Prosecution Insights
Last updated: October 04, 2026
Application No. 18/593,470

TECHNIQUES FOR CODE FINGERPRINTING

Final Rejection §101
Filed
Mar 01, 2024
Examiner
WHEATON, BRADFORD F
Art Unit
2193
Tech Center
2100 — Computer Architecture & Software
Assignee
Dazz Inc.
OA Round
2 (Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
1y 3m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
243 granted / 395 resolved
+6.5% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 10m
Avg Prosecution
24 currently pending
Career history
425
Total Applications
across all art units

Statute-Specific Performance

§101
18.4%
-21.6% vs TC avg
§103
68.3%
+28.3% vs TC avg
§102
2.1%
-37.9% vs TC avg
§112
8.9%
-31.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 395 resolved cases

Office Action

§101
DETAILED ACTION Claims 1, 3-4, 6-8, 10-11, 13-14, 16-18 and 20-26 are pending in the current application. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments, see Remarks, filed 6/3/26, with respect to the 103 rejection of the claims have been fully considered and are persuasive. The 103 rejection of the claims have been withdrawn. Applicant's arguments filed 6/3/26 have been fully considered but they are not persuasive. Applicant argues that (Argument 1; Remarks pg. 1 lines 18-20) that the claims do not recite an abstract idea and (Argument 2; Remarks pg. 2 lines 5-22) the claims improve a particular technology and therefor integrate the abstract idea into a practical application. With respect to applicant’s arguments examiner respectfully disagrees. As to argument 1, first it is noted that not every element of a claim has to recite an abstract idea for the claim as a whole to be considered as being directed to an abstract idea as long as the remaining additional elements are not significantly more than the abstract idea or limitation that do not integrate the abstract idea into a practical application. Also, the use of a generic computer/machine to perform an abstract idea mental process does not indicate that the limitations are not an abstract idea mental process on its own. The limitations directed to the generating fingerprinting code and performing a text search on the at least one code repository and identifying a pattern in the at least one code repository as claimed are viewed as some of the abstract idea mental process elements that can be done by a person by observation, analysis, evaluation, judgement and/or with the aid of pen and paper as a person can write/generate fingerprinting code to perform text search and identify pattern based on provided information and at the level recited a person can mentally analyze and search for text in provided code repository and mentally identify/determine a pattern in the code repository with respect to provided knowledge base information where the generic computer/machine operations recited to generate and perform the analysis are viewed as additional elements that do not integrate the abstract idea into a practical application and do not recite significantly more than the abstract idea with a full explanation seen below in the 101 rejection. It is also noted here that the language of “scan the at least one code repository” has been removed by the amendments to the claim language and while the claim does include “generating scanning results based on the executed fingerprint code” this is viewed as results of the text search and identifying a pattern limitations of the fingerprinting code for claim interpretation and analysis. As to argument 2, while a technical improvement to a technical problem can be used to show the integration of an abstract idea into a practical application to show a technical improvement to a technical problem the specification must provide sufficient details such that one of ordinary skill in the art would recognize the claimed inventions as pertaining to the technical improvement and the claims must reflect the technical improvement where the claims cover a particular solution/improvement as opposed to merely claiming the idea of the improvement or outcome. It is unclear where the argued technical improvement for how code repositories are scanned and fingerprinted for cybersecurity is seen in the specification and reflected in the claim language. It is noted the claim argued improvement directed to how code repositories are scanned appear to be related to the text search and identify patten limitation that are viewed as abstract idea mental process as claimed and thus not elements that can show that the additional elements are directed to a technical solution/improvement as they are abstract idea elements mental process elements. The scanning performed is viewed as traditional scanning just based on specifically determined/identified patterns/software components from the knowledge base where the fingerprinting code as claimed is executed without any particular application of the recited “executing” the code and thus viewed as an “apply it” type limitation and while the code will perform the functions viewed as being associated with scanning (i.e. the text search limitation and identifying pattern limitation) that as seen argued above and in full detail in the rejection below are viewed as abstract idea mental process elements that the generically executed code will perform and thus not viewed as a technical improvement and thus viewed that the claims are not integrated into a practical application and are still directed to an abstract idea mental process. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 3-4, 6-8, 10-11, 13-14, 16-18 and 20-26 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Examiner has evaluated the claims under the framework provided in the 2019 Patent Eligibility Guidance published in the Federal Register 01/07/2019 and has provided such analysis below. Step 1: Claims 1, 3-4, 6-8, 10-11, 13-14, 16-18 and 20-26 are claims that are directed to a process, machine, manufacture or composition of matter. In order to evaluate the Step 2A inquiry “Is the claim directed to a law of nature, a natural phenomenon or an abstract idea?” we must determine, at Step 2A Prong 1, whether the claim recites a law of nature, a natural phenomenon or an abstract idea and further whether the claim recites additional elements that integrate the judicial exception into a practical application. Step 2A Prong 1: Claims 1, 10 and 11: The limitation of “querying a knowledge base based on the cybersecurity alert,” “identifying, based on the query, a software component related to the cybersecurity alert,” “generating fingerprinting code based on the query and the identified software component,” “performing a text search on the at least one code repository,” “identifying a pattern in the at least one code repository defined with respect to the knowledge base,” “generating scanning results based on the executed fingerprinting code,” “generating statistical data based on the scanning results,” “generating a statistics vector based on the statistical data,” “determining an anomalous repository configuration for the at least one code repository based on the generated statistics vector” and “modifying a security configuration of the identified software component based on the determined anomalous repository configuration” as drafted, are functions thus under its broadest reasonable interpretation recite the abstract idea of a mental process. The limitations encompasses a human mind carrying out the function of determining/identifying information from a knowledge base related to received alert and generate code based on analysis of knowledge base of information to perform a functionality when executed to text search and identify patten in code repository with respect to the knowledge base and determine/generate statistical data from that analysis that is converted into a statistics vector format and from that being able to determine anomalous repository issues and modifying the security configuration of the identified software component code through observation, evaluation, judgment and/or opinion or even with the aid of pen and paper. Thus, this limitation recites and falls within the “Mental Process” grouping of abstract ideas under Prong 1. The claims have been identified to recite an abstract idea, Step 2A Prong 2 will evaluate whether the claims are directed to the judicial exception. Step 2A Prong 2: Claims 1, 10 and 11: The abstract idea is not integrated into a practical application. In particular the claims recite the following additional element “a knowledge base…,wherein the knowledge base includes a plurality of nodes representing respective software components of a plurality of software components,” “at least one code repository,” “A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising” and “A system for code fingerprinting, comprising: a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to” are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using generic computer, and/or mere computer components. Additionally, the claim recite the additional element of “receiving a cybersecurity alert” which do nothing more than add insignificant extra solution activity to the judicial exception of merely receiving or transmitting data which does not integrate the abstract idea into a practical application. Further, the claims recite the additional elements of “executing the fingerprinting code on at least one code repository, wherein the execution comprises” fails to meaningfully limit the claim because it does not require any particular application of the recited “executing” and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Accordingly, the additional elements do not integrate the recited judicial exception into a practical application and the claim is therefore directed to the judicial exception. See MPEP 2106.05(g). After having evaluating the inquires set forth in Steps 2A Prong 1 and 2, it has been concluded that claims, 1, 10 and 11 not only recite an abstract idea but that the claims are directed to the abstract idea as the abstract idea has not been integrated into practical application. Step 2B: Claims 1, 10 and 11: The claims do not include additional elements, alone or in combination, that are sufficient to amount to significantly more than the abstract idea. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of “a knowledge base…,wherein the knowledge base includes a plurality of nodes representing respective software components of a plurality of software components,” “at least one code repository,” “A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising” and “A system for code fingerprinting, comprising: a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to” amount to no more than mere instructions, or generic computer/computer components to carry out the exception. Additionally, the additional element of “receiving a cybersecurity alert” is merely insignificant extra-solution activity information of receiving or transmitting data which does not integrate the abstract idea into a practical application. Further, the insignificant extra-solution activity is also WURC, see MPEP 2106.05(d)(II), where “the courts have recognized the following computer functions as well-understood, routine and conventional functions when they are claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activity” i. receiving or transmitting data over a network where the receiving a cybersecurity alert limitation is akin to receiving the data. Further, the additional element of converting “executing the fingerprinting code on at least one code repository, wherein the execution comprises” does not require any particular application of the recited executing of code and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Mere instructions to apply an exception cannot provide an inventive concept. The recitation of generic computer instruction and computer components to apply the judicial exception, mere receiving data information and mere instructions to apply an exception, do not amount to significantly more, thus, cannot provide an inventive concept. Accordingly, the claims are not patent eligible under 35 USC 101. Having concluded analysis within the provided framework, claims 1, 10 and 11 do not