Prosecution Insights
Last updated: August 14, 2026
Application No. 18/638,800

HONEYPOT-BASED ATTACK DETECTION

Final Rejection §103
Filed
Apr 18, 2024
Examiner
ALGIBHAH, HAMZA N
Art Unit
2441
Tech Center
2400 — Computer Networks
Assignee
Hewlett Packard Enterprise Development L.P.
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
82%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
578 granted / 731 resolved
+21.1% vs TC avg
Minimal +3% lift
Without
With
+3.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
28 currently pending
Career history
755
Total Applications
across all art units

Statute-Specific Performance

§101
12.6%
-27.4% vs TC avg
§103
52.1%
+12.1% vs TC avg
§102
19.9%
-20.1% vs TC avg
§112
9.9%
-30.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 731 resolved cases

Office Action

§103
Detailed Action Claims 1-7 and 9-21 are pending. Claims 1-2, 5-7, 9-16, and 19-20 are rejected. Claims 3-4, 17-18 and 21 are objected. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-7, 9-16, and 19-20 are rejected under 35 U.S.C. 103) as being unpatentable over GURI et al (Pub. No.: US 2019/0332766 A1) in view of BEDHAPUDI et al (Pub. No.: US 2019/0108340 A1). As per claim 1, GURI discloses a non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to: - receive, by a data replication manager from an agent, a honeypot pattern to be contained in a honeypot file created by the agent (GURI, paragraph 0062, wherein “Updateable knowledge base 224 may also store predetermined illegal pattern(s) … The patterns stored in updateable knowledge base 224 may be periodically updated with new patterns (e.g., via a software update)”; wherein Malicious Process Detector 214 can be the data replication manager and the file(s) within the updateable knowledge base 224 storing the illegal patterns can be the honeypot file and the component creating/generating the illegal pattern can be the agent as claimed), - monitor, by the data replication manager, input/output (I/O) operations to identify data matching the honeypot pattern, the I/O operations being part of a write of the honeypot file containing the honeypot pattern by the agent to a storage system (GURI, paragraph 0062, wherein “operation analyzer 208 may compare the file access operation(s) detected by operation monitor 206 to the file access operation(s) included in the stored, predetermined pattern(s) to determine whether the file access operation(s) match any of the pattern(s) stored therein”. Paragraph 0071, wherein “At step 304, one or more file access operations are determined to be performed with respect to at least one of the one or more decoy files. For example, with reference to FIG. 4, operation monitor 406 monitors decoy file(s) 416 to determine file access operation(s) 403 are being performed with respect thereto. In accordance with an embodiment, operation monitor 406 may use hooking techniques to hook procedure calls issued to decoy file(s) 216. Examples of procedure calls that may be hooked include, but are not limited to, an NtOpenFile procedure call, an NtReadFile procedure call, an NtWriteFile procedure call, each of which are procedure calls used in a Microsoft Windows®-based operating system”); - based on identifying the data of the one or more I/O operations matching the honeypot pattern, determine, by the data replication manager, storage location information associated with the data identified as matching the honeypot pattern (GURI, paragraph 0062, wherein “operation analyzer 208 may compare the file access operation(s) detected by operation monitor 206 to the file access operation(s) included in the stored, predetermined pattern(s) to determine whether the file access operation(s) match any of the pattern(s) stored therein”; Thus, identifying a pattern associated with the one or more file access operations that are being performed with respect to the one or more decoy files inherently identifies the storage location as claimed); - detect, by the data replication manager, an access of the data at a storage location indicated by the storage location information (GURI, Fig 4, paragraph 0073, wherein “In accordance with one or more embodiments, a pattern associated with the one or more file access operations that are being performed with respect to the one or more decoy files are identified and one or more rules are applied to the pattern to determine whether the one or more file access operations originate from the malicious process. For example, with reference to FIG. 4, operation analyzer 408 may identify a pattern associated with file access operation(s) 403”); and - indicate, by the data replication manager, a potential attack based on detecting the access of the data at the storage location indicated by the storage location information (GURI, paragraph 0076, wherein “At step 308, in response to determining that the one or more file access operations originate from the malicious process, an action is performed to neutralize the malicious process. For example, with reference to FIG. 4, in response to receiving indicator 407, operation monitor 406 performs an action to neutralize the malicious process”).GURI does not explicitly disclose the data replication manager to replicate data writes to a replication data repository. However, BEDHAPUDI discloses wherein the monitoring of the I/O operations is by a data replication manager that replicates data writes to a replication data repository (BEDHAPUDI, paragraph 0291, wherein “In addition to the previously described systems, the client computing device 302 may include a filter driver 314 that can interact with data (e.g., production data) associated with the applications 310. For instance, the filter driver 314 may comprise a file system filter driver, an operating system driver, a filtering program, a data trapping program, an application, a module of one or more of the applications 310, an application programming interface (“API”), or other like software module or process that, among other things, monitors and/or intercepts particular application requests targeted at a file system, another file system filter driver, a network attached storage (“NAS”), a storage area network (“SAN”), mass storage and/or other memory or raw data. In some embodiments, the filter driver 314 may reside in the I/O stack of an application 310 and may intercept, analyze, and/or copy certain data traveling