Prosecution Insights
Last updated: October 02, 2026
Application No. 18/677,591

PROTECTING DATABASE AGAINST POTENTIALLY HARMFUL QUERIES

Non-Final OA §102§103
Filed
May 29, 2024
Examiner
CHBOUKI, TAREK
Art Unit
2165
Tech Center
2100 — Computer Architecture & Software
Assignee
Rubrik Inc.
OA Round
3 (Non-Final)
81%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
700 granted / 862 resolved
+26.2% vs TC avg
Strong +24% interview lift
Without
With
+24.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
15 currently pending
Career history
886
Total Applications
across all art units

Statute-Specific Performance

§101
9.2%
-30.8% vs TC avg
§103
53.4%
+13.4% vs TC avg
§102
12.8%
-27.2% vs TC avg
§112
8.6%
-31.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 862 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/01/2026 has been entered. Response to Amendment This Office action has been issued in response to amendment filed on 07/01/2026. Claims 1-11 and 13- 21 are pending. Applicants' arguments have been carefully and respectfully considered. Response to Arguments Applicant arguments were fully considered and are mood in view of the new ground of rejection. Allowable Subject Matter Claims 5 and 18 are objected to as being dependent upon a rejected base claim but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 3-4, 11, 13-14, 16-17 and 20-21 are rejected under 35 U.S.C. 102(a)(1)as being anticipated by Stephen Sheldon (hereinafter Sheldon) US Publication 20190354622. As per claim 1, Sheldon teaches: A method, comprising: comparing, by a query execution module prior to execution of an incoming first query, a first fingerprint associated with the incoming first query to a plurality of fingerprints stored in a fingerprint database, wherein the incoming first query is to interact with a database, and wherein the plurality of fingerprints stored in the fingerprint database correspond to one or more respective queries that are associated with an execution restriction by the database based at least in part on a set of execution details stored with respective fingerprints of the plurality of fingerprints; (Fig. 2A-B and paragraphs [0011], [0016], [0018]-[0020], [0032], [0035], [0037], [0060] and [0063], wherein receiving a request for execution of a query transmitted by a client is the incoming query) and controlling the execution of the incoming first query by selectively allowing or blocking execution of the incoming first query based at least in part on whether the first fingerprint has a corresponding matching fingerprint to at least one of the plurality of fingerprints stored in the fingerprint database. (Fig. 2A-B and paragraphs [0011], [0016], [0018]-[0020], [0032], [0035], [0037], [0060] and [0063]) As per claim 3, Sheldon teaches: The method of claim 1, wherein controlling the execution of the incoming first query comprises: running the incoming first query based at least in part on the first fingerprint lacking a matching fingerprint to at least one of the plurality of fingerprints stored in the fingerprint database. (Fig. 2A-B and paragraphs [0011], [0016], [0018]-[0020], [0035], [0037] and [0060]) As per claim 4, Sheldon teaches: The method of claim 3, further comprising: adding the first fingerprint to the plurality of fingerprints stored in the fingerprint database based at least in part on a first instance of a run time of the incoming first query exceeding a threshold run time; (Abstract and paragraphs [0008], [0012], [0022], [0028], [0032] and [0065]) and releasing the first fingerprint from the plurality of fingerprints stored in the fingerprint database based at least in part on an expiration of a timeout duration associated with the first fingerprint. (Paragraphs [0002], [0008] and [0070]-[0074]) As per claim 13, Sheldon teaches: The method of claim 1, wherein the incoming first query comprises a structured query language (SQL) query within code that sends the incoming first query to the query execution module. (Fig. 2A-B and paragraphs [0011], [0016], [0018]-[0020], [0035], [0037] and [0060], wherein the query is database query) Claims 14 and 16-17 are apparatus claims respectively corresponding to method claims 1 and 3-4 and they are rejected under the same rational as claims 1 and 3-4. Claim 20 is a non-transitory computer-readable medium claim corresponding to method claim 1 and it is rejected under the same rational as claim 1. As per claim 21, Sheldon teaches: The method of claim 1, wherein the first fingerprint comprises a unique identifier associated with the incoming first query. (Paragraphs [0022]) Claims 2 and 15 are rejected under 35 U.S.C. 103(a) as being unpatentable over Sheldon in view of Udo Klein (hereinafter Klein) US Publication No. 20200097587. As per claim 2, Sheldon teaches blocking query from executing but does not explicitly teach killing the execution of the first query based at least in part on the first fingerprint having a matching fingerprint to at least one of the plurality of fingerprints stored in the fingerprint database, wherein the corresponding matching fingerprint is indicative of a blocked query, however in analogous art of query management, Klein teaches: killing the execution of the first incoming query based at least in part on the first fingerprint having a matching fingerprint to at least one of the plurality of fingerprints stored in the fingerprint database, wherein the corresponding matching fingerprint is indicative of a blocked query. (Paragraphs [0036], [0052] and [0083]) Therefore, it would have been obvious to a person in the ordinary skill in the art at the time of the filling of the invention to combine Sheldon and Klein by incorporating the teaching of Klein into the method of Sheldon. One having ordinary skill in the art would have found it motivated to use the query management of Klein into the system of Sheldon for the purpose of protecting database against malicious query. Claim 15 is an apparatus claim corresponding to method claim 2 and it is rejected under the same rational as claim 2. Claims 6 and 19 are rejected under 35 U.S.C. 103(a) as being unpatentable over Sheldon in view of Woodward et al (hereinafter Woodward) US Publication No. 20240427876. As per claim 6, Sheldon does not explicitly teach running the first query based at least in part on the first query being associated with a hint that overrides a block of the first query, however in analogous art of query management, Woodward teaches: running the first query based at least in part on the first query being associated with a hint that overrides a block of the first