Prosecution Insights
Last updated: October 01, 2026
Application No. 18/476,161

PREDICTIVE MAINTENANCE FOR DISTRIBUTED SYSTEMS

Final Rejection §103
Filed
Sep 27, 2023
Examiner
TEKLE, DANIEL T
Art Unit
2481
Tech Center
2400 — Computer Networks
Assignee
Hewlett Packard Enterprise Development L.P.
OA Round
2 (Final)
63%
Grant Probability
Moderate
3-4
OA Rounds
6m
Est. Remaining
57%
With Interview

Examiner Intelligence

Grants 63% of resolved cases
63%
Career Allowance Rate
479 granted / 758 resolved
+5.2% vs TC avg
Minimal -6% lift
Without
With
+-6.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 6m
Avg Prosecution
24 currently pending
Career history
796
Total Applications
across all art units

Statute-Specific Performance

§101
9.9%
-30.1% vs TC avg
§103
46.9%
+6.9% vs TC avg
§102
32.5%
-7.5% vs TC avg
§112
3.9%
-36.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 758 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments and amendments received July 01, 2026 have been fully considered. with regard to 35 U.S.C. § 102, Applicant argues that the cited prior art does not disclose “see applicant argument pages 6-10”. This language corresponds to claims 1- 20, specifically to independent claims with additional limitation added to claims. As such, these have been considered and the rejection modified to 103 based amendment to claims and further applicant argument against art of Kaul are not persuasive as addressed below. See the rejection how the art on record reads on the claimed invention as well as the examiner's interpretation of the cited art in view of the presented claim set as outlined below. Furthermore, art of Kaul teaches detecting anomaly or normal by monitoring log data presented from multiple hosts or device. The system of Kaul detecting log data that consider anomaly or not normal for multiple hosts or device considered obvious corresponding to the claimed invention detecting “clique or similar behavior”. Applicant arguments in regarding the claimed invention “training the machine learning model”, Kaul teaches the contribution module receives the labeled data directly from the anomaly detector as it is generated and is then able to use this labeled data to train the one or more machine-learning models to determine the contribution of each feature. As such, the examiner stands with the rejection as outlined under 103 rejection below. For further amendment or argument, see a prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. Nyamwange et al. US 2025/0028621 at least para 0111 and Fig. 4 and Qadri et al. US 11,366,466. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-8, 13-16 and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Kaul US 2023/0275915. In regarding to claim 1 Kaul teaches: 1. A method, comprising: collecting log data from an application monitoring one or more hosts of a data center site, [0028] FIG. 1 illustrates an example network 100 that implements the principles described herein. As illustrated in FIG. 1, the network 100 includes a monitoring system 120 that is configured to monitor logon events received from various devices as the devices log onto the network 100. Based on the monitoring of the logon events, the monitoring system 120 is able to determine if any of the received events are anomalous and is able to provide information regarding which features related to the received logon events are likely to have caused the anomaly. This information may then be used to investigate if any of the anomalous events are indicative of a malicious actor or intent or are simply a benign anomaly. This process will be described in more detail to follow. Kaul, 0028 and Figs. 1, 9-10, emphasis added based on the log data, creating a clique comprising a subset of the one or more hosts exhibiting sufficiently similar behavior relative to a threshold; [0032] As shown in FIG. 1, the monitoring system 120 includes an anomaly detector 140. In one embodiment, the anomaly detector 140 receives the logon event data from the event log 130 as shown at 131 and detects anomalous instances of a logon event using one or more machine-learning models 142. In other embodiments, the logon event data 110A, 111A, 112A and potentially 113A may be received by the anomaly detector 140 directly from the devices 110-113. The one or more machine-learning models 142 are trained on at least a subset of the logon event data 131 received from the event log 130 or a subset of the logon event data received directly from the devices 110-113. [0035] The monitoring system 120 includes a contribution module 150. The labeled data 141 is provided to a contribution module 150. In operation, the contribution module 150 determines which features related to the received logon events included in the labeled data 141 are likely to have caused an instance of the logon event data to be labeled as an anomaly or as normal using one or more machine-learning models 152. As mentioned, the labeled data 141 is labeled data because the anomaly detector 140 has labeled each instance of the logon event data. Thus, the training of the one or more machine-learning models 152 are considered supervised learning models as they use labeled data as training data. The training and use of the contribution module 150 will be described in more detail to follow. Kaul, 0032-0035 and Fig. 1, 9-10, emphasis added preparing the log data to train a machine learning model configured to predict existence of a predictive maintenance state for any of the subset of the one