Prosecution Insights
Last updated: October 01, 2026
Application No. 18/425,973

LARGE LANGUAGE MODEL ASSISTED CYBERSECURITY PLATFORM

Non-Final OA §103
Filed
Jan 29, 2024
Priority
Jul 25, 2023 — provisional 63/515,488
Examiner
JOHNSON, CARLTON
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
CrowdStrike Inc.
OA Round
3 (Non-Final)
58%
Grant Probability
Moderate
3-4
OA Rounds
1y 10m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
211 granted / 364 resolved
At TC average
Strong +33% interview lift
Without
With
+33.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 6m
Avg Prosecution
13 currently pending
Career history
385
Total Applications
across all art units

Statute-Specific Performance

§101
12.0%
-28.0% vs TC avg
§103
64.6%
+24.6% vs TC avg
§102
13.2%
-26.8% vs TC avg
§112
9.4%
-30.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 364 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Continued Examination Under 37 CFR 1.114 1. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 8-18-2026 has been entered. 2. Claims 1 - 20 are pending. Claims 1, 9, 11, 19, 20 have been amended. Claims 1, 11, 20 are independent. This application was filed on 1-29-2024. Response to Arguments 3. Applicant’s arguments, see Arguments/Remarks Made in an Amendment, filed 1-2-2026, with respect to the rejection(s) under Watson in view Khillar and further in view of Wilkins and Rao have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Watson in view Khillar and further in view of Wilkins and Rao and Kimpton. A. Applicant argues on page 8 of Remarks: … Watson, Khillar, Wilkins, Rao, and Farley, alone or in any combination, do not teach or suggest "wherein the NL request is for an identifier of a host with a particular installed application," as recited in amended claim 1. The Examiner respectfully disagrees. Kimpton discloses a request including an identifier associated with a host system and a particular application installed on the host system. (see Kimpton paragraph [0014]: The host system 122 includes a remote presentation service ("RPS") 100. The host system 122 may be a desktop computer, a server system, a virtualized system, or the like.; paragraph [0015]: A user operating the Web browser 110 on the client device 120 initiates access to the application 123 via a uniform resource identifier ("URI") 105. The URI 105 may be entered manually, such as via a text input field of the Web browser 110. In other examples, the URI may be accessed via some other user interface element/control, such as via a link, button, shortcut, bookmark, icon, or the like. In some embodiments, the general form of the URI 105 is http://host-system-id/application id?args, where host-system-id identifies the host system 122, application id identifies the application 123, and args identifies arguments/parameters for the application and/or the RPS 100. Based on the URI 105, the Web browser 110 forms and transmits to the RPS 100 on the host system 122 a request to access the application 123. The request may include one or more of an identifier of the host system 122, the application 123, as well as one or more arguments, parameters, or other data, all or some of which may be obtained from the URI 105.) B. Applicant argues on page 9 of Remarks: … the Examiner has not identified any disclosure in the cited references of a natural language request that is specifically directed to obtaining an identifier of a host having a particular installed application. The Examiner respectfully disagrees. Kimpton discloses a request including an identifier associated with a host system and a particular application installed on the host system. (see Kimpton paragraph [0014]: The host system 122 includes a remote presentation service ("RPS") 100. The host system 122 may be a desktop computer, a server system, a virtualized system, or the like.; paragraph [0015]: A user operating the Web browser 110 on the client device 120 initiates access to the application 123 via a uniform resource identifier ("URI") 105. The URI 105 may be entered manually, such as via a text input field of the Web browser 110. In other examples, the URI may be accessed via some other user interface element/control, such as via a link, button, shortcut, bookmark, icon, or the like. In some embodiments, the general form of the URI 105 is http://host-system-id/application id?args, where host-system-id identifies the host system 122, application id identifies the application 123, and args identifies arguments/parameters for the application and/or the RPS 100. Based on the URI 105, the Web browser 110 forms and transmits to the RPS 100 on the host system 122 a request to access the application 123. The request may include one or more of an identifier of the host system 122, the application 123, as well as one or more arguments, parameters, or other data, all or some of which may be obtained from the URI 105.) C. Applicant argues on page 9 of Remarks: … Claim 11, as amended, recites similar subject matter as amended claim 1. With reference to the discussion of claim 1, withdrawal of this rejection of independent claim 11 and claims 12-19 that depend therefrom is also respectfully requested is respectfully requested. Independent claim 11 has similar limitations as independent claim 1. Responses to arguments against independent claim 1 also answer arguments against independent claim 11. Responses to arguments against