query. (Paragraph [0061]) Therefore, it would have been obvious to a person in the ordinary skill in the art at the time of the filling of the invention to combine Sheldon and Woodward by incorporating the teaching of Woodward into the method of Sheldon. One having ordinary skill in the art would have found it motivated to use the query management of Woodward into the system of Sheldon for the purpose of identifying query execution vulnerability. Claim 19 is an apparatus claim corresponding to method claim 6 and it is rejected under the same rational as claim 6. Claims 7-9 are rejected under 35 U.S.C. 103(a) as being unpatentable over Sheldon in view of Singh et al (hereinafter Singh) US Publication No. 20230342356. As per claim 7, Sheldon do not explicitly teach running the first query based at least in part on the first query lacking a threshold quantity of statistical similarities to one or more second queries that have corresponding matching fingerprints to at least one of the plurality of fingerprints stored in the fingerprint database, however in analogous art of query management, Singh teaches: running the first query based at least in part on the first query lacking a threshold quantity of statistical similarities to one or more second queries that have corresponding matching fingerprints to at least one of the plurality of fingerprints stored in the fingerprint database. (Paragraphs [0003], [0051], [0066] and [0072]-[0075]) Therefore, it would have been obvious to a person in the ordinary skill in the art at the time of the filling of the invention to combine Sheldon and Singh by incorporating the teaching of Singh into the method of Sheldon. One having ordinary skill in the art would have found it motivated to use the query management of Singh into the system of Sheldon for the purpose of quantifying similarity of queries and managing there execution accordingly. As per claim 8, Sheldon do not explicitly teach killing the execution of the first query based at least in part on the first query having a threshold quantity of statistical similarities to one or more second queries that have corresponding matching fingerprints to at least one of the plurality of fingerprints stored in the fingerprint database, however in analogous art of query management, Singh teaches: killing the execution of the first query based at least in part on the first query having a threshold quantity of statistical similarities to one or more second queries that have corresponding matching fingerprints to at least one of the plurality of fingerprints stored in the fingerprint database. (Paragraphs [0051]-[0055], wherein preventing the stalling of the query ) Therefore, it would have been obvious to a person in the ordinary skill in the art at the time of the filling of the invention to combine Sheldon and Singh by incorporating the teaching of Singh into the method of Sheldon. One having ordinary skill in the art would have found it motivated to use the query management of Singh into the system of Sheldon for the purpose of managing query execution based on workload criteria and managing there execution accordingly. As per claim 9, Sheldon and Singh teach: The method of claim 8, wherein killing the execution of the first query further comprises: killing the execution of the first query based at least in part on a database load associated with query execution of the database exceeding a load threshold. (Paragraphs [0051]-[0055], wherein preventing the stalling of the query )(Singh) Claims 10-11 are rejected under 35 U.S.C. 103(a) as being unpatentable over Sheldon in view of Srinivasan et al (hereinafter Srinivasan) US Publication No. 20250086175. As per claim 10, Sheldon do not explicitly teach wherein the fingerprint database stores the plurality of fingerprints and corresponding metadata associated with the plurality of fingerprints, however in analogous art of query execution, Srinivasan teaches: fingerprint database stores the plurality of fingerprints and corresponding metadata associated with the plurality of fingerprints. (Paragraph [0073]) Therefore, it would have been obvious to a person in the ordinary skill in the art at the time of the filling of the invention to combine Sheldon and Srinivasan by incorporating the teaching of Srinivasan into the method of Sheldon. One having ordinary skill in the art would have found it motivated to use the query management of Srinivasan into the system of Sheldon for the purpose of monitoring query execution. As per claim 11, Sheldon and Srinivasan teach: The method of claim 10, wherein the corresponding metadata associated with the plurality of fingerprints comprises a quantity of attempted executions for a respective query, time data for a duration of time taken to execute the respective query, a quantity of returned errors for the respective query, one or more indications of whether the respective query is internally blocked, externally blocked, or both, a quantity of timeouts associated with the respective query, or any combination thereof. (Paragraphs [0070] and [0072])( Sheldon) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Tarek Chbouki whose telephone number is 571-2703154. The examiner can normally be reached on Mon-Fri 7:30 am to 5:00 pm EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner s supervisor, Kerzhner, Aleksandr can be reached at 5712702760. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TAREK CHBOUKI/Primary Examiner, Art Unit 2165 8/28/2026
Read full office action

Prosecution Timeline

Show 1 earlier event
Oct 24, 2025
Non-Final Rejection mailed — §102, §103
Jan 26, 2026
Response Filed
Apr 01, 2026
Final Rejection mailed — §102, §103
May 13, 2026
Applicant Interview (Telephonic)
May 13, 2026
Examiner Interview Summary
Jul 01, 2026
Request for Continued Examination
Jul 02, 2026
Response after Non-Final Action
Sep 01, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12742650
REAL-TIME ROUTE CONFIGURING OF ENTERTAINMENT CONTENT
1y 9m to grant Granted Sep 22, 2026
Patent 12737366
Content Analysis System and Method
3y 7m to grant Granted Sep 15, 2026
Patent 12737350
METRICS AND EVENTS INFRASTRUCTURE
1y 10m to grant Granted Sep 15, 2026
Patent 12732389
METHODS AND SYSTEMS FOR COMPRESSING TRANSACTION IDENTIFIERS
3y 3m to grant Granted Sep 08, 2026
Patent 12718114
SYSTEM AND METHOD OF MANAGING KNOWLEDGE FOR KNOWLEDGE GRAPHS
3y 12m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
81%
Grant Probability
99%
With Interview (+24.0%)
3y 2m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 862 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month