Prosecution Insights
Last updated: October 02, 2026
Application No. 18/894,889

ADNS TELEMETRY

Final Rejection §102§103
Filed
Sep 24, 2024
Examiner
HUSSAIN, TAUQIR
Art Unit
2449
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
12m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
699 granted / 829 resolved
+26.3% vs TC avg
Strong +26% interview lift
Without
With
+25.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
29 currently pending
Career history
865
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
56.1%
+16.1% vs TC avg
§102
19.0%
-21.0% vs TC avg
§112
7.2%
-32.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 829 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This office action is in response to amendment/reconsideration filed on 06/12/2026, the amendment/reconsideration has been considered. Claims 1-20 are pending for examination as cited below. Response to Arguments Applicant's arguments filed06/12/2026 have been fully considered but they are not persuasive. In remarks applicant argues in substance that: (a) Applicant argues that Liu does not disclose an “ADNS telemetry cache” and instead only teaches a predictive cache for DNS query responses. Applicant further argues that Liu does not disclose collecting or aggregating telemetry data for transmission to a cloud security service. Examiner respectfully disagree because Liu discloses a cache that stores DNS-related data and provides it to a remote security platform. Liu expressly teaches: A predictive cache storing DNS related information e.g., “….prediction engine 174…ML model 176…cache 178…” (Liu, [0024]) A security platform that receives DNS related information e.g., “security platform 140…results of analysis (and additional information pertaining to application, domain, etc.) are stored in database 160.” (Liu [0023]) DNS tunneling detector and predictive cache operating together to detect “DNS tunning detector 138 and /or predictive cache 170.” (Liu, [0024]) The predictive cache stores DNS related information (including predicted address information, suspiciousness indicators, and domain profiles) and interacts with a remote security platform. This meets the broad claim language of “telemetry data” and “transmission to a cloud security service.” Liu further discloses collecting DNS related information and transmitting it to a remote platform. Applicant asserts Liu only performs local detection. Examiner respectfully disagree because Liu teaches, Data appliance 102 collects DN related information, Security platform 140 receives and stores analysis results, Database 160 stores domain/application information and Predictive cache 170 and detector module 172 provides DNS related telemetry to the security platform. Thus, Liu discloses collection, caching, and transmission of DNS related telemetry to a remote platform. Applicant’s arguments rely on an overly narrow interpretation of “telemetry cache.” Liu’s predictive cache and associated modules meet the claim limitation. The rejection is maintained. Regarding claims 3-5 and 13 (dual cache / active and inactive cache) Applicant argues that neither Liu nor Huq discloses dual telemetry caches or toggling between active and inactive caches. Examiner respectfully disagree because, Liu discloses multiple caches. Liu explicitly teaches, Predictive cache data 262, Legacy cache data 264, model data 260 and file system data 270, see figure 2, [0024]. Thus, Liu discloses multiple caches used for DNS related processing. Additionally, Huq discloses, cache state changes and cache role switching. Huq teaches: Modifying cache behavior when authoritative DNS is degraded, Extending TTL, Flushing cache entries, Switching between cache and non-cached resolution paths. These behaviors constitute cache role changes, which corresponds to toggling between active and inactive caches. The combination teaches toggling for instance, Liu provides multiple caches; Huq provides cache state transition. The combination yields the claimed toggling between active and inactive caches. Applicant’s argument that Huq’s cache operations are “only for degraded server conditions” is not persuasive. The claims do not require toggling to occur only for telemetry reporting; they merely require toggling. The combination teaches just that. Regarding claims 6-9 (predefined time interval / cache swap) Applicant argues that Kawa’s dual cache mechanism is limited to database streaming and does not apply to DNS telemetry. Examiner respectfully disagree because: Kawa discloses: two caches, swapping roles, toggling based on completion of write intervals and enabling simultaneous read/write operations. This is exactly the claimed “toggling according to a predefined time interval.” The claims do not require DNS-specific toggling. The claims recite generic toggling of caches. Kawa teaches DNS related caching and so the combination is proper under 35 USC 103. Regarding claims 14-17 Applicant argues that, Chen only discloses cache invalidation for mobile computers, or Chen does not disclose identifying unsent telemetry entries, discarding them, or reporting aggregated statistics and the office action allegedly relies on hindsight and ignores difference in purpose and environment. Examiner respectfully disagree because (a) Chen teaches expiration based cache