Prosecution Insights
Last updated: October 02, 2026
Application No. 18/810,672

DISPLAY DEVICE, DISPLAY METHOD, AND RECORDING MEDIUM

Final Rejection §101§103
Filed
Aug 21, 2024
Priority
Sep 19, 2023 — JP 2023-150831
Examiner
MOLES, JAMES P
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
NEC Corporation
OA Round
2 (Final)
67%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 67% — above average
67%
Career Allowance Rate
32 granted / 48 resolved
+8.7% vs TC avg
Strong +29% interview lift
Without
With
+28.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
14 currently pending
Career history
57
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
67.0%
+27.0% vs TC avg
§102
7.1%
-32.9% vs TC avg
§112
15.2%
-24.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 48 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Acknowledgment is made of applicant's claim for foreign priority to JP 2023-150831. Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55. Response to Amendment This office action is in response to the amendment filed on 06/24/2026. Claims 1-20 are pending. Claims 1, 9, and 15 are independent. Response to Arguments Objections to the claims: Objections to the claims are withdrawn in view of the filed amendment. Rejections under 35 U.S.C. 112(b): Rejections under 35 U.S.C. 112(b) are withdrawn in view of the filed amendment. Rejections under 35 U.S.C. § 101: Applicant’s arguments, see pages 7-8 of Applicant’s Remarks (hereinafter “REMARKS”) with regard to the rejection of the claims under 35 U.S.C. § 101 have been fully considered and are not persuasive. The rejection is maintained as is explained below. Rejections under 35 U.S.C. § 103: Applicant’s arguments, see pages 6-7 of Applicant’s Remarks (hereinafter “REMARKS”) with respect to the rejection of the claims under 35 U.S.C. § 103 have been fully considered and are persuasive. However, upon further consideration and in view of the filed amendment, a new ground(s) of rejection is made over TANIGUCHI et al. (US 2020/0065482; hereinafter “TANIGUCHI”) in view of Paget et al. (US PGPub No. 2023/0081144; hereinafter “Paget”) in view of Shakarian et al. (US Patent No. 11,892,897; hereinafter “Shakarian”) in view of NAM et al. (KR 102382951; hereinafter “NAM”). Shakarian teaches acquiring crime statements of a black-hat community on the deep web (Column 8, lines 25-40; Column 8, lines 41-64). NAM teaches using a tor browser or socks5 proxy for accessing the tor network and collecting information on deep web sites (Page 4, paragraphs 3-5). Therefore, TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of the independent claims 1, 9, and 15, and they are thus rejected. The amendment to the independent claims has necessitated a new ground(s) of rejection with respect to the dependent claims, and they are therefore rejected. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Although each of the claims fall within one of the four statutory categories they are directed to an abstract idea. Claim 1 recites “acquire cyberattack information by analyzing the crime statement, the cyberattack information including information of a damaged company by a plurality of cyberattack groups”. The limitation of acquiring information through analyzing other information, under its broadest reasonable interpretation, but for the use of a generic computer, is a mental process. The claim recites a judicial exception. The additional elements of the claim do not integrate the judicial exception into a practical application. The claim recites “a display device comprising: at least one memory configured to store instructions; and at least one processor configured to execute the instructions to: acquire crime statement of cyberattack groups by web-scraping a website that can be browsed using a dedicated tool including a Tor browser or by performing specific settings including socks5 proxy settings, the cyberattack groups being groups that have conducted a cyberattack …” The additional elements of a processor and memory amount to no more than mere instructions to apply the exception using a generic computer and/or computer components. Furthermore, the use of a Tor browser or using socks5 proxy settings to web-scrape a website for a crime statement is insignificant pre-solution activity. I.e., mere data gathering. The claim also recites “display the cyberattack information of the plurality of cyberattack groups.” Displaying the cyberattack information of the plurality of cyberattack groups is merely insignificant post solution activity. Hence, the claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As explained above with respect to integration of the abstract idea into a practical application, the use of a display device, memory, processor and dedicated tool amount to no more than mere instructions to apply the exception using a generic computer and/or computer component, or insignificant extra-solution activity. Moreover, the additional element of “… using a dedicated tool including a Tor browser or by performing specific settings including socks5 proxy settings …” is merely using the Internet to gather data and is well-understood, routine, and conventional activity in the art, see MPEP 2106.05(d).II.i “Receiving or transmitting data over a network”. See Berkheimer v. HP, Inc., 881 F.3d 1360, 1368, 125 USPQ2d 1649, 1654 (Fed. Cir. 2018). E.g., Immaneni et al. (US PGPub No. 2022/0180368; hereinafter “Immaneni”) teaches accessing special resources using a Tor browser (Tor is software that can be installed into a browser to enable special connections to dark websites