Prosecution Insights
Last updated: October 02, 2026
Application No. 18/785,068

HIGHLY EFFICIENT WEBPAGE CODE-PATTERNS MATCHING FOR MALICIOUS WEBSITES DETECTION

Final Rejection §101
Filed
Jul 26, 2024
Examiner
ABYANEH, ALI S
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
2 (Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
490 granted / 630 resolved
+19.8% vs TC avg
Strong +56% interview lift
Without
With
+55.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
20 currently pending
Career history
660
Total Applications
across all art units

Statute-Specific Performance

§101
18.5%
-21.5% vs TC avg
§103
50.1%
+10.1% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 630 resolved cases

Office Action

§101
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-8 and 14-25 are pending. Response to Arguments Applicant's arguments filed 07-08-2026 have been fully considered. With respect to rejections of claims under 35 USC § 101, Applicant argues that “It can easily be determined that the present claims are directed to eligible subject matter because they are not directed to any of the ineligible concepts ("judicial exceptions"). The claims are directed to detecting malicious content in a webpage based on pattern matching against indexes of malware code patterns. The malicious content detection is described throughout the Specification and is embodied in the independent claims with detailed recitation of how to perform lookups in positionally aligned indexes of malware code patterns for efficient malicious content detection”. In response, the claims, however, are directed to abstract idea of identifying whether a webpage includes malicious content by extracting and comparing information from the webpage with stored malware code pattern. In particular, the claimed steps of extracting a code pattern from a webpage, selecting a code from the extracted code pattern, looking up the selected codes in an index of malware code patterns, and determining that the webpage includes malicious content based on a successful lookup constitute evaluation and compassion of information. The additional recitation of determining a positional indexing, selecting a code according to the positional indexing, and performing a lookup does not change the underlying nature of the claim activity as information analysis and comparison. The claim’s recitation of determining positional indexing for each index, selecting a code from the first code pattern according to the positional indexing, and looking up the selected code in the corresponding index merely specifies the manner in which information is selected and compared. Such recitations, even if allegedly providing greater lookup efficiency, do not by themselves render the claimed information analysis non-abstract. Applicant’s reliance on the asserted efficiency of the lookup is likewise not persuasive. Applicant’s claim does not recite a specific improvement to the operation of a computer, processor, memory, network, or other underlying computer technology. Rather, the alleged improvement is an improvement in the manner of searching and comparing malware code patterns, i.e., an improvement to the abstract information -analysis process itself. Merely performing abstract idea more quickly or efficiently using a computer does not, by itself, integrate the abstract idea into a practical application. The USPTO’s subject-matter-eligibility guidance requires that an additional element provides a meaningful technological application of the exception rather than merely reciting the use of a computer to perform the abstract activity. Applicant argues that “Without the proper Alice/Mayo analysis, the Office overgeneralizes the claims as a human looking at a webpage and writing codes on paper”. Applicant further asserts that “The office selects snippets of the claims to interpret the claim to transform the claim into a person writing down codes on paper.” Applicant’s characterization is not persuasive. The office has considered the claim as a whole, including the recitations concerning extracting a first code pattern from the webpage, determining positional indexing for each of the plurality of malware code pattern indexes, selecting a code according to the positional indexing, and performing the lookup. These limitations, considered collectively, are directed to analyzing and comparing information to determine whether the webpage includes malicious content. The particular manner in which the information is selected and searched does not change the fact that the claimed operations are directed to analyzing and comparing information. Applicant argues that “The office does not look to the written description to understand the problem.” Applicant further contends that “Otherwise, it would have be clear that a person writing down codes on paper would not detect malicious content on a webpage with high efficiency.” This argument is also not persuasive. The specification may be considered to understand the claimed invention and the asserted improvement; however, an asserted improvement described in the specification does not, by itself, establish that the claims are directed to technological improvement. Here, the alleged improvement is efficiency results from the manner in which the malware code information selected and searched, rather than from an improvement to the operation of a computer or another technology. Applicant further argues that “The office does not consider whether the description and claims explain how to achieve the highly efficient malicious content detection and does not consider the claim language or the written description.” In response, the office has considered both the claim language and the specification. However, the fact that the