Prosecution Insights
Last updated: October 02, 2026
Application No. 18/421,600

METHOD OF AUTOMATIC REMEDIATION OF MISSING OR CORRUPT AGENTS

Final Rejection §103
Filed
Jan 24, 2024
Examiner
XIE, EDGAR WANGSHU
Art Unit
2433
Tech Center
2400 — Computer Networks
Assignee
Saudi Arabian Oil Company
OA Round
4 (Final)
85%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
23 granted / 27 resolved
+27.2% vs TC avg
Strong +32% interview lift
Without
With
+32.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
3 currently pending
Career history
32
Total Applications
across all art units

Statute-Specific Performance

§101
14.4%
-25.6% vs TC avg
§103
61.9%
+21.9% vs TC avg
§102
8.3%
-31.7% vs TC avg
§112
11.3%
-28.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 27 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action Claims filed on 06/29/2026 for patent application 18/421,600 have been acknowledged. Claims 1-20 are currently pending and have been considered below. Claims 1, 9, and 13 are independent claims. Claims 1-3, 9, 13-15, and 18-19 have been amended. No new claims have been added. In view of amendments to claim 13, the 35 U.S.C. 101 rejection of 13-20 has been withdrawn. Response to Arguments Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the arguments. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 6-13, and 18-20 are rejected under 35 U.S.C. 103 as being anticipated by Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra). Regarding Claim 1, Thakur discloses: A method of automatic remediation of a first missing or corrupted agent comprising (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”): detecting the first missing or corrupted agent installed on a first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”), determining a first service, that is associated with the first missing or corrupted agent, is non- operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and restarting the non-operational first service on the first machine, wherein the automatic remediation comprises restarting the non-operational first service on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”); and reimaging the first machine, wherein the automatic remediation further comprises reimaging the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Thakur does not explicitly teach the following limitation that Mitra teaches: for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): redetecting the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetection.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing “for a detection count less than or equal to a threshold: for the detection count greater than the threshold: redetecting the first missing or corrupted agent installed on the first machine” Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]). Regarding Claim 6, Thakur in view of Mitra teaches: The method of claim 1, further comprising: detecting a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”); determining a second service associated with the second missing or corrupted agent is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”); and reinstalling the second missing or corrupted agent on the second machine, wherein the automatic remediation further comprises reinstalling the second missing or corrupted agent on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”). Regarding Claim 7, Thakur in view of Mitra teaches: The method of claim 6, further comprising: redetecting the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”); and reimaging the second machine, wherein the automatic remediation further comprises reimaging the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Regarding Claim 8, Thakur in view of Thakur teaches: The method of claim 1, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”). Regarding Claim 9, Thakur discloses: A method of automatic remediation of a first missing or corrupted agent comprising (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”): detecting the first missing or corrupted agent installed on a first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”), determining a first service, that is associated with the first missing or corrupted agent, is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and reinstalling the first missing or corrupted agent on the first machine, wherein the automatic remediation comprises reinstalling the first missing or corrupted agent on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”); and reimaging the first machine, wherein the automatic remediation further comprises reimaging the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Thakur does not explicitly teach the following limitation that Mitra teaches: for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): redetecting the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetection.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing “for a detection count less than or equal to a threshold: for the detection count greater than the threshold: redetecting the first missing or corrupted agent installed on the first machine” Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]). Regarding Claim 10, Thakur in view of Mitra teaches: The method of claim 9, further comprising: detecting a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”); determining a second service associated with the second missing or corrupted agent is non- operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”); and restarting the second service on the second machine, wherein the automatic remediation further comprises restarting the second service on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”). Regarding Claim 11, Thakur in view of Mitra teaches: The method of claim 10, further comprising: redetecting the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”); and reimaging the second machine, wherein the automatic remediation further comprises reimaging the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Regarding Claim 12, Thakur in view of Mitra teaches: The method of claim 9, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”). Regarding Claim 13, Thakur discloses: A system comprising: a server configured to detect a first missing or corrupted agent installed on a first machine, wherein the server is communicably coupled to the first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”); and a computer system configured to (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”): determine a first service, that is associated with the first missing or corrupted agent, is non-operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and restart the non-operational first service on the first machine, wherein automatic remediation comprises to restart the first service on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”), wherein the computer system is communicably coupled to the server, wherein the computer system is further configured to reimage the first machine, wherein the automatic remediation further comprises to reimage the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Thakur does not explicitly teach the following limitation that Mitra teaches: for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”): wherein the server is further configured to redetect the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetecting.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing “for a detection count less than or equal to a threshold: for the detection count greater than the threshold: redetecting the first missing or corrupted agent installed on the first machine” Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]). Regarding Claim 18, Thakur in view of Mitra teaches: The system of claim 13, wherein the server is further configured to detect a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”), wherein the server is further communicably coupled to the second machine, and wherein the computer system is further configured to: determine a second service associated with the second missing or corrupted agent is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and reinstall the second missing or corrupted agent on the second machine, wherein the automatic remediation further comprises to reinstall the second missing or corrupted agent on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”). Regarding Claim 19, Thakur in view of Mitra teaches: The system of claim 18, wherein the server is further configured to redetect the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”), wherein the computer system is further configured to reimage the second machine, and wherein the automatic remediation further comprises to reimage the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”). Regarding Claim 20, Thakur in view of Mitra teaches: The system of claim 13, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”). Claims 2-3 and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra) and further in view of Langton et al. (US Patent Application Publication No. US 2016/0292419 A1, hereinafter, Langton). Regarding Claim 2, Thakur in view of Mitra teaches: The method of claim 1, further comprising Thakur in view of Mitra does not explicitly teach the following limitation that Langton teaches: updating an agent repository comprising increasing the detection count associated with the first missing or corrupted agent by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”). Thakur in view of Mitra and and further in view of Langton is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “information security systems.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur in view of Mitra with Langton to “updating an agent repository comprising increasing a detection count associated with the first missing or corrupted agent by one” Because the device may identify a plurality of files for a multi-file malware analysis (Langton, Abstract). Regarding Claim 3, Thakur in view of Mitra and further in view of Langton teaches: The method of claim 2, wherein redetecting the first missing or corrupted agent comprises: updating the agent repository by increasing the detection count by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”). Regarding Claim 14, Thakur in view of Mitra and further in view of Langton teaches: The system of claim 13, wherein the computer system is further configured to update an agent repository comprising increasing the detection count associated with the first missing or corrupted agent by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”). Regarding Claim 15, Thakur in view of Mitra and further in view of Langton teaches: The system of claim 14, wherein to redetect the first missing or corrupted agent comprises: update the agent repository by increasing the detection count by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”). Claims 4-5 and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra) and further in view of Langton et al. (US Patent Application Publication No. US 2016/0292419 A1, hereinafter, Langton) and Adams et al. (US Patent No. US 9,729,572 B1, hereinafter, Adams). Regarding Claim 4, Thakur in view of Mitra and further in view of Langton teaches: The method of claim 2, wherein updating the agent repository further comprises Thakur in view of Mitra and further in view of Langton does not explicitly teach the following limitation that Adams teaches: notifying a user of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may notify a user of client device 210, when causing the one or more remediation actions to be executed.”). Thakur in view of Mitra and Further in view of Langton and Adams is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “information security systems.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur in view of Mitra and further in view of Langton with Adams to “notifying a user of the first machine that the first machine has the first missing or corrupted agent” Because the device may cause the one or more remediation actions to be executed (Adams, Abstract). Regarding Claim 5, Thakur in view of Mitra and further in view of Langton and Adams teaches: The method of claim 2, wherein updating the agent repository further comprises notifying a proponent of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may provide a notification to a user device associated with an IT agent, an administrator, or the like indicating that the one or more remediation actions have been selected and executed.”). Regarding Claim 16, Thakur in view of Mitra and further in view of Langton and Adams teaches: The system of claim 14, wherein to update the agent repository further comprises notifying a user of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may notify a user of client device 210, when causing the one or more remediation actions to be executed.”). Regarding Claim 17, Thakur in view of Mitra and further in view of Langton and Adams teaches: The system of claim 14, wherein to update the agent repository further comprises notifying a proponent of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may provide a notification to a user device associated with an IT agent, an administrator, or the like indicating that the one or more remediation actions have been selected and executed.”). CONCLUSION Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDGAR W XIE whose telephone number is (703)756-4777. The examiner can normally be reached Monday - Friday, 8:00am - 5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JEFFREY PWU can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EDGAR W XIE/Examiner, Art Unit 2433 /WASIKA NIPA/Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Show 5 earlier events
Sep 05, 2025
Response Filed
Nov 14, 2025
Final Rejection mailed — §103
Jan 07, 2026
Response after Non-Final Action
Feb 06, 2026
Request for Continued Examination
Feb 20, 2026
Response after Non-Final Action
Apr 08, 2026
Non-Final Rejection mailed — §103
Jun 29, 2026
Response Filed
Sep 10, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12717896
SYSTEM AND METHOD FOR SECURING A NEURAL NETWORK RUNTIME ENGINE
3y 0m to grant Granted Aug 25, 2026
Patent 12694122
SYSTEMS AND METHODS FOR REVERSE ENGINEERING-BASED DETECTION OF VULNERABILITIES
3y 0m to grant Granted Jul 28, 2026
Patent 12688281
AUTOMATED AI MODEL-BASED PIPELINE FOR DETECTION EXPLAINABILITY
2y 1m to grant Granted Jul 21, 2026
Patent 12682070
RETRAINING MACHINE LEARNING MODEL FOR COMPUTER VULNERABILITY EXPLOITATION DETECTION
3y 4m to grant Granted Jul 14, 2026
Patent 12670244
HUMAN INTERFACE DEVICE FIREWALL
2y 8m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+32.2%)
2y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 27 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month