Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 24 April 2026 in regards to the U.S.C. 101 rejection have been fully considered but they are not persuasive.
In response to Applicant’s argument (Pages 6-8) stating that the claims do not recite a mental process because the recited operations are performed by server-implemented modules and are therefore “not practical to human beings”, the examiner respectfully disagrees.
Evaluation under Step 2A, Prong One is not whether the claim explicitly recites a human being performing the steps, but whether the claimed limitations can practically be performed in the human mind or with a pen and paper. The claims recite: receiving reported messages, classifying messages as clean/spam/threat, extracting indicators of compromise from threat messages, determining prevalence metrics, and selecting blocklist candidates based on those metrics. These are evaluation, analysis, judgment, and selection activities that are mental processes.
Applicant’s reliance on the fact that the claims are performed by “one or more servers” is not sufficient to remove the claims from the mental-process category. Generic computer implementation of an abstract mental process does not transform that process into something other than an abstract idea. The claim language remains functional and high level, and does not recite any specific improvement in computer technology or any particular technical element for performing the recited steps. Accordingly, the recited server components merely implement the steps on generic computer hardware and do not remove the claim from being nothing more than a mental process.
Applicant asserts that the claims are more than a mental process because the August 4, 2025 memorandum cautions examiners not to expand it limitations that cannot practically be performed mentally.
The claims are directed to information processing steps that can practically be performed mentally: reviewing messages, determining whether they are suspicious, identifying suspicious indicators, counting occurrences, and selecting entries based on those counts. Although the specification frames these steps as performed by servers the substance of what is being claimed does not change. The memorandum does not suggest that any claim reciting a computer or server automatically avoids mental-process treatment, rather, it requires an assessment of the claimed limitations individually.
In response to Applicant’s argument (Pages 8-9) stating that even if the claims recite an abstract idea, they integrate that idea into a practical application because they improve the technical field of email security and result in blocking messages via a private blocklist, the examiner respectfully disagrees.
The claim as a whole does not recite a particular technological improvement to computer functionality, network security architecture, message filtering technology, or blocklist enforcement mechanics. Instead, the claim recites a result-oriented pipeline for collecting reported messages, classifying them, extracting IoC, computing metrics, selecting candidates, and providing those candidates for blocklist use. These are generic functions performed by generic computer components.
The disclosed “improvement” is an improvement in the business or administrative outcome of security analysis, not a claimed technological improvement. The claims do not explain how the server, the disposition engine, the IoC decomposer, or the BLE candidate selector operate. They merely recite what those components do at a high level.
The claims do not recite any specific technological improvement to the way messages are received, stored, classified, analyzed, or blocked. Instead, they recite generic server-based data collection, labeling, counting, and selection. The claim does not specify a novel architecture, data structure, extraction technique, metric-computation method, or blocking mechanism. Accordingly, the claims do not integrate the alleged abstract idea into a practical application under Step 2A, Prong Two.
For the claim to be considered an improvement on the technology the claim itself must reflect the disclosed improvement on the technology. Given its broadest reasonable interpretation, the claims recite a process of collecting and analyzing information to produce a ranking which is used by a human to select from the ranking. Such activities of collecting data, analyzing or predicting outcomes, and organizing or ranking information fall within the mental process grouping.
In response to Applicant’s argument (Page 9) stating that that the ordered combination of claim elements provides an inventive concept because the sequence of server modules allegedly produces a non-conventional result, the examiner respectfully disagrees.
At Step 2B, the question is whether the additional elements, individually or as an ordered combination, amount to significantly more than the abstract idea itself. Here, the additional elements are generic server-based components performing routine cybersecurity and data-analysis functions.
The claim does not recite any nonconventional or non-generic hardware configuration, any special-purpose processor, any unique data structure, or any unconventional algorithm. It simply arranges conventional components in a conventional sequence to perform the abstract idea of analyzing messages and selecting candidate blocklist entries.
The statement that the ordered combination is “non-conventional” is conclusory and is not supported by the claim language. The specification describes the modules in functional terms and describes them as conventional computing components. Further, the use of the blocklist to block messages does not supply an inventive concept. Applying the output of the abstract analysis to the conventional security function of message blocking is simply post-solution activity or an intended use of the abstract result.
The examiner recommends adding to the claims a showing that the claim is not just a generic mental analysis, but an automated cybersecurity classification workflow. The claim language should be tied to a specific technical operation such as expanding upon the disposition engine which is capable of machine learning model output, YARA rule matching, real-time intelligence feeds, and sameness rules/model trained on known threat and known clean messages.
