Prosecution Insights
Last updated: October 02, 2026
Application No. 18/396,347

SYSTEM AND METHOD FOR DISCOVERING AND REMEDIATING ENDPOINTS HAVING SOFTWARE AND CONFIGURATION INCOMPLIANCE

Final Rejection §103
Filed
Dec 26, 2023
Examiner
HEBERT, THEODORE E
Art Unit
2199
Tech Center
2100 — Computer Architecture & Software
Assignee
Saudi Arabian Oil Company
OA Round
4 (Final)
74%
Grant Probability
Favorable
5-6
OA Rounds
3m
Est. Remaining
89%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
335 granted / 452 resolved
+19.1% vs TC avg
Moderate +14% lift
Without
With
+14.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
13 currently pending
Career history
476
Total Applications
across all art units

Statute-Specific Performance

§101
20.4%
-19.6% vs TC avg
§103
57.5%
+17.5% vs TC avg
§102
6.5%
-33.5% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 452 resolved cases

Office Action

§103
DETAILED ACTION This office action is responsive to amendment filed on July 29, 2026 in this application Al Mohsin et al., U.S. Patent Application No. 18/396,347, (Filed December 26, 2023) (“Mohsin”). Claims 1, 2, 6-8, 12, 13, and 17 - 20 were pending. Claims 1, 8, 12, 19, and 20 are amended. Claims 1, 2, 6-8, 12, 13, and 17 - 20 are pending. Applicants' arguments have been carefully and respectfully considered and found not persuasive. Accordingly, this action has been made FINAL. Response to Arguments 1. With respect to Applicant’s argument on pgs. 9 - 13 of the Applicant’s Remarks (“Remarks”) stating that prior art reference Kurian fails to the newly amended claims including with respect to matching a compliance scope to endpoint attribute(s), examiner respectfully disagrees. See infra § Claim Rejections - 35 USC §103, § Claim 1. Kurian teaches a compliance scope for each compliance rule includes where the rule must match the attributes of an endpoint for the rule to apply to the endpoint, where the attributes include the type of hardware, software, and identification of platform for the endpoint. Kurian at ¶¶ 0071 & 0074.. Therefore, the current prior art teaches matching a compliance scope to endpoint attribute. 3. With respect to Applicant’s argument on pgs. 13 - 18 of the Remarks stating that prior art reference Shelke fails to teach performing a plurality of remediations automatically, examiner respectfully disagrees. See infra § Claim Rejections - 35 USC §103, § Claim 1. As described infra, Shelke teaches three separate remediation modules of increasing aggressiveness that are at least executed automatically by the URA agent (some of which require subsequent manual intervention following execution). Id. at Id at ¶¶ 0059 – 0061, 0064, 0066, 0074 – 0076, 0078. To the extent each remediation module may result in some manual action being performed by a user at a subsequent time, the claims, as noted in the Remarks, merely claim automatically performing remediation rather than that every remediation is fully performed without any manual assistance at any stage. In addition, while under the BRI of the claims only one remediation may be performed, it is unclear whether the claimed characterization of associated remediation actions as “ordered” is an active step that is performed as part of the association process or merely describes the nature of the remediations selected for association. Clarification by amendment of a requirement for performance of two or more remediations having a prohibition on any manual user involvement, which are explicitly placed into an order as part of the claimed associating step, may overcome the Shelke reference for such subject matter, pending further review. Therefore, the current prior art teaches performing the remediations automatically. Claim Rejections 35 U.S.C. §103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1, 2, 6-8, 12, 13, and 17 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over Kurian et al., United States Patent Application Publication No. 20210374767 (Published December 2, 2021, filed June 2, 2020) (“Kurian”) in view of Shelke et al., United States Patent Application Publication No. 2022/0365771 (Published November 17, 2022, filed May 14, 2021) (“Shelke”), and Gupta et al., United States Patent Application Publication No. 2024/0248833 (Published July 25, 2024, filed January 23, 2023) (“Gupta”). Claims 1, 12, and 20 With respect to claims 1, 12, and 20, Kurian teaches the invention as claimed including a method for device incompliance remediation, the method comprising: generating an inventory of one or more endpoints comprising a first endpoint; determining a compliance state of each of the one or more endpoints based on a compliance definition and a compliance scope, wherein the compliance scope specifies whether the compliance definition applies to each endpoint of the one or more endpoints based on a respective attribute of each endpoint; determining that the first endpoint is incompliant based on its respective compliance state; {A list of endpoint compliance states for endpoints is generated, such as a queue of workload node non-compliance event data, the compliance state is compared to requirements rules to identify non-compliance such as a encryption failure like a too short or an incorrect password, then remediation actions required by the compliance state failing to satisfy the rule are performed for each entry in the non-compliance list such as running notification scripts or setting a password parameter value, the results of the remediation action including failures are recorded in a new list such as an event tracking log and remediation failures found in the new list may be retried again. Kurian at ¶¶ 0066, 0068, 0075, 0092 (receive non-compliance events from workload nodes); id. at ¶¶ 0067 & 0076 (queue of non-compliant nodes are prioritized by level according to time sensitivity and timestamps); id. at ¶¶ 0067, 0080, 0081 (remediation action is performed); id. at ¶¶ 0068, 0084, 0092 (list of remediation action results, or status, is created in a data store event tracking log and failed actions are retried and a counter of retries is recorded). Compliance scope for each compliance rule includes where the rule must match the attributes of an endpoint for the rule to apply, where the attributes include the type of hardware, software, and identification of platform for the endpoint. Id. at ¶¶ 0071 & 0074.} However, Kurian doesn’t explicitly teach the limitation: associating the first endpoint with two or more remediation actions, the two or more remediation actions ordered according a corresponding level, wherein a following remediation action has a more aggressive level than its previous remediation action; iteratively, until the two or more ordered remediation actions are exhausted or the first endpoint is determined to be compliant based on an updated compliance state of the first endpoint, wherein the updated compliance state is determined after each iteration: performing, on the first endpoint, an nth remediation action of the two or more remediation actions, wherein the value of n is given by a counter that increments with each iteration; …perform a manual remediation for the first endpoint in response to the two or more remediation actions being exhausted and the updated compliance state of the first endpoint indicating that the first endpoint is incompliant. {EN: Under the Broadest Reasonable Interpretation consistent with the specification the claimed process is interpreted as ending when the first endpoint is determined to be compliant. This may be after the first remediation action is performed. Since just one remediation may be performed under the BRI, the limitations directed to ordering remediations and performing n number of remediations are interpreted as not occurring under the BRI. Shelke does teach this limitation. Shelke teaches that the device updating method, as taught in Kurian, may include where an “update readiness assistant” agent performs a software update, such as to an operating system, conducts scans to identify any failed aspects of the update, and then increments through a plurality of automated remediation script modules of increasing levels, checking after each module to see if the failure has been cured, including where the modules include automated, then semi-automated, and then finally manual remediation. Shelke at Abstract; id. at ¶¶ 0059 – 0061, 0064, 0066, 0074 – 0076, 0078. Kurian and Shelke are analogous art because they are from the “same field of endeavor” and are both from the same “problem-solving area.” Specifically, they are both from the field of software configuration updating, and both are trying to solve the problem of how to remediate update errors. It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to combine a device updating method, as taught in Kurian, with applying multiple remediation actions, as taught in Shelke. Shelke teaches that the update process must be made “smoother and simpler.” Id. at ¶ 0005. Therefore, one having ordinary skill in the art would have been motivated to combine a device updating method, as taught in Kurian, with applying multiple remediation actions, as taught in Shelke, for the purpose of using a known update remediation process using multiple remediation methods to ensure update readiness with a process that requires updates be completed successfully.