Prosecution Insights
Last updated: August 17, 2026
Application No. 18/328,213

Domain Name System Threat Hunting Using Domain Name Tokenization

Non-Final OA §101§103
Filed
Jun 02, 2023
Examiner
SCHMIDT, KARI L
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
557 granted / 752 resolved
+14.1% vs TC avg
Strong +42% interview lift
Without
With
+42.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
14 currently pending
Career history
774
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
50.9%
+10.9% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 752 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to application 18/328,213 filed on 6/2/2023. Claims 1-20 have been examined and are pending in this application. The examiner notes the IDS filed on 6/2/2023 has been considered. Claim Interpretation The examiner notes the following claim interpretation: Regarding Claim(s) 10: “processor units” is noted to be statutory based on the definition found in Applicant’s Specification ⁋[0046] – “As used herein, a processor unit in the number of processor units 216 is a hardware device and is comprised of hardware circuits such as those on an integrated circuit that respond to and process instructions and program code that operate a computer. A processor unit can be implemented using processor set 110 in Figure 1. When the number of processor units 216 executes program instructions 218 for a process, the number of processor units 216 can be one or more processor units that are in the same computer or in different computers. In other words, the process can be distributed between processor units 216 on the same or different computers in computer system 212.” Therefore, the examiner construes that “A computer system comprising: a number of processor units” is statutory under 35 U.S.C. 101. Regarding Claim(s) 19; “a computer readable storage medium” is noted to be statutory based on the definition found in Applicant’s Specification ⁋[0018] – “Without limitation, the computer readable storage medium may be an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these mediums include: diskette, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded device (such as punch cards or pits / lands formed in a major surface of a disc) or any suitable combination of the foregoing. A computer readable storage medium, as that term is used in the present disclosure, is not to be construed as storage in the form of transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, light pulses passing through a fiber optic cable, electrical signals communicated through a wire, and/or other transmission media.” Therefore, the examiner construes that “a computer readable storage medium” is statutory under 35 U.S.C. 101. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1-20 is/are rejected under 35 USC 101 as being directed to an abstract idea without being integrated into a practical application or being significantly more. Regarding Claim 1, and similar Claim(s) 10 and 19, the claim recites the limitations “identifying, ... the domain name for analysis; splitting ... the domain name into tokens; combining ... the tokens into different arrangements to form permutated domain names; identifying ... features for the permutated domain names using a set of domain name databases; and analyzing ... the permutated domain names with the features to determine a maliciousness of the domain name.” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s is noted that the claims recite additional limitation/elements (i.e., by a number of processor units, program instructions, program product comprising... medium). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional elements/limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter. Regarding Claim(s) 2-9, 11-18 and 20, claim(s) 2-9, 11-18 and 20 is/are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims recite an abstract idea and the claims do not positively recite any other operations that could be considered as the abstract idea is being integrated into a practical application or significantly more. It’s noted that claim(s) 2, 11, and 20 recite the limitations: “performing... a set of actions......”. It’s noted that claim(s) 3 and 12 recites the limitations: “analyzing... the permutated domain names with features identified...”. It’s noted that claims claim(s) 4 and 13 recites the limitations: “wherein... feature is identified using... rules...”. It’s noted that claim(s) 5 and 14 recites the limitations: “wherein permutation of tokens to form the permutated domain names is performed using tokens excluding a top level domain in the domain name”. It’s noted that claim(s) 6 and 15 recites the limitations: “wherein permutation of tokens to form the permutated domain names is performed using tokens from a root domain of the domain name”. It’s noted that claim(s) 7 and 16 recites the limitations: “wherein the set of actions is selected from...”