DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/19/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 2, 4-7, 10, 12-13, and 15-20 are rejected under 35 U.S.C. 101 because the claimed invention recites a judicial exception, is directed to that judicial exception, an abstract idea, as it has not been integrated into a practical application and the claims do not recite significantly more than the judicial exception. The examiner has evaluated the claims under the framework provided in the 2019 Patent Eligibility Guidance published in the Federal Register 01/07/2019 and has provided such analysis below.
Claims 1, 2, 4-7, and 10 are directed to a method and fall within the statutory category of processes, claims 12-13, and 15-19 are directed to a system and fall within the statutory category of machines, and claim 20 is directed to a medium and falls within the statutory category of manufactures. Therefore, “Are the claims to a process, machine, manufacture, or composition of matter?” Yes.
In order to evaluate the Step 2A inquiry “Is the claim directed to a law of nature, a natural phenomenon, or an abstract idea?” we must determine, at Step 2A Prong 1, whether the claim recites a law of nature, a natural phenomenon, or an abstract idea and further whether the claim recites additional elements that integrate the judicial exception into a practical application.
Step 2A Prong 1:
Claims 1, 12, and 20: The limitation “determining that a first number of alerts generated for the first attack phase based on a set of detection operations and a second number of alerts generated for the third attack phase based on the set of detection operations each satisfy a threshold criterion”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate a set of detection operations and mentally determine, with or without the use of pen and paper, the first and third attack phases satisfy a threshold criterion. The limitation “determining that a third number of alerts generated for the second attack phase based on the set of detection operations fails to satisfy the threshold criterion, wherein failure of the third number of alerts to satisfy the threshold criterion indicates a gap in alert generation for the second attack phase using the set of detection operations”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate the set of detection operations and mentally determine, with or without the use of pen and paper, the second attack phase fails to satisfy the threshold criterion. The limitation “causing the set of detection operations to be modified to detect future malicious activities corresponding to the second attack phase in view of the indicated gap in the alert generation for the second attack phase using the set of detection operations”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate the second attack phase and mentally determine, with or without the use of pen and paper, the set of detection operations is to be modified to detect future malicious activities corresponding to the second attack phase.
Therefore, yes, claims 1, 12, and 20 recite judicial exceptions.
Step 2A Prong 2:
Claims 1, 12, and 20: The judicial exception is not integrated into a practical application. In particular, the claims recite the following additional elements – (1) “obtaining a first attack sequence associated with a first entity, the first attack sequence comprising at least a first attack phase, a second attack phase, and a third attack phase that each correspond to a different phase of a malicious attack that has occurred with respect to the first entity”, (2) “at least one hardware processor”, (3) “a memory device”, (4) “a processing device coupled to the memory device, the processing device configured to perform operations”, and (5) “a non-transitory computer-readable storage medium comprising instruction that, when executed by a processing device, cause the processing device to perform operations”. Element (1) is merely insignificant data gathering activity (see MPEP § 2106.05(g)) which does not integrate a judicial exception into a practical application and is also well-understood, routine, and conventional (see MPEP § 2106.05(d)(II): “The courts have recognized the following computer functions as well-understood, routing, and conventional functions when they are claimed in a merely generic manner (e.g., at a high level of granularity) or as insignificant extra-solution activity (i. Receiving or transmitting data over a network, e.g., using the Internet to gather data)”. That is, in the instant claims, this limitation merely receive or transmit/provide data which is well-understood, routine, and conventional. Elements (2)-(5) are merely recitations of generic computing components and functions being used as a tool to apply the abstract idea (see MPEP § 2106.05(f)), which does not integrate a judicial exception into a practical application.
Therefore, “Do the claims recite additional elements that integrate the judicial exception into a practical application?” No, these additional elements do not integrate the abstract idea into a practical application and they do not impose any meaningful limits on practicing the abstract idea. The claims are directed to an abstract idea.
After evaluating the inquiries set forth in Steps 2A Prongs 1 and 2, it has been concluded that claims 1, 12, and 20 not only recite a judicial exception but that the claims are directed to the judicial exception as the judicial exception has not been integrated into a practical application.
