Prosecution Insights
Last updated: August 08, 2026
Application No. 18/744,881

AUTOMATICALLY DETECTING AND MITIGATING RISKS ASSOCIATED WITH INSTALLING A SOFTWARE PACKAGE ON A COMPUTER SYSTEM

Non-Final OA §103
Filed
Jun 17, 2024
Examiner
DOAN, TAN
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Red Hat Inc.
OA Round
2 (Non-Final)
73%
Grant Probability
Favorable
2-3
OA Rounds
11m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
236 granted / 324 resolved
+14.8% vs TC avg
Strong +24% interview lift
Without
With
+24.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
20 currently pending
Career history
354
Total Applications
across all art units

Statute-Specific Performance

§101
11.4%
-28.6% vs TC avg
§103
58.0%
+18.0% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
14.1%
-25.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 324 resolved cases

Office Action

§103
DETAILED ACTION Response to Amendment Claims 1, 3-10, 12-17, and 19-23 are pending. Claims 2, 11, and 18 are canceled. Claims 21-23 are new. Response to Arguments Applicants’ arguments filed 04/27/2026 have been fully considered. The rejections of claims 1-20 under 35 U.S.C. 101 have been withdrawn in view of the amendment. Regarding the rejection of claim 1 under 35 U.S.C. 103 as being unpatentable over Wyatt et al. (US20130326477A1) in view of Jevans (US20160127367A1) and Mishra et al. (US20210216643A1), Applicants’ arguments are persuasive. In view of the amendment and after further search and consideration, claim 1 is rejected under new grounds of rejection as being unpatentable over Wyatt in view of Jevans and Shivanna et al. (US20220129561A1) as discussed below. As to any argument not specifically addressed, they are the same as those discussed above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 3-8, 10, 12-17, and 19-23 are rejected under 35 U.S.C. 103 as being unpatentable over Wyatt et al. (US20130326477A1) in view of Jevans (US20160127367A1) and Shivanna et al. (US20220129561A1). Regarding claim 1, Wyatt discloses a method comprising ([Abstract] shows detection of application security risks; para [0036] shows an owner of a mobile device may visit a marketplace 123 and select an application for remote installation on mobile device 147): receiving, by one or more processors (para [0010]), a request associated with installing a software package on a computing device (para [0036] shows an owner of a mobile device may visit a marketplace 123 and select an application for remote installation on mobile device 147), wherein the software package includes a plurality of software components ([Abstract] shows software applications composed of multiple components. Software applications are analyzed to determine their components and to identify the behaviors associated with each of the components; para [0110] shows static analysis may involve looking at the code inside of a component; para [0111] shows dynamic analysis may determine whether a component has a particular behavior); generating, by the one or more processors, a plurality of severity scores for the plurality of software components, each severity score of the plurality of severity scores corresponding to a respective software component of the plurality of software components and indicating a severity of one or more vulnerabilities associated with the respective software component (para [0110] shows static analysis may involve looking at the code inside of a component; para [0111] shows dynamic analysis may determine whether a component has a particular behavior; para [0138] shows a data repository storing component data for known components; para [0146] shows the component data includes risk scores for known components; para [0167] shows if the component is a newer version, the component needs to be reviewed again in order to update the database; para [0175] shows a component that has not been previously analyzed, unacceptable code is instead detected based on behavioral observation and component analysis; para [0174] shows a similarity score of known and new applications between zero to one may be used. A similarity score is returned from the server after analysis of a new application.) Wyatt discloses a component that has not been previously analyzed (para [0175]) but fails to show computing severity score for the software component. Specifically, Wyatt fails to disclose in response to receiving the request: computing, by the one or more processors, a plurality of severity scores for the plurality of software components; generating, by the one or more processors, a risk score for the software package based on the plurality of severity scores computed for the plurality of software components in the software package, the risk score representing an overall level of risk associated with installing the software package on the computing device; determining, by the one or more processors, that an alternative software component is correlated in a predefined mapping with a particular software component of the plurality of software components in the software package; determining, by the one or more processors, a first severity score for the particular software component, the first severity score being among the plurality of severity scores; determining, by the one or more processors, a second severity score for the alternative software component; comparing the first severity score for the particular software component in the software package to the second severity score for the alternative software component; and based on a result of the comparison of the first severity score to the second severity score, installing the software package with the alternative software component rather than the particular software component. However Jevans, in an analogous art (para [0098] shows the application risk control system 504 determines when the mobile device installs an application that poses a risk to the enterprise network 520 (or even possibly the mobile device 510); para [0054] shows the system 105 can perform static analyses, behavior analysis, and dynamic analyses), discloses: computing, by the one or more processors, a plurality of severity scores for the plurality of software components (para [0059] shows the system to calculate a component risk score); generating, by the one or more processors, a risk score for the software package based on the plurality of severity scores computed for the plurality of software components in the software package, the risk score representing an overall level of risk associated with installing the software package on the computing device (para [0059] shows the system