Prosecution Insights
Last updated: October 02, 2026
Application No. 18/240,099

Information Security AI-Based Border Endpoint Zero-Day Block

Final Rejection §112
Filed
Aug 30, 2023
Examiner
DAVIS, ZACHARY A
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
2 (Final)
53%
Grant Probability
Moderate
3-4
OA Rounds
1y 4m
Est. Remaining
75%
With Interview

Examiner Intelligence

Grants 53% of resolved cases
53%
Career Allowance Rate
274 granted / 513 resolved
-4.6% vs TC avg
Strong +22% interview lift
Without
With
+21.6%
Interview Lift
resolved cases with interview
Typical timeline
4y 5m
Avg Prosecution
36 currently pending
Career history
569
Total Applications
across all art units

Statute-Specific Performance

§101
12.2%
-27.8% vs TC avg
§103
30.9%
-9.1% vs TC avg
§102
15.8%
-24.2% vs TC avg
§112
38.7%
-1.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 513 resolved cases

Office Action

§112
DETAILED ACTION A response to the notice of non-compliant amendment was received on 25 February 2026. By this response, Claims 1-4, 10, 11, and 16 have been amended. Claim 20 has been canceled. New Claim 21 has been added. Claims 1-19 and 21 are currently pending in the present application. Response to Amendment It is noted that, because the notice of non-compliant amendment mailed 23 January 2026 required submission of the corrected sections in response thereto, the amendments to the drawings filed 28 October 2025 were not entered in part. Therefore, the amendments to Figures 1 and 2 filed 28 October 2025 were not entered. If Applicant desires entry of the amendments to Figures 1 and 2, they must be resubmitted in a manner fully compliant with 37 CFR 1.121(d). The amendments to the claims do not clearly comply with the requirement of 37 CFR 1.121(c)(2) that amended claims must include markings indicating the changes made relative to the immediate prior version of the claims. At least Claims 1 and 16 include text in added single brackets, which is not one of the markings set forth in 37 CFR 1.121(c)(2). The text of added subject matter must be shown by underlining, and the text of deleted subject matter must be shown by strikethrough or double brackets placed before and after the deleted characters. Additionally, the amendments to the claims do not clearly comply fully with the requirement of 37 CFR 1.121(c)(2) that the text of any deleted subject must be shown by being placed within double brackets if strikethrough cannot easily be perceived, noting that double brackets may also be used to show deletion of five or fewer characters. In particular, at least Claim 1 appears to include text (e.g. punctuation marks, or letters such as “e” and “s”) which may be intended to be marked with strikethrough for deletion; however, in the font used, it is difficult to discern whether such text is, in fact, marked with strikethrough. See also MPEP § 714 II.C(B). As a courtesy and for purposes of advancing prosecution, the amendments have been treated as though they were fully compliant with the requirements of 37 CFR 1.121(c)(2). Applicant is reminded that all subsequent amendments must fully comply with the provisions of 37 CFR 1.121. Response to Arguments Applicant's arguments filed 25 February 2026 have been fully considered but they are not persuasive. Regarding the rejection of Claims 1-20 under 35 U.S.C. 112(b) as indefinite, Applicant argues that the claims have been amended to correct the issues set forth in the outstanding rejections (pages 14-15 of the present response). It is noted that the amendments have addressed some of the outstanding issues but have also raised new issues, as detailed below. Therefore, for the reasons detailed above, the Examiner maintains the rejections as set forth below. Drawings The objection to the drawings for failure to comply with 37 CFR 1.84(p)(5) is withdrawn in light of the amendments to the specification. The objections to the drawings for informalities are NOT withdrawn because not all issues have been addressed and/or because the amendments appear to have raised new issues, as detailed below. Further, as noted above, the amendments to Figures 1 and 2 filed 28 October 2025 were not entered because the entire corrected section was required in response to the notice of non-compliant amendment, and therefore the objections thereto are also maintained. The drawings are objected to because they include informalities. For example, in Figures 1 and 2, element 104, “Maliciouis” should read “Malicious”. In Figures 1 and 2, element 130, “Acces” should read “Access”. In Figure 4, element 402, the hyphenation in the terms “external outbound” and “external-inbound”, for example, is inconsistent. In Figure 4, element 406, the commas at the end of each list item should be replaced by semicolons, because some items in the list appear to include internal commas. In Figure 4, step 420, it appears that “on” should be inserted after “based”. In Figure 4, step 422, the comma after “searching” should be deleted. In Figure 4, step 424, it appears that “die” may be intended to read “device”. In Figure 4, step 428, it appears that “and” at the beginning of the step should be deleted. Further, in step 428, it is not grammatically clear what the phrase “to a developer” is intended to modify. In Figure 5, step 506, the commas at the end of each list item should be replaced by semicolons, because some items in the list appear to include internal commas. In Figure 5, step 524, it appears that “on” should be inserted after “based”. In Figure 5, step 528, the comma after “searching” should be deleted. In Figure 5, step 534, it is not grammatically clear what the phrase “to a developer” is intended to modify. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification The objection to the disclosure for informalities is NOT withdrawn, because the amendments have raised new issues, as detailed below. The disclosure is objected to because of the following informalities: The specification includes minor typographical and other errors. For example, in paragraph 0004, lines 1-3, as amended, there appears to be an unmatched right parenthesis. In original paragraph 0009, line 6, it appears that critical language is missing after “by use of”. Appropriate correction is required. Applicant’s cooperation is again requested in correcting any errors of which applicant may become aware in the specification The specification is objected to as failing to provide proper antecedent basis for the claimed subject matter. See 37 CFR 1.75(d)(1) and MPEP § 608.01(o). Correction of the following is required: Independent Claims 1 and 16 have been amended to recite “traffic is unsolicited based on a lack of corresponding request traffic”, “traffic is anomalous based on deviation from historical traffic patterns”, and “unauthorized data that was unauthorized by the network border control device”, as well as “determining… whether the suspect traffic originates from an advanced persistent threat”. Although the specification discusses determining traffic is unsolicited or anomalous, there appears to be no discussion of a lack of corresponding request traffic or deviation from historical traffic patterns. Similarly, although the specification discusses unauthorized data, there appears to be no discussion of the data not being authorized by the network border control device. Additionally, although the specification discusses advanced persistent threats, there appears to be no mention of determining whether traffic originates from an APT, because the term “originates” does not appear in the specification. Further, Claim 11 has been amended to recite “learning… to identify future advanced persistent threats (APTs) based on the source information regarding the APT and the suspect traffic that is confirmed to originate from the said APT”. Although the specification discusses learning based on source information and suspect traffic presenting an APT, there appears to be no discussion of identifying future APTs or traffic that is confirmed to originate from an APT. New Claim 21 recites various steps “in real-time” including “continuously mirroring”, “comparing”, “detecting”, “quarantining”, “determining”, “releasing”, “blocking”, “tracing”, and “disabling”, as well as “to enable real-time oversight and adjustment” and “to improve future real-time detections”. Although the specification generally discusses a real-time process, there appears to be no discussion of any specific steps being performed in real time or how such steps would be performed in real time. Therefore, there does not appear to be clear antecedent basis for the claimed subject matter in the specification. For further detail, see below with respect to the rejection under 35 U.S.C. 112(a) for failure to comply with the written description requirement. Claim Objections The objections to Claims 16 and 20 for informalities are withdrawn (or moot) in light of the amendments to (or cancellation of) the claims. The objection to Claim 1 is NOT withdrawn because additional informalities are noted below. Claim 1 is objected to because of the following informalities: In Claim 1, line 48, it appears that “supervisor” should read “supervisory”. Appropriate correction is required. Claim Rejections - 35 USC § 112 The rejection of Claim 20 under 35 U.S.C. 112(b) is moot in view of the cancellation thereof. The rejection of Claims 1-19 under 35 U.S.C. 112(b) as indefinite is NOT withdrawn, because not all issues have been addressed and/or because the amendments have raised new issues, as detailed below. The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-19 and 21 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Independent Claims 1 and 16 have been amended to recite “traffic is unsolicited based on a lack of corresponding request traffic”, “traffic is anomalous based on deviation from historical traffic patterns”, and “unauthorized data that was unauthorized by the network border control device”. Although the specification discusses determining traffic is unsolicited or anomalous and also discusses matching a historical suspect traffic pattern (see, for example, paragraphs 0043, 0052, and 0057), there appears to be no discussion of a lack of corresponding request traffic or deviation from historical traffic patterns. Similarly, although the specification discusses unauthorized data (see, for example, paragraphs 0043, 0052, and 0057), there appears to be no discussion of the data not being authorized by the network border control device. Further, Applicant has not pointed out where the amended claims are supported. See also MPEP § 2163.04. Therefore, there does not appear to be clear written description of the claimed subject matter in the specification. Claim 11 has been amended to recite “learning… to identify future advanced persistent threats (APTs) based on the source information regarding the APT and the suspect traffic that is confirmed to originate from the said APT”. Although the specification discusses learning based on source information (for example, see paragraphs 0054-0055) and suspect traffic presenting an APT (see also original Claim 11), there appears to be no discussion of identifying future APTs or traffic that is confirmed to originate from an APT. Further, Applicant has not pointed out where the amended claims are supported. See also MPEP § 2163.04. Therefore, there does not appear to be clear written description of the claimed subject matter in the specification. New Claim 21 recites various steps “in real-time” including “continuously mirroring”, “comparing”, “detecting”, “quarantining”, “determining”, “releasing”, “blocking”, “tracing”, and “disabling”, as well as “to enable real-time oversight and adjustment” and “to improve future real-time detections”. Although the specification generally discusses a real-time process (for example, see abstract and paragraphs 0023 and 0057), there appears to be no discussion of any specific steps being performed in real time or how such steps would be performed in real time. Further, Applicant has not pointed out where the new claim is supported. See also MPEP § 2163.04. Therefore, there does not appear to be clear written description of the claimed subject matter in the specification. Claims not explicitly referred to above are rejected due to their dependence on a rejected base claim. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-19 and 21 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites “the suspect traffic” in lines 31, 34, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim further recites “any said network border control device that was compromised by the APT” in lines 41-42. The reference to “any said network border control device” is unclear because there were not clearly plural devices recited previously. The claim additionally recites “the network border control device” in lines 44, 46, and elsewhere. Because it appears that there are plural such devices recited in lines 41-42, the subsequent references are unclear to which of the plural devices these phrases are intended to refer. The claim also recites “searching in the network border control device… to identify any vulnerabilities” in lines 46-47. It is not clear what the device is searched for. The claim further recites “the endpoint supervisor server in said network border control device” in line 48. There is not clear antecedent basis for this limitation in the claim. Although the claim previously recited an endpoint supervisory server, this was not clearly in a network border control device. The claim additionally recites “generating, by the endpoint supervisory server to a developer of the software, a notification regarding the vulnerabilities” in lines 54-55. First, it is not grammatically clear what the phrase “to a developer” is intended to modify. The above ambiguities render the claim indefinite. Claim 2 recites “the network border control device” in lines 1-2. However, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer. Claim 3 recites “the network border control device” in lines 1-2. However, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer. Claim 4 recites “the network border control device” in lines 1-2. However, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer. Claim 10 recites “the tracing… of the source information” in lines 1-2. However, although Claim 1 recited tracing suspect traffic, there is not clear antecedent basis in the claims for tracing source information. Claim 11 recites “the APT” in line 3 and “the said APT” in line 4. However, the claim previously recited plural APTs in line 2 as well as the APT recited in Claim 1, and it is not clear to which of the plural APTs these limitations are intended to refer. Claim 16 recites “the suspect traffic” in lines 30, 33, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim further recites “any said firewall that was compromised by the APT” in lines 42-43. The reference to “any said firewall” is unclear because there were not clearly plural firewalls recited previously. The claim additionally recites “said firewall” in lines 45, 47, and elsewhere. Because it appears that there are plural firewalls recited in lines 42-43, the subsequent references are unclear to which of the plural devices these phrases are intended to refer. The claim also recites “searching, said firewall… to identify any vulnerabilities” in line 47. First, the comma after “searching” is grammatically unclear. Further, it is not clear what the firewall is searched for. The claim additionally recites “so that the captured data cannot be removed from by APT from the firewall” in lines 50-51. The phrase “from by APT” is not grammatically clear, and it is also not grammatically clear what the phrase “from the firewall” is intended to modify. The above ambiguities render the claim indefinite. Claim 21 recites “the method executed by a processor accessing instructions stored in a memory, comprising” in lines 2-3. The subject of the verb “comprising” is not grammatically clear. The claim further recites “data unauthorized for transmission” in line 20. It is not clear by who or by what the data would need to be authorized, and the specification does not provide any definition or standard for this. The claim additionally recites “the suspect traffic” in lines 25-26, 28, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim also recites “updating, by the endpoint supervisory server, the AI analyzer” in lines 46-47. It is not clear how this updating is distinct from the updating in line 33 and whether this is a separate step of updating. Further, it is not clear whether the two steps of updating both operate on the same version of AI analyzer or if they are sequential. The claim further recites “generating, by the endpoint supervisory server, a notification to a developer of software regarding the vulnerabilities in order to resolve the zero-day threat” in lines 48-49. First, it is not grammatically clear what the phrase “regarding the vulnerabilities” is intended to modify. Further, it is not clear how a notification would resolve the threat. The above ambiguities render the claim indefinite. Claims not explicitly referred to above are rejected due to their dependence on a rejected base claim. Allowable Subject Matter Claims 1-19 and 21 would be allowable if rewritten or amended to overcome the rejections under 35 U.S.C. 112(a) and (b) set forth in this Office action. A statement of reasons for the indication of allowable subject matter was set forth in the previous Office action mailed 30 July 2025. It is again noted that amendments that substantially change the scope of the claims may require reconsideration of the above indication of allowable subject matter. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Zachary A Davis whose telephone number is (571)272-3870. The examiner can normally be reached Monday-Friday, 9:00am-5:30pm, Eastern Time. Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal D Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Zachary A. Davis/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Aug 30, 2023
Application Filed
Jul 30, 2025
Non-Final Rejection mailed — §112
Oct 28, 2025
Response Filed
Oct 28, 2025
Response after Non-Final Action
Feb 25, 2026
Response Filed
Aug 12, 2026
Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12676750
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12676751
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12659750
ULTRA-WIDEBAND UNLOCK DEVICE
3y 8m to grant Granted Jun 16, 2026
Patent 12592929
TECHNIQUE FOR COMPUTING A BLOCK IN A BLOCKCHAIN NETWORK
4y 9m to grant Granted Mar 31, 2026
Patent 12566840
Systems And Methods For Creating Trustworthy Orchestration Instructions Within A Containerized Computing Environment For Validation Within An Alternate Computing Environment
3y 7m to grant Granted Mar 03, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
53%
Grant Probability
75%
With Interview (+21.6%)
4y 5m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 513 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month