Prosecution Insights
Last updated: July 26, 2026
Application No. 18/825,175

MALICIOUS ACTIVITY DETECTION IN MEMORY OF A DATA PROCESSING UNIT USING MACHINE LEARNING DETECTION MODELS

Final Rejection §DP
Filed
Sep 05, 2024
Priority
Feb 14, 2022 — provisional 63/309,849 +1 more
Examiner
TIV, BACKHEAN
Art Unit
2459
Tech Center
2400 — Computer Networks
Assignee
Mellanox Technologies Ltd.
OA Round
2 (Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
2y 0m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
680 granted / 902 resolved
+17.4% vs TC avg
Strong +20% interview lift
Without
With
+20.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
22 currently pending
Career history
921
Total Applications
across all art units

Statute-Specific Performance

§101
4.6%
-35.4% vs TC avg
§103
80.5%
+40.5% vs TC avg
§102
3.1%
-36.9% vs TC avg
§112
4.9%
-35.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 902 resolved cases

Office Action

§DP
Detailed Action Claims 1-20 are pending in this application. This is a response to the Amendments/Remarks filed on 4/30/26. This is a Final Rejection. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-5, 8, 9, 12-20 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 6-8, 10-12, 14-26 of U.S. Patent No. 12,261,881(17/864,310). Although the claims at issue are not identical, they are not patentably distinct from each other because ‘881 teaches the instant claims and only differs in verbiage and/or statutory class. Instant Claims 12,261,881 1. An integrated circuit comprising: a host interface operatively coupled to physical memory associated with a host device; a central processing unit (CPU) operatively coupled to the host interface; and an acceleration hardware engine operatively coupled to the host interface and the CPU, wherein the CPU and the acceleration hardware engine are to host a hardware-accelerated security service to protect the host device, wherein the hardware-accelerated security service is to: extract a plurality of features from data stored in the physical memory, the data being associated with one or more computer programs executed by the host device, wherein the data is obtained by the hardware-accelerated security service using out-of-band memory acquisitions isolated from the one or more computer programs; determine, using a machine learning (ML) detection system, whether the one or more computer programs are subject to malicious activity based on the plurality of features extracted from the data stored in the physical memory; and output an indication of the malicious activity responsive to a determination that the one or more computer programs are subject to the malicious activity. 2. The integrated circuit of claim 1, wherein the integrated circuit is a data processing unit (DPU), wherein the DPU is a programmable data center infrastructure on a chip. 3. The integrated circuit of claim 1, wherein the one or more computer programs comprises at least one a host operating system (OS), an application, a guest operating system, or a guest application, wherein the one or more computer programs reside in a first computing domain, wherein the hardware-accelerated security service and the ML detection system reside in a second computing domain different than the first computing domain. 4. The integrated circuit of claim 1, wherein the malicious activity is caused by malware, wherein the hardware-accelerated security service is out-of-band security software in a trusted domain that is different and isolated from the malware. 5. The integrated circuit of claim 1, further comprising a direct memory access (DMA) controller coupled to the host interface, wherein the DMA controller is to read the data from the physical memory via the host interface, wherein the host interface is a Peripheral Component Interconnect Express (PCIe) interface. 8. The integrated circuit of claim 1, wherein: the malicious activity is caused by a malicious uniform resource locator (URL); the hardware-accelerated security service is to obtain a snapshot of the data stored in the physical memory, the snapshot representing the data at a point in time; the ML detection system comprises: feature extraction logic to extract a set of features from the snapshot, the set of features comprising words in a candidate URL and numeric features of a URL structure of the candidate URL; and a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. 