Prosecution Insights
Last updated: October 04, 2026
Application No. 18/469,314

ANOMALY DETECTION BASED ON BEHAVIOR MODELING LEARNED FROM MONITORED COMPUTER ACTIVITIES

Non-Final OA §103
Filed
Sep 18, 2023
Examiner
XIE, EDGAR WANGSHU
Art Unit
2433
Tech Center
2400 — Computer Networks
Assignee
Mastercard Technologies Canada Ulc
OA Round
3 (Non-Final)
85%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
23 granted / 27 resolved
+27.2% vs TC avg
Strong +32% interview lift
Without
With
+32.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
3 currently pending
Career history
32
Total Applications
across all art units

Statute-Specific Performance

§101
14.4%
-25.6% vs TC avg
§103
61.9%
+21.9% vs TC avg
§102
8.3%
-31.7% vs TC avg
§112
11.3%
-28.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 27 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action Claims and Request for Continued Examination (RCE) filed on 06/09/2026 for patent application 18/469,314 have been acknowledged. Claims 1-13 and 15-20 are currently pending and have been considered below. Claims 1, 12, and 20 are independent claims. Claims 11, 12, and 20 have been amended. No new claims have been added. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/09/2026 has been entered. Response to Arguments Applicant’s arguments with respect to claims 1-8, 11-13, 15-17, and 19-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Thus, the 35 USC 103 rejection of claims 1-8, 11-13, 15-17, and 19-20 is maintained. Claim Objections Claims 9-10 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-8, 11-13, 15-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ben-Noon et al. (US Patent No. US 12,445,493 B2, hereinafter, Ben-Noon) in view of Thomas et al. (US Patent Application No. US 20230111304 A1). Regarding Claim 1, Ben-Noon discloses: A system, comprising: a computer system comprising a processor programmed to: receive, from a monitored system, user-specific behavior data that indicates one or more types of computer activities requested by a requester (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”); identify a behavior profile that was generated during a training phase to learn behaviors of the requester, the behavior profile including information that identifies one or more computer activities that were monitored during the training phase (Ben-Noon, col 17, line 21-43, “in a block 306, browser SWB.sub.b uploads sets … to the CyberSafe security hub 52 (FIG. 1). … Expected values may be determined for a plurality of instances of session CCSESS.sub.n,s for user U.sub.n. … the expected values for a given user MyCompany user U.sub.n determine a user specific normal behavior pattern for a CCSESS.sub.n,s. … user specific normal behavior patterns and group normal behavior patterns determined by the CyberSafe hub and/or a browser SWB.sub.b are stored in a memory.”); provide, during a detection phase, the user-specific behavior data to a behavior classifier to detect whether the user-specific behavior data is anomalous (Ben-Noon, col 17, line 60 – col 18, line 4, “In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session … and/or to detect occurrence of anomalous events.”), generate, as an output of the behavior classifier, an anomaly classification based on the user-specific behavior data and the behavior profile, wherein the anomaly classification indicates a predicted anomalousness of the user-specific behavior data with respect to the behavior profile (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”) and is used to determine whether a mitigative action is to be taken in response to the one or more types of activities requested by the requester (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”); and Thomas, ¶[0119], “events are continuously analyzed against a baseline. The baseline may be adjusted to account for normal behavior. Comparison to baselines may include looking for outliers and anomalies as well as impossible events. For example, if a user logs on from Germany and then logs in from San Francisco, that may be considered impossible.”) Ben-Noon does not explicitly teach the following limitation that Thomas teaches: wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”) transmit, to the monitored system, the anomaly classification (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”) Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include: “wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data transmit, to the monitored system, the anomaly classification” because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract). Regarding Claim 2, Ben-Noon in view of Thomas teaches: The system of claim 1, wherein to receive the behavior data, the processor is further programmed to: receive the behavior data from an embedded agent of the computer system, the embedded agent operating at a device of the monitored system to monitor the one or more types of computer activities without modifying a process that provides the one or more computer activities (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”). Regarding Claim 3, Ben-Noon in view of Thomas teaches: The system of claim 2, further comprising: a device of the monitored system, wherein the device is programmed via developer coding logic that encodes one or more monitoring