Prosecution Insights
Last updated: October 01, 2026
Application No. 18/425,498

SECURITY ALERTS ACROSS ORGANIZATIONS

Non-Final OA §103
Filed
Jan 29, 2024
Examiner
TRUONG, LAWRENCE QUANG
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Google LLC
OA Round
3 (Non-Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
74%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
14 granted / 16 resolved
+29.5% vs TC avg
Minimal -13% lift
Without
With
+-13.3%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
14 currently pending
Career history
42
Total Applications
across all art units

Statute-Specific Performance

§101
10.7%
-29.3% vs TC avg
§103
51.9%
+11.9% vs TC avg
§102
9.1%
-30.9% vs TC avg
§112
24.6%
-15.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 16 resolved cases

Office Action

§103
DETAILED ACTION Claim 6 is canceled. Claims 1-5 and 7-20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/30/2026 has been entered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 03/30/2026 has been considered by the examiner. Response to Arguments Applicant's arguments filed 03/30/2026 have been fully considered. Regarding Applicant’s argument that Humphrey and Petit do not teach the all the amended limitations of claim 1, Examiner agrees, however, this argument is moot in view of new grounds of rejection. The dependent claims inherit this rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6, 11-15, 17, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Levin et al. (US Pat. Pub. No. 20200310889) in view of Humphrey et al. (US Pat. Pub. No. 20230012220), and in further view of Vaswani et al. (US Pat. Pub. No. 20220377090). Re Claim 1. Levin teaches a method comprising: obtaining a first set of data pertaining to a first alert generated with respect to first malicious activity relating to a first set of computing devices of a first entity (Levin [0037], e.g., The UI 218 provides a view of alerts 220 for cloud resources accessible by the user and respective feedback controls 222 for the alerts 220. Each alert 220 regards a detected anomalous behavior performed on a cloud resource associated with the user (to which the user has access)), the first set of data comprising: the first alert (Levin [0037], e.g., Each alert 220 regards a detected anomalous behavior performed on a cloud resource associated with the user (to which the user has access); first metadata for the first malicious activity associated with the first alert (Levin [0037], e.g., The alert 220 can include an indication of a type of anomalous operation performed on the resource. Types of anomalous operations include, for example a fuzzing attempt (inputting a large amount of random data (called fuzz) to test the subject in an attempt to make it crash), a failed login attempt (or number of failed login attempts), an unrecognized Internet Protocol (IP) address attempted access, a data exfiltration operation, an unrecognized device attempted access, an application attempted to access an unauthorized port, a cloud resource was accessed an abnormal number of times in a specified time, or the like); and first user feedback relating to the first alert and provided by a first user associated with the first entity (Levin [0038], e.g., The UI 218 includes a software control 222 which allows a user to provide feedback regarding an associated alert 220; [0039], e.g., The feedback can include one or more of: (1) false positive (indicating that the alert was triggered but the anomalous behavior or the effect of the anomalous behavior was not present); (2) true positive (the alert was provided and the anomalous behavior or the effect of the anomalous behavior was present); (3) useful (the user found the alert to be helpful, this is sometimes referred to as “relevant”); (4) not useful (the user found the alert to be irrelevant, this is sometimes referred to as “not relevant”); or a combination thereof)[, the first user feedback indicating whether the first alert required action by the first user with respect to the first malicious activity relating to the first set of computing devices of the first entity]; and identifying second malicious activity relating to a second set of computing devices of a second entity, the second malicious activity having second metadata (Levin [0058], e.g., The alert generator circuitry 356 can receive or retrieve a behavior 354… determining the behavior 354 is consistent with an attack or adverse operation on a cloud resource), wherein the first entity and the second entity represent different organizations (Levin [0023], e.g., Rather than maintaining their own data centers, many enterprises (cloud customers) subscribe as customers of a database service of the cloud service system 100 to store and process their data. For example, a retail company may subscribe to a database service… As another example, a utility company may subscribe to a database service… As yet another example, a governmental entity may subscribe to a database service; [0050], e.g., A similar user or organization is one with one or more same characteristics as the user or organization in question. The characteristics can include behaviors of the user or organization); generating a first similarity score based on a comparison of [the first metadata for the first malicious activity relating to the first set of computing devices of] the first entity and [the second metadata for the second malicious activity relating to the second set of computing devices of] the second entity (Levin [0050], e.g., A similar user or organization is one with one or more same characteristics as the user or organization in question. The characteristics can