Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed April 9, 2026 have been fully considered but they are not persuasive. In claims 1, 4-12, and 15-20 were previously rejected under 35 U.S.C. § 112(a) (“112(a)”) for allegedly failing to comply with the written description requirement. To definitively resolve this issue and advance prosecution, independent claims 1, 12, and 20 have been amended to now recite “scanning, by a malware detector, the source object and the target object to determine whether any of the source object and the target object is a malicious object”, which is supported by paragraph [0039] and [0057] of the Specification, and was previously rejected in the previous Office Action (“OA”) dated January 28, 2026. Furthermore, Applicant amends the claims regarding “generating […] attack summary” to now recite a natural language processing (NLP) machine learning model used to generate the attack summary by matching actions in the attack chain to a plurality of summary templates, with support from paragraph [0043] stating a summary generator 114 performing said limitations of the claims. Applicant requests that the written description rejections under 112(a) be withdrawn, as the amended claim language is now drawn verbatim from the original Specification.
Examiner states that the limitation of “scanning, by a malware detector, the source object and the target object to determine whether any of the source object and the target object is a malicious object” will remain rejected under 112(a) for the reasons that how a user interface generator 106 determines an object being malicious in step 406 in Fig. 4, and how the invention determines whether “word.exe” or “powershell.exe” is malicious based on actions performed in the example provided in paragraph [0057] remains. However, with the addition of the malware detector 106, even as described in paragraph [0039] that is used to detect a malicious object, and then a remediation module determines remediation actions to perform, the malware detector itself does not provide any specifics as to how it performs the detection of the malicious object, such as if the objects are compared to another module that compares the object to a directory of malicious code, or if certain bytes are determined in the object to be malicious, remains unclear in the claims and in the Specification. While the limitation of “generating […] attack summary” was not originally rejected in the previous OA, Applicant has amended the claim and provided support in the Specification, specifically paragraphs [0043], to state how the process of generating the attack summary is performed, which includes matching actions in an attack chain to a plurality of summary templates, which clarifies how the limitation is performed. As a result, claims 1, 4-12, and 15-20 remain rejected under 112(a) for the lack of clarification regarding the malware detector being utilized to detect malicious objects as it was stated in the previous OA.
In page 2 of the remarks, it is stated that claims 1, 4-12, and 15-20 were previously rejected under 35 U.S.C. § 103 as being unpatentable over U.S. Publication No. 2021/0294896 (hereinafter "Murphy") in view of U.S. Patent No. 11,212,299 (hereinafter "Gamble"). Applicant has amended the independent claims to focus on the generation of an attack summary, reciting: “matching actions in the attack chain to a plurality of summary templates; and stitching the plurality of summary templates together using a natural language processing machine learning model to generate the attack summary”. Applicant states that while Murphy focuses on graphical display of a threat, and an EDR auto-play interface highlighting key events and a visual tree, it does not disclose matching actions to a plurality of text-based summary templates, and is silent regarding natural language processing (NLP) machine learning (ML) models to stitch templates together, as recited above. Gamble focuses on backend numerical analysis and correlation, processes cybersecurity logs into graph data structures to identify anomaly links and assigns probability scores to potential attack chains, and while Gamble aggregates events into clustered graphs, it relies entirely on structured numeric data, anomaly ratings, and statistical distributions, and does not recite the limitations as described above. Applicant requests withdrawal of the rejections to the independent claims above.
Applicant’s arguments with respect to the independent claims 1, 12, and 20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Examiner states that while Murphy in view of Gamble does not teach or suggest the limitation of “stitching the plurality of summary templates together using a natural language processing machine learning model to generate the attack summary”, Karabey et al. (US 20230224324 A1), hereinafter Karabey, teaches the aforementioned limitation, as described in paragraph [0043] Fig. 2, detail region 204 shown an area of user interface 200, showing additional details of a process. This can include a time which the process has started, corresponding to an origin of the at least one malicious object, and as described in paragraph [0040], additional details can be highlighted associated with other processes that connect with other processes. The motivation for combining the references of Murphy, Gamble, and Karabey is performed so that one of ordinary skill in the art would have been motivated to utilize an NLP model to reduce human effort, time to identify the tactics and techniques used by the cyber attacks, and reduces human error when describing the cyber attacks, and also maps the techniques and tactics to improve post-compromise detection of adversaries by describing steps the attacker takes to perform the attack itself (Karabey [0014]). As a result, Examiner now rejects claims 1, 4-12, and 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy, in view of Gamble, and Karabey.
