Prosecution Insights
Last updated: September 17, 2026
Application No. 18/876,946

SYSTEMS AND METHODS FOR DETECTION OF ADVANCED PERSISTENT THREATS IN AN INFORMATION NETWORK

Non-Final OA §101§103§112
Filed
Dec 19, 2024
Priority
Jun 24, 2022 — nonprovisional of PCTTR2022050653
Examiner
CHEEMA, ALI H
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Binalyze Yazilim A S
OA Round
1 (Non-Final)
75%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
156 granted / 209 resolved
+16.6% vs TC avg
Strong +54% interview lift
Without
With
+53.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
7 currently pending
Career history
217
Total Applications
across all art units

Statute-Specific Performance

§101
9.3%
-30.7% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
6.2%
-33.8% vs TC avg
§112
25.5%
-14.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 209 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Acknowledgements This office action is responsive to the election/restriction response filed on 08/05/2026. Applicant elects, without traverse, the claims 1-3 and 6 of Group I Invention for further prosecution on merits. In the application, Claims 1-3 and 6 have been elected, Claims 4-5 have been withdrawn, Claim1 is independent, and Claims 1-3 and 6 are pending and being considered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/19/2024 was filed on or after the mailing date of the application no.18/876,946 filed on 12/19/2024. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner and an initialed and dated copy of Applicant’s IDS form 1449 filed on 12/19/2024 is attached to the instant office action. Specification The disclosure is objected to because of the following informalities: paragraph numbers of the disclosure are missing. Examiner suggests to amend and resubmit the disclosure, by adding the paragraph numbers in beginning of the paragraphs to overcome this objection. The specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Claim Objections Claims 1-3 and 6 are objected to because of the following informalities: Regarding claim 1, the claim in line 7 recites “..., wherein a certain initial snapshot pertaining to the baseline operational state of an asset is created ...”. The phrase “the baseline operational state of an asset” as recited in the claim lacks antecedent bases. Examiner respectfully suggests the applicant to correct and rewrite it e.g. as “..., wherein a certain initial snapshot pertaining to [[the]] baseline operational state of an asset is created ...” Appropriate correction is required. Regarding claim 1, the claim in line 9 recites “said snapshot” which should be corrected and read as “said certain initial snapshot”, since the preceding passages of the claim (in line 6) discloses the term “a certain initial snapshot”. Appropriate correction is required. Regarding claim 1, the claim in lines 12-13 recites “... related to the operational and persistent state of at least one asset ...” which lacks antecedent bases since it has not been defined previously. Examiner respectfully suggests the applicant to correct and rewrite it e.g. as “... related to [[the]] an operational and persistent state of at least one asset ...” Appropriate correction is required. Regarding claim 1, examiner notes that the claim in line 12 recites “a set of predefined or user-defined parameters”. Then, in line 14, the claim recites “said set of pre-defined parameters”, which is expected to be read e.g. as “said set of pre-defined or user-defined parameters” for the consistency of the terms used in the claim. Appropriate correction is required. Regarding claim 1, the claim in lines 18-22 recites “diagnosis, wherein at the end of the differential analysis, the existence of a persistent threat is determined based on evidence reduction ...., and displaying what is shared, unique, changed, added, or removed from the initial snapshot to the non-initial snapshot represented by said distance in the differential analysis.” which should be corrected to read e.g. as “diagnosis, wherein after the differential analysis, [[the]] existence of a persistent threat is determined based on evidence reduction ...., and displaying what is shared, unique, changed, added, or removed from the certain initial snapshot to the at least one other forensic non-initial snapshot represented by said distance in the differential analysis.” Appropriate correction is required. Regarding claim 2, the claim in lines 1-6 recites “The method of differential analysis and investigation against cyber incidents as set forth in Claim 1 further comprising evidence reduction, wherein a set of parameters present in the initial snapshot and the non-initial snapshot are prioritized based on a user-defined measure of relevance.” which should be corrected and read e.g., as “The method of differential analysis and investigation against cyber incidents as set forth in Claim 1, further comprising: evidence reduction, wherein a set of parameters present in the certain initial snapshot and the at least one other forensic non-initial snapshot are prioritized based on a user-defined measure of relevance.”