Prosecution Insights
Last updated: October 02, 2026
Application No. 18/890,168

MALICIOUS ACTIVITY DETECTION BASED ON CHANGES IN A SECURITY GRAPH

Final Rejection §103
Filed
Sep 19, 2024
Examiner
TRUVAN, LEYNNA THANH
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
1y 8m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
397 granted / 519 resolved
+18.5% vs TC avg
Strong +20% interview lift
Without
With
+20.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
15 currently pending
Career history
540
Total Applications
across all art units

Statute-Specific Performance

§101
7.3%
-32.7% vs TC avg
§103
51.8%
+11.8% vs TC avg
§102
23.2%
-16.8% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 519 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The amendment of claims 1-20, filed on 4/6/2026, is acknowledged and considered. Claims 1, 8, and 17 are independent claims. Claims 1, 4-12, 14-23 are pending. Claims 2-3 and 13, are cancelled by Applicant. Claims 21-23 are new. Allowable Subject Matter 4. Claims 1, 4-7, and 21 are in condition for allowance. Response to Arguments 5. Applicant’s arguments with respect to claim(s) 1, 4-12, 14-23 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. The arguments of claims 8-12, 14-20, and 22-23, are directed towards new limitations that are now rejected under Guo, et al. [US 12659327] in view of Dong, et al. [US 20250029000]. Further, claims 1, 4-7, and 21 are in condition for allowance. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 8-12, 14-20, and 22-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Guo, et al. [US 12659327] in view of Dong, et al. [US 20250029000]. As per claim 8: Guo, et al. teaches a method for mitigating anomalies in a network-based computing system, the method comprising: receiving a first snapshot of a graph representative of a tenant account of the network-based computing system [Guo: col 28, line 33-60; a new snapshot is taken and information from the new snapshot is merged with existing data to create and (as additional data is collected/processed) maintain a cumulative graph. Col 74, line 44-61; An identity refers to an account or login that an entity may use, a role that an entity may assume (e.g., an AWS Assumed Role), a group (e.g., an AWS Identity and Access Management (IAM) group, that an entity may join, a unique identifier assigned to or associated with an entity, and/or any other identifier associated with one or more permissions that allow an entity to access or interact with various applications and/or resources within compute environment], the first snapshot corresponding to a first timestamp; [Guo: col 24, line 51-60; Graphs created by graph generator is written to data store and cached for further processing. A graph is a summary of all activity that happened in a particular time interval. As each graph corresponds to a distinct period of time, different rows can be aggregated to find summary information over a larger timestamp] receiving a second snapshot of the graph corresponding to a second timestamp subsequent to the first timestamp; [Guo: col 24, line 51-60; Each graph corresponds to a distinct period of time, different rows can be aggregated to find summary information over a larger timestamp. The graph with different timestamps of distinct periods suggest the graph with associated snapshot and of different or subsequent timestamp] determining, based on the first and second snapshots, a first change in the graph; [Guo: col 29, line 12-18; the detection of a new PType can be used to generate an alert where surviving nodes (i.e., present in both the cumulative graph and the snapshot graph) change PTypes, such change is noted as a transition] determining a second change in the graph related to the first change; [Guo: col 22, line 53; FIG. 2M illustrates an example of a portion of a privilege change graph, which identifies how privileges are changed between processes. If the privileges are different, a privilege change has occurred (whether a change up or a change down). See also col.53, line 33-45; a graph can be constructed which models privilege changes. In the graph, each node is a cluster of processes executed by a particular user. An edge in the graph, from a first node to a second node, indicates that a user of the first node changed its privilege to the user of the second node] determining a third change in the graph; [Guo: col 39, line 15-28; types of events represent multiple changes in the underlying GBM cluster level graph in terms of multiple new clusters or multiple new edges between clusters] determining a relationship between the first change, the second change, and the third change satisfies a cumulative anomaly criterion; [Guo: col 22, line 42-52; FIG. 2L, if the user deviates from his baseline behavior (e.g., using new applications, or changing privilege in anomalous ways), such anomalies can be surfaced. Col 28, line 52-60; PType clusters in the snapshot's graph are compared against PType clusters in the cumulative graph to identify commonality] detecting a potential anomaly based on the relationship between the first change, the second change, and the third change satisfying the cumulative anomaly criterion; and [Guo: col.29, line 23-32; changes to the cumulative graph can be used to detect anomalies. Two example kinds of anomalies that can be detected by data platform include security anomalies and devops/root cause anomalies. Detected anomalies can be recorded and surfaced, such as through alerts which are generated based on anomaly detection. More examples of detection of cumulative anomaly criterion - col.69, line 42-67] **responsive to said detecting the potential anomaly, causing a mitigation step to be performed with respect to the tenant account. [**rejected under a secondary reference, discussion below] Guo discloses detecting a potential anomaly based