Prosecution Insights
Last updated: August 18, 2026
Application No. 18/462,774

THREAT DETECTION IMPLEMENTED IN A DATA PROCESSING UNIT

Non-Final OA §103§112
Filed
Sep 07, 2023
Examiner
OLAEGBE, MUDASIRU K
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
3 (Non-Final)
74%
Grant Probability
Favorable
3-4
OA Rounds
2m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
64 granted / 86 resolved
+16.4% vs TC avg
Strong +16% interview lift
Without
With
+16.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
26 currently pending
Career history
116
Total Applications
across all art units

Statute-Specific Performance

§101
4.2%
-35.8% vs TC avg
§103
61.9%
+21.9% vs TC avg
§102
18.4%
-21.6% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 86 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This communication is in response to the RCE filed on 04/07/2026. Claims 1-20 are currently pending. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114, Applicant’s submission filed on 04/07/2026 has been entered. Response to Arguments Applicant’s arguments with respect to claims 1, 11, and 17 have been considered but are moot in view of new rejections made in response to the applicant’s amendments to the claims. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114, Applicant’s submission filed on 04/07/2026 has been entered. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 1 recites bit differences between the time-series pattern and the base line and byte differences between the time-series pattern and the base line pattern”. However, it is noted that the specification only discloses bit or byte difference between the time-series pattern and the base line pattern, but not both. This is a new matter. For the purpose of prosecution of this application, the examiner interprets the limitation as claimed, i.e. “bit and byte difference between the time-series pattern and the base line pattern”. Similarly, claims 11 and 17, recite bit and byte similarity between the time-series pattern relative to the malicious pattern which is not supported by the specification. The specification discloses in paragraphs 44, 45, and 56 support bit or byte difference or similarity and not both bit and byte similarity/mismatch. Other claims that are not specifically addressed are rejected due to dependency on one of claims 1, 11, or 17. This also constitutes new matter. Applicant may either amend the specification or the claims to address the issue. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-2, 5-6, 8, 10-13, 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker). Regarding claim 1, Goyal discloses, a data processing unit (FIG. 1B, DPU 60), comprising: at least one processor (FIG. 1C, Cores 140, ¶0071, “Cores 140 may comprise one or more microprocessors…”); and at least one memory that stores executable instructions that, when executed by the at least one processor, facilitate performance of operations (¶0206, “…the functions may be stored, as one or more instructions or code, on and/or transmitted over a computer-readable medium and executed by a hardware-based processing unit,…”) comprising: receiving a workload from a customer device that was offloaded by a server device to the data processing unit (¶0037, “each access node 17 is a highly programmable I/O processor (referred to as a data processing unit, or DPU) specially designed for offloading certain functions from servers 12 …”), (¶0057, “…. For example, hypervisor/OS 92 of CPU 90 may offload data processing tasks to DPU 60 using physical functions (PFs) and/or virtual functions (VFs) of PCIe links. VM OS 94 of CPU 90 may offload data processing tasks to DPU 60 using VFs of PCIe links.”), (¶0072, “…Thus, DPU 130 may be communicatively coupled to one or more network devices, server devices (e.g., servers 12)…”), (¶0034, FIG. 1A, “… Servers 12 provide computation and storage facilities for applications and data associated with customers 11 and may be physical (bare-metal) servers, virtual machines running on physical servers, virtualized containers running on physical servers, or combinations thereof.”, wherein customers 11 would have devices to communicate a workload to servers 12); However, Goyal does not explicitly disclose the following limitation: that the data processing unit is used for threat detection operations, determining a time-series pattern represented in the workload; comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model; and in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing a blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention. wherein the anomaly is detected based on a bit difference between the time-series pattern and the baseline pattern and a byte difference between the time-series pattern and the baseline pattern. Gechman discloses that the data processing unit is used for threat detection operations (¶0002, “…at least one embodiment pertains to processors or computing systems used to provide and enable a data processing unit (DPU) to determine, using a machine learning (ML) detection system, whether one or more computer programs, executed by a host device, are subject to malicious activity based on features extracted from data stored in physical memory of the host device”), (¶0059, FIG. 2, “FIG. 2 is a flow diagram of an example method 200 of malicious activity detection in data stored in memory associated with one or more computer programs executed by a host device, according to at least one embodiment. In at least one embodiment, method 200 may be performed by processing the logic of DPU 102. In at least one embodiment, method 200 may be performed by processing logic of DPU 152 and processing logic of accelerated AI/ML pipeline 153. The processing logic can be a combination of hardware, firmware, software, or any combination thereof. Method 200 may be performed by one or more data processing units (e.g., DPUs, CPUs, and/or GPUs), which may include (or communicate with) one or more memory devices…”), see also ¶0084, and ¶0099 to mention a few. determining by the data processing unit (¶0059, ¶0084, and ¶0099 as disclosed above), a time-series pattern represented in the workload (¶0035, “…The random-forest classification model can be a time-series-based model trained to classify a process as ransomware or non-ransomware using cascading of different numbers of snapshots in the series of snapshots. In at least one embodiment, the cascading of a different number of snapshots in the series includes a first number of snapshots obtained over a first amount of time, a second number of snapshots obtained over a second amount of time greater than the first amount of time, and a third number of snapshots obtained over a third amount of time greater than the second amount of time…”), see also ¶0029, ¶0062, ¶0075, and ¶0086, (¶0065, “…In at least one embodiment, DPU 102 can process extracted data 147 and extract features or indications from extracted data 147 before sending to ML detection system 134 (or 154). DPU 102 (or DPU 152) can collect real-time data using out-of-band memory acquisitions using hardware-accelerated security service 122. DPU 102 can integrate ransomware detection system 136 with the real-time data collected by hardware-accelerated security service 122 to detect ransomware in host physical memory 148.”); comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model (¶0035-¶0036, “… feature extraction logic 144 can extract the words and numeric features of the candidate URL and tokenize the words into tokens. In at least one embodiment, malicious URL detection system 138 includes a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. In at least one embodiment, the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure…”, wherein the output of a trained neural network classifier is fundamentally based on learned comparisons), see also ¶0063 and ¶0092, (¶0041-¶0042, “DPU 102 can be configured for traditional enterprises' modern cloud workloads and high-performance computing. In at least one embodiment, DPU 102 can deliver a set of software-defined networking, storage, security, and management services (e.g., 122-132) at a data-center scale with the ability to offload, accelerate, and isolate data center infrastructure… DPU 102 can provide a data center that is accelerated, fully programmable, and configured with security (e.g., zero-trust security) to prevent data breaches and cyberattacks. In at least one embodiment, DPU 102 can include a network adapter, an array of processor cores, and infrastructure offload engines with full software programmability. In at least one embodiment, DPU 102 can sit at an edge of a server to provide flexible, secured, high-performance cloud and AI workloads…”); in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing, by the data processing unit, an action to resolve the anomaly (¶0038, “…ML detection system 134 can send indication 149 to hardware-accelerated security service 122, and hardware-accelerated security service 122 can send an alert 151 to SIEM or XDR system 106. Alert 151 can include information about ransomware, malicious URLs, DGA domains, or the like….”), (¶0082-¶0083, “… Ransomware detection system 136, using random-forest classification model 300, classifies one or more processes as ransomware or non-ransomware and outputs an indication of ransomware 305 (or indication of non-ransomware) to SIEM or XDR system 106 for further actions by SIEM or XDR system 106”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal to include comparing the time-series pattern of a workload to the baseline pattern to detect anomaly as disclosed by Gechman and be motivated in doing so in order to output an indication of ransomware responsive to the process being classified as ransomware and specify a level of confidence