Prosecution Insights
Last updated: October 02, 2026
Application No. 18/811,998

SYSTEM AND METHOD FOR GENERATING A BASELINE MODE OF OPERATION FROM NETWORK AND APPLICATION LOGS

Final Rejection §101§102§103§112
Filed
Aug 22, 2024
Examiner
SAVENKOV, VADIM
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
2 (Final)
61%
Grant Probability
Moderate
3-4
OA Rounds
1y 3m
Est. Remaining
81%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
193 granted / 318 resolved
+2.7% vs TC avg
Strong +20% interview lift
Without
With
+20.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
26 currently pending
Career history
374
Total Applications
across all art units

Statute-Specific Performance

§101
10.6%
-29.4% vs TC avg
§103
53.7%
+13.7% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
17.3%
-22.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 318 resolved cases

Office Action

§101 §102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment / Arguments Regarding claims rejected under 35 USC 112(b): Applicant’s amendment has overcome the applied rejection, which has therefore been withdrawn. Regarding claims rejected under 35 USC 101: Applicant's arguments have been fully considered but they are not persuasive. Applicant argues that the “claim language recites a sequence of operations that collectively perform data acquisition, machine-learning inference, and physical device notification. The claimed invention does not recite or depend upon a mathematical formula, equation, or algorithm in the abstract. Similarly, the machine-learning model recited in the claims is not a generic mathematical construct; rather, it is a trained subsystem that performs specialized image-based inference for device-health prediction. Under Desjardins, operations that involve training and applying machine-learning models are not abstract when they yield specific improvements in computational efficiency, storage optimization, or continual-learning performance. The claimed invention implements model deployment and inference in a manner that improves both the accuracy and responsiveness of log errors and detection systems while reducing latency and false positives in monitoring.” In response, it is first noted that the features upon which applicant relies (i.e., “a trained subsystem that performs specialized image-based inference” and “physical device notification”) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). The claim is entirely silent as to image-based inference and further lacks any particulars of the training beyond “generat[ing] a baseline” and “generat[ing] a deviation zone,” which need not be performed by training the “artificial intelligence engine.” The AI engine may have already been trained—outside of the scope of the claim—for performing such generation. Additionally, the claim merely recites “transmit[ting] a notification to users associated with a cyber security application mode” rather than transmission to any physical devices or GUI. It is further noted that the argued “operations that involve training and applying machine-learning models” are recited at a high level of generality in the claim—i.e., merely the mention of using the AI engine for scanning and generation and the implication of training. The claim does not recite any particular training algorithm or AI engine structure (e.g., a particularly arranged neural network), and is therefore not considered to be sufficient under Desjardins. Additionally with respect to the argued improvement, it is noted that “accuracy and responsiveness of log errors and detection systems while reducing latency and false positives in monitoring” is not part of the claim scope. Specifically, the claim does not concern updating detection systems or elements which would be affected by said latency. Further, the argued improvement transcends computing because improving the accuracy of a model and reducing latency at a high level of generality are both performable by a human—e.g., an admin. Applicant further argues that “the judicial exception is integrated into a practical application in light of Example 42 of the Subject Matter Eligibility Examples: Abstract Ideas published by the USPTO in January 2019.” In response, it is noted that the claim of example 42 recites updating “information about the patient's condition in the collection of medical records in real time through a graphical user interface” and “transmitting the message to all of the users over the computer network in real time, so that each user has immediate access to up-to-date patient information,” which is drawn to simultaneously pushing information to a plurality of user interfaces in real time. This is not something that can be performed by a user because of the instantaneous and simultaneous nature which requires a computer processor. The claim also explicitly recites that this information is sent to a GUI, which likewise requires a computer. In contrast, the instant claim does not specify simultaneous real-time notification to a plurality of GUIs. Lastly, the examples provided by the USPTO are illustrative in nature to help applicants understand the PEG. They have no precedential value nor referencability for legal decision making and can not be the basis for affecting a legal conclusion. Finally, it is noted that while the amended claim language now recites that the notification “comprises a preventative action,” this is not sufficient because the action is not performed. For instance, the notification may merely describe a preventative action to be taken. Additionally, the preventative action may be something akin to informing another user. If the claim were to explicitly recite performing an action such as blocking a port or shutting down an application, then that would likely overcome the rejection. Regarding claims rejected under 35 USC 102/103: Applicant’s amendment is considered to have overcome the applied rejections. Therefore, the rejections have been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Kapoor (US 2022/0400130 A1). Where Applicant argues that Malkov and Crabtree do not “teach or suggest generating a baseline mode of operation from the set of network logs and the