include behaviors of the user or organization. Such characteristics can include one or more of resource access, account type, resource subscription, number of cloud resources subscribed to, time of access of cloud resources, size (e.g., number of employees) of the organization, or the like. The characteristics can additionally or alternatively include feedback provided by the user. The feedback can include alerts that were dismissed, alerts deemed not relevant, alerts deemed relevant, or other feedback; [0051], e.g., Similar users or organizations can be identified using collaborative filtering or other embedding technique); and responsive to the first similarity score satisfying a similarity criterion (Levin [0051], e.g., Similar users or organizations can be identified using collaborative filtering or other embedding technique; [0057], e.g., The user alert profile generator 226 can generate the alert rules 232 as discussed regarding FIG. 2. The user alert profile generator 226 can retrieve feedback from similar users on similar alerts 352 from the profile database 236), causing a second alert generated with respect to the second malicious activity relating to the second set of computing devices of the second entity (Levin [0058], e.g., The alert generator circuitry 356 can receive or retrieve a behavior 354 and generate an alert 220. The alert generator circuitry 356 can generate the alert 220 in response to determining the behavior 354 is consistent with an attack or adverse operation on a cloud resource) to be associated with first alert properties defined based on the first user feedback relating to the first alert and provided by the first user associated with the first entity (Levin [0058], e.g., The alert generator circuitry 356 can determine a score to be associated with the alert 220 based on the alert rules 232. The scored alert 358 can include the alert 220 along with an associated score. The score can indicate a relative importance of the alert 220 to the user based on the alert rules 232. As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa; [0072], e.g., The method 500 can further include generating, for a second, different user (the another user), and based on the feedback from the user, a second alert), wherein at least one value of the first alert properties associated with the second alert generated with respect to the second malicious activity relating to the second set of computing devices of the second entity is adjusted according to the first user feedback [indicating whether the first alert required action by the first user with respect to the first malicious activity relating to the first set of computing devices of the first entity] (Levin [0058], e.g., As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa; [0005], e.g., The feedback can include data indicating whether the alert is relevant to the first cloud user, not relevant to the first cloud user, the security alert is a false positive, or the security alert is a true positive. Generating the second alert can include altering a score associated with the second alert based on the feedback from the first cloud user; [0074], e.g., The method 500 can further include, wherein generating the second alert includes altering a score associated with the second alert based on the feedback from the first customer). Levin teaches comparing similar users or organizations with other users and organizations, but does not explicitly teach comparing metadata of first malicious activity with metadata of a second malicious activity. However, Humphrey teaches generating a first similarity score based on a comparison of the first metadata for the first malicious activity relating to the first set of computing devices of the first entity and the second metadata for the second malicious activity relating to the second set of computing devices of the second entity (Humphrey [0007], e.g., The first and second abnormal behavior patterns can be compared to determine a similarity score between the first and second abnormal behavior patterns). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Levin with the teachings of Humphrey with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of identifying novel attacks before they can cause harm (Humphrey [0015], e.g., In this manner, rather than specific attacks being identified based on a series of parameters or hallmarks, behavior can be linked to a specific threat actor. This can enable novel attacks to be identified before they can cause harm by identifying the behavior as being that of a hostile actor, potentially even before any harmful activity has been carried out) and advantageously allowing comparison of abnormal behavior patterns regardless of whether the patterns correspond to the same or different network (Humphrey [0012], e.g., Accordingly, it can be seen that the cyber threat defense system can generate the second abnormal behavior pattern in a similar or the same way as the first abnormal behavior pattern, advantageously allowing a good comparison of the two abnormal behavior patterns, regardless of whether the first and second abnormal behavior patterns correspond to behavior on the same network or different networks). Levin teaches that the user feedback can include alerts that were dismissed, alerts deemed not relevant, alerts deemed relevant, or other feedback, but does not explicitly teach user feedback indicating a required action. However Vaswani teaches the first user feedback indicating whether the first alert required action by the first user with respect to the first malicious activity relating to the first set of computing devices of the first entity (Vaswani [0089], e.g., In the Feedback panel 1260, the auditor is presented with various options to react to the alert, and with various information about how others have reacted to the alert. In the feedback viewing section 1262, actions by other auditors and supervisors related to the alert are summarized. An auditor may also add comments via a feedback box provided in the feedback viewing section 1262 that will be shown to others reviewing that alert, including, for example, other auditors or supervisors. Specifically, an auditor may use the feedback box to include information related to the entity's activity when escalating an alert, thus ensuring that the supervisor reviewing the escalated alert is presented with the contextual information as provided by the warning system as well as any remarks or annotations by the auditor having already reviewed the alert… The action button 1264 allows the auditor to take action regarding the alert, such as to escalate the alert to a supervisor or to dismiss the alert). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the combined teachings of Levin and Humphrey with the teachings of Vaswani with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of increasing effective information sharing and improving collaboration (Vaswani [0089], e.g., Specifically, an auditor may use the feedback box to include information related to the entity's activity when escalating an alert, thus ensuring that the supervisor reviewing the escalated alert is presented with the contextual information as provided by the warning system as well as any remarks or annotations by the auditor having already reviewed the alert. Advantageously, this allows for more effective information sharing and thus easier collaboration between auditors). Re Claim 2. Levin teaches the method of claim 1, wherein the at least one value of the first alert properties comprises at least one of: a severity value; a priority value; a risk value; a confidence value; or a usefulness value. (Levin [0040], e.g., In some embodiments, further details regarding a security alert 220 can be provided in response to a user in response to selection of the security alert 220. The details can identify the cloud resource, the action performed, a time or date on which the action was detected, a severity score indicating how much damage the operation can cause, a confidence associated with the detection (a percentage, decimal value, integer value, or the like), or a combination thereof). Re Claim 3. Levin teaches the method of claim 1, wherein: the first alert is associated with second alert properties (Levin [0074], e.g., The method 500 can further include, wherein generating the second alert includes altering a score associated with the second alert based on the feedback from the first customer); the first user feedback relating to the first alert and provided by the first user associated with the first entity comprises positive feedback (Levin [0058], e.g., As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa); and at least a first property of the first alert properties has a higher value than at least a second property of the second alert properties (Levin [0058], e.g., As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa). Re Claim 4. Levin teaches The method of claim 1, wherein: the first alert is associated with second alert properties (Levin [0074], e.g., The method 500 can further include, wherein generating the second alert includes altering a score associated with the second alert based on the feedback from the first customer); the first user feedback relating to the first alert and provided by the first user associated with the first entity comprises negative feedback (Levin [0058], e.g., As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa); and at least a first property of the first alert properties has a lower value than at least a second property of the second alert properties (Levin [0058], e.g., As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa). Re Claim 11. Levin teaches the method of claim 1, further comprising identifying third malicious activity relating to a third set of computing devices of a third entity, the third malicious activity having third metadata (Levin [0058], e.g., The alert generator circuitry 356 can receive or retrieve a behavior 354… determining the behavior 354 is consistent with an attack or adverse operation on a cloud resource); generating a second similarity score based on a comparison [of the first metadata for the first malicious activity and the third metadata for the third malicious activity] (Levin [0050], e.g., A similar user or organization is one with one or more same characteristics as the user or organization in question. The characteristics can include behaviors of the user or organization. Such characteristics can include one or more of resource access, account type, resource subscription, number of cloud resources subscribed to, time of access of cloud resources, size (e.g., number of employees) of the organization, or the like. The characteristics can additionally or alternatively include feedback provided by the user. The feedback can include alerts that were dismissed, alerts deemed not relevant, alerts deemed relevant, or other feedback; [0051], e.g., Similar users or organizations can be identified using collaborative filtering or other embedding technique); and responsive to the second similarity score satisfying the similarity criterion (Levin [0051], e.g., Similar users or organizations can be identified using collaborative filtering or other embedding technique; [0057], e.g., The user alert profile generator 226 can generate the alert