to calculate a component risk score; para [0065] shows a combination or composite (risk) score may be determined that summarizes the component risk score; para [0080] shows calculating a risk score for the application. The general risk score can be a composite of these individual risk scores, selected combinations of the individual scores, weighted portions of individual scores, and combinations thereof). It would have been obvious to one of ordinary skill in the at the time the invention was effectively filed to modify the method of Wyatt with the teaching of Jevans in order to automatically remediate the application if the risk score for the application meets or exceeds a risk score threshold (Jevans; para [0081]). Wyatt-Jevans as combined fails to teach: determining, by the one or more processors, that an alternative software component is correlated in a predefined mapping with a particular software component of the plurality of software components in the software package; determining, by the one or more processors, a first severity score for the particular software component, the first severity score being among the plurality of severity scores; determining, by the one or more processors, a second severity score for the alternative software component; comparing the first severity score for the particular software component in the software package to the second severity score for the alternative software component; and based on a result of the comparison of the first severity score to the second severity score, installing the software package with the alternative software component rather than the particular software component. However Shivanna, in an analogous art (para [0010] shows a software product may have one or multiple software components), discloses: determining, by the one or more processors, that an alternative software component is correlated in a predefined mapping with a particular software component of the plurality of software components in the software package (para [0021] shows a list of all candidate software components to be potentially used in a particular software product; para [0043] shows an alternate software components that may be perhaps more secure and meet product specific needs); determining, by the one or more processors, a first severity score for the particular software component, the first severity score being among the plurality of severity scores; determining, by the one or more processors, a second severity score for the alternative software component; comparing the first severity score for the particular software component in the software package to the second severity score for the alternative software component; and based on a result of the comparison of the first severity score to the second severity score, install the software package with the alternative software component rather than the particular software component (para [0010] shows a software product may have one or multiple software components; para [0021] shows the risk assessment engine 134 receives a list of all candidate software components to be potentially used in a particular software product; para [0022] shows the risk assessment engine 134 determines risk scores for the corresponding software components on the list based on a trust score and a security score; para [0035] shows the recommendation engine 138 receives the overall risk score for the software component from the risk assessment engine 134, and provides a recommendation based on the overall risk score; para [0061] shows approval of the use (e.g., installation) of the software component may include risk mitigation controls.) It would have been obvious to one of ordinary skill in the at the time the invention was effectively filed to modify the method of Wyatt-Jevans with the teaching of Shivanna in order to approve of the use (e.g., installation) of the recommended software component that may include risk mitigation controls (Shivanna; para [0035, 0061]). Regarding claim 3, Wyatt-Jevans-Shivanna as applied to claim 1 discloses the alternative software component is a different version of the particular software component (Wyatt; para [0167] shows that the component in the new application is a newer version.) Regarding claim 4, Wyatt-Jevans-Shivanna as applied to claim 1 discloses the alternative software component is correlated to the particular software component in the predefined mapping based on functional similarities between the alternative software component and the particular software component (Wyatt; para [0167] shows a newer version or a tampered-version; para [0169] shows determining when component has changed behavior (i.e., the actual behavior is different from the known behavior stored in the component identity). A behavior change may also be associated with a code fingerprint having changed slightly; para [0176] shows components are analyzed with respect to similarity of previously known components. Behaviors can include any actions that can be taken by applications on the device.) Regarding claim 5, Wyatt-Jevans-Shivanna as applied to claim 1 discloses outputting a notification indicating at least one difference between the particular software component and the alternative software component (Wyatt; para [0176] shows components are analyzed with respect to similarity of previously known components. Behaviors can include any actions that can be taken by applications on the device; para [0067] shows the identified behaviors are presented to the user (e.g., in a list of scan results.)) Regarding claim 6, Wyatt-Jevans-Shivanna as applied to claim 1 discloses generating the risk score by: retrieving source code associated with the software package; generating a quality score associated with the software package by analyzing the source code; and generating the risk score based on the quality score (Wyatt; para [0110] shows static analysis may also be used that involve looking at the code inside of a component; para [0170] shows actual code that is itself may be asking for inappropriate behavior. Jevans; para [0068] shows applications will have different risk scores if their publisher reputation score does not meet or exceed a publisher reputation score threshold.) Regarding claim 7, Wyatt-Jevans-Shivanna as applied to claim 6 discloses the quality score is determined based on a performance metric associated with the source code (Wyatt; para [0110] shows static analysis may also be used that involve looking at the code inside of a component; para [0170] shows actual code that is itself may be asking for inappropriate behavior). Regarding claim 8, Wyatt-Jevans-Shivanna