Prosecution Insights
Last updated: October 02, 2026
Application No. 18/238,081

SYSTEMS AND METHODS FOR HARDWARE ASSISTED INITIAL AND SUBSEQUENT EVENT DETECTION

Non-Final OA §103§112
Filed
Aug 25, 2023
Examiner
NAJI, YOUNES
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Fortinet Inc.
OA Round
3 (Non-Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
342 granted / 455 resolved
+17.2% vs TC avg
Strong +73% interview lift
Without
With
+73.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
31 currently pending
Career history
497
Total Applications
across all art units

Statute-Specific Performance

§101
9.4%
-30.6% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
12.4%
-27.6% vs TC avg
§112
19.0%
-21.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 455 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/13/2026 has been entered. Claims 1-20 have been examined. Response to Arguments Applicant’s arguments with respect to claims 1,15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. With regards to claim objection (Claim 1), Applicant amendment does not overcome the claim objection. – See 112 2nd rejection below. With regards to claim objection (Claim 13), Applicant amendment overcomes the claim objection. Therefore, the claim objection is withdrawn. With regards to 112 2nd rejection (Claims 12 &15), Applicant’s amendments overcome the rejection. Therefore, the rejection is withdrawn. With regards to 112 2nd rejection (Claim 18), Applicant’s amendment does not overcome the rejection. Therefore, the rejection is maintained. See 112 2nd rejection below. Claim Objections Claims 1,15 are objected to because of the following informalities: With regards to claim 1, the claim recites “ an first occurrence” the examiner suggests amending the claim to recite “a first occurrence”. With regards to claim 15, the claim recites “ a network interface circuit configured to….from a data communication network from a data communication network” The “from a data communication network” is repeated twice. Examiner suggested removing the second “ from a data communication network”. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-14,18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. With regards claim 1, the claim recites “ the event” it is unclear what the event is referring to because claim 1 recites “network events” . Therefore, the examiner is unable to determine the metes and bounds of the claim language. The examiner suggests amending the claim to recite “an event” With regards to claim 18, the claim recites “general purpose processor of the network security appliance” It is unclear what the network security appliance is referring to because claim 18 recites “a network security appliance” and claim 15 which claim 18 depends on recites “ a network security appliance”. It is unclear if “the network security appliance” recited in claim 18 refers to “a network security appliance” recited in claim 18 or “ a network security appliance” recited in claim 15. Therefore, the examiner is unable to determine the metes and bounds of the claim language. Examiner suggests amending the claim to recite “ wherein the device is embedded into the network security appliance”. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1,2,5,6,10,11,14,15,20 are rejected under 35 U.S.C. 103 as being unpatentable Guo et al. Patent No. US 11,223,562 (Guo hereinafter ) in view of Li et al. Publication No. US 2016/0149812 (Li hereinafter) further in view of Zhang et al. Publication No.US 2023/0125310 (Zhang hereinafter). Regarding claim 1, Guo teaches a method for classifying network events into the first occurrence of the event and the subsequent occurrence of the same event (Fig.2 & Fig.8) the method comprising: receiving, by a network event classification circuit of a network interface circuit, a network event from a data communication network ( Col.9, lines 1-35 - hardware accelerator 268 may be implemented within NIC 266 to allow the hardware acceleration function to be used by a general-purpose processor 270 as well as other devices that may be co-located in a data center, for example, with the network device 264. Further, NIC 266 may provide traffic classification service and processing services to other host systems or network nodes operatively coupled with the NIC 266 without using the processing of the general-purpose processor 27 - NIC 266 may further include network interface 276 that receives network traffic, and a network processor 274 to process a network flow. In an embodiment, the hardware accelerator 268 can be configured to perform packet classification using a CBF and maintain values of connection rate meters 284. Metering operations can be performed by the hardware accelerator 268 - network processor 216 or hardware accelerator 218 can be configured to receive an incoming packet, extract n-tuple values ( e.g. source IP address, source port, destination IP address, IP address, protocol) of the incoming packet, searches information associated with the n-tuple values using a CBF – Col.6, lines 20-35 - The term "n-tuple" is used herein to describe a set of n elements (e.g., source and/or destination IP address, port, and protocol) present, for example, in the header of a packet that can be used to identify a transport protocol connection with which the packet is associated.), [..] extracting, by the network event classification circuit, a transaction identifier identifying the network event; generating, by the network classification circuit, a search command including a subset of the transaction identifier; and executing, by