or more hosts of the clique; [0036] It will be appreciated that having the labeled data that is generated by the anomaly detector 140 be used by the contribution module 150 provides the technical benefit of having labeled data for use in near real time. In other words, there is not a need to generate and store previously labeled data to train the one or more machine-learning models 152. Rather, the contribution module 150 receives the labeled data 141 directly from the anomaly detector 140 as it is generated and is then able to use this labeled data to train the one or more machine-learning models 152 to determine the contribution of each feature as will be explained in more detail to follow. [0038] The output data 161 focuses any investigation by either a human user or a computing system of what features caused an anomaly to occur. For example, in an embodiment where there are 60 features related to each instance of a logon event, there may only be three or four of these features that had any effect on whether the logon event was labeled as an anomaly or as normal. By showing this in the output data 161, the human user or to the computing system need only focus an investigation on the three or four features that likely caused the anomaly to occur. If these features are indicative of a benign anomaly, then the investigation can quickly end. However, if the features indicate a malicious anomaly, then further investigation can be performed as needed. It will be appreciated that the focusing of the investigation provides a technical benefit of saving on time and computing resources as only a small number of the features need be investigated. Without such focusing, a human user or computing system would likely have to investigate all features, thus wasting time and computing resources on the many features that likely have no effect of whether the instance of the logon event was labeled as an anomaly or as normal. Kaul, 0037-0038 and Fig. 1, 9-10, emphasis added training the machine learning model with the log data, and operationalizing the machine learning model for the clique to predict the existence of anomalous data in further log data collected from the application, the existence of anomalous data reflecting the existence of a predictive maintenance state. [0036] It will be appreciated that having the labeled data that is generated by the anomaly detector 140 be used by the contribution module 150 provides the technical benefit of having labeled data for use in near real time. In other words, there is not a need to generate and store previously labeled data to train the one or more machine-learning models 152. Rather, the contribution module 150 receives the labeled data 141 directly from the anomaly detector 140 as it is generated and is then able to use this labeled data to train the one or more machine-learning models 152 to determine the contribution of each feature as will be explained in more detail to follow. [0038] The output data 161 focuses any investigation by either a human user or a computing system of what features caused an anomaly to occur. For example, in an embodiment where there are 60 features related to each instance of a logon event, there may only be three or four of these features that had any effect on whether the logon event was labeled as an anomaly or as normal. By showing this in the output data 161, the human user or to the computing system need only focus an investigation on the three or four features that likely caused the anomaly to occur. If these features are indicative of a benign anomaly, then the investigation can quickly end. However, if the features indicate a malicious anomaly, then further investigation can be performed as needed. It will be appreciated that the focusing of the investigation provides a technical benefit of saving on time and computing resources as only a small number of the features need be investigated. Without such focusing, a human user or computing system would likely have to investigate all features, thus wasting time and computing resources on the many features that likely have no effect of whether the instance of the logon event was labeled as an anomaly or as normal. Kaul, 0037-0038 and Fig. 1, 9-10, emphasis added however, Kaul fails to explicitly teach, the one or more hosts comprising systems housed in the data center for delivering resources to users remote from the data center. Official Notice is taken that both the concept and the advantage of implementing the one or more hosts comprising systems housed in the data center for delivering resources to users remote from the data center are well known and expected in the art since position or location hosts can be consider interchangeable in between two opposite end sites. Thus, it would have been obvious to one skilled in the art, before the effective filing date of the claimed invention to utilize said feature within said system taught by Kaul because such incorporation would result in exchange data between two devices. In regarding to claim 2 Kaul teaches: 2. The method of claim 1, further comprising fetching, from the one or more hosts, services information associated with each of the one or more hosts. [0028] FIG. 1 illustrates an example network 100 that implements the principles described herein. As illustrated in FIG. 1, the network 100 includes a monitoring system 120 that is configured to monitor logon events received from various devices as the devices log onto the network 100. Based on the monitoring of