Prosecution Insights
Last updated: August 17, 2026
Application No. 18/444,875

CYBERSECUITY TESTING BY FORCING RECOVERY PATHS

Final Rejection §101
Filed
Feb 19, 2024
Examiner
NANO, SARGON N
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
International Business Machines Corporation
OA Round
4 (Final)
81%
Grant Probability
Favorable
5-6
OA Rounds
5m
Est. Remaining
79%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
549 granted / 680 resolved
+22.7% vs TC avg
Minimal -2% lift
Without
With
+-1.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
34 currently pending
Career history
726
Total Applications
across all art units

Statute-Specific Performance

§101
26.5%
-13.5% vs TC avg
§103
32.7%
-7.3% vs TC avg
§102
20.8%
-19.2% vs TC avg
§112
10.7%
-29.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 680 resolved cases

Office Action

§101
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This office action is responsive to amendment submitted on 5/26/2026. No claims are amended. Claim 3 is previously cancelled. Consequently, claims 1, 2, 4-18 are pending examination. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 2, 4-18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim(s) 1 is/are drawn to a method, claim 7 is drawn to a program product, and claim(s) 13 is drawn to data processing system. As such, claims 1, 7, and 13 are drawn to one of the statutory categories of invention. Claims 1, 2, 4-18 are directed to testing code by recovery path, monitoring responses, and reporting potential security vulnerabilities. Specifically, the claims recite list the claim limitations that recite the abstract idea, which is grouped within the Mathematical Concepts and is similar to the concept Methods Of Organizing Human Activity and is similar to the concept of (fundamental economic principles or practices including hedging insurance, mitigating risk) OR (commercial or legal interactions including agreements in the form of contracts, legal obligations, advertising, marketing or sales activities or behaviors business relations OR (managing personal behavior or relationships or interactions between people including social activities teaching, and following rules or instructions) OR Mental Processes and is similar to the concept of (concepts performed in the human mind (including an observation, evaluation, judgement, opinion) grouping of abstract ideas in prong one of step 2A of the Alice/Mayo test (See 2019 Revised Patent Subject Matter Eligibility Guidance, 84 Fed. Reg. 50, 52, 54 (January 7, 2019)). Accordingly, the claims recite an abstract idea (See pages 7, 10, Alice Corporation Pty. Ltd. v. CLS Bank International, et al., US Supreme Court, No. 13-298, June 19, 2014; 2019 Revised Patent Subject Matter Eligibility Guidance, 84 Fed. Reg. 50, 53-54 (January 7, 2019)). Step 2A, Prong One, the claims are directed to an abstract idea. The claim recite a processor executing a code testing service and a program under test, the program under test including at least one main execution path and a recovery path different from the main execution path, the recovery path contained in the program under test prior to performing an interrupt operation, wherein the executing includes: the code testing service controlling the processor to force execution of the recovery path in the program under test; the program under test generating program checks, resulting in notifications of program checks regarding the recovery path; the processor processing the notifications by executing a code monitor to detect potential security vulnerabilities in the recovery path of the program under test; and the code monitor commanding the processor to generate and store a report of the potential security vulnerabilities in the program under test, wherein forcing the recovery path includes: executing, via the processor, the at least one main execution path in the program under test; generating an interrupt command configured to perform the interrupt operation to interrupt execution of the processor and delivering the interrupt command to the processor; and in response to receiving the interrupt command, controlling the processor to interrupt the execution of the at least one main execution path, and controlling the processor to force the execution of the recovery path in the program under test. These limitations fall within the category of mental processes and methods or organizing human activity. Specifically, testing and analysis which are judicial exceptions. Detecting potential security vulnerabilities and reporting them are conventional data processing tasks often done mentally or by abstract logic and do not improve the functioning of the computer or any technology. Step 2A, Prong Two, the claims do not integrate the abstract idea into a practical application. The claims recite generic computer components such as a processor, a code monitor. The use of these components is merely to implement the abstract idea of code testing and vulnerability detection. There is no improvement to computer technology or another technical field. The claimed steps do not require any specific technological environment or unconventional use of technology. Furthermore, the additional limitations in the dependent claims such as using timer or trigger an interrupt, limiting frequency or count, are standard control mechanism that are well understood, routine and conventional in software testing. 