recite patent eligible subject matter under 35 USC 101 As to claims 3 and 13 the limitation of “generating a plurality of statistics vectors based on the statistical data, wherein each statistics vector includes a plurality of values representing statistics for respective aspects of the plurality of software components represented in the knowledge base, the plurality of statistics vectors further includes the statistics vector” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application. Moreover, claim 3 and 13 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claim 3 and 13 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 3 and 13 does not recite patent eligible subject matter under 35 USC 101. As to claims 4 and 14 the limitation of “wherein the plurality of statistics vectors include a plurality of counts vectors, wherein each of the plurality of values of each counts vector is a count of instances for a respective aspect of the plurality of software components represented in the knowledge base” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application. Moreover, claim 4 and 14 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claim 4 and 14 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 4 and 14 does not recite patent eligible subject matter under 35 USC 101. As to claims 6 and 16 they recite the limitation of “extracting at least one text segment from the textual content” is an additional mental process element under prong 1. The claims further recite additional elements of “obtaining textual content based on the query, wherein the textual content includes a semantic concept related to the node among the plurality of nodes associated with the identified software component” which is merely insignificant extra solution activity information akin to receiving or transmitting data which does not integrate the abstract idea into a practical application. Further, the insignificant extra-solution activity is also WURC, see MPEP 2106.05(d)(II), where “the courts have recognized the following computer functions as well-understood, routine and conventional functions when they are claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activity” i. receiving or transmitting data over a network where the obtaining textual content limitation is akin to receiving the data. Furthermore, the claims recite additional elements of “wherein the generated fingerprinting code is further based on the at least one text segment, the identified patterns are patterns defined with respect to the at least one text segment” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application. Moreover, claims 6 and 16 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claims 6 and 16 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 6 and 16 does not recite patent eligible subject matter under 35 USC 101. With regard to claims 7 and 17 they recite the limitation of “detecting at least one anomaly based on outputs the machine learning model when the machine learning model is applied to the features extracted from the statistical data” is an additional mental process element under prong 1. Further the claims recites additional elements of “applying a machine learning model to features extracted from the statistical data, wherein the machine learning model is trained using training statistical data for the knowledge base, wherein the machine learning model is trained to output anomalies when applied to the features extracted from the statistical data” which merely describe in generic terms the applying of a trained machine learning model to output data anomalies by providing input into a trained machine learning model because it does not require any particular application of the recited “applying a machine learning model” and “training” of the machine learning model and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Furthermore, the claims recite additional elements of “wherein the anomalous repository configuration for the at least one code repository is further based on the detected at least one anomaly” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application Moreover, claims 7 and 17 do not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claim 7 and 17 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 7 and 17 does not recite patent eligible subject matter under 35 USC 101. As to claims 8 and 18 the limitation of “further comprising: training the machine learning model based on a historical state of the knowledge base” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application. Moreover, claim 8 and 18 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claim 8 and 18 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 8 and 18 does not recite patent eligible subject matter under 35 USC 101. As to claims 20 and 24 they recite the limitation of “identifying, based on the scanning results, one or more instances of the at least one text segment in the at least one code repository; and incrementing, for each identified instance of the at least one text segment, a count corresponding to the at least one text segment, wherein the generated statistics vector is further based on the incremented count” is an additional mental process element under prong 1. Moreover, claims 20 and 24 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claims 20 and 24 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 20 and 24 does not recite patent eligible subject matter under 35 USC 101. As to claims 21 and 25 they recite the limitation of “analyzing textual data of the cybersecurity alert using a semantic concepts dictionary of the knowledge base; identifying, based on the analyzed textual data, an entity-identifying value; identifying, based on the analyzed textual data, a semantic concept; identifying a first node among the plurality of nodes based on the entity-identifying value; identifying one or more candidate nodes based on the semantic concept; generating, for each node among the one or more candidate nodes, one or more paths originating from the first node; and selecting a second node among the one or more