the logon events, the monitoring system 120 is able to determine if any of the received events are anomalous and is able to provide information regarding which features related to the received logon events are likely to have caused the anomaly. This information may then be used to investigate if any of the anomalous events are indicative of a malicious actor or intent or are simply a benign anomaly. This process will be described in more detail to follow. Kaul, 0028 and Fig. 1, 9-10, emphasis added In regarding to claim 3 Kaul teaches: 3. The method of claim 2, wherein the services information comprises a per-host list of logged services, the logged services comprising one or more measurands. [0041] In some embodiments, there may be any number of features that are associated with the logon event data. For example, in one embodiment the features may include, but are not limited to, (1) a device name or identification, (2) an indication of a successful or unsuccessful logon, (3) an IP address from where the logon occurred, (4) a number of times a logon is successful or unsuccessful, (5) an account name, (6) an organization name, (7) a day of a week the logon occurred, (8) a time of a day the logon occurred, (9) an owner type, (10) a service type, (11) a domain type, (12) an operating system of the device, (13) whether this is a first logon attempt, (14) a location from where the logon occurs, or (15) whether a new IP host or service was used at the logon time. It will be noted that the above listed features are just some of the numerous types of features that may be associated with the logon event data. Accordingly, the types and number of features associated with the logon event data may change as circumstances warrant and is not to be used to limit the embodiments disclosed herein. Kaul, 0041-0042 and Figs. 2, 9-10, emphasis added In regarding to claim 4 Kaul teaches: 4. The method of claim 3, wherein creating the clique comprises iterating the log data over each of the one or more measurands. Kaul, 0041-0042 and Figs. 2, 9-10 In regarding to claim 5 Kaul teaches: 5. The method of claim 4, wherein creating the clique further comprises determining a correlation between each of the pairs of the one or more hosts based on the per-measurand log data associated with each host of each of the pairs of the one or more hosts and the threshold, the correlation reflecting similarity of behavior. [0058] As can be seen from the FIG. 7, features 701-704 have the greatest contribution to the logon event data being anomalous. Advantageously, a human user or a computing system is able to focus any further investigation of an anomaly on the features 7-1-704 since these features are the mostly likely to have caused the anomaly to be detected. In other words, the visualization 700 provides a starting point for the further investigation that avoids the need to look at all the features, thus saving time and computing resources. Kaul, 0057-0058 and Figs. 7, 9-10 In regarding to claim 6 Kaul teaches: 6. The method of claim 5, wherein the preparing of the log data comprises, for each of the cliques removing non-valued vectors from the log data. [0058] As can be seen from the FIG. 7, features 701-704 have the greatest contribution to the logon event data being anomalous. Advantageously, a human user or a computing system is able to focus any further investigation of an anomaly on the features 7-1-704 since these features are the mostly likely to have caused the anomaly to be detected. In other words, the visualization 700 provides a starting point for the further investigation that avoids the need to look at all the features, thus saving time and computing resources. Kaul, 0057-0058 and Figs. 7, 9-10 In regarding to claim 7 Kaul teaches: 7. The method of claim 6, wherein the preparing of the log data further comprises, for each of the cliques, imputing the log data. [0058] As can be seen from the FIG. 7, features 701-704 have the greatest contribution to the logon event data being anomalous. Advantageously, a human user or a computing system is able to focus any further investigation of an anomaly on the features 7-1-704 since these features are the mostly likely to have caused the anomaly to be detected. In other words, the visualization 700 provides a starting point for the further investigation that avoids the need to look at all the features, thus saving time and computing resources. Kaul, 0057-0058 and Figs. 7, 9-10, emphasis added In regarding to claim 8 Kaul teaches: 8. The method of claim 6, wherein the preparing of the log data further comprises, for each of the cliques, scaling the log data. [0058] As can be seen from the FIG. 7, features 701-704 have the greatest contribution to the logon event data being anomalous. Advantageously, a human user or a computing system is able to focus any further investigation of an anomaly on the features 7-1-704 since these features are the mostly likely to have caused the anomaly to be detected. In other words, the visualization 700 provides a starting point for the further investigation that avoids the need to look at all the features, thus saving time and computing resources. Kaul, 0057-0058 and Figs. 7, 9-10, emphasis added In regarding to claim 13 Kaul teaches: 13. The method of claim 1, wherein the machine learning model comprises an unsupervised autoencoder. [0033] The logon event data received at the anomaly detector 140 is considered unlabeled or unsupervised data. That is, since there has been no prior