. Appropriate correction is required. Regarding claim 3, the claim in lines 1-6 recites “The method of differential analysis and investigation against cyber incidents as set forth in Claim 1 further comprising threat prioritization, ...” which should be corrected and read e.g., as “The method of differential analysis and investigation against cyber incidents as set forth in Claim 1, further comprising: threat prioritization, ...”. Appropriate correction is required. Regarding claim 6, the claim in lines 1-6 recites “The method of differential analysis and investigation against cyber incidents as set forth in Claim 2 further comprising threat prioritization, ...” which should be corrected and read e.g., as “The method of differential analysis and investigation against cyber incidents as set forth in Claim 2, further comprising: threat prioritization, ...”. Appropriate correction is required. Examiner further notes that the limitations within claim 1 are being ended with a comma (,) symbol, which should be corrected and replaced with a semicolon (;) symbol. Appropriate correction is required. Examiner respectfully suggests the applicant to rewrite claims in a clear and concise manner to overcome informalities. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-3 and 6 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Regarding claim 1, the claim recites "A method of differential analysis and investigation against cyber incidents such as advanced persistent threats in an information system network comprising at least multiple assets such as a mobile device, a computer, a virtual machine, a cloud service, or a cloud platform" which renders the claim indefinite because it is unclear whether the limitation(s) following the phrase “such as” are part of the claimed invention or not. See MPEP § 2173.05(d). Clarification is required. Regarding claim 1, the claim in line 8 recites “the device” which lacks antecedent bases since it has not been defined previously. The preceding passages of the claim (in line 3) just disclose the term “such as a mobile device”, where it is not clear as to whether or not the feature “the device” corresponds to “a mobile device”. Clarification is required. Regarding claim 1, the claim in line 10 recites “a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file” which renders the claim indefinite because the phrase “but not limited to” introduces an open-ended and ambiguous scope without any reasonable certainty. The phrase "but not limited to" as recited fails to define the boundaries what is being claimed, as it implies the claim can encompass elements outside of what is actually written. Under MPEP 2171, claims must precisely define what is protected. "But not limited to" leaves the reader guessing what else might be covered. Clarification is required. Regarding claim 1, the claim in lines 12-13 recites “the operational and persistent state of at least one asset” which has not been defined previously, and therefore lacks antecedent bases. Appropriate correction is required. Regarding claim 1, the claim in lines 14-17 recites the limitations “differential analysis, wherein said set of predefined parameters related to the operational and persistent state of at least one asset collected is differentially compared to that of a said certain initial snapshot, and a result is achieved based on a distance between said two snapshots” which renders the claim indefinite because of the following reasons: First, the claim in previous steps does not disclose to “collect said set of predefined parameters related to the operational and persistent state of at least one asset” as claimed, instead the preceding claim limitations, as disclosed in lines 11-13 of the claim, only recites “wherein at least one other forensic non-initial snapshot based on a set of predefined or user-defined parameters related to the operational and persistent state of at least one asset is collected”, and therefore it is unclear as to how the claimed said set of predefined parameters related to the operational and persistent state of at least one asset is being collected. Clarification is required. Secondly, the limitation further recites that “a result is achieved based on a distance between said two snapshots” which lacks antecedent basis because the preceding limitation only discloses to perform a differential comparison between the said certain initial snapshot and said set of predefined parameters related to the operational and persistent state of at least one asset and does not disclose to perform a differential comparison between said two snapshots, and therefore it is unclear as to how “a result is being achieved based on a distance between said two snapshots” when no differential comparison is being performed between the said two snapshots. Clarification is required. Examiner further notes that the recited term “said two snapshots” also lacks antecedent basis. It is unclear as to which two snapshots it is being referring to. Clarification is required. Dependent claims 2-3 and 6 are likewise rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph as being indefinite since they depend on and/or carries the deficiencies of the parent claims. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. The claimed invention is not directed to patent eligible subject matter. Based upon consideration of all of the relevant factors with respect to the claim as a whole, claims 1-3 and 6 are determined to be directed to an abstract idea. Claims 1-3 and 6 are rejected under 35 USC 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Under the 2019 Revised Patent Subject Matter Eligibility Guidance (“2019 PEG”), effective January 7, 2019, claims 1-3 and 6 are directed to an abstract idea without being significantly more nor being integrated into a practical application. The claims are directed towards differential analysis based on the collected snapshots. Regarding claim 1, the claim recites method steps “initial forensic snapshot creation, wherein a certain initial snapshot pertaining to the baseline operational state of an asset is created based on predetermined characteristics of the device that may be based on properties of that specific asset or its use case, said snapshot being selectable from a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file, forensic artifacts collection, wherein at least one other forensic non-initial snapshot based on a set of predefined or user-defined parameters related to the operational and persistent state of at least one asset is collected, differential analysis, wherein said at least a set of predefined parameters related to the operational and persistent state of at least one asset collected is differentially compared to that of a said certain initial forensic snapshot, and a result is achieved based on a distance between said two snapshots, diagnosis, wherein at the end of the differential analysis, the existence of a persistent threat is determined based on evidence reduction, threat prioritization based on relevance, and displaying what is shared, unique, changed, added, or removed from the initial snapshot to the non-initial snapshot represented by said distance in the differential analysis”, as drafted, are directed to an abstract idea without being significantly more nor being integrated into a practical application. For instance, the claim limitation “initial forensic snapshot creation, wherein a certain initial snapshot pertaining to the baseline operational state of an asset is created based on predetermined characteristics of the device that may be based on properties of that specific asset or its use case, said snapshot being selectable from a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file” as drafted, is a process that, under its broadest reasonable interpretation, covers performance in a human mind or by utilizing some additional physical steps e.g., a human using pen and paper. Such as, an ‘initial forensic snapshot creation’ is fundamentally considered as an Abstract Idea under 35 U.S.C. § 101, falling into the category of "organizing information" and/or "gathering and analyzing data", which can be performed by the human mind or with standard pencil and paper (like creating a baseline log/state of an asset, deciding how a device should be characterized, or storing information in a known format) are abstract. Choosing between formats like [CSV, JSON, plaintext, or log files] is merely the selection and organization of data, which does not amount to eligible subject matter on its own. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind (and/or by using pen and paper) but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. the claim limitation “forensic artifacts collection, wherein at least one other forensic non-initial snapshot based on a set of predefined or user-defined parameters related to the operational and persistent state of at least one asset is collected” as drafted, is a process that, under its broadest reasonable interpretation, covers performance in a human mind or by utilizing some additional physical steps e.g., a human using pen and paper. In 35 U.S.C. § 101, merely collecting and analyzing data, such as taking a "snapshot" of an asset's status based on predefined parameters is typically an ineligible abstract idea, unless it is tied to a specific technological improvement, a novel forensic mechanism, or solves a concrete computer-functioning problem, then it may be deemed patent-eligible. If the claim essentially boils down to "collecting information about a system and evaluating it", but for the recitation of generic computer components, then it falls under the "data collection, analysis, or evaluation" groupings of abstract idea. the claim limitation “differential analysis, wherein said at least a set of predefined parameters related to the operational and persistent state of at least one asset collected is differentially compared to that of a said certain initial forensic snapshot, and a result is achieved based on a distance between said two snapshots” as drafted, is a process that, under its broadest reasonable interpretation, covers performance in a human mind or by utilizing some additional physical steps e.g., a human using pen and paper. Under 35 U.S.C. § 101, a claim reciting the collection of asset’s state based on parameters, differential comparison of two data states (snapshots), and achieving a result based on the "distance" between them are fundamental concepts of an abstract idea, unless it is tied to a specific technological improvement, and specifies a highly unconventional and specific technological implementation, and solves a concrete computer-functioning problem, then it may be deemed patent-eligible. The claim language provided, herein, fundamentally describes comparing two data sets (snapshots) and calculating a difference or distance