2B, the claims do not recite an inventive concept that transforms the abstract idea into patent eligible application. The additional elements are generic and perform conventional functions. The claims simply implement the abstract idea of triggering, monitoring and reporting vulnerabilities using conventional functions. Therefore claims 1, 2, 4-18 are rejected under 35 U.S.C. 101 as being directed to an abstract idea without significantly more. Response to Arguments Applicant's arguments filed regarding - 35 USC § 101 have been fully considered but they are not persuasive. The arguments are presented below: Argument 1: improvement to: Technology” or a technical Field. The applicant argues that the claims are patent eligible under Step 2A, Prong Two because they are directed to improving the technical field of cybersecurity testing. Specifically, applicant states that the claims recite a “specific technical architecture” utilizing processor-level interrupt operations to forcibly execute hidden recovery logic, which uncovers vulnerabilities that cannot be identified through routine testing. Response An improvement to a software testing methodology is not an improvement to computer functioning. Even though applicant has identified a specific software testing pattern, an advancement in a testing strategy is an improvement to a human methos of system evaluation, not an improvement to basic technology or technical functioning of the computer itself. The claims rely entirely on conventional computer functioning. The august 04, 2025 Reminder Memorandum notes that computer related claims are eligible if they reflect an improvement tot eh functioning of a computer or technical field. However, the current claims do not alter how the processor handles interrupts, how the operating system generates program checks, or how code monitor acts. The claims merely use pre-existing, native computer behaviors (e.g. stopping in main path when an interrupt command is receiving d and calling an error routine) to automate the testing method. The components are defined purely by their functional results. The claim limitations are drafted in a highly functional language such as “controlling processor to force execution”, “detect potential security vulnerabilities”,. Simply dictating a particular logical testing sequence using conventional computer features does not change how computer handles data at a physical, hardware, or base operating-system level. Argument 2: technological problem/solution. Response. The underlying problem and solution remain logical concept: The core problem identifies by the applicant is that “error recovery paths… can be overlooked” during normal code execution. The claims solution is to intentionally trigger the condition that causes the error path to run so it can be evaluated. This is a basic, logical rule of diagnostic troubleshooting: if you want to verify an alternative path, you must force it to execute. Automating this logical rule using standard processing architecture does not change its abstract nature. It is well established that a process is not patent eligible simply because it is too fast, complex or precise to be practically completed by a human mind or via manual review of code on paper. The relevant inquiry under the Reminder Memorandum is whether the claims cover a particular technological solution that modifies computer operations, rather than only claiming the generic idea of a solution. By reciting standard steps like delivering an interrupt command and capturing notifications using generic system components, the claims fail to provide a specific, technological upgrade. Argument 3: Applicant contends that the final vulnerability report is not the result of generic data analysis. Instead, applicant argues that eh report is generated by a specific sequence of processor-controlled operations that forcibly redirect computer execution to uncover hidden security flaws, thereby integrating the exception into a practical specification. Response The claims still conform to an ineligible data lifecycle, no matter how the unique testing sequence is, the claimed steps follow an abstract data lifecycle: Data generation/collection: executing a program, sending an interrupt, and forcing a path to create a program checks and modification. Data analysis: running a code monitor to process notification and detect vulnerabilities. Data reporting: commanding the processor to generate and store a report. Limiting the abstract idea to a cybersecurity environment is insufficient because collecting data, analyzing data, and reporting the results remains abstract, even when it is restricted to a particular filed of use like cybersecurity (see Electric Power Group, LLC, V Alstom S.A.). The claims lack a technological downstream application. The method concludes entirely commanding the processor to “generate and store a report of the potential security vulnerabilities”. The claim does not require taking a technical, practical step with that information, such as deploying a dynamic code patch, reconfiguring system permissions, or altering kernel security settings to actively neutralize the discovered threat. Because the final step is simply generating and storing data, the claim is directed to an abstract idea and does not present a practical application under Step 2A Prong Two. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SARGON N NANO whose telephone number is (571)272-4007. The examiner can normally be reached 7:30 AM-3:30 PM. M.S.T.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached at 571 272 3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SARGON N NANO/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Show 4 earlier events
Oct 07, 2025
Response Filed
Oct 24, 2025
Final Rejection mailed — §101
Dec 15, 2025
Response after Non-Final Action
Jan 23, 2026
Request for Continued Examination
Jan 29, 2026
Response after Non-Final Action
Feb 24, 2026
Non-Final Rejection mailed — §101
May 26, 2026
Response Filed
Jun 18, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689603
Configuring a Monitor Mode for Suspicious Content in Emails
2y 6m to grant Granted Jul 21, 2026
Patent 12683986
Systems and methods for processing electronic communications
2y 10m to grant Granted Jul 14, 2026
Patent 12665768
OBLIVIOUS TRANSFER FROM KEY ENCAPSULATION MECHANISMS
2y 7m to grant Granted Jun 23, 2026
Patent 12665833
DYNAMIC MAPPING OF NETWORKS TO MULTI-TENANTED BGP SERVERS
1y 7m to grant Granted Jun 23, 2026
Patent 12659372
LINKAGE SYSTEM, METHOD, VEHICLE, STORAGE MEDIUM AND CHIP
2y 11m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
81%
Grant Probability
79%
With Interview (-1.6%)
2y 11m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 680 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month