that the process corresponds to the ransomware class-Gechman ¶0076 in parts. However, Goyal in view of Gechman does not explicitly disclose the limitation of: blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention; wherein the anomaly is detected based on a bit difference between the time-series pattern and the baseline pattern and a byte difference between the time-series pattern and the baseline pattern. Bansal discloses blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention (Col. 3, lines 22-42, “…In implementations, storage array controller 110A-D may include an I/O controller or the like that couples the storage array controller 110A-D for data communications, through a midplane (not shown), to a persistent storage resource 170A-B (also referred to as a “storage resource” herein)…”), ( Col. 49, lines 36-63, “system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by disabling at least one element of storage system 502. For example, in response to detecting an anomaly associated with storage elements 508, system 400 may disable storage elements 508 by shutting down storage elements 508 or otherwise preventing storage elements 508 from being involved in any operations performed by storage system 502….system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by slowing down a performance of at least one operation on storage system 502. For example, in response to detecting an abnormally high number of reads from a storage element 508 within storage system 502 during a particular time period, system 400 may provide a command for storage system 502 to slow down a speed at which data may be read from storage element 508. This may allow a user (e.g., an administrator of storage system 502) to investigate the cause of the abnormally high number of reads….”), (Col. 18, lines 57-63-Col. 19, line 1-10, “… The ambiguity that arises due to transient failures can be achieved automatically by a consensus protocol such as Paxos, hot-warm failover schemes… a consensus protocol is used, and failover is automatic…”), (Col. 30, lines 29-42, “…the systems described herein may more reliably (and with less burden placed on the user) perform backup operations relative to interactive backup management systems that require high degrees of user interactivity, offer less robust automation and feature sets, and so on.”), (Col. 32, lines 37-63, “Advances in deep neural networks have ignited a new wave of algorithms and tools for data scientists to tap into their data with artificial intelligence (AI)… prevention against cyber security threats, expertise automation…”); Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal and Gechman to include blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device as disclosed by Bansal and be motivated in doing so in order to prevent security threat to the storage system-Bansal Col. 44, lines 56-67 in parts. However, Goyal in view of Gechman and Bansal does not explicitly disclose the following limitation: wherein the anomaly is detected based on a bit difference between the time-series pattern and the baseline pattern and a byte difference between the time-series pattern and the baseline pattern. Roelker discloses: wherein the anomaly is detected based on a bit difference between the time-series pattern and the baseline pattern and a byte difference between the time-series pattern and the baseline pattern (¶0005, “A typical intrusion detection system (IDS) reads a network packet, decomposes the packet into one or more application protocols, and compares stored patterns known to constitute network or computer attacks to the data contained in the one or more application protocols. Usually, the stored patterns are character strings, which are directly compared to the characters of the protocol data.”), (¶0017, “Another embodiment of the present invention is a method for detecting an HTTP evasion on a network using an IDS. A packet transmitted on the network is intercepted. A packet is an unassembled packet (e.g., a packet taken off the wire) or an assembled packet (e.g., a packet assembled from packets taken off the wire). The packet is parsed. An Internet protocol address of the packet is identified. A Web server HTTP intrusion detection policy for a network device located at the Internet protocol address is determined… a match between the pattern from a rule of the IDS and the located URI is identified as the HTTP evasion.”), (¶0109-¶0110, “If URI normalization module 150 is in the "U_ENCODING" state, URI normalization module 150 reads the next four characters. If any of these characters are not hex characters (0-9,a-z,A-Z), then URI normalization module 150 enters the "INVALID_DECODE" state. Otherwise, URI normalization module 150 calculates the value of the hex characters and compares that value against the initialized Unicode values. If there is a match, then URI normalization module 150 decodes the character to the mapped byte value. If there is no match, the URI normalization module 150 enters the "INVALID_DECODE" state. …”), (¶0111-¶0123, FIG. 2, steps 210 -270), (Claim 21, “the decoding an obfuscation within the at least one universal resource identifier based on the Web server hypertext transport protocol intrusion detection policy comprising one or more of hex decoding, double percent hex decoding, double nibble hex decoding, first nibble hex decoding, second nibble hex decoding, eight bit unicode transformation format decoding, eight bit unicode transformation format bare byte decoding, Microsoft.TM. %U decoding, and mismatch decoding.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, and Bansal to include bit and byte differences between the network intercepted network packet and stored character strings to determine anomaly such as HTTP evasion as disclosed by Roelker and be motivated in doing so in order to decoding obfuscations within the universal resource identifiers based on the Web server hypertext transport protocol intrusion detection policy-Roelker abstract in parts. Regarding claim 11, Goyal discloses, a data processing unit (FIG. 1B, DPU 60), comprising: at least one processor (FIG. 1C, Cores 140, ¶0071, “Cores 140 may comprise one or more microprocessors…”); and at least one memory that stores executable instructions that, when executed by the at least one processor, facilitate performance of operations (¶0206, “…the functions may be stored, as one or more instructions or code, on and/or transmitted over a computer-readable medium and executed by a hardware-based processing unit,…”) comprising: receiving a workload from a customer device that was offloaded by a server device to the data processing unit (¶0037, “each access node 17 is a highly programmable I/O processor (referred to as a data processing unit, or DPU) specially designed for offloading certain functions from servers 12 …”), (¶0057, “…. For example, hypervisor/OS 92 of CPU 90 may offload data processing tasks to DPU 60 using physical functions (PFs) and/or virtual functions (VFs) of PCIe links. VM OS 94 of CPU 90 may offload data processing tasks to DPU 60 using VFs of PCIe links.”), (¶0072, “…Thus, DPU 130 may be communicatively coupled to one or more network devices, server devices (e.g., servers 12)…”), (¶0034, FIG. 1A, “… Servers 12 provide computation and storage facilities for applications and data associated with customers 11 and may be physical (bare-metal) servers, virtual machines running on physical servers, virtualized containers running on physical servers, or combinations thereof.”, wherein customers 11 would have devices to communicate a workload to servers 12); However, Goyal does not explicitly disclose the following limitation: that the data processing unit is used for threat detection operations, determining a time-series pattern represented in the workload; comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model; and in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing a blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention. wherein the blocking of the input/output (1/0) transactions are based on a bit similarity between the time-series pattern relative to the malicious pattern and a byte similarity between the time-series pattern relative to the malicious pattern. Gechman discloses that the data processing unit is used for threat detection operations (¶0002, “…at least one embodiment pertains to processors or computing systems used to provide and enable a data processing unit (DPU) to determine, using a machine learning (ML) detection system, whether one or more computer programs, executed by a host device, are subject to malicious activity based on features extracted from data stored in physical memory of the host device”), (¶0059, FIG. 2, “FIG. 2 is a flow diagram of an example method 200 of malicious activity detection in data stored in memory associated with one or more computer programs executed by a host device, according to at least one embodiment. In at least one embodiment, method 200 may be performed by processing the logic of DPU 102. In at least one embodiment, method 200 may be performed by processing logic of DPU 152 and processing logic of accelerated AI/ML pipeline 153. The processing logic can be a combination of hardware, firmware, software, or any combination thereof. Method 200 may be performed by one or more data processing units (e.g., DPUs, CPUs, and/or GPUs), which may include (or communicate with) one or more memory devices…”), see also ¶0084, and ¶0099 to mention a few. determining by the data processing unit (¶0059, ¶0084, and ¶0099 as disclosed above), a time-series pattern represented in the workload (¶0035, “…The random-forest classification model can be a time-series-based model trained to classify a process as ransomware or non-ransomware using cascading