parameters that each identifies a permitted type of computer activity that the embedded agent is permitted to monitor; and cause, based on the developer coding logic, the embedded agent to monitor only the permitted type of computer activity specified by the one or more monitoring parameters (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”). Regarding Claim 4, Ben-Noon in view of Thomas teaches: The system of claim 2, further comprising: a device of the monitored system, wherein the device is programmed with the embedded agent to: identify the mitigative action based on the anomaly classification and one or more mitigation rules; and execute the mitigative action responsive to a request to perform the one or more computer activities (Thomas, ¶[0146], “the local security agent 1108 may locally analyze events 1106 and/or event vectors 1110 in order to permit suitable prioritization, as well as to support local detection and response to malicious, or potentially malicious activity.” ¶[0159], “this may include deployment of known remediations for malicious activity such as quarantine, termination of network communications, termination of processes or applications, an increase in local monitoring activity on affected compute instances 1102, messages to a network administrator, filtering of network activity, antivirus scans, deployment of security patches or fixes, and so forth.”). Regarding Claim 5, Ben-Noon in view of Thomas discloses: The system of claim 1, wherein to generate the anomaly classification, the processor is further programmed to: determine a vector value based on a monitored value of a computer activity and an expected value of the computer activity from the behavior profile (Thomas, ¶[0157], “By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and transform the vector value to a sub-classification score, wherein the anomaly classification is based on the sub-classification score (Thomas,¶[0327], “The local threat indication may also or instead include a classification indicating a category of malicious activity associated with events detected on the endpoint.”). Regarding Claim 6, Ben-Noon in view of Thomas teaches: The system of claim 5, wherein the behavior data comprises context data that specifies a context in which the computer activity was requested, and wherein the processor is further programmed to (Thomas, ¶[0166] “the filtered event stream may be arranged around anchor points such as a file, a domain name, or any other useful piece of data or metadata for which the presence can be monitored on an endpoint.”): determine a contextual vector value based on a monitored contextual value of the data for the computer activity and an expected value of the context data from the behavior profile (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and transform the contextual vector value to a contextual sub-classification score, wherein the anomaly classification is further based on the contextual sub-classification score (Thomas, ¶[0328], “the method 2400 may include receiving a contextual threat score calculated by a threat management facility based on event data received from contextual information received at the threat management facility. The threat management facility may use any context, event information, or the like, as generally described herein, and may evaluate a threat based on data from the endpoint”). Regarding Claim 7, Ben-Noon in view of Thomas teaches: The system of claim of claim 6, wherein the context data comprises a time and/or date of the computer activity (Ben-Noon, col 16, line 55 – col 17, line 20, “comprise data components that provide values for at least one, or any combination of more than one of: ... Session ToD (Time of Day); session duration.” Col 34, line 14-21, “Talon may provide information such as how long a tab was open, length of user 907 activity in a service, what actions has the user 907 taken within the service.”). Regarding Claim 8, Ben-Noon in view of Thomas teaches: The system of claim of claim 6, wherein the context data comprises a rate of the computer activity over time (Ben-Noon, col 16, line 55 – col 17, line 20, “comprise data components that provide values for at least one, or any combination of more than one of: ... Session ToD (Time of Day); session duration.” Col 34, line 14-21, “Talon may provide information such as how long a tab was open, length of user 907 activity in a service, what actions has the user 907 taken within the service.”). Regarding Claim 11, Ben-Noon in view of Thomas teaches: The system of claim 1, wherein the processor is further programmed to: re-learn the behavior profile based on the behavior data and/or new behavior data (Thomas, ¶[0152], “It will also be understood that, once an entity model is created, the entity model may usefully be updated, which may occur at any suitable intervals according to, e.g., the length of time to obtain a stable baseline, the amount of activity by the entity, the importance of the entity (e.g., to security, operation of a compute instance 1102, and so forth), or any other factors.”). Regarding Claim 12, Ben-Noon discloses: A method, comprising: receiving, by a processor of a computer system, from a monitored system, user-specific behavior data that indicates one or more types of computer activities