Prosecution Insights
Last updated: October 02, 2026
Application No. 18/661,041

IDENTIFYING AND DISRUPTING CYBER-THREATS IN TELECOMMUNICATIONS NETWORKS

Final Rejection §103
Filed
May 10, 2024
Examiner
KINCAID, LESTER G
Art Unit
2649
Tech Center
2600 — Communications
Assignee
T-Mobile USA Inc.
OA Round
2 (Final)
62%
Grant Probability
Moderate
3-4
OA Rounds
3m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
47 granted / 76 resolved
At TC average
Moderate +8% lift
Without
With
+7.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
32 currently pending
Career history
110
Total Applications
across all art units

Statute-Specific Performance

§101
4.0%
-36.0% vs TC avg
§103
60.2%
+20.2% vs TC avg
§102
21.1%
-18.9% vs TC avg
§112
11.0%
-29.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 76 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 7/7/2026 have been fully considered but they are not persuasive. Applicant argues that because the prior art wants to add noise it precludes it from filtering the signal or removing noise before or afterwards which of course is as preposterous as it sounds. In other words the argument that the preposed combination would render the prior art invention inoperable for its intended purpose is not persuasive. As implied above, signals are routinely filtered thereby removing noise. Why wouldn’t one try to filter the signal at some point? In fact, filtering is likely built in to any mechanism one would use so to argue that the improving the quality of the signal would inhibit classification is nonsensical. Further, one can argue that adding noise is the same as subtracting noise as addition and subtraction are the same when negative or out of phase signals are considered, thereby also raising an issue of anticipation. Applicant further argues that Karta merely identifies but doesn’t remove noise. Examiner maintains that the “filtered set” of data packet information implies noise removal. See [0033]-[0037]. For example [0033]: “For example, the preprocessing classifier 300 may determine that data packets … are correlated with malicious activity. In some embodiments, the preprocessing classifier 300 accounts for data traffic characteristics and/or information from network nodes to filter out the data packet fields 315 correlated with malicious activity.” Thus Karta not only teaches noise removal using AI, Karta provides a reason as well Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claim(s) 1, 3-7, 10, 12-16, 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vandikas et al. (2022/0311784) hereinafter “Vandikas” and Karta et al. (2024/0114052) hereinafter “Karta”. As to claim 1, Vandikas discloses A computerized method comprising: generating a decoy node (protection node - 212) that mimics a particular node (pattern classification node - 222) in a telecommunications network (Fig 2), (see [0004], [0024]: “a protection node 212 that includes a honeypot server 216 that performs a first clone of the machine learning algorithm that resides at pattern classification node 222…)”; monitoring the decoy node in near real-time ([0004]: “The protection node may then obtain a first classification of the noisy pattern based on processing of the noisy pattern by the machine learning algorithm performed by the protection node”, [0034]: “At step 315, honeypot server 216 may make a first classification…); logging an interaction with the decoy node based on monitoring ([0004]: “The protection node may then compare the first and second classifications to determine whether the first and second classifications satisfy a defined similarity rule”), [0028]: “…protection node 212 also may be in communication with database 220 to store and/or collect information obtained from a request from user node 214 as discussed further below.”, [0036]: “At 321, the request dispatcher may compare the first and second classifications to determine whether the first and second classifications satisfy a defined similarity rule…”) ; based on the interaction, ([0004]: “use the comparison to manage the request”, [0036]: “By adding the identifier associated with user node 214 to the distrust list, requests from user node 214 sent toward pattern classification node 222 may be blocked or monitored…”) assigning a classification to the interaction, ([0038]: “… At 327, the request dispatcher may send an instruction to the load balancer to send second classification to user node…”); and generating and communicating a notification ([0008]: “when the first and second classifications do not satisfy the defined similarity rule, the protection node may protect the pattern classification node from malicious requests”, [0036]: “When… do not satisfy the defined similarity rule, the request dispatcher may send an instruction to database 218 to add the identifier associated with user node 214 to a distrust (list)”, [0037]: “At 325… may send an instruction to store the request in a log…”, [0038]: “At 327, the request dispatcher may send an instruction to the load balancer to send second classification to