Prosecution Insights
Last updated: October 01, 2026
Application No. 18/866,252

Method and module for detecting security vulnerabilities in a computer farm

Final Rejection §103§112
Filed
Nov 15, 2024
Priority
May 16, 2022 — FR FR2204607 +1 more
Examiner
VAUGHAN, MICHAEL R
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Orange
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
643 granted / 818 resolved
+20.6% vs TC avg
Strong +31% interview lift
Without
With
+30.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
10 currently pending
Career history
832
Total Applications
across all art units

Statute-Specific Performance

§101
13.7%
-26.3% vs TC avg
§103
40.0%
+0.0% vs TC avg
§102
25.6%
-14.4% vs TC avg
§112
16.6%
-23.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 818 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION The instant application having Application No. 18/866,252 is presented for examination by the examiner. Claims 1-12 are pending. Claims 1-11 have been amended. Response to Amendment Claim Rejections - 35 USC § 112 Rejections under this statute have been overcome by amendment. Response to Arguments Applicant's arguments filed 7/6/26 have been fully considered but they are not persuasive. On page 8, Applicant alleges that Doctor does not appear to describe such an indicator of exploitability. Examiner respectfully disagrees. Paragraph 0036 describes receiving back the scan results of a vulnerability scan. Those results of the scan are processed by the SAM and if a severe vulnerability is discovered an alert is generated (previous paragraph 0035]. So, the results from the vulnerability scan are interpreted as the claim’s signal comprising an indicator of the exploitability. It is readily apparent that vulnerabilities make the system vulnerable because they are exploitable. The claim does not require more than what is taught by the reference. In view of the foregoing, respectfully the rejection must be maintained. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over USP Application Publication 2015/0150072 to Doctor et al., hereinafter Doctor in view of NPL entitled “Towards Improving Container Security by Preventing Runtime Escapes” published Oct. 18, 2021 and cited on IDS filed 11/15/24, hereinafter Reeves. As per claim 11, Doctor teaches a security management device comprising: at least one processor (Fig. 5); and at least one non-transitory computer readable medium comprising instructions stored thereon which when executed by the at least one processor configure the security management device to identify exploitability of a computer vulnerability in at least one computer (Fig. 4 and 0035), said identifying including: receiving from said at last one computer (0035) a signal comprising an indicator of the exploitability of said vulnerability in a set of processes of said at least one computer (0036); and adding said signal to a list [SAM adds vulnerabilities to listed in database; 0031, 0037]. Doctor is silent in explicitly teaching the exploitability of said vulnerability in a set of processes is associated with a namespace combination. Reeves teaches the exploitability of said vulnerability in a set of processes is associated with a namespace combination (Table II, Fig. 2, section V, paragraph A and section II, paragraph A). Reeves tests various exploits on combinations of namespaces for processes inside of the container associated with the namespaces. Reeves teaches another type of vulnerability testing. Doctor teaches scans for many types of vulnerabilities on the devices. One could have obvious substituted this type of vulnerability test or combined it with the other types of tests that Doctor scans for. Either way, performing a scan for vulnerabilities and sending the result of the scan to a list is not predicated on which type of scan or test is being conducted. Substituting one type of scan for another would yield predictable results. Doctor already teaches conforming the tests to specific types of operating systems (0022). The claim is obvious because one of can substitute methods known before the effective filing date which produce predictable results. Allowable Subject Matter Claims 1-10 and 12 are allowable over the prior art. The closest prior art is the aforementioned Reeves NPL. While it does teach the exploitability of said vulnerability in a set of processes is associated with a namespace combination (Table II, Fig. 2, section V, paragraph A and section II, paragraph A) and various exploits on combinations of namespaces for processes inside of the container associated with the namespaces, Reeves does not explicitly teach the “detecting including, for a reference process of said set: initializing, from the reference process, and executing a test process associated with said combination” in combination with all of the other claim requirements. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL R. VAUGHAN whose telephone number is (571)270-7316. The examiner can normally be reached on Monday - Thursday, 7:30am - 5:00pm, EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL R VAUGHAN/ Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Nov 15, 2024
Application Filed
Jul 15, 2025
Response after Non-Final Action
Apr 03, 2026
Non-Final Rejection mailed — §103, §112
Jul 06, 2026
Response Filed
Sep 16, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744779
GRANULAR ADMINISTRATOR APPROVAL OF USER COMMANDS AND ACTIONS IN REMOTE ACCESS SESSIONS
2y 5m to grant Granted Sep 22, 2026
Patent 12739252
Determining Approval Workflows For Obtaining Approvals To Access Resources
2y 4m to grant Granted Sep 15, 2026
Patent 12739113
NETWORK STORAGE FOR PROCESSING CRYPTOGRAPHIC FILES WHILE KEEPING PRIVATE KEY SECRET IN KEY TERMINAL
1y 7m to grant Granted Sep 15, 2026
Patent 12732368
UTILIZING A CONTINGENT ACTION TOKEN
1y 7m to grant Granted Sep 08, 2026
Patent 12719840
Remote Execution of Computer Instructions in a Kernel Space of a Communication Device
2y 1m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+30.8%)
3y 0m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 818 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month