between them. If the claim essentially boils down to ‘analyzing data, comparing information, and generating results based on those comparisons’, but for the recitation of generic computer components, then it falls under the fundamental “mental processes” and/or “mathematical concepts” groupings of abstract idea. the claim limitation “diagnosis, wherein at the end of the differential analysis, the existence of a persistent threat is determined based on evidence reduction, threat prioritization based on relevance, and displaying what is shared, unique, changed, added, or removed from the initial snapshot to the non-initial snapshot represented by said distance in the differential analysis”, as drafted, is a process that, under its broadest reasonable interpretation, covers performance in a human mind or by utilizing some additional physical steps e.g., a human using pen and paper. Diagnostic determination is a fundamental concept of an unpatentable abstract idea if it is just a "result-oriented" claim and broadly states what the system detects without describing how the system structurally or mechanically achieves the detection (beyond standard mathematical or algorithmic analysis), it lacks an "inventive concept". The claim language provided, herein, fundamentally describes data analysis, evidence reduction, and prioritizing information based on relevance which falls under the categories of "mental processes" or "mathematical concepts” of abstract idea groupings. While, the steps of comparing snapshots to determine what is shared, unique, changed, added, or removed is essentially the concept of differential analysis, and displaying the results of comparing (or differential analysis), but for the recitation of generic computer components, is a common ineligible abstract idea. This judicial exception is not integrated into a practical application because the claim does not recite any additional element(s) that perform the claimed method steps. Thus, the claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the claim does not recite any additional element(s) that perform the claimed method steps. Thus, the claim is an abstract idea and is not patent eligible. Further, the recited elements within dependent claims 2-3 and 6 taken individually do not amount to “significantly more” than just the abstract idea as previously identified above. Therefore, the claims do not amount to significantly more than the previously defined abstract idea. Some of the evidences of “significantly more” are a) improvement to another technology or field; b) applying judicial exception with or by a “particular machine’; c) transforming particular article/data into different state or thing; d) adding unconventional or non-routine steps, producing useful application; and e) other meaningful limitations beyond generic link to particular technological environment. As a result, claims 1-3 and 6 are rejected under 35 U.S.C 101 as being directed to a non-statutory subject matter as the claims do not contain any element or combination of elements that is sufficient to ensure that the patent in practice amounts to significantly more than a patent upon the ineligible concept itself. See Alice, 134 S. Ct. at 2360. Under Alice, that is not sufficient "to transform an abstract idea into a patent-eligible invention." Claim Rejections - 35 U.S.C. 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or non-obviousness. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3 and 6 are rejected under 35 U.S.C. 103 as being unpatentable over Jared M. Smith (US 2018/0167403 A1; Hereinafter “Smith”) in view of MONSEN et al. (US 2020/0028867 A1; hereinafter “Monsen”). Regarding claim 1, Smith teaches A method of differential analysis and investigation against cyber incidents such as advanced persistent threats in an information system network comprising at least multiple assets such as a mobile device, a computer, a virtual machine, a cloud service, or a cloud platform, the method comprising (Smith in Abstract and para. [0003], describes a method process that detects malware by processing notifications from an intrusion detection system and baseline snapshots from an image capture utility, e.g., by performing forensic analysis. In an implementation, as disclosed in para. [0011], the malware impact systems interface one or more Intrusion Detection Systems (IDS) 112 and/or 114 that monitor computer systems to identify attempts or activities that violate security policies of a computer system or a network. Such as, disclosed in para. [0022], when an image from a potentially infected device is received, a data comparison tool calculates and displays the differences between that image and the most recent baseline image at 208.): initial forensic snapshot creation, wherein a certain initial snapshot pertaining to the baseline operational state of an asset is created based on predetermined characteristics of the device that may be based on properties of that specific asset or its use case (Smith in para. [0003] discloses to perform forensic analysis. Such as, disclosed in para. [0014-0015], the remote image capture utility 118 generates images of the entire system state including the system's executable code, its kernel, and its Basic Input Output System (BIOS) .... Once the remote image capture utility 118 registers with