user node…”) that is specific to the classification in near real-time. Vandikas discloses wherein the interaction comprises a plurality of interactions (see [0050]: “…may repeat the receiving…”), is silent to yet in an analogous art Karta discloses the method further comprising removing noise from the plurality of interactions using a machine learning model, (see [0004],-[0005]: “A machine-learned model is trained with the training data set such that the model is configured to identify signal noise within one or more packet fields correlative to spoofed IP attacks and classify the identified signal noise as malicious or benign… producing a filtered set of data packet information”, [0024], [0033]-[0037]). Before the effective filing date of the instant invention it would have been obvious to one of ordinary skill in the art to modify Vandikas by further comprising removing noise from the plurality of interactions using a machine learning model as taught by Karta for the purpose of identifying “malicious signal noise”. As to claim 3, Vandikas and Karta discloses The method of claim 1, wherein the decoy node includes an imitation of a cybersecurity vulnerability. See [0024]: “…By including a clone of the machine language learning algorithm residing at pattern classification node 222 at honeypot server 216, protection node may mimic pattern classification node 222…” As to claim 4, Vandikas and Karta disclose The method of claim 1, further comprising, in response to assigning the classification to the interaction, revoking a service ([0021]: “…block the request…”) in the telecommunications network for a user account that is associated with the interaction, wherein the service that is revoked is (inherently) specific to the classification, and wherein the service comprises: data services, voice services, roaming services, streaming services, location services, or any combination thereof ([0033]:”… request may include an original pattern to be classified… an image, video frame, an audio sample, and a data stream…”). As to claim 5, Vandikas and Karta discloses The method of claim 1, further comprising, in response to assigning the classification to the interaction, revoking a service ([0021]: “…block the request…”) in the telecommunications network for a user device is associated with the interaction, wherein the service that is revoked is specific to the classification, and wherein the service comprises: data services, voice services, roaming services, streaming services, location services, or any combination thereof ([0033]:”… request may include an original pattern to be classified… an image, video frame, an audio sample, and a data stream…”). See [0028]: “… Protection node 212 also may be in communication with database 218 to store and/or collect an identifier associated with user node 214 to distrust list… ”. As to claim 6, Vandikas and Karta discloses The method of claim 1, wherein the interaction comprises a plurality of interactions, the method further comprising: identifying a pattern in the plurality of interactions, wherein the classification that is assigned is specific to the pattern identified. See [0021]: “…Since malicious requests may be recorded, they may be used in the background to efficiently improve and fortify the initial machine learning algorithm…”, [0025], [0035]-[0039], [0049]-[0050], etc. As to claim 7, Vandikas and Karta discloses The method of claim 6, wherein the pattern identified is indicative of an intelligent malicious entity (user node 214), and wherein the notification specifies that the plurality of interactions are predicted to be associated with the intelligent malicious entity (see [0036]: “When… do not satisfy the defined similarity rule, the request dispatcher may send an instruction to database 218 to add the identifier associated with user node 214 to a distrust (list)”, [0037]: “At 325… may send an instruction to store the request in a log…”,). As to claim 10, Vandikas and Karta discloses One or more non-transitory computer-readable media (730) storing instructions that when executed via one or more processors perform a computerized method, the instructions stored on the one or more non-transitory computer-readable media, as applied above to claim 1. Claims 12-16 correspond with method claims 3-7 respectively. As to claim 19, Vandikas and Karta discloses The media of claim 15, is silent to yet the examiner takes official notice that before the effective filing date of the instant invention it was well known in the art and would have been obvious for one of ordinary skill in the art to implement a network node as a plurality of network nodes, resulting in wherein the decoy node comprises a plurality of decoy nodes that are replications of a plurality of particular nodes in the telecommunications network. Vandikas discloses the instructions further comprising: training a machine learning model using interactions monitored for each decoy node; and subsequently monitoring each decoy node using the machine learning model to identify malicious attacks