Prosecution Insights
Last updated: August 17, 2026
Application No. 18/642,058

KERNEL-BASED THREAD TERMINATION DETECTION

Final Rejection §103
Filed
Apr 22, 2024
Priority
Apr 24, 2023 — provisional 63/461,405
Examiner
DHARIA, RUPAL
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
SOPHOS Limited
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
16 granted / 21 resolved
+18.2% vs TC avg
Minimal -3% lift
Without
With
+-3.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 3m
Avg Prosecution
7 currently pending
Career history
39
Total Applications
across all art units

Statute-Specific Performance

§101
10.1%
-29.9% vs TC avg
§103
46.5%
+6.5% vs TC avg
§102
14.0%
-26.0% vs TC avg
§112
16.3%
-23.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 21 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments, see page 5, filed 12/11/2025, with respect to 35 U.S.C. § 112(b) rejection of claims 2, 3, 10, and 11 have been fully considered and are persuasive. The 35 U.S.C. § 112(b) of claims 2, 3, 10, and 11 has been withdrawn. Applicant’s arguments, see pages 6-7, filed 12/11/2025, with respect to the rejection(s) of claim(s) 1-16 under 35 U.S.C. § 102 in view of Diehl (US 2019/0205533) have been fully considered and are persuasive. Diehl does not disclose matching a process identifier of a process owning a thread. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Balaoura “Process Injection Techniques and Detection using Volatility Framework” (published 2018) and Diehl (US 2019/0205533). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6-12, and 14-16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Balaoura “Process Injection Techniques and Detection using the Volatility Framework” (published 2018), in view of Diehl et al., US Patent Application Publication No. 20190205533 A1 (hereinafter Diehl). As to claims 1 and 9, Balaoura discloses a machine/method comprising: A system for detecting kernel-based thread termination activity, the system comprising: one or more computer-readable media having computer-executable instructions stored thereon; and (see Balaoura § 2.4 Testing Environment) one or more processors that, having executed the computer-executable instructions, are configured to execute a security agent that: (see Balaoura § 1.2 The Volatility Framework) detects thread open handle events received in detects process object reference events occurring in the operating system kernel, (“Sysinternals Livekd on the testing environment (Win10 Build 14393) to debug the Windows kernel [59].” Balaoura § 3.3) each process object reference event associated with a thread termination tag; (“Process ID…” and “Thread Exit Date and Time” See data fields in Balaoura § 3.3) matches a process identifier contained in one or more thread open handle events to a process identifier contained in one or more process object reference events; (See Balaoura Fig. 34 steps “Is this handle created from a different process than the one that created the thread?”) determines that the matching events are indicative of malware activity on the endpoint computing device when the process identifier in the thread open handle events is different than a process identifier of a process that owns a thread associated with the thread open handle events; and (See Balaoura Fig. 34 steps “Is this handle created from a different process than the one that created the thread?” and “Display Suspicious DLL, thread, handle information”) Balaoura does not disclose: Callbacks initiates a malware remediation process based at least in part on the matching events being indicative of malware activity on the endpoint computing device. Diehl discloses: one or more computer-readable media having computer-executable instructions stored thereon; and one or more processors that, having executed the computer-executable instructions (Diehl [0023], e.g., systems and devices comprising one or more processors and one or more memories, as well as non-transitory computer-readable media storing computer-executable instructions), are configured to execute a security agent that: (Diehl [0048], e.g., the user-level security agent 116 is executed in a user mode and the kernel-level security agent 118 is executed in a kernel mode). detect thread open handle events received in callbacks from an operating system kernel on an endpoint computing device ([0044], e.g., For example, at least some of the components 122, 128 may include user and kernel mode “collectors” that receive notifications log files or memory locations. See also Callback registration in Diehl [0154] and trace functionality in Diehl [0053]); detect process object reference events occurring in the operating system kernel (Diehl [0044], e.g., For example, at least some of the components 122, 128 may include “collectors” that receive notifications of semantically-interesting events), each process object reference event associated with a thread termination tag (Diehl [0077], e.g., data 206 may also be serialized as serialized data to create the message); matches a process identifier contained in one or more thread open handle events to a process identifier contained in one or more process object reference events ([0080], e.g., two different ports 208 (e.g., the ports 208(1) and 208(2), with corresponding different port identifiers) can generate overlapping message identifiers with respect to each other, and, likewise, a pair of endpoints 122 on a single port 208 (one endpoint 122 being in user mode 202, and the other endpoint 128 being in kernel mode 204) can generate overlapping message identifiers with respect to each other); … initiate a malware remediation process based at least in part on the matching events being indicative of malware activity on the endpoint computing device (Diehl [0142], e.g., Block 614 can provide a validation response corresponding with an event associated with a process. Block 706 can terminate or quarantine that process. See also Diehl [0036 and 0156]). A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Balaoura with Diehl by utilizing the user/kernel mode monitoring system of Diehl and performing remediation in real time to detected malicious software. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Balaoura with Diehl in order to provide security components that terminate malicious processes and improve the security of the system while being portable between operating systems, thereby reducing code maintenance costs and increasing versatility of the security components, Diehl [0017-0018] and Balaoura § 3.7 “Future Improvements”. Regarding claims 2 and 10, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein the security agent executes in a user space of the operating system (Diehl [0048], e.g., the user-level security agent 116 is executed in a user mode) and the kernel executes in a system space of the operating system (Diehl [0048], e.g., while the kernel-level security agent 118 is executed in a kernel mode). Regarding claims 3 and 11, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein the security agent uses an operating system trace function to monitor the process object reference events occurring in the operating system kernel (Diehl [0053], e.g., the first endpoint component 212 in the kernel mode 204 can be communicated to a second endpoint component 214 (which can represent a component 122) in the user mode 202, a communications port 208, such as the communications port 208(2), is opened and connected by the bridge component 104). Regarding claims 4 and 12, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein the thread open handle events are received by a driver in the operating system kernel via a callback function when the operating system receives a request for a thread open handle operation with terminate access (“the time interval (in sec, before DLL load time) during which it is being searched for starting threads. This is used to correlate the DLLs with threads that possibly loaded them. The default value is 10 seconds.” Balaoura p. 36. Diehl [0044], e.g., For example, at least some of the components 122, 128 may include user and kernel mode “collectors” that receive notifications log files or memory locations. See also Callback registration in Diehl [0154]) Claims 5 and 13 are canceled. Regarding claims 6 and 14, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein the one or more processors are further configured to determine that the matching events are indicative of malware activity when an executive thread pointer in the thread open handle event is the same as an executive thread pointer in the process object reference event (See Balaoura Fig. 34 steps “Is this handle created from a different process than the one that created the thread?”. “the time interval (in sec, before DLL load time) during which it is being searched for starting threads. This is used to correlate the DLLs with threads that possibly loaded them. The default value is 10 seconds.” Balaoura p. 36) Regarding claims 7 and 15, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein initiating a malware remediation process comprises transmitting a message comprising a notification of the malware activity (Diehl [0156], e.g., Operations of technique 1000 can be performed by at least one computing device 102, 110, e.g., using architecture 900. In some examples, one or more non-transitory computer-readable media, e.g., computer-readable memory 112, have thereon computer-executable instructions that, upon execution by one or more processors 106, cause the one or more processors 106 to perform a method of detecting malicious activity on a computing device 102, 110) to a remote computing device (Diehl [0036], e.g., In some embodiments, the other computing device(s) 110 can represent a remote security system, such as a security system implemented in the “Cloud” on a set of remotely located devices that provide security services to the computing device 102.). Regarding claims 8 and 16, Balaoura with Diehl discloses the system/method of claims 1 and 9 and further discloses: wherein initiating a malware remediation process comprises scanning a list of processes executing in a user space of the operating system to identify one or more processes that are known or suspected to be associated with malware. (“the time interval (in sec, before DLL load time) during which it is being searched for starting threads. This is used to correlate the DLLs with threads that possibly loaded them. The default value is 10 seconds.” Balaoura p. 36. “The analysis of data captured from hard disk is also called disk forensics. Volatile media, that is the main memory or RAM (Random Access Memory) contain information about each running process and thread, open files, deleted files, Windows registry keys and event logs” Balaoura p. 1) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US Patent Pub 2021/0218759 to Ahmed, which discloses the process from the kernel being examined for malicious events being comparing against an list see Fig. 5 & Par. 006-0010 & Par. 0014 & Par. 0058. US Patent 8065728 to Wang, which discloses the kernel events of OS being examined for malware via comparing policies and blacklisted process see Abstract & Col 9 Ln 40-54 & Col 2 Ln 14-61. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RUPAL DHARIA whose telephone number is (571)272-3880. The examiner can normally be reached Monday-Friday 6am-3pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Apr 22, 2024
Application Filed
Sep 11, 2025
Non-Final Rejection mailed — §103
Dec 05, 2025
Examiner Interview Summary
Dec 05, 2025
Applicant Interview (Telephonic)
Dec 11, 2025
Response Filed
Aug 05, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 9338111
Electronic Message Recipient Handling System and Method with Media Component and Header Information Separation
1y 4m to grant Granted May 10, 2016
Patent 9313155
Electronic Message Send Device Handling System and Method with Separation of Message Content and Header Information
1y 3m to grant Granted Apr 12, 2016
Patent 9313156
Electronic Message Send Device Handling System and Method with Separated Display and Transmission of Message Content and Header Information
1y 3m to grant Granted Apr 12, 2016
Patent 9313157
ELECTRONIC MESSAGE RECIPIENT HANDLING SYSTEM AND METHOD WITH SEPARATION OF MESSAGE CONTENT AND HEADER INFORMATION
1y 3m to grant Granted Apr 12, 2016
Patent 9306885
Electronic Message Send Device Handling System and Method with Media Component and Header Information Separation
1y 3m to grant Granted Apr 05, 2016
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
73%
With Interview (-3.3%)
2y 3m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 21 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month