Prosecution Insights
Last updated: October 02, 2026
Application No. 18/632,209

COMPREHENSIBLE THREAT DETECTION

Final Rejection §103
Filed
Apr 10, 2024
Priority
Oct 26, 2021 — provisional 63/271,771 +1 more
Examiner
DOAN, HUAN V
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
4 (Final)
80%
Grant Probability
Favorable
5-6
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
231 granted / 287 resolved
+22.5% vs TC avg
Strong +42% interview lift
Without
With
+41.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
5 currently pending
Career history
298
Total Applications
across all art units

Statute-Specific Performance

§101
12.5%
-27.5% vs TC avg
§103
58.3%
+18.3% vs TC avg
§102
15.5%
-24.5% vs TC avg
§112
11.6%
-28.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 287 resolved cases

Office Action

§103
DETAILED ACTION 1. This office action is in response to the communication filed on 08/13/2026. 2. Claims 1-20 are pending. Notice of Pre-AIA or AIA Status 3. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments 4. Applicant’s arguments filed on 08/13/2026 have been fully considered but are moot in view of the new grounds of rejections. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2017/0134415 A1, hereafter Muddu) in view of Lei et al. (US 2017/0148026 A1, hereafter Lei). Regarding claim(s) 1, 9, and 18: Muddu discloses a system comprising: one or more processors; and one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors (see fig. 1 and para. 139 where a security platform comprises one or more computers), cause the system to perform operations comprising: receiving telemetry data from a network environment, the telemetry data associated with a first modality and a second modality, the second modality being different from the first modality; detecting, in the telemetry data associated with the first modality, a first abnormal event associated with a first entity; detecting, in the telemetry data associated with the second modality, a second abnormal event associated with a second entity (see fig. 4 and paras. 135-137, 147-149, 163, 175 where data/event data/machine data (i.e., telemetry data) is received from various data sources (i.e., modalities include a first modality and a second modality) in a network, wherein events/activities are derived from the data to be analyzed to detect anomalous events/activities (i.e., a first abnormal event and a second abnormal event) associated with entities (i.e., first entity and second entity) causing anomaly/threats/attacks/malwares (i.e., security incidents) in the network); determining, from the telemetry data, a first mapping between a first user account and a first endpoint identifier of the first entity, where the first endpoint identifier is provided in the first modality; determining, from the telemetry data, a second mapping between a second user account and a second endpoint identifier of the second entity, where the second endpoint identifier is provided in the second modality; [determining that a network address of the network environment is associated with multiple endpoint identifiers concurrently and, based at least in part thereon, excluding the network address from the first mapping and the second mapping;] determining, based at least in part on the first mapping and the second mapping, that the first entity and the second entity are a same entity; based at least in part on the first abnormal event and the second abnormal event being associated with the same entity, determining that a correlation between the first abnormal event and the second abnormal event is indicative of a security incident (see para. 207 where a data source provides information of an event, an entity, an IP address associated with the entity, etc.; see paras. 214-215, 221, 224, 226 where relationships (i.e., first relationship/mapping and second relationship/mapping) between entities are discovered and recorded from data/event data associated with data sources, wherein a relationship graph is generated for each event to record the relationships between identified entities, wherein a composite relationship/security graph is generated (e.g., by combining relationship graphs) based on the relationship graphs generated from all events to include all identified relationships among all identified entities to be used for analytic on entity behaviors/activities for detecting anomalies/threats; see paras. 407-408 where security threats are identified by correlating the anomalies across the composite relationship relationships, wherein an entity poses a security threat is identified, wherein activities associated with the same user are determined; see paras. 422, 424 and/or 602-606 where anomalous/security events/activities/threat associated with entities are detected based on the relationships recorded in relationship graph(s), wherein entities include physical computing devices, users, user accounts, and identifiers/identifications (e.g., users’ ID, user account IDs, IP addresses of computing devices) associated with entities, and wherein two or more identifiers/identifications are associated with same entity/user (e.g., see paras. 264, 424). In other words, the relationships between entities including user accounts (i.e., first user account and second user account) and IP addresses (i.e., first endpoint identifier and second endpoint identifier) of computing devices (i.e., first entity and second entity) are determined from data sources, wherein IP addresses are provided in data sources. Based on the relationships between entities, a composite relationship/security graph (i.e. a unified representation) representing the relationships between entities are generated, and security events/activities/threat associated with entity/entities are detected based on the relationships recorded in composite relationship/security graph, wherein security events/activities/threat determined to be associated with the same entity/user (i.e., cross-modal entity)); and outputting an indication of the security incident (see para. 171). Muddu does not, but Lei discloses: determining that a network address of the network environment is associated with multiple endpoint identifiers concurrently and, based at least in part thereon, excluding the network address from the first mapping and the second mapping (see Lei, paras. 