. It’s noted that claim(s) 8 and 17 recites the limitations: “wherein the set of domain name databases is selected from...” It’s noted that claim(s) 9 and 18 recites the limitations: “wherein the features for a permutated domain name in the permutated domain names are selected from...” Said steps are either directed to mental processes and further may include additional elements that are insignificant extra-solution activities and/or recited at a high-level of generality, The aforementioned steps are not sufficient to consider that the abstract idea is being integrated into a practical application or significantly more. Therefore, claims 2-18 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Raemy et al. (US 2013/0091143 A1) in view of McCloy et al. (US 2008/0034073 A1). Regarding Claim 1; Raemy teaches a computer implemented method for analyzing a domain name (Abstract), the computer implemented method comprising: identifying, by a number of processor units, the domain name for analysis ([0062] - In step 420, the bigram suggestion server 110 may tokenize the input domain name request. The tokenizing of the domain name request may be similar to the tokenizing of domain names described above with respect to step 220 of FIG. 2. For example, the requested domain name "soccersportsteam.com" may be tokenized into the tokens "soccer", "sports" and "team"); splitting, by the number of processor units, the domain name into tokens ([0062] - In step 420, the bigram suggestion server 110 may tokenize the input domain name request. The tokenizing of the domain name request may be similar to the tokenizing of domain names described above with respect to step 220 of FIG. 2. For example, the requested domain name "soccersportsteam.com" may be tokenized into the tokens "soccer", "sports" and "team"); combining, by the number of processor units, the tokens into different arrangements to form permutated domain names ([0048]-[0049] - The top level domain (.com, .net, etc) may be excluded when tokenizing the domain name. The tokens may be limited to character strings that form words or other useful identifiers. For example, a domain name "soccersportsteam.com", may be tokenized in one instance as "soccer-sports-team". Each of the strings "soccer," "sports," and "team" are tokens. It should be noted that a domain name may be tokenized in more than one way. For example, the string "sportsteam" could be tokenized into both "sports-team" and "sport-steam." The tokenized domain names may be stored for future processing, for example, on the bigram suggestion server 110 or other storage devices. Other known methods of tokenizing may be used by the bigram suggestion server 110 to tokenize the domain names and [0062]-[0064]); identifying, by the number of processor units, features for the permutated domain names using a set of domain name databases ([0051]-[0053] – in step 240, the bigram suggestion server 110 may then filter the bigrams in the bigram database 140. The bigrams in the bigram database 140 may be filtered according to any criteria relating to the bigrams and [0062]-[0064]); and analyzing, by the number of processor units, the permutated domain names with the features to determine [suggestions for domain names] ([0062]-[0064]). Raemy fails to explicitly disclose analyzing, by the number of processor units, the permutated domain names with the features to determine a maliciousness of the domain name. However, in an analogous art, McCloy teaches analyzing, by the number of processor units, the permutated domain names with the features to determine a maliciousness of the domain name (FIG. 5 and [0045]-[0047] - At 515, comparison module 160 compares the hash values of the segments from the target URL 225 with the hash values stored in database 135. Comparison module 160, at 520, computes a score indicating the extent to which the hash values of the segments from the target URL 225 match one or more hash values stored in database 135. At 525, if the score computed at 520 satisfies a predetermined criterion, security module 165 takes corrective action at 530, as explained above. At 535, the process terminates). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of McCloy to the analyzing a domain name of Raemy to additionally, include, analyzing, by the number of processor units, the permutated domain names with the features to determine a maliciousness of the domain name. One would have been motivated to combine the teachings of McCloy to Raemy to do so as it provides / allows for identifying network addresses associated with suspect network destinations (McCloy, [0002]). Regarding Claim 2; Raemy in view of McCloy teaches the computer implemented method of claim 1. McCloy further discloses further comprising: performing, by the number of processor units, a set of actions for the domain name identified based on the maliciousness of the domain name (FIG. 5A and [0024] - If the computed score satisfies a predetermined criterion such as the exceeding of a threshold, appropriate corrective action can be taken. In some embodiments, taking corrective action includes alerting a user that the target URL is believed to be associated with a suspect network destination. In other embodiments, taking corrective action includes blocking a network connection between a computer and the network destination associated with the target URL and [0045]-[0047]). Similar rationale and motivation is noted for the combination of McCloy to Raemy in view of McCloy, as per Claim 1, above. Regarding Claim 3; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein analyzing, by the number of processor units, the permutated domain names with the features to determine [suggestions for domain names] comprises: analyzing, by the number of processor units, the permutated domain names with the features identified for the [suggestions for domain names] ([0051]-[0053] – In step 240, the bigram suggestion server 110 may then filter the bigrams in the bigram database 140. The bigrams in the bigram database 140 may be filtered according to any criteria relating to the bigrams and [0062]-[0064]); McCloy further discloses, wherein analyzing, by the number of processor units, the permutated domain names with the features to determine the maliciousness of the domain name comprises: analyzing, by the number of processor units, the permutated domain names with the features identified for the permutated domain names to identify a threat level for the domain