Prosecution Insights
Last updated: October 02, 2026
Application No. 18/774,051

SYSTEM FOR ENHANCED ANOMALY RECOGNITION IN NETWORK TOPOLOGIES USING INTERACTIVE VISUALIZATION

Final Rejection §103§DP
Filed
Jul 16, 2024
Priority
May 22, 2023 — continuation of 12/095,607
Examiner
BOUTAH, ALINA A
Art Unit
2458
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
2 (Final)
90%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
761 granted / 847 resolved
+31.8% vs TC avg
Moderate +9% lift
Without
With
+9.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
24 currently pending
Career history
860
Total Applications
across all art units

Statute-Specific Performance

§101
14.0%
-26.0% vs TC avg
§103
38.8%
-1.2% vs TC avg
§102
18.8%
-21.2% vs TC avg
§112
15.4%
-24.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 847 resolved cases

Office Action

§103 §DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the amendment filed April 14, 2026. Claims 1, 8, and 15 have been amended. Claims 1-20 are pending. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,095,607. See the corresponding claim table below. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims in the present application are an obvious variation of patent. For example, the present independent claims, as amended, further recites isolating the end-point device by placing the end-point device in a quarantine network. Before the effective filing date of the invention, one of ordinary skill in the art would have been motivated to place end-point in a quarantine as a way to isolate it so its faults would not spread to other devices. Present Application U.S. Patent No. 12,095,607 1. A system for anomaly recognition in network topologies using interactive visualization, the system comprising: a processing device; a non-transitory storage device containing instructions when executed by the processing device, causes the processing device to: determine that an end-point device is associated with anomalous activity; capture, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolate, using the virtual reality application, network traffic associated with the anomalous activity; initiate spatial and temporal traffic analysis on the anomalous activity; determine a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; isolate the end-point device by placing the end-point device in a quarantine network segment in response to determining that the end-point device is associated with anomalous activity; and implement the remedial action on the isolated end-point device to mitigate the effects of the anomalous activity. 2. The system of claim 1, wherein executing the instructions further causes the processing device to: determine, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiate an access management evaluation on the initiator and the recipient; determine access controls associated with the initiator and the recipient contributing to the anomalous activity; and initiate a reassessment of the access controls associated with the initiator and the recipient. 3. The system of claim 1, wherein executing instructions to capture the real-time network traffic further causes the processing device to: generate a multi-dimensional model of the real-time network traffic associated with the end-point device; and display, via the virtual reality application, the multi-dimensional model to a user. 4. The system of claim 3, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 5. The system of claim 3, wherein executing the instructions further causes the processing device to: receive, via the user input device, a user selection of one or more data layers from the stack of data layers; generate the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and display, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 6. The system of claim 3, wherein executing the instructions further causes the processing device to: determine that the end-point device is associated with a device administrator; trigger an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receive a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generate a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 7. The system of claim 6, wherein a level of access associated with the controlled access version of the multi-dimensional model is based on an authorization level of the device administrator. 8. A computer program product for anomaly recognition in network topologies using interactive visualization, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to: determine that an end-point device is associated with anomalous activity; capture, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolate, using the virtual reality application, network traffic associated with the anomalous activity; initiate spatial and temporal traffic analysis on the anomalous activity; determine a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; isolate the end-point device by placing the end-point device in a quarantine network segment in response to determining that the end-point device is associated with anomalous activity; and implement the remedial action on the isolated end-point device to mitigate the effects of the anomalous activity. 9. The computer program product of claim 8, wherein the code further causes the apparatus to: determine, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiate an access management evaluation on the initiator and the recipient; determine access controls associated with the initiator and the recipient contributing to the anomalous activity; and initiate a reassessment of the access controls associated with the initiator and the recipient. 10. The computer program product of claim 9, wherein the code further causes the apparatus to: generate a multi-dimensional model of the real-time network traffic associated with the end-point device; and display, via the virtual reality application, the multi-dimensional model to a user. 11. The computer program product of claim 10, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 12. The computer program product of claim 10, wherein the code further causes the apparatus to: receive, via the user input device, a user selection of one or more data layers from the stack of data layers; generate the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and display, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 13. The computer program product of claim 10, wherein the code further causes the apparatus to: determine that the end-point device is associated with a device administrator; trigger an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receive a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generate a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 14. The computer program product of claim 13, wherein a level of access associated with the controlled access version of the multi-dimensional model is based on an authorization level of the device administrator. 15. A method for anomaly recognition in network topologies using interactive visualization, the method comprising: determining that an end-point device is associated with anomalous activity; capturing, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolating, using the virtual reality application, network traffic associated with the anomalous activity; initiating spatial and temporal traffic analysis on the anomalous activity; determining a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; isolating the end-point device by placing the end-point device in a quarantine network segment in response to determining that the end-point device is associated with anomalous activity; and implementing the remedial action on the isolated end-point device to mitigate the effects of the anomalous activity. 16. The method of claim 15, wherein the method further comprises: determining, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiating an access management evaluation on the initiator and the recipient; determining access controls associated with the initiator and the recipient contributing to the anomalous activity; and initiating a reassessment of the access controls associated with the initiator and the recipient. 17. The method of claim 15, wherein the method further comprises: generating a multi-dimensional model of the real-time network traffic associated with the end-point device; and displaying, via the virtual reality application, the multi-dimensional model to a user. 18. The method of claim 17, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 19. The method of claim 18, wherein the method further comprises: receiving, via the user input device, a user selection of one or more data layers from the stack of data layers; generating the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and displaying, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 20. The method of claim 17, wherein the method further comprises: determining that the end-point device is associated with a device administrator; triggering an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receiving a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generating a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 1. A system for anomaly recognition in network topologies using interactive visualization, the system comprising: a processing device; a non-transitory storage device containing instructions when executed by the processing device, causes the processing device to: determine that an end-point device is associated with anomalous activity; capture, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolate, using the virtual reality application, network traffic associated with the anomalous activity; initiate spatial and temporal traffic analysis on the anomalous activity; determine, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiate an access management evaluation on the initiator and the recipient; determine access controls associated with the initiator and the recipient contributing to the anomalous activity; initiate a reassessment of the access controls associated with the initiator and the recipient; determine a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; and implement the remedial action on the end-point device. 