to or from the application 310 from or to a file system”; paragraph 0171, wherein “Replication is another type of secondary copy operation. Some types of secondary copies 116 periodically capture images of primary data 112 at particular points in time (e.g., backups, archives, and snapshots). However, it can also be useful for recovery purposes to protect primary data 112 in a more continuous fashion, by replicating primary data 112 substantially as changes occur. In some cases a replication copy can be a mirror copy, for instance, where changes made to primary data 112 are mirrored or substantially immediately copied to another location (e.g., to secondary storage device(s) 108). By copying each write operation to the replication copy, two storage systems are kept synchronized or substantially synchronized so that they are virtually identical at approximately the same time”). Therefore, it would have been obvious to one ordinary skill in the art before the effective filing date of the invention to incorporate BEDHAPUDI to GURI to achieve the claimed limitations because this would have provided a backup storage that can be used when the primary storage is not accessible which allows the system to directly access, copy, restore, back up, or otherwise manipulate the replication copies as if they were the “live” primary data 112 (see BEDHAPUDI 0172). As pre claim 2, claim 1 is incorporated and GURI discloses wherein the instructions upon execution cause the system to: create, by the agent, the honeypot pattern; and write, by the agent, the honeypot file containing the honeypot pattern to the storage system (GURI, paragraph 0062, wherein “Updateable knowledge base 224 may also store predetermined illegal pattern(s) … The patterns stored in updateable knowledge base 224 may be periodically updated with new patterns (e.g., via a software update)”). As pre claim 5, claim 1 is incorporated and BEDHAPUDI discloses wherein the instructions upon execution cause the system to: identify, by the data replication manager, a data volume to be protected by the data replication manager by replicating data writes of the data volume to the replication data repository, send information of the data volume from the data replication manager to the agent; and in response to receiving the information of the data volume from the data replication manager, write, by the agent, the honeypot file containing the honeypot pattern to the data volume in the storage system (BEDHAPUDI, paragraph 0171, wherein “Replication is another type of secondary copy operation. Some types of secondary copies 116 periodically capture images of primary data 112 at particular points in time (e.g., backups, archives, and snapshots). However, it can also be useful for recovery purposes to protect primary data 112 in a more continuous fashion, by replicating primary data 112 substantially as changes occur. In some cases a replication copy can be a mirror copy, for instance, where changes made to primary data 112 are mirrored or substantially immediately copied to another location (e.g., to secondary storage device(s) 108). By copying each write operation to the replication copy, two storage systems are kept synchronized or substantially synchronized so that they are virtually identical at approximately the same time”); As pre claim 6, claim 1 is incorporated and BEDHAPUDI discloses wherein the data writes replicated by the data replication manager comprise data writes performed by a virtual computing entity that is protected by the data replication manager (BEDHAPUDI, Fig 2A, paragraph 0070, wherein “In some embodiments, computing devices can include one or more virtual machine(s) running on a physical host computing device (or “host machine”) operated by the organization. As one example, the organization may use one virtual machine as a database server and another virtual machine as a mail server, both virtual machines operating on the same host machine. A Virtual machine (“VM”) is a software implementation of a computer that does not physically exist and is instead instantiated in an operating system of a physical computer (or host machine) to enable applications to execute within the VM's environment, i.e., a VM emulates a physical computer”; paragraph 0087, wherein “For virtual machines, the operating system and other applications 110 of client computing device(s) 102 may execute within or under the management of virtualization software (e.g., a VMM), and the primary storage device(s) 104 may comprise a virtual disk created on a physical storage device. System 100 may create secondary copies 116 of the files or other data objects in a virtual disk file and/or secondary copies 116 of the entire virtual disk file itself (e.g., of an entire .vmdk file)”). As pre claim 7, claim 6 is incorporated and GURI discloses wherein the agent is executed in the virtual computing entity (BEDHAPUDI, Fig 2A, paragraph 0070, wherein “In some embodiments, computing devices can include one or more virtual machine(s) running on a physical host computing device (or “host machine”) operated by the organization. As one example, the organization may use one virtual machine as a database server and another virtual machine as a mail server, both virtual machines operating on the same host machine. A Virtual machine (“VM”) is a software implementation of a computer that does not physically exist and is instead instantiated in an operating system of a physical computer (or host machine) to enable applications to execute within the VM's environment, i.e., a VM emulates a physical computer”; paragraph 0087, wherein “For virtual machines, the operating system and other applications 110 of client computing device(s) 102 may execute within or under the management of virtualization software (e.g., a VMM), and the primary storage device(s) 104 may comprise a virtual disk created on a physical storage device. System 100 may create secondary copies 116 of the files or other data objects in a virtual disk file and/or secondary copies 116 of the entire virtual disk file itself (e.g., of an entire .vmdk file)”). As pre claim 9, claim 1 is incorporated and GURI discloses wherein the indicating of the potential attack comprises providing a notification of the potential attack (GURI, paragraph 0060, wherein “In accordance with an embodiment, comprises one or more of terminating the malicious