Prosecution Insights
Last updated: August 17, 2026
Application No. 18/785,888

Data Exfiltration Monitoring Using Hash Values

Non-Final OA §101§102§103§DOUBLEPATENT
Filed
Jul 26, 2024
Priority
Apr 23, 2024 — IN 202441032032
Examiner
HERZOG, MADHURI R
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
Netapp Inc.
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
90%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
529 granted / 676 resolved
+20.3% vs TC avg
Moderate +12% lift
Without
With
+12.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
23 currently pending
Career history
706
Total Applications
across all art units

Statute-Specific Performance

§101
13.6%
-26.4% vs TC avg
§103
47.0%
+7.0% vs TC avg
§102
11.6%
-28.4% vs TC avg
§112
17.7%
-22.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 676 resolved cases

Office Action

§101 §102 §103 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 4-9 have been cancelled. Claims 10-26 have been newly added. Claims 1-3 and 10-26 have been examined. Election/Restrictions Applicant’s election without traverse of claims 1-3 from group I in the reply filed on 02/17/2026 is acknowledged. Priority Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55. Information Disclosure Statement The information disclosure statement (IDS) submitted on 04/07/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 10-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter. Claim 10 is directed to a system comprising a data protection service and a monitoring service. According to paragraph [0027] of the specification of the instant application: “Data protection service 110 is representative of a software service that provides data protection services…” and according to [0028]: “Monitoring service 120 is representative of a software service that is capable of monitoring dark web 130”. Therefore, claim 10 is directed software per se which is non-statutory. Claims 11-20 are also directed to software per se and are also non-statutory. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-3 and 10-26 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of copending Application No. 18/785766 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because: Instant application Copending Application No. 18/785766 1. (Original) A method of operating a data protection service, comprising: identifying one or more first hash values, each of the first hash values specifically identifying an enterprise data item of a plurality of enterprise data items in a data volume; querying a monitoring service with the one or more first hash values; receiving results from the monitoring service, wherein the results comprise an indication that at least one of the enterprise data items has been exfiltrated; and initiating a mitigation action. 10. (New) A system comprising: a data protection service configured to: identify one or more first hash values, each of the first hash values specifically identifying an enterprise data item of a plurality of enterprise data items in a data volume, query a monitoring service with the one or more first hash values, receive results from the monitoring service, wherein the results comprise an indication that at least one of the enterprise data items has been exfiltrated, and initiate a mitigation action. 18. (New) The system of claim 17, wherein the data protection service is further configured to detect the potential breach by: generating a semantic description of the data volume, querying the monitoring service with the semantic description, and receiving, from the monitoring service, an indication that exfiltrated data matches the semantic description. 1. A method of operating a data protection service, comprising: Claim 3: generating the hash value associated with the data item; Claim 7: querying an enterprise system for the semantic description of the data volume, querying the monitoring service with a request to determine if the hash value matches a corresponding hash value of any of a plurality of exfiltrated data items; and receiving, from the monitoring service, an indication that one of the plurality of exfiltrated data items has a matching hash value. Claim 1: initiating a mitigation action. 8. (Currently Amended) A system for operating a data protection service, the system comprising: Claim 10: generating the hash value associated with the data item; Claim 14: querying an enterprise system for the semantic description of the data volume, querying the monitoring service with a request to determine if the hash value matches a corresponding hash value of any of a plurality of exfiltrated data items; and receiving, from the monitoring service, an indication that one of the plurality of exfiltrated data items has a matching hash value; claim 8: initiate a mitigation action. Claim 8: generate a semantic description of a data volume, the semantic description comprising a natural-language description categorizing a set of data items in the data volume; query the monitoring service with the semantic description, and determine whether the breach occurred based on results received from the monitoring service in response to the semantic description; This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 10, 12, 21, and 23 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by US 10498748 to Fridman et al (hereinafter Fridman). As per claims 1, 10, and 21, Fridman teaches: A method of operating a data protection service, comprising: identifying one or more first hash values, each of the first hash values specifically identifying an enterprise data item of a plurality of enterprise data items in a data volume (Fridman: column 6, lines 63-67: the enterprise, such as Enterprise A, prepares a database of data to be protected. Column 7, lines 1-20: Accordingly, the database 62 is forward hashed or encoded using a hasher 64 on the premises of the enterprise data network to generate a pre-index. The hasher 64 applies a forward hash function to the database 62. In this manner, the hasher 64 generates the