the malware impact system 100, the remote image capture utility 118 captures the baseline state of the system at a particular point in time via a snapshot. The snapshot is stored with the time and date of its capture as a baseline. The snapshot may occur in response to a request from a malware impact engine 122 or updated via a schedule at preconfigured time intervals. The remote image capture utility 118 may capture baseline images at synchronous and/or asynchronous intervals too. The remote image capture utility 118 creates an image of many data types, classes, and software running on a device), forensic artifacts collection, wherein at least one other forensic non-initial snapshot based on a set of predefined or user-defined parameters related to the operational and persistent state of at least one asset is collected (Smith in para. [0015-0016], discloses that the remote image capture utility 118 creates an image of many data types, classes, and software. The classes may include: running processes (e.g., running processes may include data associated with software processes including identification (ID) numbers, time started, time ended, time running, a number of threads, a user identifier associated with it, processor consumption, and memory consumption), process hierarchies, code libraries, kernel modules (e.g., the operating and file system and its mounted file systems and devices), user logs, network data, memory, files, registry, browser history, threads, files, ports, drivers, executed commands, memory dumps, system logs, system calls, credentials, terminal sessions, network configuration, operating systems, mounted file systems, etc. (e.g., parameters related to the operational and persistent state of at least one asset is collected), and as disclosed in para. [0021], when a request for a subsequent image (e.g., at least one other forensic non-initial snapshot) is received from the malware impact engine 122, the remote image capture utility 118 on the suspected device captures classes of data and links it to a baseline image. The classes of data that are captured are the same data captured when the remote image capture utility 118 established a baseline image for that device. The malware impact system 100 receives the image while it continues collect baseline images and alert requests from other clients 106 and servers 110. (herein, classes represent predefined parameters)), differential analysis, wherein said set of predefined parameters related to the operational and persistent state of at least one asset collected is differentially compared to that of a said certain initial snapshot, and a result is achieved based on a distance between said two snapshots (Smith in para. [0021] discloses that when an image from a potentially infected device is received, a data comparison tool calculates and displays the differences (e.g., distance) between that image and the most recent baseline image at 208. The comparison tool identifies the changes made in data structure by rendering a display that a manual and/or an automated system processes to identify the differences.), diagnosis, wherein at the end of the differential analysis, the existence of a persistent threat is determined based on evidence reduction, threat prioritization based on relevance, and displaying what is shared, unique, changed, added, or removed from the initial snapshot to the non-initial snapshot represented by said distance in the differential analysis (Smith in para. [0012] discloses that in a remote IDS 112, distributed IDS, and/or network based 114 IDS, a device may detect and notify the malware impact system 100 of a suspected intrusion with data (e.g., information indicative of the attack and its priority) and indicators indicating the strength of the possible detection, and as disclosed in para. [0022], when an image from a potentially infected device is received, a data comparison tool calculates and displays the differences between that image and the most recent baseline image at 208. The comparison tool identifies the changes made in data structure by rendering a display that a manual and/or an automated system processes to identify the differences, and as disclosed in para. [0023], while the malware impact system 100 calculates and displays the differences between the images, the malware impact system 100 assigns the suspected device a POST status, an/or as further disclosed in para. [0024], when differences between an image and a baseline image are detected, an optional push notification is transmitted to an analyst and/or a fully automated malware recovery system at 210. The differences may be rendered by a dashboard). Although, the cited prior art ‘Smith’ in para. [0014 & 0019] discloses to “generate and store snapshots/images in a hierarchical database, and provides access to the images”. However, Smith fails to explicitly discloses but Monsen teaches said snapshot being selectable from a group of binary or text formats including, but not limited to, CSV, JSON, plaintext, or log file (Monsen in para. [0048] discloses that, in response to receiving the query set 194, each of the host instances 122 execute the query set 194 to generate a different snapshot 198 that encapsulates the observations generated during the execution on the query set 194. The content and format of each