Prosecution Insights
Last updated: October 02, 2026
Application No. 18/870,607

DETECTION DEVICE, DETECTION SYSTEM, AND DETECTION METHOD

Non-Final OA §103
Filed
Nov 29, 2024
Priority
May 31, 2022 — JP 2022-088140 +2 more
Examiner
NGUYEN, LINH T
Art Unit
2459
Tech Center
2400 — Computer Networks
Assignee
Autonetworks Technologies Ltd.
OA Round
1 (Non-Final)
71%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 71% — above average
71%
Career Allowance Rate
259 granted / 366 resolved
+12.8% vs TC avg
Strong +26% interview lift
Without
With
+26.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
18 currently pending
Career history
401
Total Applications
across all art units

Statute-Specific Performance

§101
10.3%
-29.7% vs TC avg
§103
62.6%
+22.6% vs TC avg
§102
10.3%
-29.7% vs TC avg
§112
15.1%
-24.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 366 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 11/29/2024is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Election/Restrictions Applicant indicates Group I, claims 1-6 and 8 is elected without traverse for prosecution. Claims 9 and 10 are new. Claims 1-6, 8-10 are pending in the instant application. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4 and 8-10 are rejected under 35 U.S.C. 103 as being unpatentable over Rooney et al. (US 2006/0010389), hereinafter Rooney in view of Rubin et al. (US 2021/0243208), hereinafter Rubin. As for claim 1, Rooney teaches a detection device configured to detect an abnormality in a network (Figures. 6, attack detection system 200; paragraphs [0078]-[0079] describe a DDoS attack detection system comprising a network processor), in the network, transmission and reception of a plurality of messages including a response message being performed by a plurality of communication apparatuses (paragraphs [0076]-[0077] describe an attacker (e.g. a computer), an agent devices, intermediary nodes (e.g., routers and servers) that require responses with request packets’ inscribed source address set to the IP address of a target machine. The attacker cause agent devices to send request packets to the intermediary nodes that requires responses, without knowing that the request packets are source address spoofed to the target’s address, the intermediary nodes flood the target machine with response packets according to the type of request packets), the detection device comprising: an acquisition unit configured to acquire a plurality of pieces of load information respectively indicating communication loads at a plurality of locations in the network (paragraphs [0083]-[0085] describe the network processor of an analyzer retrieves data accumulated in a storage facility and processes it to obtain parameters relating to the volumes of packets from the respective geographical locations. These parameters include the variances in the volumes of packets from the respective geographical locations with respect to each other over the intervals of the first defined time period), the plurality of pieces of load information respectively indicating communication loads due to the messages whose transmission sources are different from each other (paragraphs [0076] and [0085] describe a network processor is arranged to read a proportion of the packets in the observed network packet stream on a link between two ASes and to accumulate in a storage facility data pertaining to the source IP addresses of the read packets and their time of reception); and a detection unit configured to detect an abnormality in the network, based on parameters of load information acquired by the acquisition unit (paragraphs [0085]-[0086] describe the processing unit of the analyzer retrieves accumulated data from the storage facility and analyses the data to correlate, for example, the variances in the volumes of packets from the respective geographical locations. If the change in the volume of packets is greater than the threshold then the processing unit determines that a DDoS attack may be occurring and is transmitting packets on the observed link). Rooney fails to teach wherein parameters include consistency between the plurality of pieces of load information. Rubin discloses wherein parameters include consistency between the plurality of pieces of load information (paragraphs [0058]-[0059] describe a difference (e.g. 10 percent) of an amount of data transfer between a first computer to a second computer, and between a second computer to a third computer. The 10 percent tolerance is an example of consistent data transfer sizes). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Rubin for detecting lateral movement between networked computers. The teachings of Rubin, when implemented in the Rooney system, will allow one of ordinary skill in the art to detect a cyberattack on detecting anomalies. One of ordinary skill in the art would be motivated to utilize the teachings of Rubin in the Rooney system in order to limit or otherwise mitigate harm from an attack. As for claim 2, the combined system of Rooney and Rubin teaches wherein the acquisition unit acquires three or more pieces of the load information respectively indicating communication loads at three or more locations in the network (Rooney: paragraph [0086] describes the processing unit of the analyzer retrieves accumulated data from the storage facility and analyzes the data to correlate the variances in the volumes of packets from respective geographical locations with respect to each other over the intervals of that define time periods. The volumes of packets having IP source address indicating Asia, Europe and the USA), and the detection unit identifies an abnormality location in the network, based on the consistency for each combination of two pieces of the load information included in the three or more pieces of load information (Rooney: paragraph [0086] describes if the change in the volume of packets is greater than a predefined threshold then the processing unit determines that a DDoS attack may be occurring; Rubin: paragraphs [0058]-[0059] describe a difference (e.g. 10 percent) of an amount of data transfer between a first computer to a second computer, and between a second computer to a third computer. The 10 percent tolerance is an example of consistent data transfer sizes). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Rubin for detecting lateral movement between networked computers. The teachings of Rubin, when implemented in the Rooney system, will allow one of ordinary skill in the art to detect a cyberattack on detecting anomalies. One of ordinary skill in the art would be motivated to utilize the teachings of Rubin in the Rooney system in order to limit or otherwise mitigate harm from an attack. As for claim 3, the combined system of Rooney and Rubin teaches wherein in the network, transmission and reception of the messages are performed between a first of the communication apparatuses and a plurality of the communication apparatuses different from the first communication apparatus (Rooney: paragraphs [0076]-[0077] describe an attacker (e.g. a computer), an agent devices, intermediary nodes (e.g., routers and servers) that require responses with request packets’ inscribed source address set to the IP address of a target machine. The attacker cause agent devices to send request packets to the intermediary nodes that requires responses, without knowing that the request packets are source address spoofed to the target’s address, the intermediary nodes flood the target machine with response packets according to the type of request packets), the acquisition unit acquires a first of the load information indicating a communication volume of the message whose transmission source is the first communication apparatus (Rooney: paragraph [0071] describes each intermediate network comprises a network of routers in the form of an autonomous system (AS); paragraphs [0083] and [0085] describe the network processor of a packet sampler is arranged to observe a packet stream at a point between edge routers of two major networks such as ASes in the Internet to compile a profile over a first defined time period of the respective volumes of packets having IP source addresses that indicate their respective global geographical locations), and a plurality of pieces of a second of the load information each indicating a communication volume of the message whose transmission source is the communication apparatus different from the first communication apparatus (paragraphs [0083] and [0085] describe the network processor of a packet sampler is arranged to observe a packet stream at a point between edge routers of two major networks such as ASes in the Internet to compile a profile over a first defined time period of the respective volumes of packets having IP source addresses that indicate their respective global geographical locations), the plurality of pieces of the second load information respectively corresponding to a plurality of the communication apparatuses different from the first communication apparatus (Rooney: paragraph [0083] describes packet stream between edge routers are observed to compile a profile over a defined time period of the respective volumes of packets having IP source addresses that indicate their respective global geographical locations. Note: routers that belong to two major networks and having IP source addresses that indicate their respective global geographical locations are construed as distinct communication apparatus (i.e. the first and second apparatus)), and the detection unit detects an abnormality in the network, based on the consistency between the communication volume of the message indicated by the first load information and the communication volume of the message indicated by the second load information (Rooney paragraph [0086] describes the processing unit determines a DDoS attack has happened; Rubin: paragraphs [0058]-[0059] describe a difference (e.g. 10 percent) of an amount of data transfer between a first computer to a second computer, and between a second computer to a third computer. The 10 percent tolerance is an example of consistent data transfer sizes). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Rubin for detecting lateral movement between networked computers. The teachings of Rubin, when implemented in the Rooney system, will allow one of ordinary skill in the art to detect a cyberattack on detecting anomalies. One of ordinary skill in the art would be motivated to utilize the teachings of Rubin in the Rooney system in order to limit or otherwise mitigate harm from an attack. As for claim 4, the combined system of Rooney and Rubin teaches wherein the detection device further comprises an observation unit configured to observe an output, of the message having been extracted, performed by an extraction device (Rooney: paragraphs [0079]-[0081] describe the sampler includes a network processor able to sample packets from a network stream on link between two network. The network processor receives all packets transmitted through the Internet and arranged to read at least some of the packets in order to derive data pertaining to at least the source IP address of those packets and time of reception of the packets. The sampler includes a data storage facility for storing accumulated source related IP address data and packet reception times. The analyzer communicates with the storage facility of the sampler and the analyzer’s processing unit for analyzing data retrieved from the storage facility), the extraction device being configured to extract the message transmitted from the communication apparatus (Rooney: paragraphs [0079] describe the sampler includes a network processor able to sample packets from a network stream on link between two network. The network processor receives all packets transmitted through the Internet and arranged to read at least some of the packets in order to derive data pertaining to at least the source IP address of those packets and time of reception of the packets), the extraction device being configured to output the message having been extracted, to another of the communication apparatuses and the detection device (Rooney: paragraphs [0080]-[0081] describe the sampler includes a data storage facility accumulated source related IP address data and packet reception times. The data storage facility is connected by a dedicated link to the network processor of the sampler. The analyzer has a processing unit which executes an analyzer program comprising program