Prosecution Insights
Last updated: August 18, 2026
Application No. 18/342,588

RISK ANALYSIS BASED NETWORK AND SYSTEM MANAGEMENT

Non-Final OA §103§112
Filed
Jun 27, 2023
Examiner
JAKOVAC, RYAN J
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
5 (Non-Final)
66%
Grant Probability
Favorable
5-6
OA Rounds
9m
Est. Remaining
83%
With Interview

Examiner Intelligence

Grants 66% — above average
66%
Career Allowance Rate
406 granted / 617 resolved
+7.8% vs TC avg
Strong +17% interview lift
Without
With
+17.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 10m
Avg Prosecution
27 currently pending
Career history
656
Total Applications
across all art units

Statute-Specific Performance

§101
8.1%
-31.9% vs TC avg
§103
51.7%
+11.7% vs TC avg
§102
18.8%
-21.2% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 617 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed 6/10/2026 has been entered. Allowable Subject Matter Claim 21 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Response to Arguments Applicant’s arguments filed 6/10/2026have been fully considered. Whether the prior art to Sun teaches “data-plane” traffic Applicant argues that Sun fails to teach a network through which data-plane traffic flows. Data plane traffic refers to the delivery of packets through a network device, generally referring to the ability of two hosts to communicate over a network. Sun discloses an IT management system that performs risk assessment in real time utilizing operational data of the system. The operational data is e.g. user requests, incident tickets, resource usage, etc (Sun, ¶ 32-34, 65). User requests, etc. in an IT system are examples of data-plane traffic. Claim Interpretation, claim scope, and the application of Prior Art Regarding claim 1, applicant' s recitation of “receiving, at a controller that manages a network through which data-plane traffic flows, anomaly data associated with a network device in the network” would have been unclear to one of ordinary skill in the art. It is unclear whether the method comprises a receiving step and a management step related to data-plane traffic, or alternatively, a receiving step. Applicant’s claim positively recites a step of a controller receiving anomaly data. Couched within the receiving step is language describing the controller as a device which manages a network through which data-plane traffic flows. The remainder of the claim is absent a further recitation of “data-plane traffic”. The claim is obfuscated such that one of ordinary skill in the art would not know from the claim terms whether the language describes a receiving anomaly data, or alternatively, whether the claims describe receiving anomaly data and the additional performance of a management function related to the data-plane traffic. There is no positively recited management step. There is a positively recited receiving step. For purposes of claim interpretation regarding claim scope and the application of prior art, the language describing the controller as a device that manages a network through which data-plane traffic flows will be regarded as merely descriptive language of the controller and not as language requiring an additional management step. The remaining independent claims are addressed by similar rationale. For example, claim 15 describes recites “receiving, at a control device that manages a network, anomaly data associated with the network device in the network”. Whether the prior art to Sun teaches routing data traffic through a network Regarding claim 1, Applicant’s argument that Sun fails to teach the routing of data traffic through a network is not persuasive in light of Sun disclosing an IT Management network where users submit requests, incident tickets, etc. (Sun, ¶ 32-34, 65). Regarding claim 1, Applicant argues Sun fails to teach routing data traffic through a network because Sun’s disclosure does not entail instructing a network routing device to redirect data-plane traffic away from a high-risk router. Applicant’s arguments are not persuasive because the features which applicant relies upon are not recited in the claim. Applicant’s argument that Sun fails to disclose a “transmitting, from the controller, a control signal to a second network device in the network, the control signal instructing the second network device to route data traffic flowing through the network away from the network device based on the likelihood that the network device is going to experience failure in the future” are not persuasive in light of Sun’s disclosure describing predicting the failure of network nodes and providing instruction to route network traffic away from the nodes based on failure likelihood (Sun, ¶ abstract, ¶ 16, 35, 44-50, 60-64, predicted failure of network element and rerouting based on likelihood of failure; see also ¶ 74, 77 and 92-97). Whether the prior art to Sun “teaches away” from the claimed invention Applicant’s arguments that Sun teaches away from the claimed invention are not persuasive as applicant’s arguments in this regard are not germane to a rejection under section 102 (see MPEP 2131.05). Applicant’s further arguments are moot in view of the new grounds of rejection presented herein as necessitated by applicant’s amendment. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claim(s) 1-22 are rejected under 35 U.S.C. 112, second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which applicant regards as the invention. Regarding claim 1, applicant' s recitation of “receiving, at a controller that manages a network through which data-plane traffic flows, anomaly data associated with a network device in the network” would have been unclear to one of ordinary skill in the art. It is unclear whether the method comprises a receiving step and a management step related to data-plane traffic, or alternatively, a receiving step. The remaining independent claims are addressed by similar rationale. For example, claim 15 describes recites “receiving, at a control device that manages a network, anomaly data associated with the network device in the network”. It is unclear whether the control device merely receives anomaly data, or alternatively, whether the control device also performs a management function. Dependent claims not addressed are rejected for incorporating the deficiencies of their respective parent claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-6, 8-10, 12, 14-19 are rejected under 35 U.S.C. 103 as being unpatentable over US 20210084059 to Sun in view of US 20230325280 to Harsoor. Regarding claim 1, Sun teaches a method, comprising: receiving, at a controller that manages a network through which data-plane traffic flows, anomaly data associated with a network device in the network (¶ 4, 32, 44-50, received/analyzed anomaly data); identifying anomaly characteristic information associated with the anomaly data (¶ 4,7 , 29-30, 37-50, identification of anomalous data characteristics of data); computing, at the controller, a likelihood that the network device is going to experience a failure in a future based on the anomaly data (¶ 44-50, likelihood of failure based on anomaly data and characteristic information); and prior to the network device experiencing a failure, transmitting, from the controller, a control signal to a second network device in the network, the control signal instructing the second network device to route data traffic flowing through the network away from the network device based on the likelihood that the network device is going to experience failure in the future (¶ abstract, ¶ 16, 35, 44-50, 60-64, predicted failure of network element and rerouting based on likelihood of failure; see also ¶ 74, 77 and 92-97). Sun fails to teach but Harsoor teaches: identifying a third network device in the network that has a lower likelihood of experiencing one or more failures than the likelihood of the network device; and routing, by the second network device, the data traffic through the network to the third network device rather than the network device such that the data traffic flows through a different device in the network than the network device (¶ 109, 115-118). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Harsoor. The motivation to do so is that the teachings of Harsoor would have been advantageous in terms of facilitating the proactive prediction of session failure (Harsoor, ¶ 11, 16). Regarding claim 2, 9, Sun teaches: identifying an anomaly indicated via the anomaly data, wherein the anomaly data includes at least one of an identifier, a classification, or a severity associated with the anomaly (¶ 44-48, identification of anomalous node and anomaly identification). Regarding claim 3, 10, 17, Sun teaches: wherein computing the likelihood that the network device is going to experience the failure further comprises: computing a severity level associated with an anomaly indicated via the anomaly data (¶ 50-51, severity level from temporary to catastrophic failures); identifying a number of occurrences of the anomaly (¶ 44-46, 51, anomalies 1-m); computing a risk weight based on the severity level and the number of occurrences (¶ 44-51, risk threat based on occurrences and severity of anomaly); computing an anomaly frequency of a classification associated with the anomaly (¶ 34, 38, 8-10, frequencies of anomalies over time); and computing the likelihood that the network device is going to experience the failure based on the risk weight and the anomaly frequency (¶ 44-48, likelihood of failure). Regarding claim 4, Sun teaches: wherein the network device is a first network device that is a high risk network device, and wherein the control signal is utilized to instruct the second network device to at least one of i) reroute the data traffic to a third network device that is a low risk network device, or ii) reroute high risk data traffic from among the data traffic (¶ 48-50, instructions to reroute traffic). Regarding claim 5, Sun teaches: wherein an anomaly indicated via the anomaly data comprises at least one of i) a behavior of a behavior type that is not included from among a group of approved behavior types, or