the independent claims also answer arguments against the associated dependent claims (Claims 12-19). D. Applicant argues on page 9 of Remarks: … Claim 20, as amended, recites similar subject matter as amended claim 1. With reference to the discussion of claim 1, withdrawal of this rejection of independent claim 20 is also respectfully requested. Independent claim 20 has similar limitations as independent claim 1. Responses to arguments against independent claim 1 also answer arguments against independent claim 20. Claim Rejections - 35 USC § 103 4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claims 1, 2, 5 - 7, 10 - 12, 15 - 17, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Watson et al. (US Patent No. 11,971,914) in view of Khillar et al. (US PGPUB No. 20220261442) and further in view of Wilkins et al. (US PGPUB No. 20230078122) and Rao et al. (US PGPUB No. 20190392071) and Kimpton et al. (Patent No. WO 2014018175 A1). Regarding Claims 1, 11, 20, Watson discloses a method, a system, and a non-transitory computer-readable medium, comprising: b) providing the request to an artificial intelligence (AI) model trained to identify, from a plurality of databases that provides access to event datasets. (see Watson col 1: An artificial intelligence (AI) method includes a processor receiving, from a human user, a query on an external database; performing transformations on the query to produce a refined query; generating an embedding of the refined query; adding a refined query to a templated system prompt and a templated user prompt; and applying the embedding to a vector database by executing a similarity routine to identify one or more discrete vectors in the vector database most similar to the embedding, and collecting the one or more most similar vectors for application to a large language model. The method further includes applying to the large language model, the one or more most similar vectors, the refined query, and the system prompt and the user prompt, to generate a response to the query, the response including a text document, generated by execution of the large language model, as a comprehensive answer to the query.; (human user query analogous to natural language request or query)) and c) generating, by a processing device and using the AI model, a database request associated with the particular API based on the request. (see Watson col 7: the complete query-response operation involves refining the user query, applying user and system prompts, filtering relevant articles using vector embeddings, and generating comprehensive answers using Cure AI model along with the relevant context and refined queries.) Watson does not specifically disclose for a) receiving a natural language (NL) request for information associated with a private network, and for b) providing a NL request, and for c) the NL request. However, Khillar discloses: a) receiving, from an endpoint device, a natural language (NL) request for information associated with the private network; b) providing a NL request; and c) the NL request. (see Khillar paragraph [0005]: Aspects described herein are directed towards determining a query for a database based on a natural language input. A natural language input may be received from a first computing device. The natural language input may have been provided (e.g., entered) by a user and may be intended for execution with respect to a database. The natural language input may be divided into one or more segments, and the one or more segments may each correspond to one or more words in the natural language input. One or more segments may correspond to particular segments (e.g., columns, tables) of the database. One or more segments may correspond to predefined operations authorized to be performed with respect to the database. One or more segments may correspond to search clauses, such as “andwhere,” “orwhere,” “order by,” or the like.; paragraph [0027]: Various network nodes 103, 105, 107, and 109 may be interconnected via a wide area network (WAN) 101, such as the Internet. Other networks may also or alternatively be used, including private intranets, corporate networks, local area networks (LAN), metropolitan area networks (MAN), wireless networks, personal networks (PAN), and the like.; (intranet: private network)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for a) receiving a natural language (NL) request for information associated with a private network, and for b) providing a NL request, and for c) the NL request as taught by Khillar. One of ordinary skill in the art would have been motivated to employ the teachings of Khillar for the flexibility of a system that enables the utilization of multiple types of protocol requests such as a NL request to query a database within a network-connected environment. (see Khillar paragraph [0005]) Watson does not specifically disclose wherein for a) the NL request is for an identifier of a host with a particular installed application. However, Kimpton discloses wherein the NL request is for an identifier of a host with a particular installed application. (see Kimpton paragraph [0014]: The host system 122 includes a remote presentation service ("RPS") 100. The host system 122 may be a desktop computer, a server system, a virtualized system, or the like.; paragraph [0015]: A user operating the Web browser 110 on the client device 120 initiates access to the