Prosecution Insights
Last updated: August 18, 2026
Application No. 18/613,572

SYSTEMS AND METHODS FOR ANTI-FRAUD MESSAGE INSPECTION

Non-Final OA §103
Filed
Mar 22, 2024
Examiner
GYORFI, THOMAS A
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Open Text Inc.
OA Round
3 (Non-Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
528 granted / 699 resolved
+17.5% vs TC avg
Strong +16% interview lift
Without
With
+16.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
12 currently pending
Career history
715
Total Applications
across all art units

Statute-Specific Performance

§101
9.5%
-30.5% vs TC avg
§103
52.3%
+12.3% vs TC avg
§102
21.0%
-19.0% vs TC avg
§112
7.9%
-32.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 699 resolved cases

Office Action

§103
DETAILED ACTION Claims 1-20 remain for examination. The amendment filed 6/11/26 amended claims 1, 8, and 15. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 6/11/26 has been entered. Response to Arguments Applicant's arguments filed 6/11/26 have been fully considered but, except where otherwise noted, they are not persuasive. Regarding Amoudi, Applicant argues: The Examiner now cites paragraph [0012] of Amoudi and argues that a firewall (i.e., element 12 shown in FIG. 1 of Amoudi) "is a "filtering mechanism" under the broadest reasonable interpretation of the term in view of the instant specification." However, the cited paragraph [0012] of Amoudi, like the cited paragraph [0002] of Amoudi discussed in Applicant's Previous Argument 1, describes allowing "only" incoming email traffic from "the authorized node" to pass through to the on-premises email security gateway. This limitation is further emphasized by the cited paragraph [0038] of Amoudi, and highlighted by the Examiner, "any email traffic that is received from a source other than the CBES system 20 can be blocked by the firewall 12 and prevented from reaching the email security gateway 14" (emphasis in original). In this way, the "email security gateway 14" of Amoudi receives "only" email traffic from the CBES system 20 and that has passed the firewall 12. This limitation does not apply to the invention as described and claimed in the instant Application. Rather, the invention described and claimed in the instant Application solves a problem that does not exist in Amoudi (because the firewall 12 of Amoudi will block any email traffic that is not from the CBES system 20). As described in paragraph [0026] and shown in FIG. 2 of the instant Application, "some spam or fraudulent messages with valid sender addresses may not be filtered out by the firewall or gateway device 220 and/or the message ingress servers 250, allowing them to pass through existing message inspection mechanisms." Since this is not an issue in Amoudi, Amoudi does not provide a solution as described and claimed in the instant Application. Examiner disagrees. First, for the sake of clarity, Amoudi’s firewall (element 12 of Figure 1) is the “ingress server” of the claims. As paragraph 0012 states, the Internet-facing firewall “filters all email traffic to the computer network, wherein the firewall is configured to allow only incoming email traffic from the authorized node to pass through to the on-premises email security gateway”; i.e. it is at least capable of performing a rudimentary filtering operation on incoming email – specifically, filtering out any emails not received from the cloud-based email security system. Turning to the instant application, independent claims 1, 8, and 15 recite “receiving an email that has passed through a filtering mechanism at an ingress server of an enterprise computer network” (or equivalent language thereof as per claim 1). Note that these claims place no limitation whatsoever as to the nature of the filtering operation(s) implemented by the recited ingress server. Accordingly, the features upon which Applicant relies (i.e., the specific types of filtering as per paragraph 0026 of the instant specification) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Although not explicitly argued by the Applicant, Examiner acknowledges that the preceding argument has some merit when applied specifically to dependent claims 2, 9, & 16. Therefore, in the interest of expediting prosecution of the instant application, a new grounds of rejection for those three claims is presented herein in view of the newly discovered reference to Kaushik. Accordingly, this rejection will be Non-Final. Applicant additionally argues: On page 4 of the Office Action, the Examiner argued that "that Applicant has erroneously conflated the mail server (element 112 of Figure 1) with the on-premises email security [OPES] system (element 10 of Figure 1)." However, the on-premises email security [OPES] system as described and shown by Amoudi does not apply to the invention as described and claimed in the instant Application. For example, as described in paragraph [0004] of the instant Application, the claimed "message inspector" resides "between an application and an enterprise mail server" and, according to paragraph [0029] of the instant Application, this mail server "resides in an enterprise computer environment protected by a networking device such as a firewall or gateway device." Therefore, the mail server (element 112 of Figure 1) of Amoudi is more relevant to the invention as described, shown, and claimed in the instant Application than the on-premises email security [OPES] system (element 10 of Figure 1) of Amoudi, which sits outside of the firewall 18 that protects the mail server(s) 112 of Amoudi. Examiner disagrees. Independent claim 1 recites inter alia “a message inspector operating on a server machine behind an ingress server in an enterprise computer network” with no further qualifications. The on-premises email system disclosed by Amoudi is clearly one or more pieces of hardware within Amoudi’s enterprise computer network that is behind an ingress server (the Internet-facing firewall that receives emails from the CBES) and inspects emails received therefrom; ergo, it reads on the claim. Accordingly, the features upon which Applicant relies (i.e., the specific structure of the message inspector as per paragraphs 0004 & 0029 of the instant specification) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). It is additionally noted that the preceding argument is even less persuasive when applied to independent claims 8 & 15, which lack even the broad structure of claim 1 and are literally silent as to where and how the message inspector is implemented, beyond the fact that it is somehow implemented with a processor and memory. Applicant further argues: Rather, Amoudi explicitly describes and shows the email security gateway 14 as residing between firewalls 12 and 18 and also explicitly describes and shows mail servers 112 as residing behind the firewall 18. That is, Amoudi itself distinguish the email security gateway 14 from the mail servers 112 and, therefore, the email security gateway 14 of Amoudi does not disclose or suggest mail servers. Further, the ability of the email security gateway 14 of Amoudi to "work together with the sandbox security system 16 to