Prosecution Insights
Last updated: October 01, 2026
Application No. 18/825,812

ASSISTING CYBERSECURITY INVESTIGATIONS USING LARGE LANGUAGE MODELS

Final Rejection §101§103
Filed
Sep 05, 2024
Examiner
NGUYEN, CAROLINE HOANG-ANH
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Google LLC
OA Round
2 (Final)
100%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 100% — above average
100%
Career Allowance Rate
1 granted / 1 resolved
+42.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
7 currently pending
Career history
14
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
66.7%
+26.7% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
9.3%
-30.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1 resolved cases

Office Action

§101 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Applicant’s amendments file on 05/06/2026 has been received and entered. Currently Claims 1-3, 5-10, 12-17, and 19-20 are pending. Response to Arguments Applicant’s argues on pages 7-8 that the amended limitations directed to “providing the modified NL prompt and one or more example search query translation pairs as input to a second LLM, wherein each example search query translation pair comprises a corresponding example natural language prompt and a corresponding example search query in a domain-specific language (DSL) of the security investigation service; obtaining, from the second LLM, a DSL search query generated based on the modified NL prompt and the one or more example search query translation pairs; and providing the DSL search query as input to the security investigation service” integrate any alleged abstract idea into a practical application as recited in the amended claims 1, 8, and 15. The examiner respectfully disagrees. The limitation “providing the modified NL prompt and one or more example search query translation pairs as input to a second LLM, wherein each example search query translation pair comprises a corresponding example natural language prompt and a corresponding example search query in a domain-specific language (DSL) of the security investigation service” does not recite a practical application because it falls within the abstract idea itself. Considering a request alongside a set of worked examples, each pairing a sample request with its corresponding correctly-written query, is a step that can be performed in the human mind or with pen and paper. The recited “second LLM” is nothing more than generic computer functions merely used to implement an abstract idea that could be done by a human analog by hand or by merely thinking, and this does not recite a practical application or significantly more. The limitation “obtaining, from the second LLM, a DSL search query generated based on the modified NL prompt and the one or more example search query translation pairs” recites an abstract idea directed to mental processes as a human, having consulted the example request to query pairs, can compose a corresponding query in the relevant syntax by following the pattern of the examples. The limitation “providing the DSL search query as input to the security investigation service” recites a transmission of the query produced by the preceding steps to a downstream process and constitutes insignificant extra-solution activity of outputting results. Therefore, the rejection is maintained. Applicant’s arguments regarding 35 USC § 103 Claim Rejections have been considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-3, 5-10, 12-17, and 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. As per claims 1, 8, and 15, these claims recite the following limitations which are found to be abstract ideas not reciting a practical application or significantly more, with claim 1 being exemplary: receiving, by a security analytics platform, a natural language (NL) prompt (abstract idea as mental process as a human is capable of receiving a user inquiry and security analytics platform is a field-of-use limitation); providing the NL prompt as input to a large language model (LLM) (abstract idea as generic computer functions that could be done by a human analog by hand or by merely thinking); obtaining an output of the LLM comprising an indication that an intent of the NL prompt is associated with a security investigation service of a plurality of security investigation services of the security analytics platform (abstract idea as a mental process as a human mind is capable of reading a request and determining which type of service it relates to); modifying the NL prompt based on one or more parameters associated with the security investigation service (abstract idea as a mental process as a human mind is capable of reformulating a request to fit the requirements of a particular service); and providing the modified NL prompt and one or more example search query translation pairs as input to a second LLM, wherein each example search query translation pair comprises a corresponding example natural language prompt and a corresponding example search query in a domain-specific language (DSL) of the security investigation service (abstract idea as mental process as a human mind, with pen and paper, is capable of considering a request together with one or more reference examples each pairing a sample request with its corresponding written query and use of second LLM is nothing more than generic computer functions that could be done by a human analog by hand or by merely thinking); obtaining, from the second LLM, a DSL search query generated based on the modified NL prompt and the one or more example search query translation pairs (abstract idea as a mental process as a human mind, with pen and paper, is capable of composing a corresponding query in the relevant query syntax by following the pattern of the examples); and providing the DSL search query as input to the security investigation service (abstract idea as insignificant extra-solution activity of outputting results). Claims 8 and 15 further recite additional elements of “a system” storing “a memory device” and “a processing device” (claim 