Prosecution Insights
Last updated: October 02, 2026
Application No. 18/757,996

ACTIVE THREAT RESPONSE WITH HOST ISOLATION

Final Rejection §102§103
Filed
Jun 28, 2024
Examiner
PARSONS, THEODORE C
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
SOPHOS Limited
OA Round
2 (Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
369 granted / 470 resolved
+20.5% vs TC avg
Strong +21% interview lift
Without
With
+21.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
14 currently pending
Career history
485
Total Applications
across all art units

Statute-Specific Performance

§101
6.7%
-33.3% vs TC avg
§103
39.7%
-0.3% vs TC avg
§102
30.2%
-9.8% vs TC avg
§112
17.5%
-22.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 470 resolved cases

Office Action

§102 §103
DETAILED ACTION Response to Amendment The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is in reply to papers filed on 2025-10-23. Claims 1, 3-4, 6-11, 13-14, 16-25 are pending, following Applicant's cancellation of claims 2, 5, 12, 15, and addition of new claims 22-25. Claims 1, 11, 21 is/are independent. The objections to informalities in the claims are withdrawn in view of Applicant’s amendments. The rejection(s) of claims under 35 U.S.C. § 101 are withdrawn in view of Applicant’s amendments. The rejection(s) of claims on double patenting grounds are withdrawn in view of Applicant’s amendments. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Response to Arguments Applicant’s arguments have been fully considered but are moot in view of the new ground(s) of rejection. With respect to claim(s) 1 (see page(s) 3-4 of Applicant’s Remarks), Applicant argues that the prior art of record (in particular, European Patent 3544258 to Nimmagadda et al. (hereinafter "Nimmagadda '258")) does not disclose an agent on each switch and Wi-Fi access point of the entire network. However, the claim does not require both switches and access points. Use of the word "or" means that agents on either switches or access points is sufficient. Compare claim 22. U.S. Publication 20170289191 to Thioux al. (hereinafter "Thioux '191") discloses putting security agents on switches [Thioux '191 ¶ 0344, 0346, 0349, 0356, 0055, 0156]. As detailed in the rejections below, this feature of the claim(s) would have been obvious over Nimmagadda '258 in view of Thioux '191. With respect to claim(s) 1 (see page(s) 3-4 of Applicant’s Remarks), Applicant argues that the prior art of record (in particular, Nimmagadda '258) does not disclose the claimed notification and pull distribution of updates. However, U.S. Publication 20020194495 to Gladstone et al. (hereinafter "Gladstone '495") discloses agents downloading configuration changes [Gladstone '495 ¶ 0044, 0047, 0038] while Nimmagadda '258 discloses sending information to agents indicating that the configuration Is changing [Nimmagadda '258 ¶ 0092-0093; Fig. 1D; Fig. 5 at 550, 570]. As detailed in the rejections below, this feature of the claim(s) would have been obvious over Nimmagadda '258 in view of Gladstone '495. With respect to claim(s) 1 (see page(s) 3-4 of Applicant’s Remarks), Applicant argues that the prior art of record (in particular, Nimmagadda '258) does not disclose managing the entire network via agents. However, the claim does not require a multi-segment network, nor a diversity of vendors of network equipment. Thus, Nimmagadda '258 satisfies the claim with regard to managing a network using agents. Applicant's argument is unpersuasive. With respect to claim(s) 22, Examiner notes that U.S. Publication 20200162904 to Jiang et al. (hereinafter "Jiang '904") discloses installing security agents on Wi-Fi access points [Jiang '904 ¶ 0019-0020, 0023]. As detailed in the rejections below, this feature of the claim(s) would have been obvious over Nimmagadda '258 in view of Jiang '904. The same applies to claims 23-25 mutadis mutandis. Applicant’s arguments with respect to the remaining claim(s) is/are based on Applicant’s arguments with respect to claim(s) 1 and have been considered as detailed above. Summary of Claim Rejections under 35 U.S.C. § 103 The following table summarizes the rejections set forth in detail below of the claims over the prior art. Claim No. Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Spisak '319 Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Thomas '719 Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Official Notice Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Jiang '904 1 [Wingdings font/0xFC] 3 [Wingdings font/0xFC] 4 [Wingdings font/0xFC] 6 [Wingdings font/0xFC] 7 [Wingdings font/0xFC] 8 [Wingdings font/0xFC] 9 [Wingdings font/0xFC] 10 [Wingdings font/0xFC] 11 [Wingdings font/0xFC] 13 [Wingdings font/0xFC] 14 [Wingdings font/0xFC] 16 [Wingdings font/0xFC] 17 [Wingdings font/0xFC] 18 [Wingdings font/0xFC] 19 [Wingdings font/0xFC] 20 [Wingdings font/0xFC] 21 [Wingdings font/0xFC] 22 [Wingdings font/0xFC] 23 [Wingdings font/0xFC] 24 [Wingdings font/0xFC] 25 [Wingdings font/0xFC] Claim Rejections - 35 U.S.C. § 103 The following is a quotation of the appropriate paragraphs of AIA 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of AIA 35 U.S.C. 103 that forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. § 103(a) are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1, 3-4, 6, 7, 11-14, 16, 17, 21 is/are rejected under 35 U.S.C. § 103 as being unpatentable over European Patent 3544258 to Nimmagadda et al. (hereinafter "Nimmagadda '258") in view of U.S. Publication 20020194495 to Gladstone et al. (hereinafter "Gladstone '495") in view of U.S. Publication 20170289191 to Thioux al. (hereinafter "Thioux '191"). Nimmagadda '258 is prior art to the claims under 35 U.S.C. § 102(a)(1). Gladstone '495 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Thioux '191 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Per claim 1 (independent): Nimmagadda '258 discloses a method for responding to a threat with host isolation (isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078]) Nimmagadda '258 discloses receiving, by one or more processors of a threat management computer system, endpoint health information for a plurality of endpoints of a monitored network system managed by the threat management computer system (identifies threats from threat information concerning endpoints [Nimmagadda '258 ¶ 0013, 0081-0083]) Nimmagadda '258 discloses identifying, by the one or more processors of the threat management computer system, a threat associated with the monitored network system (identifies threats from threat information concerning endpoints [Nimmagadda '258 ¶ 0013, 0081-0083]) Nimmagadda '258 discloses identifying, by the one or more processors of the threat management computer system, a known device identifier or user identification associated with an endpoint of the plurality of endpoints that is responsible for the threat (identifies threat endpoint address [Nimmagadda '258 ¶ 0093, 0081-0083; Fig. 5 at 520]) Nimmagadda '258 discloses propagating, by the one or more processors of the threat management computer system, a global isolation of the endpoint across network devices of the monitored network system, wherein the global isolation is configured to block the device identifier or user identification associated with the endpoint that is responsible for the threat (identifies network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 1D; Fig. 5 at 550, 570]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078]) Nimmagadda '258 does not disclose the notification causes the software agents of the switches or Wi-Fi access points to pull a configuration change corresponding to a device identifier filter and apply the configuration change on the switch or Wi-Fi access point Further: Gladstone '495 discloses the notification causes the software agents of the nodes to pull a configuration change corresponding to a device identifier filter and apply the configuration change on the nodes (security agent 45 sends and receives notifications of updates, e.g. notifications to firewall to update rules to quarantine a particular device [Gladstone '495 ¶ 0044, 0047, 0038]) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the security agents on network nodes of Gladstone '495 to arrive at an apparatus, method, and product including: the notification causes the software agents of the nodes to pull a configuration change corresponding to a device identifier filter and apply the configuration change on the nodes A person having ordinary skill in the art would have been motivated to combine them at least because security agents on network nodes would have provided a robust and secure means of communicating between network nodes concerning event data and security commands. A person having ordinary skill in the art would have been further motivated to combine them at least because Gladstone '495 teaches [Gladstone '495 ¶ 0044, 0047, 0038, 0035 ] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Gladstone '495 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate and implements commands via security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Further: Thioux '191 discloses the notification causes the software agents of the switches or Wi-Fi access points to change configuration corresponding to a device identifier filter and apply the configuration change on the switch or Wi-Fi access point (security agent in switch or router [Thioux '191 ¶ 0344]; security agent isolates endpoint from network upon suspicion of compromise [Thioux '191 ¶ 0055, 0156]; security agent receives configuration from data control center [Thioux '191 ¶ 0346, 0349, 0356]) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 in view of Gladstone '495 with the security agents on network switches of Thioux '191 to arrive at an apparatus, method, and product including: the notification causes the software agents of the switches or Wi-Fi access points to pull a configuration change corresponding to a device identifier filter and apply the configuration change on the switch or Wi-Fi access point A person having ordinary skill in the art would have been motivated to combine them at least because security agents on network switches would have provided allowed uniform control of network switches in applying the security remediations Nimmagadda '258 concerning event data and security commands. A person having ordinary skill in the art would have been further motivated to combine them at least because Thioux '191 teaches [Thioux '191 ¶ 0344, 0346, 0349, 0356, 0055, 0156] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Thioux '191 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (security agents on network switches [Thioux '191 ¶ 0344, 0346, 0349, 0356, 0055, 0156]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (security agents on network switches [Thioux '191 ¶ 0344, 0346, 0349, 0356, 0055, 0156]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate and implements commands via security agents on network switches [Thioux '191 ¶ 0344, 0346, 0349, 0356, 0055, 0156]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 3 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 discloses the device identifier comprises a media access control (MAC) address; and the propagating the global isolation of the endpoint across network devices of the monitored network system further comprises blocking, by the one or more processors of the threat management computer system, the device identifier by a MAC filter at a VLAN level, a LAN level and/or