that offer hidden services and resources. These hidden services and resources may be provisioned in non-standard top-level domains such as .Onion (dot onion), for example [¶ 0120] and further teaches gathering information on the deep web (In one embodiment, the r-FPRS Engine gathers information from the surface web the deep web and other non-dark web data in addition to the dark web on a continuous basis, and in real time, has a risk score available for a User or the Applicant and/or his credentials [¶ 0134]) Furthermore, Lavi et al. (US PGPub No. 2019/0007440, hereinafter “Lavi”) teaches: (The dark nets which constitute the dark web include small, friend-to-friend peer-to-peer networks, as well as large, popular networks like Freenet, I2P, and Tor, operated by public organizations and individuals [¶ 0004]. To visit a site on the Dark Web that is using Tor encryption, the web user needs to be using Tor [¶ 0006]). Therefore, the claim is not patent eligible. Claim 9 is a method that recites steps corresponding to the functions recited in claim 1. Hence, claim 9 is patent ineligible for substantially the same reasons as claim 1. Claim 15 is a computer readable method claim that records a program for causing a computer to execute the functionality recited in claim 1. The use of a generic computer component as a tool to implement the abstract idea does not integrate the exception into a practical application, nor does it amount to significantly more than the abstract idea. Dependent claims 2-8, 10-14, and 16-20 all recite limitations for manipulating data and displaying the result. Hence, these claims recite mental steps and additional elements that are insignificant post solution activity. Hence, these dependent claims are also not patent eligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-2, 9-10, and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI et al. (US 2020/0065482; hereinafter “TANIGUCHI”) in view of Paget et al. (US PGPub No. 2023/0081144; hereinafter “Paget”) in view of Shakarian et al. (US Patent No. 11,892,897; hereinafter “Shakarian”) in view of NAM et al. (KR 102382951; hereinafter “NAM”). As per claim 1: TANIGUCHI discloses a display device comprising: at least one memory configured to store instructions (a non-transitory computer-readable storage medium storing a program that cause a processor included in an information processing apparatus to execute a process [TANIGUCHI ¶ 0010, ¶ 0082, Fig. 12]); and at least one processor configured to execute the instructions to (a processor included in an information processing apparatus to execute a process [TANIGUCHI ¶ 0010, ¶ 0082, Fig. 12]): [acquire crime statement] of cyberattack groups (collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034, Examiner’s Note: each intelligence includes threat actor information]) [by web-scraping a website that can be browsed] using a dedicated tool (the cyber threat intelligence collection unit 10 collects various cyber threat intelligences by crawling preset sites on the Internet [TANIGUCHI ¶ 0028, Examiner’s Note: settings being the preset sites]; collects the cyber threat intelligence 11 through the Internet and the like and stores the cyber threat intelligence 11 in the cyber threat intelligence DB 20 [TANIGUCHI ¶ 0073]) [including a Tor browser or by performing specific settings including socks5 proxy settings], the cyberattack groups being groups that have conducted a cyberattack (collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034, Examiner’s Note: each intelligence includes threat actor information]); acquire cyberattack information (The evaluation unit 30 of the information processing apparatus 1 refers to the cyber threat intelligence DB 20 and evaluates the number of types of the cyberattacks in which the feature information of the cyberattack appears regarding the feature information of the cyberattack. Furthermore, when receiving the specification of the feature information of the cyberattack by the input unit 40, the evaluation unit 30 responds the evaluation results regarding the number of types of the cyberattacks in which the feature information of the cyberattack appears. The output unit 50 of the information processing apparatus 1 outputs the evaluation results responded by the evaluation unit 30 to a file, a display, and the like [TANIGUCHI ¶ 0073]) by analyzing [the crime statement], the cyberattack information [including information of a damaged company] by a plurality of cyberattack groups (collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034, Examiner’s Note: each intelligence includes threat actor information]) using a dedicated tool or a website browsable by performing specific setting (the cyber threat intelligence collection unit 10 collects various cyber threat intelligences by crawling preset sites on the Internet [TANIGUCHI ¶ 0028, Examiner’s Note: settings being the preset sites]; collects the cyber threat intelligence 11 through the Internet and the like and stores the cyber threat intelligence 11 in the cyber threat intelligence DB 20 [TANIGUCHI ¶ 0073]); and display the cyberattack information (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]) of the plurality of cyberattack groups (collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]). TANIGUCHI discloses the claimed subject matter as discussed above but does not explicitly disclose including information of a damaged company. However, Paget teaches including information of a damaged company (the business intelligence unit 140 discovers a digital footprint and business data of the entity