Prosecution Insights
Last updated: August 17, 2026
Application No. 18/796,255

CYBERSECURITY RISK ANALYSIS AND ANOMALY DETECTION USING ACTIVE AND PASSIVE EXTERNAL RECONNAISSANCE

Final Rejection §102§103
Filed
Aug 06, 2024
Priority
Oct 28, 2015 — CIP of 14/925,974 +15 more
Examiner
HUANG, CHENG-FENG
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Qomplx LLC
OA Round
2 (Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
423 granted / 483 resolved
+29.6% vs TC avg
Strong +17% interview lift
Without
With
+16.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
22 currently pending
Career history
503
Total Applications
across all art units

Statute-Specific Performance

§101
16.9%
-23.1% vs TC avg
§103
58.2%
+18.2% vs TC avg
§102
3.7%
-36.3% vs TC avg
§112
10.8%
-29.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 483 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This is a reply to the amendment filed on 02/23/2026, in which, claim(s) 1-12 are pending. No claim(s) are cancelled or newly added. Response to Arguments Double Patenting Rejection: Applicant submitted an eTD on 02/23/2026 to overcome DP rejection of Patent 12,058,177. The eTD has been approved. The DP rejection of Patent 12,058,177 has been withdrawn. Applicant’s remarks regarding double patenting rejection of Patent 11,750,659 and Patent 11,025,674 have been acknowledged and are persuasive. Therefore, the double patenting rejection Patent 11,750,659 and Patent 11,025,674 is withdrawn. Claim Rejections - 35 U.S.C. § 102 and 35 U.S.C. § 103: Applicants’ arguments, see pages 9-13, filed 02/23/2026, regarding the U.S.C. 102 and 103 rejections of claims 1-12 have been fully considered and are not persuasive. Applicants argue that “neither Crosby alone nor in combination with Wang teaches or suggests "a graph of an organization" with "nodes representing entities associated with the organization and edges representing relationships between these entities."”, Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Crosby teaches a graph of an organization with nodes and edges ([0034], “generating a graph of nodes and edges…data object in an enterprise system”, see also Figs. 3 & 4, [0050-0051]). Applicants argue that “neither Crosby alone nor in combination with Wang teaches or suggests "applying the results of the reconnaissance search to the graph to create a profile of the organization”, Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Crosby teaches “forward the search results to user system 108 for display… to generate and update search graph” ([0029], [0016], “records of an enterprise can be effectively searched and ranked”). Applicants argue that “Wang does not teach or suggest "assigning a score to each node within the graph, indicating the importance of the entity represented by that node"”, Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Wang teaches risk score with each user (i.e., node) ([0062], “Risks associated with user behavior changes may be determined through analysis of past behavior compared to current behavior. For example, for a particular user, all domains, port numbers, IP addresses, destination countries, etc., that the user accessed during a certain period of time are stored and the behavior of traffic of that user to any new domain, IP address, destination countries that the user has never been before is monitored. Based on this data, a user-behavior based risk score may be generated”, [0099-0102]). Applicants argue that “Wang does not disclose "determine an effectiveness score for the network based on the graph and the risk value"”, Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Wang teaches determine an effectiveness score for the network” ([0099], “Using the domain corpus, the centralized controller 240 may run graph analytics modeling such as belief propagation or page rank to assign a risk score to each domain in the domain corpus, which is periodically and repeatedly updated as new data is collected. The data analysis engine 220 can query the centralized controller 240 for the domain risk score and/or access a local cache of the global intelligence stored on the data analysis engine for the domain risk score.”). Besides, in response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Therefore, the rejection is maintained. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1-12 are rejected under 35 U.S.C. 103 as being unpatentable over Jed Crosby (US 20160350442 A1) in view of Jisheng Wang (US 2015/0373039 A1). Regarding Claims 1, 4, 7 and 10, Crosby discloses creating a graph of an organization using information about the organization, the graph comprising nodes representing entities associated with the organization and edges representing relationships between these entities ([0034], “an arrangement of log nodes and log node pairs for generating a graph of nodes and edges… Each log line may be generated when a user interacts or “clicks” on a data object in an enterprise system”); performing a reconnaissance search using the graph ([0029], “The search query may be processed by enterprise server 104, which sends a request to search graph database 120”); applying the results of the reconnaissance search to the graph to create a profile of the organization ([0029], “Upon receiving search results from search graph database 120, enterprise server 104 may forward the search results to user system 108 for display on a display device of user system 108. Independently, enterprise server 104 may retrieve and process data from log database 112 and CRM database 116 over an extended time to generate and update search graph data stored in search graph database 120”); Crosby does not explicitly teach but Wang teaches using the graph and the reconnaissance search results to: assign a score to each node within the graph, indicating the importance of the entity represented by that node ([0099], “where the probability threat score information is received from the centralized controller 240”, [0102], “generates a threat score for domain 1 at operation 745”); identify risks associated with each node to which a score was assigned ([0062], “The entity risk modeling engine 340 models and monitors the risk of threats for each individual user of the customer for a certain duration of time”); identify an anomalous event based on analysis of the graph and the reconnaissance search results ([0005], “techniques for profiling the behavior of an individual entity (e.g., user, machine, service, etc.) and monitoring that entity for anomalous behavior”, [0043], “The flow records 282 allow the data analysis engine 220 (or network sensor engine 200.sub.1 itself) to formulate a threat exposure mapping (e.g., display of communication paths undertaken by network devices within the enterprise network 140), which may be used to detect anomalous communication patterns through deviations in normal communications by one or more of the network devices, such as an endpoint device”); assign a risk value to the identified anomalous event, determined based on the score of the associated node ([0062], “a user-behavior based risk score may be generated”, [0099], “run graph analytics modeling such as belief propagation or page rank to assign a risk score to each domain in the domain corpus”); and determine an effectiveness score for the network based on the graph and the risk value ([0099], “run graph analytics modeling such as belief propagation or page rank to assign a risk score to each domain in the domain corpus…The data analysis engine 220 can query the centralized controller 240 for the domain risk score and/or access a local cache of the global intelligence stored on the data analysis engine for the domain risk score”). Crosby and Wang are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Wang with the disclosure of Crosby. The motivation/suggestion would have been to use Pathfinder algorithm to monitoring that entity for anomalous behavior (Wang, [0104]). Regarding Claims 2, 5, 8 and 11, the combined teaching of Crosby and Wang teaches wherein the information about the organization further comprises information about processes within the organization (Crosby, [0029], “Upon receiving search results from search graph database 120, enterprise server 104 may forward the search results to user system 108 for display on a display device of user system 108. Independently, enterprise server 104 may retrieve and process data from log database 112 and CRM database 116 over an extended time to generate and update search graph data stored in search graph database 120”). Regarding Claims 3, 6, 9 and 12, the combined teaching of Crosby and Wang teaches wherein the information about the organization further comprises historical information for the organization (Crosby, [0031], “Each log may be structured to include a “history” or sequential list of log lines for each user action recorded in the log”), Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHENG-FENG HUANG whose telephone number is (571)272-6186. The examiner can normally be reached Monday-Friday: 9 am - 5 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHENG-FENG HUANG/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Aug 06, 2024
Application Filed
Nov 21, 2025
Non-Final Rejection mailed — §102, §103
Feb 23, 2026
Response Filed
May 26, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12707257
METHOD AND DEVICE FOR MANAGING SECURITY DOMAIN ACCESS INFORMATION OF MIGRATED USERS
2y 9m to grant Granted Aug 11, 2026
Patent 12699430
FLIGHT COMPONENT SIGNAL AUTHENTICATION
2y 2m to grant Granted Aug 04, 2026
Patent 12701106
ONGOING TRIGGER-BASED SCANNING OF CYBER-PHYSICAL ASSETS
2y 0m to grant Granted Aug 04, 2026
Patent 12695773
Behavioral Risk Scoring Framework for Performing Security Analytics
3y 8m to grant Granted Jul 28, 2026
Patent 12695733
FINGERPRINT-BASED NETWORK MAPPING OF CYBER-PHYSICAL ASSETS
2y 2m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+16.8%)
2y 5m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 483 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month