rules 232 as discussed regarding FIG. 2. The user alert profile generator 226 can retrieve feedback from similar users on similar alerts 352 from the profile database 236), causing a third alert generated with respect to the third malicious activity relating to the third set of computing devices of the third entity (Levin [0058], e.g., The alert generator circuitry 356 can receive or retrieve a behavior 354 and generate an alert 220. The alert generator circuitry 356 can generate the alert 220 in response to determining the behavior 354 is consistent with an attack or adverse operation on a cloud resource) to be associated with second alert properties defined based on the first user feedback relating to the first alert and provided by the first user associated with the first entity and with third alert properties defined based on the third malicious activity (Levin [0058], e.g., The alert generator circuitry 356 can determine a score to be associated with the alert 220 based on the alert rules 232. The scored alert 358 can include the alert 220 along with an associated score. The score can indicate a relative importance of the alert 220 to the user based on the alert rules 232. As previously discussed, the alert rules 232 can be determined based on feedback from the user alone, a similar user, or a combination thereof. The score can include, for example, a lower relative number for an alert that the user has previously deemed not relevant and a higher relative number for an alert that the user has previously deemed relevant, or vice versa; [0072], e.g., The method 500 can further include generating, for a second, different user (the another user), and based on the feedback from the user, a second alert; Note that claim 11 is similar to the second portion of claim 1, with respect to the third malicious activity). Levin teaches comparing similar users or organizations with other users and organizations, but does not explicitly teach comparing metadata of first malicious activity with metadata of a second malicious activity. However, Humphrey teaches generating a second similarity score based on a comparison of the first metadata for the first malicious activity and the third metadata for the third malicious activity (Humphrey [0007], e.g., The first and second abnormal behavior patterns can be compared to determine a similarity score between the first and second abnormal behavior patterns). The motivation to combine Humphrey is the same as that of claim 1. Re Claim 12, Levin teaches a system comprising: a memory device (Levin [0015], e.g., The software may include computer executable instructions stored on computer or other machine-readable media or storage device, such as one or more non-transitory memories (e.g., a non-transitory machine-readable media) or other type of hardware-based storage devices); and a processing device coupled to the memory device, the processing device to perform operations (Levin [0015], e.g., The software may be executed on a digital signal processor, application specific integrated circuit (ASIC), microprocessor, central processing unit (CPU), graphics processing unit (GPU), field programmable gate array (FPGA), or other type of processor operating on a computer system). The rest of the claim recites similar language to claim, therefore, it is rejected in a similar manner. Re Claims 13-15 and 17. The claims recite similar features to those of claims 2-4 and 6 respectively, therefore the claims the rejected in a similar manner. Re Claim 20. Levin teaches a non-transitory computer-readable storage medium comprising instruction instructions that, when executed by a processing device, cause the processing device to perform operations (Levin [0015], e.g., The software may include computer executable instructions stored on computer or other machine-readable media or storage device, such as one or more non-transitory memories (e.g., a non-transitory machine-readable media) or other type of hardware-based storage devices… The software may be executed on a digital signal processor, application specific integrated circuit (ASIC), microprocessor, central processing unit (CPU), graphics processing unit (GPU), field programmable gate array (FPGA), or other type of processor operating on a computer system). The rest of the claim recites similar features to claim 1, therefore, it is rejected in a similar manner. Claim(s) 5, 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Levin, in view of Humphrey and Vaswani, and in further view of Reybok et al. (US Pat. Pub. No. 20170171231). Re Claim 5. Levin, Humphrey and Vaswani do not explicitly teach, but Reybok teaches the method of claim 1, further comprising: obtaining second user feedback relating to the second alert and provided by a second user associated with the second entity (Reybok [0070], e.g., if networks NET1 402a and NET2 402b have already reported data including the depicted threats 409, 410, and 411 to the central service 403); identifying third malicious activity relating to a third set of computing devices of a third entity (Reybok [0070], e.g., network NETn 402c subsequently experiences its depicted events 411; [0068], e.g., NETn 402c might experience yet another set of security events including Threat A 409 and Threat C), the third malicious activity having third metadata (Reybok [0068], e.g., NETn 402c might experience yet another set of security events including Threat A 409 and Threat C; this data represents a risk to its networks); generating a second similarity score based on a comparison of the first metadata for the first malicious activity, the second metadata for the second malicious activity, and the third