} However, Kurian and Shelke doesn’t explicitly teach the limitation: generating, automatically, a ticket in the ticketing system to [perform a manual remediation action] {Gupta does teach this limitation. Gupta teaches that incremental automated remediation of update failures which results in a required manual remediation, as taught in Kurian and Shelke, may include where, after a plurality of software errors, automated remediation attempts are performed resulting in failed remediation and then a ticket is generated and routed to a user to complete a manual remediation step. Gupta at Abstract; id. at ¶¶ 0032, 0034 – 0037, 0040, 0042. Kurian, Shelke, and Gupta are analogous art because they are from the “same field of endeavor” and are both from the same “problem-solving area.” Specifically, they are both from the field of software remediation, and both are trying to solve the problem of how to remediate software errors. It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to combine multiple remediation actions followed by a manual remediation, as taught in Kurian and Shelke, with using a ticketing system for the manual remediation, as taught in Gupta. Shelke teaches that the update process must be made “smoother and simpler.” Id. at ¶ 0005. Therefore, one having ordinary skill in the art would have been motivated to combine multiple remediation actions followed by a manual remediation, as taught in Kurian and Shelke, with using a ticketing system for the manual remediation, as taught in Gupta, for the purpose of using a known update remediation process using multiple automated remediations and ticketing for manual remediation to ensure update readiness with a process that requires updates be completed successfully including the use of manual remediation steps.} Claims 2 and 13 With respect to claims 2 and 13, Kurian, Shelke, and Gupta, teach the invention as claimed including: wherein the two or more remediation actions comprise at least one of installing a software, starting a service, setting a value of a parameter, creating a file, deleting a file, and running a script. {A list of endpoint compliance states for endpoints is generated, such as a queue of workload node non-compliance event data, the compliance state is compared to requirements rules to identify non-compliance such as a encryption failure like a too short or an incorrect password, then remediation actions required by the compliance state failing to satisfy the rule are performed for each entry in the non-compliance list such as running notification scripts or setting a password parameter value, the results of the remediation action including failures are recorded in a new list such as an event tracking log and remediation failures found in the new list may be retried again. Kurian at ¶¶ 0066, 0068, 0075, 0092 (receive non-compliance events from workload nodes); id. at ¶¶ 0067 & 0076 (queue of non-compliant nodes are prioritized by level according to time sensitivity and timestamps); id. at ¶¶ 0067, 0080, 0081 (remediation action is performed); id. at ¶¶ 0068, 0084, 0092 (list of remediation action results, or status, is created in a data store event tracking log and failed actions are retried and a counter of retries is recorded).} Claims 6 and 17 With respect to claims 6 and 17, Kurian, Shelke, and Gupta, teach the invention as claimed including: wherein the compliance definition comprises an encryption compliance and {A list of endpoint compliance states for endpoints is generated, such as a queue of workload node non-compliance event data, the compliance state is compared to requirements rules to identify non-compliance such as a encryption failure like a too short or an incorrect password, then remediation actions required by the compliance state failing to satisfy the rule are performed for each entry in the non-compliance list such as running notification scripts or setting a password parameter value, the results of the remediation action including failures are recorded in a new list such as an event tracking log and remediation failures found in the new list may be retried again. Kurian at ¶¶ 0066, 0068, 0075, 0092 (receive non-compliance events from workload nodes); id. at ¶¶ 0067 & 0076 (queue of non-compliant nodes are prioritized by level according to time sensitivity and timestamps); id. at ¶¶ 0067, 0080, 0081 (remediation action is performed); id. at ¶¶ 0068, 0084, 0092 (list of remediation action results, or status, is created in a data store event tracking log and failed actions are retried and a counter of retries is recorded).} an operating system patching compliance. {Updating includes updating the software of an operating system. Shelke at ¶ 0002.} Claims 7 and 18 With respect to claims 7 and 18, Kurian, Shelke, and Gupta, teach the invention as claimed including: wherein the compliance state is one of compliant, incompliant, unknown, and inapplicable. {A list of endpoint compliance states for endpoints is generated, such as a queue of workload node non-compliance event data, the compliance state is compared to requirements rules to identify non-compliance such as a encryption failure like a too short or an incorrect password, then remediation actions required by the compliance state failing to satisfy the rule are performed for each entry in the non-compliance list such as running notification scripts or setting a password parameter value, the results of the remediation action including failures are recorded in a new list such as an event tracking log and remediation failures found in the new list may be retried again. Kurian at ¶¶ 0066, 0068, 0075, 0092 (receive non-compliance events from workload nodes); id. at ¶¶ 0067 & 0076 (queue of non-compliant nodes are prioritized by level according to time sensitivity and timestamps); id. at ¶¶ 0067, 0080, 0081 (remediation action is performed); id. at ¶¶ 0068, 0084, 0092 (list of remediation action results, or status, is created in a data store event tracking log and failed actions are retried and a counter of retries is recorded).} Claims 8 and 19 With respect to claims 8 and 19, Kurian, Shelke, and Gupta, teach the invention as claimed including: wherein the respective attribute of each endpoint of the one or more endpoints is one or more of an endpoint type, and endpoint region, and endpoint department, or an endpoint clearance level. {Compliance scope for each compliance rule must match the attributes of an endpoint for the rule to apply, where the attributes includes the type of hardware, software, and identification of platform for the endpoint. Kurian at ¶¶ 0071 & 0074.} Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THEODORE E HEBERT whose telephone number is (571)270-1409. The examiner can normally be reached on Monday to Friday 9:00 a.m. to 6:00 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lewis Bullock can be reached on 571-272-3759. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. //T.H./ August 22, 2026 Examiner, Art Unit 2199 /LEWIS A BULLOCK JR/Supervisory Patent Examiner, Art Unit 2199
Read full office action