a port level of one or more switches of the monitored network system (filters MAC address at network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 2]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078] at LAN or VLAN level [Nimmagadda '258 ¶ 0034]; enforces policy via MAC address and/or IP address on LAN, VLAN, and WLAN [Nimmagadda '258 ¶ 0026-0027, 0034, 0093]) Per claim 4 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 discloses blocking, by the one or more processors of the threat management computer system, the device identifier at a service set identifier (SSID) level of one or more Wi-Fi access points of the monitored network system (isolates / quarantines threat endpoint at WLAN devices [Nimmagadda '258 ¶ 0029, 0036; Fig. 1F, 1K]) Per claim 6 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 does not disclose receiving, by the one or more processors of the threat management computer system, a report of success or failure from one or more of the software agents Further: Gladstone '495 discloses receiving, by the one or more processors of the threat management computer system, a report of success or failure from one or more of the software agents (security agent 45 sends and receives notifications of status of its device [Gladstone '495 ¶ 0035, 0044, 0047]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the security agents on network nodes of Gladstone '495 to arrive at an apparatus, method, and product including: receiving, by the one or more processors of the threat management computer system, a report of success or failure from one or more of the software agents Per claim 7 (dependent on claim 6): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 6 above, incorporated herein by reference Nimmagadda '258 does not disclose verifying, by the one or more processors of the threat management computer system, the status of whether the software agents of each of the switches or access points within the monitored network system successfully applied the device identifier to block the device identifier Further: Gladstone '495 discloses verifying, by the one or more processors of the threat management computer system, the status of whether the software agents of each of the switches or access points within the monitored network system successfully applied the device identifier to block the device identifier (security agent 45 sends and receives notifications of updates, e.g. notifications to firewall to update rules to quarantine a particular device [Gladstone '495 ¶ 0044, 0047, 0038]; security agent 45 sends and receives notifications of status of its device [Gladstone '495 ¶ 0035, 0044, 0047]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the security agents on network nodes of Gladstone '495 to arrive at an apparatus, method, and product including: verifying, by the one or more processors of the threat management computer system, the status of whether the software agents of each of the switches or access points within the monitored network system successfully applied the device identifier to block the device identifier Per claim 11 (independent): Nimmagadda '258 discloses computer system comprising one or more processors; one or more computer readable storage media; computer readable code stored collectively in the one or more computer readable storage media, with the computer readable code including data and instructions to cause the one or more computer processors to perform a method (processor(s), memory, computer readable media, storage, executable instructions [Nimmagadda '258 ¶ 0060-0067]) The remaining limitations of the claim(s) correspond(s) to features of claim(s) 1 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 13 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 3 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 14 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 4 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 16 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 6 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 17 (dependent on claim 16): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 16 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 7 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 21 (independent): Nimmagadda '258 discloses a computer program product comprising one or more computer readable storage media having computer readable program code collectively stored on the one or more computer readable storage media, the computer readable program code being executed by one or more processors of a threat management computer system to cause the threat management computer system to perform a method (processor(s), memory, computer readable media, storage, executable instructions [Nimmagadda '258 ¶ 0060-0067]) The remaining limitations of the claim(s) correspond(s) to features of claim(s) 1 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Claim(s) 8, 18 is/are rejected under 35 U.S.C. § 103 as being unpatentable over Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of U.S. Publication 20200092319 to Spisak et al. (hereinafter "Spisak '319"). Spisak '319 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Per claim 8 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 does not disclose alerting, by the one or more processors of the threat management computer system, a network administrator of the monitored network system of the identified threat and the identified known device identifier or user identification associated with the threat However, Nimmagadda '258 discloses identifying, by the one or more processors of the threat management computer system, in the monitored network system of the identified threat and the identified known device identifier or user identification