the network classification circuit, the search command, wherein executing the search command includes: hashing the subset of the transaction identifier with a first hash seed to yield a first memory address, and hashing the subset of the transaction identifier with a second hash seed to yield a second memory address (Col.9, lines 60-70 & Col.10, lines 1-10 - The CBF module 306 performs search operations. The n-tuple extracted by the N-tuple header extraction module 304 is fed to CBF module 306. Then-tuple includes a source IP address, destination IP address, layer four protocol, source port, destination port, IP address family and other such information. The CBF module searches the CBF by calculating K hash values by applying K hash functions to the n-tuple values extracted from the packet, reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters, and evaluates whether all K memory locations contain non-zero values. the K hash values point to one of k memory spaces into which the CBF memory has been partitioned. Alternatively, the K hash values may point to the same memory space. Non-limiting examples of hash functions that may be used include Cyclic Redundancy Check (CRC) and exclusive ORs (XORs) with random seeds.Col.12, lines 35-60 - - As shown in FIG. 4, the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410). - Then-tuple 402 may include values of one or more of the source IP address, the destination IP address, the layer four protocol, the source port, and the destination port of a packet at issue. All or a portion of then-tuple 402 may be input to multiple hash functions). generating a classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address, (Col.12, lines 35-70 - the hash value generated by has function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented As shown in FIG. the hash function generated pointers may be used to access a memory space associated with the hash function to retrieve an s-bit unsigned integer value representing a counter. Alternatively, the pointers may access a common (non-partitioned) memory space. In one embodiment, when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection). Guo teaches extracting the transaction identifier and that the classification is transmitted within the network security appliance, wherein the network security appliance performs one or more processes using the classification (Col.9, lines 60-70 ,Col.7, lines 55-60, Col. 8, lines 60-65 – extracting n-tuple values and the network device (e.g. firewall, IDS/IPs) processes the incoming packet based on whether the incoming packet is the first packet or subsequent packet). However Guo does not explicitly teach generating the transaction Identifier identifying the network event and transmitting the classification to a network security appliance Li teaches generating the transaction Identifier identifying the network event (¶0019 - Flow engine 250 receives incoming data packets which can be communication from client devices. Flow engine 250 processes the received data packets to identify the flow associated with the received data packets. ¶ 0025 - the flow engine 250 generates a flow identifier for each received data packet. As described above, the flow identifier uniquely identifies each flow being processed. the flow identifier is therefore referred to as a "flow key." The flow key is generated from the 5-tuple or 6-tuple (or more) information of the received data packets to uniquely associate received data packets belonging to the same flow - See claim 1 - flow engine configured to receive incoming data packets and to generate a flow key identifying a flow to which the received data packet belongs, the flow engine further configured to apply a hash function to the flow key to generate a flow hash value and an entry hash value See also Claim 4). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Li. The motivation for doing so is to allow system to uniquely identify each flow being processed (Li – ¶0025). Zhang teaches transmitting the classification to a network security appliance, wherein the network security appliance performs one or more processes using the classification (Abstract - classification of the IoT device is provided to a security appliance configured to apply a policy to the Io T device). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Zhang. The motivation for doing so is to allow system to provide the classification to the security appliance instead of being within the same device in order to provide massive computing power and flexibility that local device cannot match. Regarding claim 2, Guo further teaches performing, by a processing resource, a network process using at least the classification of the network event (Claim 1 - when said determining is affirmative, classifying, by the processing resource, the packet as a subsequent packet of the active transport protocol connection, when said determining is negative: classifying, by the processing resource, the packet as a first packet of a new transport protocol connection - processing, by the processing resource, the packet in accordance with its classification as the first packet or the subsequent packet). Regarding claim 5, Guo further teaches wherein the classification of the network event indicates an initial occurrence, executing, by the network classification circuit, an increment command, wherein executing the increment command includes: incrementing the first value at the first memory address and incrementing the second value at the second memory address (Col. Lines 40-50 - classifies the packet as first packet of a new transport protocol connection when said determination is negative. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero – Claim 1,Fig.10 and Col.2, lines 1-5 -processing resource increments value of those counters of the multiple counters corresponding to the n-tuple values based on said determination. Col.10, lines 1- 30 -reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters ,the value at each of the k memory locations is incremented if the incoming packet is the first packet). Regarding claim 6, Guo further teaches when a search command corresponding to either the first memory address or the second memory address has not been received for a defined period, executing, by the network classification circuit, a decrement command, wherein executing the decrement command includes: decrementing the first value at the first memory address and the second value at the second memory address (Col. 13, lines 15-20 -after a predetermined amount of time or after a predetermined number of packets have been processed, counters that were previously incremented can be decremented. In this manner, when there has been no active CBF search for a particular connection, the counters are gradually cleared – See Claim1, Col.11, lines 20- 30 - The connection rate meter module 312 may increment the values of those counters of the multiple counters corresponding to the n-tuple values associated with a search request and may decrement one or more counters when a decrement event is detected for one or more counters of the multiple counters. In an embodiment, the decrement event includes the retirement queue reaching a predetermined or configurable depth threshold or a timestamp of a top queue entry of the retirement queue meeting a time threshold – See Also claim 10). Regarding claim 10, Guo further teaches wherein generating the classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address includes: determining that both the first value and the second value are zero; and indicating that the classification of the network event indicates an initial occurrence based at least in part on the determination that both the first value and the second value are zero (Col.3, lines 60-70 & Col.4, lines 1-5 - the CBF receives then-tuple value of the incoming packet, hashes the n-tuple values to calculate k hash values, reads k memory locations corresponding to the k hash values, and determines whether the value at each of the k memory locations is non-zero. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero and the incoming packet is classified as the subsequent packet if the value at each of the k memory locations is non-zero.Col.12, lines 45-60 - each pointer PTR_0 and PTR_l points to a separate memory space, in alternative embodiments, the pointers may be used to access the same memory space. At the time of initialization, the values of all memory locations in Mem O4 08 and Mem 1 410 may be set to zero - when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection). Regarding claim 11, Guo further teaches wherein generating the classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address includes: determining that at least one of the first value and the second value is greater than zero; and indicating that the classification of the network event indicates a subsequent occurrence based at least in part on the determination that at least one of first value and the second value is greater than zero( Col.12, lines 35-50 - the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented – Col.3, lines 60-70 & Col.4, lines 1-5 - the CBF receives then-tuple value of the incoming packet, hashes the n-tuple values to calculate k hash values, reads k memory locations corresponding to the k hash values, and determines whether the value at each of the k memory locations is non-zero. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero and the incoming packet is classified as the subsequent packet if the value at each of the k memory locations is non-zero-Col.12, lines 45-60 - each pointer PTR_0 and PTR_l points to a separate memory space, in alternative embodiments, the pointers may be used to access the same memory space. At the time of initialization, the values of all memory locations in Mem O4 08 and Mem 1 410 may be set to zero - when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection). Regarding claim 14, Guo further teaches wherein the network event is a network packet (Col.3, lines 50-55 - a processor on a network device receives an incoming packet ). Regarding claim 15, Guo teaches a network event classification device, the device comprising (Fig.2 & Fig.8) the device comprising: a network interface circuit configured to receive a network event from a data communication network from a data communication network;( Col.9, lines 1-35 - hardware accelerator 268 may be implemented within NIC 266 to allow the hardware acceleration function to be used by a general-purpose processor 270 as well as other devices that may be co-located in a data center, for example, with the network device 264. Further, NIC 266 may provide traffic classification service and processing services to other host systems or network nodes operatively coupled with the NIC 266 without using the processing of the general-purpose processor 27 - NIC 266 may further include network interface 276 that receives network traffic, and a network processor 274 to process a network flow. In an embodiment, the hardware accelerator 268 can be configured to perform packet classification using a CBF and maintain values of connection rate meters 284. Metering operations