scan, analyze, filter or remediate the received email traffic (including all attachments) to remove spam, spoofed emails, phishing emails, advanced persistent threat (APT) events, or other malicious emails, as well as viruses, worms, trojans and other harmful malware or hyperlinks that might exist in the incoming email traffic" does not solve the problem of "some spam or fraudulent messages with valid sender addresses may not be filtered out" by a firewall, gateway device, and/or ingress server, allowing them to pass through existing message inspection mechanisms because the mail servers 112 of Amoudi, which reside behind the firewall 18, do not have the ability to check on such messages on they pass through the email security gateway 14 and the firewall 18 - the mail servers 112 of Amoudi will only receive "cleared emails" and no further checks are necessary. Examiner disagrees. As noted supra, the instant claims are entirely silent regarding any aspect of the claimed invention to be implemented on a mail server. At best, the message inspector of claim 1 is implemented on a server (and specifically, one located behind an ingress server), but there is no requirement that said server must specifically be a mail server. Claims 8 and 15 are even less strict, requiring nothing but a generic computing device with a processor and memory to implement the claimed invention. Although the claims are interpreted in light of the specification, limitations from the specification (i.e. that the message inspector must be implemented on a mail server) are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Applicant’s remaining arguments regarding the secondary references are rebutted for substantially similar reasons as discussed supra, as there is no need for any of the secondary references to remedy the alleged deficiencies of the Amoudi reference in order to teach features that are not actually present in Applicant’s claims. Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claims 1, 3, 8, 10, 15, & 17 are rejected under 35 U.S.C. 103 as being unpatentable over Amoudi (U.S. Patent Publication 2021/0014198) in view of Cardinal (U.S. Patent Publication 2020/0021546). Regarding claims 1, 8, and 15: Amoudi discloses an anti-fraud message inspection method, system, and computer program product, comprising: receiving, by a message inspector operating on a server machine in an enterprise computer network, an email that has passed a filtering mechanism at ingress of the enterprise computer network (paragraph 0002: “According to a non-limiting embodiment of the disclosure, a method is provided for analyzing and filtering an email message destined to a computing resource in a computer network that has been security processed by a cloud-based email security system…”; paragraph 0012: “The network security system can further comprise an Internet facing firewall that filters all email traffic to the computer network, wherein the firewall is configured to allow only incoming email traffic from the authorized node to pass through to the on-premises email security gateway”; paragraph 0030, including: “The network security solution includes multilayer email analysis, filtering and security risk remediation, including an on-premises email security (OPES) system that can include a boarder security patrol (BSP) system located at the perimeter of the computer network. The OPES system can include an Internet email security gateway and a sandbox solution to analyze and filter email communications received from a cloud-based email security (CBES) system”; paragraph 0032: “The CBES system 20 can receive, analyze and filter email traffic from any external source that is destined to the computer network 1”, and paragraph 0038, including “Thus, any email traffic that is received from a source other than the CBES system 20 can be blocked by the firewall 12 and prevented from reaching the email security gateway 14. The firewall 12 can permit all outgoing email traffic destined to the CBES system 20 to pass through unimpeded”; i.e. the invention is for an on-premises email server that performs additional email scanning on emails received from a firewall that is by definition the ingress server to the enterprise network, wherein said firewall also performs its own filtering); performing, by the message inspector utilizing local database files, a plurality of checks on the email, the local database files stored in a database communicatively connected to the message inspector in the enterprise computer network (paragraphs 0040-0041: “The email security gateway 14 can analyze and filter the email traffic received from the firewall 12 to remove or remediate harmful or unwanted emails or email attachments…The email security gateway 14 can include a reputation filter, message filter, anti-spam engine, anti-virus engine, content filter, or outbreak filter. The email security gateway 14 can work together with the sandbox security system 16 to scan, analyze, filter or remediate the received email traffic (including all attachments) to remove spam, spoofed emails, phishing emails, advanced persistent threat (APT) events, or other malicious emails, as well as viruses, worms, trojans and other harmful malware or hyperlinks that might exist in the incoming email traffic…”; although each of the disclosed filters installed on the OPES can be construed as “local database files” and/or “databases” under the broadest reasonable interpretation of the term(s), see also paragraph 0089 regarding the use of database 150 as part of the scanning process; see also paragraph 0046: “In this non-limiting example, the computer network 1 comprises an enterprise network system that includes (in addition to the OPES system 10) a server farm 110, switching and distribution layers 120, one or more routers 130, one or more network switches 140, a database 150, and a plurality communicating devices 160, all of which can be interconnected by communication links and located behind one or more firewalls to protect against threats or breach attempts made against the computer network 1.” [emphasis Examiner’s]); and responsive to the email passing the plurality of checks, placing, by the message inspector, the email in an application processing queue in the enterprise computer network (paragraph 0042: “After the sandbox analysis has been completed, cleared emails can be forwarded to the backend mail server(s) 112 in the computer network 10. For additional security, the firewall 18 can be provided between the email security gateway(s) 14 and sandbox security system 16 and the backend mail server(s) 112, as noted earlier. The mail server(s) 112 can include, for example, SMTP servers”, further noting that SMTP servers have long since been known to inherently comprise application processing queues for delivering email – see the previously noted pertinent NPL prior art from the Non-Final Rejection of 7/29/25, page 8, paragraph #11). Although the Amoudi invention is capable of remediating any email that fails any of its scans and filters (e.g. paragraph 0041), Amoudi does not explicitly disclose responsive to the email failing any of the plurality of checks, placing, by