Prosecution Insights
Last updated: October 01, 2026
Application No. 18/760,678

SYSTEMS AND METHODS FOR MANAGING EVENT CORRELATIONS

Non-Final OA §103
Filed
Jul 01, 2024
Priority
Jan 31, 2024 — IN 202421006529
Examiner
SWIFT, CHARLES M
Art Unit
Tech Center
Assignee
Tata Group
OA Round
1 (Non-Final)
81%
Grant Probability
Favorable
1-2
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
726 granted / 900 resolved
+20.7% vs TC avg
Strong +23% interview lift
Without
With
+22.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
37 currently pending
Career history
939
Total Applications
across all art units

Statute-Specific Performance

§101
11.1%
-28.9% vs TC avg
§103
57.2%
+17.2% vs TC avg
§102
16.3%
-23.7% vs TC avg
§112
6.1%
-33.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 900 resolved cases

Office Action

§103
DETAILED ACTION This office action is in response to application filed on 7/1/2024. Claims 1 – 20 are pending. Priority is claimed to Indian application IN202421006529 (filed on 1/31/2024). Notice of Pre-AA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3, 9, 11 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rathunde et al (US 20090183023, hereinafter Rathunde), in view of Arrabolu et al (US 20200374199, hereinafter Arrabolu). As per claim 1, Rathunde discloses: A processor implemented method, comprising: receiving, via one or more hardware processors, a plurality of events pertaining to an enterprise; (Rathunde [0025].) selecting, via the one or more hardware processors, a correlation scope and a plurality of self-tuned time windows based on the plurality of events, (Rathunde [0026]) applying a heuristic function on the one or more parameters of the set of candidate events for identifying the correlation scope; (Rathunde [0050]: “When an input event is added to the event repository, the input event's attributes are checked (206). If the input event requires correlation, then the correlation timer 88 is started.”; [0051]: “Once the correlation timer 88 expires (or, if no correlation was needed) (208), the event repository is searched for all input events that contribute to an alarm/state event trigger (210). If there are any such input events, the logical event trigger is formed. This logical event trigger is passed to a processing function such as the Alarm/State Management function 82.”) and recommending the plurality of self-tuned time windows using at least one of the graph and nature associated with the plurality of events; (Rathunde [0026] – [0027]) deriving, via the one or more hardware processors, a plurality of event correlation signatures associated with the set of candidate events based on the correlation scope and the plurality of self-tuned time windows; (Rathunde [0052]: “Each row of the Alarm/State Management table represents a particular fault that is to be alarmed or result in a state change on the resource. The event trigger (which represents a list of current input events from the event repository) is compared against the event selectors defined for a particular event processing table such as the Alarm/State Management table row (212). Event Selectors are a defined set of input events that must be present in order to match a row, which defines a fault (event selectors can be statically-defined or dynamically loaded policies).”; [0027]: “This event correlation introduces the second level of detection time necessary to isolate the fault (88). At the end of the event correlation window 88, a single unique event trigger (or "fault signature") is defined and is supported in a row in the resource monitors event driven recovery table. This is a logical event type that represents one or more input events (from one or more sources) received during the event correlation window or recorded from a previous event correlation that has not been cleared.”) and interpreting, via the one or more hardware processors, the plurality of event correlation signatures to obtain a filtered set of event correlation signatures, wherein each correlation signature from the filtered set of event correlation signatures comprises one or more use cases. (Rathunde [0029]) Rathunde did not explicitly teach: wherein the step of selecting the correlation scope and the plurality of self-tuned time windows comprises: constructing a graph comprising a plurality of entities in the plurality of events and one or more associated interconnections; determining a set of candidate events from the graph; computing one or more parameters of the set of candidate events; However, Arrabolu teaches: wherein the step of selecting the correlation scope and the plurality of self-tuned time windows comprises: constructing a graph comprising a plurality of entities in the plurality of events and one or more associated interconnections; determining a set of candidate events from the graph; computing one or more parameters of the set of candidate events; (Arrabolu [0017]) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Arrabolu into that of Rathunde in order to have the step of selecting the correlation scope and the plurality of self-tuned time windows comprises: constructing a graph comprising a plurality of entities in the plurality of events and one or more associated interconnections; determining a set of candidate events from the graph; computing one or more parameters of the set of candidate events. Arrabolu [0017] has shown that the claimed limitations are merely commonly known and used steps in determining correlations between events during monitoring, applicants have thus merely claimed the combination of known parts in the field to achieve predictable results and is therefore rejected under 35 USC 103. As per claim 3, the combination of Rathunde and Arrabolu further teach: The processor implemented method of claim 1, wherein the step of recommending the plurality of self-tuned time windows comprises: analyzing timeseries of the plurality of events to determine a multi-model behavior between one or more entities associated with each of the plurality of events; and analyzing and identifying one or more multi-model criteria for each behavior in the timeseries to obtain the plurality of self-tuned time windows, and wherein the step of analyzing and identifying the one or more multi-model criteria is based on one or more attributes of the plurality of events in the timeseries. (Arrabolu [0035]) As per claim 9, it is the system variant of claim 1 and is therefore rejected under the same rationale. As per claim 11, it is the system variant of claim 3 and is therefore rejected under the same rationale. As per claim 17, it is the non-transitory machine-readable information storage mediums variant of claim 1 and is therefore rejected under the same rationale. Claim(s) 2 and 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rathunde and Arrabolu, and further in view of Chan et al (USPAT 7996353, hereinafter Chan). As per claim 2, the combination of Rathunde and Arrabolu did not teach: The processor implemented method of claim 1, wherein the heuristic function (i) constructs a matrix corresponding to each of the plurality of events, and wherein the matrix comprises days and number of times an event occurs in each day, and (ii) computes dot product of matrices to identify number of events and the correlation scope. However, Chan teaches: The processor implemented method of claim 1, wherein the heuristic function (i) constructs a matrix corresponding to each of the plurality of events, and wherein the matrix comprises days and number of times an event occurs in each day, and (ii) computes dot product of matrices to identify number of events and the correlation scope. (Chan claim 7 and col 5, line 39 – col 6, line 40.) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Chan into that of Rathunde and Arrabolu in order to have the heuristic function (i) constructs a matrix corresponding to each of the plurality of events, and wherein the matrix comprises days and number of times an event occurs in each day, and (ii) computes dot product of matrices to identify number of events and the correlation scope. Chan claim 7 and col 5, line 39 – col 6, line 40 has shown that the claimed limitations are merely commonly known and used steps for determining even correlations, and applicants have thus merely claimed the combination of known parts in the field to achieve predictable results and is therefore rejected under 35 USC 103. As per claim 10, it is the system variant of claim 2 and is therefore rejected under the same rationale. Claim(s) 4 – 7 and 12 – 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rathunde and Arrabolu, and further in view of Singla et al (US 20160019388, hereinafter Singla). As per claim 2, the combination of Rathunde and Arrabolu further teach: The processor implemented method of claim 1, wherein the step of deriving the one or more event correlation signatures comprises: selecting one or more candidate events from the set of candidate events based on the correlation scope and the plurality of self-tuned time windows to obtain one or more associated correlation signatures; (Rathunde [0025] – [0029]) The combination of Rathunde and Arrabolu did not teach: and identifying a correlation signature type for each of the one or more associated correlation signatures based on a comparison of an associated confidence value and a confidence threshold. However, Singla teaches: and identifying a correlation signature type for each of the one or more associated correlation signatures based on a comparison of an associated confidence value and a confidence threshold. (Singla figure 3 and [0049] – [0051]) It would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Singla into that of Rathunde and Arrabolu in order to identify a correlation signature type for each of the one or more associated correlation signatures based on a comparison of an associated confidence value and a confidence threshold. Singla has shown that the claimed limitations are merely commonly known and used steps for determining even correlations, and applicants have thus merely claimed the combination of known parts in the field to achieve predictable results and is therefore rejected under 35 USC 103. As per claim 5, the combination of Rathunde, Arrabolu and Singla further teach: The processor implemented method of claim 4, wherein the correlation signature type comprises a first correlation signature or a second correlation signature. (Rathunde [0025] – [0029]) As per claim 6, the combination of Rathunde, Arrabolu and Singla further teach: The processor implemented method of claim 5, wherein when the correlation signature type is the first correlation signature, the method comprises: identifying a set of pre-conditions based on one or more attributes of the plurality of events to obtain the one or more groups of correlation events, and wherein each group identifies a unique pre-conditional value; and applying the set of pre-conditions on the one or more associated correlation signatures identified as the first correlation signature to increase the associated confidence value. (Singla [0032] – [0034]) As per claim 7, the combination of Rathunde, Arrabolu and Singla further teach: The processor implemented method of claim 5, when the correlation signature type is the second correlation signature, the method comprises: analyzing the second correlation signature based on a topology further comprising a plurality of entities and an associated entity type to increase a correlation support for the second correlation signature. (Singla [0032] – [0034]) As per claim 12, it is the system variant of claim 4 and is therefore rejected under the same rationale. As per claim 13, it is the system variant of claim 5 and is therefore rejected under the same rationale. As per claim 14, it is the system variant of claim 6 and is therefore rejected under the same rationale. As per claim 15, it is the system variant of claim 7 and is therefore rejected under the same rationale. Allowable Subject Matter Claims 8, 16 and 18 – 20 objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Gurnov et al (US 20230199006) teaches “A method for machine learning-based detection of an automated fraud or abuse attack includes: identifying, via a computer network, a digital event associated with a suspected automated fraud or abuse attack; composing, via one or more computers, a digital activity signature of the suspected automated fraud or abuse attack based on digital activity associated with the suspected automated fraud or abuse attack; computing, via a machine learning model, an encoded representation of the digital activity signature; searching, via the one or more computers, an automated fraud or abuse signature registry based on the encoded representation of the digital activity signature; determining a likely origin of the digital event based on the searching of the automated fraud or abuse signature registry; and selectively implementing one or more automated threat mitigation actions based on the likely origin of the digital event.” Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHARLES M SWIFT whose telephone number is (571)270-7756. The examiner can normally be reached Monday - Friday: 9:30 AM - 7PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, April Blair can be reached at 5712701014. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHARLES M SWIFT/Primary Examiner, Art Unit 2196
Read full office action

Prosecution Timeline

Jul 01, 2024
Application Filed
Sep 01, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730667
SWITCH FOR MANAGING SERVICE MESHES
4y 8m to grant Granted Sep 08, 2026
Patent 12730670
Queue Management for Task Graphs
3y 0m to grant Granted Sep 08, 2026
Patent 12724634
MEDICAL INFORMATION PROCESSING SYSTEM AND MEDICAL INFORMATION PROCESSING METHOD, MEDICAL INFORMATION PROCESSING SERVICE PROVIDING METHOD, AND PROGRAM
2y 12m to grant Granted Sep 01, 2026
Patent 12717614
SYSTEMS AND METHODS FOR COMPLETING TASKS
4y 6m to grant Granted Aug 25, 2026
Patent 12717632
DYNAMIC PROCESSING OF TRANSACTIONS BASED ON PREDICTED COMPUTATION COSTS
3y 1m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
81%
Grant Probability
99%
With Interview (+22.6%)
3y 0m (~9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 900 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month