9. The integrated circuit of claim 8, wherein the feature extraction logic is to tokenize the words into tokens, and wherein the binary classification model comprises: an embedding layer to receive the tokens as an input sequence of tokens representing the words in the candidate URL and generate an input vector based on the input sequence of tokens; a Long Short-Term Memory (LSTM) layer trained to generate an output vector based on the input vector; and a fully connected neural network layer trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure. 7. An integrated circuit comprising: a host interface operatively coupled to physical memory associated with a host device; a central processing unit (CPU) operatively coupled to the host interface; and an acceleration hardware engine operatively coupled to the host interface and the CPU, wherein the CPU and the acceleration hardware engine are to host a hardware-accelerated security service to protect the host device, wherein the hardware-accelerated security service is to: obtain a snapshot of data stored in the physical memory, the data being associated with one or more computer programs executed by the host device, wherein the snapshot of data is obtained by the hardware-accelerated security service using out-of-band memory acquisitions isolated from the one or more computer programs; extract, using a machine learning (ML) detection system, a set of features from the snapshot, wherein the set of features comprising words in a candidate uniform resource locator (URL) and numeric features of a URL structure of the candidate URL; classify, using the set of features and the ML detection system, the candidate URL as malicious or benign; and output an indication of a malicious URL responsive to the candidate URL being classified as malicious. 8. The integrated circuit of claim 7, wherein the integrated circuit is a data processing unit (DPU), wherein the DPU is a programmable data center infrastructure on a chip. 10. The integrated circuit of claim 7, wherein the one or more computer programs comprises at least one a host operating system (OS), an application, a guest operating system, or a guest application. 14. The integrated circuit of claim 7, wherein the hardware-accelerated security service is out-of-band security software in a trusted domain that is different and isolated from the malicious URL. 15. The integrated circuit of claim 7, further comprising a direct memory access (DMA) controller coupled to the host interface, wherein the DMA controller is to read the data from the physical memory via the host interface. 16. The integrated circuit of claim 15, wherein the host interface is a Peripheral Component Interconnect Express (PCIe) interface. 11. The integrated circuit of claim 7, wherein: the hardware-accelerated security service is to obtain a snapshot of the data stored in the physical memory, the snapshot representing the data at a point in time; the ML detection system comprises: feature extraction logic to extract a set of features from the snapshot, the set of features comprising words in the candidate URL and the numeric features of the URL structure of the candidate URL; and a binary classification model trained to classify the candidate URL as malicious or benign using the set of features. 12. The integrated circuit of claim 11, wherein the feature extraction logic is to tokenize the words into tokens, and wherein the binary classification model comprises: an embedding layer to receive the tokens as an input sequence of tokens representing the words in the candidate URL and generate an input vector based on the input sequence of tokens; a Long Short-Term Memory (LSTM) layer trained to generate an output vector based on the input vector; and a fully connected neural network layer trained to classify the candidate URL as malicious or benign using the output vector from the LSTM layer and the numeric features of the URL structure. Allowable Subject Matter Claims 1-20 allowed over prior art. The applicant is advised to file TD to overcome the Double Patenting Rejection. REASONS FOR ALLOWANCE The following is an examiner’s statement of reasons for allowance: the prior art singly or in combination does not teach the totality of the independent claims when read in light of the specification. The closest prior art of record is US 2021/0141897 issued to Seifert, teaches as per claims 1,12,16, extract a plurality of features from data stored in the physical memory, the data being associated with the one or more computer programs(Fig.7B, para.102; extract features from the computer object); determine, using a machine learning (ML) detection system, whether the one or more computer programs are subject to malicious activity based on the plurality of features extracted from the data stored in the physical memory(Fig.7B, para.103; Per block 709, based on the features (extracted at block 705), a similarity score is generated (e.g., by the unknown evaluator 211), via a deep learning model, between the computer object and each computer object of a plurality of computer objects known to contain malicious content. In some embodiments, the deep learning model is associated with a plurality of indications representing known malicious computer objects. The plurality of indications may be compared with an indication representing the computer object. In some embodiments, based at least in part on processing or running the indication of the computer object through the deep learning model, a similarity score is generated between the computer object and each of the