requested by a requester (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”); identifying, by the processor, a behavior profile that was generated during a training phase to learn behaviors of the requester, the behavior profile including information that identifies one or more computer activities that were monitored during the training phase (Ben-Noon, col 17, line 21-43, “in a block 306, browser SWB.sub.b uploads sets … to the CyberSafe security hub 52 (FIG. 1). … Expected values may be determined for a plurality of instances of session CCSESS.sub.n,s for user U.sub.n. … the expected values for a given user MyCompany user U.sub.n determine a user specific normal behavior pattern for a CCSESS.sub.n,s. … user specific normal behavior patterns and group normal behavior patterns determined by the CyberSafe hub and/or a browser SWB.sub.b are stored in a memory.”); providing, by the processor, during a detection phase, the user-specific behavior data to a behavior classifier to detect whether the user-specific behavior data is anomalous (Ben-Noon, col 17, line 60 – col 18, line 4, “In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session … and/or to detect occurrence of anomalous events.”); generating, by the processor, as an output of the behavior classifier, an anomaly classification based on the user-specific behavior data and the behavior profile, wherein the anomaly classification indicates a predicted anomalousness of the user-specific behavior data with respect to the behavior profile (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”) and is used to determine whether a mitigative action is to be taken in response to the one or more types of activities requested by the requester (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”); and Ben-Noon does not explicitly teach the following limitation that Thomas teaches: wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”) transmit, to the monitored system, the anomaly classification (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”) Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include: “wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data transmit, to the monitored system, the anomaly classification” because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract). Regarding Claim 13, Ben-Noon in view of Thomas teaches: The method of claim 12, wherein receiving the behavior data comprises: receiving the behavior data from an embedded agent of the computer system, the embedded agent operating at a device of the monitored system to monitor the one or more types of computer activities without modifying a process that provides the one or more computer activities (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”). Regarding Claim 15, Ben-Noon in view of Thomas teaches: The method of claim 12, further comprising: identifying, by a device of the monitored system, the mitigative action based on the anomaly classification and one or more mitigation rules; and executing, by the device, the mitigative action responsive to a request to perform the one or more computer activities (Thomas, ¶[0146], “the local security agent 1108 may locally analyze events 1106 and/or event vectors 1110 in order to permit suitable prioritization, as well as to support local detection and response to malicious, or potentially malicious activity.” ¶[0159], “this may include deployment of known remediations for malicious activity such as quarantine, termination of network communications, termination of processes or applications, an increase in local monitoring activity on affected compute instances 1102, messages to a network administrator, filtering of network activity, antivirus scans, deployment of security patches or fixes, and so forth.”). Regarding Claim 16, Ben-Noon in view of Thomas teaches: The method of claim 12, wherein generating the anomaly classification comprises: determining a vector value based on a monitored value of a computer activity and an expected value of the computer activity from the behavior profile (Thomas, ¶[0157], “By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and transforming the vector value to a sub-classification score, wherein the anomaly classification is based on the sub-classification score (Thomas,¶[0327], “The local threat indication may also or instead include a classification indicating a category of malicious activity associated with events detected on the endpoint.”). Regarding Claim 17, Ben-Noon in view of Thomas teaches: The method of claim 16, wherein the behavior data comprises context data that specifies a context in which the computer activity was requested, the method further comprising (Thomas, ¶[0166] “the filtered event stream may be arranged around anchor points such as a file, a domain name, or any other useful piece of data or metadata for which the presence can be monitored on an endpoint.”): determining a contextual vector value based on a monitored contextual value of the data for the computer activity and an expected value of the context data from the behavior profile (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and transform the contextual vector value to a contextual sub-classification score, wherein the anomaly classification is further based on the contextual sub-classification score (Thomas, ¶[0328], “the method 2400 may include receiving a contextual threat score calculated by a threat management facility based on event data received from contextual information received at the threat management facility. The threat management facility may use any context, event information, or the like, as generally described herein, and may evaluate a threat based on data from the endpoint”). Regarding Claim 19, Ben-Noon in view of Thomas teaches: The method of claim 12, the method further comprising: re-learning the behavior profile based on the behavior data and/or new behavior data (Thomas, ¶[0152], “It will also be understood that, once an entity model is created, the entity model may usefully be updated, which may occur at any suitable intervals according to, e.g., the length of time to obtain a stable baseline, the amount of activity by the entity, the importance of the entity (e.g., to security, operation of a compute instance 1102, and so forth), or any other factors.”). Regarding Claim 20, Ben-Noon discloses: A computer readable medium storing instructions of an embedded agent that, when executed by one or more processors, program the one or more processors to: access a request by a requester to execute a computer activity (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”); obtain context data associated with the computer activity (Ben-Noon, col 16, line 55 – col 17, line 20, “A CCaaS-KPI(n,s) may by way of example comprise KPIs that provide values for at least one, or any combination of more than one of: CPU usage; memory usage; bandwidth usage; response time to a user's request; throughput; latency; request error rate; resources accessed; permission changes; and/or network requests.”); generate user-specific behavior data comprising an identification of the computer activity and the context data (Ben-Noon, col 17, line 60 – col 18, line 4, “in a block 314 a particular user U.sub.n′ using a given browser SWB.sub.b in a given UE.sub.e requests and is permitted access to and use of a particular My-CCaaS.sub.s′ and engages in a “current” session CCSESS.sub.n′,s′ with My-CCaaS.sub.s′. In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session to add to data already accumulated.”); transmit the user-specific behavior data to a computer system for anomaly classification of the user-specific behavior data (Ben-Noon, col 17, line 44 – col 18, line 4, “in a block 310, SWB.sub.b and/or the CyberSafe hub processes data provided by CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and/or SMETA(n,s) to determine cyber vulnerabilities associated with MyCompany users using a My-CCaaS.sub.s and/or with a specific MyCompany user.”); the anomaly classification representing a prediction of an extent to which the computer activity deviates from a learned normal behavior based on previously learned computer activities of the requester (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”); access one or more mitigation rules corresponding to the anomaly classification; and identify a mitigative action to take or no mitigative action to take based on the one or more mitigation rules (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”). Ben-Noon does not explicitly teach the following limitation that Thomas teaches: wherein the computer system is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; being based on the plurality of deviation values (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”) receive an anomaly classification from the computer system (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”) Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include: “wherein the computer system is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; being based on the plurality of deviation values receive an anomaly classification from the computer system” because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDGAR W XIE whose telephone number is (703)756-4777. The examiner can normally be reached Monday - Friday, 8:00am - 5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JEFFREY PWU can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EDGAR W XIE/ Examiner, Art Unit 2433 /WASIKA NIPA/ Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Show 2 earlier events
Nov 14, 2025
Examiner Interview Summary
Nov 14, 2025
Applicant Interview (Telephonic)
Nov 20, 2025
Response Filed
Jan 29, 2026
Examiner Interview (Telephonic)
Mar 09, 2026
Final Rejection mailed — §103
Jun 09, 2026
Request for Continued Examination
Jun 16, 2026
Response after Non-Final Action
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12717896
SYSTEM AND METHOD FOR SECURING A NEURAL NETWORK RUNTIME ENGINE
3y 0m to grant Granted Aug 25, 2026
Patent 12694122
SYSTEMS AND METHODS FOR REVERSE ENGINEERING-BASED DETECTION OF VULNERABILITIES
3y 0m to grant Granted Jul 28, 2026
Patent 12688281
AUTOMATED AI MODEL-BASED PIPELINE FOR DETECTION EXPLAINABILITY
2y 1m to grant Granted Jul 21, 2026
Patent 12682070
RETRAINING MACHINE LEARNING MODEL FOR COMPUTER VULNERABILITY EXPLOITATION DETECTION
3y 4m to grant Granted Jul 14, 2026
Patent 12670244
HUMAN INTERFACE DEVICE FIREWALL
2y 8m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+32.2%)
2y 7m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 27 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month