Prosecution Insights
Last updated: October 02, 2026
Application No. 18/744,473

APPARATUS FOR DISTRIBUTED DENIAL OF SERVICE (DDOS) DETECTION AND MITIGATION

Non-Final OA §102§DOUBLEPATENT
Filed
Jun 14, 2024
Priority
May 05, 2022 — continuation of 12/052,280
Examiner
COULTER, KENNETH R
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Charter Communications Operating LLC
OA Round
3 (Non-Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
82%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
738 granted / 851 resolved
+28.7% vs TC avg
Minimal -5% lift
Without
With
+-4.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
15 currently pending
Career history
861
Total Applications
across all art units

Statute-Specific Performance

§101
19.3%
-20.7% vs TC avg
§103
18.1%
-21.9% vs TC avg
§102
39.9%
-0.1% vs TC avg
§112
10.0%
-30.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 851 resolved cases

Office Action

§102 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . After consultation, prosecution is hereby reopened in the present Application. Response to Arguments Applicant’s arguments with respect to the rejection claims 1, 14, 25, and 26 have been considered but are moot because of the new ground of rejection under 35 USC 103. The rejection of claims 1 – 31 under nonstatutory double patenting has not been addressed by Applicant. Applicant has deferred resolution of the double patenting rejection until patentable subject matter is agreed upon. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1 – 31 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 – 31 of U.S. Patent No. 12,052,280. Although the claims at issue are not identical, they are not patentably distinct from each other because of the mapping below. Claim 1 of the present Application maps to claim 1 of ‘280. 1. A method comprising: comparing, by a controller, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (“comparing, by the controller, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack”); and the controller initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (“the controller initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack”). Claim 2 of the present Application maps to claim 2 of ‘280. 2. The method of Claim 1, further comprising the controller determining, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing step further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer (“The method of claim 1, further comprising the controller determining, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing step further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer”). Claim 3 of the present Application maps to claim 3 of ‘280. 3. The method of Claim 2, wherein the controller determining, for the plurality of internet service provider customers, the projected bandwidth per customer comprises the controller determining the projected bandwidth per customer using machine learning (“The method of claim 2, wherein the controller determining, for the plurality of internet service provider customers, the projected bandwidth per customer comprises the controller determining the projected bandwidth per customer using machine learning”). Claim 4 of the present Application maps to claim 4 of ‘280. 4. The method of Claim 3, wherein the controller determining, for the plurality of internet service provider customers, the projected bandwidth per customer using machine learning comprises the controller carrying out inferencing with a trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data (“The method of claim 3, wherein the controller determining, for the plurality of internet service provider customers, the projected bandwidth per customer using the machine learning comprises the controller carrying out inferencing with a trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data”). Claim 5 of the present Application maps to claim 5 of ‘280. 5. The method of Claim 4, further comprising training the neural network on the historical data to project the bandwidth per customer (“The method of claim 4, further comprising training the neural network on the historical data to project the bandwidth per customer”). Claim 6 of the present Application maps to claim 6 of ‘280. 6. The method of Claim 5, further comprising updating the training of the neural network over time for those of the plurality of customers other than the at least one given customer putatively suffering from the distributed denial of service attack (“The method of claim 5, further comprising updating the training of the neural network over time for those of the plurality of customers other than the at least one given customer putatively suffering from the distributed denial of service attack”). Claim 7 of the present Application maps to claim 7 of ‘280. 7. The method of Claim 3, wherein the comparing step comprises determining that the at least one given customer putatively suffers from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount (“The method of claim 4, wherein the comparing step comprises determining that the at least one given customer putatively suffers from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount”). Claim 8 of the present Application maps to claim 8 of ‘280. 8. The method of Claim 7, wherein, in the comparing step, the additional applied amount is determined multiplicatively (“The method of claim 7, wherein, in the comparing step, the additional applied amount is determined multiplicatively”). Claim 9 of the present Application maps to claim 9 of ‘280. 9. The method of Claim 7, wherein, in the comparing step, the additional applied amount is determined additively (“The method of claim 7, wherein, in the comparing step, the additional applied amount is determined additively”). Claim 10 of the present Application maps to claim 10 of ‘280. 10. The method of Claim 7, wherein the at least one remedial action initiated by the controller comprises the controller pushing a configuration to a plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack (“The method of claim 7, wherein the at least one remedial action initiated by the controller comprises the controller pushing a configuration to the plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack”). Claim 11 of the present Application maps to claim 11 of ‘280. 11. The method of Claim 10, further comprising the plurality of peering entry points blocking the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration (“The method of claim 10, further comprising the plurality of peering entry points blocking the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration”). Claim 12 of the present Application maps to claim 12 of ‘280. 