Prosecution Insights
Last updated: October 02, 2026
Application No. 18/428,703

NETWORK ANOMALY DETECTION WITH GRAPH ATTENTION NETWORK

Final Rejection §103
Filed
Jan 31, 2024
Examiner
ALRIYASHI, ABDULKADER MOHAMED
Art Unit
2447
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
2 (Final)
67%
Grant Probability
Favorable
3-4
OA Rounds
4m
Est. Remaining
71%
With Interview

Examiner Intelligence

Grants 67% — above average
67%
Career Allowance Rate
261 granted / 388 resolved
+9.3% vs TC avg
Minimal +4% lift
Without
With
+3.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
29 currently pending
Career history
424
Total Applications
across all art units

Statute-Specific Performance

§101
10.0%
-30.0% vs TC avg
§103
50.4%
+10.4% vs TC avg
§102
13.8%
-26.2% vs TC avg
§112
22.3%
-17.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 388 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim status in the amendment received on 7/2/2026: Claims 1, 3-4, 11, 13, 15, 17 and 19 have been amended. Claims 1-20 are pending. Response to Amendments The amendments to the specification filed on 7/2/2026 have been considered and entered. Response to Arguments Applicant’s arguments have been considered but are moot because the arguments do not apply to any of the references being used in the current rejection. Allowable Subject Matter Claims 3-5, 7, 9-12, 15-16 and 19-20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 6, 13-14 and 17-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chinese Patent Application (No.: CN114221790A) (“CPA” hereinafter, mappings are made to the attached translation) in view of Chandra et al. (Pub. No.: US 20230006901 A1). As to claim 1, CPA teaches a computer-implemented method comprising: obtaining, from a plurality of data sources, data related to operation or configuration of Border Gateway Protocol (BGP) in an enterprise network (paragraph [0014], “Use an automatic data acquisition program to collect and store BGP update message data from Route Views and RIPE NCC in chronological order by region”); extracting one or more BGP features based on at least one correlation among the data from the plurality of data sources (Paragraph [0020], “Store the 45 feature values in the order of timestamps. The data under each timestamp is treated as a sample. Add a label to each sample according to the time period of the abnormal event”); detecting one or more network anomalies by performing a weakly supervised machine learning of the one or more BGP features based on a plurality of BGP labels (paragraph [0052], “The model prediction module uses known event datasets as training samples and untrained datasets as test samples to evaluate the model's detection performance for unknown abnormal events. This module can also be directly used in practical applications.” And paragraph [0066], “abnormal labels are automatically added according to the time period of the abnormal event to construct the experimental dataset”, teaches weakly supervised machine learning). CPA does not explicitly teach generating labels based on fusing and embedding a subset of the data and providing information about the anomalies for performing actions. However, in the same field of endeavor (network anomaly detection) Chandra teaches plurality of labels is generated based on fusing and embedding a subset of data (paragraph [0022], “…aggregate network metrics from the monitored network in the historical network data database, identify incidents based on the network metrics, generate a training data set based on the network metrics and the incidents, wherein the training data set comprises time series of network metrics as training input and incidents as labels, train, with a machine learning algorithm, an incident model using the training data set…”); providing information about the one or more network anomalies for performing one or more actions associated with the enterprise network (paragraph [0025], “…alert includes the incident type indicator, the incident severity indicator, or the indication of a network component. In some embodiments, the alert may further include a suggested action determined based on one or more of incident type, incident severity, and one or more associated network components…”). Based on CPA in view of Chandra, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate generating labels based on fusing and embedding a subset of the data and providing information about the anomalies for performing actions (taught by Chandra) with network anomaly detection (taught by CPA) in order to enable generating training data set based on network metrics and perform various remedial actions to enable the system to continue operating and reduce downtime. As to claim 2, Chandra further teaches performing the one or more actions to configure one or more network devices in the enterprise network based on the information about the one or more network anomalies (paragraph [0025], “…alert includes the incident type indicator, the incident severity indicator, or