the message inspector, the email in a suspect queue in the enterprise network. However, Cardinal discloses in a related invention for processing emails and other electronic messages wherein when it is determined that an incoming message is suspicious, it should be placed in a queue explicitly designated for that purpose (paragraphs 0052-0055, including “Next, as represented by block 302, the system automatically places the flagged data transmission in the queue for suspicious transmissions. This may be done by forwarding the data transmission to another recipient, such as a security branch of the enterprise…”). It would have been obvious prior to the effective filing date of the instant application for Amoudi to store any email that fails any of the local checks in a suspect queue – including but not limited to using said queue to transmit the suspect emails to the sandbox security system for remediation (Amoudi, paragraph 0040) – as doing so allows one to isolate the potentially dangerous emails in a separate memory to minimize or prevent security risk (Cardinal, paragraph 0055). Regarding claims 3, 10, and 17: The combination further discloses wherein the local database files comprise at least two of a Sender Policy Framework (SPF) rule, a blacklist, a whitelist, a destination file, a country code limit configuration file, a usage limit configuration file, or a job rate limit configuration file (blacklists and whitelists at Amoudi, paras. 0007, 0018, & 0073). Claims 2, 9, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Amoudi in view of Cardinal as applied to claims 1, 8, & 15 above, and further in view of Kaushik (U.S. Patent Publication 2021/0329459). Regarding claims 2, 9, and 16: The combination further discloses wherein the filtering mechanism comprises a fraud detection filter, a spam detection filter, or virus scanning software running on a networking device (Amoudi, paragraph 0032) and wherein the networking device comprises at least one of a firewall, router, gateway, access point, or switch (Amoudi, paragraph 0038). Assuming arguendo that the filtering mechanism(s) disclosed by Amoudi at paragraph 0032 cannot in any embodiment of that invention be construed as being operable on the firewall (element 12 of Figure 1), it is observed that Kaushik discloses a related invention for network security wherein firewalls capable of performing filtering including inter alia spam and malware filtering were known in the art (Kaushik, paragraph 0041: “In an embodiment, the security management facility 122 may provide for email security and control, for example to target spam, viruses, spyware and phishing, to control email content, and the like. Email security and control may protect against inbound and outbound threats, protect email infrastructure, prevent data leakage, provide spam filtering, and more. Aspects of the email security and control may be provided, for example, in the security agent of an endpoint 12, in a wireless access point 11 or firewall 10, as part of application protection 150 provided by the cloud, and so on.” [emphasis Examiner’s]). It would have been obvious prior to the effective filing date of the instant application for the firewall employed by Amoudi to perform the one or more filtering mechanisms as per Moore – either in conjunction with or as a substitute for the cloud-based email filters disclosed by Amoudi - as these were well-known and equally valid options within the grasp of a person of ordinary skill in the art in order to protect their network from various threats (Kaushik, Ibid) Claims 4, 6, 7, 11, 13, 14, 18, & 20 are rejected under 35 U.S.C. 103 as being unpatentable over Amoudi in view of Cardinal as applied to claims 1, 8, & 15 above, and further in view of Pickman (U.S. Patent Publication 2023/0403296). Regarding claims 4, 11, and 18: The combination further discloses wherein the plurality of checks comprises at least an Internet Protocol (IP) check (Amoudi, paragraphs 0048-0049) but does not appear to explicitly disclose any of the remaining options. However, Pickman discloses a related invention for email security wherein the corresponding email security apparatus can perform various checks including but not limited to a Sender Policy Framework (SPF) failure check (Pickman, paragraphs 0011 & 0036-0039), a destination check (Pickman, paragraph 0036), a volume check (Pickman, paragraph 0080), a usage limit check (Pickman, paragraphs 0083-0084), or a job rate limit check (Pickman, paragraph 0080). It would have been obvious prior to the effective filing date of the instant application for Amoudi to incorporate any or all of the additional checks disclosed by Pickman into his invention, as these techniques were known in the art to reduce the likelihood of erred determinations (both false positive and false negative) in classifying emails (Pickman, paragraph 0008). Regarding claims 6, 13, and 20: The combination further discloses wherein the usage limit check involves checking a usage limit for a sender address or originating domain of the email (Pickman, paragraphs 0083-0084). Regarding claims 7 and 14: The combination further discloses wherein the job rate limit check involves checking a job rate limit that specifies a number of messages that can be submitted by a domain, a single user, or a single user in a domain in a timeframe (Pickman, paragraph 0080). Claims 5, 12, & 19 are rejected under 35 U.S.C. 103 as being unpatentable over Amoudi in view of Cardinal in view of Pickman as applied to claims 4, 11, and 18 above, and further in view of Abbasi (U.S. Patent Publication 2024/0333761) Regarding claims 5, 12, and 19: None of Amoudi, Cardinal, or Pickman disclose wherein the country code limit check involves checking a country code limit associated with the email. However, Abbasi discloses a related invention for email security in which this limitation is taught (paragraphs 0021 & 0049). It would have been obvious prior to the effective filing date of the instant application for Amoudi to use a country code check as part of his email scanning invention, as country codes were a known option within the grasp of a person of ordinary skill in the art to identify potentially suspicious emails. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure, each of which disclose using firewalls for email filtering: U.S. Patent Publication 2013/0104251 (Moore) – see paragraph 0386 U.S. Patent Publication 2010/0251372 (Luck) – see paragraph 0088 Japanese Patent Publication JP2015056158 (Takashi) – e.g. page 3, third paragraph: “Specifically, the malware detection unit 13 may be provided in a network device such as a mail server, a spam filter server, a UTM, or a firewall connected to the network 4 that passes in the mail delivery process” (emphasis Examiner’s) Any inquiry concerning this communication or earlier communications from the examiner should be directed to Thomas A Gyorfi whose telephone number is (571)272-3849. The examiner can normally be reached 10:00am - 6:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. THOMAS A. GYORFI Examiner Art Unit 2435 /THOMAS A GYORFI/Examiner, Art Unit 2435 6/27/2026
Read full office action