ii) an operation of an operation type that is not included from among a group of approved operation types (¶ 4,7 , 29-30, 37-50). Regarding claim 6, Sun teaches: identifying an anomaly indicated via the anomaly data (¶ 44-51, 60); wherein the anomaly data includes an anomaly classification from among a group of classifications (¶ 44-51, 60), Sun fails to teach but Harsoor teaches: the group of classifications includes at least one of a software error classification, a hardware error classification, or a consistency check classification (abstract, ¶ 3, software errors). Motivation to include Harsoor is the same as presented above. Claim 8 addressed by similar rationale as claim 1. Regarding claim 12, Sun teaches: wherein the anomaly is included in a cluster from among a group of clusters, and the group of clusters include a software critical cluster, a hardware critical cluster, and a consistency critical cluster (figs. 9-10, ¶ 92-94). Regarding claim 14, Sun teaches: wherein the network device is a first network device, and transmitting the control signal further comprises: transmitting the control signal to a second network device, the control signal being utilized to instruct the second network device to at least one of i) reroute the data traffic to a third network device, or ii) reroute a portion of the data traffic (¶ 48-50). Claim 15 is addressed by similar rational as claim 1. Regarding claim 16, Sun teaches: wherein the anomaly characteristic information includes an identifier, a classification, and a severity associated with an anomaly indicated in the anomaly data (¶ 44-52, ¶ 60, identifier, severity, category of anomaly). Regarding claim 18, Sun teaches: wherein the network device is a first network device that is a high risk network device, and transmitting the control signal further comprises: transmitting the control signal to a second network device, the control signal being utilized to instruct the second network device to reroute the data traffic to a third network device that is a low risk network device (¶ 48-50, instructions to reroute traffic). Regarding claim 19, Sun teaches: wherein the network device is a first network device, and transmitting the control signal further comprises: transmitting the control signal to a second network device, the control signal being utilized to instruct the second network device to reroute high risk data traffic from among the data traffic (¶ 50), instructions to reroute). Claims 7, 11, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Sun and Harsoor in view of AU 2015202706 A1 to Lefebvre in view of US 20210360407 to Obaidi. Regarding claim 7, Sun teaches: wherein computing the estimated overall risk factor information further comprises: computing a severity level associated with a first anomaly indicated via the anomaly data (¶44-52, ¶ 60, severity levels); computing a number occurrences of the first anomaly indicated via the anomaly data (¶ 44-46, 51, anomalies 1-m); computing a first risk weight based on the severity level and the occurrences (¶ 44-51, risk threat based on occurrences and severity of anomaly). Sun fails to teach but Lefebvre teaches: computing an estimated overall risk factor of the estimated overall risk factor information based on the first risk weight and a second risk weight, the second risk weight being associated with a second anomaly of a different type than the first anomaly (¶ 66-69, score based on secondary risks such as connection association, packet throughput per time, time variance of connections, etc.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Lefebvre. The motivation to do so is that the teachings of Lefebvre would have been advantageous in terms of facilitating the control of network traffic (Lefebvre, ¶ 1-4). Lefebvre fails to teach the number of occurrences is a “percentage of occurrences”. However, Obaidi teaches discloses the number of anomalous occurrences as a percentage of occurrences (¶ 38, percentage of anomalies). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Obaidi. The motivation to do so is that the teachings of Obaidi would have been advantageous in terms of facilitating scam prevention and anomalous pattern detection (Obaidi, ¶ 9, 38). Regarding claim 11, Sun teaches: wherein computing the estimated overall risk factor further comprises: identifying a number of occurrences of anomalies in a cluster that comprises the anomaly identified by the data, based at least in part on a time interval in which the anomalies occur (¶ 44-46, occurrences of anomaly per time period; ¶ 92-94, fig. 9-10, cluster); Sun fails to teach but Obaidi teaches: identifying a total number of occurrences of anomalies during the time interval; computing a percentage of occurrences based at least in part on the number of occurrences and a total number of occurrences; and computing the estimated overall risk factor based at least on part on the percentage of occurrences (¶ 38, anomaly detection based on total / percentage of occurrences). Motivation to include Obaidi is the same as presented above. Regarding