set of application logs via the artificial intelligence engine that consistently regenerated upon changes to the set of actions performed within the set of networks from a group of users” and do not “teach or suggest a deviation zone that permits modes of operation deviating from the baseline mode of operation,” Applicant's arguments have been fully considered but they are not persuasive. It is first noted that Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. With respect to “generating a baseline mode of operation from the set of network logs and the set of application logs via the artificial intelligence engine that consistently regenerated upon changes to the set of actions performed within the set of networks from a group of users,” it is noted that [0009], [0119]-[0126], TABLE 2, and [0153] of Malkov explicitly concern network and application logs for a cloud and cloud regions (e.g., FIG. 2A). For instance, “system logs and online data streams of various operating resources such as the host's or VM's CPU activity, memory, disk usage (read/write/etc.), network and bandwidth activity are closely monitored and analyzed to establish baselines that fall within normal or typical operating parameters” and “data derived or originating from instance firewalls, web application firewalls, VPC flow logs, VPC flow logs, DNS logs, network traffic logs, AWS CloudTrail logs, netflow logs, snmp logs, network traffic logs, and the like… VPC flow logs and other log files are created and accessible via one or more AWS APIs made available by AWS.” Additionally, [0009] and [0115]-[0116] of Malkov explicitly concern retraining: e.g., “embodiments continually learn from the monitored resources as to what constitutes normal, routine and non-compromised (typical) activity and what constitutes anomalous (atypical) activity indicative of a threat to the VM. Through machine learning and AI, patterns of behavior and activity are continually accessed, processed and monitored.” Further, at least [0121]-[0127] of Malkov concern user behavior: e.g., “an access log can be useful to identify number of visitors, the domains from which they are visiting, the number of requests for each page, usage patterns according day of the week or even the hour of the day.” Likewise, at least FIG. 20 and [0161] of Crabtree concern user groups for behavioral profiling. With respect to “a deviation zone that permits modes of operation deviating from the baseline mode of operation,” at least [0011], [0141]-[0142], [0147], and [0155] of Malkov explicitly concern clustering and a membership degree for comparison to a baseline: e.g., “such process algorithms are generally based on a combination of three well-known approaches: fuzzy sets theory (the fact that the event is “typical” or “atypical” is determined by the value of its membership degree)… it is also a process algorithm that provides the opportunity to simultaneously estimate the degree of “typicality” and “primary objective of the classification processes of AI anomaly detection engine 300A, discussed below, is the creation of membership degree functions of events (typical and atypical) from system logs to the clusters.” Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1, 3-4, 7-8, 10-11, 14-15, and 17-18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Note that the courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper or a slide rule) to perform the claim limitation (refer to MPEP 2106.04(a)(2)). Example independent claim 1 recites the following abstract idea limitations: A system for generating a baseline mode of operation from network and application logs, the system comprising: identify a set of network logs from a set of networks and a set of application logs from a set of applications (observation and evaluation as part of a mental process—e.g., an analyst looks over a set of data and labels particular elements); scan the set of network logs and the set of application logs via [a model] (observation and evaluation as part of a mental process—e.g., the analyst looks over the labeled data in view of a given model) generate a baseline mode of operation from the set of network logs and the set of application logs via the [model] (evaluation and judgement as part of a mental process—e.g., the analyst determines routine behavior in the data using the model), wherein the baseline mode of operation comprises a set of actions performed within the set of networks and the set of applications (extra solution activity concerning the genre and form of data—e.g., the data and routine elements having to do with activity rather than configuration and compliance information), and wherein the baseline mode of operation is regenerated upon changes to the set of actions performed within the set of networks from a group of users (evaluation and judgement as part of a mental process—e.g., the analyst adjusts the baseline in response to learning new information); generate a deviation zone from the baseline mode of operation, wherein the deviation zone permits modes of operation deviating from the baseline mode of operation (evaluation as part of a mental process—e.g., the analyst determines a threshold deviation value); monitor a received mode of operation from the set of networks and the set of applications (observation and evaluation as part of a mental process—e.g., the analyst observes system behavior data); evaluate the received mode of operation with respect to the baseline mode of operation (evaluation and judgement as part of a mental process—e.g., the analyst checks the observed system behavior data against their determined routine behavior); transmit a notification to users associated with a cyber security application mode (alerting as part of certain methods of organizing human activity—e.g., the analyst alerts their supervisor or an administrator) when the received mode of operation deviates outside the deviation zone from the baseline mode of operation for the cyber security application (evaluation and judgement as part of a mental process—e.g., the analyst checks the observed system behavior data against their determined routine behavior), wherein the notification comprises