Prosecution Insights
Last updated: October 02, 2026
Application No. 18/788,562

CLIENT-SIDE ANTI-PHISHING SYSTEMS AND METHODS

Final Rejection §103
Filed
Jul 30, 2024
Examiner
HOLLISTER, JAMES ROSS
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Open Text Corporation
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
171 granted / 225 resolved
+18.0% vs TC avg
Strong +24% interview lift
Without
With
+24.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
11 currently pending
Career history
237
Total Applications
across all art units

Statute-Specific Performance

§101
18.3%
-21.7% vs TC avg
§103
54.7%
+14.7% vs TC avg
§102
10.1%
-29.9% vs TC avg
§112
10.8%
-29.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 225 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Summary This action is a responsive to the amendment filed on 6/9/2026. Claims 1-20 are pending and have been examined. Claims 1-20 are rejected. Response to Arguments Rejection of Claims under 35 USC 103 Applicant’s Response: Applicant submits that the cited references fail to teach the newly added limitations. Examiner’s Response: Applicant’s arguments with respect to claims 1, 8, 15 have been considered but are moot because the arguments are directed to amended subject matter properly addressed with the newly cited reference of VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1). The combination of VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1) teaches the language of the independent claims. All remaining arguments are now moot in regards to the new rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-2, 6, 8-9, 13, 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over VINOKUROV et al. (US 20240265074 A1) and further in view of Cao et al. (US 11323476 B1). As to claim 1, VINOKUROV et al. teaches An apparatus, comprising: a processor; a non-transitory computer-readable medium; and instructions stored on the non-transitory computer-readable medium and translatable by the processor for implementing an anti-phishing browser plug-in and an anti-phishing module for: initiating an anti-phishing operation on the apparatus as a user enters a login credential on a web page originating from a website (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered.), the anti-phishing operation comprising: generating a random number of phishing credentials based on the login credential (See ¶¶ [0044]-[0045], [0049], Teaches that credential module 105 modifies (203) the detected credential of interest in accordance with predefined modification rules, thus giving rise to a modified credential. Unless specifically stated otherwise, the terms “credential's modification” and alike refer throughout the specification to any changes of credential's content (e.g. inserting special characteristics, replacing at least part of the characteristics, encrypting, etc.). It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); randomly selecting, from the random number of phishing credentials, a phishing credential (See ¶¶ [0048]-[0049], Teaches that Credential module 105 further replaces (204) the credential of interest in the browsing request by the modified credential such that the modified credential is hidden from the user. It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); and causing a browser application on the apparatus to submit the phishing credential to the website on behalf of the user (See ¶ [0050], Teaches that Credential module 105 enables (205) sending the request with the modified credential to webserver 102. In certain embodiments credential module 105 can release the intercepted CI request upon modifying credential therein. In other embodiments, credential module 105 can block the intercepted request and generate and send, instead, a new request with the modified credential.). However, it does not expressly teach the details of depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page. Cao et al., from analogous art, teaches depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into VINOKUROV et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 2, the combination of VINOKUROV et al. and Cao et al. teaches the apparatus according to claim 1 above. VINOKUROV et al. further teaches wherein the instructions are further translatable by the processor for: receiving an indication that the user is entering the login credential on the web page; capturing user input including the login credential being entered on the webpage (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered). However, it does not expressly teach the details of determining whether the web page comes from a good website, a bad website, or an unknown website. Cao et al., from analogous art, teaches determining whether the web page comes from a good website, a bad website, or an unknown website (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Col 1 Ln 33, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal. The existing technologies in today's market for combating credential phishing include: list-based techniques (whitelisting the authentic site and blacklisting the phony Web site)). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into the combination of VINOKUROV et al. and Cao et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 6, the combination of VINOKUROV et al. and Cao et al. teaches the apparatus according to claim 1 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked. Cao et al., from analogous art, teaches wherein the instructions are further translatable by the processor for: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Col 1 Ln 33, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal. The existing technologies in today's market for combating credential phishing include: list-based techniques (whitelisting the authentic site and blacklisting the phony Web site)). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into the combination of VINOKUROV et al. and Cao et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 8, VINOKUROV et al. teaches A method, comprising: initiating, by an anti-phishing module on a user device, an anti-phishing operation as a user enters a login credential on a web page originating from a website (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered.), the anti-phishing operation comprising: generating a random number of phishing credentials based on the login credential (See ¶¶ [0044]-[0045], [0049], Teaches that credential module 105 modifies (203) the detected credential of interest in accordance with predefined modification rules, thus giving rise to a modified credential. Unless specifically stated otherwise, the terms “credential's modification” and alike refer throughout the specification to any changes of credential's content (e.g. inserting special characteristics, replacing at least part of the characteristics, encrypting, etc.). It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); randomly selecting, from the random number of phishing credentials, a phishing credential (See ¶¶ [0048]-[0049], Teaches that Credential module 105 further replaces (204) the credential of interest in the browsing request by the modified credential such that the modified credential is hidden from the user. It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); and causing a browser application on the user device to submit the phishing credential to the website on behalf of the user (See ¶ [0050], Teaches that Credential module 105 enables (205) sending the request with the modified credential to webserver 102. In certain embodiments credential module 105 can release the intercepted CI request upon modifying credential therein. In other embodiments, credential module 105 can block the intercepted request and generate and send, instead, a new request with the modified credential.). However, it does not expressly teach the details of depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page. Cao et al., from analogous art, teaches depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into VINOKUROV et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 9, the combination of VINOKUROV et al. and Cao et al. teaches the method according to claim 8 above. VINOKUROV et al. further teaches further comprising: receiving an indication that the user is entering the login credential on the web page; capturing user input including the login credential being entered on the webpage (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered). However, it does not expressly teach the details of determining whether the web page comes from a good website, a bad website, or an unknown website. Cao et al., from analogous art, teaches determining whether the web page comes from a good website, a bad website, or an unknown website (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Col 1 Ln 33, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal. The existing technologies in today's market for combating credential phishing include: list-based techniques (whitelisting the authentic site and blacklisting the phony Web site)). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into the combination of VINOKUROV et al. and Cao et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 13, the combination of VINOKUROV et al. and Cao et al. teaches the method according to claim 8 above. However, it does not expressly teach the details of further comprising: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked. Cao et al., from analogous art, teaches further comprising: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Col 1 Ln 33, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal. The existing technologies in today's market for combating credential phishing include: list-based techniques (whitelisting the authentic site and blacklisting the phony Web site)). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into the combination of VINOKUROV et al. and Cao et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 15, VINOKUROV et al. teaches A computer program product comprising a non-transitory computer- readable medium storing instructions translatable by a processor for implementing an anti- phishing browser plug-in and an anti-phishing module on a user device for: initiating an anti-phishing operation on the user device as a user enters a login credential on a web page originating from a website (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered.), the anti-phishing operation comprising: generating a random number of phishing credentials based on the login credential (See ¶¶ [0044]-[0045], [0049], Teaches that credential module 105 modifies (203) the detected credential of interest in accordance with predefined modification rules, thus giving rise to a modified credential. Unless specifically stated otherwise, the terms “credential's modification” and alike refer throughout the specification to any changes of credential's content (e.g. inserting special characteristics, replacing at least part of the characteristics, encrypting, etc.). It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); randomly selecting, from the random number of phishing credentials, a phishing credential (See ¶¶ [0048]-[0049], Teaches that Credential module 105 further replaces (204) the credential of interest in the browsing request by the modified credential such that the modified credential is hidden from the user. It is noted that credential module 105 can be configured to enable selection of one or more credentials to specify credential-involved requests. Likewise, credential module 105 can be configured to enable selection of one or more credentials of interest to be modified and replaced.); and causing a browser application on the user device to submit the phishing credential to the website on behalf of the user (See ¶ [0050], Teaches that Credential module 105 enables (205) sending the request with the modified credential to webserver 102. In certain embodiments credential module 105 can release the intercepted CI request upon modifying credential therein. In other embodiments, credential module 105 can block the intercepted request and generate and send, instead, a new request with the modified credential.). However, it does not expressly teach the details of depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page. Cao et al., from analogous art, teaches depending upon whether the phishing credential is accepted by the website, blocking or allowing access to the website, wherein the allowing comprises allowing the user to re-enter the login credential on the web page (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into VINOKUROV et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). As to claim 16, the combination of VINOKUROV et al. and Cao et al. teaches the computer program product according to claim 15 above. VINOKUROV et al. further teaches wherein the instructions are further translatable by the processor for: receiving an indication that the user is entering the login credential on the web page; capturing user input including the login credential being entered on the webpage (See ¶¶ [0040]-[0041], Teaches that credential module 105 monitors generating a browsing request from client device 100 to webserver 102 to detect (201) submission of a credential of interest (e.g. username, password, email, etc.) into a browsing interface. Credential module 105 analyses the generated browsing request to discover the existence of the credential of interest. and intercepts (202) the request when the credential of interest is discovered). However, it does not expressly teach the details of determining whether the web page comes from a good website, a bad website, or an unknown website. Cao et al., from analogous art, teaches determining whether the web page comes from a good website, a bad website, or an unknown website (See Col 7 Ln 63, Col 10 Ln 12, Col 10 Ln 28, Col 1 Ln 33, Teaches that a check is performed as to whether the Web site has returned a page indicating that the credentials submitted are incorrect or not. If the site returns a page that says that the credentials are correct (or a “Login Success” page, or other indication, etc.), then under the first scenario it is concluded in step 644 that the site is a phishing Web site because if it were a legitimate site, it would have detected the incorrect credentials. In step 644 when software 540 concludes that the site is a phishing site it can take a variety of actions to alert the user, block the site, etc. For example, the software may display a warning page that will be show on the browser. In step 648 when software 540 concludes that the site is a legitimate site it can take a variety of actions such as displaying a window in the browser indicating that the site is not a phishing site, or similar. Or, the software may simply do nothing and allow the user to interact with the Web site, in which case the user submits a valid user name and password and software 540 will not perform the steps of FIG. 6 and will allow the user to log in to the site as normal. The existing technologies in today's market for combating credential phishing include: list-based techniques (whitelisting the authentic site and blacklisting the phony Web site)). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Cao et al. into the combination of VINOKUROV et al. and Cao et al. in order to detection and prevention of credential phishing by a malicious Web site (See Cao et al. Col 1 Ln 9). Claims 3, 10, 17 are rejected under 35 U.S.C. 103 as being unpatentable over VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1) and further in view of Orhan (US 20220174093 A1). As to claim 3, the combination of VINOKUROV et al. and Cao et al. teaches the apparatus according to claim 2 above. However, it does not expressly teach the details of wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL. Orhan, from analogous art, teaches wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL (See ¶ [0020], Teaches that the visited URL 16 is checked within existing blacklist 18 and whitelist 20 of the control layer 2. There are three different possible values for the web page 10 being visited: URL 16 is in whitelist 20, in blacklist 18, URL 16 is neither of the list, thus it is unknown. In step 203 URL 16 is found in whitelist, so the website 12 is known, and it is safe. In step 204 the control layer 2 allows the viewing of the webpage 10 and all further interaction. Thus, there is no further involvement of the proposed control layer 2 until the user 14 visits another web page 10. This guarantees that the user 14 is using the safe/known websites 12 and can submit any sensitive data to these websites and perform any activity on them. In step 205 the URL 16 is found in blacklist 18. In step 206 the web page 10 is blocked. In step 207 the user 14 is informed that the web page 10 is malicious/phishing. In step 208 the URL 16 is not listed in either whitelist 20 or blacklist 18 and the web page 10 is still unknown). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). As to claim 10, the combination of VINOKUROV et al. and Cao et al. teaches the method according to claim 9 above. However, it does not expressly teach the details of wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL. Orhan, from analogous art, teaches wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL (See ¶ [0020], Teaches that the visited URL 16 is checked within existing blacklist 18 and whitelist 20 of the control layer 2. There are three different possible values for the web page 10 being visited: URL 16 is in whitelist 20, in blacklist 18, URL 16 is neither of the list, thus it is unknown. In step 203 URL 16 is found in whitelist, so the website 12 is known, and it is safe. In step 204 the control layer 2 allows the viewing of the webpage 10 and all further interaction. Thus, there is no further involvement of the proposed control layer 2 until the user 14 visits another web page 10. This guarantees that the user 14 is using the safe/known websites 12 and can submit any sensitive data to these websites and perform any activity on them. In step 205 the URL 16 is found in blacklist 18. In step 206 the web page 10 is blocked. In step 207 the user 14 is informed that the web page 10 is malicious/phishing. In step 208 the URL 16 is not listed in either whitelist 20 or blacklist 18 and the web page 10 is still unknown). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). As to claim 17, the combination of VINOKUROV et al. and Cao et al. teaches the computer program product according to claim 16 above. However, it does not expressly teach the details of wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL. Orhan, from analogous art, teaches wherein the web page resides at a universal resource locator (URL), wherein the determining comprises performing a lookup operation on the URL over an offenders database, and wherein the offenders database stores a plurality of URLs, each respective URL of the plurality of URLs having a phishing status indicative of whether the respective URL is a good URL, a phishing URL, or a new URL (See ¶ [0020], Teaches that the visited URL 16 is checked within existing blacklist 18 and whitelist 20 of the control layer 2. There are three different possible values for the web page 10 being visited: URL 16 is in whitelist 20, in blacklist 18, URL 16 is neither of the list, thus it is unknown. In step 203 URL 16 is found in whitelist, so the website 12 is known, and it is safe. In step 204 the control layer 2 allows the viewing of the webpage 10 and all further interaction. Thus, there is no further involvement of the proposed control layer 2 until the user 14 visits another web page 10. This guarantees that the user 14 is using the safe/known websites 12 and can submit any sensitive data to these websites and perform any activity on them. In step 205 the URL 16 is found in blacklist 18. In step 206 the web page 10 is blocked. In step 207 the user 14 is informed that the web page 10 is malicious/phishing. In step 208 the URL 16 is not listed in either whitelist 20 or blacklist 18 and the web page 10 is still unknown). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). Claims 4, 11, 18 are rejected under 35 U.S.C. 103 as being unpatentable over VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1) and Orhan (US 20220174093 A1) and further in view of Yue et al. (US 20110126289 A1). As to claim 4, the combination of VINOKUROV et al. and Cao et al. and Orhan teaches the apparatus according to claim 3 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential; performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Orhan, from analogous art, teaches wherein the instructions are further translatable by the processor for: responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential (See ¶ [0021], Teaches that the user 14 visits an unknown web page 10 (web page might be safe or malicious). In step 302 the control layer 2 checks if there is a form 8 in the web page 10. The form 8 examples are shown in FIGS. 3C and 3D. In step 303 unknown web page 10 has no input form 8. In step 304 the control layer 2 allows the user 14 to interact with the web page 10 and does not block it. For this case the web page 10 is marked as not phishing. In step 305 the form 8 is found in the web page 10. In step 306 the control layer 2 extracts fields from presented form 8. As illustrated, a first field (field1) and a second field (field2) are extracted.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). However, it does not expressly teach the details of performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Yue et al., from analogous art, teaches performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true (See ¶¶ [0038]-[0039], Teaches that computer 50 uses the provided substitution rule to construct a set of derived or possible U/P credentials based upon the U/P submission that caused the failed login attempt. Next, at step 64, computer 50 compares each constructed/possible U/P credential with those in database 52. If there is a match with one of the legitimate U/P credentials, the chances are high that the U/P submission causing the failed login attempt was one generated by the present invention during a phishing attack as described above. If there is no match, the failed login generated by the U/P submission was most likely caused by an innocent error. If the failure of a login attempt is caused by a phisher who is verifying any one of the S U/P credentials it received, the above-described procedure will readily determine if the U/P submission originated from the set of S U/P credentials. Since computer 50 uses the same substitution rule to construct derived U/P credentials based on the U/P submission and then looks for a matching U/P credential with those in database 52, the probability is very high that a match is indicative of U/P submission that originated from a phisher trying to verify S U/P credentials provided thereto by a client computer 10 as described above. The legitimate website can then implement security to thwart the phisher.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Yue et al. into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to generate S fake U/P credentials that appear legitimate by making them generally look like a real username (e.g., janetc, carlwork, etc.) and not a set of randomly-generated letters/numbers (See Yue et al. ¶ [0022]). As to claim 11, the combination of VINOKUROV et al. and Cao et al. and Orhan teaches the method according to claim 10 above. However, it does not expressly teach the details of further comprising responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential; performing a lookup operation on the login credential over a registration database; andresponsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Orhan, from analogous art, teaches further comprising responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential (See ¶ [0021], Teaches that the user 14 visits an unknown web page 10 (web page might be safe or malicious). In step 302 the control layer 2 checks if there is a form 8 in the web page 10. The form 8 examples are shown in FIGS. 3C and 3D. In step 303 unknown web page 10 has no input form 8. In step 304 the control layer 2 allows the user 14 to interact with the web page 10 and does not block it. For this case the web page 10 is marked as not phishing. In step 305 the form 8 is found in the web page 10. In step 306 the control layer 2 extracts fields from presented form 8. As illustrated, a first field (field1) and a second field (field2) are extracted.