7. The system of claim 1, wherein executing the instructions further causes the processing device to: isolate the end-point device in response to determining that the end-point device is associated with anomalous activity; and implement the remedial action on the isolated end-point device to mitigate the effects of the anomalous activity. 2. The system of claim 1, wherein executing instructions to capture the real-time network traffic further causes the processing device to: generate a multi-dimensional model of the real-time network traffic associated with the end-point device; and display, via the virtual reality application, the multi-dimensional model to a user. 3. The system of claim 2, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 4. The system of claim 3, wherein executing the instructions further causes the processing device to: receive, via the user input device, a user selection of one or more data layers from the stack of data layers; generate the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and display, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 5. The system of claim 2, wherein executing the instructions further causes the processing device to: determine that the end-point device is associated with a device administrator; trigger an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receive a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generate a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 6. The system of claim 5, wherein a level of access associated with the controlled access version of the multi-dimensional model is based on an authorization level of the device administrator. 8. A computer program product for anomaly recognition in network topologies using interactive visualization, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to: determine that an end-point device is associated with anomalous activity; capture, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolate, using the virtual reality application, network traffic associated with the anomalous activity; initiate spatial and temporal traffic analysis on the anomalous activity; determine, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiate an access management evaluation on the initiator and the recipient; determine access controls associated with the initiator and the recipient contributing to the anomalous activity; and initiate a reassessment of the access controls associated with the initiator and the recipient; determine a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; and implement the remedial action on the end-point device. 14. The computer program product of claim 8, wherein the code further causes the apparatus to: isolate the end-point device in response to determining that the end-point device is associated with anomalous activity; and implement the remedial action on the isolated end-point device to mitigate the effects of the anomalous activity. 9. The computer program product of claim 8, wherein the code further causes the apparatus to: generate a multi-dimensional model of the real-time network traffic associated with the end-point device; and display, via the virtual reality application, the multi-dimensional model to a user. 10. The computer program product of claim 9, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 11. The computer program product of claim 10, wherein the code further causes the apparatus to: receive, via the user input device, a user selection of one or more data layers from the stack of data layers; generate the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and display, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 12. The computer program product of claim 9, wherein the code further causes the apparatus to: determine that the end-point device is associated with a device administrator; trigger an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receive a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generate a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 13. The computer program product of claim 12, wherein a level of access associated with the controlled access version of the multi-dimensional model is based on an authorization level of the device administrator. 15. A method for anomaly recognition in network topologies using interactive visualization, the method comprising: determining that an end-point device is associated with anomalous activity; capturing, using a virtual reality application installed on a user input device, real-time network traffic associated with the end-point device; isolating, using the virtual reality application, network traffic associated with the anomalous activity; initiating spatial and temporal traffic analysis on the anomalous activity; determining, using the virtual reality application, an initiator and a recipient associated with the anomalous activity based on the spatial and temporal traffic analysis; initiating an access management evaluation on the initiator and the recipient; determining access controls associated with the initiator and the recipient contributing to the anomalous activity; initiating a reassessment of the access controls associated with the initiator and the recipient; determining a remedial action based on the spatial and temporal traffic analysis to mitigate effects of the anomalous activity; and implementing the remedial action on the end-point device. 16. The method of claim 15, wherein the method further comprises: generating a multi-dimensional model of the real-time network traffic associated with the end-point device; and displaying, via the virtual reality application, the multi-dimensional model to a user. 17. The method of claim 16, wherein the multi-dimensional model further comprises a stack of data layers for visualization of the real-time network traffic, wherein the stack of data layers comprises a network topology layer, a network traffic layer, a performance metric layer, an incident layer, an application data layer, and nodal information layer. 18. The method of claim 17, wherein the method further comprises: receiving, via the user input device, a user selection of one or more data layers from the stack of data layers; generating the multi-dimensional model of the real-time network traffic by overlaying the one or more data layers on one another; and displaying, via the virtual reality application, the multi-dimensional model with the one or more data layers overlaid on one another to the user. 19. The method of claim 16, wherein the method further comprises: determining that the end-point device is associated with a device administrator; triggering an access prompt on a computing device associated with the device administrator to allow the device administrator to access the multi-dimensional model of the real-time network traffic; receiving a request from the computing device of the device administrator to access the multi-dimensional model in response to the access prompt; and generating a controlled access version of the multi-dimensional model of the real-time network traffic in response to the request. 20. The method of claim 19, wherein a level of access associated with the controlled access version of the multi-dimensional model is based on an authorization level of the device administrator. Response to Arguments Double Patenting The double patenting rejection over co-pending Application 18/774,011 is withdrawn because the co-pending application is amended to be significantly different from the present claims. However, the claims, as currently amended, is not sufficient to overcome the double patenting rejection over U.S. Patent No. 12,095,607, therefore is rejection is sustained. Claim Rejections - 35 USC § 103 The claim amendment and Applicant’s arguments are sufficient to overcome the rejection. Therefore, it is withdrawn. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALINA N BOUTAH whose telephone number is (571)272-3908. The examiner can normally be reached M-F 7:00 AM - 3:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at (571) 270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. ALINA BOUTAH Primary Examiner Art Unit 2458 /ALINA A BOUTAH/Primary Examiner, Art Unit 2458
Read full office action