8), and “a non-transitory computer-readable medium” executed by a “processing device” (claim 15). While these limitations are additional elements, they are not sufficient to recite a practical application of the abstract ideas as they amount to mere generic computer elements and thus amount to no more than a recitation of the words “apply it” (or an equivalent) or are no more than mere instructions to implement an abstract idea or other exception on a computer. See MPEP § 2106.05(f). Further, the claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because when considered separately and in combination, the above recited additional elements from claims 8 and 15 do not add significantly more (also known as an “inventive concept”) to the exception. Rather, the additional elements disclosed above perform well-understood, routine, conventional computer functions as recognized by the court decisions listed in MPEP § 2106.05(d). Therefore, independent claims 1, 8, and 15 are directed towards an abstract idea without a practical application or significantly more. As per claims 2, 9, and 16, the limitation directed towards the “modified NL prompt corresponds to a specified prompt format of the security investigation service” is merely an abstract idea of a mental process since the human mind is capable of taking a formatted request to match an expected input structure of a particular service. Further, this additional limitation does not recite a practical application or significantly more. As per claims 3, 10, and 17, the limitations directed towards “providing user log data as input to the LLM” and “the LLM is further configured to modify the NL prompt to include one or more characteristics of the user log data” are merely abstract ideas of mental processes as the human mind, with pen and paper, is capable of reviewing log data, identifying relevant characteristics, and incorporating those characteristics into a request. The use of an LLM to perform this modification is nothing more than generic computer functions merely used to implement an abstract idea, such as an idea that could be done by a human analog by hand or by merely thinking, see MPEP § 2106.05(d)(II). Further these additional limitations do not recite a practical application or significantly more. As per claims 5, 12, and 19, the limitation “a security knowledge service configured to answer security questions related to at least one of: security investigation techniques, types of security vulnerabilities, or known security threat entities” are merely abstract ideas as mental processes as the human mind is capable of referencing known investigation techniques and security knowledge to answer security-related questions. Further, this additional limitation does not recite a practical application or significantly more. As per claims 6, 13, and 20, the limitations towards “receiving one or more outputs of the security investigation service,” “providing the one or more outputs and one or more example summaries as input to a third LLM configured to summarize the one or more outputs based on the one or more examples summaries,” “obtaining an output of the third LLM comprising a summary of the one or more outputs,” and “providing the summary of the one or more outputs to be presented via a graphical user interface (GUI) of the security analytics platform” are merely abstract ideas as mental processes as the human mind, with pen and paper, is capable of reviewing investigation results, referencing example summaries for guidance on format and content, and drafting a summary accordingly.; The use of a third LLM to perform summarization is nothing more than generic computer functions merely used to implement an abstract idea, such as an idea that could be done by a human analog by hand or by merely thinking, see MPEP § 2106.05(d)(II). The receiving and providing steps are insignificant extra-solution activity of mere data gathering and output. See MPEP § 2106.05(g). Further, these additional limitations do not recite a practical application or significantly more. As per claims 7 and 14, the limitation directed towards “providing one or more pre-defined NL prompts to be presented via a graphical user interface (GUI) of the security analytics platform” are merely insignificant extra-solution activity as the act of displaying suggested prompts to a user is a well understood conventional activity like showing an FAQ or a menu of options, see MPM § 2106.05(g). To the extent of limiting the technological environment to a “security analytics platform,” it is merely field-of-use limitation, see MPEP § 2106.05(h). Further, this additional limitation does not recite a practical application or significantly more. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 5-6, 8-10, 12-13, 15-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Humphrey et al. US 20240414191 hereinafter referred to as Humphrey in view of Kopp et al. US 20240356943 hereinafter referred to as Kopp and Mace US 20240070270 hereinafter referred to as Mace. As per claim 1, Humphrey teaches a method comprising: receiving, by a security analytics platform, a natural language (NL) prompt (Humphrey [0026], [0030]: “interactive cyber-security user-interface (e.g. a chatbot) 182 receives supplied input from a user, whether it be via written, voice input, or other input source… interactive cyber-security user-interface for cybersecurity components 182 is a natural language interface”); providing the NL prompt as input to a large language model (LLM) (Humphrey [0026]: “the interactive cyber-security user-interface 182 can convert the speech to text and/or text from the user into supplied text that is fed into both an orchestrator LLM 111a that is also trained on natural language processing”); obtaining an output of the LLM comprising an indication that an intent of the NL prompt is associated with a security investigation service of a plurality of security investigation services of the security analytics platform (Humphrey [FIG. 1], [0026]: element 182 – interactive cyber-security user-interface