based on the associated domain name and based on non-intrusively gathered information from a computer network 120 and from various connected data sources 110 [Paget ¶ 0025]; A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]; The adjustments can reduce a vulnerability to ransom attacks of cyber infrastructure associated with the one or more of the entities that are analyzed by the cyber-risk assessment system 100 or the user organization(s) [Paget ¶ 0030]). TANIGUCHI and Paget are analogous art because they are from the same field of endeavor of cyberattack analysis. Therefore, based on TANIGUCHI in view of Paget, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Paget to the system of TANIGUCHI in order to analyze attack information to show how remediation from attacks can result in improved cyber security stance conditions (¶ 0030). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. TANIGUCHI in view of Paget discloses the claimed subject matter as discussed above but does not explicitly disclose acquire crime statement by web-scraping a website that can be browsed; the crime statement. However, Shakarian teaches acquire crime statement by web-scraping a website that can be browsed (DW (black-hat community). The data collection infrastructure was summarized. In the present disclosure, the exploit prediction model may be implemented to crawl websites on DW, both marketplaces and forums, to collect data relating to malicious hacking. Sites are first identified before developing scripts for automatic data collection. A site is being put forward to script development after it has been established that the content is of interest (hacking-related) and relatively stable. The population size of the site is being observed, though not much decisive power is assigned to it. While a large population is an indicator for the age and stability of the site, a small population number can be associated with higher-value information (closed forums). While it would be incorrect to label forum users as criminals, there are clearly users communicating malicious intent and sometimes malicious code is exchanged [Column 8, lines 25-40]; Users in DW advertise and sell their wares on marketplaces. Hence, DW marketplaces provide a new avenue to gather information about vulnerabilities and exploits. Forums on the other hand, feature discussions on newly discovered vulnerabilities and exploits kits. Data related to malicious hacking is filtered from the noise and added to a database using a machine learning approach with high precision and recall. Not all exploits or vulnerability items in the database have a CVE number associated with them. First, the subject database may be queried to extract all items with CVE mentions. Some vulnerabilities are mentioned in DW using Microsoft Security Bulletin Number (e.g., MS16-006) every bulletin number was mapped to its corresponding CVE ID, making ground truth assignment easy. These items can be both products sold on markets as well as posts extracted from forums discussing topics relating to malicious hacking. 378 unique CVE mentions were found between 2015 and 2016 from more than 120 DW websites. This number is a lot more than previous works have discovered (n=103). The posting date and descriptions associated with all the CVE mentions were also queried including product title and description, vendor information, entire discussion with the CVE mention, author of the posts, topic of the discussion [Column 8, lines 41-64]); the crime statement (These items can be both products sold on markets as well as posts extracted from forums discussing topics relating to malicious hacking. 378 unique CVE mentions were found between 2015 and 2016 from more than 120 DW websites. This number is a lot more than previous works have discovered (n=103). The posting date and descriptions associated with all the CVE mentions were also queried including product title and description, vendor information, entire discussion with the CVE mention, author of the posts, topic of the discussion [Column 8, lines 41-64]). Shakarian and the instant application are analogous art because they are from the same field of endeavor of data gathering. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Shakarian to the system of TANIGUCHI in view of Paget in order to obtain higher-value information from the source of hacking posts in black-hat communities. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. TANIGUCHI in view of Paget in view of Shakarian discloses the claimed subject matter as discussed above but does not explicitly disclose including a Tor browser or by performing specific settings including socks5 proxy settings. However, NAM teaches including a Tor browser or by performing specific settings including socks5 proxy settings (the deep web cannot be accessed through the general surface web and can be accessed only through a specific program using a special browser such as TOR (The Onion Routers), as well as a number of network nodes (Proxy, Because the network line is configured to allow access only through VPN, etc.), IP tracking is very difficult and anonymization is guaranteed Can not [Page 4, para. 3]; That is, the crawler that targets the Surface Web directly performs crawling in accordance with the HTTP/HTTPS protocol. However, crawling in this way is not possible in the deep web, and as described above, the Tor browser is generally used to access the deep web site. Tor Browser is a browser developed based on the open source Firefox, and is a browser integrated with the Tor program that can access the deep web. When Tor browser is launched to access the deep web, the Tor program is executed together, and HTTP/HTTPS web access requested by the browser is transmitted through the SOCKS5-based proxy port of the Tor network (anonymous network), so that access to the deep web is possible. there is. [Page 4, para. 4]; Accordingly, it is preferable that the deep web malicious code analysis unit 110 analyzes web data of deep web sites by performing crawling by accessing the deep web while mimicking the operation method of the Tor browser through a controllable browser. [Page 4, para. 5, Examiner’s Note: using tor browser to access deep web sites]). NAM and the instant application are analogous art because they are from the same field of endeavor of data gathering. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of NAM to the system of TANIGUCHI in view of Paget in view of Shakarian in order to effectively analyze websites of the deep web through a dedicated tool. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 2: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 1. Furthermore, TANIGUCHI and Paget disclose aggregate a number of cyberattacks for each cyberattack group (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) or each type of damaged company based on the cyberattack information (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]); and display (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]) the number of cyberattacks for each of the cyberattack groups or each of the types (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]). As per claim 9: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 1. The limitations of claim 9 are substantially similar to claim 1 above, and therefore are likewise rejected. As per claim 10: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 9. The limitations of claim 10 are substantially similar to claim 2 above, and therefore the claim is likewise rejected. As per claim 15: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 1. Furthermore, TANIGUCHI discloses A non-transitory computer-readable recording medium that records a program for causing a computer to execute (a non-transitory computer-readable storage medium storing a program that cause a processor included in an information processing apparatus to execute a process [TANIGUCHI ¶ 0010, ¶ 0082, Fig. 12]): The limitations of claim 15 are substantially similar to claim 1 above, and therefore are likewise rejected. As per claim 16: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 15. The limitations of claim 16 are substantially similar to claim 2 above, and therefore the claim is likewise rejected. Claims 3-4, 11-12, and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of KIM et al. (US PGPub No. 2025/0028825; hereinafter “KIM ‘825”). As per claim 3: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose aggregate the number of cyberattacks (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [for each business type of damaged company] (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027, Examiner’s Note: industry is business type]); and display the number of cyberattacks (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [of each business type]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose for each business type of damaged company; of each business type. However, KIM ‘825 teaches for each business type of damaged company (Here, the analyzed CTI includes a document or a script included in the document, an executable or non-executable file, assembly code converted from the file, function information in the code, or maliciousness according to a CFG instruction sequence, a hash value indicating maliciousness, an attack technique, an attack group, an attack campaign, an attack nation, an attack industry, etc. The analyzed CTI includes visualization information of the above analysis information [KIM ¶ 1050, Examiner’s Note: an attack industry]; information on attack actions and attack groups, attack campaigns related to files, attack nations, attack industries, etc [KIM ¶ 1056]); of each business type (Here, the analyzed CTI includes a document or a script included in the document, an executable or non-executable file, assembly code converted from the file, function information in the code, or maliciousness according to a CFG instruction sequence, a hash value indicating maliciousness, an attack technique, an attack group, an attack campaign, an attack nation, an attack industry, etc. The analyzed CTI includes visualization information of the above analysis information [KIM ¶ 1050]). TANIGUCHI in view of Paget in view of Shakarian in view of NAM and KIM ‘825 are analogous art because they are from the same field of endeavor of cyberthreat analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of KIM ‘825, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of KIM ‘825 to the system of TANIGUCHI in view of Paget in view of Shakarian in view of NAM in order to analyze the common attributes of the attack such as the target industry for appropriate response. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 4: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose wherein the at least one processor is further configured to execute the instructions to: aggregate the number of cyberattacks (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) for each host country of the damaged company (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]); and display the number of cyberattacks (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [for the each host country]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose display the number of cyberattacks for the each host country. However, KIM ‘825 teaches display the number of cyberattacks for the each host country (Here, the analyzed CTI includes a document or a script included in the document, an executable or non-executable file, assembly code converted from the file, function information in the code, or maliciousness according to a CFG instruction sequence, a hash value indicating maliciousness, an attack technique, an attack group, an attack campaign, an attack nation, an attack industry, etc. The analyzed CTI includes visualization information of the above analysis information [KIM ¶ 1050, Examiner’s Note: an attack industry]; information on attack actions and attack groups, attack campaigns related to files, attack nations, attack industries, etc [KIM ¶ 1056]). TANIGUCHI in view of Paget in view of Shakarian in view of NAM and KIM ‘825 are analogous art because they are from the same field of endeavor of cyberthreat analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of KIM ‘825, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of KIM ‘825 to the system of TANIGUCHI in view of Paget in order to analyze the common attributes of the attack such as the country for appropriate response. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 11: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 10. The limitations of claim 11 are substantially similar to claim 3 above, and therefore the claim is likewise rejected. As per claim 12: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 10. The limitations of claim 12 are substantially similar to claim 4 above, and therefore the claim is likewise rejected. As per claim 17: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 16. The limitations of claim 17 are substantially similar to claim 3 above, and therefore the claim is likewise rejected. As per claim 18: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 16. The limitations of claim 18 are substantially similar to claim 4 above, and therefore the claim is likewise rejected. Claims 5, 13, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of KIM et al. (KR 20210118321 A, citations refer to English translation; hereinafter “KIM ‘321”). As per claim 5: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose wherein the at least one processor is further configured to execute the instructions to: aggregate the number of cyberattacks (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) for each host country (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]) [of a headquarter of the damaged company]; and display the number of cyberattacks (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) for each host country (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]) [of the headquarter]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose of a headquarter of the damaged company; of the headquarter. However, KIM ‘321 teaches of a headquarter of the damaged company (In this case, the security events may have information such as event generation time, IP address, port number, security event name, operation headquarters, and operating company constituting the corresponding event [Kim ‘321, Page 3, 12th para.]; First, when the name of the operating company, the operating headquarters, and the security equipment exists in the event group, in the case of the operating company node [Kim ‘321, Page 7, 10th para.]); of the headquarter (In this case, the security events may have information such as event generation time, IP address, port number, security event name, operation headquarters, and operating company constituting the corresponding event [Kim ‘321, Page 3, 12th para.]; First, when the name of the operating company, the operating headquarters, and the security equipment exists in the event group, in the case of the operating company node [Kim ‘321, Page 7, 10th para.]). TANIGUCHI in view of Paget and KIM ‘321 are analogous art because they are from the same field of endeavor of cyberattack analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of KIM ‘321, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of KIM ‘321 to the system of TANIGUCHI in view of Paget in view of Shakarian in view of NAM in order to analyze the common attributes of the attack such as the headquarters for appropriate response. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 13: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 10. The limitations of claim 13 are substantially similar to claim 5 above, and therefore the claim is likewise rejected. As per claim 19: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 16. The limitations of claim 19 are substantially similar to claim 5 above, and therefore the claim is likewise rejected. Claims 6, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of Talbot et al. (US PGPub No. 2022/0294819; hereinafter “Talbot”). As per claim 6: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose wherein the at least one processor is further configured to execute the instructions to: aggregate the number of cyberattacks of each of the cyberattack groups (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) or each type of damaged company (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]) [a predetermined period of time ago]; and display (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [a difference in the number of cyberattacks from the predetermined period of time ago]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose a predetermined period of time