metadata for the third malicious activity (Reybok [0070], e.g., the hub 403 can formulate its own threat score (e.g., for Threat A 409) based on correlation of data reported by networks NET1 402a and NETn 402c and, if it determines that a threshold has been met for this score, it can query network NET2 402b and ask it to perform local searching for indicators associated with this threat, and responsively update its score based on the results); and responsive to the second similarity score satisfying the similarity criterion (Reybok [0070], e.g., if it determines that a threshold has been met for this score, it can query network NET2 402b and ask it to perform local searching for indicators associated with this threat), causing a third alert generated with respect to the third malicious activity relating to the third set of computing devices of the third entity to be associated with second alert properties defined based on a combination of the first user feedback relating to the first alert and provided by the first user associated with the first entity and the second user feedback relating to the second alert and provided by the second user associated with the second entity (Reybok [0070], e.g., NETn 402c might want to be notified of the common threat (Threat C 411) to network NET2 402b, or alternatively, it might want to be notified if both networks NET1 402a and NET2 402b experience the same security event (e.g., Threat B 410); Examiner’s note: NETn makes a decision based on feedback from NET1 and NET2). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Levin, Humphrey and Vaswani with the teachings of Reybok with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of timely obtaining updated information regarding fast evolving network security threats (Reybok [0030], e.g., Systems and methods described herein may address the problem of the persistent need for timely updated information regarding fast evolving network security threats that are endemic in a wide area network (e.g., the Internet). Network threat information is received from many different client networks and aggregated by a central hub. For example, information about a new threat may be correlated with a group of similar client networks that are serviced by the hub). Re Claim 16. The claim recites similar features to claim 5, therefore, it is rejected in a similar manner. Claim(s) 7-9, 18-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Levin, in view of Humphrey and Vaswani, and in further view of Jennings et al. (US Pat. Pub. No. 20230019837). Re Claim 7. Levin does not explicitly teach, but Humphrey teaches the method of claim 1, wherein generating the first similarity score comprises: applying a machine learning model to the first metadata for the first malicious activity to obtain a first encoding (Humphrey [0125-0126], e.g., The first abnormal behavior pattern represents behavior on a first network deviating from a normal benign behavior of that network. The abnormal behavior pattern is an encoding of metadata……… Receiving the first abnormal behavior pattern comprises comparing input data monitoring the first network to at least one machine-learning model trained on a normal benign behavior of the first network using a normal behavior benchmark describing parameters corresponding to a normal pattern of activity of the first network to determine that a network behavior of the first network deviates from the normal benign behavior of the first network (Block 602)); applying the machine learning model to the second metadata for the second malicious activity to obtain a second encoding (Humphrey [0139], e.g., A second abnormal behavior pattern is received (Block 608). Like the first abnormal behavior pattern, the second abnormal behavior pattern represents behavior on a network deviating from a normal benign behavior of that network. The network in this case may be the same network that the first abnormal behavior relates to or a different network); [and computing a distance between the first encoding and the second encoding, the distance representing the first similarity score]. The motivation to combine Humphrey is the same as that of claim 1. Levin, Humphrey, and Vaswani does not explicitly teach, but Jennings teaches computing a distance between the first encoding and the second encoding, the distance representing the first similarity score (Jennings [0057], e.g., In an embodiment, and without limitation, string distance may be calculated as a function of a name matching algorithm, wherein name matching algorithm includes any of the name matching algorithm as described in FIG. 1. In another embodiment, and without limitation, name matching algorithm may include a distance algorithm, wherein the distance algorithm is extended to as many dimensions). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Levin, Humphrey, and Vaswani with the teachings of Jennings with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of improving matching (Jennings [0036], e.g., Additionally, name matching algorithm may average different algorithms as well as dividing by total character count to compute a percentage can also improve matching). Re Claim 8. Levin, Humphrey, and Vaswani do not explicitly teach, but Jennings the method of claim 1, wherein generating the first similarity score comprises: calculating a first distance between a first data of the first metadata for the first malicious activity and a second data of the second metadata for the second malicious activity (Jennings [0057], e.g., In an embodiment, and without limitation, string distance may be calculated as a function of a name matching algorithm, wherein name