for cybersecurity components; (Humphrey [0026-0027]: determines which cybersecurity components need to be queried, see e.g., “orchestrator LLM 111a to perform natural language processing in order to derive what the user said and what the user intended… the orchestrator LLM 111a provides the output of the natural language processing”); providing the NL prompt as input to a second LLM (Humphrey [0031], [0062-0063]: “Each of the task dedicated LLMs 111b-111e… second task dedicated LLM 111c is trained on a task of formatting a query from the user input into a search syntax”); and obtaining, from the second LLM, a search query (Humphrey [0062-0063]: “second task dedicated LLM 111c is trained on the search syntax for different things so that it knows how to understand, using that natural language processing functionality on what the user is asking, and then the search syntax required by the third-party service and/or the cybersecurity component being queried so that the second task dedicated LLM 111c knows what to send out”). Humphrey does not explicitly disclose modifying the NL prompt based on one or more parameters associated with the security investigation service and providing the modified NL prompt as input to the security investigation service. Kopp teaches modifying the NL prompt based on one or more parameters associated with the security investigation service and providing the modified NL prompt (Kopp [FIG. 5]: element 500 - analyst work unit data enhancement; Kopp [FIG. 9, step 906], [0157]: modifying a prompt with derived from work unit and threat intelligence data, see e.g., “can configure a natural language command, one or more first events based on the analyst work unit, one or more second events based on the at least one similar threat identified at 904, and/or a risk level based on the at least one similar threat identified at 904”) and providing the modified NL prompt as input to an LLM (Kopp [FIG. 9, step 906], [0157]: “inputs can be provided to the neural network-based generator to initiate operation 908”). Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Humphrey of an interactive cyber security user-interface system with the teachings of Kopp to include modifying the NL prompt based on parameters associated with the security investigation service and providing the modified NL prompt to the security investigation service in order to generate outputs that are contextually tailored to the specific security incident (Kopp [0108-0109]) and simplify the investigation process (Kopp [0075]). Humphrey in view of Kopp does not explicitly teach providing the modified NL prompt and one or more example search query translation pairs as input to a second LLM, wherein each example search query translation pair comprises a corresponding example natural language prompt and a corresponding example search query in a domain-specific (DSL) of the security investigation service; obtaining, from the second LLM, a DSL search query generated based on the modified NL prompt and the one or more example search query translation pairs; and providing the DSL search query as input to the security investigation service. Mace teaches one or more example search query translation pairs as input to an LLM, wherein each example search query translation pair comprises a corresponding example search query in a domain-specific language (DSL) of the security investigation service (Mace [Abstract], [FIG. 2], [0002], [0024], [0026], [0046]: example input queries and corresponding KQL queries consititute example NL prompt and corresponding example search query; shots constitute the example search query translation pair, see e.g., “generating a prompt, the prompt comprising: the input security hunting user query; the selected example user security hunting query and the corresponding example security language query… inputting the prompt to a large language model… generating a query in a security query language (i.e. a structured, code-like language such as KQL) from unstructured user input… The prompt 400 also includes shots 403, which are example input queries and corresponding KQL queries”); obtaining, from the LLM, a DSL search query generated based on the one or more example search query translation pairs (Mace [Abstract], [0002], [0037], [0100]: “receiving a security language query from the large language model corresponding to the input security hunting query”); and providing the DSL search query as input to the security investigation service.The use of the trained machine learning model to select the shots and query metadata results in accurate security language queries closely corresponding to the intent of the original user input (Mace [0027, [0040],[0101]: “The use of the trained machine learning model to select the shots and query metadata results in accurate security language queries closely corresponding to the intent of the original user input… security system 504 may comprise Microsoft® Defender® or Sentinel®. The user may interact with system 500 via the user interface 503… step S1007 includes executing the query in the security system 504”). Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Humphrey in view of Kopp of a security analytics platform that provides a modified NL prompt to a second LLM to generate a search query in the domain-specific language of the security investigation service with the teachings of Mace to include providing one or more example search query translation pairs each comprising an example NL prompt and a corresponding example search query in the DSL of the service as input to the LLM along with the prompt, such that the DSL search query is generated based on the example pairs in order to provide reliable, accurate DSL search queries that closely correspond to the intent of the original user input. As per claim 2, Humphrey in view of Kopp and Mace teaches the method of claim 1, wherein the modified NL prompt corresponds to a specified prompt format of the security investigation service (Kopp [FIG. 5]: element 500 - analyst work unit data enhancement; Kopp [0109]: command