within the telecommunications network. See [0021], [0028], [0036], [0039], etc. As to claim 20, Vandikas and Karta discloses A system comprising: a [[plurality of]] decoy nodes 212 deployed in a telecommunications network, each decoy node in the plurality mimicking an actual node with an imitation of a cybersecurity vulnerability ([0024]: “protection node 212 may mimic pattern classification node 222”); a [[centralized]] monitoring system 216 deployed in the telecommunications network ; a [[centralized]] repository 218 associated with the centralized monitoring system deployed in the telecommunications network to store data that is associated with an interaction in near real-time (see [0028]); wherein the centralized monitoring system is configured perform as applied above to claim 1. The examiner takes official notice that before the effective filing date of the instant invention it was well known in the art and would have been obvious to one of ordinary skill in the art to design a system with one or a plurality of nodes and centralize or distribute equipment as seen fit by the designers. Claim(s) 2 and 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vandikas and Karta as applied to claim 1 above further in view of Murchison et al. (9686296) hereinafter “Murchison”. As to claim 2, Vandikas and Karta discloses The method of claim 1, is silent to yet in an analogous art Murchison discloses, wherein the decoy node mimics: a 5G user plane function (UPF) node; a Unified Data Repository (UDR)node; a Unified Data Management (UDM) node; a Secure Shell Daemon application (SSH daemon) node; an Authentication Server Function (AUSF) node; or any combination thereof. See col 11 lines 52-57. Before the effective filing date of the instant invention it would have been obvious to one of ordinary skill in the art to modify Vandikas wherein the decoy node mimics: a 5G user plane function (UPF) node; a Unified Data Repository (UDR)node; a Unified Data Management (UDM) node; a Secure Shell Daemon application (SSH daemon) node; an Authentication Server Function (AUSF) node; or any combination thereof as taught by Murchison for the purpose of conforming to the latest standards. It is noted that the BRI of the claim does not include a step of “mimicking” and therefore the limitation is considered an intended use not carrying patentable weight but was addressed for compact prosecution. Claim 11 corresponds with claim 2. Claim(s) 8 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vandikas and Karta further in view of Katta (2022/0417222). As to claim 8, Vandikas and Karta discloses The method of claim 6, is silent to yet in an analogous art Katta discloses wherein a pattern identified is indicative of a malicious bot (see [0004]: “…thereby preventing bots and/or malicious actors…”), and wherein the notification specifies that the plurality of interactions are predicted to be associated with the malicious [[bot]] (see [0036]: “When… do not satisfy the defined similarity rule, the request dispatcher may send an instruction to database 218 to add the identifier associated with user node 214 to a distrust (list)”, [0037]: “At 325… may send an instruction to store the request in a log…”,). Before the effective filing date of the instant invention it would have been obvious to one of ordinary skill in the art to modify Vandikas wherein a pattern identified is indicative of a malicious bot and wherein and the notification specifies that the plurality of interactions are predicted to be associated with the malicious bot, as taught by Katta for the purpose of identifying a bot as a malicious actor. Claim 17 corresponds with claim 8. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LESTER KINCAID whose telephone number is (571)272-7922. The examiner can normally be reached M-Th: 7-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yuwen Pan can be reached at 571-272-7855. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. LESTER G. KINCAID Primary Patent Examiner Art Unit 2649 /LESTER G KINCAID/Primary Examiner, Art Unit 2649
Read full office action

Prosecution Timeline

May 10, 2024
Application Filed
Apr 07, 2026
Non-Final Rejection mailed — §103
Jul 07, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750090
WIRELESS COMMUNICATION METHOD AND APPARATUS
3y 2m to grant Granted Sep 29, 2026
Patent 12744584
MANAGEMENT OF CONNECTION REQUESTS BASED ON SERVICES LOADED ON SATELLITES
2y 10m to grant Granted Sep 22, 2026
Patent 12739595
METHOD FOR TRANSMITTING REQUEST TO EXTERNAL DEVICE, AND ELECTRONIC DEVICE SUPPORTING SAME
3y 9m to grant Granted Sep 15, 2026
Patent 12739606
METHODS AND ARRANGEMENTS FOR EMERGENCY NOTIFICATION
3y 5m to grant Granted Sep 15, 2026
Patent 12739790
METHOD AND APPARATUS FOR PAGING REJECTION RESPONSE, AND COMMUNICATION DEVICE
2y 10m to grant Granted Sep 15, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
62%
Grant Probability
70%
With Interview (+7.7%)
2y 8m (~3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 76 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month