specification describes the claimed technique as providing highly efficient malicious content detection does not, by itself, establish that the claimed subject matter is directed to a technological improvement. The claimed positional indexing and successive lookups specify how information is selected and compared to identify manicous content, but do not recite a modification or improvement to the operation of the computer itself or to another technology. Accordingly, Applicant’s characterization of the claimed technique as highly efficient does not alter the determination that the claimed operations are directed to analyzing and comparing information. Applicant further arguers that “The Office has not looked to the written description to understand the problem and claimed solution, nor has the Office considered whether the claims and written description teach how to implement the highly efficient malicious content detection against indexes of malware code patterns having different positional indexing”. This argument is unpersuasive for the same reason discussed above. Event assuming that claimed positional indexing provide more efficient malware-pattern searching, the claimed improvement is directed to the efficiency of information-analysis process, rather than an improvement in computer functionality or another technological field. Accordingly, the particularity of the claimed indexing technique does not remove the claim form the Judaical exception. Applicant’s argument with respect to rejection of claims 1, 14 and 21 under 35 USC §112 is persuasive. The rejections have been withdrawn. Applicant’s argument with respect to rejections of claims under 35 USC §103 is persuasive. The rejections of claims have been withdrawn. Claim Rejections - 35 USC § 101 835 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-8 and 14-25 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims when analyzed under 2019 Revised Patent Subject Matter Eligibility Guidance, are directed to abstract idea. Claim 1 for example, recites a method and, therefore, is a process. The claim recites the limitation of “…determining whether a webpage include malicious content based on pattern matching…extracting a first code pattern from the webpage…performing a lookup in each index of a plurality of malware code pattern based on a different code pattern until a successful lookup…of the plurality of malware code pattern has been accessed…determining positional indexing of the index…selecting the code in the first code pattern according to optional indexing …looking up the selected code in the index…based on successful lookup, determining webpage include malicious content; and based on a determination…indicating the one of the plurality of malware code patterns returned …”. These limitations, under broadest reasonable interpretation are directed performance of the limitation in a human mind. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, the claim encompasses a human simply by looking at a webpage could extract a first code pattern form the webpage and compare different codes of the first code with a plurality of malware code pattern displayed or written on a piece of paper until a successful match is detected. A human by looking at an index or table displayed or written on a piece of paper that includes positional data of index could determine positional indexing, selecting a code form the first code pattern according to the positional indexing, comparing it to the index, determining malicious webpage based on comparison, and indicating the malware code patterns detected from the successful lookup. Claim is further analyzed in step 2A prong 2, to evaluate whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by identifying whether there are any additional elements recited in the claim beyond the judicial exception, and evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. However, each of the remaining limitations appears to be generic computer functions which do not constitute meaningful limitations that would amount to significantly more than the abstract idea. The combination of this additional element is no more than generic computer functions. Thus, even in combination, additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limitations on practicing the abstract idea. Claim is additionally analyzed under Step 2B to evaluate whether the claim as a whole amount to significantly more than the recited exception, whether any additional element, or combination of additional elements, adds an inventive concept to the claim. When claims are evaluated under step 2B, it is no more than what is well-understood, routine, conventional activity in the field. The specification does not provide any indication anything other than a generic computer component. The mere …extracting a first code pattern from the webpage…performing a lookup in each index of a plurality of malware code pattern…determining positional indexing of the index…selecting the code in the first code pattern…looking up the selected code in the index…based on successful lookup, determining webpage include malicious content…indicating the one of the plurality of malware code patterns returned…is a well-understood, routing and conventional function when it is claimed in a merely generic manner as it is here. Independent claims 14 and 21 include limitations similar to the limitations of claim 1 and are rejected under 35 U.S.C. 101 as being directed to abstract idea for the same reasons discussed above with respect to claim 1. In claims 2, 15 and 22, an alignment includes left, right, and middle with respect to code in a code pattern is considered as extra solution activity of gathering data for use in the claimed process. Insignificant extra-solution activity does not amount to an inventive concept. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose meaningful limits on practicing abstract idea. In claim 3, 16 and 23, selecting the code in the first code pattern by determining which code in the first code patten corresponds to the alignment indicated by the positional indexing of the index; and selecting the code at the position indicated by positional indexing of the index relative to the determined alignment code, could be performed by a human. The claims do not recite additional element that amount to significantly more than the judicial exception. Claims 4, 17 and 24 recite, wherein selecting the code in the first code pattern according to the positional indexing of the index comprises: determining that the alignment for the index is middle, wherein determining which code in the first code pattern corresponds to the alignment comprises determining which code in the first code pattern corresponds to the middle of the first code pattern, and wherein selecting the code at the position indicated by the positional indexing comprises selecting the code at the position relative to the determined middle code of the first code pattern. However, determining that alignment for the index is middle, determining which code in the first code pattern corresponds to the middle of the first code pattern and selecting the code at the position relative to the determined middle code of the code pattern could be performed by a human. Claims do not recite additional element that amount to significantly more than the judicial exception. In claim 5, 18 and 25, looking up the first code pattern in the index based on the selected code comprises searching the index for the selected code and, if found, determining whether the first code pattern matches the one of the malware code patterns indexed by the index matching the selected code, could be performed by a huma. A human could simply search an index of codes written on a piece of paper and look for the first code pattern and determine if the first code pattern matches one of the malware code patterns. Claims do not recite additional element that amount to significantly more than the judicial exception. Claim 6 adds that a code of a code pattern corresponds to one of a JavaScript section of a webpage, a form section of a webpage, a title section of a webpage, a cascading style sheet section of a webpage, an iframe section of a webpage, a header section of a hypertext transfer protocol (HTTP) request or response, and an image section of a webpage, which is considered as insignificant extra solution activity of gathering data for use in the claimed process. Insignificant extra-solution activity does not amount to an inventive concept. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose meaningful limits on practicing abstract idea. Claim 7, recites, looking up the selected code in the index comprises hashing the selected code and determining whether the hash of the selected code occurs in the index. However, hashing the selected code could be performed by a human through mathematical operation using a pen and paper. The human could look at the hash result on the paper and determine if the hash of the selected code occurs in the index shown on a display or paper. Claim does not recite additional element that amounts to significantly more than the judicial exception. Claim 8, recites, searching a second plurality of malware code patterns for a match with the first code pattern based on failure of the successive lookups, wherein the second plurality of malware code patterns is not covered by the indexes of the plurality of malware code patterns. A human could search a second plurality of malware patterns by looking at a list, for a match with a first code pattern. Additionally, the second plurality of malware code patterns is not covered by the indexes of the plurality of malware code patterns is considered as insignificant extra solution activity of gathering data for use in the claimed process. Insignificant extra-solution activity does not amount to an inventive concept. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose meaningful limits on practicing abstract idea. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Ali Abyaneh whose telephone number is (571) 272-7961. The examiner can normally be reached on Monday-Friday from (8:00-5:00). If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone numbers for the organization where this application or proceeding is assigned as (571) 273-8300 Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /ALI S ABYANEH/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Jul 26, 2024
Application Filed
Apr 09, 2026
Non-Final Rejection mailed — §101
Jun 17, 2026
Interview Requested
Jul 07, 2026
Applicant Interview (Telephonic)
Jul 08, 2026
Response Filed
Jul 11, 2026
Examiner Interview Summary
Sep 22, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12717935
INLINE CRYPTOGRAPHIC ENGINE FOR STORAGE CONTROLLERS
3y 7m to grant Granted Aug 25, 2026
Patent 12719917
System and method for generating dynamic remote based isolation configurations based on application specific cyber threats
2y 3m to grant Granted Aug 25, 2026
Patent 12712887
VISUALIZATION TOOL FOR REAL-TIME NETWORK RISK ASSESSMENT
2y 0m to grant Granted Aug 18, 2026
Patent 12695789
SYSTEM AND METHOD TO CREATE ZERO TRUST FRAMEWORK FOR SECURITY AS A SERVICE
4y 3m to grant Granted Jul 28, 2026
Patent 12651063
OBTAINING IMMUTABLE SNAPSHOTS IN STORAGE SYSTEMS FOR RECOVERY AFTER CORRUPTED DATA DETECTION
2y 4m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+55.7%)
3y 3m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 630 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month