12. The method of Claim 10, wherein: the controller comprises a core logic module, a machine learning module coupled to the core logic module, and a configuration push module coupled to the core logic module; the machine learning module implements the trained neural network; the controller comparing, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer comprises the core logic module obtaining the assigned bandwidth per customer from the customer profile collector, the core logic module obtaining the currently used bandwidth per customer from the IP flows collector, the core logic module obtaining the projected bandwidth per customer from the machine learning module, and the core logic module comparing the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer; and the controller initiating the at least one remedial action comprises the configuration push module pushing the configuration (“The method of claim 10, wherein: the controller comprises a core logic module, an IP flows collector coupled to the core logic module, a customer profile collector coupled to the core logic module, a machine learning module coupled to the core logic module, and a configuration push module coupled to the core logic module; the controller obtaining the assigned bandwidth per customer for the plurality of internet service provider customers comprises the customer profile collector querying the at least one provisioning database; the machine learning module implements the trained neural network; the controller obtaining the currently used bandwidth per customer comprises the IP flows collector obtaining the currently used bandwidth per customer from the plurality of peering entry points of the internet service provider; the controller comparing, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer comprises the core logic module obtaining the assigned bandwidth per customer from the customer profile collector, the core logic module obtaining the currently used bandwidth per customer from the IP flows collector, the core logic module obtaining the projected bandwidth per customer from the machine learning module, and the core logic module comparing the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer; and the controller initiating the at least one remedial action comprises the configuration push module pushing the configuration”). Claim 13 of the present Application maps to claim 13 of ‘280. 13. The method of Claim 12, further comprising displaying, on a graphical user interface, data related to the putative distributed denial of service attack (“The method of claim 12, further comprising displaying, on a graphical user interface, data related to the putative distributed denial of service attack”). Claim 14 of the present Application maps to claim 14 of ‘280. 14. A system comprising: a memory (“A system comprising: a memory”); and at least one processor, coupled to the memory, and operative to (“and at least one processor, coupled to the memory, and operative to”): compare, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (“compare, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack”); and initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (“and initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack”). Claim 15 of the present Application maps to claim 15 of ‘280. 15. The system of Claim 14, wherein the at least processor is further operative to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer (“The system of claim 14, wherein the at least one processor is further operative to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer”). Claim 16 of the present Application maps to claim 16 of ‘280. 16. The system of Claim 15, wherein the at least processor is operative to determine, for the plurality of internet service provider customers, the projected bandwidth per customer using machine learning (“The system of claim 15, wherein the at least one processor is operative to determine, for the plurality of internet service provider customers, the projected bandwidth per customer using machine learning”). Claim 17 of the present Application maps to claim 17 of ‘280. 17. The system of Claim 16, wherein the at least processor implements a trained neural network, and wherein the at least one processor is operative to determine, for the plurality of internet service provider customers, the projected bandwidth per customer, using machine learning, by carrying out inferencing with the trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data (“The system of claim 16, wherein the at least one processor implements a trained neural network, and wherein the at least one processor is operative to determine, for the plurality of internet service provider customers, the projected bandwidth per customer, using the machine learning, by carrying out inferencing with the trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data”). Claim 18 of the present Application maps to claim 18 of ‘280. 18. The system of Claim 17, wherein the at least processor is further operative to train the neural network on the historical data to project the bandwidth per customer (“The system of claim 17, wherein the at least one processor is further operative to train the neural network on the historical data to project the bandwidth per customer”). Claim 19 of the present Application maps to claim 19 of ‘280. 19. The system of Claim 18, wherein the at least processor is further operative to update the training of the neural network over time for those of the plurality of customers other than the at least one given customer putatively suffering from the distributed denial of service attack (“The system of claim 18, wherein the at least one processor is further operative to update the training of the neural network over time for those of the plurality of customers other than the at least one given customer putatively suffering from the distributed denial of service attack”). Claim 20 of the present Application maps to claim 20 of ‘280. 20. The system of Claim 16, wherein the at least one processor is operative to determine that the at least one given customer putatively suffers from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount (“The system of claim 17, wherein the at least one processor is operative to determine that the at least one given customer putatively suffers from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount”). Claim 21 of the present Application maps to claim 21 of ‘280. 