process, suspending the malicious process, performing backup of the one or more other files stores in the file directory, checking an integrity of the one or more other files, activating an anti-virus program, recording in an event log an event that indicates that the malicious process performed the one or more file access operations to the one or more decoy files, or prompting a user of the computing device to indicate an operation to perform”) GURI does not explicitly disclose information identifying a latest recovery point for data. However, BEDHAPUDI discloses information identifying a latest recovery point for data (BEDHAPUDI, paragraph 0101-0104, 0184-085, wherein “According to certain embodiments, storage manager 140 provides one or more of the following functions: … initiating restore and recovery operations”). Therefore, it would have been obvious to one ordinary skill in the art before the effective filing date of the invention to incorporate BEDHAPUDI to GURI to achieve the claimed limitations because this would have provided a backup storage that can be used when the primary storage is not accessible which allows the system to directly access, copy, restore, back up, or otherwise manipulate the replication copies as if they were the “live” primary data 112 (see BEDHAPUDI 0172). As pre claim 10, claim 1 is incorporated and GURI discloses wherein the indicating of the potential attack comprises providing a notification of the potential attack and write data written to the storage location indicated by the storage location information (GURI, paragraph 0060, wherein “In accordance with an embodiment, comprises one or more of terminating the malicious process, suspending the malicious process, performing backup of the one or more other files stores in the file directory, checking an integrity of the one or more other files, activating an anti-virus program, recording in an event log an event that indicates that the malicious process performed the one or more file access operations to the one or more decoy files, or prompting a user of the computing device to indicate an operation to perform”). As pre claim 11, claim 1 is incorporated and GURI discloses wherein the instructions upon execution cause the system to: detect a change of the storage location of the data matching the honeypot pattern; based on detecting the change of the storage location, determine whether an access of the data matching the honeypot pattern at the changed storage location has occurred; and indicate a potential attack based on detecting the access of the data at the changed storage location (GURI, paragraph 0060-0061, wherein “An example of a rule that specifies an illegal pattern may be a read operation that reads a portion of data from a file, a write operation that rewrites that portion with an encrypted version of that data, and repeating these operations until all the portions of data from the file are encrypted. Another example be a read operation that reads the whole file for data included therein, a create operation that creates a new file (having the same file name) that contains an encrypted version of that data, and a delete operation that deletes the original file”). As pre claim 12, claim 1 is incorporated and GURI discloses wherein the detected access comprises a read access or a write access (GURI, paragraph 0060-0061, wherein “An example of a rule that specifies an illegal pattern may be a read operation that reads a portion of data from a file, a write operation that rewrites that portion with an encrypted version of that data, and repeating these operations until all the portions of data from the file are encrypted. Another example be a read operation that reads the whole file for data included therein, a create operation that creates a new file (having the same file name) that contains an encrypted version of that data, and a delete operation that deletes the original file”). As pre claim 13, claim 1 is incorporated and GURI discloses wherein the monitoring of the I/O operations and the determining of the storage location information are performed during an initialization stage of a data protection process (GURI, Fig 3, paragraph 0064, wherein “Malicious process detector 114 may create one or more decoy files 116 in one or more of director(ies) 110. Examples of such directories include, but are not limited to, a default documents storage directory of operating system 106, directories that contain user, documents, spreadsheets, pictures, images, or any other directory maintained by file system 108. It is noted in addition to or in lieu of file(s) 112 and decoy file(s) 116 being stored in director(ies) 110, file(s) 112 and decoy file(s) 116 may be stored in any suitable storage location and may be stored accordance with any suitable organization”), and wherein the detecting of the access and the indicating of the potential attack are performed during a tracking stage of the data protection process after the initialization stage (GURI, Fig 3, paragraph 0071, wherein “For example, with reference to FIG. 4, operation monitor 406 monitors decoy file(s) 416 to determine file access operation(s) 403 are being performed with respect thereto”; paragraph 0073, wherein “In accordance with one or more embodiments, a pattern associated with the one or more file access operations that are being performed with respect to the one or more decoy files are identified and one or more rules are applied to the pattern to determine whether the one or more file access operations originate from the malicious process. For example, with reference to FIG. 4, operation analyzer 408 may identify a pattern associated with file access operation(s) 403”). Claims 14-16, 19-20 are rejected under the same rationale as claim 1, 2-7 and 9-13. Allowable Subject Matter Claims 3-4, 17-18 and 21 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Response to Arguments Applicant's arguments filed on 06/05/2026 have been fully considered but they are not moot in light of the new mapping. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HAMZA N ALGIBHAH whose telephone number is (571)270-7212. The examiner can normally be reached 7:30 am - 3:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ario Etienne can be reached at . The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HAMZA N ALGIBHAH/Primary Examiner, Art Unit 2457
Read full office action