Step 2B:
Claims 1, 12, and 20: The claims do not recite additional elements, alone or in combination, that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements amount to no more than generic computing components and insignificant extra-solution activity which do not amount to significantly more than the abstract idea.
Therefore, “Do the claims recite additional elements that amount to significantly more than the judicial exception?” No, these additional elements, alone or in combination, do not amount to significantly more than the judicial exception.
Having concluded analysis within the provided framework, claims 1, 12, and 20 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 2 and 13, the limitation “associating the first alert with the first attack phase based on one or more properties of the first alert”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate one or more properties of a first alert and mentally associate, with or without the use of pen and paper, the first alert with the first attack phase. Claim 2 and 13 further recite the limitation “associating the second alert with the third attack phase based on one or more properties of the second alert”, which as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate one or more properties of a second alert and mentally associate, with or without the use of pen and paper, the second alert with the third attack phase. Claims 2 and 13 recite the additional element “obtaining a plurality of generated alerts comprising at least a first alert and a second alert”, which is merely insignificant data gathering activity (see MPEP § 2106.05(g)) which does not integrate a judicial exception into a practical application and is also well-understood, routine, and conventional (see MPEP § 2106.05(d)(II): “The courts have recognized the following computer functions as well-understood, routing, and conventional functions when they are claimed in a merely generic manner (e.g., at a high level of granularity) or as insignificant extra-solution activity (i. Receiving or transmitting data over a network, e.g., using the Internet to gather data)”. That is, in the instant claims, this limitation merely receives or transmits/provides data which is well-understood, routine, and conventional. Claims 2 and 13 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 2 and 13 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 2 and 13 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 4 and 15, the limitation “identifying within event logs one or more events associated with the second attack phase”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate event logs and mentally identify, with or without the use of pen and paper, one or more events associated with the second attack phase. Claims 4 and 15 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 4 and 15 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 4 and 15 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 5 and 16, the limitation “identifying a first event with a first event metadata value that satisfies a magnitude criterion”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate a magnitude criterion and mentally identify, with or without the use of pen and paper, a first event with a first event metadata value that satisfies the magnitude criterion. Claim 5 and 16 further recite the limitation “identifying a second event with a second event metadata value that satisfies a baseline-deviation criterion”, which as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate a baseline-deviation criterion and mentally identify, with or without the use of pen and paper, a second event with a second event metadata value that satisfies the baseline-deviation criterion. Claims 5 and 16 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 5 and 16 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 5 and 16 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 6 and 17, the limitation “identifying a third event of the first entity with a third event metadata value that matches a corresponding event metadata value of the external event”, as drafted, is a process that, but for the recitation of generic computing components, under its broadest reasonable interpretation, covers performance of the limitation in the mind. For example, a person can think and observe, judge and evaluate a third event of the first entity with a third event metadata value and a corresponding event metadata value of the external event and mentally identify, with or without the use of pen and paper, a match. Claims 6 and 17 further recites the additional element “obtaining an external alert associated with a second entity, the external alert having an associated external event”, which is merely insignificant data gathering activity (see MPEP § 2106.05(g)) which does not integrate a judicial exception into a practical application and is also well-understood, routine, and conventional (see MPEP § 2106.05(d)(II): “The courts have recognized the following computer functions as well-understood, routing, and conventional functions when they are claimed in a merely generic manner (e.g., at a high level of granularity) or as insignificant extra-solution activity (i. Receiving or transmitting data over a network, e.g., using the Internet to gather data)”. That is, in the instant claims, this limitation merely receives or transmits/provides data which is well-understood, routine, and conventional. Claims 6 and 17 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 6 and 17 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 6 and 17 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 7 and 18, the additional element “wherein the set of detection operations is based at least on a first malicious activity detection rule corresponding to the first attack phase and a second malicious activity detection rule corresponding to the third attack phase”, which is merely a recitation of field of use/technological environment (see MPEP § 2106.05(h)) which does not integrate a judicial exception into a practical application. Claims 7 and 18 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 7 and 18 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 7 and 18 do not recite patent eligible subject matter under 35 USC 101.
