Prosecution Insights
Last updated: October 01, 2026
Application No. 18/399,987

APPLICATION SESSION-SPECIFIC NETWORK TOPOLOGY GENERATION FOR TROUBLESHOOTING THE APPLICATION SESSION

Non-Final OA §103
Filed
Dec 29, 2023
Priority
Jan 14, 2022 — provisional 63/299,733 +1 more
Examiner
MACILWINEN, JOHN MOORE JAIN
Art Unit
2454
Tech Center
2400 — Computer Networks
Assignee
Juniper Networks Inc.
OA Round
5 (Non-Final)
68%
Grant Probability
Favorable
5-6
OA Rounds
1y 2m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 68% — above average
68%
Career Allowance Rate
465 granted / 689 resolved
+9.5% vs TC avg
Strong +28% interview lift
Without
With
+27.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
18 currently pending
Career history
718
Total Applications
across all art units

Statute-Specific Performance

§101
9.5%
-30.5% vs TC avg
§103
55.6%
+15.6% vs TC avg
§102
10.8%
-29.2% vs TC avg
§112
19.5%
-20.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 689 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 6/19/2026 have been fully considered, and are partially persuasive. On page 12, Applicant notes the amendments to claims 21, 32, and 40, including the new language “wherein the application session includes communication between the client device [at a site] and an application server hosting the cloud-based application transmitted through a set of network devices including at least one access point (AP) device of a wireless network at the site, at least one switch of a wired network at the site, and at least one gateway device of a wide area network (WAN)." In response, the Examiner notes that the combination of Maroulis (US-10469346-B2) in view of Madsen (US-20170358111-A1) in view Wu (US-11184403-B1) remains highly relevant to the amended language; the network devices considered by Maroulis, for example, include switches and gateways as claimed (Maroulis, col. 20 lines 9-14, col. 23 lines10-25, col. 24 lines 15-33). However, the access point (AP) communication is absent, and thus after further search and consideration, a new grounds of rejection has been made further in view of Pronk (US-20220263723-A1). Applicant next notes that the claims have been amended to recite “the entity information and the connectivity information is extracted from historical network data collected from the set of network devices over time." In response, the Examiner notes that Maroulis recites collection and correlation of such information in col. 4 lines 2-10 and 21-50, which is noted as being generated during operation and then reported to a data intake and query system (and thus by the time the data is at the data intake and query system it is historical data, e.g., as discussed in col. 3 line 65 – col. 4 line 2, col. 4 lines 26-36 and col. 9 line 63 – col. 10 line 5). Concluding on page 12 and continuing through page 13, Applicant details other sections of the substantial claim amendments presented in the 6/19/2026 response. Responsive to the new details recited by the amended language, a new grounds of rejection has been presently presented (while still based on the teachings of Maroulis in view of Madsen and Wu). Continuing on page 13, Applicant emphasizes the amended “backward-looking troubleshooting”, “an indication of the prior connectivity issue at the network device within the topology”, and generation of “an indication in the user interface of a root cause” language now recited in the amended claims. Regarding the “backward-looking troubleshooting”, the Examiner notes that Maroulis discusses specification of time ranges such as “yesterday” and “last week”, which are within the scope of “backward-looking” (col. 16 lines 25-38); said data evaluations performed via the complaint evaluation process (within the scope of “troubleshooting”) discussed, e.g., in col. 24 lines 34-62 and col. 29 lines 5-20. Regarding the “indication of the prior connectivity issue at the network device within the topology”, the Examiner notes that Madsen anticipates this language via the discussion of using a topology database ([23-24]) when evaluating “bottlenecks, erroneous connections” ([14]) and other warnings, said information collected as displayed in a GUI ([17]). Regarding the “indication in the user interface of a root cause”, the Examiner notes that such an indication is discussed in Madsen in [62-63] which discusses improperly connected switches suffering from “reduced performance”, where the disclosure will “detect this anomaly and highlights the faulty wiring”. A new grounds of rejection is presented below responsive to the presently entered amended claim language. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 21, 23, 24, 28, 32, 33, 36, 38, 39, and 40 are rejected under 35 U.S.C. 103 as being unpatentable over Maroulis (US-10469346-B2) in view of Madsen (US-20170358111-A1), Wu (US-11184403-B1), Naous (US-20180034685-A1) and Pronk (US-20220263723-A1). Regarding claim 21, Maroulis shows a computing system comprising: one or more processors (Fig. 12 item 1204), and memory comprising instructions executable by the one or more processors (Fig. 12, items 1206, 1208, 1210) to cause the computing system to: retrieve from a database (col. 10 line 11, discussing storage in a “database table” and col. 11 lines 25-31 discussing “indexers that process and store the data in one or more data stores”), entity information (col. 4 lines 5 – 10, see “information about the client device itself”) and connectivity information (col. 3 line 44 – col. 4 line 20, col. 6 lines 31-54, col. 6 lines 66-67) for an application session (col. 9 lines 22-31 discussing a “’sessionIdentifier’ field storing a value that identifies a particular application session”) of a application with a client device at a site (e.g., a “data intake and query system”, col. 3 line 65 – col. 4 line 2, col. 9 lines 31-37), wherein the application session includes communication between the client device and an application server hosting (col. 5 lines 32-41, col. 6 lines 31-38, col. 8 lines 16-30) the application transmitted through a set of network devices (col. 5 lines 35-47 discussing implementation of a network-based service) including a wireless network at the site, at least one of a switch of a wired network at the site, and at least one gateway device of a wide area network (WAN) (col. 20 lines 9-14, col. 23 lines 10-23, col. 24 lines 15-33), wherein the entity information and the connectivity information is extracted from historical network data collected from the set of network devices over time (col. 3 line 65-col. 4 line 2, col. 4 lines 26-36, col. 9 line 63 – col. 10 line 5), and wherein the entity information represents the set of network devices and the connectivity information represents connections between the set of network devices (col. 4 lines 54-56, col. 5 line 61 – col. 6 line 10); determine, based on the historical network data, a prior connectivity issue at a network device of the set of network devices that occurred during the application session (col. 24 line 34 – col. 25 line 5); and perform backward-looking troubleshooting for the application session (col. 16 lines 25-38, col. 29 lines 5-20), wherein the one or more processors are configured to: generate, based on the entity information and the connectivity information for the application session retrieved from the database a user interface (col. 16 lines 39-50) visualization (col. 14 lines 40-45). Maroulis, while processing data based on and in consideration of application sessions (col. 9 lines 22-31), does not show the user interface including a topology that represents an historical arrangement of network devices and the connections during the evaluation period, and an indication of the prior connectivity issue at the network device within the topology; and in response to receipt of user input selecting the indication, generate an indication in the user interface of a root cause of the prior connectivity issue at the network device. Madsen suggests a user interface including a topology that represents an historical arrangement of network devices and the connections during the evaluation period ([32,42-43]), and an indication of the prior connectivity issue ([14,17,49]) at the network device within the topology ([13-17,27,53]); and in response to receipt of user input, generate an indication in the user interface ([56-58]) of a root cause of the prior connectivity issue at the network device ([62-63]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the network data collection and event storage and analysis of Maroulis, including Maroulis suggestions to gather, store, and utilize application and session identification information (Maroulis, col. 30 lines 22-44), with the data collection and visualization techniques of Madsen in order to improve the ease with which system administrators can review and analyze network state, simplifying and improving network maintenance. The above combination thus does show display of a root cause in response to user input (as cited above when addressing Madsen; e.g., [13-17,27]), but does not show where the user in put is selecting an indication of a connectivity issue. Naous shows where the user in put is selecting an indication of a connectivity issue ([3-4]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the network troubleshooting disclosure of the above combination with the root cause display techniques of Naous in order to provide users with root causes of network issues in a more streamlined and manner that is more responsive to a variety of common user input mechanisms familiar to one of ordinary skill in the art (i.e., displaying the cause of an issue related to a device responsive to a selection of the device). The above combination does not show: where the information is related to a cloud-based application. Wu shows information related to a cloud-based application (col. 10 lines 36-39, col. 27 lines 53-63). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the cloud-based techniques of the above combination with the cloud-application execution of Wu in order to ensure robust support for additional operating environments, particularly the increasingly common trend of leveraging cloud-based application execution, thus facilitating use of the network monitoring techniques for additional system administrators. The above combination does not show evaluation including at least one access point (AP) device. Pronk suggests evaluation including at least one access point (AP) device (Fig. 4, [46-51]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the network troubleshooting disclosure of the above combination with the wireless AP awareness of Pronk in order to improve network problem diagnosis by better considering the unique properties of wireless access (Pronk, [23-24]). Regarding claim 23, the above combination further shows wherein the instructions further cause the computing system to receive a query (Madsen, [57]) identifying the application session (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68) of the cloud-based application (Wu, col. 10 lines 36-39, col. 27 lines 53-63) for the backward-looking troubleshooting (Maroulis, col. 29 lines 5-20) of the prior connectivity issue at the network device (Madsen, [42] and Maroulis, col. 16 lines 25-38 and col. 29 lines 5-20) of the set of network devices that occurred (Madsen, [63]) during the application session with respect to the topology of the application session (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68, discussing time-bounded queries as well as queries bounded by other recorded data fields such as those identifying an application session). Regarding claim 24, the above combination further shows wherein the entity information for the application session (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68 and Wu, col. 10 lines 36-49 and col. 27 lines 53-63) is stored in the database as nodes representative of network devices of the set of network devices and the connectivity information is stored in the database as edges representative of the connections between the network devices of the set of network devices (Madsen, Figs. 5A-5C, [33-35, 38]). Regarding claim 28, the above combination further shows wherein the instructions further case the computing system to perform root cause analysis to determine a root cause (Maroulis col. 19 lines 29-49, col. 22 lines 10-15 and 29-36 and Naous, [3-4]) of the prior connectivity issue at the network device of the set of network devices (Madsen, [42]) during the application session (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68). Regarding claims 32 and 40, the limitations of said claims are addressed in the analysis of claim 21. Regarding claim 33, the limitations of said claim are addressed in the analysis of claim 23. Regarding claim 36, the limitations of said claim are addressed in the analysis of claim 28. Claims 26, 29, 34, and 37 are rejected under 35 U.S.C. 103 as being unpatentable over Maroulis in view of Madsen, Wu, Naous, and Pronk as applied to claim 21 above, further in view of Taylor (Taylor, Teryl, et al. "Flovis: Flow visualization system." 2009 Cybersecurity Applications & Technology Conference for Homeland Security. IEEE. (Year: 2009)). Regarding claim 26, the above combination shows evaluation and consideration of application session data (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68, and Wu, col. 10 lines 36-49 and col. 27 lines 53-63), as well as obtaining entity (col. 7 line 63 – col. 8 line 30 discussing entity information such as location, signal strength, memory performance and other “device performance information”) and connectivity information (col. 8 line 62 – col. 9 line 5 discussing connectivity information such as latency) for the application session (col. 9 lines 23-31 discussing the data is in regards to an “application session” and includes an identifier for the particular session and connectivity information for the application session). The above combination does not show wherein the instructions further cause the computing system to: correlate data from multiple application flows; and identify the set of network devices from a plurality of network devices of the network as being used to transmit traffic based on the data correlated from the multiple application flows, wherein to obtain the information, the one or more processors are configured to obtain the information from the database based on the identified set of network devices. Taylor shows wherein the one or more processors are configured to: correlate data from multiple application flows (pg. 2, L42 – R14); and identify the set of network devices from a plurality of network devices of the network as being used to transmit traffic based on the data correlated from the multiple application flows (pg. 2 L42-L43, R52-R57, and pg. 3 R29-R32), wherein to obtain the information, the one or more processors are configured to obtain the information from the database based on the identified set of network devices (pg. 2 R5-R14, R35-R41, pg. 4 L17-L60). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the monitoring and analysis techniques of Taylor improve the visualization options provided to the system administrator, improving their ability to extrapolate connections or review proposed connections between system state and events occurring within the system. Regarding claim 29, the above combination shows evaluation and consideration of application session data, including session time periods (Maroulis, col. 9 lines 24-32, col. 14 lines 15-27 and 60-68, and Wu, col. 10 lines 36-49 and col. 27 lines 53-63). The above combination does not show to: generate the user interface including the topology, the instructions further cause the computing system to generate one or more icons representative of at least a portion of the set of network devices and the connections between the at least a portion of the set of network devices used to transmit traffic for the at a given time during the time period. Taylor shows to: generate the user interface including the topology, the instructions further cause the computing system to generate one or more icons representative of at least a portion of the set of network devices and the connections between the at least a portion of the set of network devices used to transmit traffic for the at a given time during the time period (Figs. 2-5, pg. 5 R42-R57, pg. 6 L41-R55). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the above combination with the monitoring and analysis techniques of Taylor improve the visualization options provided to the system administrator, improving their ability to extrapolate connections or review proposed connections between system state and events occurring within the system. Regarding claim 34, the limitations of said claim are addressed in the analysis of claim 26. Regarding claim 37, the limitations of said claim are addressed in the analysis of claim 29. Claims 30 and 38 are rejected under 35 U.S.C. 103 as being unpatentable over Maroulis in view of Madsen, Wu, Naous, and Pronk as applied to claim 21 above, further in view of O’Connor (US-20200192344-A1) Regarding claim 30, the above combination shows: wherein to generate the user interface including the indication of the prior connection issue at the network deice (Madsen, [32,42-43]) the instructions further cause the computing system to generate a representative illustration of the set of network devices (Madsen, [23,37-38]) having the indication of the prior connection issue (Madsen, [13-17]) during the application session (Maroulis, col. 9 lines 23-31). The above combination does not show: generation of an icon representative of the network device, wherein the indication of the prior connection issue comprises at least one of a color, a shape, a symbol, or a combination thereof. O’Connor shows: generation of an icon representative of the network device ([98]), wherein the indication of the prior connection issue comprises at least one of a color, a shape, a symbol, or a combination thereof (Fig. 7, [13,35,40-42,86-87,94]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the network troubleshooting techniques of the above combination with the icon use and graphical emphasis techniques of O’Connor in order to utilize a well-known prior art technique for its intended purpose (using pictures, shapes, colors, etc. to convey information in an easy-to-understand manner). Regarding claim 38, the limitations of said claim are addressed in the analysis of claim 30. Claims 31 and 39 are rejected under 35 U.S.C. 103 as being unpatentable over Maroulis in view of Madsen, Wu, Naous, Pronk and O’Connor as applied to claim 30 above, further in view of Côté (US-20210028973-A1). Regarding claim 31, the above combination shows wherein to generate the user interface including the indication of the root cause, the instructions further cause the computing system to generate data regarding the prior connectivity issue (Madsen, [17,62-63]). The above combination does not show to generate text in the user interface descriptive of the root cause of the issue at the network device. Côté suggests to generate text in the user interface descriptive of the root cause of the issue at the network device ([84,87,144,154,177]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the network troubleshooting techniques of the above combination with the text display of Côté in order to provide a detailed description of the current problem and potential solution to the system operator, improving the likelihood of an efficient resolution to the network problem. Regarding claim 39, the limitations of said claim are addressed in the analysis of claim 31. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN M MACILWINEN whose telephone number is (571)272-9686. The examiner can normally be reached Monday - Friday, 9:00 - 5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571) 272 - 3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. JOHN MACILWINEN Primary Examiner Art Unit 2442 /JOHN M MACILWINEN/Primary Examiner, Art Unit 2454
Read full office action

Prosecution Timeline

Show 15 earlier events
Feb 26, 2026
Response Filed
Mar 25, 2026
Final Rejection mailed — §103
May 19, 2026
Interview Requested
Jun 03, 2026
Applicant Interview (Telephonic)
Jun 05, 2026
Examiner Interview Summary
Jun 19, 2026
Request for Continued Examination
Jun 23, 2026
Response after Non-Final Action
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744816
CENTRALIZED COMPLIANCE MANAGEMENT PLATFORM FOR SECURITY OBJECTS
2y 8m to grant Granted Sep 22, 2026
Patent 12712804
PACKET TRANSMISSION METHOD, APPARATUS, AND SYSTEM, NETWORK DEVICE, AND STORAGE MEDIUM
2y 7m to grant Granted Aug 18, 2026
Patent 12706934
Systems and methods for active directory protection in zero trust networks
2y 4m to grant Granted Aug 11, 2026
Patent 12689559
AUTOMATED PREVENTATIVE CONTROLS IN DIGITAL WORKFLOW
2y 4m to grant Granted Jul 21, 2026
Patent 12676892
Security policy framework for cloud environments
2y 8m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
68%
Grant Probability
95%
With Interview (+27.9%)
3y 11m (~1y 2m remaining)
Median Time to Grant
High
PTA Risk
Based on 689 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month