of different numbers of snapshots in the series of snapshots. In at least one embodiment, the cascading of a different number of snapshots in the series includes a first number of snapshots obtained over a first amount of time, a second number of snapshots obtained over a second amount of time greater than the first amount of time, and a third number of snapshots obtained over a third amount of time greater than the second amount of time…”), see also ¶0029, ¶0062, ¶0075, and ¶0086, (¶0065, “…In at least one embodiment, DPU 102 can process extracted data 147 and extract features or indications from extracted data 147 before sending to ML detection system 134 (or 154). DPU 102 (or DPU 152) can collect real-time data using out-of-band memory acquisitions using hardware-accelerated security service 122. DPU 102 can integrate ransomware detection system 136 with the real-time data collected by hardware-accelerated security service 122 to detect ransomware in host physical memory 148.”); comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model (¶0035-¶0036, “… feature extraction logic 144 can extract the words and numeric features of the candidate URL and tokenize the words into tokens. In at least one embodiment, malicious URL detection system 138 includes a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. In at least one embodiment, the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure…”, wherein the output of a trained neural network classifier is fundamentally based on learned comparisons), see also ¶0063 and ¶0092, (¶0041-¶0042, “DPU 102 can be configured for traditional enterprises' modern cloud workloads and high-performance computing. In at least one embodiment, DPU 102 can deliver a set of software-defined networking, storage, security, and management services (e.g., 122-132) at a data-center scale with the ability to offload, accelerate, and isolate data center infrastructure… DPU 102 can provide a data center that is accelerated, fully programmable, and configured with security (e.g., zero-trust security) to prevent data breaches and cyberattacks. In at least one embodiment, DPU 102 can include a network adapter, an array of processor cores, and infrastructure offload engines with full software programmability. In at least one embodiment, DPU 102 can sit at an edge of a server to provide flexible, secured, high-performance cloud and AI workloads…”); in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing, by the data processing unit, an action to resolve the anomaly (¶0038, “…ML detection system 134 can send indication 149 to hardware-accelerated security service 122, and hardware-accelerated security service 122 can send an alert 151 to SIEM or XDR system 106. Alert 151 can include information about ransomware, malicious URLs, DGA domains, or the like….”), (¶0082-¶0083, “… Ransomware detection system 136, using random-forest classification model 300, classifies one or more processes as ransomware or non-ransomware and outputs an indication of ransomware 305 (or indication of non-ransomware) to SIEM or XDR system 106 for further actions by SIEM or XDR system 106”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal to include comparing the time-series pattern of a workload to the baseline pattern to detect anomaly as disclosed by Gechman and be motivated in doing so in order to output an indication of ransomware responsive to the process being classified as ransomware and specify a level of confidence that the process corresponds to the ransomware class-Gechman ¶0076 in parts. However, Goyal in view of Gechman does not explicitly disclose the limitation of: blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention; wherein the blocking of the input/output (1/0) transactions are based on a bit similarity between the time-series pattern relative to the malicious pattern and a byte similarity between the time-series pattern relative to the malicious pattern. Bansal discloses blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention (Col. 3, lines 22-42, “…In implementations, storage array controller 110A-D may include an I/O controller or the like that couples the storage array controller 110A-D for data communications, through a midplane (not shown), to a persistent storage resource 170A-B (also referred to as a “storage resource” herein)…”), ( Col. 49, lines 36-63, “system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by disabling at least one element of storage system 502. For example, in response to detecting an anomaly associated with storage elements 508, system 400 may disable storage elements 508 by shutting down storage elements 508 or otherwise preventing storage elements 508 from being involved in any operations performed by storage system 502….system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by slowing down a performance of at least one operation on storage system 502. For example, in response to detecting an abnormally high number of reads from a storage element 508 within storage system 502 during a particular time period, system 400 may provide a command for storage system 502 to slow down a speed at which data may be read from storage element 508. This may allow a user (e.g., an administrator of storage system 502) to investigate the cause of the abnormally high number of reads….”), (Col. 18, lines 57-63-Col. 19, line 1-10, “… The ambiguity that arises due to transient failures can be achieved automatically by a consensus protocol such as Paxos, hot-warm failover schemes… a consensus protocol is used, and failover is automatic…”), (Col. 30, lines 29-42, “…the systems described herein may more reliably (and with less burden placed on the user) perform backup operations relative to interactive backup management systems that require high degrees of user interactivity, offer less robust automation and feature sets, and so on.”), (Col. 32, lines 37-63, “Advances in deep neural networks have ignited a new wave of algorithms and tools for data scientists to tap into their data with artificial intelligence (AI)… prevention against cyber security threats, expertise automation…”); Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal and Gechman to include blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device as disclosed by Bansal and be motivated in doing so in order to prevent security threat to the storage system-Bansal Col. 44, lines 56-67 in parts. However, Goyal in view of Gechman and Bansal does not explicitly disclose the following limitation: wherein the blocking of the input/output (1/0) transactions are based on a bit similarity between the time-series pattern relative to the malicious pattern and a byte similarity between the time-series pattern relative to the malicious pattern. Roelker discloses: wherein the blocking of the input/output (1/0) transactions are based on a bit similarity between the time-series pattern relative to the malicious pattern and a byte similarity between the time-series pattern relative to the malicious pattern (¶0005, “A typical intrusion detection system (IDS) reads a network packet, decomposes the packet into one or more application protocols, and compares stored patterns known to constitute network or computer attacks to the data contained in the one or more application protocols. Usually, the stored patterns are character strings, which are directly compared to the characters of the protocol data.”), (¶0017, “Another embodiment of the present invention is a method for detecting an HTTP evasion on a network using an IDS. A packet transmitted on the network is intercepted. A packet is an unassembled packet (e.g., a packet taken off the wire) or an assembled packet (e.g., a packet assembled from packets taken off the wire). The packet is parsed. An Internet protocol address of the packet is identified. A Web server HTTP intrusion detection policy for a network device located at the Internet protocol address is determined… a match between the pattern from a rule of the IDS and the located URI is identified as the HTTP evasion.”), (¶0109-¶0110, “If URI normalization module 150 is in the "U_ENCODING" state, URI normalization module 150 reads the next four characters. If any of these characters are not hex characters (0-9,a-z,A-Z), then URI normalization module 150 enters the "INVALID_DECODE" state. Otherwise, URI normalization module 150 calculates the value of the hex characters and compares that value against the initialized Unicode values. If there is a match, then URI normalization module 150 decodes the character to the mapped byte value. If there is no match, the URI normalization module 150 enters the "INVALID_DECODE" state. …”), (¶0111-¶0123, FIG. 2, steps 210 -270), (Claim 21, “the decoding an obfuscation within the at least one universal resource identifier based on the Web server hypertext transport protocol intrusion detection policy comprising one or more of hex decoding, double percent hex decoding, double nibble hex decoding, first nibble hex decoding, second nibble hex decoding, eight bit unicode transformation format decoding, eight bit unicode transformation format bare byte decoding, Microsoft.TM. %U decoding, and mismatch decoding.