Claim Rejections - 35 USC § 112(a)
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1, 4-12, and 15-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
In claim 1, there is no description provided as to how a method of ‘scanning, by a malware detector, the source object and the target object to determine whether any of the source object and the target object is a malicious object’ in the specification. Paragraph [0057] provides no description as to how determining if an object is malicious is determined apart from using malware detector 102 from Fig. 1 in the process of Fig. The limitation of “determining whether any of source object […] is a malicious target” is also a mere repetition of the Specification, as a person of ordinary skill in the art would not understand how to make or use the invention with regards to the determination of source or target objects being malicious, as it is unclear how a user interface generator 106 determines an object being malicious in step 406 in Fig. 4, and how the invention determines whether “word.exe” or “powershell.exe” is malicious based on actions performed in the example provided in paragraph [0057].
In claims 4-11, the dependent claims that depend on an independent claim inherits the deficiency of their respective independent claim, and therefore, claims 4-11 inherit the deficiencies of claim 1 as recited above.
In claim 12, limitations of this claim are similar to claim 1, and therefore, the deficiencies of claim 1 are shared with claim 12.
In claims 15-19, the dependent claims that depend on an independent claim inherits the deficiency of their respective independent claim, and therefore, claims 15-19 inherit the deficiencies of claim 12 as recited above.
In claim 20, limitations of this claim are similar to claim 1, and therefore, the deficiencies of claim 1 are shared with claim 20.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 4-12, and 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy et al. (US 20210294896 A1), hereinafter Murphy, in view of Gamble et al. (US 11212299 B2), hereinafter Gamble, and Karabey et al. (US 20230224324 A1), hereinafter Karabey.
Regarding claim 1, Murphy discloses ‘a method for generating a user interface for endpoint detection and response (EDR) systems, the method comprising: detecting a plurality of actions performed on a computing device’ ([0020] Fig. 1, method 100 is an instance of endpoint detection and response attack tree analysis. [0023] Fig. 1, when analysis is complete for alerts, process moves to block 120 to display a full flow of an attack, as seen in Figs. 2-5.);
‘for each respective action of the plurality of actions: identifying a source object performing the respective action and a target object on which the respective action is performed’ ([0049] Fig. 4, each line in a process tree represents an action in tree region 402, and each dot represents an object, wherein dots that are left of a line correspond to a source object of the applicant, and dots right of a line correspond to a target object.);
‘scanning, by a malware detector, the source object and the target object to determine whether any of the source object and the target object is a malicious object’ ([0036] Fig. 1, block 114, processes and events are identified on analyst device that determines if an alert raises information about malicious objects. Analyst device corresponds to malware detector, it uses information gathered to determine malicious objects while creating an attack flow. [0051] Fig. 4 shows a malware attack at play, which corresponds to a source object being a malicious object. Furthermore, a malicious child object is shown as 'downloader.exe' in the attack tree.);
‘in response to detecting at least one malicious object, generating, for display on a graphical user interface, an attack chain comprising a plurality of branches associated with the at least one malicious object,’ ([0040] Fig. 1, an attack tree is shown when all alerts have been processed for displaying a full flow of an attack tree. [0049] Fig. 4, an attack tree is displayed, wherein an attack tree corresponds to an attack chain of the applicant. Furthermore, a plurality of processes is shown as lines connecting dots, wherein lines, representing connections of processes, correspond to 'third visual identifier of a respective action' connecting two objects together. Processes correspond to objects of an applicant, wherein dots that are left of a line correspond to 'first visual identifier of a source objects', and dots which are right of a line correspond to 'second visual identifier of a target objects', respectfully.);
“generating, for display on the graphical user interface, an attack summary by: matching actions in the attack chain to a plurality of summary templates” ([Col. 11, lines 47-58] Fig. 6 of Gamble, where events are linked, as either independent or dependent elements of a small 'chain', where this is detailed to a user, where events corresponds to multiple summary templates of the Applicant. [0050] Fig. 4 of Murphy, stating that a user clicks on a process on a branch that contains both a parent and child process, and details are given for the processes, which corresponds to determining a summary template from multiple summary templates, and involve describing attack events of the Applicant.);
Murphy and Gamble do not appear to teach or suggest, but Karabey teaches the limitation of ”stitching the plurality of summary templates together using a natural language processing machine learning model to generate the attack summary” ([0043] Fig. 2, detail region 204 shown an area of user interface 200, showing additional details of a process. This can include a time which the process has started, corresponding to an origin of the at least one malicious object, and as described in paragraph [0040], additional details can be highlighted associated with other processes that connect with other processes, with detail region 204 being an example as to what types of details can be shown. Paragraph [0040] stating that other related processes can be displayed corresponds to target objects also being shown that are affected by the at least one malicious object.).