application 123 via a uniform resource identifier ("URI") 105. The URI 105 may be entered manually, such as via a text input field of the Web browser 110. In other examples, the URI may be accessed via some other user interface element/control, such as via a link, button, shortcut, bookmark, icon, or the like. In some embodiments, the general form of the URI 105 is http://host-system-id/application id?args, where host-system-id identifies the host system 122, application id identifies the application 123, and args identifies arguments/parameters for the application and/or the RPS 100. Based on the URI 105, the Web browser 110 forms and transmits to the RPS 100 on the host system 122 a request to access the application 123. The request may include one or more of an identifier of the host system 122, the application 123, as well as one or more arguments, parameters, or other data, all or some of which may be obtained from the URI 105.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for a) the NL request is for an identifier of a host with a particular installed application as taught by Kimpton. One of ordinary skill in the art would have been motivated to employ the teachings of Kimpton for the benefits achieved from the flexibility of a system that enables multiple parameters such as host identifier and application identifier in the processing of information I a network environment. (see Kimpton paragraph [0014]; paragraph [0015]) Khillar discloses a natural language request as stated above. Watson does not specifically disclose an endpoint device on a private network and a model trained, using training data comprising a plurality of event datasets collected from a plurality of endpoint devices of the private network. However, Wilkins discloses wherein an endpoint device on a private network, and a model trained, using training data comprising a plurality of event datasets collected from a plurality of endpoint devices of the private network. (see Wilkins paragraph [0033]: An orchestration service 106 may include one or more computing devices (e.g., computer system 1 or a portion thereof in FIG. 2) that can communicate with the distributed collectors 102A-102N. In some instances, the application(s) 104A-104N are located in various tenants (virtual spaces) in a cloud. Orchestration service 106 can also be located in the cloud but can also reside outside the cloud environment and can communicate with the distributed collectors 102A-102N through a network 108 that can include any public and/or private network as described above.; paragraph [0036]: Multiple applications or endpoints can send data to different collectors. While three collectors 102A, B, and N are physically shown in FIG. 2, the letter N can be any integer and the collectors 102A-N can reside in spaces across multiple networks. Each collector 102A-N can identify events that are related to a request) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for an endpoint device on a private network and a model trained, using training data comprising a plurality of event datasets collected from a plurality of endpoint devices of the private network as taught by Wilkins. One of ordinary skill in the art would have been motivated to employ the teachings of Wilkins for the benefits achieved from the flexibility of a system that enables multiple network configurations to be utilized such as a distributed network environment in the processing of network traffic. (see Wilkins paragraph [0033]; paragraph [0036]) Furthermore, Watson does not specifically disclose identifying, from a plurality of application programming interfaces (APIs) that provides access to a unique event dataset associated with a respective event type. However, Rao discloses wherein to identify, from a plurality of application programming interfaces (APIs) generated for a plurality of databases of the private network a particular API that provides access to a unique event dataset associated with a respective event type. (see Rao paragraph [0020]: the augmented media system 202 can also include an application programming interface (API) module 210. The API module 210 can act as an interface with one or more database(s) 216. In addition, API module can enable data tracker module 208 to retrieve data from database nodes and/or monitor movements of the data across the database nodes and other media data deriving from the network(s) 218. In some embodiments, the API module 210 may establish a universal protocol for communication of data between the API module 210 and each of the database(s) 216 and/or nodes. In other embodiments, the API module 210 may generate a data request (e.g., a query) in any one of several formats corresponding to the database 216. Based on a request for data intending for a specific database from the data tracker module 208, the API module 210 may convert the request to a data query in a format (e.g., an SQL query, a DMX query, a Gremlin query, a LINQ query, and the like) corresponding to the specific database. Additionally, the server 214 may store, and retrieve data previously stored for use with the analytics module 206.