Prosecution Timeline

Apr 18, 2024
Application Filed
Mar 09, 2026
Non-Final Rejection mailed — §103
May 21, 2026
Interview Requested
Jun 01, 2026
Applicant Interview (Telephonic)
Jun 05, 2026
Response Filed
Jun 17, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701124
METHOD FOR DETECTING A MALICIOUS DEVICE IN A COMMUNICATION NETWORK, CORRESPONDING COMMUNICATION DEVICE AND COMPUTER PROGRAM
3y 2m to grant Granted Aug 04, 2026
Patent 12682280
IDENTIFYING OPTIMAL WEIGHTS TO IMPROVE PREDICTION ACCURACY IN MACHINE LEARNING TECHNIQUES
4y 1m to grant Granted Jul 14, 2026
Patent 12683953
MECHANISM FOR ENFORCING ACCESS CONTROL AT SCALE TO AN INTERNET SERVICE USING TRANSPORT LAYER SECURITY (TLS)
2y 0m to grant Granted Jul 14, 2026
Patent 12656394
MEMORY, MEMORY SYSTEM AND METHOD OF CONTROLLING STORAGE DEVICE
2y 9m to grant Granted Jun 16, 2026
Patent 12652192
Independent Datastore In A Network Routing Environment
3y 0m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
82%
With Interview (+3.1%)
2y 12m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 731 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month