Prosecution Insights
Last updated: October 02, 2026
Application No. 18/763,000

SECURITY ANALYSIS ASSISTANCE APPARATUS, SECURITY ANALYSIS ASSISTANCE METHOD, AND COMPUTER-READABLE RECORDING MEDIUM

Final Rejection §102§103
Filed
Jul 03, 2024
Priority
Oct 22, 2018 — nonprovisional of PCTJP2018039247 +1 more
Examiner
LEE, CLAY C
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
NEC Corporation
OA Round
2 (Final)
55%
Grant Probability
Moderate
3-4
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 55% of resolved cases
55%
Career Allowance Rate
133 granted / 243 resolved
+2.7% vs TC avg
Strong +58% interview lift
Without
With
+57.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
31 currently pending
Career history
279
Total Applications
across all art units

Statute-Specific Performance

§101
30.6%
-9.4% vs TC avg
§103
47.3%
+7.3% vs TC avg
§102
8.0%
-32.0% vs TC avg
§112
12.0%
-28.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 243 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment The amendment filed May 26, 2026 has been entered. Claims 1-9 remain pending in the application. Applicant’s amendments to the Claims have overcome each and every objections and 101 and 102 rejections previously set forth in the Non-Final Office Action mailed February 25, 2026. Claim Objections Claims 1-9 are objected to because of the following informalities: In claim 1, lines 15-16; and claims 7-8, corresponding lines, “Deep Packet Inspection” should read --deep packet inspection--. In claim 1, lines 22 and 24; and claims 7-8, corresponding lines, “department information” should read --the department information--. In claim 9, line 1, “according to ,” should read --according to claim 1,--. In claim 9, line 3, “organization information” should read --the organization information--. In claim 9, line 7, “Internet Protocol” should read --internet protocol--. Claims 2-6 and 9 are further objected due to their dependency. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Zorlular (US 20180183827 A1) in view of Pilkington (US 20190044969 A1). Regarding Claims 1 and 7-8, Zorlular teaches A network system for improving computer security of an organization comprising: a security analysis assistance apparatus; a mail server; terminal devices; a communication network connecting the mail server, the terminal devices, and the security analysis assistance apparatus, a security appliance configured to output security alerts of suspicious events that occurred in the network system; wherein the security analysis assistance apparatus comprises: a memory configured to store instructions; and a processor configured to execute the instructions to (Zorlular: Paragraph(s) 0019, 0010-0012, 0022, 0038): A security device for improving computer security of an organization that has terminal devices connecting with a mail server and a security appliance which outputs security alerts of suspicious events that occurred in the organization via a communication network, comprising; a memory configured to store instructions; and a processor configured to execute the instructions to (Zorlular: Paragraph(s) 0019, 0010-0012, 0022, 0038): A method for improving computer security of an organization that has terminal devices connecting with a mail server and a security appliance which outputs security alerts of suspicious events that occurred in the organization via a communication network, comprising (Zorlular: Paragraph(s) 0019, 0010-0012, 0022, 0038); obtain the alerts from the security appliance, each of the security alerts identifying a network address of a device in the terminal devices, the device being a subject of each of the security alerts (Zorlular: Paragraph(s) 0023, 0080, 0067 teach(es) Upon processing these indicators, the warning system may determine that an event, namely an email being sent, had occurred, and may assign various attributes and properties to the event, such as, for example, the time and date of the occurrence of the event, and the users, IP addresses, computers, servers or other actors involved); specify a relation between a mail address used in each of the terminal devices and a network address of each of the terminal devices based on data of Deep Packet Inspection (DPI) or packet capturing of a communication path between the mail server and the terminal devices or data obtained from a request of authentication from a terminal device in the terminal devices to the mail server (Zorlular: Paragraph(s) 0080-0081, 0102, 0105 teach(es) the warning system accesses indicators of a potential cyber attack related to the resource. Examples of such indicators include proxy logs, email logs, data loss prevention logs, application firewall logs, etc.; the warning system may extract various features, such as IP addresses, ports, signatures, packet headers and other characteristics, from past alerts that were determined by an analyst to be related to a cyber attack on a resource, or that were determined by an analyst not to be related to such an attack; indicators from an email server may be matched against a set of rules to determine indicators related to emails that were sent to a recipient inside the organization and that appear to be social engineering attacks against an employee of the organization); obtain a mail address used in the device being a subject of each of the security alerts based on the specified relation (Zorlular: Paragraph(s) 0023, 0025, 0060-0062 teach(es) Upon processing these indicators, the warning system may determine that an event, namely an