Prosecution Insights
Last updated: August 18, 2026
Application No. 18/327,129

AUTOMATIC BACKDOOR VULNERABILITY DETECTION

Non-Final OA §112
Filed
Jun 01, 2023
Examiner
ARANI, TAGHI T
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
3 (Non-Final)
48%
Grant Probability
Moderate
3-4
OA Rounds
1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 48% of resolved cases
48%
Career Allowance Rate
13 granted / 27 resolved
-9.9% vs TC avg
Strong +69% interview lift
Without
With
+68.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
1 currently pending
Career history
29
Total Applications
across all art units

Statute-Specific Performance

§101
14.6%
-25.4% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
21.4%
-18.6% vs TC avg
§112
22.3%
-17.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 27 resolved cases

Office Action

§112
Detailed Action This Non-Final action is in response to the amendment filed on 05/12/2026 Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are pending and examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Request for Continued Examination Receipt is acknowledged of a request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e) and a submission, filed on 05/12/2026. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 21 and 28 recite “analyzing system information relating to operation of an application programming interface (API) at a computer system relative to another API other than the API”; The wording “another API other than the API” is not standard English and the phrase obscures whether the claim means: one additional API, one or more additional APIs, or a specific second API distinct from the first API. Also, the claim later recites “the other API,” which lacks an antecedent-basis/clarity issue if the earlier phrase is “another API,” because it is unclear which API is being referred to when more than another API may exist. Examiner suggest to rewrite: Examiner suggest to rewrite the phrase as “the API and at least one other API”. Additionally: Claims 1, 21 and 28 recite “restriction of access between at least part of the API, at least part of the other API, and the computer system”. It is unclear what access is restricted and which entity is restricted from accessing which other entity. Examiner suggests to clarify the access relationship, e.g., restriction between the API and the computer system, between APIs, or by an API to a system resource. Furthermore, claims recite “constructing a call function for execution of the API and the other API in a sequence or at least partially in parallel with one another and executing the call function”. Partially in parallel is a relative term and indefinite Claim 3 in part recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process, and generating a system file” The claim is unclear as to whether the claimed system itself initiates/generates the process/file, or whether the system monitors for process initiation/file generation caused by API execution. Claim 7 in part recites “conducting monitoring of the system over a defined period of time for outgoing system traffic, initiating a system process or generating a system file”. The phrase is grammatically ambiguous because it is unclear whether “initiating” and “generating” are monitored events or active steps performed by the system. Claim 22 recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process, and generating a system file”. It is unclear whether the system initiates/generates the process/file or monitors for initiation/generation caused by API execution. Examiner suggests to amend to “monitoring outgoing system traffic, monitoring initiation of a system process, and monitoring generation of a system file.” Claim 27 recites “conducting monitoring of the system over a defined period of time for outgoing system traffic, initiating a system process or generating a system file”. The phrase is ambiguous as to whether “initiating” and “generating” are monitored events or active steps. Examiner suggests to amend to “monitoring the system over a defined period of time for outgoing system traffic, initiation of a system process, or generation of a system file.” Claim 29 recites “the generating of the impact data comprises monitoring outgoing system traffic, initiating a system process and generating a system file”. It is unclear whether the method actively initiates/generates the process/file or monitors for process initiation/file generation caused by API execution. Examiner suggests to amend to “monitoring outgoing system traffic, monitoring initiation of a system process, and monitoring generation of a system file.” Claims 31–33 depend from method claim 28 but recite “the operations further comprise.” Because claim 28 is a method claim and does not introduce “operations,” , “the operations” lacks antecedent basis in method claim 28. Claim 36 recites “learns an operation norm of the system, and identifies an occurrence of operation of the system that is counter to the learned norm”. “Operation norm” and “counter to the learned norm” lack objective boundaries unless the specification clearly defines how the norm is determined and what qualifies as counter to the norm. Specification ¶ [0072] states that the analytical model can learn system operation norms and identify occurrences counter to observed norms, but additional objective boundaries is needed under MPEP § 2173. Dependent claims 2, 6, 24-26, and 34-36 are rejected by virtue of their dependencies. Allowable subject matter Claims 1-3, 6-7, 21-22, 24-29, and 31-36 are considered allowable over prior art of record, pending 35 USC 112(b) rejections addressed before. Examiner’s Statement of Reasons for Allowance Closest prior art of record Malton et al. ( US10664377) directed to Systems, methods, and software that can be used to automate software verifications. In some aspects, one or more application program interface (API) call pairs are generated based on a source code of a user module that invokes an API. Each of the one or more API call pairs comprises a first API call that invokes the API followed by a second API call that invokes the API. One or more fragments are generated based on the one or more API calls pairs. Each of the one or more fragments represents an execution sequence that includes at least one of the one or more API call pairs. The one or more fragments are verified. Prior art of record Malton or others individually or in combination fail to disclose or suggest amended independent claims 1, 21 and 28 reciting “analyzing system information relating to operation of an application programming interface (API) at a computer system relative to another API other than the API; based on a result of the analyzing of the system information, constructing a call function for execution of the API and the other API in a sequence or at least partially in parallel with one another and executing the call function”. claims 1-3, 6-7, 21-22, 24-29, and 31-36 are considered allowable since when reading the claims in light of the specification, as per MPEP §2111.01 or Toro Co. v. White Consolidated Industries Inc., 199 F.3d 1295, 1301, 53 USPQ2d 1065, 1069 (Fed. Cir. 1999), none of the references of record alone or in combination disclose or suggest the combination of limitations specified in the independent claims. Pertinent prior art of record not relied upon : US 8499354 B1 directed to US 8499354 B1 directed to attempted exploit of a vulnerability of an application executed by a computer is detected. The exploit attempts to call an application programming interface (API) and abuse application data through a malicious parameter of the call. The API of the application is hooked and monitored for a call made to the hooked API. A parameter of the call is analyzed to determine whether the parameter has a malicious characteristic indicating an attempt to use data within an address space of the application to execute malicious software. A remediation action is taken responsive to determining that the parameter has a malicious characteristic. 20190325143 A1 directed to methods and systems of identifying vulnerabilities of an application. An exemplary method comprises identifying at least one function in executable code of the application according to at least one rule for modification of functions, adding an interception code to the executable code of the application upon launching of the application, executing the application with the added interception code, collecting, by the interception code, data relating to function calls performed by the application during execution, analyzing the collected data based on criteria for safe execution of applications, wherein the criteria comprises a range of permissible values of arguments of intercepted function calls and identifying inconsistencies between the analyzed data and the criteria for safe execution of applications, wherein the inconsistencies indicate vulnerabilities in the application. US 10558809 B1 directed to An example method includes monitoring execution of one or more applications on a runtime computing system that includes a plurality of processing units, receiving, from the runtime computing system during execution of the applications, monitoring information that includes at least one of function call data or application programming interface call data associated with operations performed by the plurality of processing units during execution of the applications, importing the monitoring information into a risk model, analyzing the monitoring information within the risk model to determine one or more potential vulnerabilities and one or more impacts of the one or more vulnerabilities in the runtime computing system, and outputting, for display in a graphical user interface, a graphical representation of the one or more potential vulnerabilities and the one or more impacts within the risk model. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Taghi T Arani whose telephone number is (571)272- 3787. The examiner can normally be reached Mon-Fri 8:am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http:/Avwww.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Amy Johnson can be reached at (571) 272-2238. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https:/Awww.uspto.gov/patents/apply/patent- center for more information about Patent Center and https:/Awww.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TAGHI T ARANI/Supervisory Patent Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Show 7 earlier events
Mar 06, 2026
Interview Requested
Mar 10, 2026
Interview Requested
Mar 12, 2026
Examiner Interview (Telephonic)
Mar 12, 2026
Examiner Interview Summary
Apr 01, 2026
Response after Non-Final Action
May 12, 2026
Request for Continued Examination
May 22, 2026
Response after Non-Final Action
Jul 31, 2026
Non-Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12682246
Neurosynaptic Processing Core with Spike Time Dependent Plasticity (STDP) Learning For a Spiking Neural Network
3y 4m to grant Granted Jul 14, 2026
Patent 12670361
MACHINE LEARNING BASED TECHNIQUES FOR PREDICTING COMPONENT CORROSION LIKELIHOOD
3y 11m to grant Granted Jun 30, 2026
Patent 12627712
IDENTITY-AWARE SECURE NETWORK
3y 2m to grant Granted May 12, 2026
Patent 12585943
TRANSFER LEARNING FOR SENIORITY MODELING LABEL SHORTAGE
3y 5m to grant Granted Mar 24, 2026
Patent 12579260
EMAIL SECURITY SYSTEM AND OPERATION METHOD THEREOF FOR BLOCKING AND RESPONDING TO TARGETED EMAIL ATTACKS, WHICH PERFORM INSPECTION OF UNAUTHORIZED EMAIL SERVER ACCESS ATTACK
2y 3m to grant Granted Mar 17, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
48%
Grant Probability
99%
With Interview (+68.6%)
3y 3m (~1m remaining)
Median Time to Grant
High
PTA Risk
Based on 27 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month