Prosecution Insights
Last updated: August 08, 2026
Application No. 18/405,199

SYSTEM AND METHOD FOR NETWORK TELEMETRY DATA ANALYSIS WITH STREAM PROCESSING AND NON-UNIFORM SAMPLING

Non-Final OA §103§112
Filed
Jan 05, 2024
Priority
Nov 08, 2023 — CIP of 18/504,991
Examiner
TALIOUA, ABDELBASST
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Aviz Networks, Inc.
OA Round
3 (Non-Final)
59%
Grant Probability
Moderate
3-4
OA Rounds
5m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
67 granted / 113 resolved
+1.3% vs TC avg
Strong +35% interview lift
Without
With
+35.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
28 currently pending
Career history
149
Total Applications
across all art units

Statute-Specific Performance

§101
3.3%
-36.7% vs TC avg
§103
72.5%
+32.5% vs TC avg
§102
10.5%
-29.5% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 113 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on May 14th, 2026 has been entered. In this office action: Claims 1, 3-7, 9-13, and 15-18 are pending. Claims 1, 3-7, 9-13, and 15-18 are rejected. Summary of Previous Office Action In the Final Office Action mailed on January 14th, 2026: Claims 1, 7, 13, and 15 were objected to because of informalities. Claims 7 and 9-12 were rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 3, 5-7, 9, 11-13, 15, and 17-18 were rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (Pub. No. US 2021/0334186), hereinafter Chen; in view of Jueping (Pub. CN115037621A, published on 09/09/2022); and further in view of Myla et al. (Patent No. US 11,405,261), hereinafter Myla. Claims 4, 10, and 16 were rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (Pub. No. US 2021/0334186), hereinafter Chen; in view of Jueping (Pub. CN115037621A, published on 09/09/2022); further in view of Myla et al. (Patent No. US 11,405,261), hereinafter Myla; and further in view of Mazzaferri et al. (Pub. No. US 2007/0174429), hereinafter Mazzaferri. Response to Amendment The amendments filed on May 14th, 2026 have been entered. Claims 1, 7, 10, 13 and 15 have been amended. The previously raised claim objections are withdrawn for claims 1, 7, 13, and 15 in light of the amendments. The previously raised 35 U.S.C. 112(b) rejection is withdrawn for claims 7 and 9-12 in light of the amendments. Response to Arguments Applicant Arguments/Remarks, filed on May 14th, 2026, have been fully considered by the Examiner, and are moot in view of the new grounds of rejection, as presented in this Office Action. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 3, 5-7, 9, 11-13, 15, and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (Pub. No. US 2021/0334186), hereinafter Chen; in view of Jueping (Pub. CN115037621A, published on 09/09/2022); further in view of Song et al. (Pub. No. US 2021/0084530), hereinafter Song; and further in view of Myla et al. (Patent No. US 11,405,261), hereinafter Myla. Claim 1. Chen discloses [a] method, comprising: providing one or more collectors which periodically request memory utilization from a device (See Parag. [0038-0040]; agents 304 (one or more collectors) may refer to different types of agents that locally generate or sample a state of memory usage on the host node 302 (device) ... the agents 304 may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302; the memory usage data 306 may include performance counters indicative of memory usage for specific processes ... the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals. See also Fig. 6. Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data. Therefore, the Examiner interpreted one or more collectors periodically request memory utilization as the agents (monitoring agent) obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents may capture a current status of memory allocation at five-minute intervals); receiving, by a stream processor, memory utilization from the one or more collectors (See Parag. [0038]; the agents 304 may refer to different types of agents that provide memory usage data 306 to the memory leak management system 106 (a stream processor) (e.g., aggregation system 202) for further analysis. See also Parag. [0015], Fig. 2, and Fig. 6); monitoring, by the stream processor, if memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Parag. [0045]; the data aggregator 204 can provide aggregated data 308 to a time interval manager 206 (within the memory leak management system 106) to identify time intervals (predetermined time) for the memory usage data 306. See Parag. [0048-0049]; … the data aggregator 204 applies an algorithm to the aggregated memory usage data to determine a dynamic severity score corresponding to a current status of the memory usage data. Over time, as the severity score increases, the data aggregator 204 may determine that the aggregated memory usage data results in a severity score over a threshold value (crosses a predetermined threshold) ... the time interval manager 206 can provide an indication of the time interval(s) 310 to the data aggregator 204 ... the data aggregator 204 can provide a subset of aggregated data 308 limited to memory usage data 306 for the identified time interval 310 to the diagnosis and mitigation system 210. See also Parag. [0092]; aggregating the memory usage data over one or more predetermined intervals (predetermined time) to determine a subset of host nodes from the plurality of host nodes predicted to have memory leaks based on memory usage data for the subset of host nodes satisfying one or more impact metrics. The one or more impact metrics may include one or more of a threshold increase in memory usage over a relevant time interval, a threshold increase in memory usage over a short duration of time ... See also Parag. [0043] [0046-0047] [0049] [0068] [0085-0088], Fig. 2, Fig. 3A-B, Fig. 5A-C, and Fig. 