Prosecution Insights
Last updated: August 17, 2026
Application No. 18/627,585

System and method for securing software applications and computing networks

Non-Final OA §103
Filed
Apr 05, 2024
Examiner
GEE, JASON KAI YIN
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
599 granted / 771 resolved
+19.7% vs TC avg
Strong +23% interview lift
Without
With
+23.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
25 currently pending
Career history
790
Total Applications
across all art units

Statute-Specific Performance

§101
11.1%
-28.9% vs TC avg
§103
50.8%
+10.8% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
21.4%
-18.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 771 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is response to communication: RCE filed on 02/23/2026. Claims 1-3, 5-10, 12-17, and 19-23 are currently pending in this application. No new IDS has been filed. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 02/23/2026 has been entered. Response to Arguments Applicant’s arguments concerning the rejections have been fully considered but are not found persuasive. Applicants argue that the combination of Ries and Bellekens references are improper, as the combination would change the principle of operation of Ries and render Ries unsatisfactory for its intended purpose. Applicants argue that Ries teaches that a honeypot generates IaaS instances only in response to attacker requests, while Bellekens deploys a deception framework regardless of any specific request made by that entity. This is not persuasive. Assuming applicants are correct in characterizing that Ries teaches generating IaaS instances in response to attacker requests, Bellekens deception framework performs in the same way. Bellekens deception framework lures and deceives attackers, and the responses Bellekens provides are directly in response to attacker requests (see pages 17-19, with providing responses that are dynamically selected based on actions performed by unauthorized entities). Applicants point to the Bellekens abstract, but as seen clearly in the abstract as well, the system is “configured to dynamically adapt or select the artificial components based on the interaction with the unauthorized entity and/or a characterization of the unauthorized entity.” Applicants characterize Bellekens’ operations as “continuous, non-condition, and insensitive to the attacker’s specific provisioning behavior,” but as clearly seen in the abstract, and throughout the entire reference, Bellekens’ system performs the opposite. It performs dynamically in response to the interactions and the characterization of the unauthorized entity. Applicants have further amended the claims to include “at least one succeeding file in the file path structure is generatively presented in response to the user interacting with a preceeding file, such that the file path structure is generatively presented during the user execution of the one or more interactions.” However, this is taught by Bellekens. As discussed above, Bellekens teaches a dynamic system that performs actions based on the interaction with the unauthorized entity. Thus, applicant’s arguments are not persuasive. See below for amended rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3. 5-10, 12-17, and 19-23 are rejected under 35 U.S.C. 103 as being unpatentable over Ries et al. US Patent Application Publication 2021/0067553 (Ries), in view of Bellekens WO 2022/234272A1 (Bellekens) As per claim 1, Ries teaches a system, comprising: a memory configured to store a plurality of instances of a software application executable within a computing environment; and one or more processors operably coupled to the memory and configured to: receive an interaction to initiate an execution of a sequence of user interactions with at least one instance of the plurality of instances of the software application executing within the computing environment (paragraphs 29-30 and throughout with honeypots; see paragraphs 136-137 with receiving interaction from user/attack; see paragraph 54 with generating responses accordingly); execute one or more generative machine-learning models trained to generate a structure configured to generatively present different responses configured to generatively present different responses of the structure in response to an execution of one or more user interactions with the structure so as to prompt the user to complete the execution of the one or more user actions with the structure (paragarphs 137-140 with generating appropriate responses to attackers request; see also paragraph 54; see paragraph 10 with generated responses based on requests; see paragraph 85 and 106 wherein rules and responses may be generated based on machine learning); generate, based on the generatively presented different responses of the structure, one or more classification labels configured to associate with the user each of the generatively presented different responses and the execution of the one or more user interactions (paragraph 88 and throughout with generating profile of attacker/attacks based on responses); and in response to determining at least a partial completion of the execution of the one or more user interactions with the file path structure, store a log of other one or more classification labels, the generatively presented different responses, and the execution of the one o more user interactions (see paragraph 88 with compiling all the information in an attack; see paragraph 113 with logging data regarding interactions; see also paragraph 118 and throughout). Although Ries teaches generatively presenting responses to a user/attacker, Ries does not explicitly teach a file path structure and presenting different files of the file path structure to prompt the user to complete the execution of the one or more user interactions with the file path structure. However, this would have been obvious. Ries already teaches presenting responses, with may be data items, and uses a file system list (see paragraphs 140 and 131). However, for a more explicit teaching and to show the obviousness of file path structures, see Bellekens (page 17 and throughout with artificial intelligence and a determined path to deceive entity; system utilizes gamification to convince entity to remain on a determined path; also see page 18 liens 10-21). Bellekens further teaches classification labels configured to associate with the user each of the generatively presented different files and the execution of the one or more user interactions (pages 18 and 19 with characterizing the entity and providing a corresponding path appropriate for the entity; also see page 18 liens 15-21), and further teaches storing a log of all the information (page 19 lines 34 to page 20 line 20). Bellekens further teaches a sequence of different files, wherein at least one succeeding file int eh file path structure is generatively presented in response to the user interacting with a preceeding file, such that the file path structure is generatively presented during the user execution fo the one or more interactions (page 16 lines 14-21 with dynamically adapting and providing reactive guidance to hacker in order to maintain attack progression on pre-determined deception paths that can be dynamically adapted; the narrative provides a chronological chain of events; see example on page 17 line 30 to page 18 line 10, with providing a decoy fake credit card, and if entity achieves the decoy, then fake data sheets or account details then are provided in narrative in order to continue to tempt