a preventative action for the users and how the mode of operation deviated outside the deviation zone (extra solution activity concerning the genre and form of a message—e.g., the message describing an action and having an explanation). Example independent claim 1 recites the following limitations which may comprise additional elements that are sufficient to amount to significantly more than the abstract idea: “at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to” perform the abstract idea steps; the model further comprising “an artificial intelligence engine.” With respect to step 2A, the judicial exception is not integrated into a practical application because it is drawn to reviewing log data to determine whether it is indicative of routine or abnormal behavior at a high level of generality, and because adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea is not considered to be sufficient—see MPEP 2106.05(f). The claim is drawn to steps which may be performed by a human analyst, including obtaining log data, reviewing the log data to determine routine patterns of behavior using a model, and checking to see whether new data is routine or abnormal. The claim does incorporate using an artificial intelligence engine as the model, but this is considered to be the equivalent of merely using the artificial intelligence engine as a tool to perform the abstract idea of classifying data. The artificial intelligence engine is specified at a high level of generality rather than in terms of its particular structure, algorithm, or training methodology. For example, “via an artificial intelligence engine” can mean that the analyst queries an artificial intelligence engine at any point while classifying the data. Where the claim recites “a processing device; at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to” perform the abstract idea steps, this is considered to merely require implementing the abstract idea on a base level computer (processor and memory). The computer is not otherwise specified in any particular detail. As such, the invention is addressing a problem that transcends computing (classifying and reviewing data) rather than improving the functioning of a computer, or an improvement to other technology or a technical field. With respect to step 2B, the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea is not considered to be sufficient—see MPEP 2106.05(f). In this case, at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to” perform the abstract idea steps may be interpreted as any generic base level computer (processor and memory) for performing the judicial exception. Merely performing the judicial exception using a base level computer is not considered to be sufficient. Regarding using “an artificial intelligence engine,” this is considered to be using a computer as a tool to perform the abstract idea. In this case, the AI engine is being used to help in classifying data, without otherwise detailing the particular machine or design of the AI engine. Independent claims 8 and 15 are substantially similar to independent claim 1, and are therefore rejected under the same analysis. Regarding dependent claims 3-4 and 7, they are considered to merely further specify the abstract idea (i.e., the genre of data under review), and are rejected under the same analysis as independent claim 1 above. Regarding dependent claims 10-11 and 14, and claims 17-18, they are substantially similar to claims 3-4 and 7 above, and are therefore likewise rejected. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3-4, 7-8, 10-11, 14-15, and 17-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Malkov (US 2020/0159624 A1) in view of Crabtree (US 2023/0412620 A1) and Kapoor (US 2022/0400130 A1). Regarding claim 1, Malkov discloses: A system for generating a baseline mode of operation from network and application logs, the system comprising: at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to: Refer to at least FIG. 1, [0012], and [0085] of Malkov with respect to system hardware elements (e.g., processors and storage). identify a set of network logs from a set of networks (e.g., FIG. 2A and [0095] of Malkov) and a set of application logs from a set of applications (e.g., FIG. 1, [0013], and [0087] of Malkov); Refer to at least [0009], [0119]-[0126], TABLE 2, and [0153] of Malkov with respect to accessing and compiling information from various types of network and activity logs, such as network traffic logs and application logs. As per at least [0132], the information may come from any connected systems. scan the set of network logs and the set of application logs via an artificial intelligence engine; generate a baseline mode of operation from the set of network logs and the set of application logs via the artificial intelligence engine, Refer to at least 200 in FIG. 3, FIG. 4, [0006], [0009], [0115], [0119], and [0132] of Malkov with respect to establishing baselines from the logs using machine learning (e.g., the machine learning logic module). wherein the baseline mode of operation comprises a set of actions performed within the set of networks and the set of applications Refer to at least the abstract, [0009], [0115], TABLE2, and [0158] of Malkov with respect to activities learned as part of establishing the baseline. For example, read/write, application errors, login attempts, privilege changes, and DNS name resolutions. and wherein the baseline mode of operation is regenerated upon changes to the set of actions performed within the set of networks [associated with user behavior]; Refer to at least [0009] and [0115]-[0116] of Malkov with respect to continuously learning and refining the baseline based on incoming information such as logs; at least [0121]-[0127] of Malkov with respect to incoming information comprising user behavior. generate a deviation zone from the baseline mode of operation, wherein the deviation zone permits modes of operation deviating from the baseline mode of operation; Refer to at least [0011], [0141]-[0142], [0147], and [0155] of Malkov with respect to a membership degree for behavior clusters. Deviation from the baseline may require a high membership degree or