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for identifying, from a plurality of application programming interfaces (APIs) that provides access to a unique event dataset associated with a respective event type as taught by Rao. One of ordinary skill in the art would have been motivated to employ the teachings of Rao for the benefits achieved from the flexibility of a system that enables the utilization of multiple techniques such as an API specific to a particular database. (see Rao paragraph [0020]) Furthermore, for Claim 11, Watson discloses wherein a system comprising: a memory; and a processing device, operatively coupled to the memory, to perform operations. (see Watson col 8: an example computer program executable to implement the herein disclosed artificial intelligence systems. In FIG. 2, computer program 200, which may be stored on non-transient computer-readable storage medium 110, includes data acquisition module 211, data processing module 212, embeddings module 213, database generator module 214, user interface module 215, and query response module 216. One or more of the processors 120 may access the program 200, upload all or portions of the program 200 to memory, and execute machine instructions or scripts associated with the uploaded program 200.) Furthermore, for Claim 20, Watson discloses wherein a non-transitory computer-readable medium storing instructions that, when execute by a processing device, cause the processing device to perform operations. (see Watson col 8: an example computer program executable to implement the herein disclosed artificial intelligence systems. In FIG. 2, computer program 200, which may be stored on non-transient computer-readable storage medium 110, includes data acquisition module 211, data processing module 212, embeddings module 213, database generator module 214, user interface module 215, and query response module 216. One or more of the processors 120 may access the program 200, upload all or portions of the program 200 to memory, and execute machine instructions or scripts associated with the uploaded program 200.) Regarding Claims 2, 12, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1 and the method of claim 11, further comprising: a) collecting the plurality of event datasets from the plurality of endpoint devices of the private network; (see Watson col 10: PubMed content or data (i.e., articles) are acquired (block 301) by one or more of the processors 120. The PubMed data then are provided (block 302) to an embedding model, which generates (block 303) vector embeddings for the PubMed data. The vector embeddings are stored (block 305) in vector database 140, and may include a reference to the original PubMed content (for example, by use of a PMID). Subsequently, a query application generates (block 401) a specific query, and the same embedding model generates (block 302) an embedding for the query; the query embedding then is used to query (block 405) the vector database 140, and through a similarity function, to identify similar embeddings.; (storing data within databases)) and b) indexing the plurality of event datasets into the plurality of databases based on the plurality of event types. (see Watson col 1: The large language model uses the one or more similar vectors as an index to the external database and retrieves documents from the external database, as indicated by the index, for use in generating the comprehensive answer.; col 6: technical solutions include structures, systems, and methods to implement a context-specific vector database with indexes to a PubMed database.; (index: map to an indicator or an identifier)) Regarding Claims 5, 15, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 2 and the method of claim 12, further comprising: a) generating mapping data that indicates a relationship between the plurality of databases and the plurality of access objects; b) wherein generating the database request associated with the particular access object is further based on the mapping data. (see Watson col 1: user prompt includes a search context, and inclusion of the search context requires the processor to generate the query response using only documents as identified by the index (i.e. mapping data); col 6: technical solutions include structures, systems, and methods to implement a context-specific vector database with indexes to a PubMed database. The herein disclosed technical solutions further include structures, systems, and methods to receive queries on the vector database, refine the queries, generate prompts, refine the prompts, apply the refined queries to the vector database, and provide a context-specific query response, including a comprehensive answer to the refined query, with citations to the PubMed database) Regarding Claims 6, 16, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1 and the method of claim 11, wherein further comprising converting the request to the database request associated with the particular access object. (see Watson col 1: An artificial intelligence (AI) method includes a processor receiving, from a human user, a query on an external database; performing transformations on the query to produce a refined query; generating an embedding of the refined query; adding a refined query to a templated system prompt and a templated user prompt; and applying the embedding to a vector database by executing a similarity routine to identify one or more discrete vectors in the vector database most similar to the embedding, and collecting the one or more most similar vectors for application to a large language model. In addition, Khillar discloses a NL query as stated above. Regarding Claims 7, 17, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1 and the method of claim 11, further comprising: providing, to an endpoint device, access to the one or more event datasets based on the database request. (see Watson col 1: applying to the large language model, the one or more most similar vectors, the refined query, and the system prompt and the user prompt, to generate a response to the query (provide access), the response including a text document, generated by execution of the large language model, as a comprehensive answer to the query.) Regarding Claim 10, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1. Watson does not specifically disclose database request is a structured query language. However, Khillar discloses wherein the database request is a structured query language (SQL) request. (see Khillar paragraph [0079]: The initiation of the generated query may depend on, e.g., the structure of the database, the formatting of the query, and the like. For example, the first database 129 may be a Structured Query Language (SQL)-compliant server executing on a separate computing device and the generated query may be an SQL-compliant query, such that causing execution of the generated query may comprise transmitting the query to the SQL server for execution.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for database request is a structured query language as taught by Khillar. One of ordinary skill in the art would have been motivated to employ the teachings of Khillar for the flexibility of a system that enables the utilization of multiple types of protocol requests such as a NL request to query a database within a network-connected environment. (see Khillar paragraph [0005]) 5. Claims 3, 4, 8, 9, 13, 14, 18, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Watson in view of Khillar and further in view of Wilkins and Rao and Kimpton and Farley et al. (US PGPUB No. 20060265746). Regarding Claims 3, 13, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 2 and the method of claim 12, wherein indexing the plurality of event datasets into the plurality of databases based on the plurality of event types. c) storing the first dataset in a first database of the plurality of databases and the second dataset in a second database of the plurality of databases. (see Watson col 10: PubMed content or data (i.e., articles) are acquired (block 301) by one or more of the processors 120. The PubMed data then are provided (block 302) to an embedding model, which generates (block 303) vector embeddings for the PubMed data. The vector embeddings are stored (block 305) in vector database 140, and may include a reference to the original PubMed content (for example, by use of a PMID). Subsequently, a query application generates (block 401) a specific query, and the same embedding model generates (block 302) an embedding for the query; the query embedding then is used to query (block 405) the vector database 140, and through a similarity function, to identify similar embeddings.; (storing data within databases)) Watson does not specifically disclose for a) determining that a first dataset of the plurality of event datasets is indicative of a first event type of the plurality of event types, and for b) determining that a second dataset of the plurality of event datasets is indicative of a second event type of the plurality of event types. However, Farley discloses: a) determining that a first dataset of the plurality of event datasets is indicative of a first event type of the plurality of event types; (see Farley paragraph [0161]: This determination is made based on the CoBRA vulnerability status 504 value of the raw event previously established by step 1010 of procedure 730 described in FIG. 10. ... If the inquiry to decision step 1110 is positive, then the "yes" branch is followed to step 1115. In step 1115, the raw event is compared to vulnerability-adjustable event types stored in a list in the context database 630. These vulnerability-adjustable event types stored in the context database 630 are events identified by either a user or a system for which the assessment of a machine's vulnerability status is believed trustworthy and for which therefore it is allowed to adjust priority based on vulnerability status information.; (selected: a factor indicating a degree of exposure that a particular computing device has to a particular threat type; (first event type)) and b) determining that a second dataset of the plurality of event datasets is indicative of a second event type of the plurality of event types. (see Farley paragraph [0165]: the frequency-adjustable event types can comprise those raw event types for which a high historical event frequency between a given pair of machines is seen as a reliable indicator of non-maliciousness for the network or computer being monitored by the fusion engine 22. Alternatively, also similar to the vulnerability-adjustable event types discussed above, in another exemplary embodiment (not shown) the context database 630 could instead comprise a list that identifies those raw event types for which a high historical event frequency between a given pair of machines for a network or computer being monitored by the fusion engine 22 is not seen as a reliable indicator of non-maliciousness, and historical event frequency can then be considered a trustworthy indicator of non-maliciousness for all other