Prosecution Insights
Last updated: October 02, 2026
Application No. 18/383,076

Email Security and Prevention of Phishing Attacks Using a Large Language Model (LLM) Engine

Final Rejection §101
Filed
Oct 24, 2023
Examiner
NANO, SARGON N
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
Varonis Systems Inc.
OA Round
4 (Final)
81%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
79%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
559 granted / 692 resolved
+22.8% vs TC avg
Minimal -1% lift
Without
With
+-1.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
27 currently pending
Career history
729
Total Applications
across all art units

Statute-Specific Performance

§101
27.4%
-12.6% vs TC avg
§103
32.2%
-7.8% vs TC avg
§102
20.3%
-19.7% vs TC avg
§112
10.5%
-29.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 692 resolved cases

Office Action

§101
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This office action is responsive to amendment submitted on 7/16/2026. Claims 1,2, 7, 8, 11, 15, 16, 17, 18, 19, and 20 are amended. Claims 21-23 are newly added. Consequently, claims 1, 2, 7, 8, 9, 10, 11, 12, 15, 16, 17, 18, 19, 20, 21, 22 and 23 are pending examination. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 2, 7, 8, 9, 10, 11, 12, 15, 16, 17, 18, 19, 20, 21, 22 and 23 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim 1 is drawn to method (i.e., a process), claim 20 is drawn to a system (i.e., a machine/manufacture), and claim(s) 19 is drawn to non-transitory computer readable medium (i.e., a machine/manufacture). As such, claims 1, 19, and 20 are drawn to one of the statutory categories of invention. Step 2A, prong One, claim 1 recites an abstract idea in the form of certain methods of organizing human activity and mental processes. Specifically, the claim recites collecting information (organizational data, message content, metadata, embeddings, and probing questions), analyzing and evaluating that information to determine whether a digital message is malicious, generating a confidence score, and selecting an appropriate fraud mitigation action. These limitations describe observation, evaluation, judgment, and decision making that can be practically performed int eh human mind or with pen and paper and further relate to managing cybersecurity and fraud prevention activities. Step 2A prong Two, the claim does not integrate the abstract idea into a practical application. Although the claim recites constructing an Organizational Context Index, generating LLM based embeddings, tokenizing the digital message, generating a query envelope, processing the query envelope using LLM engine, applying a machine learning model, and performing fraud mitigation operations, these additional limitations merely describe how the abstract analysis is carried out using computer technology. The claim does not recite improvement tot eh operation of the computer, the LLM engine, the machine learning model, embedding generation, tokenization, or another technological component. Rather, these components are used as tools to improve the accuracy of determining whether a digital message is malicious. Step 2B, the claims do not recite an inventive concept sufficient to transform the abstract idea into patent eligible subject matter. The additional elements are recited at a high level of generality and perform their expected functions. When considered individually and as an ordered combination, these elements simply implement the abstract idea using known computer components and AI techniques and do not amount to significantly more than the judicial exception itself. Accordingly, the claims are directed to an abstract idea and do not recite additional elements that integrate the abstract idea into a practical application or provide an inventive concept. Therefore, the clams are not directed to patent eligible subject matter under 35 U.S.C 101. Response to Argument Applicant's arguments filed regarding 35 USC § 101 have been fully considered but they are not persuasive. The applicant argues that the amended claim 1 is not merely directed to determining whether a digital message is malicious because the claim now recites generating organizational context embeddings, converting the message into indexed embeddings, constructing a query envelope, processing the query envelope using LLM engine, applying an ML model to generate a weighted confidence score, and performing fraud mitigation operations. The examiner has fully considered the amendment but is not persuaded. Even though the amended claim now includes additional details describing how the message is analyzed. The claim is still directed to evaluating information to determine whether a digital message is malicious and selecting an appropriate response. The added limitations describe additional processing performed as part of that analysis but do not change the focus of the claim. The applicant further argues that the LLM engine is not used as a “black box” because it constructs organizational context embeddings, processes a query envelope, and generates responses to probing questions. The examiner agrees that the claim now recites additional functions performed by the LLM engine. However, the claim does not recite any improvement to how the LLM engine itself operates. The LLM performs its ordinary functions of generating embeddings, processing prompts, and producing responses. The claim uses the LLM as a tool within the overall phishing detection process rather than improving the LLM technology. The applicant also argues, that the claimed invention uses multiple AI components operating in multiple processing stages. The examiner agrees that the claim recites multiple stages involving LLM engine and an ML model. However, arranging multiple analytical stages does not remove the clam form abstract idea. Each stage adds tot eh same overall process or analyzing information to determine whether a digital message is malicious. The additional stages make the analysis more detailed but do not improve the operation of the computer or the AI components themselves. The applicant further argues that the claimed invention provides a practical application by improving computer system security. The examiner agrees that the claimed process may improve the accuracy of phishing detection and may help reduce malicious messages received by a user. However, improving the accuracy of security decision is different from improving computer technology itself. The claim does not improve how computers store data, retrieve data, process embeddings, operate an LLM, perform machine learning, or otherwise improve the functioning of the computer. Instead, the claimed technology uses known computing components to make a better determination regarding whether a message is malicious. The applicant further argues, that the claimed multi-layer architecture improves system functionality. The claimed architecture consists of known components performing their expected functions. The LLM generates embeddings and responses, the ML model calculates a confidence score, and the fraud mitigation components perform an action based on the score. The claim does not recite a new architecture for LLM, a new embedding technique, a new tokenization methos, or a new machine learning algorithm. rather, these components are used together as part of the information analysis workflow. Accordingly, the examiner maintains that the claims are directed to collecting information, organizing information, analyzing information and making a determination based on that information. The additional limitations describing tokenization, embeddings, organizational context, query envelopes, probing questions, confidence scores, and fraud mitigation describe how the abstract analysis is carried out but do not integrate the abstract idea into a practical application that improves computer technology itself. Therefore, the amendment does not overcome the rejection under 35 U.S.C 101. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SARGON N NANO whose telephone number is (571)272-4007. The examiner can normally be reached 7:30 AM-3:30 PM. M.S.T.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached at 571 272 3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SARGON N NANO/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Show 3 earlier events
Aug 28, 2025
Final Rejection mailed — §101
Nov 24, 2025
Request for Continued Examination
Dec 01, 2025
Response after Non-Final Action
Jan 28, 2026
Non-Final Rejection mailed — §101
Mar 11, 2026
Examiner Interview Summary
Mar 11, 2026
Applicant Interview (Telephonic)
Jul 16, 2026
Response Filed
Aug 10, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12717892
Attestation Engine(s) for Authenticating Software Deployment
2y 4m to grant Granted Aug 25, 2026
Patent 12711256
APPARATUS AND METHODS FOR MODIFYING A UNION FILE SYSTEM USING SUPERCOPY CONTROL
2y 7m to grant Granted Aug 18, 2026
Patent 12712819
COMMUNICATION METHOD AND APPARATUS
1y 6m to grant Granted Aug 18, 2026
Patent 12689603
Configuring a Monitor Mode for Suspicious Content in Emails
2y 6m to grant Granted Jul 21, 2026
Patent 12683986
Systems and methods for processing electronic communications
2y 10m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
81%
Grant Probability
79%
With Interview (-1.4%)
2y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 692 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month