on the relationship between the first change, the second change, and the third change satisfying the cumulative anomaly criterion by changes to the cumulative graph can be used to detect anomalies. Two example kinds of anomalies that can be detected by data platform include security anomalies and devops/root cause anomalies. The detection of a new PType can be used to generate an alert where surviving nodes (i.e., present in both the cumulative graph and the snapshot graph) change PTypes, such change is noted as a transition. Detected anomalies can be recorded and surfaced, such as through alerts which are generated based on anomaly detection. [Guo: col.29, line 12-32, col.69, line 42-67]. However, Guo did not clearly teach “responsive to said detecting the potential anomaly, causing a mitigation step to be performed with respect to the tenant account”. Dong teaches an electronic communications processing systems evaluate a set of known entities to identify other entities that are close to the set of known entities within an electronic communication network graph [Dong: para 0016]. Dong discloses the generation of features for nodes in snapshots of a network graph may advantageously allow for evaluation of anomalies in different entities at different windows of time. In this example, such techniques advantageously allow electronic communication processing systems to quickly analyze electronic communication data to identify problematic suspicious behavior and, thereby, mitigate potential future suspicious (and potentially fraudulent) behavior. Such techniques advantageously decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss (e.g., financial, user trust, etc.) associated with problematic or suspicious electronic communications. [Dong: para 0019]. As such, Dong obviously suggest “responsive to said detecting the potential anomaly, causing a mitigation step to be performed with respect to the tenant account”, where one would be motivated to advantageously allow for evaluation of anomalies in different entities at different windows of time and decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss associated with problematic or suspicious electronic communications. Dong further discloses a network graph include nodes representing both entities (e.g., servers, users, user wallets, user accounts, etc.) and the communications in which the entities have participated (e.g., server transmissions, electronic transactions, etc.) [Dong: para 0030]. Dong also use in training a machine learning model to predict anomalies in entity behavior [Dong: para 0047]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Dong with Guo to teach “responsive to said detecting the potential anomaly, causing a mitigation step to be performed with respect to the tenant account”, for the reason to evaluate anomalies in different entities at different windows of time and advantageously decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss associated with problematic or suspicious electronic communications [Dong: para 0019]. Claim 9: Guo: col 28, line 52-60 and col.29, line 12-32 [the snapshot's graph are compared in the cumulative graph to identify commonality changes, detection of nodes]; discussing the method of claim 8, wherein: the graph comprises a first node and a second node; said determining the first change comprises determining a change in the first node; and said determining the second change comprises determining a change in the second node. Claim 10: Guo: col 78, line 53-67 and col 88, line 17-20 [node with resources and account]; discussing the method of claim 9, wherein: the first node represents a user account of the tenant account; the second node represents a first resource of the tenant account; and said determining the change in the first node comprises determining the user account is granted access to the first resource. Claim 11: Guo: col 73, line 15-30; discussing the method of claim 10, wherein said determining the change in the second node comprises: determining the first resource is granted access to a second resource. Claim 12: Guo: col 69, line 50-67; discussing the method of claim 9, wherein said detecting a potential anomaly comprises: determining a severity level of the potential anomaly based on the first node, the second node, and an edge corresponding to the first and second nodes. Claim 13: Cancelled Claim 14: Guo: col 29, line 23-32; discussing the method of claim 8, wherein said determining the first change comprises determining a level of access property of a user account associated with the tenant account has changed; and wherein the method further comprises determining a number of new edges connected to a first node of the graph satisfies an anomaly criterion. Claim 15: Guo: col 11, line 10-25 and col 40, line 55-col 41, line 15 [different users with respective access and determine malicious activity]; discussing the method of claim 8, wherein said determining the first change comprises determining a level of access property of a user account associated with the tenant account has changed; and wherein the method further comprises detecting an amount of download activity associated with the user account satisfies an anomaly criterion. Claim 16: Guo: col 24, line 51-60 and col 39, line 15-28 [Each graph corresponds to a distinct period of time with timestamp, multiple changes in cluster level graph in terms of multiple new clusters or multiple new edges between clusters]; discussing the method of claim 8, wherein the first node is representative of a first resource, the second node is representative of a second resource, the first edge indicates the first resource has access to the second resource, the second snapshot of the graph further comprises a third node representative of an account and a second edge indicating the account has access to the first resource, and