Prosecution Insights
Last updated: August 16, 2026
Application No. 18/582,583

INTROSPECTION DRIVEN BY INCIDENTS FOR CONTROLLING INFILTRATION

Final Rejection §102
Filed
Feb 20, 2024
Priority
Jan 24, 2019 — divisional of 11/416,641 +1 more
Examiner
LESNIEWSKI, VICTOR D
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
NetSkope Inc.
OA Round
2 (Final)
59%
Grant Probability
Moderate
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
286 granted / 488 resolved
+0.6% vs TC avg
Strong +55% interview lift
Without
With
+55.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
20 currently pending
Career history
511
Total Applications
across all art units

Statute-Specific Performance

§101
8.9%
-31.1% vs TC avg
§103
57.9%
+17.9% vs TC avg
§102
17.0%
-23.0% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 488 resolved cases

Office Action

§102
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The amendment filed 5/12/2026 has been placed of record in the file. No claims have been amended. The double patenting rejection remains of record. Claims 1, 2, and 5-14 are pending. The applicant’s arguments with respect to claims 1, 2, and 5-14 have been fully considered but they are not persuasive as discussed above. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 2, and 5-14 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Barday et al. (U.S. Patent Application Publication Number 2018/0341784), hereinafter referred to as Barday. Regarding claim 1, Barday discloses a tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Regarding claim 2, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data). Regarding claim 5, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method, wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 6, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII). Regarding claim 7, Barday discloses a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Regarding claim 8, Barday discloses program instructions that, when executed on processors, cause the processors to implement the method including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data). Regarding claim 9, Barday discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; further including removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 10, Barday discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII). Regarding claim 11, Barday discloses a system for responding to requests to be forgotten (paragraph 163, right to be forgotten), the system including a processor, memory coupled to the processor, and computer instructions loaded into memory that, when executed on processors, cause the processors to implement a method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc.); the CASB performing deep inspection of the consumer data stored at the identified locations and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Regarding claim 12, Barday discloses in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (paragraph 169, display personal data). Regarding claim 13, Barday discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier; further including removing records referenced by the identifier of the particular consumer (paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 14, Barday discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (paragraph 2, personal data includes PII). Response to Arguments In the remarks, the applicant has argued that Barday does not disclose a “CASB” as recited in independent claim 1. In response, it is maintained that Barday teaches the features as claimed. Barday explicitly states the servers being managed as cloud-based servers. See, again, Barday, paragraph 186. The applicant’s argument that “Barday does not use the acronym CASB” is not persuasive as the term is defined by the limitations of the claim. Here, Barday teaches the functionality as claimed (“controlling exfiltration,” “identifying one or more locations,” etc.) and, as such, is seen to meet the terms used in the claim that provide said functionality. To the applicant’s statement about “use cases,” it is unclear how this relates to the limitations of the claim. To the applicant’s statement about Barday’s “inventors,” it is unclear how this relates to the limitations of the claim. To the applicant’s statement that Barday only uses the word cloud “to explain that a centralized repository can be hosted on a cloud-based server,” it is noted that this is incorrect and misleading. At the cited paragraph 186, Barday clearly states that all components of the system, including management servers, system servers, and the databases may be cloud-based servers. The applicant’s argument that “the Office relies on features from alternative embodiments to formulate the rejection” is also unpersuasive. Barday explicitly states that the described “alternative embodiments” simply provide for additional features to the embodiments already described. Adding features to a disclosed embodiment is not exclusionary of the previous disclosure. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Victor Lesniewski/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Feb 20, 2024
Application Filed
Jan 16, 2026
Non-Final Rejection mailed — §102
May 12, 2026
Response Filed
Jul 17, 2026
Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706916
IDENTIFYING AND AUTHENTICATING USERS IN A CONFERENCE ROOM
2y 10m to grant Granted Aug 11, 2026
Patent 12688278
DISCOVERY OF RANSOMWARE PROCESSES USING LAST-INTERACTED METADATA TAGGING
3y 3m to grant Granted Jul 21, 2026
Patent 12683976
SYSTEM AND METHOD FOR CONTINUOUS MONITORING AND REVOCATION OF DEVICE ACCESS AUTHORIZATION
2y 5m to grant Granted Jul 14, 2026
Patent 12671997
ELEVATED SECURITY EXECUTION MODE FOR NETWORK-ACCESSIBLE DEVICES
2y 5m to grant Granted Jun 30, 2026
Patent 12665764
VERIFICATION SYSTEM FOR OMNICHANNEL END-USER VERIFICATION
2y 4m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
59%
Grant Probability
99%
With Interview (+55.1%)
3y 3m (~10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 488 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month