Prosecution Insights
Last updated: August 16, 2026
Application No. 18/870,124

DETECTION AND RESPONSE CONTROL SYSTEM, DETECTION AND RESPONSE CONTROL METHOD, HARDWARE ACCELERATOR, CONTROLLER, AND PROGRAM

Non-Final OA §103
Filed
Nov 27, 2024
Priority
Jun 01, 2022 — nonprovisional of PCTJP2022022305
Examiner
GUNDRY, STEPHEN T
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Nippon Telegraph and Telephone Corporation
OA Round
1 (Non-Final)
92%
Grant Probability
Favorable
1-2
OA Rounds
2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 92% — above average
92%
Career Allowance Rate
558 granted / 608 resolved
+33.8% vs TC avg
Moderate +9% lift
Without
With
+9.0%
Interview Lift
resolved cases with interview
Fast prosecutor
1y 11m
Avg Prosecution
18 currently pending
Career history
621
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
53.4%
+13.4% vs TC avg
§102
0.5%
-39.5% vs TC avg
§112
20.6%
-19.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 608 resolved cases

Office Action

§103
DETAILED ACTION This office action is in response to the application filed on 11/27/2024. Claim(s) 8-14 is/are pending and are examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority/Benefit Applicant’s priority claim is hereby acknowledged of 371 of PCT/JP2022/022305 06/01/2022, which papers have been placed of record in the file. Information Disclosure Statement PTO-1449 The Information Disclosure Statement(s) submitted by applicant on 11/27/2024 and 11/20/2025 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto. Examiner’s Note – Allowable Subject Matter Claim 9 overcomes the prior art and would otherwise be allowable if incorporated into the base claim along with any intervening claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 8, 10-13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Terada (US 2018/0332061 A1), in view of Joseph (US 2018/0084010 A1). Regarding claims 8 and 10-11, Terada teaches: “An attack detection and handling control system for performing detection and handling of a cyber attack (Terada, ¶ 29-30 teaches implementation with a processor, memory and medium to implement method steps), the attack detection and handling control system comprising: a controller configured to perform network control in an access network (Terada, Fig. 1 element 50 ¶ 26-27 teaches management server, i.e., controller, controlling network elements and policy); and a hardware accelerator configured to be connected to a communication device of the access network and to the controller (Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device), wherein the hardware accelerator comprises: a data acquisition unit configured to acquire communication data from the communication device (Terada, ¶ 26 and 31 monitoring apparatus acquires packets via communications acquisition unit 21); a data preprocessing unit configured to perform, on the acquired communication data, preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data (Terada, ¶ 67-70 teaches preprocessing the acquired packets and classifying them), an attack detection unit configured to receive a learning model for detecting an attack to be executed through the communication data from the controller and make a first determination in inline processing using the learning model as to whether the communication data acquired by the data acquisition unit is the attack (Terada, ¶ 47 teaches that the pattern data comes from the management server, i.e., controller. Terada, ¶ 67-70 teaches that the system is a learning model. Terada, ¶ 33-35 teaches detecting an attack. Terada, ¶ 47 teaches that the process is inline); a detection alert notification unit configured to generate a detection alert including detection information and network information, the detection information including a detection reason of the communication data determined as the attack, the network information being related to the communication data (Terada, ¶ 32, 72, 82, and 97-98 teaches issuing an alert of the attack with the pertinent information); and a handling performance unit configured to acquire, and perform, based on the acquired handling control policy, the attack handling on the communication data acquired by the data acquisition unit in inline processing (Terada, ¶ 32, 72, 82, and 97-98 teaches implementing a countermeasure to the attack)”. Terada does not, but in related art, Joseph teaches machine to machine interactions as well as: “wherein the controller comprises: a learning unit configured to receive the preprocessed data from the hardware accelerator and, based on the received preprocessed data, generate the learning model for detecting the attack to be executed through the communication data (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model); and a handling determination unit configured to receive the detection alert from the hardware accelerator, make a second determination using the received detection alert as to whether attack handling is required, and when the second determination is that attack handling is required, create the handling control policy so as to include a type of the attack and a handling technique and transmit the handling control policy to the hardware accelerator (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”. Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results. Regarding claim 12, Terada teaches: “A hardware accelerator configured to be connected to a controller that performs network control in an access network and to a communication device of the access network Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device), the hardware accelerator comprising: a data acquisition unit configured to acquire communication data from the communication device (Terada, ¶ 26 and 31 monitoring apparatus acquires packets via communications acquisition unit 21); a data preprocessing unit configured to perform, on the acquired communication data, preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data (Terada, ¶ 67-70 teaches preprocessing the acquired packets and classifying them), an attack detection unit configured to receive a learning model for detecting an attack to be executed through the communication data from the controller and make a first determination in inline processing using the learning model as to whether the communication data acquired by the data acquisition unit is the attack (Terada, ¶ 47 teaches that the pattern data comes from the management server, i.e., controller. Terada, ¶ 67-70 teaches that the system is a learning model. Terada, ¶ 33-35 teaches detecting an attack. Terada, ¶ 47 teaches that the process is inline); a detection alert notification unit configured to generate a detection alert including detection information and network information and transmits the detection alert to the controller, the detection information including a detection reason of the communication data determined as the attack, the network information being related to the communication data (Terada, ¶ 32, 72, 82, and 97-98 teaches issuing an alert of the attack with the pertinent information); and a handling performance unit configured to acquire, and perform, based on the acquired handling control policy, the attack handling on the communication data acquired by the data acquisition unit in inline processing (Terada, ¶ 32, 72, 82, and 97-98 teaches implementing a countermeasure to the attack)”. Terada does not, but in related art, Joseph teaches: “transmit the preprocessed data to the controller (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model); from the controller, a handling control policy including information required for attack handling (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”. Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results. Regarding claims 13 and 14, Terada teaches: “A controller configured to be communicably connected with a hardware accelerator connected to a communication device of an access network (Terada, ¶ 29-30 teaches implementation with a processor, memory and medium to implement method steps. Terada, Fig. 1 element 50 ¶ 26-27 teaches management server, i.e., controller, controlling network elements and policy. Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device)”. Terada does not, but in related art, Joseph teaches machine to machine interactions as well as: “the controller comprising: a learning unit configured to acquire, from the hardware accelerator, communication data on which preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data has been performed and generate a learning model for detecting an attack to be executed through the communication data (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model); and a handling determination unit configured to acquire a detection alert on the communication data in which the attack is detected by the hardware accelerator using the learning model, make a determination using the acquired detection alert as to whether attack handling is required, and when the determination is that the attack handling is required, create a handling control policy including a type of the attack and a handling technique and transmit the handling control policy to the hardware accelerator (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”. Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results. Conclusion In the case of amending the claimed invention, Applicant is respectfully requested to indicate the portion(s) of the specification which dictate(s) the structure relied on for proper interpretation and also to verify and ascertain the metes and bounds of the claimed invention. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure: See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Stephen T Gundry whose telephone number is (571) 270-0507. The examiner can normally be reached Monday-Friday 9AM-5PM (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /STEPHEN T GUNDRY/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Nov 27, 2024
Application Filed
May 20, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705393
System and Process for Location-Based Anonymity and Privacy
2y 2m to grant Granted Aug 11, 2026
Patent 12699758
INFORMATION PROCESSING SYSTEM, INFORMATION PROCESSING APPARATUS AND METHOD, STORAGE CASE AND INFORMATION PROCESSING METHOD, AND PROGRAM
2y 4m to grant Granted Aug 04, 2026
Patent 12682114
ANONYMIZING DATA IN DATABASE ON A SERVER
2y 3m to grant Granted Jul 14, 2026
Patent 12675577
SYSTEMS AND METHODS FOR INTRODUCING DATA QUALITY AWARENESS IN SECURITY ANALYTICS SOLUTIONS
3y 8m to grant Granted Jul 07, 2026
Patent 12675608
METHOD AND SYSTEM FOR SANITIZATION OF SENSITIVE DATA
2y 7m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
92%
Grant Probability
99%
With Interview (+9.0%)
1y 11m (~2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 608 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month