Applicant's arguments (pages 10-11) filed 24 April 2026 in regards to the U.S.C. 103 rejections of the independent claims 1 and 11 are moot in view of new ground(s) of rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Claims 1 and 11 recite receiving reported messages, classifying the messages as clean, spam, or threat, determining indicators of compromise from threat messages, determining one or more metrics for each indicator of compromise, selecting indicators of compromise as blocklist entry candidates based on the metrics, and providing the candidates for selection to be included in a private blocklist used to block messages.
The limitations of classifying the messages as one of clean, spam, or threat, determining indicators of compromise from the threat messages, determining one or more metrics for each indicator of compromise, and selecting indicators of compromise as blocklist entry candidates based on the metrics, as drafted, are processes that, under their broadest reasonable interpretation, cover performance of the limitations in the mind but for the recitation of generic computer components. That is, other than reciting implementation by one or more servers, nothing in the claim precludes these steps from practically being performed mentally.
For example, but for the recitation of a disposition engine or servers, classifying messages as clean, spam, or threat encompasses a person reviewing the messages and mentally determining whether each message appears suspicious. Similarly, determining indicators of compromise from threat messages encompasses a person reviewing message content and identifying suspicious sender addresses, URLs, file names, domains, hashes, or other indicators of compromise. Likewise, determining one or more metrics for each indicator of compromise encompasses a person counting how many times an indicator appears, how broadly it appears across organizations, or how harmful it appears to be. Finally, selecting indicators of compromise as blocklist entry candidates based on those metrics encompasses a person mentally ranking or choosing the most prevalent or most severe indicators for inclusion in a blocklist. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the mental processes grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim recites only generic computer implementation, including a message collection system, a disposition engine, an IoC decomposer, and a BLE candidate selector, all implemented on one or more servers. These components are recited at a high level of generality as generic components performing generic computer functions of receiving, classifying, extracting, counting, selecting, and outputting information. The claim does not recite a specific technical improvement to message processing, threat analysis, indicator extraction, metric computation, or blocklist enforcement. Rather, the claimed modules merely apply the abstract evaluation and selection process using generic computer components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limit on practicing the abstract idea.
The claim also does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration into a practical application, the additional limitations amount to no more than instructions to apply the abstract idea using generic computer components. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
The dependent claims fail to provide significantly more than the abstract idea, because they either fall under the abstract idea or add additional elements that amount to appending well-understood routing and conventional activities previously known in the industry, specified at a high level of generality, to the judicial exception. The dependent claims merely add another layer of data selection, filtering, or ranking, all of which remain abstract analytical operations. None of the dependent limitations introduces a specific technological mechanism sufficient to transform the claims into something more than a mental process.
Claim Objections
Claims 1, 6, 7, and 11 are objected to because of the following informalities: The claims recite “indicators of comprise” and should be --indicators of compromise--.
Claim 1 is objected to because of the following informalities: On line 11, the claim recites “to decomposes the messages” should be --to decompose the messages--.
Claim 11 is objected to because of the following informalities: On line 16, the claim recites “select based at least” should be --select, based at least--.
Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5, 8, 10-15, 18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Singh (U.S. Patent Publication 2017/0223046) in view of Jeyakumar et al. (U.S. Patent Publication 2020/0389486), hereinafter Jeyakumar and further in view of Shinde et al. (U.S. Patent Publication 2008/0114843), hereinafter Shinde.
Regarding claim 1, Singh shows
A method comprising: (Fig. 46; [0691]; i.e. A method performed by a malicious email detection engine as a hardware appliance/server including both hardware and software.)
receiving, by a message collection system (Fig. 47, 4714/4716; [0717-0718]) implemented on one or more servers ([0691]; Fig. 4, 4712; i.e. malicious email detection engine) and configured to prepare reported messages for disposition, messages that have been reported by users (i.e. security operations team) of one or more organizations, ([0112]; i.e. customer) the one or more servers storing the messages into a message collection system; (i.e. The malicious email detection engine must store the messages for a period time in order to analyze the messages.) ([0702]; [0696])
classifying, by a disposition engine (Fig. 47, 4722; [0723]; i.e. decision engine) implemented on the one or more servers and configured to process and disposition the messages received from the message collection system, the messages as one of clean, spam or threat, (i.e. suspect/malicious) the one or more servers tagging the messages responsive to the classification; ([0705-0707])
determining, by an indicator of compromise (IoC) decomposer (Fig. 47, 4724; [0724]; i.e. analytic engine) implemented on the one or more servers and configured to decomposes the messages classified and tagged as a threat to extract indicators of compromise, the plurality of indicators of compromise from the messages classified and tagged as a threat; ([0707]; [0709])
However, Singh fails to show
determining, by a blocklist entry (BLE) candidate selector implemented on the one or more servers and configured to use a metric calculator to determine one or more metrics for an indicator of compromise, one or more metrics for each of the plurality of indicators of compromise;
selecting, by the blocklist entry (BLE) candidate selector implemented on the one or more servers based at least on the one or more metrics, one or more of the plurality of indicators of compromise as blocklist entry (BLE) candidates; and
providing, by the blocklist entry (BLE) candidate selector implemented on the one or more servers, the BLE candidates for selection to be included in a private blocklist, the selected BLE candidates included in the private blocklist being used to block messages.