With regard to claims 10 and 19, the additional element “wherein the set of detection operations is based at least on a first machine learning model trained to identify malicious activity associated with the first attack phase and a second machine learning model trained to identify malicious activity associated with the third attack phase”, which is merely a recitation of field of use/technological environment (see MPEP § 2106.05(h)) which does not integrate a judicial exception into a practical application. Claims 10 and 19 do not recite any further additional elements and for the same reasons as above with regard to integration into a practical application and whether additional elements amount to significantly more, claims 10 and 19 fail both Step 2A Prong 2 for being directed to a judicial exception that has not been integrated into a practical application and Step 2B for not amounting to significantly more. Therefore, claims 10 and 19 do not recite patent eligible subject matter under 35 USC 101.
Therefore, claims 1, 2, 4-7, 10, 12-13, and 15-20 do not recite patent eligible subject matter under 35 USC 101.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Black et al. (U.S. Patent Application Publication No. 2021/0320945, hereinafter “Black”) in view of Meir et al. (U.S. Patent Application Publication No. 2021/0067531, hereinafter “Meir”).
Claims 1, 12, and 20:
Black discloses a system comprising:
a memory device (§ 0010, Lines 1-4; Method S100 can be executed by a computer system, which includes at least a memory); and
a processing device coupled to the memory device (§ 0010, Lines 1-4; Method S100 can be executed by a computer system, which includes at least a processor coupled to the memory), the processing device to perform operations comprising:
obtaining a first attack sequence associated with a first entity (§ 0024, Lines 4-7; An “asset” is referred to herein as a machine loaded with attack simulation software and configured to execute actions prescribed by a phase of an attack validation scenario), the first attack sequence comprising at least a first attack phase, a second attack phase, and a third attack phase that each correspond to a different phase of a malicious attack (§ 0015, Lines 1-5; The computer system can generate an attack validation scenario containing a set of phases that, in aggregate, trigger assets on the computer network to execute a sequence of actions analogous to an attack, a security threat, or other risky activity on the computer network) (§ 0031, Lines 1-4; An attack validation scenario includes a sequence of phases executable by one or more assets on the computer network to generate network actions that mimic malicious phases of an attack on the network) (See Fig. 1, which illustrates an attack validation scenario including Phase #1, Phase #2, and so on…);
determining that a first number of alerts generated for the first attack phase based on a set of detection operations and a second number of alerts generated for the third attack phase based on the set of detection operations each satisfy a threshold criterion (§ 0010, Lines 13-21; Pool security events written to logs of these security technologies and alerts published to an alert feed by these security technologies; correlate these pooled security events and alerts to known parameters and characteristics of phases of the attack validation scenario; confirm whether these security technologies properly logged, detected, prevented, or alerted on their assigned phases of the attack validation scenario based on these correlations);
determining that a third number of alerts generated for the second attack phase based on the set of detection operations fails to satisfy the threshold criterion (§ 0010, Lines 21-23; (Continuing from the citation above) Flag any security technology that failed to log, detect, prevent, or alert—as planned—on its assigned phases), wherein failure of the third number of alerts to satisfy the threshold criterion indicates a gap in alert generation for the second attack phase using the set of detection operations (See citation above. Any security technology that failed to log, detect, prevent, or alert on its assigned phases (i.e., a gap in alert generation) is flagged); and
causing the set of detection operations to be modified to detect future malicious activities corresponding to the second attack phase in view of the indicated gap in the alert generation for the second attack phase using the set of detection operations (§ 0093; The security portal flags or highlights a security technology that failed at least one response type in its assigned phase (i.e., indicated gap) and presents a recommendation for reconfiguring the security technology to preempt this failure when the phase is rerun on the target asset and when analogous behaviors occur on the computer network in the future).
Black does not explicitly disclose the malicious attack has occurred with respect to the first entity.
Meir discloses for the purposes of detecting malicious behavior for a chain of processes, a threat detection model can be trained based on either synthetic or real-world data corresponding to malicious causality chains (§ 0020, Lines 1-4).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Black’s system to be trained based on real-world data corresponding to malicious causality chains, as taught by Meir, in order to account for situations where details of a particular attack sequence are not known in advance.