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). However, it does not expressly teach the details of performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Yue et al., from analogous art, teaches performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true (See ¶¶ [0038]-[0039], Teaches that computer 50 uses the provided substitution rule to construct a set of derived or possible U/P credentials based upon the U/P submission that caused the failed login attempt. Next, at step 64, computer 50 compares each constructed/possible U/P credential with those in database 52. If there is a match with one of the legitimate U/P credentials, the chances are high that the U/P submission causing the failed login attempt was one generated by the present invention during a phishing attack as described above. If there is no match, the failed login generated by the U/P submission was most likely caused by an innocent error. If the failure of a login attempt is caused by a phisher who is verifying any one of the S U/P credentials it received, the above-described procedure will readily determine if the U/P submission originated from the set of S U/P credentials. Since computer 50 uses the same substitution rule to construct derived U/P credentials based on the U/P submission and then looks for a matching U/P credential with those in database 52, the probability is very high that a match is indicative of U/P submission that originated from a phisher trying to verify S U/P credentials provided thereto by a client computer 10 as described above. The legitimate website can then implement security to thwart the phisher.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Yue et al. into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to generate S fake U/P credentials that appear legitimate by making them generally look like a real username (e.g., janetc, carlwork, etc.) and not a set of randomly-generated letters/numbers (See Yue et al. ¶ [0022]). As to claim 18, the combination of VINOKUROV et al. and Cao et al. and Orhan teaches the computer program product according to claim 17 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential; performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Orhan, from analogous art, teaches wherein the instructions are further translatable by the processor for: responsive to not finding the URL of the web page in the offenders database, parsing the user input to obtain the login credential (See ¶ [0021], Teaches that the user 14 visits an unknown web page 10 (web page might be safe or malicious). In step 302 the control layer 2 checks if there is a form 8 in the web page 10. The form 8 examples are shown in FIGS. 3C and 3D. In step 303 unknown web page 10 has no input form 8. In step 304 the control layer 2 allows the user 14 to interact with the web page 10 and does not block it. For this case the web page 10 is marked as not phishing. In step 305 the form 8 is found in the web page 10. In step 306 the control layer 2 extracts fields from presented form 8. As illustrated, a first field (field1) and a second field (field2) are extracted.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Orhan into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to protect users from sending their sensitive information to criminal servers (See Orhan ¶ [0007]). However, it does not expressly teach the details of performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true. Yue et al., from analogous art, teaches performing a lookup operation on the login credential over a registration database; and responsive to finding the login credential in the registration database, setting a phishing status to indicate that the URL of the web page comes from a new website and setting a credential status to indicate that the login credential is true, wherein the initiating is performed responsive to the phishing status being set to new and the credential status being set to true (See ¶¶ [0038]-[0039], Teaches that computer 50 uses the provided substitution rule to construct a set of derived or possible U/P credentials based upon the U/P submission that caused the failed login attempt. Next, at step 64, computer 50 compares each constructed/possible U/P credential with those in database 52. If there is a match with one of the legitimate U/P credentials, the chances are high that the U/P submission causing the failed login attempt was one generated by the present invention during a phishing attack as described above. If there is no match, the failed login generated by the U/P submission was most likely caused by an innocent error. If the failure of a login attempt is caused by a phisher who is verifying any one of the S U/P credentials it received, the above-described procedure will readily determine if the U/P submission originated from the set of S U/P credentials. Since computer 50 uses the same substitution rule to construct derived U/P credentials based on the U/P submission and then looks for a matching U/P credential with those in database 52, the probability is very high that a match is indicative of U/P submission that originated from a phisher trying to verify S U/P credentials provided thereto by a client computer 10 as described above. The legitimate website can then implement security to thwart the phisher.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Yue et al. into the combination of VINOKUROV et al. and Cao et al. and Orhan in order to generate S fake U/P credentials that appear legitimate by making them generally look like a real username (e.g., janetc, carlwork, etc.) and not a set of randomly-generated letters/numbers (See Yue et al. ¶ [0022]). Claims 5, 12, 19 are rejected under 35 U.S.C. 103 as being unpatentable VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1) and Orhan (US 20220174093 A1) and Yue et al. (US 20110126289 A1) and further in view of Singh (US 20230362193 A1). As to claim 5, the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. teaches the apparatus according to claim 4 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: updating the offenders database to reflect whether the website passed or failed the anti-phishing operation. Singh, from analogous art, teaches wherein the instructions are further translatable by the processor for: updating the offenders database to reflect whether the website passed or failed the anti-phishing operation (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). As to claim 12, the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. teaches the method according to claim 11 above. However, it does not expressly teach the details of further comprising: updating the offenders database to reflect whether the website passed or failed the anti- phishing operation. Singh, from analogous art, teaches further comprising: updating