associated with the threat (filters MAC address at network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 2]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078] at LAN or VLAN level [Nimmagadda '258 ¶ 0034]) Nimmagadda '258 does not disclose receiving, by the one or more processors of the threat management computer system, approval from the network administrator to propagate the isolation of the endpoint that is responsible for the threat before the propagating However, Nimmagadda '258 discloses receiving, by the one or more processors of the threat management computer system, instructions to propagate the isolation of the endpoint that is responsible for the threat before the propagating (filters MAC address at network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 2]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078] at LAN or VLAN level [Nimmagadda '258 ¶ 0034]) Further: Spisak '319 discloses alerting, by the one or more processors of the threat management computer system, a network administrator of the monitored network system of a proposed configuration change associated with the threat (alerts admin of needed configuration change and gets approval before implementing change [Spisak '319 ¶ 0028, 0099, 0046]) Spisak '319 discloses receiving, by the one or more processors of the threat management computer system, approval from the network administrator to propagate the configuration change before the propagating (alerts admin of needed configuration change and gets approval before implementing change [Spisak '319 ¶ 0028, 0099, 0046]) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the administrator approval of Spisak '319 to arrive at an apparatus, method, and product including: alerting, by the one or more processors of the threat management computer system, a network administrator of the monitored network system of the identified threat and the identified known device identifier or user identification associated with the threat receiving, by the one or more processors of the threat management computer system, approval from the network administrator to propagate the isolation of the endpoint that is responsible for the threat before the propagating A person having ordinary skill in the art would have been motivated to combine them at least because waiting for administrator approval before automatically implementing certain kinds of changes would allow the administrator to evaluating them in the larger context of the system and prevent the changes from accidentally breaking something else unintentionally. A person having ordinary skill in the art would have been further motivated to combine them at least because Spisak '319 teaches [Spisak '319 ¶ 0028, 0099, 0046] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Spisak '319 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (administrator approval [Spisak '319 ¶ 0028, 0099, 0046]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (administrator approval [Spisak '319 ¶ 0028, 0099, 0046]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate and implements the change based on administrator approval [Spisak '319 ¶ 0028, 0099, 0046]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 18 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 8 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Claim(s) 9, 19 is/are rejected under 35 U.S.C. § 103 as being unpatentable over Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of U.S. Publication 20230114719 to Thomas et al. (hereinafter "Thomas '719"). Thomas '719 is prior art to the claims under 35 U.S.C. § 102(a)(1). Per claim 9 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 does not disclose the one or more processors of the threat management computer system is a cloud-based system includes a managed detection and response (MDR) service in communication with a data lake, the data lake is configured to receive and store activity information associated with the plurality of endpoints of the monitored network system, and the MDR service is configured to facilitate the identifying the threat associated with the monitored network system based on the activity information received and stored in the data lake Further: Thomas '719 discloses the one or more processors of the threat management computer system is a cloud-based system includes a managed detection and response (MDR) service in communication with a data lake, the data lake is configured to receive and store activity information associated with the plurality of endpoints of the monitored network system, and the MDR service is configured to facilitate the identifying the threat associated with the monitored network system based on the activity information received and stored in the data lake (analyzes data lake of network data to identify security events [Thomas '719 ¶ 0209, 0211, 0249, 0282, Fig. 21]) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the network event data lake analysis of Thomas '719 to arrive at an apparatus, method, and product including: the one or more processors of the threat management computer system is a cloud-based system includes a managed detection and response (MDR) service in communication with a data lake, the data lake is configured to receive and store activity information associated with the plurality of endpoints of the monitored network system, and the MDR service is configured to facilitate the identifying the threat associated with the monitored network system based on the activity information received and stored in the data lake A person having ordinary skill in the art would have been motivated to combine them at least because storing network events in a data lake for analysis permits the system to look for threat indicators in vast amounts