name (FIG. 5A and [0047]] – At 525, if the score computed at 520 satisfies a predetermined criterion, security module 165 takes corrective action at 530, as explained above. At 535, the process terminates). Regarding Claim 4; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein, wherein analyzing, by the number of processor units, the permutated domain names with the features identified is performed using at least one of a rule-based engine or a machine learning model ([0014]-[0016] and [0051]-[0053] – in step 240, the bigram suggestion server 110 may then filter the bigrams in the bigram database 140. The bigrams in the bigram database 140 may be filtered according to any criteria relating to the bigrams). Regarding Claim 5; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein permutation of tokens to form the permutated domain names is performed using tokens excluding a top level domain in the domain name ([0048] - Tokenizing the domain names may include dividing the domain names into sets of strings of characters, or tokens. The top level domain (.com, .net, etc) may be excluded when tokenizing the domain name). Regarding Claim 6; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein permutation of tokens to form the permutated domain names is performed using tokens from a root domain of the domain name ([0048] - For example, a domain name "soccersportsteam.com", may be tokenized in one instance as "soccer-sports-team". Each of the strings "soccer," "sports," and "team" are tokens. It should be noted that a domain name may be tokenized in more than one way. For example, the string "sportsteam" could be tokenized into both "sports-team" and "sport-steam." The tokenized domain names may be stored for future processing, for example, on the bigram suggestion server 110 or other storage devices. Other known methods of tokenizing may be used by the bigram suggestion server 110 to tokenize the domain names). Regarding Claim 7; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein the set of actions is selected from at least one of updating a threat intelligence database, blocking a lookup of the domain name in a domain name system service, or generating an alert (FIG. 5A and [0024] - If the computed score satisfies a predetermined criterion such as the exceeding of a threshold, appropriate corrective action can be taken. In some embodiments, taking corrective action includes alerting a user that the target URL is believed to be associated with a suspect network destination. In other embodiments, taking corrective action includes blocking a network connection between a computer and the network destination associated with the target URL and [0045]-[0047]). Similar rationale and motivation is noted for the combination of McCloy to Raemy in view of McCloy, as per Claim 1, above. Regarding Claim 8; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses wherein the set of domain name databases is selected from at least one of a domain registration database, a domain name system database, a domain lookup database, a threat intelligence database, a threat intelligence domain database, or a threat intelligence index ([0037] - Although FIG. 1 illustrates the bigram suggestion server 110, the bigram database 140, and the domain name database 150 as separate components, the suggestion server 110 may alternatively be integrated with the bigram database 140 and/or the domain names database 150. Additionally, the bigram database 140 and the domain names database 150 may be integrated into a single database or stored in a same memory device). Regarding Claim 9; Raemy in view of McCloy teaches the computer implemented method of claim 1. Raemy further discloses, wherein the features for a permutated domain name in the permutated domain names are selected from at least one of an Internet Protocol address, a registrar name, a registrant name, registrant information, an administrative contact, a technical contact, a name server, domain status, a creation date for a registered domain name, an expiration date for the registered domain name, a threat actor, a threat level, or a maliciousness level ([0043]-[0044] - The user terminal 120 may send data to the bigram suggestion server 110 representing a domain name that a user desires to register). Regarding Claim(s) 10-18; claim(s) 10-18 is/are directed to a/an system associated with the method claimed in claim(s) 1-9. Claim(s) 10-18 is/are similar in scope to claim(s) 1-9, and is/are therefore rejected under similar rationale. Regarding Claim(s) 19-20; claim(s) 19-20 is/are directed to a/an program product associated with the method claimed in claim(s) 1-2. Claim(s) 19-20 is/are similar in scope to claim(s) 1-2, and is/are therefore rejected under similar rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KARI L SCHMIDT/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Jun 02, 2023
Application Filed
Nov 29, 2023
Response after Non-Final Action
Jul 15, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705372
CONTROLLING AN INTERACTION USING ONLINE ACCOUNT OPENING INDICATORS
3y 1m to grant Granted Aug 11, 2026
Patent 12695782
UPDATING REMOTE SCAN ENGINES WITH CUSTOM VULNERABILITY CHECKS
1y 7m to grant Granted Jul 28, 2026
Patent 12689917
Determining a Subset of Base Stations in a Wireless Network
2y 3m to grant Granted Jul 21, 2026
Patent 12682026
MULTIDIMENSIONAL LOCAL LARGE LANGUAGE MODEL USER AUTHENTICATION
2y 5m to grant Granted Jul 14, 2026
Patent 12666259
Authentication of a Communications Device
5y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+42.4%)
3y 9m (~6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 752 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month