claim 13, Sun teaches: wherein computing the estimated overall risk factor further comprises: computing a severity level associated with the anomaly (¶ 51-54, severity); computing occurrences of the anomaly (¶ 44-48, occurrences of anomaly); computing a risk weight of the anomaly based on the severity level; and computing the estimated overall risk factor based at least in part on the risk weight (¶ 44-51). computing an anomaly frequency of a classification associated with the anomaly (¶ 8-9, 10, 34, 38, 41, frequencies of anomalies over time); and computing an estimated overall risk factor of the estimated overall risk factor information based on the risk weight and the anomaly frequency (¶ 2-7, 24, 48-49, 66-72, 89, 102). Sun fails to teach the number of occurrences is a “percentage of occurrences”. However, Obaidi teaches discloses the number of anomalous occurrences as a percentage of occurrences (¶ 38, percentage of anomalies). Motivation to include Obaidi is the same as presented above. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Sun and Harsoor in view of AU 2015202706 A1 to Lefebvre. Regarding claim 20, Sun fails to teach but Lefebvre teaches: wherein the network device is a first network device, the control signal is a first control signal, wherein transmitting the first control signal further comprises: transmitting, to the control device, the first control signal, the first control signal being routed by the control device to a second network device, the operations further comprising: transmitting, to the control device, a second control signal, the second control signal being routed by the control device to a third network device, the second network device and the third network device being utilized to control data traffic associated with the first network device (fig. 1, fig. 2, ¶ 57, 74, 76, routing between monitoring device and firewall and/or user device to control traffic associated with network devices). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Lefebvre. The motivation to do so is that the teachings of Lefebvre would have been advantageous in terms of facilitating the control of network traffic (Lefebvre, ¶ 1-4). Claim 22 is rejected under 35 U.S.C. 103 as being unpatentable over Sun and Harsoor in view of US 20180034736 to Anchan. Regarding claim 22, Sun fails to teach but Anchan teaches: wherein routing the data traffic to the third network device further comprises: identifying, at the controller, a priority level associated with the data traffic based on a differentiated services code point (DSCP) value of the data traffic; routing, by the second network device, data traffic having a first priority level that meets or exceeds a priority threshold through the network to the third network device rather than the network device; and routing, by the second network device, data traffic having a second priority level that is below the priority threshold through the network to the network device, wherein the first priority level is higher than the second priority level (¶ 146, routing for first and second priority levels; ¶ 171, routing/assigning DSCP values to first priority level for routing based on threshold). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Anchan. The motivation to do so is that the teachings of Anchan would have been advantageous in terms of facilitating the scheduling of traffic flows (Anchan, abstract, 171) CONCLUSION Any inquiry concerning this communication or earlier communications from the examiner should be directed to RYAN J JAKOVAC whose telephone number is (571)270-5003. The examiner can normally be reached on 8-4 PM EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar A. Louie can be reached on 572-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RYAN J JAKOVAC/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Show 8 earlier events
Sep 04, 2025
Request for Continued Examination
Sep 16, 2025
Response after Non-Final Action
Oct 07, 2025
Non-Final Rejection mailed — §103, §112
Feb 09, 2026
Response Filed
Mar 10, 2026
Final Rejection mailed — §103, §112
Jun 10, 2026
Request for Continued Examination
Jun 17, 2026
Response after Non-Final Action
Jun 24, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12704949
TECHNIQUES FOR PREVENTING CONCURRENT EXECUTION OF DECLARATIVE INFRASTRUCTURE PROVISIONERS
3y 3m to grant Granted Aug 11, 2026
Patent 12706969
CONTENT MANAGEMENT SYSTEMS PROVIDING ZERO RECOVERY TIME OBJECTIVE
2y 9m to grant Granted Aug 11, 2026
Patent 12695770
SYSTEM AND METHOD THEREOF FOR ENHANCED COLLECTION OF DATA OF THIRD-PARTY APPLICATIONS
2y 11m to grant Granted Jul 28, 2026
Patent 12684038
SYSTEMS AND METHODS FOR INTELLIGENT LOAD BALANCING OF HOSTED SESSIONS
3y 9m to grant Granted Jul 14, 2026
Patent 12684014
METHODS AND SYSTEMS FOR DETECTING DENIAL OF SERVICE ATTACKS ON A NETWORK
2y 3m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
66%
Grant Probability
83%
With Interview (+17.4%)
3y 10m (~9m remaining)
Median Time to Grant
High
PTA Risk
Based on 617 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month