can be performed by the hardware accelerator 268 - network processor 216 or hardware accelerator 218 can be configured to receive an incoming packet, extract n-tuple values ( e.g. source IP address, source port, destination IP address, IP address, protocol) of the incoming packet, searches information associated with the n-tuple values using a CBF – Col.6, lines 20-35 - The term "n-tuple" is used herein to describe a set of n elements (e.g., source and/or destination IP address, port, and protocol) present, for example, in the header of a packet that can be used to identify a transport protocol connection with which the packet is associated.), a network processor configured to [..] extracting a transaction identifier identifying the network event; generate a search command including a subset of the transaction identifier; and execute the search command, wherein executing the search command includes: hashing the subset of the transaction identifier with a first hash seed to yield a first memory address, and hashing the subset of the transaction identifier with a second hash seed to yield a second memory address (Col.9, lines 60-70 & Col.10, lines 1-10 - The CBF module 306 performs search operations. The n-tuple extracted by the N-tuple header extraction module 304 is fed to CBF module 306. Then-tuple includes a source IP address, destination IP address, layer four protocol, source port, destination port, IP address family and other such information. The CBF module searches the CBF by calculating K hash values by applying K hash functions to the n-tuple values extracted from the packet, reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters, and evaluates whether all K memory locations contain non-zero values. the K hash values point to one of k memory spaces into which the CBF memory has been partitioned. Alternatively, the K hash values may point to the same memory space. Non-limiting examples of hash functions that may be used include Cyclic Redundancy Check (CRC) and exclusive ORs (XORs) with random seeds.Col.12, lines 35-60 - - As shown in FIG. 4, the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410). - Then-tuple 402 may include values of one or more of the source IP address, the destination IP address, the layer four protocol, the source port, and the destination port of a packet at issue. All or a portion of then-tuple 402 may be input to multiple hash functions). generating a classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address, wherein the classification indicates whether the network event is an initial occurrence or a subsequent occurrence of a same event;, (Col.12, lines 35-70 - the hash value generated by has function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented As shown in FIG. the hash function generated pointers may be used to access a memory space associated with the hash function to retrieve an s-bit unsigned integer value representing a counter. Alternatively, the pointers may access a common (non-partitioned) memory space. In one embodiment, when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection). Guo teaches extracting the transaction identifier and that the classification is transmitted within the network security appliance and wherein the network security appliance performs one or more processes using the classification (Col.9, lines 60-70 ,Col.7, lines 55-60, Col. 8, lines 60-65 – extracting n-tuple values and the network device (e.g. firewall, IDS/IPs) processes the incoming packet based on whether the incoming packet is the first packet or subsequent packet). However Guo does not explicitly teach generating the transaction Identifier identifying the network event and transmitting the classification to a network security appliance Li teaches generating the transaction Identifier (¶ 0019 - Flow engine 250 receives incoming data packets which can be communication from client devices. Flow engine processes the received data packets to identify the flow associated with the received data packets. ¶ 0025 - the flow engine generates a flow identifier for each received data packet. As described above, the flow identifier uniquely identifies each flow being processed. the flow identifier is therefore referred to as a "flow key." The flow key is generated from the 5-tuple or 6-tuple (or more) information of the received data packets to uniquely associate received data packets belonging to the same flow - See claim 1 - flow engine configured to receive incoming data packets and to generate a flow key identifying a flow to which the received data packet belongs, the flow engine further configured to apply a hash function to the flow key to generate a flow hash value and an entry hash value See Claim 4). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Li. The motivation for doing so is to allow system to uniquely identify each flow being processed (Li – ¶0025). Zhang teaches transmitting the classification to a network security appliance, wherein the network security appliance performs one or more processes using the classification (Abstract - classification of the IoT device is provided to a security appliance configured to apply a policy to the Io T device). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Zhang. The motivation for doing so is to allow system to provide the classification to the security appliance instead of being within the same device in order to provide massive computing power and flexibility that local device cannot match. Regarding claim 20, Guo further teaches wherein the classification of the network event indicates an initial occurrence, and wherein the network processor is further configured to: execute an increment command, wherein executing the increment command includes: incrementing the first value at the first memory address and incrementing the second value at the second memory address(Col. 10, Lines 40-50 - classifies the packet as first packet of a new transport protocol connection when said determination is negative. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero – Claim 1,Fig.10 and Col.2, lines 1-5 -processing resource increments value of those counters of the multiple counters corresponding to the n-tuple values based on said determination. Col.10, lines 1- 30 -reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters ,the value at each of the k memory locations is incremented if the incoming packet is the first packet Claims 3,16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Lan et al. Publication No. US 2021/0303984 A1 ( Lan hereinafter) Regarding claim 3, Guo further teaches wherein the network process is selected from a group consisting of: a denial of service attack detection process (Col.5, lines 30-35 & lines 60-65). However, Guo does not explicitly teach wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process However, Lan teaches wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (¶0044 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan). Regarding claim 16, Guo further teaches wherein the device is implemented as a network interface card, and wherein the network interface card (Fig.2C). However, Guo does not explicitly teach wherein the network interface card includes a first general purpose processor configured to interface with a second general purpose processor of a network security appliance. However, Lan teaches device is implemented as a network interface card, and wherein the network interface card includes a first general purpose processor configured to interface with a second general purpose processor of a network security appliance (¶ 0037 - Fig.1B – device is implemented as NIC and NIC includes processor configured to interface with second processor of network security device 102). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan). Regarding claim 17, Guo further teaches wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to: perform a network process using at least the classification of the network event, and wherein the network process is selected from a denial of service attack detection process (Claim 12 - non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to: process the packet in accordance with its classification as the first packet or the subsequent packet.Col.2, lines 20-30 - For processing the packet further, the network device makes a determination regarding whether the subsequent packet is part of a denial of service (DoS) attack, and drops the subsequent packet if its determined to be part of the denial of server attack. The denial of service attack may include a Transmission Control Protocol (TCP) SYN flood or a port scan attack). However, Guo does not explicitly teach wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process Lan teaches wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (Fig.1B, ¶ 0037, ¶ 0027 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan). Regarding claim 18, Guo further teaches device is embedded into a network security appliance (Col. 7, lines 40-45 - The network device 104 may include a hardware accelerator module 206. In one embodiment the CBF may be implemented by the hardware accelerator module 206 to facilitate efficient packet classification and/or further processing relating to the packet based on defined policies. The network device 104 may have other processing resources, including one or more of a network processor, an embedded processor and/or a general-purpose processor to perform different functions. In the text of the present example, the network device 204 may represent a network security device (e.g., a firewall appliance, a UTM appliance, an IDS/IPS, or the like) and includes a network interface 206 that can act as a point of interconnection between network device 204 and a network 202) However, Guo does not explicitly teach where the network processor is coupled to a general purpose processor of the network security appliance However, Lan teaches wherein the device is imbedded into a network security appliance, and where the network processor is coupled to a general purpose processor of the network security appliance(¶ 0031 - Fig.1A – device is embedded in to network security device 102 , and the network processor 112 is coupled to general purpose processor 104). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan). Regarding claim 19, Guo further teaches wherein the general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the general purpose processor causes the general purpose processor to: perform a network process using at least the classification of the network event. wherein the network process is selected from: a denial of service attack detection process (Claim 12 - non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to: process the packet in accordance with its classification as the first packet or the subsequent packet.Col.2, lines 20-30 - For processing the packet further, the network device makes a determination regarding whether the subsequent packet is part of a denial of service (DoS) attack, and drops the subsequent packet if its determined to be part of the denial of server attack. The denial of service attack may include a Transmission Control Protocol (TCP) SYN flood or a port scan attack). However, Guo does not explicitly teach wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process Lan teaches wherein the general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the general purpose processor causes the general purpose processor to: perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (Fig.1B, ¶ 0037, ¶ 0027 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan). Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable Guo in view of Li further in view of Zhang further in view of Guleria et al. Publication No. US 2016/0285753 A2 ( Guleria hereinafter) Regarding claim 4, Guo does not explicitly teach wherein the memory is organized into a plurality of tables, wherein the subset of the transaction identifier is a first subset of the transaction identifier, and wherein the method further comprises: enabling, by the network classification circuit, a memory table of the plurality of tables, wherein the memory table is selected based at least in part on a second subset of the transaction identifier. However, Guleria teaches a memory is organized into a plurality of tables, wherein the subset of the transaction identifier is a first subset of the transaction identifier, and wherein the method further comprises: enabling, by the network classification circuit, a memory table of the plurality of tables, wherein the memory table is selected based at least in part on a second subset of the transaction identifier (¶ 0030 - Packet classification involves executing a lookup in memory to classify the packet by determining which flow entry in the forwarding tables best matches the packet based upon the match structure, or key, of the flow entries – ¶ 0039 - Upon receipt of a packet of a flow of packets at the network device, it is determined, based on an identification of the flow, whether the packet has a corresponding forwarding table entry within a set of one or more forwarding tables of the network device. If the packet is determined not to have any corresponding forwarding table entry (i.e., the packet belongs to an unknown flow, which is to be inserted in a forwarding table), a flow learning element is retrieved from a flow learning table using a first portion of the flow identification. A second portion of the flow identification for the received packet is used to determine whether the flow of the packet is currently being learnt. In response to determining that the second portion matches a sub-element of the retrieved flow learning element - ¶ 0049 – 0052 Alternatively if the second portion of the flow identification does not match any sub-element of the flow learning element 520 which has a "used" bit set, this means that the flow is not being learnt by the forwarding device and an entry needs to be inserted in the flow learning table 500 See Also – ¶ 0069). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Guleria. The motivation for doing so is to allow system to provide techniques which avoid sending multiple requests to the control plane in order to learn the same flow and to avoid delays in the processing of new flow entries ( ¶ 0004 – Guleria). Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Panwar et al. Patent No. US 7,966,442 B1 ( Panwar hereinafter) Regarding claim 7, Guo does not explicitly teach wherein the defined period is user programmable However, Panwar teaches defined period is user programmable ( Col.10, lines 1-10 an administrator may set the update period to one day or one hour). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Panwar. The motivation for doing so is to allow user to set the period for tracking purposes. Claims 8,9 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Verplanken et al. Publication No. US 2021/0124694 A1 ( Verplanken hereinafter) Regarding claim 8, Guo does not explicitly teach as part of the executing the increment command, queuing, by the network classification circuit, a decrement command However, Verplanken teaches as part of the executing the increment command, queuing, by the network classification circuit, a decrement command (¶ 0009 - in which when an increment request to increment the at least one counter is pending, the cache control circuitry is configured to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter- ¶ 0015 - when an increment request to increment the at least one counter is pending, prioritizing the pending increment request in preference over a decrement request to decrement the at least one counter – ¶ 0031 - FIG. 9 is a flow diagram illustrating a method for allocating decrement requests to a decrement request buffer – ¶ 0043 - if two decrement/increment requests can be carried out per processing cycle, the cache control circuitry may delay the decrement request until a cycle in which either no increment requests are being processed, or only one increment request is being processed). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken) Regarding claim 9, Guo further teaches determining, by the network classification circuit, a time expiration of the decrement command; and based at least in part on the time expiration, executing, by the network classification circuit, the decrement command, wherein executing the decrement command includes: decrementing the first value at the first memory address and the second value at the second memory address (Col 16, lines 50-60 - those counters of the multiple counters corresponding to the n-tuple values are incremented. For example, the various n-tuple values may be fed into k separate hash functions to produce k hash value pointers that identify the respective counters in a partitioned or nonpartitioned memory of the CBF. At block 1016, responsive to a decrement event for one or more counters in the CBF memory, the counters are decremented. As noted above, the decrement event may represent the retirement queue (e.g., FIFO 412) reaching a depth threshold or a timestamp of a tape queue entry of the retirement queue meeting a time threshold). Claims 12,13 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Verplanken further in view of Heo et al. Publication No. US 2021/0374131 A1 ( Heo hereinafter) Regarding claim 12, Guo does not explicitly teach wherein the search command is stored in a search command queue, the increment command is stored in an increment command queue, and the decrement command is stored to a decrement command queue. However, Verplanken teaches the increment command is stored in an increment command queue, and the decrement command is stored to a decrement command queue ( ¶ 0098- The cache control circuitry 102 prioritizes pending increment requests to any of the counters stored in the SRAM over the decrement requests stored in the decrement request buffer 110, for example by waiting until a processing cycle in which no increment requests are executed ( e.g. a cycle in which no allocations to the cache are made) to process the next decrement request in the decrement request buffer 110. It should be noted that increment requests to any of the stored counters are prioritized over decrement requests to any of the stored counters, even if the decrement request is to another one of the stored counters, rather than merely prioritizing increment requests to a given counter over decrement requests to that same counter). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken) However, Guo in view of Verplanken does not explicitly teach wherein the search command is stored in a search command queue Heo teaches search command is stored in a search command queue (¶ 0065 - The command queue 110 sequentially stores search commands) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo in view of Verplanken to include the teachings of Heo. The motivation for doing so is to allow the system to store search commands in command queue for processing ( Heo – ¶ 0065). Regarding claim 13, Guo does not explicitly teach wherein accessing a command by the network classification circuit from one of the search command queue, the increment command queue, or the decrement command queue is based upon a priority algorithm, and wherein the priority algorithm causes all commands in the increment command queue to be executed before any command in either the search command queue or the decrement command queue. However, Verplanken teaches wherein accessing a command by the network classification circuit from one of the search command queue, the increment command queue, or the decrement command queue is based upon a priority algorithm, and wherein the priority algorithm causes all commands in the increment command queue to be executed before any command in either the search command queue or the decrement command queue (¶ 0009 - in which when an increment request to increment the at least one counter is pending, the cache control circuitry is configured to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter – ¶ 0037 -Prioritizing requests to increment the counters over requests to decrement the counters allows the performance of the system to be further improved - ¶ 0098- The cache control circuitry 102 prioritizes pending increment requests to any of the counters stored in the SRAM over the decrement requests stored in the decrement request buffer 110, for example by waiting until a processing cycle in which no increment requests are executed ( e.g. a cycle in which no allocations to the cache are made) to process the next decrement request in the decrement request buffer 110. It should be noted that increment requests to any of the stored counters are prioritized over decrement requests to any of the stored counters, even if the decrement request is to another one of the stored counters, rather than merely prioritizing increment requests to a given counter over decrement requests to that same counter). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOUNES NAJI whose telephone number is (571)272-2659. The examiner can normally be reached Monday - Friday 8:30 AM -5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar A Louie can be reached on (571) 270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /YOUNES NAJI/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Aug 25, 2023
Application Filed
Aug 27, 2025
Non-Final Rejection mailed — §103, §112
Nov 28, 2025
Response Filed
Jan 13, 2026
Final Rejection mailed — §103, §112
May 13, 2026
Request for Continued Examination
May 23, 2026
Response after Non-Final Action
Sep 23, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732490
REDUCING BLUETOOTH CONNECTION LATENCY USING SELECTIVE GATT CACHE REQUESTS
3y 10m to grant Granted Sep 08, 2026
Patent 12706891
TUNNELLED REMOTE INTENT MECHANISM
3y 5m to grant Granted Aug 11, 2026
Patent 12665749
MIGRATING SECRETS FROM A CLOUD ENVIRONMENT TO A LOCAL SYSTEM
3y 3m to grant Granted Jun 23, 2026
Patent 12659322
Systems and methods for identifying legitimate network traffic imitation
2y 2m to grant Granted Jun 16, 2026
Patent 12647495
METHODS AND APPARATUS TO IDENTIFY MAIN PAGE VIEWS
1y 8m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
99%
With Interview (+73.4%)
2y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 455 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month