52, 54, 56, where an IP address is excluded from building a link analysis web when the IP address is linked to multiple entities/credit card numbers (i.e., endpoint identifiers); see fig. 6 and/or paras. 33, 41-42 where a link analysis web includes transaction data for a period of time (i.e., concurrently at the same period of time) and the associations/links (i.e., mappings) between the transaction data). It would have been obvious to one having ordinary skill in the art to which the claimed invention pertains, before the effective filing date of the claimed invention, to modify Mudu's invention by enhancing it to determining that a network address of the network environment is associated with multiple endpoint identifiers concurrently and, based at least in part thereon, excluding the network address from the first mapping and the second mapping, as taught by Lei, in order to exclude a IP address/node shared for legitimate reasons from link analysis (Lei, paras. 33-34). Regarding claim(s) 2: Muddu discloses: wherein the first modality and the second modality are associated with at least one of: a web proxy log, a file execution log, a firewall log, a network connection log, an endpoint log, an email activity tog, or an instant messaging log (see paras. 135, 163, 278, and/or 326). Regarding claim(s) 3: Muddu discloses: wherein the indication of the security incident includes information associated with the first modality and the second modality (see fig. 4, and paras. 171, 173). Regarding claim(s) 4: Muddu discloses: determining that the first abnormal event and the second abnormal event originated from the same entity, wherein determining that the first abnormal event and the second abnormal event are each associated with the same entity is based at least in part on the first abnormal event and the second abnormal event having originated from the same entity (see para. 408 where security threats are identified by correlating the anomalies across the relationships; see paras. 424 and/or 602-606 where anomalous/security events/activities/threat associated with entities are detected based on the relationships, wherein entities include physical computing devices, users, user accounts, and identifiers/identifications associated with entities, and wherein two or more identifiers/identifications are associated with same entity/user). Regarding claim(s) 5: Muddu discloses: wherein the first abnormal event is detected by a first unimodal detector that is specific to the first modality and that processes the telemetry data associated with the first modality independently of the telemetry data associated with the second modality and the second abnormal event is detected by a second unimodal detector that is specific to the second modality and that processes the telemetry data associated with the second modality independently of the telemetry data associated with the first modality (see para. 35 where data sources (e.g., web servers, application servers, databases, firewalls, routers, operating systems, etc.) are independent; see fig. 3 and paras. 158, 161, 163, and/or 193 where a plurality of components/applications/analyzers (i.e., unimodal detectors) are used to detect anomalies/threats/attacks/malware from various data sources (i.e., modalities), wherein an analyzer (e.g., real-time analyzer) independently processing a data source from the other analyzer (e.g., batch analyzer) processing). Regarding claim(s) 6: Muddu discloses: wherein determining that the first abnormal event and the second abnormal event are each associated with the same entity comprises determining that the first abnormal event and the second abnormal event are each associated with a same server (see paras. 215 where a user is using a machine with an IP address to visit a certain website; see para. 244 where a machine is used as a server; see paras. 604-606 where detected anomalous events/activities are associated with entities, and wherein the identifications are associated with same entity/user). Regarding claim(s) 7: Muddu discloses: wherein determining that the first abnormal event and the second abnormal event are each associated with the same entity comprises determining that the first abnormal event and the second abnormal event are each associated with a same user device (see paras. 215 where a user is using a machine (i.e., user device) with an IP address to visit a certain website; see paras. 604-606 where detected anomalous events/activities are associated with entities, and wherein the identifications are associated with same entity/user). Regarding claim(s) 8: Muddu discloses: assigning the first abnormal event and the second abnormal event to a same network address; and determining the correlation between the first abnormal event and the second abnormal event based at least in part on the assigning (see para. 408 where security threats are identified by correlating the anomalies across the relationships; see paras. 604-606 where detected anomalous events/activities are associated with entities, physical computing devices, users, user accounts, IP addresses, and identifiers/identifications associated with entities, and wherein the identifications are associated with same entity (i.e., same IP address)). Regarding claim(s) 10: Muddu discloses: determining that the telemetry data associated with the first modality indicates that the same entity is affected by the first abnormal event; and determining that the telemetry data associated with the second modality indicates that the same entity is affected by the second abnormal event, wherein the correlation is associated with determining that the same entity is affected by the first abnormal event and the second abnormal event (see paras. 604-606 where detected anomalous events/activities are associated with entities, wherein each of the entities includes identifications comprising user account, identifier, and IP addresses, and wherein the identifications are associated with same entity/user; see para. 136 where a compromised account is used to conduct malicious activities; see para. 186 where anomalies/threats are detected based on time-series analysis (e.g., number of log-ins per hour); see para. 350 where an anomaly associated with an account is detected; see paras. 