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, and Bansal to include a bit similarity between the time-series pattern relative to the malicious pattern and a byte similarity between the time-series pattern relative to the malicious pattern to determine anomaly such as HTTP evasion as disclosed by Roelker and be motivated in doing so in order to decoding obfuscations within the universal resource identifiers based on the Web server hypertext transport protocol intrusion detection policy-Roelker abstract in parts. Regarding claim 17, Goyal discloses, a method (abstract, “this disclosure describes a method that includes storing, by a data processing unit integrated circuit…”), comprising: data processing unit (FIG. 1B, DPU 60), at least one processor (FIG. 1C, Cores 140, ¶0071, “Cores 140 may comprise one or more microprocessors…”); and receiving a workload from a customer device that was offloaded by a server device to the data processing unit (¶0037, “each access node 17 is a highly programmable I/O processor (referred to as a data processing unit, or DPU) specially designed for offloading certain functions from servers 12 …”), (¶0057, “…. For example, hypervisor/OS 92 of CPU 90 may offload data processing tasks to DPU 60 using physical functions (PFs) and/or virtual functions (VFs) of PCIe links. VM OS 94 of CPU 90 may offload data processing tasks to DPU 60 using VFs of PCIe links.”), (¶0072, “…Thus, DPU 130 may be communicatively coupled to one or more network devices, server devices (e.g., servers 12)…”), (¶0034, FIG. 1A, “… Servers 12 provide computation and storage facilities for applications and data associated with customers 11 and may be physical (bare-metal) servers, virtual machines running on physical servers, virtualized containers running on physical servers, or combinations thereof.”, wherein customers 11 would have devices to communicate a workload to servers 12); However, Goyal does not explicitly disclose the following limitation: that the data processing unit is used for threat detection operations, determining a time-series pattern represented in the workload; comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model; and in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing a blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention. wherein the determining of the potential threat is based on a bit similarity between the time-series pattern relative to the stored pattern; Gechman discloses that the data processing unit is used for threat detection operations (¶0002, “…at least one embodiment pertains to processors or computing systems used to provide and enable a data processing unit (DPU) to determine, using a machine learning (ML) detection system, whether one or more computer programs, executed by a host device, are subject to malicious activity based on features extracted from data stored in physical memory of the host device”), (¶0059, FIG. 2, “FIG. 2 is a flow diagram of an example method 200 of malicious activity detection in data stored in memory associated with one or more computer programs executed by a host device, according to at least one embodiment. In at least one embodiment, method 200 may be performed by processing the logic of DPU 102. In at least one embodiment, method 200 may be performed by processing logic of DPU 152 and processing logic of accelerated AI/ML pipeline 153. The processing logic can be a combination of hardware, firmware, software, or any combination thereof. Method 200 may be performed by one or more data processing units (e.g., DPUs, CPUs, and/or GPUs), which may include (or communicate with) one or more memory devices…”), see also ¶0084, and ¶0099 to mention a few. determining by the data processing unit (¶0059, ¶0084, and ¶0099 as disclosed above), a time-series pattern represented in the workload (¶0035, “…The random-forest classification model can be a time-series-based model trained to classify a process as ransomware or non-ransomware using cascading of different numbers of snapshots in the series of snapshots. In at least one embodiment, the cascading of a different number of snapshots in the series includes a first number of snapshots obtained over a first amount of time, a second number of snapshots obtained over a second amount of time greater than the first amount of time, and a third number of snapshots obtained over a third amount of time greater than the second amount of time…”), see also ¶0029, ¶0062, ¶0075, and ¶0086, (¶0065, “…In at least one embodiment, DPU 102 can process extracted data 147 and extract features or indications from extracted data 147 before sending to ML detection system 134 (or 154). DPU 102 (or DPU 152) can collect real-time data using out-of-band memory acquisitions using hardware-accelerated security service 122. DPU 102 can integrate ransomware detection system 136 with the real-time data collected by hardware-accelerated security service 122 to detect ransomware in host physical memory 148.”); comparing, by the data processing unit, the time-series pattern to a baseline pattern generated from previously received workloads according to a long short-term memory model (¶0035-¶0036, “… feature extraction logic 144 can extract the words and numeric features of the candidate URL and tokenize the words into tokens. In at least one embodiment, malicious URL detection system 138 includes a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. In at least one embodiment, the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure…”, wherein the output of a trained neural network classifier is fundamentally based on learned comparisons), see also ¶0063 and ¶0092, (¶0041-¶0042, “DPU 102 can be configured for traditional enterprises' modern cloud workloads and high-performance computing. In at least one embodiment, DPU 102 can deliver a set of software-defined networking, storage, security, and management services (e.g., 122-132) at a data-center scale with the ability to offload, accelerate, and isolate data center infrastructure… DPU 102 can provide a data center that is accelerated, fully programmable, and configured with security (e.g., zero-trust security) to prevent data breaches and cyberattacks. In at least one embodiment, DPU 102 can include a network adapter, an array of processor cores, and infrastructure offload engines with full software programmability. In at least one embodiment, DPU 102 can sit at an edge of a server to provide flexible, secured, high-performance cloud and AI workloads…”); in response to an anomaly being detected in the time-series pattern relative to the baseline pattern, performing, by the data processing unit, an action to resolve the anomaly (¶0038, “…ML detection system 134 can send indication 149 to hardware-accelerated security service 122, and hardware-accelerated security service 122 can send an alert 151 to SIEM or XDR system 106. Alert 151 can include information about ransomware, malicious URLs, DGA domains, or the like….”), (¶0082-¶0083, “… Ransomware detection system 136, using random-forest classification model 300, classifies one or more processes as ransomware or non-ransomware and outputs an indication of ransomware 305 (or indication of non-ransomware) to SIEM or XDR system 106 for further actions by SIEM or XDR system 106”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal to include comparing the time-series pattern of a workload to the baseline pattern to detect anomaly as disclosed by Gechman and be motivated in doing so in order to output an indication of ransomware responsive to the process being classified as ransomware and specify a level of confidence that the process corresponds to the ransomware class-Gechman ¶0076 in parts. However, Goyal in view of Gechman does not explicitly disclose the limitation of: blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention; wherein the determining of the potential threat is based on a bit similarity between the time-series pattern relative to the stored pattern; Bansal discloses blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device resulting in mitigation of malicious or anomalous workloads directly within the data-path hardware without host or cloud intervention (Col. 3, lines 22-42, “…In implementations, storage array controller 110A-D may include an I/O controller or the like that couples the storage array controller 110A-D for data communications, through a midplane (not shown), to a persistent storage resource 170A-B (also referred to as a “storage resource” herein)…”), ( Col. 49, lines 36-63, “system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by disabling at least one element of storage system 502. For example, in response to detecting an anomaly associated with storage elements 508, system 400 may disable storage elements 508 by shutting down storage elements 508 or otherwise preventing storage elements 508 from being involved in any operations performed by storage system 502….system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by slowing down a performance of at least one operation on storage system 502. For example, in response to detecting an abnormally high number of reads from a storage element 508 within storage system 502 during a particular time period, system 400 may provide a command for storage system 502 to slow down a speed at which data may be read from storage element 508. This may allow a user (e.g., an administrator of storage system 502) to investigate the cause of the abnormally high number of reads….”), (Col. 18, lines 57-63-Col. 19, line 1-10, “… The ambiguity that arises due to transient failures can be achieved automatically by a consensus protocol such as Paxos, hot-warm failover schemes… a consensus protocol is used, and failover is automatic…”), (Col. 30, lines 29-42, “…the systems described herein may more reliably (and with less burden placed on the user) perform backup operations relative to interactive backup management systems that require high degrees of user interactivity, offer less robust automation and feature sets, and so on.”), (Col. 32, lines 37-63, “Advances in deep neural networks have ignited a new wave of algorithms and tools for data scientists to tap into their data with artificial intelligence (AI)… prevention against cyber security threats, expertise automation…”); Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal and Gechman to include blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device as disclosed by Bansal and be motivated in doing so in order to prevent security threat to the storage system-Bansal Col. 44, lines 56-67 in parts. However, Goyal in view of Gechman and Bansal does not explicitly disclose the following limitation: wherein the determining of the potential threat is based on a bit similarity between the time-series pattern relative to the stored pattern; Roelker discloses: wherein the determining of the potential threat is based on a bit similarity between the time-series pattern relative to the stored pattern (¶0005, “A typical intrusion detection system (IDS) reads a network packet, decomposes the packet into one or more application protocols, and compares stored patterns known to constitute network or computer attacks to the data contained in the one or more application protocols. Usually, the stored patterns are character strings, which are directly compared to the characters of the protocol data.”), (¶0017, “Another embodiment of the present invention is a method for detecting an HTTP evasion on a network using an IDS. A packet transmitted on the network is intercepted. A packet is an unassembled packet (e.g., a packet taken off the wire) or an assembled packet (e.g., a packet assembled from packets taken off the wire). The packet is parsed. An Internet protocol address of the packet is identified. A Web server HTTP intrusion detection policy for a network device located at the Internet protocol address is determined… a match between the pattern from a rule of the IDS and the located URI is identified as the HTTP evasion.”), (¶0109-¶0110, “If URI normalization module 150 is in the "U_ENCODING" state, URI normalization module 150 reads the next four characters. If any of these characters are not hex characters (0-9,a-z,A-Z), then URI normalization module 150 enters the "INVALID_DECODE" state. Otherwise, URI normalization module 150 calculates the value of the hex characters and compares that value against the initialized Unicode values. If there is a match, then URI normalization module 150 decodes the character to the mapped byte value. If there is no match, the URI normalization module 150 enters the "INVALID_DECODE" state. …”), (¶0111-¶0123, FIG. 2, steps 210 -270), (Claim 21, “the decoding an obfuscation within the at least one universal resource identifier based on the Web server hypertext transport protocol intrusion detection policy comprising one or more of hex decoding, double percent hex decoding, double nibble hex decoding, first nibble hex decoding, second nibble hex decoding, eight bit unicode transformation format decoding, eight bit unicode transformation format bare byte decoding, Microsoft.TM. %U decoding, and mismatch decoding.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing date of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, and Bansal to include wherein the determining of the potential threat is based on a bit similarity between the time-series pattern relative to the stored pattern as disclosed by Roelker and be motivated in doing so in order to decoding obfuscations within the universal resource identifiers based on the Web server hypertext transport protocol intrusion detection policy-Roelker abstract in parts. Regarding claim 2, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. Gechman further discloses wherein the long short-term memory model comprises multiple layers of memory cells configured for scanning or forecasting short term and long term trends, seasonalities, or other time-series characteristics (¶0036, “the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure…”), (¶0063, “The binary classification model can include an embedding layer, an LSTM layer, and a fully connected neural network layer. The embedding layer can receive the tokens as an input sequence of tokens representing the words in the candidate URL and generate an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure.”), (¶0092, “binary classification model 500 includes an embedding layer 502, an LSTM layer 504, and a fully connected neural network layer 506. Embedding layer 502 can receive word tokens 507 as an input sequence of tokens representing the words in the candidate URL. Embedding layer 502 can generate an input vector 511 based on the input sequence of tokens. An input vector 511 can include one embedding for each word and represent word tokens 507 in a representation of words different than the input sequence. Input vector 511 can represent the words in the candidate URL in a vector space used by LSTM layer 504. LSTM layer 504 can receive input vector 511 and generate an output vector 513 based on input vector 511. Fully connected neural network layer 506 can receive output vector 513 from LSTM layer 504 and numeric features 509. Fully connected neural network layer 506 is trained to classify the candidate URL as a malicious 501 or benign 503 using output vector 513 from the LSTM layer 504 and the numeric features 509 of the URL structure...”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include long term and short term trends forecast as disclosed by Gechman and be motivated in doing so in order to predict the level of confidence that the candidate URL corresponds to the malicious class Gechman -¶0092 in parts. Regarding claim 5, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. Gechman further discloses wherein the operations further comprise comparing the time-series pattern to a malicious pattern, of a malicious workload, generated according to the long short-term memory model (¶0029, “… obtaining a series of snapshots of the data stored in the memory and extracting a set of features from each snapshot of the series of snapshots, each snapshot representing the data at a point in time. The ML detection system can include a random-forest classification model. The random-forest classification model is a time-series-based model trained to classify a process (workload) as ransomware or non-ransomware using cascading of different numbers of snapshots in the series of snapshots (e.g., 3, 5, and 10 snapshots).”, wherein the classifier compares observed patterns over time against established baseline to make a classification decision), (¶0035-¶0036, “…malicious URL detection system 138 includes a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. In at least one embodiment, the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure. Additional details of the features of URLs and the binary classification model are described below with respect to FIGS. 5A-7.”), ¶0063, ¶0075, ¶0086, ¶0098, and ¶0102. Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include comparing the time-series pattern to a malicious pattern as disclosed by Rozenbaum and be motivated in doing so in order to accurately classify the pattern as malicious or benign using the LSTM- Gechman ¶0063 in parts. Regarding claim 6, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 5. Bansal further discloses performing the blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device (Col. 3, lines 22-42, “…In implementations, storage array controller 110A-D may include an I/O controller or the like that couples the storage array controller 110A-D for data communications, through a midplane (not shown), to a persistent storage resource 170A-B (also referred to as a “storage resource” herein)…”), (Col. 49, lines 36-63, “system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by disabling at least one element of storage system 502. For example, in response to detecting an anomaly associated with storage elements 508, system 400 may disable storage elements 508 by shutting down storage elements 508 or otherwise preventing storage elements 508 from being involved in any operations performed by storage system 502.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device as disclosed by Bansal and be motivated in doing so in order to prevent security threat to the storage system-Bansal Col. 44, lines 56-67 in parts. Regarding claim 8, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. Bansal further discloses wherein the blocking procedure further comprises transmitting a feedback request message to the customer device and the long short-term memory model uses a response to the feedback request for training or refinement (Col. 49, lines 27-35, “the notification provided by system 400 may include an option that may be selected by the user to provide feedback to system 400 regarding the detected anomaly. For example, as described herein, the user may provide feedback that indicates whether the detected anomaly is representative of an actual security threat. This feedback may be used by system 400 to refine a process by which an anomaly is identified as being a potential security threat.”), (Col. 43, lines 25-52, “… in some embodiments of the FPGA-based AI or ML platform, the FPGAs that are contained within the FPGA-accelerated servers may be reconfigured for different types of ML models (e.g., LSTMs, CNNs, GRUs). The ability to reconfigure the FPGAs that are contained within the FPGA-accelerated servers may enable the acceleration of a ML or AI application based on the most optimal numerical precision and memory model being used…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include user feedback for training or refining the model as disclosed by Bansal and be motivated in doing so in order to improve detection accuracy of the model. Regarding claim 10, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. Bansal further discloses wherein the long short-term memory model generates at least one of a first workload pattern associated with a disk wiping operation, a second workload pattern associated with a database update that is specific to a type of database, a third