of unprocessed data from network nodes. A person having ordinary skill in the art would have been further motivated to combine them at least because Thomas '719 teaches [Thomas '719 ¶ 0209, 0211, 0249, 0282, Fig. 21] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Thomas '719 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (network event data lake analysis [Thomas '719 ¶ 0209, 0211, 0249, 0282, Fig. 21]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (network event data lake analysis [Thomas '719 ¶ 0209, 0211, 0249, 0282, Fig. 21]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate using network event data lake analysis [Thomas '719 ¶ 0209, 0211, 0249, 0282, Fig. 21]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 19 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 9 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Claim(s) 10, 20 is/are rejected under 35 U.S.C. § 103 as being unpatentable over Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of the knowledge of a person having ordinary skill in the art. Per claim 10 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 discloses initiating, by the one or more processors of the threat management computer system, a request to the network devices of the monitored network system to block the device identifier or user identification associated with the endpoint that is responsible for the threat (filters MAC address at network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 2]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078] at LAN or VLAN level [Nimmagadda '258 ¶ 0034]) Nimmagadda '258 does not disclose verifying, by a gateway in communication with the threat management computer system, authenticity of the request before forwarding the request to network devices of the monitored network system Further: The Examiner takes Official Notice that it was well known and conventional in the art at the time to cryptographically verify received security commands before forwarding them and/or carrying them out. For example, U.S. Publication 20150326589 to Smith (hereinafter "Smith '589") teaches cryptographically authenticating communications with security agents on network nodes [Smith '589 ¶ 0078]. It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 with the cryptographic verification within the knowledge of a person having ordinary skill in the art to arrive at an apparatus, method, and product including: verifying, by a gateway in communication with the threat management computer system, authenticity of the request before forwarding the request to network devices of the monitored network system A person having ordinary skill in the art would have been motivated to combine them at least because security agents on network nodes would have provided a robust and secure means of communicating between network nodes concerning event data and security commands. A person having ordinary skill in the art would have been further motivated to combine them at least because Gladstone '495 teaches [Gladstone '495 ¶ 0044, 0047, 0038, 0035 ] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Gladstone '495 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate and implements commands via security agents on network nodes [Gladstone '495 ¶ 0044, 0047, 0038, 0035]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 20 (dependent on claim 11): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 11 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 10 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Claim(s) 22-25 is/are rejected under 35 U.S.C. § 103 as being unpatentable over Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of U.S. Publication 20200162904 to Jiang et al. (hereinafter "Jiang '904"). Jiang '904 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Per claim 22 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference Nimmagadda '258 does not disclose the propagating includes sending the notification to the software agent of each switch and Wi-Fi access point within the monitored network system However, Nimmagadda '258 discloses the propagating includes sending the notification to the software agent of each node within the monitored network system (identifies network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 1D; Fig. 5 at 550, 570]; isolates/quarantines threat endpoint throughout network via switches [Nimmagadda '258 ¶ 0036, 0078]) Further: Thioux '191 discloses the propagating includes sending the notification to the software agent of each switch within the monitored network system (security agent in switch or router [Thioux '191 ¶ 0344]; security agent isolates endpoint from network upon suspicion of compromise [Thioux '191 ¶ 0055, 0156]; security agent receives configuration from data control center [Thioux '191 ¶ 0346, 0349, 0356]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 in view of Gladstone '495 with the security agents on network switches of Thioux '191 to arrive at an apparatus, method, and product including: the propagating includes sending the notification to the software agent of each switch within the monitored network system Further: Jiang '904 discloses the propagating includes sending the notification to the software agent of each Wi-Fi access point within the monitored network system (security agent installed to wireless AP receives security commands from agent controller [Jiang '904 ¶ 0019-0020, 0023]) It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 with the security agents on network access points of Jiang '904 to arrive at an apparatus, method, and product including: the propagating includes sending the notification to the software agent of each switch and Wi-Fi access point within the monitored network system A person having