code suitable for analyzing data retrieved from the storage facility), and the acquisition unit generates the load information, based on an observation result from the observation unit (Rooney: paragraph [0086] describes the processing unit of the analyzer retrieves accumulated data from the storage facility and analyzes the data to correlate the variances in the volumes of packets from the respective geographical locations with respect to each other over the intervals of the defined time period). As for claim 8, Rooney teaches detection method performed in a detection device configured to detect an abnormality in a network (paragraphs [0082]-[0083] describe a method of DDoS detection), in the network, transmission and reception of a plurality of messages including a response message being performed by a plurality of communication apparatuses (paragraphs [0076]-[0077] describe an attacker (e.g. a computer), an agent devices, intermediary nodes (e.g., routers and servers) that require responses with request packets’ inscribed source address set to the IP address of a target machine. The attacker cause agent devices to send request packets to the intermediary nodes that requires responses, without knowing that the request packets are source address spoofed to the target’s address, the intermediary nodes flood the target machine with response packets according to the type of request packets), the detection method comprising the steps of: acquiring a plurality of pieces of load information respectively indicating communication loads at a plurality of locations in the network (paragraphs [0083]-[0085] describe the network processor of an analyzer retrieves data accumulated in a storage facility and processes it to obtain parameters relating to the volumes of packets from the respective geographical locations. These parameters include the variances in the volumes of packets from the respective geographical locations with respect to each other over the intervals of the first defined time period), the plurality of pieces of load information respectively indicating communication loads due to the messages whose transmission sources are different from each other (paragraphs [0076] and [0085] describe a network processor is arranged to read a proportion of the packets in the observed network packet stream on a link between two ASes and to accumulate in a storage facility data pertaining to the source IP addresses of the read packets and their time of reception). Rooney fails to teach detecting an abnormality in the network, based on consistency between the plurality of pieces of load information having been acquired. Rubin discloses detecting an abnormality in the network, based on consistency between the plurality of pieces of load information having been acquired (paragraphs [0058]-[0059] describe a difference (e.g. 10 percent) of an amount of data transfer between a first computer to a second computer, and between a second computer to a third computer. The 10 percent tolerance is an example of consistent data transfer sizes). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Rubin for detecting lateral movement between networked computers. The teachings of Rubin, when implemented in the Rooney system, will allow one of ordinary skill in the art to detect a cyberattack on detecting anomalies. One of ordinary skill in the art would be motivated to utilize the teachings of Rubin in the Rooney system in order to limit or otherwise mitigate harm from an attack. As for claim 9, the combined system of Rooney and Ruby teaches wherein the network includes a switch device configured to relay the messages transmitted and received between the communication apparatuses (Rooney: paragraph [0078] describes the DDoS attack detection system samples packets being transmitted over a link between two networks or between two Automated Systems (ASes). The detection system is physically located with a router/gateway at an edge of the networks), and each piece of the information indicates the data pertaining to volumes of packets in a transmission path between the switch device and a corresponding one of the communication apparatuses serving as the transmission sources (Rooney: paragraphs [0078]-[0079] and [0086] describe the DDoS attack detection system samples packets using a packet sampler. The sampler includes a network processor which is located in the internet so as to be able to sample packets from a network stream on a link between two networks. The network processor is arranged to read at least some of those packets in order to derive data pertaining to at the source IP addresses of those packets and the time of reception of those packets. The processing unit of the analyzer receives accumulate data and analyzes the data to correlate the variances in the volumes of packets from respective geographical locations with respect to each other over the intervals of a defined time period). Rooney fails to teach wherein data pertaining to volumes of packets is the communication load. Rubin discloses wherein data pertaining to volumes of packets is the communication load (paragraphs [0058]-[0059] describe data being transferred from a first computer to a second computer, then to a third computer. The data transfer size between the computers is calculated to derive a tolerance in percentage that leads to a decision that an attack is occurring). As for claim 10, the combined system of Rooney and Ruby teaches wherein the network includes a switch device configured to relay the messages transmitted and received between the communication apparatuses (Rooney: paragraph [0078] describes the DDoS attack detection system samples packets being transmitted over a link between two networks or between two Automated Systems (ASes). The detection system is physically located with a router/gateway at an edge of the networks), and the plurality of pieces of load information include the load information indicating the communication load in the switch device and the load information indicating data pertaining to volumes of packets in a transmission path between the switch device and each communication apparatus serving as the transmission source (Rooney: paragraphs [0078]-[0079] and [0086] describe the DDoS attack detection