workload pattern associated with disk defragmentation, a fourth workload pattern indicative of on a number of overwrites after reading a specific block or track within a time slice, a fifth workload pattern indicative of a fraction of overwritten blocks relative to a total number of write requests in a specified time window, a sixth workload pattern indicative of an amount of overwriting for the specified time window consisting of multiple time slices, a seventh workload pattern indicative of an average I/O length of continuously overwritten blocks in the specified time window, or an eighth workload pattern indicative of a fraction of a first number of overwrites during the specified time window as a function of an average number of overwrites of a previous time window; and Bansal further discloses a second workload pattern associated with a database update that is specific to a type of database (Col. 16, lines 46-63, “… Each authority has an authority owner, which is a storage node that has the exclusive right to update the entities in the authority. In other words, a storage node contains the authority, and that the authority, in turn, contains entities.”), (Col. 19, lines 11-26, “As authorities are transferred between storage nodes and authority owners update entities in their authorities, the system transfers messages between the storage nodes and non-volatile solid state storage units...”), (Col. 22, lines 24-37, “… One feature of elasticity is that authorities 168 are stateless, i.e., they cache active data and metadata in their own blades' 252 DRAMs for fast access, but the authorities store every update in their NVRAM 204 partitions on three separate blades 252 until the update has been written to flash 206…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include updating of a database as disclosed by Bansal and be motivated in doing so in order to make efficient use of each storage medium-Bansal (Col. 19, lines 11-26, in parts. Regarding claim 12, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 11. Gechman further discloses wherein the operations further comprise comparing the time-series pattern to a benign pattern, of a benign workload, generated according to the long short-term memory model (¶0029, “… obtaining a series of snapshots of the data stored in the memory and extracting a set of features from each snapshot of the series of snapshots, each snapshot representing the data at a point in time. The ML detection system can include a random-forest classification model. The random-forest classification model is a time-series-based model trained to classify a process (workload) as ransomware or non-ransomware using cascading of different numbers of snapshots in the series of snapshots (e.g., 3, 5, and 10 snapshots).”, wherein the classifier compares observed patterns over time against established baseline to make a classification decision), (¶0035-¶0036, “…malicious URL detection system 138 includes a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. In at least one embodiment, the binary classification model includes an embedding layer, a Long Short-Term Memory (LSTM) layer, and a fully connected neural network layer. The embedding layer receives the tokens as an input sequence of tokens representing the words in the candidate URL and generates an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure. Additional details of the features of URLs and the binary classification model are described below with respect to FIGS. 5A-7.”), ¶0063, ¶0075, ¶0086, ¶0098, and ¶0102. Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include comparing the time-series pattern to a malicious pattern as disclosed by Gechman and be motivated in doing so in order to accurately classify the pattern as malicious or benign using the LSTM- Gechman ¶0063 in parts. Regarding claim 13, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 12. Bansal further discloses wherein the operations further comprise, in response to an anomaly being detected in the time-series pattern relative to the benign pattern, initiating the blocking of the I/O transactions of the workload prior to the I/O transactions reaching the device (Col. 3, lines 22-42, “…In implementations, storage array controller 110A-D may include an I/O controller or the like that couples the storage array controller 110A-D for data communications, through a midplane (not shown), to a persistent storage resource 170A-B (also referred to as a “storage resource” herein)…”), (Col. 49, lines 36-63, “system 400 may perform a remedial action with respect to a detected anomaly in performance metric data 604 by disabling at least one element of storage system 502. For example, in response to detecting an anomaly associated with storage elements 508, system 400 may disable storage elements 508 by shutting down storage elements 508 or otherwise preventing storage elements 508 from being involved in any operations performed by storage system 502….”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include blocking procedure that blocks input/output (I/O) transactions of the workload prior to the I/O transactions reaching a storage array device as disclosed by Bansal and be motivated in doing so in order to prevent security threat to the storage system-Bansal Col. 44, lines 56-67 in parts. Regarding claim 16, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 11. Bansal further discloses wherein the blocking comprises transmitting a feedback request message to the customer device and wherein the long short-term memory model uses a response to the feedback request for training or refinement (Col. 49, lines 27-35, “the notification provided by system 400 may include an option that may be selected by the user to provide feedback to system 400 regarding the detected anomaly. For example, as described herein, the user may provide feedback that indicates whether the detected anomaly is representative of an actual security threat. This feedback may be used by system 400 to refine a process by which an anomaly is identified as being a potential security threat.”), (Col. 43, lines 25-52, “… in some embodiments of the FPGA-based AI or ML platform, the FPGAs that are contained within the FPGA-accelerated servers may be reconfigured for different types of ML models (e.g., LSTMs, CNNs, GRUs). The ability to reconfigure the FPGAs that are contained within the FPGA-accelerated servers may enable the acceleration of a ML or AI application based on the most optimal numerical precision and memory model being used…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include user feedback for training or refining the model as disclosed by Bansal and be motivated in doing so in order to improve detection accuracy of the model. Regarding claim 18, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the method of claim 17. Gechman further discloses further comprising determining, by the data processing unit, that the time-series pattern is a benign pattern (¶0063, “…the binary classification model being trained to classify the candidate URL as malicious or benign using the set of features. The binary classification model can include an embedding layer, an LSTM layer, and a fully connected neural network layer. The embedding layer can receive the tokens as an input sequence of tokens representing the words in the candidate URL and generate an input vector based on the input sequence of tokens. The LSTM layer is trained to generate an output vector based on the input vector. The fully connected neural network layer is trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure”), (¶0095-¶0096, “… Malicious URL detection system 138, using binary classification model 500, can classify candidate URL 521 as malicious or benign and output an indication of malicious URL 505 (or indication of benign URL) to SIEM or XDR system 106 for further actions by SIEM or XDR system 106…”) Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include benign time-series pattern as disclosed by Gechman, and be motivated in doing so in order to determine by the classification model whether the system is subjected to a malicious activities-Gechman ¶0065 in parts. Roelker further discloses threat determination base on difference between the time-series pattern and the stored pattern (¶0005, “A typical intrusion detection system (IDS) reads a network packet, decomposes the packet into one or more application protocols, and compares stored patterns known to constitute network or computer attacks to the data contained in the one or more application protocols. Usually, the stored patterns are character strings, which are directly compared to the characters of the protocol data.