as applied to claim 6 discloses the quality score is determined based on a programming error identified within the source code (Wyatt; para [0110] shows static analysis may also be used that involve looking at the code inside of a component; para [0171] shows actual code that is itself may be asking for inappropriate behavior. Shivanna; para [0001] shows security vulnerabilities of the component may be identified; errors, or bugs, in the component may be identified). Regarding claims 10-16, claims 10-16 are directed to a computer-readable medium. Claims 10-16 require limitations that are similar to those recited in the method claims 1-7 to carry out the method steps. And since the references of Wyatt-Jevans-Shivanna combined teach the method including limitations required to carry out the method steps, therefore claims 10-16 would have also been obvious in view of the structures disclosed in Wyatt-Jevans-Shivanna combined. Furthermore, Wyatt-Jevans-Shivanna combined discloses computer-readable medium comprising program code that is executable by one or more processors for causing the one or more processors to perform operations (Wyatt; para [0011]). Regarding claims 17-20, claims 17-20 are directed to a system. Claims 17-20 require limitations that are similar to those recited in the method claims 1-4 to carry out the method steps. And since the references of Wyatt-Jevans-Shivanna combined teach the method including limitations required to carry out the method steps, therefore claims 17-20 would have also been obvious in view of the structures disclosed in Wyatt-Jevans-Shivanna combined. Furthermore, Wyatt-Jevans-Shivanna combined discloses one or more processors; and one or more memories including program code that is executable by the one or more processors for causing the one or more processors to perform operations (Wyatt; para [0011]). Regarding claim 21, Wyatt-Jevans-Shivanna as applied to claim 17 discloses a severity score of the plurality of severity scores is computed based on a likelihood that a vulnerability in a corresponding software component will be exploited (Wyatt; para [0173] shows a behavior has previously been determined to be acceptable (or to have a low risk score). Shivanna; para ]0001] shows security vulnerabilities of the component may be identified). Regarding claim 22, Wyatt-Jevans-Shivanna as applied to claim 17 discloses a severity score of the plurality of severity scores is computed based on a negative effect of a vulnerability in a corresponding software component (Shivanna; para [0026] shows information about the source software components such as known vulnerabilities and exposures that may be used by the risk assessment engine 134 to infer trust and/or security levels of the components; para [0022] shows the risk assessment engine 134 determines the overall risk score for a given software component based on a trust and a security score that represents a determined degree of security risk). Regarding claim 23, Wyatt-Jevans-Shivanna as applied to claim 17 discloses the operations further comprise: computing, based on the second severity score for the alternative software component, a modified risk score for a modified version of the software package that includes the alternative software component in place of the particular software component (Shivanna; para [0010] shows a software product may have one or multiple software components; para [0021] shows the risk assessment engine 134 receives a list of all candidate software components to be potentially used in a particular software product; para [0022] shows the risk assessment engine 134 determines risk scores for the corresponding software components on the list based on the features of the software component; para [0035] shows the recommendation engine 138 receives the overall risk score for the software component from the risk assessment engine 134, and provides a recommendation based on the overall risk score); and outputting a notification that includes the modified risk score for the modified version of the software package (Shivanna; para [0041] shows risk assessment engine 134 notifies product owners 290 of anticipated risks and recommended mitigations at regular intervals.) Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Wyatt in view of Jevans and Shivanna, further in view of Simanavicius et al. (US20220368621A1). Regarding claim 9, Wyatt-Jevans-Shivanna as applied to claim 1 fails to show the software package is an image file for deploying an application inside a container. However, Simanavicius discloses the software package is an image file for deploying an application inside a container ([Abstract] shows installing containerized applications; para [0193] shows a container image is a lightweight, standalone, executable package of software that includes everything needed to run an application.) It would have been obvious to one of ordinary skill in the at the time the invention was effectively filed to modify the method of Wyatt-Jevans- Mishra with the teaching of Simanavicius in order to install a lightweight, standalone, executable package of software that includes everything needed to run an application (Simanavicius; para [0193]). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAN DOAN whose telephone number is (571)270-0162. The examiner can normally be reached Monday - Friday 8am - 5pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie, can be reached at (571) 270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TAN DOAN/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Show 1 earlier event
Feb 19, 2026
Non-Final Rejection mailed — §103
Apr 27, 2026
Examiner Interview Summary
Apr 27, 2026
Applicant Interview (Telephonic)
Apr 29, 2026
Response Filed
Jun 17, 2026
Final Rejection mailed — §103
Jul 21, 2026
Applicant Interview (Telephonic)
Jul 21, 2026
Examiner Interview Summary
Jul 28, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695634
SECURE MULTI DISTRIBUTED LEDGER SYSTEM
3y 2m to grant Granted Jul 28, 2026
Patent 12689802
METHODS AND SYSTEMS FOR LOW LATENCY STREAMING
3y 4m to grant Granted Jul 21, 2026
Patent 12683786
DYNAMIC AND INTELLIGENT TOKEN-BASED RESOURCE EVENT FACILITATION NETWORK
2y 4m to grant Granted Jul 14, 2026
Patent 12670275
CONFIGURATION DATA PROTECTION
2y 4m to grant Granted Jun 30, 2026
Patent 12627574
SYSTEM AND METHOD FOR MANAGING COMPUTING DEVICES
3y 7m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
73%
Grant Probability
97%
With Interview (+24.2%)
3y 0m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 324 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month