21. The system of Claim 20, wherein the at least one processor is operative to initiate the at least one remedial action by pushing a configuration to a plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack (“The system of claim 20, wherein the at least one processor is operative to initiate the at least one remedial action by pushing a configuration to the plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack”). Claim 22 of the present Application maps to claim 22 of ‘280. 22. The system of Claim 21, further comprising the plurality of peering entry points, wherein the plurality of peering entry points are configured to blocking the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration (“The system of claim 21, further comprising the plurality of peering entry points, wherein the plurality of peering entry points are configured to blocking the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration”). Claim 23 of the present Application maps to claim 23 of ‘280. 23. The system of Claim 21, wherein: the at least one processor is operative to instantiate a core logic module, a machine learning module coupled to the core logic module, and a configuration push module coupled to the core logic module; the controller comprises the core logic module, the machine learning module coupled to the core logic module, and the configuration push module coupled to the core logic module; the machine learning module implements the trained neural network; the controller comparing, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer comprises the core logic module obtaining the assigned bandwidth per customer from the customer profile collector, the core logic module obtaining the currently used bandwidth per customer from the IP flows collector, the core logic module obtaining the projected bandwidth per customer from the machine learning module, and the core logic module comparing the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer; and the controller initiating the at least one remedial action comprises the configuration push module pushing the configuration (“The system of claim 21, wherein: the at least one processor is operative to instantiate a core logic module, an IP flows collector coupled to the core logic module, a customer profile collector coupled to the core logic module, a machine learning module coupled to the core logic module, and a configuration push module coupled to the core logic module; a controller comprises the core logic module, the IP flows collector coupled to the core logic module, the customer profile collector coupled to the core logic module, the machine learning module coupled to the core logic module, and the configuration push module coupled to the core logic module; the controller obtaining the assigned bandwidth per customer for the plurality of internet service provider customers comprises the customer profile collector querying the at least one provisioning database; the machine learning module implements the trained neural network; the controller obtaining the currently used bandwidth per customer comprises the IP flows collector obtaining the currently used bandwidth per customer from the plurality of peering entry points of the internet service provider; the controller comparing, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer comprises the core logic module obtaining the assigned bandwidth per customer from the customer profile collector, the core logic module obtaining the currently used bandwidth per customer from the IP flows collector, the core logic module obtaining the projected bandwidth per customer from the machine learning module, and the core logic module comparing the assigned bandwidth per customer to the currently used bandwidth per customer and the currently used bandwidth per customer to the projected bandwidth per customer; and the controller initiating the at least one remedial action comprises the configuration push module pushing the configuration”). Claim 24 of the present Application maps to claim 24 of ‘280. 24. The system of Claim 23, wherein the at least one processor is further operative to cause display, on a graphical user interface, of data related to the putative distributed denial of service attack (“The system of claim 23, wherein the at least one processor is further operative to cause display, on a graphical user interface, of data related to the putative distributed denial of service attack”). Claim 25 of the present Application maps to claim 25 of ‘280. 25. A non-transitory computer readable medium comprising processor executable instructions which when executed by a processor cause the processor to perform the method of (“A non-transitory computer readable medium comprising processor executable instructions which when executed by a processor cause a processor to perform the method of”): comparing, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (“comparing, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack”); and initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (“initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack”). Claim 26 of the present Application maps to claim 26 of ‘280. 26. A hardware system comprising (“A system comprising”): a core logic module, configured to compare, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (“a core logic module, coupled to the customer profile collector and the IP flows collector, and configured to compare, for the plurality of internet service provider customers, the assigned bandwidth per customer to the currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack”); and a configuration push module, coupled to the core logic module, and configured to initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (“a configuration push module, coupled to the core logic module, and configured to initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack”). Claim 27 of the present Application maps to claim 27 of ‘280. 