the method further comprises: receiving a third snapshot of the graph corresponding to a third timestamp different from the first timestamp and the second timestamp [Guo: col 24, line 51-60; Each graph corresponds to a distinct period of time, different rows can be aggregated to find summary information over a larger timestamp], the third snapshot comprising a third edge coupling the first node to a fourth node representative of a third resource, and wherein said determining the second change is based on the third snapshot. [Guo: col.53, line 33-45; a graph can be constructed which models privilege changes, each node is a cluster of processes. An edge in the graph, from a first node to a second node, indicates that a user of the first node changed its privilege to the user of the second node] As per claim 17: Guo, et al. teaches a computer-readable storage medium encoded with program instructions structured to cause a processor circuit to perform a method comprising: generating a graph representative of a tenant account of a network-based computing system [Guo: col 28, line 33-60; a new snapshot is taken and information from the new snapshot is merged with existing data to create and (as additional data is collected/processed) maintain a cumulative graph. Col 74, line 44-61; An identity refers to an account or login that an entity may use, a role that an entity may assume (e.g., an AWS Assumed Role), a group (e.g., an AWS Identity and Access Management (IAM) group, that an entity may join, a unique identifier assigned to or associated with an entity, and/or any other identifier associated with one or more permissions that allow an entity to access or interact with various applications and/or resources within compute environment], the graph comprising a first node and a second node; [Guo: col.53, line 33-45; a graph can be constructed which models privilege changes. In the graph, each node is a cluster of processes executed by a particular user. An edge in the graph, from a first node to a second node, indicates that a user of the first node changed its privilege to the user of the second node] detecting a first change in the graph based on a first snapshot of the graph at a first timestamp; [Guo: col 29, line 12-18; the detection of a new PType can be used to generate an alert where surviving nodes (i.e., present in both the cumulative graph and the snapshot graph) change PTypes, such change is noted as a transition] detecting a second change in the graph based on a second snapshot of the graph at a second timestamp subsequent to the first timestamp; [Guo: col 22, line 53; FIG. 2M illustrates an example of a portion of a privilege change graph, which identifies how privileges are changed between processes. If the privileges are different, a privilege change has occurred (whether a change up or a change down). See also col 24, line 51-60; Each graph corresponds to a distinct period of time, different rows can be aggregated to find summary information over a larger timestamp. The graph with different timestamps of distinct periods suggest the graph with associated snapshot and of different or subsequent timestamp] detecting a third change in the graph; [Guo: col 39, line 15-28; types of events represent multiple changes in the underlying GBM cluster level graph in terms of multiple new clusters or multiple new edges between clusters] determining a relationship between the first change, the second change, and the third change satisfies a cumulative anomaly criterion; [Guo: col 22, line 42-52; FIG. 2L, if the user deviates from his baseline behavior (e.g., using new applications, or changing privilege in anomalous ways), such anomalies can be surfaced. Col 28, line 52-60; PType clusters in the snapshot's graph are compared against PType clusters in the cumulative graph to identify commonality] detecting a potential anomaly based on the cumulative anomaly criterion being satisfied; and [Guo: col.29, line 23-32; changes to the cumulative graph can be used to detect anomalies. Two example kinds of anomalies that can be detected by data platform include security anomalies and devops/root cause anomalies. Detected anomalies can be recorded and surfaced, such as through alerts which are generated based on anomaly detection. More examples of detection of cumulative anomaly criterion - col.69, line 42-67] **responsive to the detection of the potential anomaly, cause a mitigation step to be performed with respect to the tenant account. [**rejected under a secondary reference, discussion below] Guo discloses detecting a potential anomaly based on the relationship between the first change, the second change, and the third change satisfying the cumulative anomaly criterion by changes to the cumulative graph can be used to detect anomalies. Two example kinds of anomalies that can be detected by data platform include security anomalies and devops/root cause anomalies. The detection of a new PType can be used to generate an alert where surviving nodes (i.e., present in both the cumulative graph and the snapshot graph) change PTypes, such change is noted as a transition. Detected anomalies can be recorded and surfaced, such as through alerts which are generated based on anomaly detection. [Guo: col.29, line 12-32, col.69, line 42-67]. However, Guo did not clearly teach “responsive to the detection of the potential anomaly, cause a mitigation step to be performed with respect to the tenant account”. Dong teaches an electronic communications processing systems evaluate a set of known entities to identify other entities that are close to the set of known entities within an electronic communication network graph [Dong: para 0016]. Dong discloses the generation of features for nodes in snapshots of a network graph may advantageously allow for evaluation of anomalies in different entities at different windows of