pre-index of hashed data values from the clear text data in the database 62. Storing a database in a data volume was well known to one of ordinary skill in the art before the effective filing date of the claimed invention); querying a monitoring service with the one or more first hash values (Fridman: column 7, lines 26-27 and 66-67 and column 8, lines 1-4 and 20-50: With the pre-index thus generated, the hasher 64 uploads the pre-index to a multi-tenant cloud service 45. In cloud DLP system 50, the indexer cluster 52 is notified when the upload of the pre-index is complete. The indexer cluster 52 downloads the pre-index from the cloud service 45 and performs processing on the pre-index data to generate a search index of the pre-index which contains hash values of the database to be protected. The detection cluster 54 pulls or downloads the search index from cloud service 45. At the cloud DLP system 50, the detection cluster 54 receives data content or data files that belong to the enterprise for examination. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then searches the data content in the hashed data files using the search index to detect for matched content); receiving results from the monitoring service, wherein the results comprise an indication that at least one of the enterprise data items has been exfiltrated (Fridman: column 8, lines 52-67: in the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations. In the present example, the detection cluster 54 detects for data loss violations (data exfiltration) by using the search index to find matching data content from the hashed data content. Claim 1: determine that data that should not be outside the enterprise is outside the enterprise); and initiating a mitigation action (Fridman: column 8, lines 52-60: the detection cluster 54 may be configured to apply remediation measures). As per claims 12 and 23, Fridman teaches: The system of claim 10, wherein: the identifying the one or more first hash values comprises identifying a plurality of hash values, each specifically identifying one of a plurality of enterprise data items in the data volume, the results further comprise an indication that a subset of the plurality of enterprise data items has been exfiltrated (Fridman: column 8, lines 29-67: At the cloud DLP system 50, the detection cluster 54 receives data content or data files that belong to the enterprise for examination. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then searches the data content in the hashed data files using the search index to detect for matched content. In the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations. The detection cluster 54 may be configured to apply remediation measures, such as deleting or quarantining the data content containing the violation, i.e., a subset of data content is identified as exfiltrated). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 2, 11, 14-16, and 22 are rejected under 35 U.S.C. 103 as being unpatentable over Fridman and US 11201728 to Bouchard et al (hereinafter Bouchard). As per claims 2, 11, and 22, Fridman teaches: The method of claim 1 wherein: the identifying the one or more first hash values comprises generating the one or more first hash values using a hashing algorithm (Fridman: Column 7, lines 1-20: The hasher 64 applies a forward hash function to the database 62. In this manner, the hasher 64 generates the pre-index of hashed data values from the clear text data in the database 62), and the indication that at least one of the plurality of enterprise data items has been exfiltrated (Fridman: column 8, lines 29-67: At the cloud DLP system 50, the detection cluster 54 receives data content or data files that belong to the enterprise for examination. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then searches the data content in the hashed data files using the search index to detect for matched content. In the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations). Fridman teaches determining that enterprise data has been exfiltrated but does not teach: to a dark web. However, Bouchard teaches: the indication that at least one of the plurality of enterprise data items has been exfiltrated to a dark web (Bouchard: column 4, lines 50-67: a centralized data leakage mitigation service can utilize the disclosed example data leakage mitigation solutions to search multiple data sources (e.g., public websites, public data services, the dark web, etc.) and compare the protected data fingerprints in the blockchain with fingerprints of data items found on those data sources to identify leaked data items corresponding to the protected data items represented by the protected data fingerprints in the blockchain. column 15, lines 53-66: For example, if the leaked data item is verified and also corresponds to a protected data item with a protected data fingerprint in the fingerprint database 410, the leaked data notifier 430 issues the data leakage notification to indicate that the leaked data item is associated with the protected data item and has been verified). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Bouchard in the invention of Fridman to include the above limitations. The motivation to do so would be to perform data leakage mitigation with a blockchain (Bouchard: column 2, lines 46-47). As per claim 14, Fridman teaches: The system of claim 10, further comprising: the monitoring service configured to: (Fridman: column 8, lines 29-40: At the cloud DLP system 50, the detection cluster 54 receives data content or data files that belong to the enterprise for examination. For example, data files or network data traffic can be provided by the network intermediary 25 which intercepts network traffic to and from the enterprise. The data files can be files being uploaded or downloaded to or from the enterprise data network, i.e., the data files are not obtained from the data protection service. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content.). Fridman does not teach: scrape a dark web to obtain exfiltrated data items. However, Bouchard teaches: scrape a dark web to obtain exfiltrated data items (Bouchard: column 4, lines 50-67: a centralized data leakage mitigation service can utilize the disclosed example data leakage mitigation solutions to search multiple data sources (e.g., public websites, public data services, the dark web, etc.) and compare the protected data fingerprints in the blockchain with fingerprints of data items found on those data sources to identify leaked data items corresponding to the protected data items represented by the protected data fingerprints in the blockchain). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Bouchard in the invention of Fridman to include the above limitations. The motivation to do so would be to perform data leakage mitigation with a blockchain (Bouchard: column 2, lines 46-47). As per claim 15, Fridman in view of Bouchard teaches: The system of claim 14, wherein the monitoring service is further configured to: obtain the one or more first hash values from the data protection service (Fridman: column 6, lines 63-67: the enterprise, such as Enterprise A, prepares a database of data to be protected. Column 7, lines 1-27: Because the database 62 contains sensitive data, the database 62 cannot leave the enterprise premises in clear text. Accordingly, the database 62 is forward hashed or encoded using a hasher 64 on the premises of the enterprise data network to generate a pre-index. The hasher 64 applies a forward hash function to the database 62. In this manner, the hasher 64 generates the pre-index of hashed data values from the clear text data in the database 62. With the pre-index thus generated, the hasher 64 uploads the pre-index to a multi-tenant cloud service 45.), compare the one or more first hash values with the associated hash values, generate the results based on at least one match between the one or more first hash values and the associated hash values, and provide the results to the data protection service (Fridman: column 8, lines 46-56: The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then searches the data content in the hashed data files using the search index to detect for matched content. I3n the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations). As per claim 16, Fridman in view of Bouchard teaches: The system of claim 15, wherein: the data protection service is further configured to generate each of the first hash values by processing the associated enterprise data item with a hashing algorithm (Fridman: Column 7, lines 1-27: Accordingly, the database 62 is forward hashed or encoded using a hasher 64 on the premises of the enterprise data network to generate a pre-index. The hasher 64 applies a forward hash function to the database 62. In this manner, the hasher 64 generates the pre-index of hashed data values from the clear text data in the database 62), and the monitoring service is further configured to generate the associated hash values using the same hashing algorithm, thereby facilitating the detection of exfiltrated data matching enterprise data (Fridman: column 8, lines 46-56: The cloud DLP system 50 is provided with the key 65 used by the enterprise to perform forward hashing of the database 62. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content). Claims 3, 13, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Fridman and US 11750625 to Sharma et al (hereinafter Sharma). As per claim 3, Fridman teaches: The method of claim 1, wherein: the identifying the one or more first hash values comprises identifying a plurality of hash values, each specifically identifying one of a plurality of enterprise data items in the data volume, the results further comprise an indication that a subset of the plurality of enterprise data items has been exfiltrated (Fridman: column 8, lines 29-67: At the cloud DLP system 50, the detection cluster 54 receives data content or data files that belong to the enterprise for examination. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then searches the data content in the hashed data files using the search index to detect for matched content. In the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations. The detection cluster 54 may be configured to apply remediation measures, such as deleting or quarantining the data content containing the violation, i.e., a subset of data content is identified as exfiltrated), and Fridman does not teach: the initiating the mitigation action comprises: estimating an extent of a data breach based at least on a number of enterprise data items in the subset, and generating a report indicating the extent of the data breach. However, Sharma teaches: the initiating the mitigation action comprises: estimating an extent of a data breach based at least on a number of enterprise data items in the subset, and generating a report indicating the extent of the data breach (Sharma: column 6, lines 20-22 and 44-46: Returning to FIG. 2, the breach detection component 208 is configured to detect or otherwise identify a data breach. In response to a breach, the remediation component 210 may instruct the monitoring component 202 to determine the extent of the breach. The extent of the breach may be determined by the volume (number) of customer information that is compromised. Column 10, lines 13-16: Additionally, law enforcement may be notified (generating a report) of the extent of a breach along with the list of compromised customers). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Sharma in the invention of Fridman to include the above limitations. The motivation to do so would be to initiate remediation as a function of risk severity (Sharma: column 1, lines 38-39). As per claims 13 and 24, Fridman does not teach the limitations of claim 13. However, Sharma teaches: wherein the mitigation action comprises: estimating an extent of a data breach based at least on a number of enterprise data items in the subset, and generating a report indicating the extent of the data breach (Sharma: column 6, lines 20-22 and 44-46: Returning to FIG. 2, the breach detection component 208 is configured to detect or otherwise identify a data breach. In response to a breach, the remediation component 210 may instruct the monitoring component 202 to determine the extent of the breach. The extent of the breach may be determined by the volume (number) of customer information that is compromised. Column 10, lines 13-16: Additionally, law enforcement may be notified (generating a report) of the extent of a breach along with the list of compromised customers). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Sharma in the invention of Fridman to include the above limitations. The motivation to do so would be to initiate remediation as a function of risk severity (Sharma: column 1, lines 38-39). Claims 17 and 25 are rejected under 35 U.S.C. 103 as being unpatentable over Fridman and US 20210409435 to Gowda et al (hereinafter Gowda). As per claim 17, Fridman teaches: The system of claim 10, wherein: the system further comprises the data volume, the data protection service is further configured to detect a potential breach of the data volume, and the querying with the one or more first hash values is performed to verify the potential breach (Fridman: column 6, lines 63-67: the enterprise, such as Enterprise A, prepares a database of data to be protected. Storing a database in a data volume was well known to one of ordinary skill in the art before the effective filing date of the claimed invention. Column 8, lines 46-67: The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content. In the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations. In the present example, the detection cluster 54 detects for data loss violations (data exfiltration) by using the search index to find matching data content from the hashed data content). Fridman teaches data breach of a database but does not explicitly teach: detect a potential breach of the data volume. However, Gowda teaches: detect a potential breach of the data volume (Gowda: [0032]: One or more embodiments include applying such techniques at storage layers such as LUNs (data volume) and file systems to detect data breach patterns). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Gowda in the invention of Fridman to include the above limitations. The motivation to do so would be to detect security threats in storage systems using artificial intelligence (AI) techniques (Gowda: [0003]). As per claim 25, Fridman teaches: The computer-readable storage media device of claim 21, wherein the program instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to: wherein the querying with the one or more first hash values is performed in response to detecting the potential breach (Fridman: Column 8, lines 46-67: The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content. In the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert). Fridman does not teach: detect a potential breach of the data volume. However, Gowda teaches: detect a potential breach of the data volume (Gowda: [0032]: One or more embodiments include applying such techniques at storage layers such as LUNs and file systems to detect data breach patterns. [0035]-[0036]: Additionally, as depicted in FIG. 2, real-time performance and capacity data (derived from one or more storage objects of a storage system) are evaluated by the machine learning security threat detection model 214 to detect one or more data patterns therein. If at least one such detected pattern matches a security threat-related pattern (as determined via the machine learning security threat detection model 214), a security threat detection output 216 is generated). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Gowda in the invention of Fridman to include the above limitations. The motivation to do so would be to detect security threats in storage systems using artificial intelligence (AI) techniques (Gowda: [0003]). Claims 18, 19, and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Fridman in view of Gowda as applied to claims 17 and 25 above, and further in view of WO 2025087520 A1 to Pogorelik et al (hereinafter Pogorelik). As per claims 18 and 26, Fridman in view of Gowda does not teach the limitations of claim 18. However, Pogorelik teaches: wherein the data protection service is further configured to detect the potential breach by: generating a semantic description of the data volume, querying the monitoring service with the semantic description, and receiving, from the monitoring service, an indication that exfiltrated data matches the semantic description (Pogorelik: page 6, lines 1-20: In operation, at step 102, the method 100 includes obtaining one or more semantic interpretations of an input text with a generative pre-trained transformer, GPT, configured for interpreting the input text with reference to a target context. In other words, the GPT is configured to analyze and generate one or more semantic interpretations of the input text. Furthermore, at step 104, the method 100 includes determining whether the input text includes a hidden data leakage by checking the semantic interpretations of the input text with a data leak prevention, DLP, system configured for detecting a data leakage based on a collection of words and phrases of interest. The DLP system utilizes the collection of words and phrases of interest that can be used to check the semantic interpretations of the input text with the data leak prevention. Moreover, the corresponding words and phrases of interest are indicative of sensitive information or data leakage. Therefore, if any of the words or phrases from the collection of the words and phrases of interest are detected within the semantic interpretations, then, in such a case, the data leakage is detected). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Pogorelik in the invention of Fridman in view of Gowda to include the above limitations. The motivation to do so would be to mitigate the risk of sensitive information being leaked through semantic manipulation (Pogorelik: page 5, lines 25-26). As per claim 19, Fridman in view of Gowda and Pogorelik teaches: The system of claim 18, wherein the semantic description comprises a natural- language description of at least a portion of data items in the data volume (Pogorelik: page 10, lines 6-15: Furthermore, the probing engine 206 is configured for obtaining one or more semantic interpretations of the input text 212 by loading the input text 212 to the GPT 210 configured for interpreting the input text 212 with reference to the target context. The GPT 210 refers to a specialized component or model that is used for natural language processing to analyze and generate human-like text based on the input text 212 and targeted context). The examiner provides the same rationale to combine prior arts Fridman in view of Gowda and Pogorelik as in claim 18 above. Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Fridman in view of Gowda and Pogorelik as applied to claim 18 above, and further in view of Bouchard. As per claim 20, Fridman in view of Gowda and Pogorelik teaches: The system of claim 18, further comprising: the monitoring service configured to: (Pogorelik: page 6, lines 1-20: In operation, at step 102, the method 100 includes obtaining one or more semantic interpretations of an input text with a generative pre-trained transformer, GPT, configured for interpreting the input text with reference to a target context. In other words, the GPT is configured to analyze and generate one or more semantic interpretations of the input text. Furthermore, at step 104, the method 100 includes determining whether the input text includes a hidden data leakage by checking the semantic interpretations of the input text with a data leak prevention, DLP, system configured for detecting a data leakage based on a collection of words and phrases of interest. The DLP system utilizes the collection of words and phrases of interest that can be used to check the semantic interpretations of the input text with the data leak prevention. Moreover, the corresponding words and phrases of interest are indicative of sensitive information or data leakage. Therefore, if any of the words or phrases from the collection of the words and phrases of interest are detected within the semantic interpretations, then, in such a case, the data leakage is detected). Fridman in view of Gowda and Pogorelik does not teach: scrape a dark web to obtain exfiltrated data items. However, Bouchard teaches: scrape a dark web to obtain exfiltrated data items (Bouchard: column 4, lines 50-67: a centralized data leakage mitigation service can utilize the disclosed example data leakage mitigation solutions to search multiple data sources (e.g., public websites, public data services, the dark web, etc.) and compare the protected data fingerprints in the blockchain with fingerprints of data items found on those data sources to identify leaked data items corresponding to the protected data items represented by the protected data fingerprints in the blockchain). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Bouchard in the invention of Fridman in view of Gowda and Pogorelik to include the above limitations. The motivation to do so would be to perform data leakage mitigation with a blockchain (Bouchard: column 2, lines 46-47). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 10412102 to Fridman et al: A system for providing data loss prevention services includes an indexer system configured to generate a search index based on structured data to be protected and a detection system configured to receive the search index and network data content and to detect in the network data content for matching data based on the search index. The detection system includes a first processor and multiple graphical processing units. The first processor provides words from the network data content in parallel to each of the graphical processing units, each graphical processing unit receiving a different word from the network data content. The graphical processing units perform detection of the words in parallel to detect for matched data content in at least a portion of the search index. US 11582248 to El-Moussa: A computer implemented method to detect a data breach in a network-connected computing system including generating, at a trusted secure computing device, a copy of data distributed across a network; the computing device accessing sensitive information for the network-connected computer system and searching for at least part of the sensitive information in the copy of the data; in response to an identification of sensitive information in the copy of the data identifying the sensitive information as compromised sensitive information. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MADHURI R HERZOG whose telephone number is (571)270-3359. The examiner can normally be reached 8:30AM-4:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at (571)272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. MADHURI R. HERZOG Primary Examiner Art Unit 2438 /MADHURI R HERZOG/Primary Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Jul 26, 2024
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705379
METHODS AND APPARATUS FOR USING SCAN OPERATIONS TO PROTECT SECURE ASSETS
5y 1m to grant Granted Aug 11, 2026
Patent 12682083
CRYPTOSYSTEM MIGRATION FOR SECURE BOOT SEQUENCES
2y 8m to grant Granted Jul 14, 2026
Patent 12670277
ACCESS CONTROL LIST (ACL) AND ROLE-BASED ACCESS CONTROL (RBAC) MANAGEMENT USING CONTENT-BASED DATASETS
3y 8m to grant Granted Jun 30, 2026
Patent 12671718
System and Method for Quantum-Enabled Cyber Security in a Wireless Mobile Network
2y 2m to grant Granted Jun 30, 2026
Patent 12652540
METHOD AND ELECTRONIC DEVICE FOR DETERMINING SECURITY THREAT ON RADIO ACCESS NETWORK
2y 10m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
90%
With Interview (+12.0%)
2y 11m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 676 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month