a sufficiently high frequency of events. monitor a received mode of operation from the set of networks and the set of applications; evaluate the received mode of operation with respect to the baseline mode of operation; Refer to at least 300A and 1122 in FIG. 3, [0009], [0116], and [0158] of Malkov with respect to its anomaly detection engine monitoring system behavior in real time and determining deviation from the established baseline. and transmit a notification to users associated with a cyber security application mode when the received mode of operation deviates outside the deviation zone from the baseline mode of operation for the cyber security application, wherein the notification comprises a preventative action for the users. Refer to at least 460 in FIG. 4, [0010], and [0117] of Malkov with respect to notifications to system and security admins as part of remedial actions responsive to detecting anomalous behavior. Malkov does not specify: the user behavior further comprising actions from a group of users; the notification further comprising how the mode of operation deviated outside the deviation zone. However, Malkov in view of Crabtree discloses: the user behavior further comprising actions from a group of users. Refer to at least FIG. 20 and [0161] of Crabtree with respect to establishing groups of users from network interaction, and further establishing a behavioral baseline for each group. Refer to at least [0126] of Crabtree with respect to dynamic adjustment of similarity scores. The teachings of Malkov and Crabtree both concern using machine learning to establish behavioral baselines for computer and network security (e.g., [0134] of Crabtree), and are considered to be within the same field of endeavor and combinable a such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Malkov to further implement learning and monitoring user group behavior for at least the purpose of increasing the scope of detected behavioral anomalies and thereby increasing security (a single user communicating with a server may not be as indicative of malicious behavior as an entire user group—e.g., indicating a botnet). Crabtree further describes detection scenarios using groups in at least [0126] (e.g., lateral movements being indicative of malicious behavior). Although Malkov-Crabtree discloses notifying an administrator with an assessment including contextual information (e.g., [0101] and [0159] of Crabtree; [0146] of Crabtree for generating alerts for deviations), Malkov-Crabtree does not fully specify: the notification further comprising how the mode of operation deviated outside the deviation zone. However, Malkov-Crabtree in view of Kapoor discloses: the notification further comprising how the mode of operation deviated outside the deviation zone. Refer to at least [0790], [0487], and [0686] of Kapoor with respect to an alert including an indication of a deviation from typical user network activity. The teachings of Kapoor likewise concern establishing behavioral baselines for computer and network security, and are considered to be within the same field of endeavor and combinable a such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Malkov-Crabtree to further implement alerts indicating contextual information such as that of deviation outside of a baseline because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art. Regarding claim 3, Malkov-Crabtree-Kapoor discloses: The system of claim 1, wherein generation of the baseline mode of operation is based on an individual user. Refer to at least [0094] of Makov with respect to a user as a cloud customer whose VPC (e.g., FIG. 2) is being monitored; at least [0123] and TABLE 2 of Malkov with respect to users as those whose activities are logged (e.g., emails, adding users, user logins). The baseline is therefore based on the customer’s VPC and/or the logged users’ respective individual activities. Regarding claim 4, it is rejected for substantially the same reasons as claim 1 above (i.e., the citations concerning generating the baseline and user groups; also the obviousness rationale). Regarding claim 7, Malkov-Crabtree-Kapoor discloses: The system of claim 1, wherein the baseline mode of operation is at least partially generated based on associated authentication credentials. Refer to at least TABLE 2 and [0102] of Malkov with respect to logged valid and invalid login attempts being used as part of the log data for both learning and anomalous behavior detection (e.g., [0115] of Malkov). Access granted to other users, and permissions and authorizations associated therewith, may be based on having the essential credentials (e.g., password). Regarding independent claim 8, it is substantially similar to independent claim 1 above, and is therefore likewise rejected under the same analysis. Regarding claims 10-11 and 14, they are substantially similar to claims 3-4 and 7 above, and are therefore likewise rejected. Regarding independent claim 15, it is substantially similar to independent claim 1 above, and is therefore likewise rejected under the same analysis. Regarding claims 17-18, they are substantially similar to claims 3-4 above, and are therefore likewise rejected. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432 /V.S/ Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Aug 22, 2024
Application Filed
Nov 25, 2025
Non-Final Rejection mailed — §101, §102, §103
Feb 25, 2026
Response Filed
Jun 24, 2026
Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12639449
SYSTEM AND METHOD FOR SCANNING CONTAINERS FOR VULNERABILITIES
2y 4m to grant Granted May 26, 2026
Patent 12632534
ACCESSING SECURE SYSTEM RESOURCES BY LOW PRIVILEGE PROCESSES
7y 12m to grant Granted May 19, 2026
Patent 12613999
DETECTING ELECTRONIC SYSTEM MODIFICATION
6y 10m to grant Granted Apr 28, 2026
Patent 12608482
DETERMINING A SECURITY SCORE IN BINARY SOFTWARE CODE
6y 5m to grant Granted Apr 21, 2026
Patent 12608501
Privacy-Preserving Log Analysis
5y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
61%
Grant Probability
81%
With Interview (+20.3%)
3y 5m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 318 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month