Prosecution Insights
Last updated: August 06, 2026
Application No. 18/765,713

SYSTEM FOR MANAGING SECURITY RISKS WITH GENERATIVE ARTIFICIAL INTELLIGENCE

Final Rejection §103
Filed
Jul 08, 2024
Priority
Jul 07, 2023 — provisional 63/525,522
Examiner
HARRIS, CHRISTOPHER C
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Code42 Software Inc.
OA Round
2 (Final)
77%
Grant Probability
Favorable
3-4
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
288 granted / 376 resolved
+18.6% vs TC avg
Strong +25% interview lift
Without
With
+25.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
14 currently pending
Career history
390
Total Applications
across all art units

Statute-Specific Performance

§101
15.4%
-24.6% vs TC avg
§103
41.3%
+1.3% vs TC avg
§102
9.6%
-30.4% vs TC avg
§112
26.7%
-13.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 376 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. DETAILED ACTION Remarks This Final action is in response to communications filed on 04/09/2026, claim(s) 1, 13 and 20 are amended per Applicant's request. Therefore, claims 1-20 are presently pending in the application and have been considered as follows. In light of the applicant amendment the examiner hereby withdraws the previous 35 USC 101 rejection. Response to Arguments Applicant's arguments filed 04/29/2026 have been fully considered but they are not persuasive. -The applicants’ remarks on page 6-7 with respect to: “Applicant respectfully submits that neither Tietz nor Boyer disclose or suggest the use of file analysis information for fine-tuning the LLM and producing a generative output including a generative AI summary of file contents without disclosing sensitive information of the file content. On this point, Applicant respectfully notes that Tietz expressly performs analysis without regard to file contents.” Have been carefully considered but are non-persuasive; In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). The examiner notes that Tietz is not relied upon for teaching the newly added claim limitation directed to “analysis of file content.” Tietz is relied upon for the exfiltration-risk system that includes file tracking, file history chains, exfiltration-risk assessment, alerts and mitigation (Tietz, Para. 0004-0008, 0020-0024, 0029-0039). Boyer is relied upon for the LLM query, fine-tuning and cybersecurity summary generation features. (Boyer, Para. 0019-0029, 0046-0051, 0088-0091). Singh is relied upon for the newly added content analysis and sensitive restriction feature limitations (Singh, Para. 0041-0043, 0058-0073, 097-0101). As will soon be discussed below in the substance for the subsequent 103 rejection, Singh teaches data loss prevention techniques for interfacing with artificial intelligence tools. Singh teaches that data loss prevention can include identifying and classifying sensitive data, continuously tracking and analyzing the movement and usage of sensitive data and inspecting data at rest or in motion. Singh further teaches using pattern matching, embeddings, artificial intelligence or machine learning to analyze data and identify potentially sensitive data and preventing confidential content addressed by a data loss prevention policy from being submitted to an artificial intelligence tool. (Singh, Para. 0041-0043, 0058-0073, 097-0101). Thus, the applicants arguments are considered non-persuasive. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 8-16 and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over US 20200193019 to Tietz et al. (hereinafter “Tietz”) in view of US 20240414211 to Boyer et al. (hereinafter “Boyer”) and further in view of US 20240370584 to Singh et al. (hereinafter “Singh”) Claim 1 Tietz teaches a system for exfiltration analysis, [e.g. Tietz; Abstract, Para. 0007, 0019, 0020– Tietz discloses a an exfiltration detection and response system configured to manage data exfiltration risk in a computer network (e.g. exfiltration analysis) .] the system comprising: a processor subsystem; and memory including instructions, which when executed by the processor subsystem, [e.g. Tietz; Abstract, Para. 0007, 0019, 0020– Tietz discloses a memory and processor.] cause the processor subsystem to: receive a plurality of file identifiers of a corresponding plurality of files, the plurality of files related to exfiltration alerts; [e.g. Tietz; Abstract, Para. 0004, 0005, 0007, 0019-0024, 0026-0033– Tietz discloses collecting computer file management information associated with a plurality of computer files and tracking files from purposes of data exfiltration risk assessment (e.g. receiving file