Detailed Action
This Non-Final action is in response to the amendment filed on 05/12/2026
Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are pending and examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Request for Continued Examination
Receipt is acknowledged of a request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e) and a submission, filed on 05/12/2026.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 21 and 28 recite “analyzing system information relating to operation of an application programming interface (API) at a computer system relative to another API other than the API”;
The wording “another API other than the API” is not standard English and the phrase obscures whether the claim means:
one additional API, one or more additional APIs, or a specific second API distinct from the first API.
Also, the claim later recites “the other API,” which lacks an antecedent-basis/clarity issue if the earlier phrase is “another API,” because it is unclear which API is being referred to when more than another API may exist.
Examiner suggest to rewrite:
Examiner suggest to rewrite the phrase as “the API and at least one other API”.
Additionally:
Claims 1, 21 and 28 recite “restriction of access between at least part of the API, at least part of the other API, and the computer system”.
It is unclear what access is restricted and which entity is restricted from accessing which other entity.
Examiner suggests to clarify the access relationship, e.g., restriction between the API and the computer system, between APIs, or by an API to a system resource.
Furthermore, claims recite “constructing a call function for execution of the API and the other API in a sequence or at least partially in parallel with one another and executing the call function”. Partially in parallel is a relative term and indefinite
Claim 3 in part recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process, and generating a system file”
The claim is unclear as to whether the claimed system itself initiates/generates the process/file, or whether the system monitors for process initiation/file generation caused by API execution.
Claim 7 in part recites “conducting monitoring of the system over a defined period of time for outgoing system traffic, initiating a system process or generating a system file”.
The phrase is grammatically ambiguous because it is unclear whether “initiating” and “generating” are monitored events or active steps performed by the system.
Claim 22 recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process, and generating a system file”.
It is unclear whether the system initiates/generates the process/file or monitors for initiation/generation caused by API execution.
Examiner suggests to amend to “monitoring outgoing system traffic, monitoring initiation of a system process, and monitoring generation of a system file.”
Claim 27 recites “conducting monitoring of the system over a defined period of time for outgoing system traffic, initiating a system process or generating a system file”.
The phrase is ambiguous as to whether “initiating” and “generating” are monitored events or active steps.
Examiner suggests to amend to “monitoring the system over a defined period of time for outgoing system traffic, initiation of a system process, or generation of a system file.”
Claim 29 recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process and generating a system file”.
It is unclear whether the method actively initiates/generates the process/file or monitors for process initiation/file generation caused by API execution.
Examiner suggests to amend to “monitoring outgoing system traffic, monitoring initiation of a system process, and monitoring generation of a system file.”
Claims 31–33 depend from method claim 28 but recite “the operations further comprise.” Because claim 28 is a method claim and does not introduce “operations,” , “the operations” lacks antecedent basis in method claim 28.
Claim 36 recites “learns an operation norm of the system, and identifies an occurrence of operation of the system that is counter to the learned norm”.
“Operation norm” and “counter to the learned norm” lack objective boundaries unless the specification clearly defines how the norm is determined and what qualifies as counter to the norm.
Specification ¶ [0072] states that the analytical model can learn system operation norms and identify occurrences counter to observed norms, but additional objective boundaries is needed under MPEP § 2173.
Dependent claims 2, 6, 24-26, and 34-36 are rejected by virtue of their dependencies.
Allowable subject matter
Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are considered allowable over prior art of record, pending 35 USC 112(b) rejections addressed before.
Examiner’s Statement of Reasons for Allowance
Closest prior art of record Malton et al. ( US10664377) directed to Systems, methods, and software that can be used to automate software verifications. In some aspects, one or more application program interface (API) call pairs are generated based on a source code of a user module that invokes an API. Each of the one or more API call pairs comprises a first API call that invokes the API followed by a second API call that invokes the API. One or more fragments are generated based on the one or more API calls pairs. Each of the one or more fragments represents an execution sequence that includes at least one of the one or more API call pairs. The one or more fragments are verified.
Prior art of record Malton or others individually or in combination fail to disclose or suggest amended independent claims 1, 21 and 28 reciting “analyzing system information relating to operation of an application programming interface (API) at a computer system relative to another API other than the API; based on a result of the analyzing of the system information, constructing a call function for execution of the API and the other API in a sequence or at least partially in parallel with one another and executing the call function”.
claims 1-3, 6-7, 21-22, 24-29, and 31-36 are considered allowable since when reading the claims in light of the specification, as per MPEP §2111.01 or Toro Co. v. White Consolidated Industries Inc., 199 F.3d 1295, 1301, 53 USPQ2d 1065, 1069 (Fed. Cir. 1999), none of the references of record alone or in combination disclose or suggest the combination of limitations specified in the independent claims.
Pertinent prior art of record not relied upon :
US 8499354 B1 directed to US 8499354 B1 directed to attempted exploit of a vulnerability of an application executed by a computer is detected. The exploit attempts to call an application programming interface (API) and abuse application data through a malicious parameter of the call. The API of the application is hooked and monitored for a call made to the hooked API. A parameter of the call is analyzed to determine whether the parameter has a malicious characteristic indicating an attempt to use data within an address space of the application to execute malicious software. A remediation action is taken responsive to determining that the parameter has a malicious characteristic.
20190325143 A1 directed to methods and systems of identifying vulnerabilities of an application. An exemplary method comprises identifying at least one function in executable code of the application according to at least one rule for modification of functions, adding an interception code to the executable code of the application upon launching of the application, executing the application with the added interception code, collecting, by the interception code, data relating to function calls performed by the application during execution, analyzing the collected data based on criteria for safe execution of applications, wherein the criteria comprises a range of permissible values of arguments of intercepted function calls and identifying inconsistencies between the analyzed data and the criteria for safe execution of applications, wherein the inconsistencies indicate vulnerabilities in the application.
US 10558809 B1 directed to An example method includes monitoring execution of one or more applications on a runtime computing system that includes a plurality of processing units, receiving, from the runtime computing system during execution of the applications, monitoring information that includes at least one of function call data or application programming interface call data associated with operations performed by the plurality of processing units during execution of the applications, importing the monitoring information into a risk model, analyzing the monitoring information within the risk model to determine one or more potential vulnerabilities and one or more impacts of the one or more vulnerabilities in the runtime computing system, and outputting, for display in a graphical user interface, a graphical representation of the one or more potential vulnerabilities and the one or more impacts within the risk model.
Conclusion
Any inquiry concerning this communication or earlier communications from the
examiner should be directed to Taghi T Arani whose telephone number is (571)272-
3787. The examiner can normally be reached Mon-Fri 8:am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing
using a USPTO supplied web-based collaboration tool. To schedule an interview,
applicant is encouraged to use the USPTO Automated Interview Request (AIR) at
http:/Avwww.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's
supervisor, Amy Johnson can be reached at (571) 272-2238. The fax phone number for
the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be
obtained from Patent Center. Unpublished application information in Patent Center is
available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https:/Awww.uspto.gov/patents/apply/patent-
center for more information about Patent Center and https:/Awww.uspto.gov/patents/docx for information about filing in DOCX format. For
additional questions, contact the Electronic Business Center (EBC) at 866-217-9197
(toll-free). If you would like assistance from a USPTO Customer Service
Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TAGHI T ARANI/Supervisory Patent Examiner, Art Unit 2438