the indication of a network component. In some embodiments, the alert may further include a suggested action determined based on one or more of incident type, incident severity, and one or more associated network components…”). The limitations of claim 2 are rejected in view of the analysis of claim 1 above, and the rationale to combine, as discussed in claim 1, applies here as well. As to claim 6, CPA teaches wherein the one or more BGP features include at least one statistical network feature and at least one network topology feature and detecting the one or more network anomalies includes: generating a graph attention network indicative of one or more interrelationships between the at least one statistical network feature and the at least one network topology feature (paragraph [0005], “This invention, based on sliding window and STL decomposition of event datasets, captures feature relationships and temporal dependencies through feature-based graph attention networks and time-series-based graph attention networks, respectively”); and generating a ranking-based anomaly score by performing a long short-term memory machine learning of the graph attention network (paragraph [0005], “Finally, a basic LSTM model can be used to accurately predict unknown events from training on known events”). As to claim 13, CPA further teaches an apparatus comprising: a memory; a network interface configured to enable network communications; and a processor, wherein the processor is configured to perform a method (paragraph [0001]). Therefore, the limitations of claim 13 are substantially similar to claim 1. Please refer to claim 1 above. As to claim 14, the limitations of the claim are substantially similar to claim 2. Please refer to claim 2 above. As to claim 17, CPA further teaches One or more non-transitory computer readable storage media encoded with software comprising computer executable instructions that, when executed by a processor, cause the processor to perform a method (paragraph [0001]). Therefore, the limitations of claim 17 are substantially similar to claim 1. Please refer to claim 1 above. As to claim 18, the limitations of the claim are substantially similar to claim 2. Please refer to claim 2 above. Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chinese Patent Application (No.: CN114221790A) in view of Chandra et al. (Pub. No.: US 20230006901 A1) and further in view of Pei et al. (Patent No.: US 7889666 B1). As to claim 8, CPA in view of Chandra does not explicitly teaches determining root cause of network anomaly based on temporal and spatial correlation. However, in the same field of endeavor (network anomaly detection) Pei teaches determining a root cause of the one or more network anomalies by grouping the data from the plurality of data sources based on a temporal correlation and a spatial topology correlation (fig. 2, 207-213). Based on CPA in view of Chandra and further in view of Pei, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate determining root cause of network anomaly based on temporal and spatial correlation (taught by Pei) with generating labels based on fusing and embedding a subset of the data and providing information about the anomalies for performing actions (taught by Chandra) with network anomaly detection (taught by CPA) in order to enable generating training data set based on network metrics and perform various remedial actions to enable the system to continue operating and reduce downtime, and in order to further point out the root cause impact and mitigation analysis. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULKADER M ALRIYASHI whose telephone number is (313)446-6551. The examiner can normally be reached Monday - Friday, 8AM - 5PM Alt, Friday, EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JOON HWANG can be reached at (571)272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Abdulkader M Alriyashi/Primary Examiner, Art Unit 2447 9/12/2026
Read full office action

Prosecution Timeline

Jan 31, 2024
Application Filed
Apr 09, 2026
Non-Final Rejection mailed — §103
Jun 23, 2026
Applicant Interview (Telephonic)
Jun 23, 2026
Examiner Interview Summary
Jul 02, 2026
Response Filed
Sep 15, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750381
UNSUPERVISED ANOMALY DETECTION USING LOOKAHEAD PAIRS
2y 8m to grant Granted Sep 29, 2026
Patent 12732506
SEGMENTATION MANAGEMENT INCLUDING VISUALIZATION, CONFIGURATION, SIMULATION, OR A COMBINATION THEREOF
2y 4m to grant Granted Sep 08, 2026
Patent 12726460
HARDWARE OFFLOAD OF QUIC DISTRIBUTED DENIAL OF SERVICE PROTECTION
2y 11m to grant Granted Sep 01, 2026
Patent 12726490
WEBSITE CLASSIFICATION
2y 7m to grant Granted Sep 01, 2026
Patent 12712795
MICRO SEGMENT IDENTIFIER INSTRUCTIONS FOR PATH TRACING OPTIMIZATION
2y 1m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
67%
Grant Probability
71%
With Interview (+3.6%)
3y 0m (~4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 388 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month