labeling of the logon event data by either a human actor or a computerized system, the logon event data includes no ground truth labeling. Thus, the one or more machine-learning models 142 are considered unsupervised machine learning models as they perform the anomaly detection. In the embodiments disclosed herein, the use of unlabeled or unsupervised data as training data for the one or more machine-learning models 142 advantageously provides the technical benefit of not having to have a large data store for a large amount of labeled or supervised data. Rather, as previously discussed, the anomaly detector 140 is able to use the one or more machine-learning models 142 on recently obtained logon event data to determine anomalies. Thus, computing processing and storage resources are saved. The training and use of the anomaly detector 140 will be described in more detail to follow. Kaul, 0033-0054 and Figs. 9-10, emphasis added In regarding to claim 14 Kaul teaches: 14. The method of claim 13, wherein the unsupervised autoencoder is designed for accurate reconstruction of non-anomalous log data from the monitoring application, and less-accurate reconstruction of anomalous log data from the monitoring application. [0033] The logon event data received at the anomaly detector 140 is considered unlabeled or unsupervised data. That is, since there has been no prior labeling of the logon event data by either a human actor or a computerized system, the logon event data includes no ground truth labeling. Thus, the one or more machine-learning models 142 are considered unsupervised machine learning models as they perform the anomaly detection. In the embodiments disclosed herein, the use of unlabeled or unsupervised data as training data for the one or more machine-learning models 142 advantageously provides the technical benefit of not having to have a large data store for a large amount of labeled or supervised data. Rather, as previously discussed, the anomaly detector 140 is able to use the one or more machine-learning models 142 on recently obtained logon event data to determine anomalies. Thus, computing processing and storage resources are saved. The training and use of the anomaly detector 140 will be described in more detail to follow. Kaul, 0033-0054 and Figs. 9-10, emphasis added In regarding to claim 15 Kaul teaches: 15. The method of claim 14, wherein the existence of anomalous data is determined based on a reconstruction error threshold. [0052] The machine learning model 530 is then configured to analyze the plurality of features to train the one or more machine-learning models 540. The one or more machine-learning models 540 are trained to determine a contribution score for each of the extracted features to the label given to the instance of the logon event data. In other words, a score is determined that specifies which features are likely to have caused an instance of the logon event data to be labeled as an anomaly or as normal. Kaul, 0052, 0054 and Figs. 7, 9-10, emphasis added. In regarding to claim 16 Kaul teaches: 16. A system, comprising: a processor; and a memory comprising machine-readable instructions that when executed, cause the processor to: collect data reflecting state values corresponding to features of one or more hosts of a data center site; [0028] FIG. 1 illustrates an example network 100 that implements the principles described herein. As illustrated in FIG. 1, the network 100 includes a monitoring system 120 that is configured to monitor logon events received from various devices as the devices log onto the network 100. Based on the monitoring of the logon events, the monitoring system 120 is able to determine if any of the received events are anomalous and is able to provide information regarding which features related to the received logon events are likely to have caused the anomaly. This information may then be used to investigate if any of the anomalous events are indicative of a malicious actor or intent or are simply a benign anomaly. This process will be described in more detail to follow. Kaul, 0028 and Figs. 1, 9-10, emphasis added process and derive representations of the collected data to create one or more groups comprising one or more subsets of the one or more hosts exhibiting sufficiently similar behavior relative to a threshold; [0032] As shown in FIG. 1, the monitoring system 120 includes an anomaly detector 140. In one embodiment, the anomaly detector 140 receives the logon event data from the event log 130 as shown at 131 and detects anomalous instances of a logon event using one or more machine-learning models 142. In other embodiments, the logon event data 110A, 111A, 112A and potentially 113A may be received by the anomaly detector 140 directly from the devices 110-113. The one or more machine-learning models 142 are trained on at least a subset of the logon event data 131 received from the event log 130 or a subset of the logon event data received directly from the devices 110-113. [0035] The monitoring system 120 includes a contribution module 150. The labeled data 141 is provided to a contribution module 150. In operation, the contribution module 150 determines which features related to the received logon events included in the labeled data 141 are likely to have caused an instance of the logon event data to be labeled as an anomaly or as normal using one or more machine-learning models 152. As mentioned, the labeled data 141 is labeled data because the anomaly detector 140 has labeled