Prosecution Insights
Last updated: October 02, 2026
Application No. 18/368,873

DETECTING DATA EXFILTRATION VIA API CALLS USING LANGUAGE MODEL EMBEDDINGS

Final Rejection §103§112
Filed
Sep 15, 2023
Examiner
DHARIA, RUPAL
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
68%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
19 granted / 25 resolved
+18.0% vs TC avg
Minimal -8% lift
Without
With
+-8.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
8 currently pending
Career history
41
Total Applications
across all art units

Statute-Specific Performance

§101
9.9%
-30.1% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
15.9%
-24.1% vs TC avg
§112
14.6%
-25.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 25 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is in response to the amendment and arguments filed 9/17/2025. Claims 1-20 are pending. Claims 1 (a method), 11 (a machine), and 20 (a non-transitory CRM) are independent. Response to Arguments Applicant’s arguments, see pages 9 and 10, filed 9/17/2025, with respect to the rejection(s) of claim(s) 1-8, 11-18, and 20 under 35 U.S.C. § 103 as obvious in view of Yadav and Erickson (US 2023/0319017 and US 2024/0386041) have been fully considered and are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. A new ground(s) of rejection is made in view of Yadav, US 2023/0319017, in view of Weber et al., US 2022/0116420, and Kermabon-Bobinnec et al. “Proactive Security Policy Enforcement for Containers.” Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2 and 12 contain an antecedent basis issue in the limitation "a service mesh". However, claims 1 and 11 already require “a service mesh” making the additional “a service mesh” of claims 2 and 12 ambiguous. Claims 3 and 13 contain an antecedent basis issue in the limitation "a sidecar proxy". However, claims 1 and 11 already require “a device as a sidecar proxy” making the additional “a sidecar proxy” of claims 3 and 13 ambiguous. The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph: Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. Claims 2 and 12 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claims 1 and 11 appear to already require that “the device is located in a service mesh”. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-6, 8, 9, 11-16, and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Yadav, US 2023/0319017, in view of Weber et al., US 2022/0116420, and Kermabon-Bobinnec et al. “Proactive Security Policy Enforcement for Containers.” Regarding claim 1, 11, and 20, Yadav discloses a method and apparatus comprising: (regarding the memory/processor of claim 11 and the CRM of claim 20, see Yadav Fig. 5 and associated disclosure). intercepting, by a device more documents deemed sensitive; and (“another way to identify sensitive information is to call other third party tools that inspect document content to determine if it contains sensitive information.” Yadav ¶ 39) blocking, by the device and Yadav does not explicitly disclose: as a sidecar proxy in a service mesh converting, by the device, the return data into an embedding by inputting the return data into an artificial intelligence-based language model trained to convert text into embeddings; determining, by the device, a similarity between the embedding and one or more embeddings in a database that were generated from one or based on the similarity exceeding a threshold Weber discloses: converting, by the device, the return data into an embedding by inputting the return data (“feature data extraction and preprocessing S210, generate word embeddings and/or sentence embeddings for communication corpus S220, compute similarity score for target email S230, and [return email with highest score] identify whether remediate cybersecurity threat S240.” Weber ¶ 53. “a sentence embeddings model that may function to map each distinct string of text to vectors of real numbers or the like in n-dimensional space.” Weber ¶ 69) into an artificial intelligence-based language model trained to convert text into embeddings; (“each machine learning model may be trained with one or more corpora of labeled training data comprising a plurality of distinct training samples of malicious (adverse) or non-malicious (non-adverse) electronic communications.” Weber ¶ 96) determining, by the device, a similarity (“the phishing threat score indicates a likelihood that a target electronic communication comprises an adverse electronic communication or a malicious electronic communication.” Weber ¶ 15. See also Weber ¶ 9) between the embedding and one or more embeddings in a database that were generated from one or (“the similarity module may include and/or have access to a database storing one or more corpora of historical electronic communication data (e.g., historical malicious communications, non-malicious communications (e.g., marketing emails, etc.), and/or the like).” Weber ¶ 52. “a vector and a search performed of a vectorized database of the historical sender data.” Weber ¶ 102) based on the similarity exceeding a threshold (“identify one or more cognate or similar malicious communications based on identifying the one or more historical electronic communications producing similarity metric values satisfying or exceeding a phishing threat threshold or a similarity threshold. Preferably, the phishing threat threshold or the similarity threshold relates to a minimum similarity metric value or score that may indicate a high or statistically significant degree of similarity between two compared pieces of content or compared embeddings.” Weber ¶ 85. See also ¶ 103) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Yadav with Weber by utilizing a machine learning algorithm (Weber) in the firewall/proxy of Yadav. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Yadav with Weber in order to improve threat detection and scaling to respond to large volumes of threats using the machine learning of Weber, see Weber ¶ 5. Yadav in view of Weber does not disclose: a sidecar proxy in a service mesh Kermabon-Bobinnec discloses the use of a policy compliance tool (§ 2.2, page 8) in the form of a sidecar (“we modify the OPA/Gatekeeper container image and deploy a sidecar container running a Kubernetes API proxy,” Kermabon-Bobinnec p. 38 and § 5.2.5. “ProSPEC leverages the Kubernetes admission controller mechanism to intercept the requests sent to the Kube- API server.” Kermabon-Bobinnec p. 31) within a mesh (see Kermabon-Bobinnec §§ 1.1, 2.2 and figure 1 discussing a Kubernetes mesh architecture. Note Applicant’s specification pages 11-12 noting the relevance of Kubernetes). Where policy decisions are based on a threshold (“it first identifies the highly probable (which have a prediction probability higher than a chosen threshold) future critical events from the current event using the predictive model (line 8 and line 9).” Kermabon-Bobinnec § 4.1.2. see also § 4.2.1 discussing thresholding and machine learning.) and the policy decisions include allow or deny (Kermabon-Bobinnec page 27, lines 1-2) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Yadav in view of Weber with Kermabon-Bobinnec by implementing the policy enforcement disclosed by Yadav in view of Weber in a sidecar mesh using policy enforcement thresholds. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Yadav in view of Weber with Kermabon-Bobinnec in order to establish microservices with increased scalability, reliability and observability using container orchestrators, Kermabon-Bobinnec § 1.1. Regarding claims 2 and 12, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 and further discloses: wherein the device is located in a service mesh (see Yadav; paragraph [0051]). Regarding claims 3 and 13 Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 and further discloses: wherein the return data is intercepted by a sidecar proxy (“we modify the OPA/Gatekeeper container image and deploy a sidecar container running a Kubernetes API proxy,” Kermabon-Bobinnec p. 38 and § 5.2.5) associated with a service or microservice (Kubernetes) that receives the application programming interface call (“ProSPEC leverages the Kubernetes admission controller mechanism to intercept the requests sent to the Kube- API server.” Kermabon-Bobinnec p. 31) Regarding claims 4 and 14, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 3 and 13 and further discloses: wherein blocking the return data from being sent via the network to the requester comprises: sending a notification to the sidecar proxy indicative to block the return data from being sent (“to call other third party tools that inspect document content to determine if it contains sensitive information.” Yadav ¶ 39. See also Yadav; paragraphs [0035] and [0064]). Regarding claims 5 and 15, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 and further discloses: inputting the return data into an artificial intelligence-based language model trained to convert text into embeddings (“feature data extraction and preprocessing S210, generate word embeddings and/or sentence embeddings for communication corpus S220, compute similarity score for target email S230, and [return email with highest score] identify whether remediate cybersecurity threat S240.” Weber ¶ 53) Regarding claims 6 and 16, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 5 and 15 and further discloses: generating, by the device and using the artificial intelligence-based language model, the one or more embeddings from the one or more documents deemed sensitive; (“each machine learning model may be trained with one or more corpora of labeled training data comprising a plurality of distinct training samples of malicious (adverse) or non-malicious (non-adverse) electronic communications.” Weber ¶ 96) and storing the one or more embeddings in the database (“the similarity module may include and/or have access to a database storing one or more corpora of historical electronic communication data (e.g., historical malicious communications, non-malicious communications (e.g., marketing emails, etc.), and/or the like).” Weber ¶ 52. “a vector and a search performed of a vectorized database of the historical sender data.” Weber ¶ 102) Regarding claims 8 and 18, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claim 1 and 11 and further discloses: wherein the database is a vector