identifiers, file information for files related to exfiltration alerts).] store information about the plurality of files in a forensic file data store, ... [e.g. Tietz; Abstract, Para. 0029-0039 – Tietz discloses a history and exfiltration tracker that creates and maintains history chains including file management information and correlated user activity information for tracked files (e.g. forensic data store storing information about the plurality of files).] While Tietz teaches the system of claim 1 Tietz fails to explicitly teach utilizing large language models to aid in exfiltration analysis. More specifically Tietz fails to teach however, Boyer teaches cybersecurity components configured to cooperate with one or more large language models (LLMs). Boyer teaches one or more cybersecurity components configured to cooperate with one or more are configured to communicate and cooperate with the one or more cybersecurity components via one or more Application Program Interfaces (APIs) to receive cyber security information and apply language generation functionality in order to assist a human in an understanding of the cyber security information. Boyer further teaches that the LLMs can launch an investigation using APIs, can be trained or fine-tuned for cybersecurity tasks, can receive a user query, can obtain contextual cybersecurity information and can generate human readable cybersecurity reports or summaries. Thus Boyer teaches: ... the forensic file data store used to provide contextual information for a large language model (LLM), wherein the LLM is fine-tuned using the contextual information; [e.g. Boyer; Abstract, Para. 0019-0028, 0046-0051, 0088-0091 – Boyer discloses LLMs receiving cybersecurity information, context from cybersecurity components through APIs and being trained and fine-tuned for cybersecurity tasks (e.g. store cybersecurity and exfiltration information used as contextual information for a fine-tuned LLM) .] receive an exfiltration query from a user of the system; [e.g. Boyer; Abstract, Para. 0021-0024, 0046-0050, 0064-0077 – Boyer discloses sending a query interface allowing a user to interact with the LLM and cybersecurity components and discloses translating user questions into API queries for cybersecurity information (e.g. receiving a user query regarding an exfiltration, cybersecurity event.)] and produce a generative output using the LLM based on the exfiltration query and the contextual information. [e.g. Boyer; Abstract, Para. 00019-0029, 0030-0045, 0048-0051 – Boyer discloses using an LLM to generate human readable cybersecurity summaries, reports based on cybersecurity information and additional contextual information obtained through cybersecurity components, APIs (e.g. producing a generative output based on the query and contextual information).] Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to include, the features above in the invention as disclosed by Tietz as a primary benefit is that it allows cyber security system operators to explain the ongoing incidents to different levels of end users with cyber security knowledge without requiring human time to rephrase that data, and present that data to explain things such as why the network was breached as disclosed by Boyer in paragraph 0029. While the combination teaches the system of claim 1, the combination fails to explicitly teach storing information about the plurality of files including analysis of file contents and producing the generative output including a generative AI summary of file content without disclosing sensitive information. More specifically the combination fails to teach however, Singh teaches data loss prevention techniques for interfacing with artificial intelligence tools. Singh teaches that data loss prevention can include identifying and classifying sensitive data, continuously tracking and analyzing the movement and usage of sensitive data and inspecting data at rest or in motion. Singh further teaches using pattern matching, embeddings, artificial intelligence or machine learning to analyze data and identify potentially sensitive data and preventing confidential content addressed by a data loss prevention policy from being submitted to an artificial intelligence tool. Thus Sign teaches: storing information about the plurality of files including analysis of file contents; [e.g. Singh; Abstract, Para. 0029, 0033, 0034, 0041-0043, 0090-0097, 0100, 0101 – Singh discloses inspecting data, files, identifying and classifying sensitive information, using embeddings or artificial intelligence, machine learning to analyze data, identifying potentially sensitive data and determining whether content is addressed by a DLP policy (e.g. e.g. analysis of file contents) .] the generative output including a generative Al summary of file content without disclosing sensitive information of the file content. [e.g. Singh; Abstract, Para. 0024-0029, 0033, 0034, 0084-0088, 0097-0101 – Sign discloses DLP policies adapted for generative AI tools and preventing confidential, sensitive contented addressed by a DLP policy from being submitted to an AI tool (e.g. e.g. preventing disclosure of sensitive file contents) .] Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to include, the features above in the invention as disclosed by the combination in order to identify sensitive information in file content and prevent unauthorized disclosure or transmission of sensitive information when interacting with AI tools which would predictably protected sensitive file content while still permitting LLM-assisted cybersecurity, exfiltration analysis (Singh Para. 0088, 0097). Claim 2: Tietz teaches the system of claim 1, wherein an exfiltration alert of the exfiltration alerts is based on at least one filesystem event. [e.g. Tietz; Abstract, Para. 0004, 0005, 0007, 0019-0024, 0026-0039– Tietz discloses file management information including file operations and using file, user activity information assess file exfiltration risk and generate alerts (e.g. exfiltration event based on filesystem event).] Claim 3: Tietz teaches the system of claim 2, wherein the at least one filesystem event includes an operation to create, read, modify, or delete a filesystem element. [e.g. Tietz; Abstract, Para. 0022-0024, 0026-0033 – Tietz discloses file management information including whether a file has been created, opened, copied, deleted, etc. (e.g. operations to create, read modify, delete filesystem element).] Claim 4: Tietz teaches the system of claim 2, wherein an exfiltration alert of the exfiltration alerts is based on an exfiltration model used to determine whether the at least one filesystem event is indicative of exfiltration. [e.g. Tietz; Abstract, Para. 0038, 0039 – Tietz discloses a rules engine (e.g. exfiltration model) that applies rules, logic to a file history chain to determine whether user activity on a tracked file creates an exfiltration risk warranting action (e.g. used to determine whether the at least one filesystem event is indicative of exfiltration).] Claim 6 and 7: While Tietz and Boyer teaches the system of claim 1 the combination fails to explicitly teach however, Singh teaches: wherein to produce the generative output, the processor subsystem is to: vectorize the exfiltration query to produce a vector representation of the exfiltration query; and perform a vector comparison of the vector representation of the exfiltration query and vector representations of the contextual information. [e.g. Singh; Abstract, Para. 0015, 0033, 0034, 0043, 0090-0097 – Singh discloses translating DLP patterns and communication, content into embeddings to determine similarity score and using embeddings, AI, ML to detect sensitive information (e.g. vectorizing the query, contextual information and comparing vector representations).] wherein the vector comparison is one of: a dot product operation, a cosine similarity operation, or a soft cosine similarity operation. [e.g. Singh; Abstract, Para. 0090-0095 – Singh discloses embeddings represented as vectors and comparing vectors by calculating proximity in an embedding space (e.g. known vector similarity comparisons such as dot product, cosine similarity, etc.] Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to include, the features above in the invention as disclosed by Tietz and Boyer with the advantage of finding similar matches even if content (e.g. query) is modified. Furthermore, these techniques are well known and it would have been obvious to choose from a finite number of identified, predictable solutions, with a reasonable expectation of success. Claim 8: Tietz teaches the system of claim 1, wherein the processor subsystem is to generate a risk score of an activity related to at least one of the exfiltration alerts. [e.g. Tietz; Abstract, Para. 0004, 0009, 0038, 0039 – Tietz discloses a assessing exfiltration risk using file management information and correlated user activity information (e.g. generate a risk score, assessment for activity related to an exfiltration alerts).] Claim 9: Tietz teaches the system of claim 8, wherein the processor subsystem is to initiate a mitigation function based on the risk score. [e.g. Tietz; Abstract, Para. 0004-0009, 0038, 0039, 0044, 0081 – Tietz discloses the rules engine outputting a response based on a level of exfiltration risk such as sending alerts to the user, system administrator, block an action etc.] Claim 10: Tietz teaches the system of claim 9, wherein to initiate the mitigation function, the processor subsystem is to alert a human administrator. [e.g. Tietz; Abstract, Para. 0005, 0009, 0038, 0039 – Tietz discloses the rules engine outputting a response based on a level of risk such as sending alerts to the user, system administrator, block an action etc.] Claim 11: Tietz teaches the system of claim 9, wherein to initiate the mitigation function, the processor subsystem is to transmit an educational ... to a user related to the activity. [e.g. Tietz; Abstract, Para. 0005, 0009, 0038, 0039, 0044, 0081 – Tietz discloses the rules engine outputting a response based on a level of risk such as explaining to the user why an action was not allowed (e.g. educating the user).] While Tietz teaches the system of claim 1 and teaches in paragraph 0044 and 0081 of providing a message that explains why the user action was not allowed via text, pop-up etc. Tietz fail to explicitly teach providing a video. However, as Tietz population of the education responses are open ended it would have been an obvious matter of design choice to further modify the message of Tietz by also providing a response that would include a video which would yield predictable results. In this case, the predictable result would be informing and educating the user of the action in a different format. Claim 12: Tietz teaches the system of claim 9, wherein to initiate the mitigation function, the processor subsystem is to restrict access to network resources for a user related to the activity. [e.g. Tietz; Abstract, Para. 0005, 0008, 0009, 0038, 0039 – Tietz discloses the rules engine outputting a response based on a level of risk such as sending alerts to the user, system administrator, block an action etc.] Regarding claims 13-16 and 18-20 they are method and manufacture claims essentially corresponding to the above recitations, and they are rejected, at least, for the same reasons. Claims 5 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over US 20200193019 to Tietz et al. (hereinafter “Tietz”) in view of US 20240414211 to Boyer et al. (hereinafter “Boyer”) and further in view of US 20240291833 to Murphy et al. (hereinafter “Murphy”) Claim 5: While Tietz and Boyer teaches the system of claim 1 and Boyer teaches fine tuning LLM with contextual information the combination fails to explicitly teach that the LLM is a commercially available LLM. More specifically the combination fails to teach however, Murphy teaches: wherein the LLM is a commercially available model fine-tuned .... [e.g. Murphy; Abstract, Para. 0457-0461– Murphy discloses it is well known to fine-tune a commercially available LLM such as OpenAI’s GPT-3.] Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to include, the features above in the invention as disclosed by Tietz and Boyer as enables developers to create more accurate and effective natural language processing application and it well known in the art as disclosed by Murphy in paragraphs 0457-0461. Regarding claim 17 it is a method claims essentially corresponding to the above recitations, and they are rejected, at least, for the same reasons. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER C HARRIS whose telephone number is (571)270-7841. The examiner can normally be reached Monday through Friday between 8:00 AM to 4:00 PM CST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER C HARRIS/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jul 08, 2024
Application Filed
Nov 14, 2025
Non-Final Rejection (signed) — §103
Dec 29, 2025
Non-Final Rejection mailed — §103
Apr 29, 2026
Response Filed
Jul 01, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699768
SYSTEM AND METHOD FOR RUNNING ENCLAVE-AWARE EXECUTABLES
1y 6m to grant Granted Aug 04, 2026
Patent 12670254
STORAGE ACCESS MONITORING METHOD AND STORAGE ACCESS MONITORING DEVICE
2y 2m to grant Granted Jun 30, 2026
Patent 12670251
STRUCTURING IPV6 ADDRESSES INTO BIT FIELDS TO EMBED LANGUAGE LOCALIZATION AND SERVICES
2y 1m to grant Granted Jun 30, 2026
Patent 12661778
SPARE ROBOT CONTROLLER
3y 8m to grant Granted Jun 23, 2026
Patent 12657287
SYSTEM AND METHOD AND FOR LOADING ENCLAVE-AWARE EXECUTABLES
1y 5m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
77%
Grant Probability
99%
With Interview (+25.3%)
2y 10m (~9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 376 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month