of the snapshots 198 depend on the query set 194 and the query/monitor infrastructure 172. For instance, in some embodiments, each of the snapshots 198 may include any number of JavaScript Object Notation “JSON” files. In the same or other embodiments, each of the snapshots 198 may include a tabular output (e.g. CSV) representing the current operational state, and as disclosed in para. [0096], At step 414, the baseline analysis engine 160 attempts to retrieve, from the baseline database 140, the baseline snapshot 220 and the baseline query set 294 associated with the target instance group 120 specified in the forensic request 154. At step 416, the baseline analysis engine 160 determines whether the baseline analysis engine 160 has successfully retrieved the baseline snapshot 220 and the baseline query set 294. If, at step 416, the baseline analysis engine 160 determines that the baseline analysis engine 160 has successfully retrieved the baseline snapshot 220 and the baseline query set 294, then the method proceeds to step 418.), Although, as disclosed above, the cited prior art ‘Smith’ teaches the limitation “differential analysis, wherein said set of predefined parameters related to the operational and persistent state of at least one asset collected is differentially compared to that of a said certain initial snapshot, and a result is achieved based on a distance between said two snapshots” but Monsen in Abstract and para. [0088-0090 & 0107] also teaches “a method process to efficiently determine the host instances that are operating in an anomalous fashion during a security attack and remedy the attacks accordingly. The process includes to detect any outliers with respect to security-relevant features/subsets of features derived from observations included in the snapshots 198. Each snapshot represents a current operational state of the associated host instance. In an implementation, the clustering engine 320 then executes any number and type of clustering algorithms k-means clustering, k-nearest neighbors, etc.) based on different features and/or subsets of features across the different snapshots 198 to generate the clusters 330. The clustering engine 320 may identify the cluster 330 that is associated with the largest number of host instances 122 as a primary cluster (not shown) and all other clusters 330 as anomalous clusters 340. In another implementation, the clustering engine 320 weights the least common features based on the weight list 322 to determine an overall priority ranking for the features. The priory ranking for a feature estimates a relative likelihood that the observed differences associated with the feature are signs of a security attack. As depicted with the bubble numbered 10, the clustering engine 320 generates the anomaly dataset 290 based on the differences for the features having the highest priority rankings.” Thus, it would have been obvious to one ordinary skilled in the art before the effective filling date of the claimed invention to have modified the ‘Smith’ by incorporating the above features, as taught by Monsen, such modification provides an enhanced forensic analysis of host instances based on an acquired snapshot for each host instance in an instance group. The forensic analysis would detect the host instances that are being attacked, compromised and/or operating in an anomalous fashion during a security attack and would mitigate any damage arising from the attack; Monsen, Abstract & Para. [0003]. Regarding claim 2, Smith as modified by Monsen teaches the method of differential analysis and investigation against cyber incidents as set forth in Claim 1 further comprising wherein Smith further teaches evidence reduction, wherein a set of parameters present in the initial snapshot and the non-initial snapshot are prioritized based on a user-defined measure of relevance (Smith in para. [0012] discloses that in a remote IDS 112, distributed IDS, and/or network based 114 IDS, a device may detect and notify the malware impact system 100 of a suspected intrusion with data (e.g., information indicative of the attack and its priority) and indicators indicating the strength of the possible detection. If the one or more devices suspect an attack with weak or inconclusive data and/or indicators, the one or more devices may request an impact analysis by making one or more alert requests to the malware impact system 100 and transmitting its state information and its priority. And/or as disclosed in para. [0020] when a malware attack occurs, one or more remote 112, distributed, and/or network based 114 IDS transmit an alert request at 204 to the malware impact engine API 124. Each alert request contains a confidence level and a priority. When a confidence level establishes the likelihood of an infection, the malware impact engine 122 parses the alert request, cancel scheduled transfers to the suspected device, and schedules a snapshot of the suspected device through the remote image capture utility 118 on the suspected machine. As other alert requests are received, those requests are served in the order of their priority.). Regarding claim 3, Smith as modified by Monsen teaches the method of differential analysis and investigation against cyber incidents as set forth in claim 1 further comprising wherein Smith further teaches threat prioritization (Smith in para. [0012] discloses that in a remote IDS 112, distributed IDS, and/or network based 114 IDS, a device may detect and notify the malware impact system 100 of a suspected intrusion with data (e.g., information indicative of the attack and its priority) and/or as disclosed in para. [0020] when a malware attack occurs, one or more remote 112, distributed, and/or network based 114 IDS transmit an alert request at 204 to the malware impact engine API 124. Each alert request contains a confidence level and a priority. When a confidence level establishes the likelihood of an infection, the malware impact engine 122 parses the alert request, cancel scheduled transfers to the suspected device, and schedules a snapshot of the suspected device through the remote image capture utility 118 on the suspected machine. As other alert requests are received, those requests are served in the order of their priority.), wherein a level of threat is ascribed to at least two of said multiple assets, based on the distance between their respective initial images and non-initial images (Smith in para. [0014] discloses that the remote image capture utility 118 generates images of the entire system state including the system's executable code, its kernel, and its Basic Input Output System (BIOS) (e.g., assets), and as disclosed in para. [0024-0025], when differences between images are detected, an optional push notification is transmitted to an analyst and/or a fully automated malware recovery system at 210. In response, an optional malware recovery system may initiate remediation at 212, based on the differences between the images, the remediation may or may not shut down the affected device, revert the suspected device to an earlier baseline image without wiping the infected device, ignore the alert request because the differences between the images is deemed not harmful, etc.). Regarding claim 6, Smith as modified by Monsen teaches the method of differential analysis and investigation against cyber incidents as set forth in Claim 2 further comprising wherein Smith further teaches threat prioritization (Smith in para. [0012] discloses that in a remote IDS 112, distributed IDS, and/or network based 114 IDS, a device may detect and notify the malware impact system 100 of a suspected intrusion with data (e.g., information indicative of the attack and its priority) and/or as disclosed in para. [0020] when a malware attack occurs, one or more remote 112, distributed, and/or network based 114 IDS transmit an alert request at 204 to the malware impact engine API 124. Each alert request contains a confidence level and a priority. When a confidence level establishes the likelihood of an infection, the malware impact engine 122 parses the alert request, cancel scheduled transfers to the suspected device, and schedules a snapshot of the suspected device through the remote image capture utility 118 on the suspected machine. As other alert requests are received, those requests are served in the order of their priority.), wherein a level of threat is ascribed to at least two of said multiple assets, based on the distance between their respective initial images and non-initial images (Smith in para. [0014] discloses that the remote image capture utility 118 generates images of the entire system state including the system's executable code, its kernel, and its Basic Input Output System (BIOS) (e.g., assets), and as disclosed in para. [0024-0025], when differences between images are detected (e.g., level of threat is detected), an optional push notification is transmitted to an analyst and/or a fully automated malware recovery system at 210. In response, an optional malware recovery system may initiate remediation at 212, based on the differences between the images, the remediation may or may not shut down the affected device, revert the suspected device to an earlier baseline image without wiping the infected device, ignore the alert request because the differences between the images is deemed not harmful, etc.). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See form PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALI CHEEMA, whose contact number is 571-272-1239 and email: ali.cheema@uspto.gov. The examiner can normally be reached on Monday-Friday: 8:00AM – 4:00PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached on 571-272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ALI H. CHEEMA/ Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Dec 19, 2024
Application Filed
Aug 11, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739126
Data Transmission Method and Apparatus, Device, System, and Storage Medium
3y 4m to grant Granted Sep 15, 2026
Patent 12732362
Distribute Encryption Keys Securely and Efficiently
1y 8m to grant Granted Sep 08, 2026
Patent 12712919
APPLICATION PROGRAMMING INTERFACE (API) DOMAIN SPECIFIC LANGUAGE
2y 1m to grant Granted Aug 18, 2026
Patent 12712895
NEURAL NETWORK CONSTRUCTION
1y 10m to grant Granted Aug 18, 2026
Patent 12712740
SYSTEMS AND METHODS FOR ESTABLISHING DATA PROVENANCE BY GENERATING ONE-TIME SIGNATURES
1y 7m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
75%
Grant Probability
99%
With Interview (+53.8%)
2y 11m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 209 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month