matching algorithm includes any of the name matching algorithm as described in FIG. 1. In another embodiment, and without limitation, name matching algorithm may include a distance algorithm, wherein the distance algorithm is extended to as many dimensions… ); calculating a second distance between a third data of the first metadata for the first malicious activity and a fourth data of the second metadata for the second malicious activity (Jennings [0057], e.g., a distance algorithm, wherein the distance algorithm is extended to as many dimensions); and combining the first distance and the second distance to obtain a third distance, the third distance representing the first similarity score (Jennings [0057], e.g., In an embodiment, and without limitation, string distance may be determined as a function of combining the distance of two parameters to determine a combined distance for comparing two software components). The motivation to combine Jennings is the same as that of claim 7. Re Claim 9. Levin, Humphrey, and Vaswani do not explicitly teach, but Jennings teaches the method of claim 8, wherein the combining the first distance and the second distance comprises at least one of: calculating a sum of the first distance and the second distance; calculating a max value of the first distance and the second distance; calculating an average of the first distance and the second distance; or calculating a linear combination of the first distance and the second distance (Jennings [0041], e.g., vector similarity may alternatively or additionally be determined using averages of similarities between like attributes). The motivation to combine Jennings is the same as that of claim 7. Re Claim 18 and 19. The claims recite similar features to those of claims 7 and 8 respectively, therefore, the claims are rejected in a similar manner. Claim(s) 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Levin, in view of Humphrey and Vaswani, and in further view of Liburdi et al. (US Pat. Pub. No. 20240422175). Re Claim 10. Levin, Humphrey, and Vaswani do not explicitly teach, but Liburdi teaches the method of claim 1, wherein causing the second alert generated with respect to the second malicious activity relating to the second set of computing devices of the second entity to be associated with first alert properties defined based on the first user feedback relating to the first alert and provided by the first user associated with the first entity results in the second alert being suppressed (Liburdi [0013], e.g., For example, where another past alert with the same or similar name was previously seen by a user and suppressed, the alert management system may suppress the new alert). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Levin, Humphrey, and Vaswani with the teachings of Liburdi with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of reducing computational processing and memory use, while also improving the efficiency of the system (Liburdi [0013], e.g., As such, the service provider may provide automated processes for suppression and deduplication of alerts, which can improve the functionality and efficiency of computer systems tasked with handling alerts by reducing computational processing and memory use). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Manadhata et al. (US Pat. Pub. No. 20180219911) discloses in some examples, an alert relating to an issue in a computing arrangement is received. It is determined that the received alert is similar to a given alert in an information repository containing information of past processes performed to address respective issues, the determining comprising comparing a property associated with the received alert to a property of alerts associated with the past processes, and the information contained in the information repository comprising actions taken in the past processes to address the respective issues. Performance of a remediation action is triggered that comprises an action, identified by the information in the information repository, taken to respond to the given alert [abstract]. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to LAWRENCE TRUONG whose telephone number is (571)272-6973. The examiner can normally be reached Monday - Friday, 8:00 am - 4 pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /LAWRENCE TRUONG/Examiner, Art Unit 2434 /ALI SHAYANFAR/Supervisory Patent Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Show 2 earlier events
Oct 07, 2025
Response Filed
Dec 29, 2025
Final Rejection mailed — §103
Feb 09, 2026
Interview Requested
Feb 19, 2026
Applicant Interview (Telephonic)
Feb 19, 2026
Examiner Interview Summary
Mar 30, 2026
Request for Continued Examination
Apr 07, 2026
Response after Non-Final Action
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688270
SYSTEMS AND METHODS FOR HUMAN-MOUNTED BIOSENSORS AND PROCESSING BIOSENSOR INFORMATION
2y 10m to grant Granted Jul 21, 2026
Patent 12676897
SYSTEMS AND METHODS FOR APPLYING POLICIES IN A DATACENTER ENVIRONMENT
1y 10m to grant Granted Jul 07, 2026
Patent 12647249
ENCRYPTION PROCESSING APPARATUS AND ENCRYPTION PROCESSING METHOD
2y 6m to grant Granted Jun 02, 2026
Patent 12619697
IDENTITY RECOGNITION METHOD AND APPARATUS, AND FEATURE EXTRACTION METHOD AND APPARATUS FOR BIOMETRIC PATTERN INFORMATION
2y 6m to grant Granted May 05, 2026
Patent 12608704
METHOD OF CONTRACTING RESERVES WITH SINGLE TRANSACTION IN RESPONSE TO A PLURALITY OF CONTRACT REQUESTS
2y 4m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
74%
With Interview (-13.3%)
2y 1m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 16 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month