27. The system of Claim 26, further comprising: a machine learning module, implementing a trained neural network, coupled to the core logic module, and configured to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, by carrying out inferencing with the trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data (“The system of claim 26, further comprising: a machine learning module, implementing a trained neural network, coupled to the core logic module, and configured to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, by carrying out inferencing with the trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data”); wherein the core logic module is further configured to compare the currently used bandwidth per customer to the projected bandwidth per customer to determine the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (“wherein the core logic module is further configured to compare the currently used bandwidth per customer to the projected bandwidth per customer to determine the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack”). Claim 28 of the present Application maps to claim 28 of ‘280. 28. The system of Claim 27, wherein the core logic module is configured to determine the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount (“The system of claim 27, wherein the core logic module is configured to determine the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack when the currently used bandwidth per customer for the at least one given customer exceeds the projected bandwidth per customer for the at least one given customer and the currently used bandwidth per customer for the at least one given customer is at least equal to: the assigned bandwidth per customer for the at least one given customer; and an additional applied amount”). Claim 29 of the present Application maps to claim 29 of ‘280. 29. The system of Claim 28, wherein the configuration push module is configured to initiate the at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack by pushing a configuration to the plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack (“The system of claim 28, wherein the configuration push module is configured to initiate the at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack by pushing a configuration to the plurality of peering entry points to cause the plurality of peering entry points to block at least one of an IP address and a port associated with the putative distributed denial of service attack”). Claim 30 of the present Application maps to claim 30 of ‘280. 30. The system of Claim 29, further comprising the plurality of peering entry points, wherein the plurality of peering entry points are configured to block the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration (“The system of claim 29, further comprising the plurality of peering entry points, wherein the plurality of peering entry points are configured to block the at least one of an IP address and a port associated with the putative distributed denial of service attack in accordance with the pushed configuration”). Claim 31 of the present Application maps to claim 31 of ‘280 31. The system of Claim 30, further comprising a graphical user interface coupled to the core logic module and configured to display data related to the putative distributed denial of service attack (“The system of claim 30, further comprising a graphical user interface coupled to the core logic module and configured to display data related to the putative distributed denial of service attack”). Although the conflicting claims are not identical, they are not patentably distinct from each other because the scope of the claims of the patent encompasses that of the current application. The independent claims of the present Application are broader than the claim language in ‘280. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1 – 3, 14 – 16, and 25 – 27 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Edelstein et al. (U.S. Pat. No. 10,834,110) (Methods For Preventing DDoS Attack Based on Adaptive Self Learning of Session and Transport Layers and Devices Thereof) 2.1 Regarding claim 1, Edelstein disclose a method comprising: comparing, by a controller, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (Fig. 4, item 410; col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”); and the controller initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (Fig. 4, item 425; Abstract “A plurality of network traffic anomaly threshold values and a plurality of server health anomaly threshold values for the monitored session layer and the transport layer network traffic data are estimated … A mitigation action is initiated based on the determination”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4”). 2.2 Regarding claim 2, Edelstein disclose the method of Claim 1, further comprising the controller determining, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing step further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer (col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”). 2.3 Regarding claim 3, Edelstein disclose method of Claim 2, wherein the controller determining, for the plurality of internet service provider customers, the projected bandwidth per customer comprises the controller determining the projected bandwidth per customer using machine learning (col. 9, lines 42 – 64 “… estimated threshold values …”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4. In particular, first an example of a method for estimating threshold to detect anomalies in network traffic will now be illustrated with reference to FIG. 3”). 2.4 Regarding claim 14, Edelstein disclose a system comprising: a memory (Fig. 2, item 20; col. 3, lines 26 – 33); and at least one processor, coupled to the memory, and operative to (Fig. 2, item 18; col. 3, lines 26 – 33 “As illustrated in FIG. 2, the network traffic manager apparatus 14 includes processor or central processing unit (CPU) 18, memory 20, optional configurable hardware logic 21, and a communication system 24 which are coupled together by a bus device 26”): compare, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (Fig. 4, item 410; col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”); and initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (Fig. 4, item 425; Abstract “A plurality of network traffic anomaly threshold values and a plurality of server health anomaly threshold values for the monitored session layer and the transport layer network traffic data are estimated … A mitigation action is initiated based on the determination”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4”). 2.5 Regarding claim 15, Edelstein disclose the system of Claim 14, wherein the at least processor is further operative to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, wherein the comparing further comprises comparing the currently used bandwidth per customer to the projected bandwidth per customer (col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”). 