plurality of known malicious computer objects. …… The distance may be specifically based on the exact feature values that the computer object has compared to the known malicious computer objects. For example, if the computer object has the exact feature values that have been weighted toward prominence or importance during training (e.g., as described with respect to block 708 of FIG. 7A) as some known malware computer object, then the distance between these two computer objects would be close within a threshold in feature space, such that the similarity score is high.); and output an indication of the malicious activity responsive to a determination that the one or more computer programs are subject to the malicious activity(Fig.7B, para.108; [0108] Per block 713, one or more identifiers (e.g., names of particular malware families or files) representing at least one of the plurality of known malicious computer objects is provided (e.g., by the rendering component 217) or generated on a computing device. The one or more identifiers may indicate that the computer objects is likely malicious and/or the computer object likely belongs to a particular malicious family.). However these prior art does not teach nor would it be obvious to one ordinary skill in the art to combine to teach the totality of the claim and at least the underlined portions below 1. (Original) An integrated circuit comprising: a host interface operatively coupled to physical memory associated with a host device; a central processing unit (CPU) operatively coupled to the host interface; and an acceleration hardware engine operatively coupled to the host interface and the CPU, wherein the CPU and the acceleration hardware engine are to host a hardware- accelerated security service to protect the host device, wherein the hardware-accelerated security service is to: extract a plurality of features from data stored in the physical memory, the data being associated with one or more computer programs executed by the host device, wherein the data is obtained by the hardware-accelerated security service using out-of-band memory acquisitions isolated from the one or more computer programs; determine, using a machine learning (ML) detection system, whether the one or more computer programs are subject to malicious activity based on the plurality of features extracted from the data stored in the physical memory; and output an indication of the malicious activity responsive to a determination that the one or more computer programs are subject to the malicious activity. 12. (Currently Amended) A computing system comprising: a data processing unit (DPU) comprising a host interface, a central processing unit (CPU), and an acceleration hardware engine, the DPU to host a hardware-accelerated security service to protect a host device, wherein the hardware-accelerated security service is to extract a plurality of features from data stored in physical memory associated with the host device, the data being associated with one or more computer programs executed by the host device, wherein the data is obtained by the hardware-accelerated security service using out-of-band memory acquisitions isolated from the one or more computer programs; and accelerated pipeline hardware coupled to the DPU, wherein the accelerated pipeline hardware is to: determine, using a machine learning (ML) detection system, whether the one or more computer programs are subject to malicious activity based on the plurality of features extracted from the data stored in the physical memory; and output an indication of the malicious activity responsive to a determination that the one or more computer programs are subject to the malicious activity. 16. (Original) A method comprising: extracting, by a data processing unit (DPU) coupled to a host device, a plurality of features from data stored in physical memory of the host device, the data being associated with one or more computer programs executed by the host device, wherein the data is obtained by the DPU using out-of-band memory acquisitions isolated from the one or more computer programs; determining, using a machine learning (ML) detection system, whether the one or more computer programs are subject to malicious activity based on the plurality of features extracted from the data stored in the physical memory; and outputting an indication of the malicious activity responsive to a determination that the one or more computer programs are subject to the malicious activity. The applicant's reply makes evident the reason for allowance, satisfying the record as a whole as required by rule 37 CFR 1.104 (e). In this case, the substance of applicant's remarks filed on 4/30/26in combination with other claimed features point out the reason that claims are patentable over the prior art of record. Thus, the reason for allowance is in all probability evident from the record (see MPEP 1302.14). Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.” Response to Arguments The applicant filed TD to overcome the Double Patenting Rejection for 12,118,078, therefore that rejection is withdrawn. Applicant's arguments filed 4/30/26 have been fully considered and are partially persuasive. The applicant argues in substance, a) For the double patenting rejection with US 12,261,881, the instant claims encompasses a broader scope of malicious activity detection that is not limited to URL-based methodologies, while ‘881 are specifically constrained to URL-based detection requires URL-specific feature extraction and URL classification, therefore the inventive concepts are separate applications. In reply to a); The examiner agrees that ‘881 is specifically constrained to URL-based detection requiring URL-specific feature extraction and is more narrow than the instant claims, however ‘881 narrowed claims would teach and/or anticipate the more broadly instant claims. For instance if the instant claims was claiming a truck(broad) and the patent was a red truck(narrowed). The red truck would teach/anticipate a truck. Also note that claim 8 of the instant claims is drawn to feature extraction of the URL and URL classification, therefore claims 1 and 8 of the instant claims is claiming the same subject matter of ‘881 claim 1. b) The prior art does not teach as per claim 1, “an acceleration hardware engine operatively coupled to the host interface and the CPU, wherein the CPU and the acceleration hardware engine are to host a hardware-accelerated security service” and as per claims 12,16, “ a data processing unit(DPU) comprising a host interface, a central processing unit(CPU), and an acceleration hardware engine, the DPU to host a hardware-accelerated security service” therefore does not teach an integrated circuit where a CPU and an acceleration hardware engine together host a hardware-accelerated security service. In reply to b); The applicant’s arguments pertaining to claims 1,12,16 are persuasive therefore the prior art rejection is withdrawn. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892. US 2017/0134397 issued to Dennison et al., teaches a computer system identifies malicious Uniform Resource Locator (URL) data items from a plurality of unscreened data items that have not been previously identified as associated with malicious URLs. The system can execute a number of pre-filters to identify a subset of URLs in the plurality of data items that are likely to be malicious. A scoring processor can score the subset of URLs based on a plurality of input vectors using a suitable machine learning model. Optionally, the system can execute one or more post-filters on the score data to identify data items of interest. Such data items can be fed back into the system to improve machine learning or can be used to provide a notification that a particular resource within a local network is infected with malicious software. US 2021/0377301 issued to Desai et al., teaches obtaining a Uniform Resource Locator (URL) for a site on the Internet; analyzing the URL with a Machine Learning (ML) model to determine whether or not the site is suspicious for phishing; responsive to the URL being suspicious for phishing, loading the site to determine whether or not an associated brand of the site is legitimate or not; and, responsive to the site being not legitimate for the brand, categorizing the URL for phishing and performing a first action based thereon. The systems and methods can further include, responsive to the URL being not suspicious for phishing or the site being legitimate for the brand, categorizing the URL as legitimate and performing a second action based thereon. US 2015/0281259 issued to Ranum et al., teaches leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have catalogued to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BACKHEAN TIV whose telephone number is (571)272-5654. The examiner can normally be reached Mon.-Thurs. 5:30-3:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, TONIA L DOLLINGER can be reached at (571) 272-4170. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BACKHEAN TIV/ Primary Examiner Art Unit 2459
Read full office action

Prosecution Timeline

Sep 05, 2024
Application Filed
Feb 02, 2026
Non-Final Rejection mailed — §DP
Apr 30, 2026
Response Filed
May 29, 2026
Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683958
BIOMETRIC MULTI-FACTOR AUTHENTICATION
4y 3m to grant Granted Jul 14, 2026
Patent 12659284
MESSAGE MODIFICATION BASED ON DEVICE COMPATABILITY
1y 9m to grant Granted Jun 16, 2026
Patent 12652157
APPARATUS AND METHOD WITH INTERSECTION OPERATION
2y 3m to grant Granted Jun 09, 2026
Patent 12647384
INTELLIGENT MESSAGING DELIVERY
1y 11m to grant Granted Jun 02, 2026
Patent 12639415
MANAGEMENT OF EDGE COMPUTING NETWORK DEPLOYMENTS WITH LEGACY EDGE DEVICES
2y 7m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
96%
With Interview (+20.3%)
3y 11m (~2y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 902 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month