follows a specified prompt template format for the neural network-based generator, see e.g., “the neural network input generator 520 can configure a command… Here are some data from a security alert. Compose a concise story of what happened, as if it were a security risk report”). As per claim 3, Humphrey in view of Kopp and Mace teaches the method of claim 2, wherein the NL prompt is modified using the LLM, and wherein the method further comprises: providing user log data as input to the LLM, wherein the LLM is further configured to modify the NL prompt to include one or more characteristics of the use log data (Kopp [0109-0113], [0158]: the analyst work unit data enhancement inputs into the neural network input generator which configures to include user log data, see e.g., “the neural network input generator 520 can configure a command 521, analyst work unit data 522, and threat data 523… comprise events or attributes from the input analyst work unit 441… Event 1 title: Tor… Event 1 text: You are sending traffic to the Tor network … Event 2 title: Disabling security tools… Event 2 data commandLineArguments: sudo spctl-master-disable…the neural network-based generator can be configured to use at least one of NLP or a LLM” – i.e. user log data, capturing specific user activity logs such as event data and command-line arguments). As per claim 5, Humphrey in view of Kopp and Mace teach the method of claim 1, wherein the security investigation service comprises a security knowledge service configured to answer security questions related to at least one of: security investigation techniques, types of security vulnerabilities, or known security threat entities (Humphrey [0062]: 111c is a service of the platform; Kopp [0053]: NL prompt is provided to neural network, which generates security analysis outputs, see e.g., “high-level overview… alert resembles a malware dropper… potential risk ranges from malicious advertisement… resembles a new strain of qakbot… according to techniques used, the alert resembles the work of the known advanced persistent threat (APT) group”). As per claim 6, Humphrey in view of Kopp and Mace teach the method of claim 1, further comprising: receiving one or more outputs of the security investigation service; providing the one or more outputs and one or more example summaries as input to a third LLM configured to summarize the one or more outputs (Humphrey [0032]: discloses LLM 111d which is separate from the orchestrator LLM 111a and LLM 111c, and can constitute a third LLM, see e.g., “LLM 111d produces both a summarization of the cyber security information including the model breaches and the trends as well as provides any recommendations”) based on the one or more example summaries (Humphrey [0169]: formatting module uses ML models trained on “analyzing previous reports” in order to assess and populate data into incident reports… system uses “a multitude of a dynamic human-supplied and/or machine created templates corresponding to different types of cyber threats”); obtaining an output of the third LLM comprising a summary of the one or more outputs (Humphrey [0169]: formatting module generates “a textual write up of an incident report in the formalized report”); and providing the summary of the one or more outputs to be presented via a graphical user interface (GUI) of the security analytics platform (Humphrey [FIG. 1], [0026]: element 182 – interactive cyber-security user-interface for cybersecurity components, provides output to interactive cyber-security user-interface). As per claims 8-10 and 12-13, the claims disclose a system corresponding to the method claims 1-3 and 5-6 above, and they are rejected, at least for the same reasons. As per claims 15-17 and 19-20, the claims disclose a non-transitory computer-readable medium corresponding to the method claims 1-3 and 5-6 above, and they are rejected, at least for the same reasons. Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Humphrey in view of Kopp and Mace, and further in view Erlingsson et al. US 11770398 of hereinafter referred to as Erlingsson. As per claim 7, Humphrey in view of Kopp and Mace teaches the method of claim 1 and a security analytics platform (Humphrey [FIG. 1], [0026]: element 182 – interactive cyber-security user-interface for cybersecurity components). Humphrey in view of Kopp and Mace does not explicitly disclose prior to receiving the NL prompt, providing one or more pre-defined NL prompts to be presented via a graphical user interface (GUI). Erlingsson teaches prior to receiving the NL prompt, providing one or more pre-defined NL prompts to be presented via a graphical user interface (GUI) (Erlingsson [Col. 95, lines 64-66]: “the prompt describes the one or more natural language inputs in that the prompt suggests, to a user of the natural language interface”). Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Humphrey in view of Kopp and Mace of using a security analytics platform with the teachings of Erlingsson to include providing one or more pre-defined NL prompts prior to receiving the NL prompt via a UI in order to guide the user toward possible inquiries (Erlingsson [Col. 96, lines 13-15]). As per claim 14, the claim discloses a system corresponding to the method claim 7 above, and they are rejected, at least for the same reasons. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CAROLINE HOANG-ANH NGUYEN whose telephone number is (571)272-8309. The examiner can normally be reached Monday-Thursday 7am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /C.H.N./Examiner, Art Unit 2495 /HENRY TSANG/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Sep 05, 2024
Application Filed
Feb 09, 2026
Non-Final Rejection mailed — §101, §103
Apr 28, 2026
Applicant Interview (Telephonic)
Apr 28, 2026
Examiner Interview Summary
May 06, 2026
Response Filed
Jun 16, 2026
Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
100%
Grant Probability
99%
With Interview (+0.0%)
2y 1m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 1 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month