2.6 Regarding claim 16, Edelstein disclose the system of Claim 15, wherein the at least processor is operative to determine, for the plurality of internet service provider customers, the projected bandwidth per customer using machine learning (col. 9, lines 42 – 64 “… estimated threshold values …”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4. In particular, first an example of a method for estimating threshold to detect anomalies in network traffic will now be illustrated with reference to FIG. 3”). 2.7 Regarding claim 25, Edelstein disclose a non-transitory computer readable medium comprising processor executable instructions which when executed by a processor cause the processor to perform the method of (Abstract “A method, non-transitory computer readable medium, and device includes monitoring a session layer and transport layer network traffic data received from a plurality of client computing devices and plurality of servers”): comparing, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (Fig. 4, item 410; col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”); and initiating at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (Fig. 4, item 425; Abstract “A plurality of network traffic anomaly threshold values and a plurality of server health anomaly threshold values for the monitored session layer and the transport layer network traffic data are estimated … A mitigation action is initiated based on the determination”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4”). 2.8 Regarding claim 26, Edelstein disclose a hardware system comprising (col. 4, lines 26 – 30 “The optional configurable hardware logic device 21 in the network traffic manager apparatus 14 may comprise specialized hardware configured to implement one or more steps of this technology as illustrated and described with reference to the examples herein”): a core logic module (col. 3, lines 36 – 46), configured to compare, for a plurality of internet service provider customers, assigned bandwidth per customer to currently used bandwidth per customer, to determine at least one given customer of the plurality of internet service provider customers putatively suffering from a distributed denial of service attack (Fig. 4, item 410; col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”); and a configuration push module (col. 4, lines 26 – 30), coupled to the core logic module, and configured to initiate at least one remedial action for the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (Fig. 4, item 425; Abstract “A plurality of network traffic anomaly threshold values and a plurality of server health anomaly threshold values for the monitored session layer and the transport layer network traffic data are estimated … A mitigation action is initiated based on the determination”; col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4”). 2.9 Regarding claim 27, Edelstein disclose the system of Claim 26, further comprising: a machine learning module, implementing a trained neural network, coupled to the core logic module, and configured to determine, for the plurality of internet service provider customers, a projected bandwidth per customer, by carrying out inferencing with the trained neural network, the trained neural network being trained on historical data to project the bandwidth per customer based on measured data (col. 9, lines 42 – 64 “Next in step 410, the network traffic manager apparatus 14 determines whether there is a network traffic anomaly based on the thresholds estimated to detect network traffic anomaly. In this example, the network traffic manager apparatus 14 compares the values of the reference attributes and the protocol attributes of the network traffic that is currently being monitored against the corresponding estimated thresholds values for each of the reference attributes and the protocol attributes to determine whether there is an anomaly in the network traffic, although the network traffic manager apparatus 14 can use other techniques to determine anomaly in network traffic”); wherein the core logic module is further configured to compare the currently used bandwidth per customer to the projected bandwidth per customer to determine the at least one given customer of the plurality of internet service provider customers putatively suffering from the distributed denial of service attack (col. 7, lines 47 – 52 “An example of a method detecting and preventing distributed denial of service (DDoS) attack based on an adaptive self-learning will now be described with reference to FIGS. 1-4”; col. 9, lines 42 – 64). For future email communications (including interview agendas), Applicant should file the appropriate PTO form (PTO/SB/439) or file an air interview request. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KENNETH R COULTER whose telephone number is (571) 272-3879. The examiner can normally be reached M-F, 9am-5pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie can be reached at M-H, 7:30am-2:30pm (EST) (571-270-1684). The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KENNETH R COULTER/Primary Examiner, Art Unit 2445 /KRC/
Read full office action

Prosecution Timeline

Show 3 earlier events
Oct 06, 2025
Applicant Interview (Telephonic)
Oct 07, 2025
Examiner Interview Summary
Jan 02, 2026
Final Rejection mailed — §102, §DOUBLEPATENT
May 01, 2026
Notice of Allowance
May 01, 2026
Response after Non-Final Action
May 21, 2026
Response after Non-Final Action
Jul 29, 2026
Non-Final Rejection (signed) — §102, §DOUBLEPATENT
Sep 10, 2026
Non-Final Rejection mailed — §102, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739175
ELECTRONIC DEVICE FOR MANAGING NETWORK DEVICE USING DIGITAL TWIN AND METHOD FOR OPERATING THE SAME
1y 10m to grant Granted Sep 15, 2026
Patent 12732854
METHOD AND APPARATUS FOR NOTIFYING CHANGE OF NETWORK SLICE IN WIRELESS COMMUNICATION SYSTEM
2y 6m to grant Granted Sep 08, 2026
Patent 12726440
2 LAYER ALPHA BASED BUFFER MANAGEMENT WITH DYNAMIC RED
3y 10m to grant Granted Sep 01, 2026
Patent 12726528
SUPPORT FOR SIMULTANEOUS EDGE APPLICATION SERVER (EAS) CONNECTIVITY IN APPLICATION CONTEXT RELOCATION (ACR)
2y 1m to grant Granted Sep 01, 2026
Patent 12720289
SERVICE PROVISION TO IoT DEVICES
2y 7m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
82%
With Interview (-4.7%)
3y 2m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 851 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month