Therefore, one of ordinary skill in the art would have been capable of applying this known method of "stitching the plurality of summary templates together using a natural language processing machine learning model to generate the attack summary" in a method for generating an innovative user interface for endpoint detection and response (EDR) systems for and the results would have been predictable to one of ordinary skill in the art. The one of ordinary skill in the art would have been motivated to utilize an NLP model to reduce human effort, time to identify the tactics and techniques used by the cyber attacks, and reduces human error when describing the cyber attacks, and also maps the techniques and tactics to improve post-compromise detection of adversaries by describing steps the attacker takes to perform the attack itself (Karabey [0014]).
Regarding claim 4, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy also discloses ‘wherein the attack summary comprises visual identifiers of the at least one malicious object and the target objects affected by the at least one malicious object’ ([0049] Fig. 4, each line in a process tree represents an action in tree region 402, and a user can click on a process, where in tree region 402, target objects are shown that are affected by the malicious 'parent'/'source' object selected.);
Regarding claim 5, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy does not appear to disclose, but Gamble teaches ‘determining a severity level associated with the at least one malicious object based on an amount of target objects affected by the at least one malicious object’ (In [Cols. 13, lines 4-6] of Gamble, security platform 100 can determine if a score of an attack chain is based on if event is a false positive, and the severity of the event. Combined with paragraph [0040] of Murphy, additional details can be highlighted associated with other processes that connect with other processes, with detail region 204 being an example as to what types of details can be shown, wherein events seen in Gamble, Fig. 4, can work in conjunction with the amount of processes linked with other processes in Murphy.);
‘and generating the severity level for display on the graphical user interface’ (In [Cols. 13, lines 4-6] of Gamble, security platform 100 can determine a severity of the event. Combined with paragraph [0040] of Murphy, where additional details can be displayed, both passages teach the limitations of claim 5 of the applicant.).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Murphy and Gamble before them, to include Gamble’s ‘determining a severity level associated with the at least one malicious object based on an amount of target objects affected by the at least one malicious object’, and ‘generating the severity level for display on the graphical user interface’ in Murphy’s method performing ‘generating an innovative user interface for endpoint detection and response (EDR) systems, the method comprising: detecting a plurality of actions performed on a computing device’. One would have been motivated to make such a combination to enhance security as a severity level can indicate how dangerous an event is such that a user can take action to mitigate an event from occurring, as stated in [Col. 13, lines 4-6].
Regarding claim 6, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy does not appear to disclose, but Gamble teaches ‘wherein the severity level is a function of a determined value of importance of each target object, the importance being an importance score selected from predefined tiers indicative of system-criticality assigned to each target object, and a type of action applied on each target object by the at least one malicious object’ (After [Cols. 15-16, line 33] onwards, a table spanning multiple pages is shown. In [Cols. 17-18] "page_rank" is used as a determined value of importance of a connection in graph theory. In [Cols. 13, lines 4-6], security platform 100 can determine if a score of an attack chain is based on if event is a false positive, and the severity of the event. [Col. 12, lines 67-Col. 13, line 3] Each event can be assigned a score by how severe a threat is. Events can also be weighted to indicate how likely an event is not a false positive. Fig. 4 shows properties (408, 410, 412) of events, such as severity level and probability, with Fig. 6 describing that an overall security score can be used, as stated in [Col. 12, lines 40-43].).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Murphy and Gamble before them, to include Gamble’s ‘wherein the severity level is a function of a determined value of importance of each target object and a type of action applied on each target object by the at least one malicious object’ in Murphy’s method performing ‘generating an innovative user interface for endpoint detection and response (EDR) systems, the method comprising: detecting a plurality of actions performed on a computing device’. One would have been motivated to make such a combination to enhance security by assigning a ranking or score as to how severe an event is so that a response can be taken before attackers can exploit the issue, as stated in Gamble [Col. 12, line 67]-[Col. 13, line 3].