The method of claim 1 is implemented by the system of claim 12 and is therefore rejected with the same rationale.
Regarding the “non-transitory computer-readable storage medium” of claim 20, Black discloses that his invention can be executed by a computer system, which includes at least a processor and a memory storing instructions, within a computer network (§ 0010, Lines 1-4).
Claims 2 and 13:
Black in view of Meir further discloses wherein determining that the first number of alerts generated for the first attack phase based on the set of detection operations and the second number of alerts generated for the third attack phase based on the set of detection operations satisfy the threshold criterion comprises:
obtaining a plurality of generated alerts comprising at least a first alert and a second alert (Black, § 0010, Lines 13-15; Pool security events written to logs of these security technologies and alerts published to an alert feed by these security technologies;);
associating the first alert with the first attack phase based on one or more properties of the first alert (Black, § 0010, Lines 15-21; Correlate these pooled security events and alerts to known parameters and characteristics of phases of the attack validation scenario; confirm whether these security technologies properly logged, detected, prevented, or alerted on their assigned phases of the attack validation scenario based on these correlations); and
associating the second alert with the third attack phase based on one or more properties of the second alert (Black, § 0010, Lines 15-21; Correlate these pooled security events and alerts to known parameters and characteristics of phases of the attack validation scenario; confirm whether these security technologies properly logged, detected, prevented, or alerted on their assigned phases of the attack validation scenario based on these correlations).
Claims 3 and 14:
Black in view of Meir further discloses:
detecting, based on the modified set of detection operations, malicious activity associated with the second attack phase (Black, § 0101, Lines 7-12; The integration manager can rerun a second instance of this phase at the same target asset and repeat the foregoing methods and techniques to verify that reconfiguration of the security technology resolved logging, detection, prevention, or alerting failure detected in the previous instance of the phase executed by this target asset).
Claims 4 and 15:
Black in view of Meir further discloses wherein causing the set of detection operations to be modified comprises identifying within event logs one or more events associated with the second attack phase (Black, § 0010, Lines 13-23; Pool security events written to logs of these security technologies and alerts published to an alert feed by these security technologies; correlate these pooled security events and alerts to known parameters and characteristics of phases of the attack validation scenario; confirm whether these security technologies properly logged, detected, prevented, or alerted on their assigned phases of the attack validation scenario based on these correlations; flag any security technology that failed to log, detect, prevent, or alert—as planned—on its assigned phases).
Claims 5 and 16:
Black in view of Meir further discloses wherein the identifying within event logs the one or more events associated with the second attack phase comprises at least one of:
identifying a first event with a first event metadata value that satisfies a magnitude criterion (Black, § 0013, Lines 13-21; Differences between expected responses by the security technology and actual logging, detection, and prevention events and alerts by the security technology during execution of the phase may indicate that this security technology is not properly configured or not configured according to an expectation (e.g., of security personnel) to timely log, detect, prevent, and/or alert on network behaviors within an analogous phase of a malicious attack on the network); or
identifying a second event with a second event metadata value that satisfies a baseline-deviation criterion (Black, § 0010, Lines 21-23; Flag any security technology that failed to log, detect, prevent, or alert—as planned—on its assigned phases. Failure is a deviation from a baseline).
Claims 6 and 17:
Black in view of Meir further discloses wherein the identifying within event logs the one or more events associated with the second attack phase further comprises:
obtaining an external alert associated with a second entity, the external alert having an associated external event (Black, § 0010, Lines 12-18; Deploy these phases of the attack validation scenario to assets on the network; pool security events written to logs of these security technologies and alerts published to an alert feed by these security technologies; correlate these pooled security events and alerts to known parameters and characteristics of phases of the attack validation scenario); and
identifying a third event of the first entity with a third event metadata value that matches a corresponding event metadata value of the external event (See citation above. Security events across the phases of the attack validation scenario are pooled and correlated).
Claims 7 and 18:
Black in view of Meir further discloses wherein the set of detection operations is based at least on a first malicious activity detection rule corresponding to the first attack phase and a second malicious activity detection rule corresponding to the third attack phase (Black, § 0011, Lines 1-2; An attack validation scenario can be populated with a set of phases) (Black, § 0012, Lines 5-9; If the security technology is tune to interpret actions within the phase an anomalous behaviors or similar to a known security threat, the security technology may flag actions within the phase and write detection events for these actions to the log).