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include determining the potential threat based on a difference between the time-series pattern and the stored pattern as disclosed by Roelker and be motivated in doing so in order to detect hypertext transport protocol attacks and hypertext transport protocol intrusion detection evasions from packets observed on a network-Roelker ¶0003 in parts. Regarding claim 19, Goyal in view of Gechman, and further in view of Bansal and further in view of Roelker discloses the method of claim 17. Gechman further discloses further comprising determining, by the data processing unit, that the time-series pattern is a malicious pattern and, in response, determining the potential threat a based on a similarity between the time-series pattern and the stored pattern (¶0028-¶0029, “…determines, using an ML detection system, whether the one or more computer programs are subject to malicious activity based on the features extracted from the data stored in the memory. The hardware-accelerated security service outputs an indication of the malicious activity responsive to a determination that one or more computer programs are subject to the malicious activity. The computer programs can be any of a host operating system (OS), an application, a guest operating system, a guest application, or the like. The hardware-accelerated security service operating on a DPU is an agentless hardware product that inspects the memory of the one or more computer programs. As such, the malware is unaware of its existence, and the hardware-accelerated security service can detect the malware during the attack, i.e., when the malware exposes itself in memory, which is easier to detect the malware…”, wherein the malware represents a potential threat), (¶0054, “…The NVIDIA Morpheus platform can provide information security to data centers to enable dynamic protection, real-time telemetry, and adaptive defenses for detecting and remediating cybersecurity threats. In at least one embodiment of FIG. 1B, DPU 152 extracts the data stored in host physical memory 148 and sends extracted data 147 to accelerated AI/ML pipeline 153 hosting ML detection system 154. In this embodiment, ML detection system 154 includes ransomware detection system 136, malicious URL detection system 138, DGA detection system 140, and optionally other malware detection systems 142 similar to ML detection system 134 of FIG. 1A.”) Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the method of Goyal, Gechman, Bansal, and Roelker to include determining the potential threat a based on a similarity between the time-series pattern and the stored pattern as disclosed by Gechman and be motivated in doing so in order to easily detect the malware during an attack, thus preventing the malware from spreading to the entire syste-Gechman ¶0028 in parts. Regarding claim 20, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the method of claim 17. Bansal further discloses further comprising, in response to the blocking, facilitating, by the data processing unit, transmission of a feedback request and utilizing, by the data processing unit, a response to the feedback request as input to the long short-term memory model to create a modified long short-term memory model for further usage (Col. 49, lines 27-35, “the notification provided by system 400 may include an option that may be selected by the user to provide feedback to system 400 regarding the detected anomaly. For example, as described herein, the user may provide feedback that indicates whether the detected anomaly is representative of an actual security threat. This feedback may be used by system 400 to refine a process by which an anomaly is identified as being a potential security threat.”), (Col. 43, lines 25-52, “… in some embodiments of the FPGA-based AI or ML platform, the FPGAs that are contained within the FPGA-accelerated servers may be reconfigured for different types of ML models (e.g., LSTMs, CNNs, GRUs). The ability to reconfigure the FPGAs that are contained within the FPGA-accelerated servers may enable the acceleration of a ML or AI application based on the most optimal numerical precision and memory model being used…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the method of Goyal, Gechman, Bansal, and Roelker to include user feedback for training or refining the model as disclosed by Bansal and be motivated in doing so in order to improve detection accuracy of the model. Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of and further in view of U.S.PGPub. No. 20220103591 to Maturana et al. (hereinafter Maturana). Regarding claim 3, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. However, the combination of Goyal, Gechman, Bansal, and Roelker does not explicitly disclose the following limitation: wherein the time-series pattern is determined in response to an examination of time-series data relating to the I/O transactions of the workload Maturana discloses wherein the time-series pattern is determined in response to an examination of time-series data relating to the I/O transactions of the workload (¶0061, “using the time-series data, the social network analyzer 72 may generate a state-space model 78 using machine learning algorithms to identify time-series patterns (e.g., network communication and behaviors of the identified IoT devices during particular time periods) and forecast information, which may be used to detect present anomalies and predict future anomalies…”) Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include using time-series data to determine time-series pattern of a workload as disclosed by Maturana and be motivated in doing so in order to continuously updating the state-space model as new network communication patterns are identified which improves forecast accuracy in detecting anomalies and potential network vulnerabilities-Maturana-¶0076 in parts. Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of and further in view of U.S.PGPub. No. 20220103591 to Maturana et al. (hereinafter Maturana) and further in view of U.S.PGPub. No. 20190379589 to Ryan et al. (hereinafter Ryan). Regarding claim 4, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker and further in view of Maturana discloses the data processing unit of claim 3. However, Goyal, in view of Gechman, Bansal, Roelker, and Maturana does not explicitly disclose: wherein the time-series data comprises at least one of: compression ratio data indicative of compression ratios of the I/O transactions over time, criticality data indicative of a priority or weight associated with an element of the time-series data, size data indicative of data sizes associated with the I/O transactions over time, type data indicative of types of the I/O transactions over time, or distribution data indicative of a distribution of the types of the I/O transactions over time. Ryan discloses size data indicative of data sizes associated with the I/O transactions over time (¶0116-¶0118, “…The standard approach to demonstrate the performance of anomaly detection (transaction) in large size time-series data is to first create a controllable abstraction of normal data and then add labeled anomalies. Thus, the properties of the data are specified including the number of sensors, time stamps and interval durations, maximum and minimum range of signals,…”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, Roelker and Maturana to include size of time-series data over time window as disclosed by Ryan and be motivated in doing so in order to detect one or more patterns of a particular category in the time-series data, and localizing the one or more patterns in time-Ryan, abstract in parts. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of U.S. Pat. No. 12095793 to Rozenbaum et al. (hereinafter Rozenbaum). Regarding claim 7, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. Bansal further discloses wherein the blocking procedure blocks the I/O transactions (Col. 49, lines 36-63, cited in claim 1 rejections. However, Goyal in view of Gechman, Bansal, and Roelker does not explicitly disclose wherein the blocking procedure blocks the I/O transactions immediately upon detection or after a defined amount of time based on a policy of a customer entity associated with the customer device. Rozenbaum discloses the limitation (Col. 14, lines 46-67 to Col. 15, lines 1-6, “…The hardware-accelerated security service allows live-network analysis (or real-time data analysis) of the network traffic and provides mitigation or enforcement to stop the network traffic that is classified as malicious immediately. In at least one embodiment, a DPU can process a copy of the network data, extract features or indications from network data, and extract features from the DPU hardware itself before sending it to an ML detection system on accelerated hardware, such as a GPU coupled to the DPU. The DPU can collect real-time data using out-of-band filtering using the hardware-accelerated security service. The DPU can integrate a network-anomaly detection system with the real-time data collected by hardware-accelerated security service to detect malicious network activity in the network traffic and immediately take enforcement, mitigation, or remedial actions in response.”), (Col. 15, lines 66-67 to Col. 16, lines 1-19, “… Hardware-accelerated security service 122 extracts feature data 321 as described above with respect to FIG. 3A, and sends, or otherwise makes available, the feature data 321 to network-anomaly detection system 136. Network anomaly detection system 136, using binary classification model 300, classifies the network activity as malicious or benign and sends an enforcement rule 323 to the hardware-accelerated security service 122, such as immediately blocking subsequent network activity by the attacker. In at least one embodiment, the network-anomaly detection system 136 can also output an indication of malicious network activity 313 to SIEM or XDR system 106 for further actions by SIEM or XDR system 106…”) Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include blocking the transaction immediate after detecting malicious activity as disclosed by Rozenbaum and be motivated in doing so in order to prevent the malicious activity by the attacker to spread to across the entire network system. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of U.S. PGPub. No. 20240168817 to Bahirat; Shirish (hereinafter Bahirat). Regarding claim 9, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 1. However, Goyal in view of Gechman, Bansal, and Roelker does not explicitly disclose: wherein the long short-term memory model generates workload patterns that are specific to a specified customer entity, the customer device, or a specified application executing on the customer device. Bahirat discloses wherein the long short-term memory model generates workload patterns that are specific to a specified customer entity, the customer device, or a specified application executing on the customer device (¶0081-¶0082, “The parameter embedding(s) 232 may be input into the parameter NN(s) 402 as a stream. The parameter NN(s) 402 may sample the stream occasionally (e.g., e.g., periodically) and output the values 422 of the parameter gradient(s) for the sample. Each of the values of 422 the parameter gradient(s) may be characterized as being a rate of change of an associated one of the parameter embedding(s) 232. Thus, by way of non-limiting examples, the parameter gradient(s) may include a bandwidth gradient, a latency gradient, a utilization gradient, an energy usage gradient, an IOP gradient, a QoS gradient, and/or a reliability gradient. The parameter gradient(s) (or rate(s) of change) may be expressed with respect to time, with respect to one another, or the like. The values 422 of the parameter gradient(s) may track variability (e.g., with respect to time) for each of the operating parameter(s). The values 422 of the parameter gradient(s) may be used to determine whether state changes caused by the action(s) 240 and/or another event are delayed in time. The values 422 of the parameter gradient(s) may reflect directional trends (e.g., increases and/or decreases) in the parameter value(s) 222. The parameter NN(s) 402 may output the values 422 of the parameter gradient(s) as an array (e.g., Tensor Values). In at least one embodiment, the parameter NN(s) 402 includes Long Short-Term Memory (“LSTM”)…”, wherein the parameter embeddings such as bandwidth gradient, a latency gradient, a utilization gradient, an energy usage gradient, an IOP gradient, a QoS gradient, etc which change over time is interpreted as workload pattern), (¶0168, “information regarding an order may be communicated to an order orchestration module 1122 that is configured to orchestrate provisioning of services and resources for an order placed by a customer. In at least one embodiment, order orchestration module 1122 may use services of order provisioning module 1124 for provisioning…”, wherein orchestrate provisioning of services and resources for an order placed by a customer is interpreted as a workload pattern). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include wherein the long short-term memory model generates workload patterns that are specific to a specified customer entity as disclosed by Bahirat and be motivated in doing so in order to performs processing to provide services in a customer's subscription order-Bahirat ¶0155 in parts. Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of U.S. Pat. No. 12058160 to Erlingsson et al. (hereinafter Erlingsson). Regarding claim 14, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 11. However, Goyal in view of Gechman, Bansal, and Roelker does not explicitly disclose the limitation of: wherein initiating the blocking comprises initiating the blocking of the I/O transactions upon detection of the match. Erlingsson discloses wherein initiating the blocking comprises initiating the blocking of the I/O transactions upon detection of the match (Col. 87, lines 15-42, “… if an identical (or sufficiently similar, following a general recognized pattern or ‘fingerprint’) threat is detected in a second customer's cloud deployment, additional context may be provided by including information in an alert that is delivered to the second customer that indicates that the threat matches the profile of a ransomware attack that was detected in the first customer's cloud deployment. In fact, information describing the remedial actions (e.g., disabling encryption, increasing the frequency of backups, locking down a backup system, blocking transmission of data externally, etc.) that were taken by the first customer may even be included in the alert to the second customer or otherwise recommended to the second customer…”) Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include detection of a match before initiating blocking the input/output (I/O) transactions of the workload prior to the I/O transactions as disclosed by Erlingsson and be motivated in doing so in order to send alert to other customers experiencing the same attack -Erlingsson Col. 87, lines 15-42 in parts. Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over PGPub. No. 20200159568 to Goyal et al. (hereinafter Goyal) in view of PGPub. No. 20230259614 to Gechman et al. (hereinafter Gechman) and further in view of US. Pat No. 10970395 to Bansal et al. (hereinafter Bansal) and further in view of US. PGPub. No. 20080276316 to Roelker et al. (hereinafter Roelker) and further in view of U.S PGPub. No. 20200311280 to Byrne; Kenneth (hereinafter Byrne). Regarding claim 15, Goyal in view of Gechman and further in view of Bansal and further in view of Roelker discloses the data processing unit of claim 11. However, Goyal in view of Gechman, Bansal, and Roelker does not explicitly disclose the following limitation: wherein initiating the blocking comprises initiating the blocking of the I/O transactions after a defined amount of time based on a policy corresponding to a customer entity associated with the customer device. Byrne discloses wherein initiating the blocking comprises initiating the blocking of the I/O transactions after a defined amount of time based on a policy corresponding to a customer entity associated with the customer device (¶0121-122, “the computer host device is a first computer host device, and operation 1008 comprises implementing, by the system, a first learning period for a second computer host device upon initially communicating with the system during which anomalous behavior by the second computer host device does not result in mitigation. That is, when the second computer host device initially connects to the system, the system may implement a learning period for a predetermined amount of time, where the second computer host device's behavior is learned. In some examples, the second computer host device can then be determined to be behaving anomalously after this learning period expires… in response to determining that the computer host device continues to behave anomalously after a predefined time period, modifying, by the system, the mitigation against the computer host device behaving anomalously. That is, the type of mitigation can be escalated (or de-escalated). In some examples, the mitigation can be escalated (e.g., escalated from Level 0 mitigation to Level 1 mitigation) where the computer host device continues to behave anomalously for a predetermined amount of time after Level 0 mitigation is implemented.”), (¶0039, “implementing the remedial action can comprise intrusion detected actions 110 indicating to computer system 110 to perform a remedial action (e.g., terminate the connection with host 102). In other examples, implementing the remedial action can comprise intrusion detected actions 110 sending an indication of the anomaly and recommended remedial action to intrusion detection user interface 116. An administrator of computer system 100 can then manually evaluate the recommended remedial action, and, optionally, indicate to computer system 104 to implement the remedial action.”), (¶0100, “… an action can be selected by intrusion management system 106 based on a predetermined set of rules for which types of mitigation correspond to which types of anomalous behavior. In other examples, an action can be selected based on receiving user input of such from an administrator of intrusion management system 106.”). Thus, one of ordinary skill in the art would have found it obvious before the effective filing data of applicant’s claimed invention to modify the data processing unit of Goyal, Gechman, Bansal, and Roelker to include blocking of the I/O transactions after a defined amount of time based on a policy as disclosed by Byrne and be motivated in doing so in order to learn the anomalous behavior of the host device-Byrne ¶0121 in parts. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 10785255. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MUDASIRU K OLAEGBE whose telephone number is (571)272-2082. The examiner can normally be reached MON-FRI. 7.30AM-5.30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 5712723739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MUDASIRU K OLAEGBE/Examiner, Art Unit 2495 /FARID HOMAYOUNMEHR/Supervisory Patent Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Show 2 earlier events
Nov 04, 2025
Applicant Interview (Telephonic)
Nov 06, 2025
Response Filed
Nov 14, 2025
Examiner Interview Summary
Jan 22, 2026
Final Rejection mailed — §103, §112
Mar 18, 2026
Response after Non-Final Action
Apr 07, 2026
Request for Continued Examination
Apr 15, 2026
Response after Non-Final Action
Jul 23, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688317
SYSTEM AND METHOD FOR ELECTRONIC ACCESS CONTROL IN MESH NETWORKED SITES
3y 8m to grant Granted Jul 21, 2026
Patent 12683932
DYNAMIC ROUTING OF APPLICATION TRAFFIC TO ZTNA CONNECTORS
3y 6m to grant Granted Jul 14, 2026
Patent 12676887
METHOD AND SYSTEM FOR GENERATING DECOY FILES USING A DEEP LEARNING ENGINE FOR PROTECTION AGAINST RANSOMWARE ATTACKS
3y 4m to grant Granted Jul 07, 2026
Patent 12621320
SYSTEMS, METHODS, AND APPARATUSES FOR DETERMINING RESOURCE MISAPPROPRIATION BASED ON DISTRIBUTION FREQUENCY IN AN ELECTRONIC NETWORK
3y 5m to grant Granted May 05, 2026
Patent 12574406
SYSTEM AND METHOD FOR DATA FILTERING IN MACHINE LEARNING MODEL TO DETECT IMPERSONATION ATTACKS
5y 3m to grant Granted Mar 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
74%
Grant Probability
91%
With Interview (+16.4%)
3y 1m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 86 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month