Regarding claim 7, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy also discloses ‘receiving a selection of a visual identifier associated with the at least one malicious object’ ([0049] A plurality of processes are shown as dots in a tree region 402, wherein the processes are considered malicious. [0051] Fig. 4 shows a malware attack at play, which corresponds to a source object being a malicious object. Furthermore, a malicious child object is shown as 'downloader.exe' in the attack tree.);
‘in response to receiving the selection, generating, for display on the graphical user interface, a window that includes additional information about the at least one malicious object’ ([0049] Fig. 4, when a process is clicked in tree region 402, detail region 404 is shown that shows more details about the process, which is considered a malicious object.).
Regarding claim 8, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy also discloses ‘wherein the additional information includes a reason of detection, a tactic used for malicious activity, a detection date, and a malware detection signature identifier used by malware detector to detect the at least one malicious object’ ([0023] Dates and times are associated with a file or process, including an access time, corresponding to a detection date of the applicant. A command line shown in a detail region 204 corresponds to a tactic used for malicious activity as that is what a process utilizes to execute on a system. Furthermore, a hash or identifier such as an MD5 corresponds to a security definition used to detect the at least one malicious object of the applicant. In paragraph [0022], a file alert can indicate that a file contains malware, a link to malware, or otherwise is associated with malware, and can be included in details in paragraph [0023], corresponding to a reason of detection when found. [0023] Identifiers include MD5 hash, signatures, process IDs, etc. [0028] Alert for device for impersonation example can contain MD5 signature for a process is performed by the analyst device. Analyst device determines alerts via an anti-virus or other detection software, as stated in [0026].).
Murphy does not appear to fully disclose, but Gamble also teaches the limitation of ‘a verdict on maliciousness’ ([Col. 12, line 67]-[Col. 13, line 3] Fig. 4, probability score is a statement of what the possibility is that an event is not a false positive, indicating that an event is considered malicious, corresponding to a verdict on maliciousness of the applicant.).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Murphy and Gamble before them, to include Gamble’s ‘a verdict on maliciousness’ in Murphy’s method performing ‘generating an innovative user interface for endpoint detection and response (EDR) systems, the method comprising: detecting a plurality of actions performed on a computing device’. One would have been motivated to make such a combination to enhance security as descriptive data comprises a risk rating, or a probability indicating likelihood that a security event is a false positive is included to indicate what the probability is of a potential issue occurring, as stated in Gamble [Col. 6, lines 19-25].
Regarding claim 9, Murphy in view of Gamble and Karabey teach the limitations of claims 1 and 7 as recited above. Murphy also discloses ‘in response to receiving the selection, modifying visual identifiers not directly associated as source objects or target objects with the at least one malicious object such that the attack chain solely depicts visual identifiers of the at least one malicious object’ ([0042] Fig. 2, where a process tree and selected detail of a process, that can be used in conjunction with displaying a full flow that is shown in Fig. 4, described in paragraph [0051], and Fig. 4 shows a malware attack at play, which corresponds to a source object being a malicious object. [0042] When used in conjunction with Fig. 4's full flow display, Fig. 2 shows a few process that are directly related to a selected process, wherein a process to the left is a 'source object' of the applicant, and a process to the right is a 'target object' of the applicant.).
Regarding claim 10, Murphy in view of Gamble and Karabey teach the limitations of claim 1 as recited above. Murphy also discloses ‘generating, for display on the graphical user interface, a timeline associated with the attack chain, wherein each time indicator of the timeline corresponds to a respective branch of the attack chain’ ([0050] Fig. 4, timeline 408 is populated with dots that represent events, with related events to processes linked together, and placed on approximately different times in the timeline.).