Jeyakumar shows
determining, by a blocklist entry (BLE) candidate selector (Fig. 3; [0062]; i.e. computer modules of threat detection platform such as analysis module and remediation engine to perform the cited methods) implemented on the one or more servers ([0219]; i.e. computing device implementing threat detection platform) and configured to use a metric calculator (i.e. computer instructions to calculate the metrics) to determine one or more metrics for an indicator of compromise, one or more metrics (i.e. probability of being malicious/severity/scores) for each of the plurality of indicators of compromise; ([0170-0177])
selecting, by the blocklist entry (BLE) candidate selector implemented on the one or more servers based at least on the one or more metrics, one or more of the plurality of indicators of compromise as blocklist entry (BLE) candidates; and (Fig. 15B; [0178]; i.e. The IOCs may be sorted/selected such as recent or highest severity level for review by the enterprise.)
providing, by the blocklist entry (BLE) candidate selector implemented on the one or more servers, the BLE candidates for selection to be included in a private blocklist, the selected BLE candidates included in the private blocklist being used to block messages. ([0157]; i.e. An enterprise may enable/select from most recent or highest severity IOCs for their enterprise as entries/private blocklist for enterprise for examining their emails.)
Jeyakumar and Singh are considered analogous art because they involve identifications of threatening email using IOCs. Singh shows identifying IOCs from emails. Jeyakumar shows that the IOCs may filtered. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh to incorporate the teachings of Jeyakumar wherein determining, by a blocklist entry (BLE) candidate selector implemented on the one or more servers and configured to use a metric calculator to determine one or more metrics for an indicator of compromise, one or more metrics for each of the plurality of indicators of compromise, selecting, by the blocklist entry (BLE) candidate selector implemented on the one or more servers based at least on the one or more metrics, one or more of the plurality of indicators of compromise as blocklist entry (BLE) candidates, and providing, by the blocklist entry (BLE) candidate selector implemented on the one or more servers, the BLE candidates for selection to be included in a private blocklist, the selected BLE candidates included in the private blocklist being used to block messages. Doing so bolsters the ability to detect security threats while saving computation time of all of the IOCs.
Signh and Jeyakumar fail to disclose wherein the metric calculator determines the one or more metrics comprising a prevalence metric, the prevalence metric comprising a count of a number of times an indicator of comprise is included in the plurality of indicators of compromise from classified messages for a time period.
In an analogous art, Shinde discloses wherein the metric calculator (208 – fig. 2) determines the one or more metrics comprising a prevalence metric (i.e., counts), the prevalence metric comprising a count of a number of times an indicator of comprise (i.e., sender email address) is included in the plurality of indicators of compromise from classified messages (i.e., email messages) for a time period (i.e., counts are compiled for a predefined period, such as 24 hours) (¶ 0019-0021).
Singh, Jeyakumar, and Shinde are considered analogous art because they involve handling unwanted email messages. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Jeyakumar to include wherein the metric calculator determines the one or more metrics comprising a prevalence metric, the prevalence metric comprising a count of a number of times an indicator of comprise is included in the plurality of indicators of compromise from classified messages for a time period as taught by Shinde for the benefit of accumulating historical classification for a sender address and using a threshold to classify the sender email address.
Regarding claim 2, Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches providing, by the one or more servers, the BLE candidates to a false positive prevention unit. (Jeyakumar: Fig. 2, 212; Fig. 3, 318; i.e. visualization component/customer device) (Jeyakumar: [0157]; Fig. 15B; [0178]; i.e. Providing a visual result to an enterprise/customer is considered false positive prevention because the enterprise can identify issues with the results.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar wherein providing, by the one or more servers, the BLE candidates to a false positive prevention unit in order to review the results of the analysis.
Regarding claim 3, Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches removing, by the one or more servers, from the messages classified as a threat, messages with a timestamp of receipt in a reporting user’s mailbox before a predetermined time period before the classification. (Jeyakumar: [0116])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar wherein removing, by the one or more servers, from the messages classified as a threat, messages with a timestamp of receipt in a reporting user’s mailbox before a predetermined time period before the classification in order to prevent a user from being exposed to an email attack.
Regarding claim 4, Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches excluding, by the one or more servers, from the plurality of indicators of compromise any indicators of compromise on a BLE exclusion list. (i.e. IoCs disabled for the enterprise) (Jeyakumar: [0157])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar wherein excluding, by the one or more servers, from the plurality of indicators of compromise any indicators of compromise on a BLE exclusion list to customize the IOCs for the enterprise.