ordinary skill in the art would have been motivated to combine them at least because security agents on network access points would have provided allowed uniform control of network access points in applying the security remediations Nimmagadda '258 concerning event data and security commands. A person having ordinary skill in the art would have been further motivated to combine them at least because Jiang '904 teaches [Jiang '904 ¶ 0019-0020, 0023] modifying a threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] such as that of Nimmagadda '258 to arrive at the claimed invention; because Jiang '904 and Nimmagadda '258 are in the same field of endeavor; because doing so constitutes use of a known technique (security agents on network access points [Jiang '904 ¶ 0019-0020, 0023]) to improve similar devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) in the same way; because doing so constitutes applying a known technique (security agents on network access points [Jiang '904 ¶ 0019-0020, 0023]) to known devices and/or methods (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (threat mitigation system [Nimmagadda '258 ¶ 0036, 0078] identifies nodes to isolate and implements commands via security agents on security agents on network access points [Jiang '904 ¶ 0019-0020, 0023]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion. Per claim 23 (dependent on claim 22): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Jiang '904 discloses the elements detailed in the rejection of claim 22 above, incorporated herein by reference Nimmagadda '258 does not disclose the configuration change applied on the switch comprises a MAC filter at a VLAN level, a LAN level and/or a port level, and the configuration change applied on the Wi-Fi access point comprises a MAC filter at a service set identifier (SSID) level However, Nimmagadda '258 discloses the configuration change applied on the node comprises a MAC filter at a VLAN level, a LAN level and/or a port level, and the configuration change applied on the node comprises a MAC filter at a service set identifier (SSID) level (filters MAC address at network nodes, e.g. switches, firewalls, to enforce remediation of threat host [Nimmagadda '258 ¶ 0092-0093; Fig. 2]; enforces policy via MAC address and/or IP address on LAN, VLAN, and WLAN [Nimmagadda '258 ¶ 0026-0027, 0034, 0093]) Further: Thioux '191 discloses the configuration change applied on the switch comprises a MAC filter at a VLAN level, a LAN level and/or a port level, (security agent in switch or router [Thioux '191 ¶ 0344]; security agent isolates endpoint from network upon suspicion of compromise [Thioux '191 ¶ 0055, 0156]; security agent receives configuration from data control center [Thioux '191 ¶ 0346, 0349, 0356]) For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 in view of Gladstone '495 with the security agents on network switches of Thioux '191 to arrive at an apparatus, method, and product including: the configuration change applied on the switch comprises a MAC filter at a VLAN level, a LAN level and/or a port level Further: Jiang '904 discloses the configuration change applied on the Wi-Fi access point comprises a MAC filter at a service set identifier (SSID) level (security agent installed to wireless AP receives security commands from agent controller [Jiang '904 ¶ 0019-0020, 0023]) For the reasons detailed above with respect to claim 22, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 with the security agents on network access points of Jiang '904 to arrive at an apparatus, method, and product including: the configuration change applied on the switch comprises a MAC filter at a VLAN level, a LAN level and/or a port level, and the configuration change applied on the Wi-Fi access point comprises a MAC filter at a service set identifier (SSID) level Per claim 24 (dependent on claim 1): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 22 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Per claim 25 (dependent on claim 24): Nimmagadda '258 in view of Gladstone '495 in view of Thioux '191 in view of Jiang '904 discloses the elements detailed in the rejection of claim 24 above, incorporated herein by reference The remaining limitations of the claim(s) correspond(s) to features of claim(s) 23 and the claim(s) is/are rejected for the reasons detailed with respect to those claims. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THEODORE C PARSONS whose telephone number is (571)270-1475. The examiner can normally be reached on MTWRF 7:30-4:30. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/apply/forms. /THEODORE C PARSONS/Primary Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Jun 28, 2024
Application Filed
Jan 08, 2026
Non-Final Rejection mailed — §102, §103
Apr 23, 2026
Applicant Interview (Telephonic)
Apr 23, 2026
Examiner Interview Summary
May 08, 2026
Response Filed
Aug 11, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726501
Vector-Based Anomaly Detection
1y 8m to grant Granted Sep 01, 2026
Patent 12717977
PROXIMITY-BASED CONTENT VISIBILITY CONTROL
3y 5m to grant Granted Aug 25, 2026
Patent 12705402
STORAGE DEVICE, OPERATING METHOD THEREOF, AND SYSTEM FOR PROVIDING SAFE STORAGE SPACE BETWEEN APPLICATION AND STORAGE DEVICE ON APPLICATION-BY-APPLICATION BASIS
3y 0m to grant Granted Aug 11, 2026
Patent 12705316
GEO-FENCING OF AN APPLICATION FOR A SECURE CRYPTOGRAPHIC ENVIRONMENT
1y 12m to grant Granted Aug 11, 2026
Patent 12705351
APPARATUS AND METHODS TO CLASSIFY MALWARE WITH EXPLAINABILITY WITH ARTIFICIAL INTELLIGENCE MODELS
1y 10m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+21.3%)
3y 1m (~10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 470 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month