Regarding claim 11, Murphy in view of Gamble and Karabey teach the limitations of claims 1 and 10 as recited above. Murphy also discloses ‘receiving a selection of a first time indicator on the timeline’ ([0051] Key events and processes are highlighted along the way, which fulfills the requirement of marking at least one malicious object of the applicant.);
‘generating, for display on the graphical user interface, a highlighting visual on a first branch corresponding to the first time indicator’ ([0050] Selected events on the timeline 408 can be displayed on event region 410, corresponding to highlighting visually in accordance with the applicant.);
‘and generating, for display on the graphical user interface, a time window depicting a timestamp of when a first action of the first branch was performed’ ([0050] As events are displayed in event region 410 during a timeframe, a first action of a first branch is performed and is in the event region 410.).
Regarding claim 12, Murphy in view of Gamble and Karabey teach limitations similar to independent claim 1, and therefore, the rejections of claim 1 are shared with claim 12. Murphy also discloses ‘a system for generating a user interface for endpoint detection and response (EDR) systems, comprising: at least one memory;’ ([0020] Fig. 1, method 100 is an instance of endpoint detection and response attack tree analysis. [0023] Fig. 1, when analysis is complete for alerts, process moves to block 120 to display a full flow of an attack, shown in Figs. 2-5. [0056]-[0057] Fig. 6, Memory 630. [0056] Fig. 6 shows a system of an invention of Murphy.);
‘and at least one hardware processor coupled with the at least one memory and configured, individually or in combination, to: detect a plurality of actions performed on a computing device’ ([0056]-[0057] Fig. 6, CPU 605 is coupled to a memory 630 via an interconnect/bus 620. [0023] Fig. 1, when analysis is complete for alerts, process moves to block 120 to display a full flow of an attack, shown in Figs. 2-5.);
Regarding claim 15, Murphy in view of Gamble and Karabey teach the limitations of claim 12 as recited above. Murphy and Gamble teach limitations similar to dependent claim 4 above, and shares the rejections of claim 4 stated above.
Regarding claim 16, Murphy in view of Gamble and Karabey teach the limitations of claim 12 as recited above. Murphy and Gamble teach limitations similar to dependent claim 5 above, and shares the rejections of claim 5 stated above.
Regarding claim 17, Murphy in view of Gamble and Karabey teach the limitations of claim 12 as recited above. Murphy and Gamble teach limitations similar to dependent claim 6 above, and shares the rejections of claim 6 stated above.
Regarding claim 18, Murphy in view of Gamble and Karabey teach the limitations of claim 12 as recited above. Murphy and Gamble teach limitations similar to dependent claim 7 above, and shares the rejections of claim 7 stated above.
Regarding claim 19, Murphy in view of Gamble and Karabey teach the limitations of claim 12 as recited above. Murphy and Gamble teach limitations similar to dependent claim 8 above, and shares the rejections of claim 8 stated above.
Regarding claim 20, Murphy in view of Gamble and Karabey teach limitations similar to independent claim 1, and therefore, the rejections of claim 1 are shared with claim 12. Murphy discloses ‘a non-transitory computer readable medium storing thereon computer executable instructions for generating a user interface for endpoint detection and response (EDR) systems, including instructions for: detecting a plurality of actions performed on a computing device’ ([0092] Computer readable storage medium/media containing program instructions for a processor to carry out the invention. [0093] describes varying types of media, including RAM, ROM, a hard disk, a compact disc, and other media formats used for storing instructions to a physical medium. [0020] Fig. 1, method 100 is an instance of endpoint detection and response attack tree analysis. [0023] Fig. 1, when analysis is complete for alerts, process moves to block 120 to display a full flow of an attack, shown in Figs. 2-5.);
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TOMMY MARTINEZ whose telephone number is (703)756-5651. The examiner can normally be reached Monday thru Friday 8AM-4PM ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571) 272-7624 on Monday thru Friday 7AM-7PM ET. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.M./ Examiner, Art Unit 2496
/JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496