Regarding claim 5 Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches determining, by the one or more servers, one or more metrics comprising a severity metric representing an extent of harm to an organization (i.e. enterprise) a message having an indicator of compromise can cause. (Jeyakumar: [0174]; [0178]; [0168])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar further comprising determining, by the one or more servers, one or more metrics comprising a severity metric representing an extent of harm to an organization a message having an indicator of compromise can cause for the same motivation as detailed in claim 1.
Regarding claim 8, Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches excluding, by the one or more servers, as BLE candidates the plurality of indicators of compromise with one or more metrics below a threshold value (i.e. 1) for the respective metric, wherein the one or more metrics comprises a prevalence metric (i.e. score) or a breadth metric. (Jeyakumar: [0175]; [0139]; [0159]; i.e. An IOC with a confidence score of 0 would not be included as a block list candidate.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar further comprising excluding, by the one or more servers, as BLE candidates the plurality of indicators of compromise with one or more metrics below a threshold value for the respective metric, wherein the one or more metrics comprises a prevalence metric or a breadth metric for the same motivation as detailed in claim 1.
Regarding claim 10, Singh, Jeyakumar, and Shinde disclose, in particular Jeyakumar teaches outputting, by the one or more servers, as BLE candidates each of the selected plurality of indicators of compromise with the one or more metrics. (i.e. severity) (Jeyakumar: Fig. 15B; [0178])
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh and Shinde to incorporate the teachings of Jeyakumar further comprising outputting, by the one or more servers, as BLE candidates each of the selected plurality of indicators of compromise with the one or more metrics to provide a user with the identified information.
Regarding claim 11, this system claim comprises limitations substantially the same as those detailed in claim 1 above and is accordingly rejected on the same basis.
Regarding claim 12, this system claim comprises limitations substantially the same as those detailed in claim 2 above and is accordingly rejected on the same basis.
Regarding claim 13, this system claim comprises limitations substantially the same as those detailed in claim 3 above and is accordingly rejected on the same basis.
Regarding claim 14, this system claim comprises limitations substantially the same as those detailed in claim 4 above and is accordingly rejected on the same basis.
Regarding claim 15, this system claim comprises limitations substantially the same as those detailed in claim 5 above and is accordingly rejected on the same basis.
Regarding claim 18, this system claim comprises limitations substantially the same as those detailed in claim 8 above and is accordingly rejected on the same basis.
Regarding claim 20, this system claim comprises limitations substantially the same as those detailed in claim 10 above and is accordingly rejected on the same basis.
Claim(s) 9 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Singh in view of Jeyakumar and further in view of Shinde as applied to claims 1 and 11 above, and further in view of Chen et al. (U.S. Patent Publication 2021/0266345), hereinafter Chen.
Regarding Claims 9 and 19, Singh, Jeyakumar, and Shinde fail to disclose determining, by an artificial intelligence model of the one or more servers, which of the BLE candidates are approved to be included in the blocklist, the artificial intelligence model being trained on previous BLE candidates.
In an analogous art, Chen discloses determining, by an artificial intelligence model of the one or more servers (104 – fig. 1), which of the BLE candidates are approved to be included in the blocklist (i.e., the machine learning model is used to determine likelihood that message is malicious or ‘approved to be included in the blocklist” and utilized to handle a security response associated with the message), the artificial intelligence model being trained on previous BLE candidates (i.e., the machine learning model may be trained using historical data) (figs 3-4; ¶ 0011, 0015, & 0032-0033).
Singh, Jeyakumar, Shinde, and Chen are considered analogous art because they involve handling malicious email messages. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Singh, Jeyakumar, and Shinde to include determining, by an artificial intelligence model of the one or more servers, which of the BLE candidates are approved to be included in the blocklist, the artificial intelligence model being trained on previous BLE candid as taught by Chen for the benefit of improving classification by automatically learning from prior classification decisions to accelerate candidate review, improve consistency, and reduce false-positive entries.
Allowable Subject Matter
Claims 6 and 16 could not be rejected using prior art. The claims may be allowable over prior art if rewritten in independent form including all of the limitations of the base claim and any intervening claims and amended to overcome any outstanding U.S.C. 101 rejections.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following publications show the general state of the art related to detecting and classifying email messages.
US 2023/0086556 A1 to Himler et al.
US 2022/0345485 A1 to Kras
US 2022/0166784 A1 to Patton et al.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRIS PARRY whose telephone number is (571)272-8328. The examiner can normally be reached Monday through Thursday 7:00 am to 4:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Colleen Fauz can be reached at 571-272-1667. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
CHRIS PARRY
Supervisory Patent Examiner
Art Unit 2451
/Chris Parry/Supervisory Patent Examiner, Art Unit 2451