candidate nodes based on the generated one or more paths, wherein identifying the software component is further based on the selected second node” is an additional mental process element under prong 1. Moreover, claims 21 and 25 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claims 21 and 25 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 21 and 25 does not recite patent eligible subject matter under 35 USC 101. With regard to claims 22 and 26 they additional elements of “executing a set of one or more queries” which merely describe in generic terms the executing queries it does not require any particular application of the recited “executing” and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Furthermore, the claims recite additional elements of “wherein each query among the set of one or more queries is defined with respect to a file of attribute among one or more attributes of files, each node among the plurality of nodes includes one or more attributes of files, the query includes the executed set of one or more queries” which is merely a field of use/technological environment which does not integrate the judicial exception into a practical application Moreover, claims 22 and 26 do not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claims 22 and 26 also fail both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claims 22 and 26 do not recite patent eligible subject matter under 35 USC 101. As to claim 23 it recites the limitation of “wherein modifying the security configuration of the identified software component comprises modifying a configuration parameter that controls a capability of the identified software component” is an additional mental process element under prong 1. Moreover, claim 23 does not recite any other additional elements and for the same reasons as above with regard to the integration into a practical application and whether the additional elements amount to significantly more, claim 23 also fails both Step 2A prong 2, thus the claims are directed to the abstract idea as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 23 does not recite patent eligible subject matter under 35 USC 101. Allowable Subject Matter Claims 1, 3-4, 6-8, 10-11, 13-14, 16-18 and 20-26 are viewed as allowable over prior art and will be allowed once the remaining 101 rejection of the claims have been addressed. The following is an examiner’s statement of reasons for allowance: The claims are viewed as reciting allowable subject matter over prior art as the specific way of determine anomalous repository configuration for use in modifying security configuration of software component associated with the identified anomalous repository configuration where it is determined based on generating fingerprinted code for at least one repository that will perform text search on the at least one repository and identify a pattern in the repository with respect to knowledge base and using those results to generate statistical data that can be represented in statistical vectors to identify anomalous repository configuration from where the fingerprinting code is generated based on a received cybersecurity alert and searching knowledge based for a software component related to the cybersecurity alert for the specifics of the generated fingerprinting code. While prior art such as Hines shows the basics of generating code based on information from a knowledge base to perform associated functionality, and prior art of Carback discloses the basics of code performing software analysis on code that can include text search and pattern matching, and prior art of Kirat shows the specifics of code performing fingerprinting based on knowledge base of information and prior art of Aishawabkeh discloses being able to analyze results to generate statistical data that can further be represented in statistical vectors the specifics of determine anomalous repository configuration for use in modifying security configuration of software component associated with the identified anomalous repository configuration where it is determined based on generating fingerprinted code for at least one repository that will perform text search on the at least one repository and identify a pattern in the repository with respect to knowledge base and using those results to generate statistical data that can be represented in statistical vectors to identify anomalous repository configuration from where the fingerprinting code is generated based on a received cybersecurity alert and searching knowledge based for a software component related to the cybersecurity alert for the specifics of the generated fingerprinting code is not seen reflected in the prior art and thus viewed as allowable subject matter over prior art. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRADFORD F WHEATON whose telephone number is (571)270-1779. The examiner can normally be reached Monday-Friday 8:00-5:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Chat Do can be reached at 571-272-3721. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRADFORD F WHEATON/Examiner, Art Unit 2193
Read full office action

Prosecution Timeline

Mar 01, 2024
Application Filed
Mar 05, 2026
Non-Final Rejection mailed — §101
Jun 03, 2026
Response Filed
Sep 03, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737177
ISOLATED ENVIRONMENT PROVISIONING IN SERVICE MESH-BASED MICROSERVICES SYSTEMS
3y 8m to grant Granted Sep 15, 2026
Patent 12737276
MULTI-LAYER INTERACTION AND CODE EXAMINER FOR N-TIER ARCHITECTURE APPLICATIONS
3y 1m to grant Granted Sep 15, 2026
Patent 12717700
APPLICATION DEBUGING METHOD AND ELECTRONIC DEVICE
3y 3m to grant Granted Aug 25, 2026
Patent 12705160
MANAGING COMPUTING RESOURCE CONSUMPTION OF SOFTWARE APPLICATIONS USING CONTROL GROUPS TO FACILITATE SAFETY COMPLIANCE
2y 8m to grant Granted Aug 11, 2026
Patent 12699769
DYNAMIC RUNTIME MICRO-SEGMENTATION OF INTERPRETED LANGUAGES
3y 2m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
73%
With Interview (+11.2%)
3y 10m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 395 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month