the offenders database to reflect whether the website passed or failed the anti- phishing operation (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). As to claim 19, the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. teaches the computer program product according to claim 18 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: updating the offenders database to reflect whether the website passed or failed the anti- phishing operation. Singh, from analogous art, teaches wherein the instructions are further translatable by the processor for: updating the offenders database to reflect whether the website passed or failed the anti- phishing operation (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. and Orhan and Yue et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). Claims 7, 14, 20 are rejected under 35 U.S.C. 103 as being unpatentable VINOKUROV et al. (US 20240265074 A1) and Cao et al. (US 11323476 B1) and further in view of Singh (US 20230362193 A1). As to claim 7, the combination of VINOKUROV et al. and Cao et al. teaches the apparatus according to claim 1 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed. Singh, from analogous art, teaches wherein the instructions are further translatable by the processor for: responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to notify the user if the site passes the test.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). As to claim 14, the combination of VINOKUROV et al. and Cao et al. teaches the method according to claim 8 above. However, it does not expressly teach the details of further comprising: responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed. Singh, from analogous art, teaches further comprising: responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to notify the user if the site passes the test.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). As to claim 20, the combination of VINOKUROV et al. and Cao et al. teaches the computer program product according to claim 15 above. However, it does not expressly teach the details of wherein the instructions are further translatable by the processor for: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked; and responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed. Singh, from analogous art, teaches wherein the instructions are further translatable by the processor for: responsive to the phishing credential being accepted by the website, generating a message indicating that the website has failed the phishing operation and, therefore, access to the website is to be blocked; and responsive to the phishing credential being rejected by the website, generating a message indicating that the website has passed the phishing operation and, therefore, access to the website is allowed (See ¶¶ [0110]-[0111], [0125], Teaches that in the case of an affirmative or successful reply from the suspicious site, the system may determine to execute a precautionary operation, such as terminating the request. This is because an affirmative or successful reply to an incorrect login may indicate the suspicious site is a phishing site, as described in the examples of FIGS. 2B-2C and 3A-3B above. In some examples, the system may terminate the visual instance of the browser and/or may render a notification for the user, such as via a dialog. In some examples, the system may add the site to a blacklist of unsafe or phishing sites, and may thereafter forbid visiting the site. In some examples, the system may share such a blacklist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared blacklist periodically by repeating the method 500. In the case of an unsuccessful reply or an error message, the system may determine to proceed with the request. This is because an unsuccessful reply or an error message may indicate the suspicious site is not a phishing site, as described above. In some examples, the system may add the site to a whitelist of safe or legitimate sites, and may thereafter allow visiting the site. In some examples, the system may share such a whitelist across user sessions or workspace sessions, such as by updating a repository on the workspace server or in the cloud, and/or may update the shared whitelist periodically by repeating the method 500. Next, responsive to the sign in control having reappeared, the workspace application, workspace server, or VDA can proceed 614 with the request. For example, the system may add the site to a whitelist of safe or legitimate sites, share such a whitelist across user sessions or workspace sessions, and/or thereafter allow visiting the site. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to notify the user if the site passes the test.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Singh into the combination of VINOKUROV et al. and Cao et al. in order to receive a request to visit the suspected website, sending an incorrect password to the suspected website, receiving a reply from the suspected website, and determining, based on the reply to the incorrect password, whether to execute a precautionary operation (See Singh ¶ [0014]). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Hollister whose telephone number is (571)270-3152. The examiner can normally be reached Mon - Fri 7:30 am - 4:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. James Hollister /J.R.H./Examiner, Art Unit 2499 9/3/26 /PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Jul 30, 2024
Application Filed
Mar 09, 2026
Non-Final Rejection mailed — §103
May 28, 2026
Interview Requested
Jun 09, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744776
AUTHENTICATION OF MEDICAL DEVICES
3y 0m to grant Granted Sep 22, 2026
Patent 12732486
OBFUSCATION IN PRIVACY BEACON
3y 1m to grant Granted Sep 08, 2026
Patent 12719680
VIRTUAL ACCESS CREDENTIAL INTERACTION SYSTEM AND METHOD
2y 9m to grant Granted Aug 25, 2026
Patent 12701007
System, Method, and Computer Program Product for Third-Party Authorization
1y 9m to grant Granted Aug 04, 2026
Patent 12688276
SHARING CONTAINER DATA INSIDE A TENANT'S POD UNDER DIFFERENT TRUSTED EXECUTION ENVIRONMENTS (TEES)
3y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+24.3%)
2y 7m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 225 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month