event types.; (second event type)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for a) determining that a first dataset of the plurality of event datasets is indicative of a first event type of the plurality of event types, and for b) determining that a second dataset of the plurality of event datasets is indicative of a second event type of the plurality of event types as taught by Farley. One of ordinary skill in the art would have been motivated to employ the teachings of Farley for the enhanced security of a system detecting the vulnerability status of an event associated with a particular computing system. (see Farley paragraph [0161]) Regarding Claims 4, 14, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 2 and the method of claim 12. Watson does not specifically disclose for a) generating a first schema that indicates a first dataset stored in a first database, and for b) generating a second schema that indicates a second dataset stored in a second database. However, Khillar discloses further comprising: a) generating, using a first access object of the plurality of access objects, a first schema that indicates a first dataset stored in a first database of the plurality of databases, the first dataset is associated with a first event; and b) generating, using a second access object of the plurality of access objects, a second schema that indicates a second dataset stored in a second database of the plurality of databases, the second dataset is associated with a second event. (see Khillar paragraph [0005]: a query (e.g., a GraphQL-compliant query) may be generated based on a database schema (e.g., a GraphQL database schema) associated with the database. The generated query may be validated based on the database schema and, if the validation is successful, the query may be executed with respect to the database.; paragraph [0050]: the client 301 may transmit queries and receive results from the first database 129 via the server 302 and with respect to a database schema 303. The database schema 303 may be any data (e.g., a file) which provides information with respect to a database (e.g., the first database 129). That information may include one or more rules associated with a database which improve queries and/or results with respect to the database.; paragraph [0057]: Databases, such as the first database 129 and/or the second database 131, may be formatted such that results to queries executed with respect to the database, such as the results 600, are in a particular structure. Additionally and/or alternatively, queries may be formatted to request results (e.g., the results 600) in a particular format.; (multiple databases: first schema, second schema for accessing databases)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for a) generating a first schema that indicates a first dataset stored in a first database, and for b) generating a second schema that indicates a second dataset stored in a second database as taught by Khillar. One of ordinary skill in the art would have been motivated to employ the teachings of Khillar for the flexibility of a system that enables the utilization of multiple types of protocol requests such as a NL request to query a database within a network-connected environment. (see Khillar paragraph [0005]) Watson does not specifically disclose for a) a first event type, and for b) a second event type. However, Farley discloses wherein for a) a first event type; (see Farley paragraph [0161]: This determination is made based on the CoBRA vulnerability status 504 value of the raw event previously established by step 1010 of procedure 730 described in FIG. 10. ... If the inquiry to decision step 1110 is positive, then the "yes" branch is followed to step 1115. In step 1115, the raw event is compared to vulnerability-adjustable event types stored in a list in the context database 630. These vulnerability-adjustable event types stored in the context database 630 are events identified by either a user or a system for which the assessment of a machine's vulnerability status is believed trustworthy and for which therefore it is allowed to adjust priority based on vulnerability status information., and for b) a second event type. (see Farley paragraph [0165]: the frequency-adjustable event types can comprise those raw event types for which a high historical event frequency between a given pair of machines is seen as a reliable indicator of non-maliciousness for the network or computer being monitored by the fusion engine 22. Alternatively, also similar to the vulnerability-adjustable event types discussed above, in another exemplary embodiment (not shown) the context database 630 could instead comprise a list that identifies those raw event types for which a high historical event frequency between a given pair of machines for a network or computer being monitored by the fusion engine 22 is not seen as a reliable indicator of non-maliciousness, and historical event frequency can then be considered a trustworthy indicator of non-maliciousness for all other event types.; (second event type)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for a) a first event type, and for b) a second event type as taught by Farley. One of ordinary skill in the art would have been motivated to employ the teachings of Farley for the enhanced security of a system detecting the vulnerability status of an event