Prosecution Timeline

Mar 22, 2024
Application Filed
Jul 29, 2025
Non-Final Rejection mailed — §103
Oct 29, 2025
Response Filed
Mar 11, 2026
Final Rejection mailed — §103
Jun 11, 2026
Request for Continued Examination
Jun 17, 2026
Response after Non-Final Action
Jul 01, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706952
LARGE LANGUAGE MODEL POWERED SOCIAL INTEGRITY SYSTEM
3y 3m to grant Granted Aug 11, 2026
Patent 12695769
ADAPTIVE SYSTEM FOR NETWORK AND SECURITY MANAGEMENT
3y 1m to grant Granted Jul 28, 2026
Patent 12695786
METHOD AND APPARATUS FOR DDoS ATTACK DETECTION AND MITIGATION IN IoT NETWORK SLICES OF 5G NETWORKS
2y 8m to grant Granted Jul 28, 2026
Patent 12695777
DATA PROCESSING DEVICE, DATA PROCESSING METHOD, AND RECORDING MEDIUM
2y 4m to grant Granted Jul 28, 2026
Patent 12676888
VIRTUAL FILE HONEY POTS FOR COMPUTING SYSTEMS PROTECTION AGAINST RANSOMWARE ATTACKS
2y 9m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
92%
With Interview (+16.3%)
3y 5m (~1y 0m remaining)
Median Time to Grant
High
PTA Risk
Based on 699 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month