Claim 8:
Black in view of Meir wherein causing the set of detection operations to be modified comprises adding a third malicious activity detection rule corresponding to the second attack phase, the third malicious activity detection rule being based on the identified one or more events (Black, § 0093; The security portal flags or highlights a security technology that failed at least one response type in its assigned phase and presents a recommendation for reconfiguring the security technology to preempt this failure when the phase is rerun on the target asset and when analogous behaviors occur on the computer network in the future) (Black, § 0094, Lines 9-10; Sensitivity of the security technology to detecting significant behaviors).
Claim 9:
Black in view of Meir further discloses wherein the third malicious activity detection rule is generated by applying a trained machine learning model to the identified one or more events to obtain a machine learning output, the machine learning output representing the third malicious activity detection rule (Black, § 0094, Lines 1-10; In response to failure of a target security technology to conform to a target response type for an action within a phase, the security portal can access a feature map of the security technology, such as in the form of a predefined model, decision tree, or artificial intelligence that defines associations between parameters and configuration of the security technology and: logging, detection, prevention, and alerting behaviors of the security technology; sensitivity of the security technology to detecting significant behaviors) (Black, § 0094, Lines 20-25; For example, the security portal can insert the target response type, the actual response type, characteristics of the action, and the current feature setting of the security technology into the feature map, which can then return a (ranked or aggregate) set of possible adjustments to settings of the security technology that may correct this failure).
Claims 10 and 19:
Black in view of Meir further wherein the set of detection operations is based at least on a first machine learning model trained to identify malicious activity associated with the first attack phase and a second machine learning model trained to identify malicious activity associated with the third attack phase (Meir, § 0020, Lines 1-4 and 13-19; A threat detection model can be trained using on either synthetic or real-world data corresponding to malicious causality chains where the causality chains used to train the detection model can include metadata related to the events to increase the model complexity and accuracy of the threat detection model and can be a simple probabilistic model or a complex machine learning based model depending on the available computing resources, the amount of event data, etc.).
Claim 11:
Black in view of Meir further discloses modifying the set of detection operations by adding a third machine learning model trained to identify malicious activity associated with the second attack phase (Black, § 0094, Lines 1-10; In response to failure of a target security technology to conform to a target response type for an action within a phase, the security portal can access a feature map of the security technology, such as in the form of a predefined model, decision tree, or artificial intelligence that defines associations between parameters and configuration of the security technology and: logging, detection, prevention, and alerting behaviors of the security technology; sensitivity of the security technology to detecting significant behaviors), wherein the third machine learning model is trained using the identified one or more events (Black, § 0094, Lines 20-25; For example, the security portal can insert the target response type, the actual response type, characteristics of the action, and the current feature setting of the security technology into the feature map, which can then return a (ranked or aggregate) set of possible adjustments to settings of the security technology that may correct this failure).
Response to Arguments
Applicant's arguments filed 03/19/2026 have been fully considered but they are not persuasive: On page 8, Applicant argues that claims 1, 12, and 20 as amended are directed to statutory subject matter. The examiner disagrees. The “causing” step is abstract as analyzed above (in Step 2A Prong 1). It is not an additional element and is not analyzed in Step 2A Prong 2 or Step 2B. It is suggested that a step claiming mitigation of malicious activity based on the modified set of detection operations be added to potentially overcome this rejection (see § 0020 of the originally-filed specification). The examiner is available if Applicant would like to discuss this further.
Applicant’s arguments with respect to claim(s) 1-20 on pages 9-11 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. The Meir reference discloses that for the purposes of detecting malicious behavior for a chain of processes, a threat detection model can be trained based on either synthetic (similar to Black’s system) or real-world data corresponding to malicious causality chains.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NAM T TRAN whose telephone number is (408)918-7553. The examiner can normally be reached Monday-Friday 7AM-3PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Emmanuel Moise can be reached at 571-272-3865. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NAM T TRAN/Primary Examiner, Art Unit 2455