442-443 where anomalies/threats are identified from even data generated from user log-ins to an account). Regarding claim(s) 11: Muddu discloses: wherein: the telemetry data associated with the first modality includes a first timestamp associated with the first abnormal event, the telemetry data associated with the second modality includes a second timestamp associated with the second abnormal event, and determining that the correlation is indicative of the security incident is further based at least in part on the first timestamp and the second timestamp (see fig. 4 and paras. 135-137, 147-148, 163 where data/event data/machine data is received from various data sources (i.e., modalities include a first modality and a second modality), wherein events/activities are derived from the data to be analyzed to detect anomalous events/activities (i.e., a first abnormal event and a second abnormal event) associated with threats/attacks/malwares; see paras. 409, 412, 428, and/or 434 where anomalous events/activities are detected based on timestamps from the event data). Regarding claim(s) 12: Muddu discloses: determining a length of a period of time between the first timestamp and the second timestamp, wherein determining that the correlation is indicative of the security incident is further based at least in part on the length of the period of time (see paras. 186, 217, 221, 224 and/or 317). Regarding claim(s) 13: Muddu discloses: wherein the telemetry data associated with the first modality is different from the telemetry data associated with the second modality, the telemetry data associated with the first modality comprising at least one of: a web proxy log, a file execution log, a firewall log, a network connection log, an endpoint log, an email activity log, or an instant messaging log (see paras. 135, 163, 278, and/or 326). Regarding claim(s) 14: Muddu discloses: inputting, into a machine-learned model, first telemetry data associated with the first abnormal event and second telemetry data associated with the second abnormal event; and receiving, from the machine-learned model, an output indicating that the first abnormal event and the second abnormal event are indicative of the security incident (see fig. 4 and paras. 170, 182). Regarding claim(s) 15: Muddu discloses: wherein determining that the first abnormal event and the second abnormal event are each associated with the same entity is based at least in part on a mapping between endpoint identifiers associated with the first modality and the second modality and at least one network address associated with the same entity (see paras. 604-606 where detected anomalous events/activities are associated with entities, wherein each of the entities includes identifications comprising user account, identifier, and IP addresses, and wherein the identifications are associated with same entity/user). Regarding claim(s) 16: Muddu discloses: wherein detecting the first abnormal event comprises employing a first unimodal detector specifically configured for the first modality and wherein detecting the second abnormal event comprises employing a second unimodal detector specifically configured for the second modality (see fig. 4 and paras. 135, 158, 161, and/or 170 for various applications/analyzers/machine learning models used for detecting anomalous events/activities from various data sources). Regarding claim(s) 17: See the rejection to claim 6 or 7. Regarding claim(s) 19: Muddu discloses: wherein: the telemetry data associated with the first modality includes a first indication of the same entity affected by the first abnormal event, the telemetry data associated with the second modality includes a second indication of the same entity affected by the second abnormal event, and determining that the first abnormal event and the second abnormal event are each associated with the same entity is based at least in part on the first indication and the second indication (see paras. 604-606 where detected anomalous events/activities are associated with entities, wherein each of the entities includes identifications comprising user account, identifier, and IP addresses, and wherein the identifications are associated with same entity/user; see para. 136 where a compromised account is used to conduct malicious activities; see para. 186 where anomalies/threats are detected based on time-series analysis (e.g., number of log-ins per hour); see para. 350 where an anomaly associated with an account is detected; see paras. 442-443 where anomalies/threats are identified from even data generated from user log-ins to an account). Regarding claim(s) 20: See the rejection to claim 11. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HUAN V. DOAN whose telephone number is 571-272-3809. The examiner can normally be reached on Monday – Thursday, 9:00am – 5:00pm EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, PHILIP CHEA, can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HUAN V DOAN/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Show 8 earlier events
Apr 10, 2026
Examiner Interview Summary
Apr 15, 2026
Request for Continued Examination
Apr 26, 2026
Response after Non-Final Action
May 13, 2026
Non-Final Rejection mailed — §103
Aug 12, 2026
Examiner Interview Summary
Aug 12, 2026
Applicant Interview (Telephonic)
Aug 13, 2026
Response Filed
Sep 23, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12717919
DETECTING AND MITIGATING PROMPT INJECTION ATTACKS ON LARGE LANGUAGE MODELS
2y 5m to grant Granted Aug 25, 2026
Patent 12719664
Optimized Encryption Key Management By A Group Of Storage Systems
2y 0m to grant Granted Aug 25, 2026
Patent 12717657
DETECTION OF ABNORMAL APPLICATION PROGRAMMING INTERFACE (API) SESSIONS INCLUDING A SEQUENCE OF API REQUESTS
1y 11m to grant Granted Aug 25, 2026
Patent 12706739
METHOD, APPARATUS, DEVICE AND MEDIUM FOR PROCESSING GENETIC DATA
1y 12m to grant Granted Aug 11, 2026
Patent 12706910
MIGRATION OF USER AUTHENTICATION FROM ON-PREMISE TO THE CLOUD
1y 9m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+41.9%)
2y 12m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 287 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month