system samples packets using a packet sampler. The sampler includes a network processor which is located in the internet so as to be able to sample packets from a network stream on a link between two networks. The network processor is arranged to read at least some of those packets in order to derive data pertaining to at the source IP addresses of those packets and the time of reception of those packets. The processing unit of the analyzer receives accumulate data and analyzes the data to correlate the variances in the volumes of packets from respective geographical locations with respect to each other over the intervals of a defined time period). Rooney fails to teach wherein data pertaining to volumes of packets is the communication load. Rubin discloses wherein data pertaining to volumes of packets is the communication load (paragraphs [0058]-[0059] describe data being transferred from a first computer to a second computer, then to a third computer. The data transfer size between the computers is calculated to derive a tolerance in percentage that leads to a decision that an attack is occurring). Claims 5 and 6 are rejected under 35 U.S.C. 103 as being unpatentable over Rooney (US 2006/0010389) in view of Rubin (US 2021/0243208) further in view of Sudo et al. (US 2018/0041471), hereinafter Sudo. As for claim 5, the combined system of Rooney and Rubin teaches wherein the acquisition unit acquires the load information indicating a communication load calculated based on a value and the communication volume of the message transmitted by the first communication apparatus (Rooney: paragraphs [0086]-[0088] describe the processing unit of the analyzer retrieves accumulate data and analyzes the data to correlate, for example, the variances in the volumes of packets from the respective geographical locations). The combined system of Rooney and Rubin fails to teach wherein a value includes a number of the response messages predicted based on a type of the message transmitted by the first communication apparatus. Sudo discloses wherein a value includes a number of the response messages predicted based on a type of the message transmitted by the first communication apparatus (paragraph [0024] and [0026] describe attack packets of the reflective DDoS attack are DNS request packets; paragraphs [0033] and [0052] describes a controller observes the amount of traffic of target-addresses DNS reply that reaches each of the border routers. Then, on the basis of the amount of traffic of target-addresses DNS reply that reach each of the border routers, the controller estimates the total amount of traffic of target-addressed DNS replies that would be transferred from the border routers to the controller when the border routers shift to the list preparation state). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Sudo for sampling an attack-target addressed DNS reply. The teachings of Sudo, when implemented in the Rooney and Rubin system, will allow one of ordinary skill in the art to add the transmission-source IP address of the sampled DNS reply to a black list. One of ordinary skill in the art would be motivated to utilize the teachings of Sudo in the Rooney and Rubin system in order to enable a border router to transfer a reply packet, whose destination is the IP address and the port number described in a white list, but block other reply packets of a DNS (Sudo: paragraph [0003]). As for claim 6, the combined system of Rooney, Rubin and Sudo teaches wherein the acquisition unit acquires the load information indicating a communication load calculated based on a number of the response messages predicted further based on header information of the message transmitted by the first communication apparatus (Sudo: paragraphs [0080]-[0082] and [0093] describe a received packet is determined whether it is a DNS reply and a UDP subsequent fragment by checking the IP header of the packet). One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Sudo for sampling an attack-target addressed DNS reply. The teachings of Sudo, when implemented in the Rooney and Rubin system, will allow one of ordinary skill in the art to add the transmission-source IP address of the sampled DNS reply to a black list. One of ordinary skill in the art would be motivated to utilize the teachings of Sudo in the Rooney and Rubin system in order to enable a border router to transfer a reply packet, whose destination is the IP address and the port number described in a white list, but block other reply packets of a DNS (Sudo: paragraph [0003]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Soni et al. (US 2020/0120131) teach predicted network traffic Gabaev et al. (US 2018/0278647) teach computer security attack detection using distribution departure Dewagamage et al. (US 2014/0289397) transmission method Any inquiry concerning this communication or earlier communications from the examiner should be directed to L. T N. whose telephone number is (571)272-1013. The examiner can normally be reached M & Th 5:30 am - 2:30 pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, TONIA DOLLINGER can be reached at 571-272-4170. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /L. T. N/ Examiner, Art Unit 2459/TONIA L DOLLINGER/Supervisory Patent Examiner, Art Unit 2459
Read full office action

Prosecution Timeline

Nov 29, 2024
Application Filed
Aug 17, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750314
NETWORK ADDRESS TRANSLATION (NAT) HOLE PUNCHING OVER SOFTWARE-DEFINED WIDE AREA NETWORKING (SD-WAN) FOR LINK QUALITY SELECTION OF VIRTUAL PRIVATE NETWORKING (VPN) TUNNELS
1y 9m to grant Granted Sep 29, 2026
Patent 12726543
METHODS PROVIDING V2X APPLICATION SERVER REGISTRATION
1y 9m to grant Granted Sep 01, 2026
Patent 12719951
MOBILE ROBOT AND CONTROL METHOD THEREOF
2y 6m to grant Granted Aug 25, 2026
Patent 12718257
Establishing Ownership of Dual Route Processors (RPs) using Secure Zero-Touch Provisioning (ZTP)
2y 4m to grant Granted Aug 25, 2026
Patent 12706849
ROUTABLE AND INTENT-BASED SERVICE CHAINS
3y 0m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
71%
Grant Probability
97%
With Interview (+26.5%)
2y 11m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 366 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month