database (“a vector and a search performed of a vectorized database of the historical sender data.” Weber ¶ 102) Regarding claims 9 and 19, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 and further discloses: Wherein the one or more documents include personally identifiable information. (“Content Inspection tools can be configured with their own rules to look for certain keywords or patterns like credit card information or social security number inside the document content.” Yadav ¶ 39) Claims 7, 10 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Yadav, US 2023/0319017, in view of Weber et al., US 2022/0116420, and Kermabon-Bobinnec et al. “Proactive Security Policy Enforcement for Containers.” And Feuz et al., US 2020/0293687. Regarding claims 7 and 17, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 but does not disclose: wherein the one or more documents were flagged as sensitive via a user interface. Feuz discloses: wherein the one or more documents were flagged as sensitive via a user interface. (“subject users' responses to such requests may be used to determine whether future requests should be fulfilled or denied. For example, in some implementations, various aspects of the answer, the data sources used, attributes of Dave, attributes of a relationship between Dave and Alice, etc., may be used to generate a feature vector that is then labeled as a positive or negative training example (depending on whether Alice permitted or denied the request) and used to train a machine learning model. Alternatively, if Alice denies permission, that may be used as a negative training example (i.e., deny access). In either case, the machine learning model (e.g., neural network, support vector machine, etc.) may be trained to generate output that indicates whether or not a requesting user should be provided with information responsive to their request. ” Feuz ¶ 10. Note that “users’ responses” is interpreted to indicate an interface for providing said responses.) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Yadav in view of Weber and Kermabon-Bobinnec with Feuz by obtaining user input via an interface to select the training examples of historical malicious communications (Weber ¶ 52). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Yadav in view of Weber and Kermabon-Bobinnec with Feuz in order to update the model with new training data input by users to adapt to changing corpus of sensitive information. Regarding claim 10, Yadav in view of Weber and Kermabon-Bobinnec discloses the limitations of claims 1 and 11 and further: Wherein the similarity comprises a Euclidean distance or cosine similarity. (“identifying whether the suspicious electronic communication comprises one of the adverse electronic communication and the non-adverse electronic communication includes: identifying one or more historical electronic communication vectors having a calculated cosine distance that is less than or equal to a distance threshold, wherein the distance threshold comprises a maximum cosine distance value for indicating a relatedness” Weber ¶ 9) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Yadav in view of Weber and Kermabon-Bobinnec with Feuz by obtaining user input via an interface to select the training examples of historical malicious communications (Weber ¶ 52). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Yadav in view of Weber and Kermabon-Bobinnec with Feuz in order to update the model with new training data input by users to adapt to changing corpus of sensitive information. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892, particularly: Bruce et al., US 2024/0386130, disclosing data plane management systems and methods. Srinivasan et al., US 2024/0073290, disclosing sensitive data classification. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RUPAL DHARIA whose telephone number is (571)272-3880. The examiner can normally be reached Monday-Friday, 6am-3pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Sep 15, 2023
Application Filed
Jun 17, 2025
Non-Final Rejection mailed — §103, §112
Aug 23, 2025
Interview Requested
Sep 11, 2025
Applicant Interview (Telephonic)
Sep 11, 2025
Examiner Interview Summary
Sep 17, 2025
Response Filed
Sep 03, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744768
SYSTEMS AND METHODS FOR CONNECTING USERS IN AN EXTENDED REALITY SETTING
4y 1m to grant Granted Sep 22, 2026
Patent 12743534
VERSION CONTROL SYSTEM USING CONTENT-BASED DATASETS AND DATASET SNAPSHOTS
3y 11m to grant Granted Sep 22, 2026
Patent 12724868
METHOD AND SYSTEM FOR STARTING UP OR MANAGING AN OFFLINE CONTROL DEVICE
3y 8m to grant Granted Sep 01, 2026
Patent 9338111
Electronic Message Recipient Handling System and Method with Media Component and Header Information Separation
1y 4m to grant Granted May 10, 2016
Patent 9313155
Electronic Message Send Device Handling System and Method with Separation of Message Content and Header Information
1y 3m to grant Granted Apr 12, 2016
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
68%
With Interview (-8.5%)
2y 5m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 25 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month