6); sending data downstream to a data sink for persistence (See Parag. [0034]; The monitor and reporting system 216 (within the memory leak management system 106) may receive memory usage data and provide further analysis in connection with diagnosing and mitigating memory leaks on host nodes; the monitor and reporting system 216 can utilize third-party analysis systems to perform a more thorough analysis of diagnosis information and/or memory usage information to develop a detailed report including information associated with specific host nodes and/or processes that may be used in preventing or otherwise mitigating memory impact events across nodes of the cloud computing system. See Parag. [0035]; the memory leak management system 106 may include a data storage 218. The data storage 218 may include any information associated with respective host nodes and/or processes and services hosted by the respective host nodes. Examiner’s interpretation: The Examiner interpreted sending data downstream to a data sink for persistence as sending data downstream for a destination for storage); sending a sampling strategy to the one or more collectors, if the memory utilization evaluated over the predetermined time crosses the predetermined threshold (See Parag. [0048-0054] and Fig. 3A-B; the data aggregator 204 provides the aggregated subset 312 (and the associated severity score) to the diagnosis and mitigation system 210 based on the severity score exceeding the threshold value … the diagnosis manager 212 can evaluate the aggregated subset 312 of memory usage data to determine a diagnosis command 314 including instructions for the host nodes associated with the aggregated subset 312 of memory usage data … the diagnosis command 314 may include an indication of a memory leak or other memory impact event as well as instructions indicating one or more diagnosis actions that the candidate node 322 can perform to enable the memory leak management system 106 to effectively monitor further memory usage data … In response to receiving the diagnosis command 314, agents 324 (the one or more collector) on the candidate node(s) 322 can collect additional memory usage data. In particular, each of multiple agents 324 can collect or sample different types of memory usage data; the agents 324 can sample memory usage data at predetermined intervals (e.g., every five minutes). See also Fig. 2. Examiner’s interpretation: The Examiner interpreted “sending a new sampling strategy to the one or more collector” as sending the diagnosis command to agent(s) to effectively monitor/collect additional memory usage data and perform new sampling using the additional memory usage data. In addition, the command is based on the severity score exceeding the threshold value over a time interval); requesting, by the one or more collectors, process information repeatedly from the device for a predetermined process information period of time (See Parag. [0038-0040]; the agents 304 (one or more collectors) may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302 (device). For example, the memory usage data 306 may include performance counters indicative of memory usage for specific processes … the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals (a predetermined process information period of time). Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data). Chen doesn’t explicitly disclose the evaluated memory utilization over a predetermined time is an average memory utilization; the sampling strategy is non-uniform, wherein the non-uniform sampling strategy dynamically adjusts a sampling rate; [and] receiving, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Jueping discloses monitoring, by the stream processor, if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Page 5, Lines 8-17 and 30-36; Get the CPU usage and memory usage of the controller; Define the time period T1 (predetermined time), and calculate the average memory usage and CPU usage in the previous T1 time period at the current time point; set the T1 time to 5 minutes … a third threshold (predetermined threshold) is set for the average usage rate of the memory, that is, within a certain period of time … when the average usage rate of the memory is greater than or equal to the third threshold, it indicates that the current resource load of the controller is relatively large). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the data aggregator determining if the aggregated memory usage data, over a predetermined interval, results in a severity score over a threshold value, taught by Chen, to monitor if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold, as taught by Jueping. This would be convenient to indicate that the current resource load of the controller is relatively large; thus, no new network device audit operations are added (Jueping, See Page 5, Lines 30-36). Chen in view of Jueping doesn’t explicitly disclose the sampling strategy is non-uniform, wherein the non-uniform sampling strategy dynamically adjusts a sampling rate; [and] receiving, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Song discloses sending a non-uniform sampling strategy to the one or more collectors, if the memory utilization crosses the predetermined threshold, wherein the non-uniform sampling strategy dynamically adjusts a sampling rate (See Parag. [0004]; receiving, by a receiver of a controller, one or more congestion indicators from a collector. The method further comprises generating, by a processor of the controller, an adjusted sampling rate (dynamically adjust a sampling rate, See Parag. [0036]) of instruction header insertion for in-band network telemetry (INT) based on the congestion indicators ... transmitting, by a transmitter of the controller, the adjusted sampling rate to a head node configured to perform INT via instruction header insertion into user packets. For example, in some systems INT is performed at a head end node by inserting instruction headers into user packets. The instruction header directs each node in a path to collect indicated telemetry data and report such telemetry back to a collector ... See Parag. [0049]; adjust the sampling rate 143 in response to receiving a congestion indicator 141 indicating actual data loss (e.g., dropped packet) or predicted data loss (e.g., node status indicator such as buffer occupancy is in excess of a threshold) (memory utilization crosses the predetermined threshold). See also Parag. [0005] [0008] [0036] [0040] [0051] and Fig. 3). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the sampling strategy sent to the one or more collectors, taught by Chen in view of Jueping, as a non-uniform sampling strategy, wherein the non-uniform sampling strategy dynamically adjusts a sampling rate, as taught by Song. This would be convenient to allow for maximizing INT coverage over a network without negatively impacting user traffic forwarding (Song, See Parag. [0036]). The combination doesn’t explicitly disclose receiving, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Myla discloses receiving, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors (See Col. 4 lines 60-67 and Col. 5 lines 1-9; network device (the one or more collectors) may determine a first time interval (a predetermined process information frequency) (e.g., every 2 seconds, every 5 seconds, every 10 seconds, every 30 seconds, and/or the like) to collect and send the delta values of the telemetry data to the collector device (stream processor). See Col. 2 lines 24-40; The collector device analyzes the telemetry data to determine a status of the network device, a health of the network device, and/or the like ... Examiner’s interpretation: The Examiner interpreted the network device, taught by Myla, as a collector as it collects and sends the telemetry data including information of the one or more resources of the network device at a particular time to the collector device. In addition, the Examiner interpreted the collector device, taught by Myla, as a stream processor as it receives and analyzes the telemetry data to determine a status of the network device and a health of the network device). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the memory leak management system (the stream processor), taught by the combination, to receive process information repeatedly at a predetermined process information frequency from the one or more collectors, as taught by Myla. This would be convenient to maintain and/or improve a performance of the network device (Myla, See Col. 2 lines 24-40). Claim 3. Chen in view of Jueping, Song, and Myla discloses [t]he method of claim 1, Chen discloses the method further comprising generating alerts, by the stream processor, and sending the generated alerts to the data sink (See Parag. [0081]; See Parag. [0081] and Fig. 4; The memory leak management system 106 (the stream processor) can utilize the monitored data in a variety of ways; the job monitor 422 (within the memory leak management system 106) can generate a usage report 442 including information about customer impact, such as a rollout correlation metric (e.g., correlation between rollout of various applications and instances of memory leaks (generating alerts). See Parag. [0082]; the job monitor 422 may provide a rollout stop signal to a health server 440 to indicate that a particular application rollout has a problem and that the rollout should be stopped to any and all host nodes (sending the generated alerts to the data sink)). Claim 5. Chen in view of Jueping, Song, and Myla discloses [t]he method of claim 3, Chen doesn’t explicitly disclose wherein the predetermined time is 5 minutes. However, Jueping discloses wherein the predetermined time is 5 minutes (See Page 5, Lines 8-17 and 30-36; Define the time period T1 (predetermined time), and calculate the average memory usage and CPU usage in the previous T1 time period at the current time point; set the T1 time to 5 minutes …). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the identified time interval (predetermined interval), taught by Chen, as a 5 minutes predetermined time, as taught by Jueping. This would be convenient to determine if the average usage rate of the memory is greater than or equal to the third threshold to indicate if the current resource load of the controller is relatively large; thus, no new network device audit operations are added (Jueping, See Page 5, Lines 30-36). Claim 6. Chen in view of Jueping, Song, and Myla discloses [t]he method of claim 5, Chen further discloses wherein the predetermined process information period of time is approximately 5 minutes (See Parag. [0038-0040]; the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals (the predetermined process information period of time)). Chen in view of Jueping doesn’t explicitly disclose the predetermined process information frequency is approximately 2 seconds. However, Myla discloses the predetermined process information frequency is approximately 2 seconds (See Col. 4 lines 60-67 and Col. 5 lines 1-9; network device may determine a first time interval (e.g., every 2 seconds) (the predetermined process information frequency is approximately 2 seconds) to collect and send the delta values of the telemetry data to the collector device). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the memory leak management system (the stream processor), taught by Chen in view of Jueping, to receive process information repeatedly at a predetermined process information frequency of approximately 2 seconds, as taught by Myla. This would be convenient to maintain and/or improve a performance of the network device (Myla, See Col. 2 lines 24-40). Claim 7. Chen discloses [a] non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a computing system, cause the one or more processors to (See Parag. [0089]; a non-transitory computer-readable medium can include instructions that, when executed by one or more processors, cause a computing device to perform the acts of for diagnosing and mitigating memory leaks on host node(s). See also Fig. 2): provide one or more collectors which periodically request memory utilization from a target device (See Parag. [0038-0040]; agents 304 (one or more collectors) may refer to different types of agents that locally generate or sample a state of memory usage on the host node 302 (device) ... the agents 304 may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302; the memory usage data 306 may include performance counters indicative of memory usage for specific processes ... the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals. See also Fig. 6. Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data. Therefore, the Examiner interpreted one or more collectors periodically request memory utilization as the agents (monitoring agent) obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents may capture a current status of memory allocation at five-minute intervals); receive, by a stream processor, memory utilization from the one or more collectors (See Parag. [0038]; the agents 304 may refer to different types of agents that provide memory usage data 306 to the memory leak management system 106 (a stream processor) (e.g., aggregation system 202) for further analysis. See also Parag. [0015], Fig. 2, and Fig. 6); monitor, by the stream processor, if memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Parag. [0045]; the data aggregator 204 can provide aggregated data 308 to a time interval manager 206 (within the memory leak management system 106) to identify time intervals (predetermined time) for the memory usage data 306. See Parag. [0048-0049]; … the data aggregator 204 applies an algorithm to the aggregated memory usage data to determine a dynamic severity score corresponding to a current status of the memory usage data. Over time, as the severity score increases, the data aggregator 204 may determine that the aggregated memory usage data results in a severity score over a threshold value (crosses a predetermined threshold) ... the time interval manager 206 can provide an indication of the time interval(s) 310 to the data aggregator 204 ... the data aggregator 204 can provide a subset of aggregated data 308 limited to memory usage data 306 for the identified time interval 310 to the diagnosis and mitigation system 210. See also Parag. [0092]; aggregating the memory usage data over one or more predetermined intervals (predetermined time) to determine a subset of host nodes from the plurality of host nodes predicted to have memory leaks based on memory usage data for the subset of host nodes satisfying one or more impact metrics. The one or more impact metrics may include one or more of a threshold increase in memory usage over a relevant time interval, a threshold increase in memory usage over a short duration of time ... See also Parag. [0043] [0046-0047] [0049] [0068] [0085-0088], Fig. 2, Fig. 3A-B, Fig. 5A-C, and Fig. 6); send data downstream to a data sink for persistence (See Parag. [0034]; The monitor and reporting system 216 (within the memory leak management system 106) may receive memory usage data and provide further analysis in connection with diagnosing and mitigating memory leaks on host nodes; the monitor and reporting system 216 can utilize third-party analysis systems to perform a more thorough analysis of diagnosis information and/or memory usage information to develop a detailed report including information associated with specific host nodes and/or processes that may be used in preventing or otherwise mitigating memory impact events across nodes of the cloud computing system. See Parag. [0035]; the memory leak management system 106 may include a data storage 218. The data storage 218 may include any information associated with respective host nodes and/or processes and services hosted by the respective host nodes. Examiner’s interpretation: The Examiner interpreted sending data downstream to a data sink for persistence as sending data downstream for a destination for storage); send a sampling strategy to the one or more collectors, if the memory utilization evaluated over the predetermined time crosses the predetermined threshold (See Parag. [0048-0054] and Fig. 3A-B; the data aggregator 204 provides the aggregated subset 312 (and the associated severity score) to the diagnosis and mitigation system 210 based on the severity score exceeding the threshold value … the diagnosis manager 212 can evaluate the aggregated subset 312 of memory usage data to determine a diagnosis command 314 including instructions for the host nodes associated with the aggregated subset 312 of memory usage data … the diagnosis command 314 may include an indication of a memory leak or other memory impact event as well as instructions indicating one or more diagnosis actions that the candidate node 322 can perform to enable the memory leak management system 106 to effectively monitor further memory usage data … In response to receiving the diagnosis command 314, agents 324 (the one or more collector) on the candidate node(s) 322 can collect additional memory usage data. In particular, each of multiple agents 324 can collect or sample different types of memory usage data; the agents 324 can sample memory usage data at predetermined intervals (e.g., every five minutes). See also Fig. 2. Examiner’s interpretation: The Examiner interpreted “sending a new sampling strategy to the one or more collector” as sending the diagnosis command to agent(s) to effectively monitor/collect additional memory usage data and perform new sampling using the additional memory usage data. In addition, the command is based on the severity score exceeding the threshold value over a time interval). request, by the one or more collectors, process information repeatedly from the target device for a predetermined process information period of time (See Parag. [0038-0040]; the agents 304 (one or more collectors) may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302 (device). For example, the memory usage data 306 may include performance counters indicative of memory usage for specific processes … the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals (a predetermined process information period of time). Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data). Chen doesn’t explicitly disclose the evaluated memory utilization over a predetermined time is an average memory utilization; the sampling strategy is non-uniform; [and] receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Jueping discloses monitor, by the stream processor, if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Page 5, Lines 8-17 and 30-36; Get the CPU usage and memory usage of the controller; Define the time period T1 (predetermined time), and calculate the average memory usage and CPU usage in the previous T1 time period at the current time point; set the T1 time to 5 minutes … a third threshold (predetermined threshold) is set for the average usage rate of the memory, that is, within a certain period of time … when the average usage rate of the memory is greater than or equal to the third threshold, it indicates that the current resource load of the controller is relatively large). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the data aggregator determining if the aggregated memory usage data, over a predetermined interval, results in a severity score over a threshold value, taught by Chen, to monitor if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold, as taught by Jueping. This would be convenient to indicate that the current resource load of the controller is relatively large; thus, no new network device audit operations are added (Jueping, See Page 5, Lines 30-36). Chen in view of Jueping doesn’t explicitly disclose the sampling strategy is non-uniform; [and] receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Song discloses send a non-uniform sampling strategy to the one or more collectors, if the memory utilization crosses the predetermined threshold (See Parag. [0004]; receiving, by a receiver of a controller, one or more congestion indicators from a collector. The method further comprises generating, by a processor of the controller, an adjusted sampling rate (dynamically adjust a sampling rate, See Parag. [0036]) of instruction header insertion for in-band network telemetry (INT) based on the congestion indicators ... transmitting, by a transmitter of the controller, the adjusted sampling rate to a head node configured to perform INT via instruction header insertion into user packets. For example, in some systems INT is performed at a head end node by inserting instruction headers into user packets. The instruction header directs each node in a path to collect indicated telemetry data and report such telemetry back to a collector ... See Parag. [0049]; adjust the sampling rate 143 in response to receiving a congestion indicator 141 indicating actual data loss (e.g., dropped packet) or predicted data loss (e.g., node status indicator such as buffer occupancy is in excess of a threshold) (memory utilization crosses the predetermined threshold). See also Parag. [0005] [0008] [0036] [0040] [0051] and Fig. 3). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the sampling strategy sent to the one or more collectors, taught by Chen in view of Jueping, as a non-uniform sampling strategy, as taught by Song. This would be convenient to allow for maximizing INT coverage over a network without negatively impacting user traffic forwarding (Song, See Parag. [0036]). The combination doesn’t explicitly disclose receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Myla discloses receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors (See Col. 4 lines 60-67 and Col. 5 lines 1-9; network device (the one or more collectors) may determine a first time interval (a predetermined process information frequency) (e.g., every 2 seconds, every 5 seconds, every 10 seconds, every 30 seconds, and/or the like) to collect and send the delta values of the telemetry data to the collector device (stream processor). See Col. 2 lines 24-40; The collector device analyzes the telemetry data to determine a status of the network device, a health of the network device, and/or the like ... Examiner’s interpretation: The Examiner interpreted the network device, taught by Myla, as a collector as it collects and sends the telemetry data including information of the one or more resources of the network device at a particular time to the collector device. In addition, the Examiner interpreted the collector device, taught by Myla, as a stream processor as it receives and analyzes the telemetry data to determine a status of the network device and a health of the network device). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the memory leak management system (the stream processor), taught by the combination, to receive process information repeatedly at a predetermined process information frequency from the one or more collectors, as taught by Myla. This would be convenient to maintain and/or improve a performance of the network device (Myla, See Col. 2 lines 24-40). Claim 9 is taught by Chen in view of Jueping, Song, and Myla as described for claim 3. Claim 11 is taught by Chen in view of Jueping, Song, and Myla as described for claim 5. Claim 12 is taught by Chen in view of Jueping, Song, and Myla as described for claim 6. Claim 13. Chen discloses [a] system comprising: one or more processors configured to (See Parag. [0089]; one or more processors): provide one or more collectors which periodically request memory utilization from a device (See Parag. [0038-0040]; agents 304 (one or more collectors) may refer to different types of agents that locally generate or sample a state of memory usage on the host node 302 (device) ... the agents 304 may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302; the memory usage data 306 may include performance counters indicative of memory usage for specific processes ... the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals. See also Fig. 6. Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data. Therefore, the Examiner interpreted one or more collectors periodically request memory utilization as the agents (monitoring agent) obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents may capture a current status of memory allocation at five-minute intervals); receive, by a stream processor, memory utilization from the one or more collectors (See Parag. [0038]; the agents 304 may refer to different types of agents that provide memory usage data 306 to the memory leak management system 106 (a stream processor) (e.g., aggregation system 202) for further analysis. See also Parag. [0015], Fig. 2, and Fig. 6); monitor, by the stream processor, if memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Parag. [0045]; the data aggregator 204 can provide aggregated data 308 to a time interval manager 206 (within the memory leak management system 106) to identify time intervals (predetermined time) for the memory usage data 306. See Parag. [0048-0049]; … the data aggregator 204 applies an algo algorithm to the aggregated memory usage data to determine a dynamic severity score corresponding to a current status of the memory usage data. Over time, as the severity score increases, the data aggregator 204 may determine that the aggregated memory usage data results in a severity score over a threshold value (crosses a predetermined threshold) ... the time interval manager 206 can provide an indication of the time interval(s) 310 to the data aggregator 204 ... the data aggregator 204 can provide a subset of aggregated data 308 limited to memory usage data 306 for the identified time interval 310 to the diagnosis and mitigation system 210. See also Parag. [0092]; aggregating the memory usage data over one or more predetermined intervals (predetermined time) to determine a subset of host nodes from the plurality of host nodes predicted to have memory leaks based on memory usage data for the subset of host nodes satisfying one or more impact metrics. The one or more impact metrics may include one or more of a threshold increase in memory usage over a relevant time interval, a threshold increase in memory usage over a short duration of time ... See also Parag. [0043] [0046-0047] [0049] [0068] [0085-0088], Fig. 2, Fig. 3A-B, Fig. 5A-C, and Fig. 6); send data downstream to a data sink for persistence (See Parag. [0034]; The monitor and reporting system 216 (within the memory leak management system 106) may receive memory usage data and provide further analysis in connection with diagnosing and mitigating memory leaks on host nodes; the monitor and reporting system 216 can utilize third-party analysis systems to perform a more thorough analysis of diagnosis information and/or memory usage information to develop a detailed report including information associated with specific host nodes and/or processes that may be used in preventing or otherwise mitigating memory impact events across nodes of the cloud computing system. See Parag. [0035]; the memory leak management system 106 may include a data storage 218. The data storage 218 may include any information associated with respective host nodes and/or processes and services hosted by the respective host nodes. Examiner’s interpretation: The Examiner interpreted sending data downstream to a data sink for persistence as sending data downstream for a destination for storage); send a sampling strategy to the one or more collectors, if the memory utilization evaluated over the predetermined time crosses the predetermined threshold (See Parag. [0048-0054] and Fig. 3A-B; the data aggregator 204 provides the aggregated subset 312 (and the associated severity score) to the diagnosis and mitigation system 210 based on the severity score exceeding the threshold value … the diagnosis manager 212 can evaluate the aggregated subset 312 of memory usage data to determine a diagnosis command 314 including instructions for the host nodes associated with the aggregated subset 312 of memory usage data … the diagnosis command 314 may include an indication of a memory leak or other memory impact event as well as instructions indicating one or more diagnosis actions that the candidate node 322 can perform to enable the memory leak management system 106 to effectively monitor further memory usage data … In response to receiving the diagnosis command 314, agents 324 (the one or more collector) on the candidate node(s) 322 can collect additional memory usage data. In particular, each of multiple agents 324 can collect or sample different types of memory usage data; the agents 324 can sample memory usage data at predetermined intervals (e.g., every five minutes). See also Fig. 2. Examiner’s interpretation: The Examiner interpreted “sending a new sampling strategy to the one or more collector” as sending the diagnosis command to agent(s) to effectively monitor/collect additional memory usage data and perform new sampling using the additional memory