email being sent, had occurred, and may assign various attributes and properties to the event, such as, for example, the time and date of the occurrence of the event, and the users, IP addresses, computers, servers or other actors involved. An event may or may not be indicative of any risk to a resource); obtain department information for identifying a department of the organization by specifying department information associated with the obtained mail address based on organization information, the department having the device, the organization information including department information and mail addresses used in the department (Zorlular: Paragraph(s) 0025, 0060 teach(es) an analyst reviewing whether a certain user's act of e-mailing confidential documents to the user's private email account represents activity related to a cyber attack against a resource may make better decisions when presented with information regarding prior, similar activity by the user, the user's department or the user's organization); analyze occurrence tendency of the security alerts for the department (Zorlular: Paragraph(s) 0022, 0061 teach(es) the indicators may be dynamically re-grouped and/or filtered in an interactive user interface so as to enable an analyst to quickly navigate among information associated with various alerts and efficiently evaluate the groups of alerts in the context of, for example, an audit for data breach or other activity related to a cyber attack against a resource); visualize a result of the occurrence tendency as a visualization comprising a hierarchical configuration of the organization (Zorlular: Paragraph(s) 0100, 0025 teach(es) The alert and event graph displays a graphical representation of alerts and events for the resource; displays alerts and events based on their occurrence in time and their risk score; an analyst reviewing whether a certain user's act of e-mailing confidential documents to the user's private email account represents activity related to a cyber attack against a resource may make better decisions when presented with information regarding prior, similar activity by the user, the user's department or the user's organization). However, Zorlular does not explicitly teach switch, based on a user operation, the visualization between displaying a first hierarchy level of the department in the hierarchical configuration and displaying a second hierarchy level of the department in the hierarchical configuration. Pilkington from same or similar field of endeavor teaches switch, based on a user operation, the visualization between displaying a first hierarchy level of the department in the hierarchical configuration and displaying a second hierarchy level of the department in the hierarchical configuration (Pilkington: Paragraph(s) 0047, 0058, 0067-0069 teach(es) The techniques provide for the dynamic and arbitrary, but still useful, groupings of different populations to compare different population risk scores, without limiting to a pre-defined structures such as the organization's departments; The risk score for a population may be determined at different points in time in order to visualize trends in different population risk scores, without limiting to pre-defined structures (such as the organization)). It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the teachings of Zorlular to incorporate the teachings of Pilkington for switch, based on a user operation, the visualization between displaying a first hierarchy level of the department in the hierarchical configuration and displaying a second hierarchy level of the department in the hierarchical configuration. There is motivation to combine Pilkington into Zorlular because Pilkington’s teachings of visualization according to organization's departments would facilitate to analyze risk scores across an organization (Pilkington: Paragraph(s) 0047, 0058, 0067-0069). Regarding Claim 2, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the processor is further configured to execute the instructions to: analyze the occurrence tendency of the security alerts for each department at each hierarchy level in the hierarchical configuration of the organization, and visualize the occurrence tendency of the security alerts in an aspect that reflects the hierarchical configuration (Zorlular: Figs. 5-7; Paragraph(s) 0096-0098, 0105, 0025, 0100 teach(es) Referring to FIG. 5, example user interface illustrates a network overview provided by the warning system to an analyst to allow the analyst to review the risk level of all resources on the network that are being monitored by the warning system). Regarding Claim 3, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the processor is configured to execute the instructions to visualize the occurrence tendency of the security alerts in aspect where occurrence rates of the security alerts are visualized (Zorlular: Figs. 5-7; Paragraph(s) 0096-0098, 0105, 0025, 0100, as stated above with respect to claim 2). Regarding Claim 4, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the occurrence rates are categorized into a plurality of classes (Zorlular: Paragraph(s) 0087 teach(es) The alerts may dynamically be grouped and filtered, for example according to different alert types). Regarding Claim 5, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the processor is configured to execute the instructions to visualize the occurrence tendency in aspect where a class of an upper department of a device with the highest class is the highest (Zorlular: Paragraph(s) 0087 teach(es) the alerts may be sorted by the risk score, for example so as to show the alerts starting with the highest risk score). Regarding Claim 6, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the processor is configured to execute the instructions to visualize the occurrence tendency in aspect where occurrence tendency visualized for each higher-level department is switched to occurrence tendency visualized a lower-level department according to an operation (Zorlular: Paragraph(s) 0100 teach(es) The show historical alerts toggle switch allows the analyst, by selecting and deselecting it, to determine whether or not historical alerts, that is, alerts that have already been responded to by an analyst, should be displayed in the alert and event graph. The show events toggle switch allows the analyst by enabling or disabling it to determine whether or not events should be displayed in the alert and event graph). Regarding Claim 9, the combination of Zorlular and Pilkington teaches all the limitations of claim 1 above; and Zorlular further teaches wherein the processor is further configured to execute the instructions to: obtain, from a service server, organization information specifying at least: departments forming the organization, members of the departments, and email addresses of the members; specify, based on transmission processing and processing of email used in the organization, a specification result comprising: the email addresses and Internet Protocol (IP) addresses corresponding to the email addresses; compare the specification result with the organization information; and generate organization address information specifying at least: the departments, the members, the email addresses, and the IP addresses (Zorlular: Paragraph(s) 0023, 0064, 0067, 0080, 0110 teach(es) Upon processing these indicators, the warning system may determine that an event, namely an email being sent, had occurred, and may assign various attributes and properties to the event, such as, for example, the time and date of the occurrence of the event, and the users, IP addresses, computers, servers or other actors involved; the notification and/or notification may include a URL of a webpage (or other online information) associated with the notification, such that when the device (e.g., a mobile device) receives the notification, a browser (or other application) is automatically activated and the URL included in the notification and/or notification is accessed via the Internet. Advantageously, this keeps analysts and other interested members of an organization informed about critical development, without requiring them to periodically check the status of the warning system). Response to Arguments Applicant's arguments filed May 26, 2026 have been fully considered but they are not persuasive. Regarding applicant’s argument under Claim Rejections - 35 USC § 102/103 that “cited art Zorlular fails to teach or suggest at least the claim features "visualize a result of the occurrence tendency as a visualization comprising a hierarchical configuration of the organization" and "switch, based on a user operation, the visualization between displaying a first hierarchy level of the department in the hierarchical configuration and displaying a second hierarchy level of the department in the hierarchical configuration",” examiner respectfully argues that the combination of Zorlular and Pilkington teaches the features as stated above in the 103 rejections (Zorlular: Paragraph(s) 0100, 0025; and Pilkington: Paragraph(s) 0047, 0058, 0067-0069). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Paine (US 20180255080 A1) teaches System And Method For Cyber Security Threat Detection, teaches alert and division/department/business unit inside the organization/company. Kraning (US 20180337941 A1) teaches Correlation-Driven Threat Assessment And Remediation. Siadati (US 20180124082 A1) teaches Classifying Logins, For Example As Benign Or Malicious Logins, In Private Networks Such As Enterprise Networks For Example, including alert, department, organization, and visualization. Qureshi (EP 3499839 B1) teaches Mobile Device Management And Security. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CLAY LEE whose telephone number is (571)272-3309. The examiner can normally be reached Monday-Friday 8-5pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at (571)270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CLAY C LEE/Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Jul 03, 2024
Application Filed
Feb 25, 2026
Non-Final Rejection mailed — §102, §103
Apr 29, 2026
Applicant Interview (Telephonic)
Apr 29, 2026
Examiner Interview Summary
May 26, 2026
Response Filed
Aug 18, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12725153
METHOD AND APPARATUS FOR BOOKKEEPING, OWNING AND TRANSFERRING DIGITALLY LOCKED COINS
1y 3m to grant Granted Sep 01, 2026
Patent 12718223
USER AUTHENTICATION USING A BROWSER COOKIE SHARED BETWEEN A BROWSER AND AN APPLICATION
2y 2m to grant Granted Aug 25, 2026
Patent 12711508
REAL-TIME FRAUD SESSION TERMINATION IN DIRECT PAY SYSTEM
2y 7m to grant Granted Aug 18, 2026
Patent 12711509
SYSTEMS AND METHODS FOR IMPROVED FRAUD DETECTION
2y 8m to grant Granted Aug 18, 2026
Patent 12701013
MEDIA SHARING PLATFORM
1y 11m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
55%
Grant Probability
99%
With Interview (+57.5%)
3y 4m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 243 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month