Prosecution Timeline

Show 2 earlier events
Dec 16, 2025
Response Filed
Jan 15, 2026
Final Rejection mailed — §103
Mar 13, 2026
Response after Non-Final Action
Apr 15, 2026
Request for Continued Examination
Apr 24, 2026
Response after Non-Final Action
May 11, 2026
Non-Final Rejection mailed — §103
Jul 29, 2026
Response Filed
Sep 02, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748588
PACKAGE MAINTENANCE ARCHITECTURE
4y 2m to grant Granted Sep 29, 2026
Patent 12748582
USER ENVIRONMENT MANAGEMENT
3y 11m to grant Granted Sep 29, 2026
Patent 12737159
DATA SCIENCE WORKFLOW EXECUTION PLATFORM WITH AUTOMATICALLY MANAGED CODE AND GRAPH-BASED DATA JOB MANAGEMENT
3y 10m to grant Granted Sep 15, 2026
Patent 12705038
CODE PACKAGING FOR FLEXIBLE DEPLOYMENT WITHIN A MULTI-TENANT SYSTEM
3y 6m to grant Granted Aug 11, 2026
Patent 12705042
REVOKING A SOFTWARE SYSTEM UPGRADE WITHOUT DATA LOSS
3y 2m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
74%
Grant Probability
89%
With Interview (+14.5%)
3y 0m (~3m remaining)
Median Time to Grant
High
PTA Risk
Based on 452 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month