usage data. In addition, the command is based on the severity score exceeding the threshold value over a time interval); request, by the one or more collectors, process information repeatedly from the device for a predetermined process information period of time (See Parag. [0038-0040]; the agents 304 (one or more collectors) may include a monitoring agent that collects process related performance counters associated with specific processes … The memory usage data 306 may refer to various types of information indicative of memory usage on the host nodes 302 (device). For example, the memory usage data 306 may include performance counters indicative of memory usage for specific processes … the agents 304 may obtain or capture snapshots of memory usage at points in time representative of allocation of memory blocks at the specific points in time; the agents 304 may capture a current status of memory allocation at five-minute intervals (a predetermined process information period of time). Examiner’s interpretation: In the context of network monitoring or application performance, obtaining snapshot data often involves making a request to retrieve that data). Chen doesn’t explicitly disclose the evaluated memory utilization over a predetermined time is an average memory utilization; the sampling strategy is non-uniform; [and] receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Jueping discloses monitor, by the stream processor, if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold (See Page 5, Lines 8-17 and 30-36; Get the CPU usage and memory usage of the controller; Define the time period T1 (predetermined time), and calculate the average memory usage and CPU usage in the previous T1 time period at the current time point; set the T1 time to 5 minutes … a third threshold (predetermined threshold) is set for the average usage rate of the memory, that is, within a certain period of time … when the average usage rate of the memory is greater than or equal to the third threshold, it indicates that the current resource load of the controller is relatively large). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the data aggregator determining if the aggregated memory usage data, over a predetermined interval, results in a severity score over a threshold value, taught by Chen, to monitor if an average memory utilization evaluated over a predetermined time crosses a predetermined threshold, as taught by Jueping. This would be convenient to indicate that the current resource load of the controller is relatively large; thus, no new network device audit operations are added (Jueping, See Page 5, Lines 30-36). Chen in view of Jueping doesn’t explicitly disclose the sampling strategy is non-uniform; [and] receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Song discloses send a non-uniform sampling strategy to the one or more collectors, if the memory utilization crosses the predetermined threshold (See Parag. [0004]; receiving, by a receiver of a controller, one or more congestion indicators from a collector. The method further comprises generating, by a processor of the controller, an adjusted sampling rate (dynamically adjust a sampling rate, See Parag. [0036]) of instruction header insertion for in-band network telemetry (INT) based on the congestion indicators ... transmitting, by a transmitter of the controller, the adjusted sampling rate to a head node configured to perform INT via instruction header insertion into user packets. For example, in some systems INT is performed at a head end node by inserting instruction headers into user packets. The instruction header directs each node in a path to collect indicated telemetry data and report such telemetry back to a collector ... See Parag. [0049]; adjust the sampling rate 143 in response to receiving a congestion indicator 141 indicating actual data loss (e.g., dropped packet) or predicted data loss (e.g., node status indicator such as buffer occupancy is in excess of a threshold) (memory utilization crosses the predetermined threshold). See also Parag. [0005] [0008] [0036] [0040] [0051] and Fig. 3). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the sampling strategy sent to the one or more collectors, taught by Chen in view of Jueping, as a non-uniform sampling strategy, as taught by Song. This would be convenient to allow for maximizing INT coverage over a network without negatively impacting user traffic forwarding (Song, See Parag. [0036]). The combination doesn’t explicitly disclose receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors. However, Myla discloses receive, by the stream processor, the process information repeatedly at a predetermined process information frequency from the one or more collectors (See Col. 4 lines 60-67 and Col. 5 lines 1-9; network device (the one or more collectors) may determine a first time interval (a predetermined process information frequency) (e.g., every 2 seconds, every 5 seconds, every 10 seconds, every 30 seconds, and/or the like) to collect and send the delta values of the telemetry data to the collector device (stream processor). See Col. 2 lines 24-40; The collector device analyzes the telemetry data to determine a status of the network device, a health of the network device, and/or the like ... Examiner’s interpretation: The Examiner interpreted the network device, taught by Myla, as a collector as it collects and sends the telemetry data including information of the one or more resources of the network device at a particular time to the collector device. In addition, the Examiner interpreted the collector device, taught by Myla, as a stream processor as it receives and analyzes the telemetry data to determine a status of the network device and a health of the network device). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the memory leak management system (the stream processor), taught by Chen in view of Jueping, to receive process information repeatedly at a predetermined process information frequency from the one or more collectors, as taught by Myla. This would be convenient to maintain and/or improve a performance of the network device (Myla, See Col. 2 lines 24-40). Claim 15 is taught by Chen in view of Jueping, Song, and Myla as described for claim 3. Claim 17 is taught by Chen in view of Jueping, Song, and Myla as described for claim 5. Claim 18 is taught by Chen in view of Jueping, Song, and Myla as described for claim 6. Claims 4, 10, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (Pub. No. US 2021/0334186), hereinafter Chen; in view of Jueping (Pub. CN115037621A, published on 09/09/2022); further in view of Song et al. (Pub. No. US 2021/0084530), hereinafter Song; further in view of Myla et al. (Patent No. US 11,405,261), hereinafter Myla; and further in view of Mazzaferri et al. (Pub. No. US 2007/0174429), hereinafter Mazzaferri. Claim 4. Chen in view of Jueping, Song, and Myla discloses [t]he method of claim 3, Chen discloses the method further comprising sending the memory utilization to the stream processor (See Parag. [0038]; the agents 304 may refer to different types of agents that provide memory usage data 306 to the memory leak management system 106 (the stream processor) (e.g., aggregation system 202) for further analysis). The combination doesn’t explicitly disclose periodically requesting memory utilization from the device, by the one or more collectors, approximately every 30 seconds. However, Mazzaferri discloses periodically requesting memory utilization from the device, by the one or more collectors, approximately every 30 seconds (See Parag. [0321]; operational meters are used by a LMS (load management subsystem) to measure server performance at predetermined intervals, which may be configured by an administrator. A LMS on each remote machine 30 in the machine farm 38 evaluates various performance metrics for the remote machine 30 for each predetermined period of time. For example, every thirty seconds, an evaluation of server load may include a query (periodically requesting) to operational meters for server's CPU utilization and memory utilization. See also Parag. [1179]). It would be obvious to one of ordinary skill in the art at the time before the effective filling date of the claimed invention to modify the monitoring agent (the one or more collectors) that collects process related performance counters associated with specific processes, taught by the combination, to periodically requesting memory utilization from the device approximately every 30 seconds, as taught by Mazzaferri. This would be convenient for providing a load management capability and manage overall server and network load to minimize response time to client requests (Mazzaferri, Parag. [0316]). Claim 10 is taught by Chen in view of Jueping, Song, Myla, and Mazzaferri as described for claim 4. Claim 16 is taught by Chen in view of Jueping, Song, Myla, and Mazzaferri as described for claim 4. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Ferreira et al. (Pub. No. US 2015/0074258) – Related art in the area of scalable performance monitoring using dynamic flow sampling, (Abstract; Techniques for scalable performance monitoring using dynamic flow sampling are described. According to one approach, a method comprises intercepting, at an intermediary network device, one or more packets traveling between a source device and a destination device; identifying, at the intermediary network device, a traffic flow based on the one or more packets; determining, at the intermediary network device, whether to collect one or more metrics from the traffic flow based on one or more performance factors of the intermediary network device; in response to a determination to collect the one or more metrics from the traffic flow, the intermediary network collecting the one or more metrics from subsequently intercepted packets belonging to the traffic flow; wherein the method is performed by one or more computing devices). Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDELBASST TALIOUA whose telephone number is (571)272-4061. The examiner can normally be reached on Monday-Thursday 7:30 am - 5:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the Examiner’s supervisor, Oscar Louie can be reached on 571-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Abdelbasst Talioua/ Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Jan 05, 2024
Application Filed
Mar 27, 2025
Non-Final Rejection mailed — §103, §112
Sep 29, 2025
Response Filed
Jan 14, 2026
Final Rejection mailed — §103, §112
May 14, 2026
Request for Continued Examination
May 22, 2026
Response after Non-Final Action
Jul 15, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683852
Root Cause and Impact Determination Based on Automated Service Identification
2y 6m to grant Granted Jul 14, 2026
Patent 12671621
System, Method, and Computer Program Product for Detecting an Anomaly in Network Activity
2y 4m to grant Granted Jun 30, 2026
Patent 12652251
SYSTEMS, METHODS, AND DEVICES FOR LOAD BALANCING IN MULTIPLANE NETWORKS
3y 2m to grant Granted Jun 09, 2026
Patent 12652324
METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR PRESERVING NETWORK BANDWIDTH DURING NETWORK ADDRESS TRANSLATION (NAT) DEVICE UNAVAILABILITY OR AFTER NAT DEVICE REBOOT
2y 5m to grant Granted Jun 09, 2026
Patent 12652213
SYSTEMS AND METHODS FOR ERROR CODE ANALYTICS IN TELECOMMUNICATIONS NETWORKS
2y 8m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
59%
Grant Probability
94%
With Interview (+35.0%)
3y 0m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 113 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month