time. In this example, such techniques advantageously allow electronic communication processing systems to quickly analyze electronic communication data to identify problematic suspicious behavior and, thereby, mitigate potential future suspicious (and potentially fraudulent) behavior. Such techniques advantageously decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss (e.g., financial, user trust, etc.) associated with problematic or suspicious electronic communications. [Dong: para 0019]. As such, Dong obviously suggest “responsive to the detection of the potential anomaly, cause a mitigation step to be performed with respect to the tenant account”, where one would be motivated to advantageously allow for evaluation of anomalies in different entities at different windows of time and decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss associated with problematic or suspicious electronic communications. Dong further discloses a network graph include nodes representing both entities (e.g., servers, users, user wallets, user accounts, etc.) and the communications in which the entities have participated (e.g., server transmissions, electronic transactions, etc.) [Dong: para 0030]. Dong also use in training a machine learning model to predict anomalies in entity behavior [Dong: para 0047]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Dong with Guo to teach “responsive to the detection of the potential anomaly, cause a mitigation step to be performed with respect to the tenant account”, for the reason to evaluate anomalies in different entities at different windows of time and advantageously decrease the amount of computer resources necessary to perform feature queries as well as decreasing loss associated with problematic or suspicious electronic communications [Dong: para 0019]. Claim 18: col 29, line 23-32 and col 88, line 17-20 [node with resources and account]; discussing the computer-readable storage medium of claim 17, wherein: the first node represents a user account of the tenant account; the second node represents a first resource of the tenant account; said determining the first change comprises determining the user account is granted access to the first resource; and said determining the second change comprises determining the first resource is granted access to a second resource. Claim 19: Guo: col 69, line 50-67; discussing the computer-readable storage medium of claim 17, wherein said detecting a potential anomaly comprises: determining a severity level of the potential anomaly based on the first node, the second node, and an edge corresponding to the first and second nodes. Claim 20: Guo: col 28, line 52-60 and col.29, line 12-32 [changes to the cumulative graph can be used to detect anomalies, detection of cumulative anomaly criterion]; discussing the computer-readable storage medium of claim 17, wherein said detecting the potential anomaly comprises: determining a plurality of other changes in the graph different from the first change and the second change; determining a relationship between the first change, the second change, and the plurality of other changes; and determining the relationship satisfies a cumulative anomaly criterion. Claim 22: Guo: col 28, line 52-60 and col.29, line 12-32 [changes to the cumulative graph can be used to detect anomalies, with a threshold amount of commonality]; discussing the method of claim 8, wherein said determining the relationship satisfies a cumulative anomaly criterion comprises: determining a number of changes comprising the first change, the second change, and the third change satisfies a threshold. Claim 23: Guo: col 74, line 44-61 and col 78, line 53-67 [different nodes with respective account and resource access]; discussing the method of claim 16, wherein: the first node is representative of a first resource, the second node is representative of a second resource, the graph further comprises a first edge indicating the first resource has access to the second resource, the second snapshot of the graph further comprises a third node representative of an account and a second edge indicating the account has access to the first resource, the third snapshot comprises a third edge coupling the first node to a fourth node representative of a third resource, and said determining the second change is based on the third snapshot. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Leynna Truvan whose telephone number is (571)272-3851. The examiner can normally be reached Monday-Friday 9:00AM-5:00PM, EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Leynna Truvan Examiner Art Unit 2435 /L.TT/Examiner, Art Unit 2435 /EDWARD ZEE/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Sep 19, 2024
Application Filed
Jan 06, 2026
Non-Final Rejection mailed — §103
Feb 24, 2026
Examiner Interview Summary
Feb 24, 2026
Applicant Interview (Telephonic)
Apr 06, 2026
Response Filed
Jun 29, 2026
Final Rejection mailed — §103
Sep 16, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750217
SIGN-EFFICIENT ADDITION AND SUBTRACTION FOR STREAMINGCOMPUTATIONS IN CRYPTOGRAPHIC ENGINES
4y 2m to grant Granted Sep 29, 2026
Patent 12744819
FRICTIONLESS SUPPLEMENTARY MULTI-FACTOR AUTHENTICATION FOR SENSITIVE TRANSACTIONS WITHIN AN APPLICATION SESSION
2y 2m to grant Granted Sep 22, 2026
Patent 12726371
METHOD AND APPARATUS FOR CONTROLLING TITLE TO A PHYSICAL OBJECT
3y 3m to grant Granted Sep 01, 2026
Patent 12695616
NON-FUNGIBLE TOKENS FOR VIRTUAL ACCESSORIES DURING VIRTUAL MEETINGS
4y 0m to grant Granted Jul 28, 2026
Patent 12695611
METHODS AND SYSTEMS FOR GENERATING, SUBSCRIBING TO AND PROCESSING ACTION PLANS USING A BLOCKCHAIN
3y 4m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
97%
With Interview (+20.1%)
3y 9m (~1y 8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 519 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month