and lead unauthorized entity down a deception pathway) At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of Ries with Bellekens. One of ordinary skill in the art would have been motivated to perform such an addition to provide a dynamically adaptable decoy network that is adapted according to strategy and behavior of an unauthorized user (page 10 liens 5-15). As per claim 2, the Ries combination teaches wherein the one or more processors are further configured to execute the one or more generative machine-learning models as further trained to generatively present the different files in response to the user performing one or more textual command interactions with the file path structure ((paragraph 48-50 of Ries with command line requests from attacker; see further paragraph 58 of Ries with an attacker utilizing GUI; see further Bellekens page 17 line 30 to page 19 line 15 with presenting different files in response to user performing commands). As per claim 3, the Ries combination teaches wherein the file path structure comprises one or more honeypots configured to prompt the user to complete the execution of the one or more user interactions with the file path structure (see throughout Ries with honeypots, which are used to lure users to complete interactions; see paragraph 85 with honeypot generating responses). As per claim 5, the Ries combination teaches wherein the one or more processors are further configured to: prior to receiving the interaction to initiate the execution of the sequence of user interactions with the at least one instance, train the one or more generative machine-learning models based at least in part on the plurality of instances of the software application executing within the computing environment and a network layout of the computing environment (Ries paragraph 85 with machine learning to grow and build responses, which may be used in subsequent interactions; see also paragraph 106; see also throughout Bellekens). As per claim 6, it would have been obvious over the Ries combination wherein the one or more processors are further configured to: associate the one or more classification labels with one or more electronic files accessed by the user during the execution of the one or more user interactions with the file path structure; and update the log based at least in part on the one or more electronic files accessed by the user (obvious over Ries; see paragraph 86 with collecting information about attack including the activities of attacker such as sequence of actions, port numbers used, etc; see paragraph 87 with logging server to collect all the received information from honeypot; see paragraph 88 wherein the data can be analyzed and classified accordingly, such as the different resoruces and objects accessed by attackers; also see Bellekens page 19 lines 32 to page 20 line 20.). As per claim 7, it would have been obvious over the Ries combination wherein the one or more processors are further configured to: receive a second interaction to initiate an exception of a second sequence of user interactions with the at least one instance of the plurality of instances of the software application executing within the computing environment, and in response: execute the one or more generative machine-learning models trained to generate a second file path structure configured to generatively present different files of the second file path structure in response to an execution of one or more user interactions with the second file path structure so as to prompt a second ser to compelte the execution of the one or more user interactions with the second file path structure; generate, based on the generatively presented different files of the second file path structure, one or more second classification labels configured to associate with the second user each of the generatively presented different files of the second file path structure and the execution of the one or more second user interactions; and in response to determining at least a partial completion of the execution of the one or more second user interactions with the second file path structure, store a second log of the one or more second classification labels, the generatively presented second different files of the second file path structure, and the execution of the one or more second user interactions (see the rejection of claim 1 above; see Ries paragraph 106 and throughout wherein attacks may be continuous and data used can be used for subsequent attacks; the process is then performed again; see further Ries paragraph 108 with plurality of dummy iaas instances which can be used for other sessions) Claim 8 is rejected using the same basis of arguments used to reject claim 1 above. Claim 9 is rejected using the same basis of arguments used to reject claim 2 above. Claim 10 is rejected using the same basis of arguments used to reject claim 3 above. Claim 12 is rejected using the same basis of arguments used to reject claim 5 above. Claim 13 is rejected using the same basis of arguments used to reject claim 6 above. Claim 14 is rejected using the same basis of arguments used to reject claim 7 above. Claim 15 is rejected using the same basis of arguments used to reject claim 1 above. Claim 16 is rejected using the same basis of arguments used to reject claim 2 above. Claim 17 is rejected using the same basis of arguments used to reject claim 3 above. Claim 19 is rejected using the same basis of arguments used to reject claim 5 above. Claim 20 is rejected using the same basis of arguments used to reject claim 6 above. As per claim 21, the Ries combination teaches wherein the file path structure comprises one or more honeypots configured to prompt the user to engage with file path structure for at least a predetermined period of time (see throughout Ries with utilizing honeypots; see also Bellekens page 5 line 29 to page 6 line 4 with gamification triggers based on predefined time periods; see also page 15 line 4-25 wherein certain paths of different threshold times). Claim 22 is rejected using the same basis of arguments used to reject claim 21 above. Claim 23 is rejected using the same basis of arguments used to reject claim 21 above. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON KAI YIN GEE whose telephone number is (571)272-6431. The examiner can normally be reached on Monday-Friday 8:30-5:00 PST Pacific. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /JASON K GEE/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Apr 05, 2024
Application Filed
Aug 11, 2025
Non-Final Rejection mailed — §103
Nov 12, 2025
Response Filed
Dec 01, 2025
Final Rejection mailed — §103
Feb 23, 2026
Request for Continued Examination
Mar 13, 2026
Response after Non-Final Action
Jul 28, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695595
Ciphertext Header-Based Data Security
2y 2m to grant Granted Jul 28, 2026
Patent 12695592
ELECTRONIC DEVICE FOR ESTIMATING APPROXIMATE RANK OF HOMOMORPHIC CIPHERTEXT AND CONTROL METHOD THEREOF
1y 11m to grant Granted Jul 28, 2026
Patent 12688314
AUTHENTICATION AND IDENTIFICATION OF THIRD PARTIES USING GENERAL AND PERSONALIZED LARGE LANGUAGE MODELS
2y 1m to grant Granted Jul 21, 2026
Patent 12664250
DELAY-BASED PUF FOR CHIPLET INTERCONNECTS
3y 5m to grant Granted Jun 23, 2026
Patent 12657316
PROVIDING SECURE GATEWAY TO BACKPLANE-CONNECTED DEVICES VIA AN EDGE COMPUTE MODULE
2y 10m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+23.2%)
3y 0m (~8m remaining)
Median Time to Grant
High
PTA Risk
Based on 771 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month