Prosecution Timeline

Jul 16, 2024
Application Filed
Jan 14, 2026
Non-Final Rejection mailed — §103, §DP
Apr 14, 2026
Response Filed
May 06, 2026
Applicant Interview (Telephonic)
May 18, 2026
Final Rejection mailed — §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748876
PROXY AND VETO SERVICES IN DATA PRIVACY INTEGRATION SCENARIOS
2y 2m to grant Granted Sep 29, 2026
Patent 12745126
APPARATUSES, SYSTEMS AND METHODS FOR CONTROLLING TRAFFIC IN A CELLULAR NETWORK BASED ON RENEWABLE ENERGY UTILIZATION OF THE CELLULAR NETWORK
2y 7m to grant Granted Sep 22, 2026
Patent 12744703
SYSTEM FOR ENHANCED ANOMALY RECOGNITION IN NETWORK TOPOLOGIES USING INTERACTIVE VISUALIZATION
2y 2m to grant Granted Sep 22, 2026
Patent 12739204
PACKET PROCESSING METHOD AND RELATED APPARATUS
3y 1m to grant Granted Sep 15, 2026
Patent 12739045
METHOD AND A SYSTEM FOR CREATING MULTI-PORT NETWORK SYNCHRONIZATION BRIDGE
2y 3m to grant Granted Sep 15, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+9.3%)
2y 7m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 847 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month