENG-HEWLETT-LOMAN teaches all limitations of claim 1. DENG further teaches “wherein parsing the monitored network traffic includes performing a single session detection.” ([DENG, para. 0052] “Whenever flow module 338 identifies packets as being part of a new session, it creates a new session flow. Subsequent packets will be identified as belonging to the session based on a flow lookup”) ([DENG, para. 0034] “a security platform with external inline processing of assembled selected traffic includes monitoring network traffic of a session at a security platform”). Regarding claims 7 and 19, DENG-HEWLETT-LOMAN teaches all limitations of claims 1 and 14. LOMAN further teaches “wherein taking the remedial action includes generating a report that indicates one or more problematic portions of a payload.” (LOMAN, para. 0021] “the function call can be an internal call associated with any suitable action within the compute device For example, malware can initiate a malicious process that is a beacon that upon activation is configured to initiate a communication with an external entity such as, for example, a command-and-control center (C2 center)”) (LOMAN, para. 0003] “The MD interface is configured to provide a connection between the MD analysis device 101 and a compute device (e.g., compute devices 102-104) to send/receive information associated with one or more processes including monitoring activity (e.g., loading of programs in a first memory), identifying the first program associated with an identified function call and when it is loaded in a first memory … characterizing the potential malicious process or malware, and/or to determine or initiate one or more remedial measures based on the analysis, identification, classifying, or characterizing the potential malicious process or malware, and/or generating a report based on the detection and/or location of the malicious process.”). The same motivation to modify DENG-HEWLETT with LOMAN as in the rejection of claim 1 applies. Regarding claim 8, DENG-HEWLETT-LOMAN teaches all limitations of claim 1. DENG further teaches “wherein the remote service is configured to update a block list, at least in part, in response to the verdict.” ([DENG, para. 0065] “In the event an application is determined to be malicious, data appliances can be configured to automatically block the file download based on the analysis result. Further, a signature can be generated for the malware and distributed (e.g., to data appliances such as security platform 202) to automatically block future file transfer requests to download the file determined to be malicious.”) ([DENG, para. 0062] “security services 222 can provide to security platform 202 a set of signatures of known-malicious files (e.g., as part of a subscription). If a signature for a given malware is included in the set (e.g., an MD5 hash of the malware file, such as DOCX shown in FIG. 2A)”). Regarding claims 10 and 20, DENG-HEWLETT-LOMAN teaches all limitations of claims 1 and 14. LOMAN further teaches “wherein the processor is further configured to determine telemetry associated with obtaining the verdict.” ([LOMAN, para. 0094] “FIG. 7 is an example of an alert message 790, generated by an MD system described herein, according to an embodiment. The alert message 790 can be generated as part of a remedial measure following an identification of potential malware or a malicious process at a source location identified using the malware locating methods described herein. … The message can include any suitable information associated with the identification of the potential malware including code snippets, instructions, signatures used, time stamps, platform, application used, memory addresses involved, and/or the like.”). The same motivation to modify DENG-HEWLETT with LOMAN as in the rejection of claim 1 applies. Regarding claims 13 and 23, DENG-HEWLETT-LOMAN teaches all limitations of claims 10 and 20. LOMAN further teaches “wherein the collected telemetry includes which, of a plurality of forwarding criteria, was met by the monitored network traffic.” ([LOMAN, para. 0095] “For example, as shown in FIG. 7 , the second portion 793 can include communication parameters associated with the detected malicious process (e.g., communication parameters used by a beacon to make contact with a command- and -control (C2) server, the address of the C2 server with which the malicious process was attempting to connect, the user agent used to initiate communication with the C2 server (e.g., a string that identifies the browser that was used for the network communication), application parameters associated with communication to the C2 server, the process in which the malware is intended to be injected (e.g.: www.cobaltstrike.com/blog/cobalt-strikes-process-injection-the-details-cobalt-strike/or boschko.ca/cobalt-strike-process-injection/), and a name of the ‘named pipe’ (e.g., Cobalt Strike can use both named and unnamed pipes to exchange data between the beacon and its sacrificial processes”). The same motivation to modify DENG-HEWLETT with LOMAN as in the rejection of claim 1 applies. Regarding claim 16, DENG-HEWLETT-LOMAN teaches all limitations of claim 1. DENG further teaches “wherein the remote service is configured to provide portions of the single copy of the tagged traffic to a plurality of modules.” ([DENG, para. 0036] “the disclosed techniques for a security platform with external inline processing of assembled selected traffic are implemented in an inline Data Loss Prevention (DLP) feature of a cloud security service (e.g., a commercially available cloud-based security service, such as the WildFire™ cloud-based malware analysis environment that is a commercially available cloud security service provided by Palo Alto Networks, Inc., which includes automated