ago; a difference in the number of cyberattacks from the predetermined period of time ago. However, Talbot teaches a predetermined period of time ago (the visual cyber-attack representation details different cyber-attack types in different dialogue boxes and this facilitates the user and/or administrator to visualize, in real-time, a current cyber-attack threat frequency state of an enterprise computing environment. In some embodiment, the visual cyber-attack representation details a likelihood of a cyber-attack, of an enterprise computing environment. The bottom of each dialogue box may have a graph to illustrate the frequencies of each cyber-attack type. Each of the dialogue boxes may also have one or more numeric values 401. In some embodiments, a numeric value 401, by way of example, may be the number of times on an annual basis that cyber-attacks of a cyber-attack type are expected to occur, succeed and/or cause harm. In some embodiments, the numeric value 401 is the cyber-attack event frequency value [¶ 0061]); a difference in the number of cyberattacks from the predetermined period of time ago (the visual cyber-attack representation details different cyber-attack types in different dialogue boxes and this facilitates the user and/or administrator to visualize, in real-time, a current cyber-attack threat frequency state of an enterprise computing environment. In some embodiment, the visual cyber-attack representation details a likelihood of a cyber-attack, of an enterprise computing environment. The bottom of each dialogue box may have a graph to illustrate the frequencies of each cyber-attack type. Each of the dialogue boxes may also have one or more numeric values 401. In some embodiments, a numeric value 401, by way of example, may be the number of times on an annual basis that cyber-attacks of a cyber-attack type are expected to occur, succeed and/or cause harm. In some embodiments, the numeric value 401 is the cyber-attack event frequency value [¶ 0061]). TANIGUCHI in view of Paget in view of Shakarian in view of NAM and Talbot are analogous art because they are from the same field of endeavor of cyberattack analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of Talbot, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Talbot to the system of TANIGUCHI in view of Paget in view of Shakarian in view of NAM in order to analyze the common attributes of the attack such as the time period for appropriate response and prediction. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 14: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 10. The limitations of claim 14 are substantially similar to claim 6 above, and therefore the claim is likewise rejected. As per claim 20: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 16. The limitations of claim 20 are substantially similar to claim 6 above, and therefore the claim is likewise rejected. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of COSTEA et al. (US PGPub No. 2021/0136089; hereinafter “COSTEA”). As per claim 7: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose wherein the at least one processor is further configured to execute the instructions to: aggregate the number of cyberattacks for each of the cyberattack groups (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) or each type of damaged company (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]) [in each predetermined period]; and display the number of cyberattacks (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [in each predetermined period]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose in each predetermined period; in each predetermined period. However, COSTEA teaches in each predetermined period (he clusters of instances of the cyberattack can be analyzed, based on visualizations and interpretations of cluster segments of the instance of the activity (e.g., cyberattack segments), to generate multi-attribute cluster-identifiers. For example, by clustering emails in a single cyberattack campaign over a period of time (e.g., days, weeks, months, etc.), malicious activity management operations can assist in determining the nature of the cyberattack and its impact. Features of a campaign, such as IOCs, spanning a large dataset are identified and showcase a cybercriminal's infrastructure used for email sending and payload hosting [¶ 0033]); in each predetermined period (he clusters of instances of the cyberattack can be analyzed, based on visualizations and interpretations of cluster segments of the instance of the activity (e.g., cyberattack segments), to generate multi-attribute cluster-identifiers. For example, by clustering emails in a single cyberattack campaign over a period of time (e.g., days, weeks, months, etc.), malicious activity management operations can assist in determining the nature of the cyberattack and its impact. Features of a campaign, such as IOCs, spanning a large dataset are identified and showcase a cybercriminal's infrastructure used for email sending and payload hosting [¶ 0033]). TANIGUCHI in view of Paget in view of Shakarian in view of NAM and COSTEA are analogous art because they are from the same field of endeavor of cyberattack analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of COSTEA, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of COSTEA to the system of TANIGUCHI in view of Paget in view of Shakarian in view of NAM in order to analyze the common attributes of the attack such as specific time periods for effective response and further detection. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of FALKOWITZ et al. (US PGPub NO. 2016/0134648; hereinafter “FALKOWITZ”). As per claim 8: TANIGUCHI in view of Paget in view of Shakarian in view of NAM teach all the limitations of claim 2. Furthermore, TANIGUCHI and Paget disclose wherein the at least one processor is further configured to execute the instructions to: aggregate [a cumulative number] of the number of cyberattacks for each of the cyberattack groups (evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]; collects various cyber threat intelligences [TANIGUCHI ¶ 0027, Examiner’s Note: plural intelligences]; explaining the cyber threat intelligence … Structured Threat Information eXpression (STIX) … eight information groups … cyberattack activities (Campaigns), attackers (Threat_Actors) [TANIGUCHI ¶ 0029]; in an area 11/ sandwiched by tags of "Threat_Actors", information regarding a person/organization for contributing to the cyberattack is individually described from viewpoints of a type of the attacker of the cyberattack, synchronization of the attacker, a skill of the attacker, an intention of the attacker … an account of a social network service [TANIGUCHI ¶ 0034]) or each of the types (A ransomware attacks database 130 stores statistical information related to real ransomware attacks, for example, the industry, size, country, and digital footprint of the target organization, the attack method, the cyber identity of the attacker, etc., that is generated using the non-intrusively gathered information from the computer network 120 and from the data sources 110 [Paget ¶ 0027]) [from a predetermined time]; and display (Outputs the evaluation results … to a file, a display, and the like [TANIGUCHI ¶ 0060]; The monitor 103 displays, for example, various screens operated by the operator [TANIGUCHI ¶ 0081]; evaluates the number of types of the cyberattacks (campaign and malware) in which the element appears regarding each element indicating the feature of the cyberattack such as the observable (IP, domain, hash value, and the like) [TANIGUCHI ¶ 0036-0037]) [the cumulative number]. TANIGUCHI in view of Paget in view of Shakarian in view of NAM discloses the claimed subject matter as discussed above but does not explicitly disclose a cumulative number of the cyberattacks from a predetermined time; the cumulative number. However, FALKOWITZ teaches a cumulative number of the cyberattacks from a predetermined time (The operations of block 236, 238 may comprise generating and displaying data at a user computer or workstation that is coupled to security control computer 120 for the purpose of trend analysis, geographic analysis, or other reporting relating to threats. For example, risk reports relating to a particular enterprise computer 112 or compromised computer 106 may be generated that catalog all threats that have been identified. Other reports or graphics may indicate total attacks by geographic location, total attacks of different types by hour, day or other period [¶ 0099]); the cumulative number (The operations of block 236, 238 may comprise generating and displaying data at a user computer or workstation that is coupled to security control computer 120 for the purpose of trend analysis, geographic analysis, or other reporting relating to threats. For example, risk reports relating to a particular enterprise computer 112 or compromised computer 106 may be generated that catalog all threats that have been identified. Other reports or graphics may indicate total attacks by geographic location, total attacks of different types by hour, day or other period [¶ 0099]). TANIGUCHI in view of Paget in view of Shakarian in view of NAM and FALKOWITZ are analogous art because they are from the same field of endeavor of attack analysis. Therefore, based on TANIGUCHI in view of Paget in view of Shakarian in view of NAM in view of FALKOWITZ, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of FALKOWITZ to the system of TANIGUCHI in view of Paget in view of Shakarian in view of NAM in order to analyze the common attributes of the attack such as a cumulative number of attacks in a time period for effective response and further detection. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES P MOLES whose telephone number is (703)756-1043. The examiner can normally be reached M-F 8:00am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES P MOLES/Examiner, Art Unit 2494 /JUNG W KIM/Supervisory Patent Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Aug 21, 2024
Application Filed
Mar 25, 2026
Non-Final Rejection mailed — §101, §103
Jun 13, 2026
Interview Requested
Jun 24, 2026
Examiner Interview Summary
Jun 24, 2026
Response Filed
Sep 14, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743521
Systems and Methods for Merging Performance and Security into a Unit Testing Environment
4y 4m to grant Granted Sep 22, 2026
Patent 12732388
NON-FUNGIBLE TOKEN (NFT) BASED INTELLIGENT DOCUMENT PROTOCOLS
3y 4m to grant Granted Sep 08, 2026
Patent 12724884
Adaptive Incident Prioritization Based on User Feedback
2y 3m to grant Granted Sep 01, 2026
Patent 12705362
METHOD, APPARATUS, SYSTEM AND COMPUTER PROGRAM FOR IDENTIFYING AND RESPONDING TO QUANTUM VULNERABILITY USING DYNAMIC ANALYSIS FOR APPLICATION
2y 2m to grant Granted Aug 11, 2026
Patent 12671592
METHOD AND APPARATUS FOR ESTABLISHING END-TO-END SECURITY IN WIRELESS COMMUNICATION SYSTEM
3y 6m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
67%
Grant Probability
95%
With Interview (+28.6%)
2y 9m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 48 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month