associated with a particular computing system. (see Farley paragraph [0161]) Regarding Claims 8, 18, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1 and the method of claim 11. Watson does not specifically disclose event types is indicative of at least one of detection data, vulnerability data, or threat data. However, Farley discloses wherein the plurality of event types is indicative of at least one of detection data, vulnerability data, or threat data. (see Farley paragraph [0161]: This determination is made based on the CoBRA vulnerability status 504 value of the raw event previously established by step 1010 of procedure 730 described in FIG. 10. ... If the inquiry to decision step 1110 is positive, then the "yes" branch is followed to step 1115. In step 1115, the raw event is compared to vulnerability-adjustable event types stored in a list in the context database 630. These vulnerability-adjustable event types stored in the context database 630 are events identified by either a user or a system for which the assessment of a machine's vulnerability status is believed trustworthy and for which therefore it is allowed to adjust priority based on vulnerability status information.; (selected: a factor indicating a degree of exposure that a particular computing device has to a particular threat type; (selected: vulnerability data)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for event types is indicative of at least one of detection data, vulnerability data, or threat data as taught by Farley. One of ordinary skill in the art would have been motivated to employ the teachings of Farley for the enhanced security of a system detecting the vulnerability status of an event associated with a particular computing system. (see Farley paragraph [0161]) Regarding Claims 9, 19, Watson-Khillar-Watson-Rao-Kimpton discloses the method of claim 1 and the method of claim 11. Watson does not specifically disclose the request is for one or more of the following: an identifier of one or more threat actors associated with a particular industry; a factor indicating a degree of exposure that a particular computing device has to a particular threat type. However, Farley discloses wherein the request is for one or more of the following: an identifier of one or more threat actors associated with a particular industry; a factor indicating a degree of exposure that a particular computing device has to a particular threat type; or an identifier of one or more hosts with a particular installed application. (see Farley paragraph [0161]: This determination is made based on the CoBRA vulnerability status 504 value of the raw event previously established by step 1010 of procedure 730 described in FIG. 10. ... If the inquiry to decision step 1110 is positive, then the "yes" branch is followed to step 1115. In step 1115, the raw event is compared to vulnerability-adjustable event types stored in a list in the context database 630. These vulnerability-adjustable event types stored in the context database 630 are events identified by either a user or a system for which the assessment of a machine's vulnerability status is believed trustworthy and for which therefore it is allowed to adjust priority based on vulnerability status information.; (selected: a factor indicating a degree of exposure that a particular computing device has to a particular threat type, vulnerability)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Watson for the NL request is for one or more of the following: an identifier of one or more threat actors associated with a particular industry; a factor indicating a degree of exposure that a particular computing device has to a particular threat type; or an identifier of one or more hosts with a particular installed application as taught by Farley. One of ordinary skill in the art would have been motivated to employ the teachings of Farley for the enhanced security of a system detecting the vulnerability status of an event associated with a particular computing system. (see Farley paragraph [0161]) Khillar discloses a NL request as stated above. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to CARLTON JOHNSON whose telephone number is (571)270-1032. The examiner can normally be reached Work: 12-9PM (most days). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CJ/ September 21, 2026 /SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Jan 29, 2024
Application Filed
Oct 01, 2025
Non-Final Rejection mailed — §103
Jan 02, 2026
Response Filed
May 18, 2026
Final Rejection mailed — §103
Aug 18, 2026
Request for Continued Examination
Sep 01, 2026
Response after Non-Final Action
Sep 25, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724718
CRYPTOGRAPHIC COMPUTATIONS FOR MEMORY REGIONS
2y 8m to grant Granted Sep 01, 2026
Patent 12683769
ENCRYPTED SEARCH WITH A PUBLIC KEY
3y 2m to grant Granted Jul 14, 2026
Patent 12666269
METHODS AND SYSTEMS FOR ALLOWING DEVICE TO SEND AND RECEIVE DATA
4y 1m to grant Granted Jun 23, 2026
Patent 12664253
AUTOMATED ONLINE POLICY GENERATION FOR ZERO-TRUST ARCHITECTURES
3y 1m to grant Granted Jun 23, 2026
Patent 12626261
SYSTEM AND METHOD FOR AUTOMATED SCAM DETECTION
1y 0m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
58%
Grant Probability
91%
With Interview (+33.0%)
4y 6m (~1y 10m remaining)
Median Time to Grant
High
PTA Risk
Based on 364 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month