security analysis of malware samples as well as security expert analysis, or another commercially available cloud security service)”) Regarding claim 17, DENG-HEWLETT-LOMAN teaches all limitations of claim 1. DENG further teaches “wherein the remote service is configured to reformat at least a portion of the single copy of the tagged traffic.” ([DENG, 0097] “the external processing unit (e.g., proxy, such as the EIPAT as described above) is located in a cloud network of a security service provider.”) ([DENG, 0097] “However, packets that are associated with a zip archive are assembled as shown at stage 3 and then sent to a cloud-based security service 222 as shown at stage 4 using the disclosed EIPAT component (e.g., EIPAT component 210 as shown in FIGS. 2A-C) and the above-described techniques.”) ([DENG, 0071] “security rules/policies, which can be configured to handle different types of content/files (file type) using EIPAT 210 and/or security services 222 (such as a policy on which file types to send to which cloud-based security services, such as JavaScript (JS) files/content, Windows PE files, and/or Word/PDF docs, etc.) “) Claims 6 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over DENG-HEWLETT-LOMAN in view of MCGREW (US-20200120107-A1). Regarding claims 6 and 18, DENG-HEWLETT-LOMAN teaches all limitations of claims 1 and 14. However, DENG-HEWLETT-LOMAN does not teach “wherein taking the remedial action includes dropping the session. In analogous teaching MCGREW teaches “wherein taking the remedial action includes dropping the session.” ([MCGREW, para. 0128] “a mitigation command 416 may cause a display device or other user interface to present an alert to a network administrator regarding the findings. In further cases, a mitigation command 416 may initiate automatic mitigation actions in the network, such as by blocking or redirecting traffic associated with the infected endpoint device and/or the server”). Thus, given the teaching of MCGREW, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of dropping the session by MCGREW into the teaching of a system to parse suspicious session traffic by DENG-HEWLETT-LOMAN. One of ordinary skill in the art would have been motivated to do so because MCGREW recognizes the need to efficiently prevent empire attacks ([MCGREW, para. 0145] “By applying the previous transformations to the Cookie or CF-RAY header, security process 248 can detect an Empire C&C channel with high efficacy.”). Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over DENG-HEWLETT-LOMAN in view of LEDDY (US-20200067861-A1). Regarding claim 9, DENG-HEWLETT-LOMAN teaches all limitations of claim 8. However, DENG-HEWLETT-LOMAN does not teach “wherein the processor is further configured to perform automated validation prior to updating the block list.”. In analogous teaching LEDDY teaches “wherein the processor is further configured to perform automated validation prior to updating the block list.” ([LEDDY, para. 0220] “Because the message was placed in the yellow bin, it is flagged for training potential. The training module is configured to select the message from the yellow bucket. … information indicating that the message was placed in the yellow bin due to an unrecognized URL (or a URL that was recently formed and/or not associated with a known brand) is also passed with the message.”) ([LEDDY, para. 0226] “In this example scenario, no filters in a filter set triggered. The message is passed to the training module 176 for further evaluation. In some embodiments, a manual evaluation is performed, and a filter update is performed. In other embodiments, the filter update is performed automatically”) ([LEDDY, para. 0120] “the training module is also configured to determine whether the rule will result in false positives. In some embodiments, false positives are determined based on a check against a ham repository, such as ham repository 178.”) ([LEDDY, para. 0121] “the training module is provided instructions on what filters/rules should be trained/updated/generated.”). Thus, given the teaching of LEDDY, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of validation prior to updating the block list by LEDDY into the teaching of a system to parse suspicious session traffic by DENG-HEWLETT-LOMAN. One of ordinary skill in the art would have been motivated to do so because LEDDY recognizes the need to efficiently protect users ([LEDDY, para. 0004] “There therefore exists an ongoing need to protect users against such evolving scams.”) ([LEDDY, para. 0056] “Described herein is a system that is configured to pre-validate electronic communications before they are seen by users. In some embodiments, the system described herein is an automated adaptive system that can protect users against evolving scams”). Claims 11 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over DENG-HEWLETT-LOMAN in view of NENE (US-20200067861-A1). Regarding claims 11 and 21, DENG-HEWLETT-LOMAN teaches all limitations of claims 10 and 20. However, DENG-HEWLETT-LOMAN does not teach “wherein the collected telemetry includes a round trip time associated with obtaining the verdict.”