each instance of the logon event data. Thus, the training of the one or more machine-learning models 152 are considered supervised learning models as they use labeled data as training data. The training and use of the contribution module 150 will be described in more detail to follow. Kaul, 0032-0035 and Fig. 1, 9-10, emphasis added further process and derive representations of the collected data to train an unsupervised machine learning model configured to predict existence of a predictive maintenance state for any of the one or more subsets of the one or more hosts of the one or more groups; [0033] The logon event data received at the anomaly detector 140 is considered unlabeled or unsupervised data. That is, since there has been no prior labeling of the logon event data by either a human actor or a computerized system, the logon event data includes no ground truth labeling. Thus, the one or more machine-learning models 142 are considered unsupervised machine learning models as they perform the anomaly detection. In the embodiments disclosed herein, the use of unlabeled or unsupervised data as training data for the one or more machine-learning models 142 advantageously provides the technical benefit of not having to have a large data store for a large amount of labeled or supervised data. Rather, as previously discussed, the anomaly detector 140 is able to use the one or more machine-learning models 142 on recently obtained logon event data to determine anomalies. Thus, computing processing and storage resources are saved. The training and use of the anomaly detector 140 will be described in more detail to follow. Kaul, 0033-0054 and Figs. 9-10, emphasis added predict the existence of anomalous data in further collected data by applying the trained unsupervised machine learning models to respective ones of the one or more groups, the existence of anomalous data reflecting the existence of a predictive maintenance state. [0036] It will be appreciated that having the labeled data that is generated by the anomaly detector 140 be used by the contribution module 150 provides the technical benefit of having labeled data for use in near real time. In other words, there is not a need to generate and store previously labeled data to train the one or more machine-learning models 152. Rather, the contribution module 150 receives the labeled data 141 directly from the anomaly detector 140 as it is generated and is then able to use this labeled data to train the one or more machine-learning models 152 to determine the contribution of each feature as will be explained in more detail to follow. [0038] The output data 161 focuses any investigation by either a human user or a computing system of what features caused an anomaly to occur. For example, in an embodiment where there are 60 features related to each instance of a logon event, there may only be three or four of these features that had any effect on whether the logon event was labeled as an anomaly or as normal. By showing this in the output data 161, the human user or to the computing system need only focus an investigation on the three or four features that likely caused the anomaly to occur. If these features are indicative of a benign anomaly, then the investigation can quickly end. However, if the features indicate a malicious anomaly, then further investigation can be performed as needed. It will be appreciated that the focusing of the investigation provides a technical benefit of saving on time and computing resources as only a small number of the features need be investigated. Without such focusing, a human user or computing system would likely have to investigate all features, thus wasting time and computing resources on the many features that likely have no effect of whether the instance of the logon event was labeled as an anomaly or as normal. Kaul, 0033-0034, 0037-0038 and Fig. 1, 9-10, emphasis added however, Kaul fails to explicitly teach, the one or more hosts comprising systems housed in the data center for delivering resources to users remote from the data center. Official Notice is taken that both the concept and the advantage of implementing the one or more hosts comprising systems housed in the data center for delivering resources to users remote from the data center are well known and expected in the art since position or location hosts can be consider interchangeable in between two opposite end sites. Thus, it would have been obvious to one skilled in the art, before the effective filing date of the claimed invention to utilize said feature within said system taught by Kaul because such incorporation would result in exchange data between two devices. In regarding to claim 18 Kaul teaches: 18. The system of claim 17, wherein the further processing and deriving of the representations comprises generating a time-host matrix, each row of which represents the state values corresponding to the at least one host of the one or more hosts at a given time. [0058] As can be seen from the FIG. 7, features 701-704 have the greatest contribution to the logon event data being anomalous. Advantageously, a human user or a computing system is able to focus any further investigation of an anomaly on the features 7-1-704 since these features are the mostly likely to have caused the anomaly to be detected. In other words, the visualization 700 provides a starting point for the further investigation that avoids the need to look at all the features, thus saving time and computing resources. Kaul, 0057-0058 and Figs. 7, 9-10, emphasis added Claims 19-20 list all similar elements of claims 14-15, but in system form rather than method form. Therefore, the supporting rationale of the rejection to claims 14-15 applies equally as well to claims 19-20. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 9-12 and are rejected under 35 U.S.C. 103 as being unpatentable over Kaul US 2023/0275915 as applied to claims 1-8 above, and further in view of Arnaldo et al. US 2018/0176243. In regarding to claim 9 Kaul teaches: 9. The method of claim 3, however, Kaul fails to explicitly teach, but Arnaldo teaches: further comprising generating a time-host matrix, rows of which correspond to state values of each of the one or more measurands at various points in time. [0012] According to various embodiments, the present disclosure provides a cybersecurity method comprising: forming a time based series of behavioral features by extracting at least one behavioral feature from a first set of log data retrieved over a first time segment, and extracting at least one behavioral feature from a second set of log data retrieved over a second time segment; and analyzing the time based series of behavioral features for attack detection, new features derivation, features evaluation, or a combination thereof, wherein said analyzing the time based series of behavioral features comprises using a neural network based system, a dimensionality reduction system, random forest system, or combinations thereof. In one embodiment, the behavioral features of the time-based series of behavioral features comprise human engineered features, machined learned features, or a combination thereof. In a further embodiment, each of the at least one behavioral features is a human engineered feature, and analyzing the time based series of features is used to derive new features. In a further embodiment, each of the at least one the behavioral feature is extracted by activity tracking, activity aggregation, or a combination thereof. In yet a further embodiment, forming a time based series of behavioral features further comprises retrieving log lines belonging to at least one log line parameter. In another embodiment, each of the at least one behavioral feature is associated with a unique entity. In a further embodiment, the time-based series of behavioral features is formatted into a time-based matrix, wherein each behavioral feature is associated with an entity and a time segment. In yet a further embodiment, the time based series of behavioral features comprises a multivariate time series dataset, Arnaldo, 0012, 0037-0038 and Fig. 1, emphasis added. Accordingly, it would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Arnaldo with the system of Kaul in order further comprising generating a time-host matrix, rows of which correspond to state values of each of the one or more measurands at various points in time, as such, the behavioral features of the time-based series of behavioral features comprise human engineered features, and/or machined learned features, wherein the method may be used to learn new features from historic features..—Abstract. Note: The motivation that was applied to claim 9 above, applies equally as well to claims 10-12 and 17 as presented blow. In regarding to claim 10 Kaul teaches: 10. The method of claim 9, further comprising removing from the time-host matrix, state values associated with a host that does not belong in the clique, creating a clique-specific time-host matrix. Arnaldo, 0012, 0037-0038 and Fig. 1 In regarding to claim 11 Kaul teaches: 11. The method of claim 10, further comprising imputing and scaling the clique-specific time-host matrix. Arnaldo, 0012, 0037-0038 and Fig. 1 In regarding to claim 12 Kaul teaches: 12. The method of claim 11, further comprising training the machine learning model with the state values of the imputed and scaled clique-specific time-host matrix. Arnaldo, 0012, 0037-0038 and Fig. 1 Claim 17 list all similar elements of claim 9, but in system form rather than method form. Therefore, the supporting rationale of the rejection to claim 9 applies equally as well to claim 17. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL T TEKLE whose telephone number is (571)270-1117. The examiner can normally be reached Monday-Friday 8:00-4:30 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Vaughn can be reached at 571-272-3922. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DANIEL T TEKLE/Primary Examiner, Art Unit 2481
Read full office action

Prosecution Timeline

Sep 27, 2023
Application Filed
Apr 01, 2026
Non-Final Rejection mailed — §103
Jun 19, 2026
Interview Requested
Jul 01, 2026
Response Filed
Sep 10, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744859
VIDEO SPECIAL EFFECT PROCESSING METHOD AND APPARATUS, AND ELECTRONIC DEVICE
2y 3m to grant Granted Sep 22, 2026
Patent 12743218
METHOD AND SYSTEM FOR SYSTEM DATA STORAGE AND MANAGEMENT
2y 2m to grant Granted Sep 22, 2026
Patent 12732594
BANDWIDTH ALLOCATION
3y 10m to grant Granted Sep 08, 2026
Patent 12718562
Electronic Monitoring System and Method Having Dynamic Activity Zones
2y 6m to grant Granted Aug 25, 2026
Patent 12720043
IMAGE ENCODING/DECODING METHOD AND APPARATUS AND RECORDING MEDIUM FOR STORING BITSTREAM
1y 8m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
63%
Grant Probability
57%
With Interview (-6.0%)
3y 6m (~6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 758 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month