. In analogous teaching NENE teaches “wherein the collected telemetry includes a round trip time associated with obtaining the verdict.” ([NENE, col. 2 lines 59-67, col. 3 lines 1-5] “the receiving service causes an entry to be added to a diagnostics log service. The diagnostics log service may include a separate diagnostics log for each of the services. The entry added to a respective service's diagnostics log may include the data flow token. A time stamp also may be included in the diagnostics log entry. The time stamp may be generated by the service that receive the packet and extracted the data flow token from the packet (or generated the token). The time stamp corresponds to the time that the service received the packet. Upon completion of its operation, the service updates the entry in its diagnostic log (or adds another entry) with another time stamp indicate of when the service completed its operation. The difference between the two time stamps provides a measure of the amount of time the service took to complete its operation.”). Thus, given the teaching of NENE, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of collected telemetry includes a round trip time by NENE into the teaching of a system to parse suspicious session traffic by DENG-HEWLETT-LOMAN. One of ordinary skill in the art would have been motivated to do so because NENE recognizes the debug and diagnose applications efficiently ([NENE, col. 1 lines 58-62] “Unfortunately, having a service provider host an application without requiring management of virtual machines and software stacks also makes it difficult by the application developer to debug and diagnose problems with an application.”) ([NENE, col. 8 lines 25-28] “Either way (for a data flow token generated from scratch or extracted from the packet), the method includes at 212 writing diagnostics data to a diagnostics log 140 corresponding to the service that received the packet”) ([NENE, col. 9 lines 46-50] “The diagnostics data stored in the diagnostics logs 140 can be analyzed for any of a variety of reasons. For example, the diagnostics log data can be analyzed to “recreate” a given data flow.”) Claims 12 and 22 are rejected under 35 U.S.C. 103 as being unpatentable over DENG-HEWLETT-LOMAN in view of BANSAL (US-20180276041-A1). Regarding claims 12 and 22, DENG-HEWLETT-LOMAN teaches all limitations of claims 10 and 20. However, DENG-HEWLETT-LOMAN does not teach “wherein the collected telemetry includes a determination of whether a quota of service value has been exceeded.”. In analogous teaching BANSAL teaches “wherein the collected telemetry includes a determination of whether a quota of service value has been exceeded.” ([BANSAL, para. 0016] “For a given time slot, embodiments determine whether each metered cloud service has a sufficient quota of operations available to execute respective metered transactions of each workload, and whether each non-metered cloud service has a sufficient processing load to execute respective non-metered transactions.”) ([BANSAL, para. 0220] “embodiments invoke the corresponding metadata endpoint to determine if any of the quota is available at 1408. If the expected number of invocations is more than the remaining quota (i.e., the needed quota is not available), then the workload is scheduled to be processed in the next time slot and functionality returns to 1404.”). Thus, given the teaching of BANSAL, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of quota of service value has been exceeded by BANSAL into the teaching of a system to parse suspicious session traffic by DENG-HEWLETT-LOMAN. One of ordinary skill in the art would have been motivated to do so because BANSAL recognizes the need for secure access to cloud based applications ([BANSAL, para. 0002] “Accordingly, there is a need for secure access to cloud-based applications, or applications located anywhere, regardless of from what device type or by what user type the applications are accessed.”) ([BANSAL, para. 0003] “The system determines a plurality of cloud services needed to execute each of the plurality of transactions, where at least one of the determined cloud services is a metered cloud service that executes metered transactions”). Pertinent Art The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. WANG (US-20190238565-A1): This prior art teaches of a malware profile is received. The malware profile comprises a set of one or more activities associated with executing a copy of a known malicious application that is associated with the malware profile. A set of one or more log entries is analyzed for a set of entries that matches the malware profile. Based at least in part on identifying the set of entries matching the malware profile, a determination is made that a host was compromised. WANG (US-20190238566-A1): This prior art teaches of a sample is executed and one or more network activities associated with executing the sample are recorded. The recorded network activities are compared to a malware profile. The malware profile comprises a set of network activities taken by a known malicious application during execution of the known malicious application. A verdict of “malicious” is assigned to the sample based at least in part on a determination that the recorded network activities match the malware profile. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.A./ 09/16/2026 /AFAQ ALI/Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Show 11 earlier events
Feb 18, 2026
Response after Non-Final Action
Feb 24, 2026
Non-Final Rejection mailed — §103, §112
Apr 30, 2026
Interview Requested
Jun 03, 2026
Interview Requested
Jun 18, 2026
Applicant Interview (Telephonic)
Jun 18, 2026
Examiner Interview Summary
Jun 24, 2026
Response Filed
Sep 21, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750358
NON-CUSTODIAL TOOL FOR BUILDING DECENTRALIZED COMPUTER APPLICATIONS
2y 1m to grant Granted Sep 29, 2026
Patent 12726508
DYNAMIC INTELLIGENT CYBER PLAYBOOKS
2y 4m to grant Granted Sep 01, 2026
Patent 12689649
DETERMINING ADDITIONAL SIGNALS FOR DETERMINING CYBERSECURITY RISK
1y 12m to grant Granted Jul 21, 2026
Patent 12665926
System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
1y 9m to grant Granted Jun 23, 2026
Patent 12639404
Authorization of Access Rights Licenses
2y 2m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+11.9%)
2y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 143 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month