invalidation. Chen expressly discloses, “…periodic broadcast invalidation reports from the server…”, “…cached objects are invalidated upon expiration….” These teachings corresponds directly to the claim requirements of determining that a particular time interval expired and performing cache operations based on that expiration. Chen further discloses, identifying stale or unsent entries e.g., identifying cached objects that are no longer valid, identifying objects are were not synchronized during disconnection, and marking or discarding those objects. This meets the claim requirement of: “identifying entries in the inactive cache that were not successfully communicated during the interval.” Chen further teaches discarding entries after expiration e.g., “…cached object s are discarded when invalidation reports indicate they are outdated…” This corresponds to, “discarding entries not successfully communicated during the interval.” Chen yet again teaches reporting aggregated information. Chen’s invalidation reports include, metadata, summary information, aggregated invalidation data and that meets the claim requirement of: “providing aggregated statistics for entries not sent during the interval.” Applicant’s argument that Chen is limited to “database coherency” is not persuasive. The claim do not require any specific type of telemetry, nor they exclude database style invalidation. The claims recite generic cache management operations, and Chen teaches those operations. Applicant’s argument of “hindsight reconstruction” is not persuasive. Each reference contributes a well-known, predictable cache management technique, e.g., Liu discloses, DNS telemetry and predictive caching; Huq discloses, cache state transition and Chen discloses, expiration based invalidation and reporting, Kawa teaches “dual cache toggling”. The combination is proper under KSR because: The references address similar problems (cache management, synchronization, reporting), The techniques are well-known and predictable, The claims recite generic cache operations. Applicant argues that Chen’s purpose differs from the claimed telemetry reporting. Examiner respectfully disagree because obviousness does not require identical purpose (MPEP 2141). The claims recite generic cache operations, not DNS specific or telemetry specific operations. Chen’s invalidation logic is directly applicable to any cached data, including telemetry. The office action does not “ignore difference”; rather properly applies Chen’s teachings to the claimed generic cache operations. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-2, and 25-26 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232”. As to claim 1. Liu discloses, a system (Liu232, Abstract, fig.1), comprising: one or more processors configured to: cache advanced domain name system (ADNS) telemetry data in an ADNS telemetry cache in a local security platform (Liu232, [0024], security platform 140 comprises DNS tunneling detector 138 and/or predictive cache 170. Also see fig.1, [0036], local DNS-122); send the cached ADNS telemetry data from the local security platform to a cloud security service in near real time for a real-time threat analysis using ADNS telemetry (Liu232, fig.1, [0036], security platform 140 will determine (e.g., using DNS tunneling detector 138) whether the queried domain indicates a malicious DNS tunneling attempt and provide a result back to DNS module 134 (e.g., “malicious DNS tunneling” or “non-tunneling”) and [0031], malicious DNS tunneling can efficiently be detected, in real time, and stopped.); and a memory coupled to the one or more processors and configured to provide the one or more processors with instructions (Liu232, [0014], The system comprises one or more processors and a memory. The one or more processors are configured to receive a DNS query, determine whether to obtain target address information corresponding to the DNS query from a predictive cache). As to claim 2. Liu232 discloses, wherein the local security platform is a next generation firewall (Liu232, [0020], the predictive cache is deployed on a firewall.) . As to claim 25 is rejected for same rationale as applied to claim 1 above. As to claim 26 is rejected for same rationale as applied to claim 1 above. Claim(s) 3-5 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232” in view of Huque et al. (Pub. No.: US 2018/0375716 A1, hereinafter “Huq”. As to claim 3. Liu232 disclose the invention as in parent claim above. Liu232 however is silent to disclose explicitly, wherein the ADNS telemetry cache comprises a first telemetry cache and a second telemetry cache. Huq discloses a similar concept in the same field on endeavor including, wherein the ADNS telemetry cache comprises a first telemetry cache and a second telemetry cache (Huq, [0140], wherein the first cache is used to store DNS records; and generating a first DNS response to the first DNS query based on a first DNS record stored in the modified first cache.). Therefore, before the effective filing date of the instant application it would have been obvious to one of the ordinary skilled in the art to incorporate the teachings of “Huq” into those of “Liu232” to provide a resolution resiliency application. A resolution resiliency application modifies domain name service (DNS) resolution. In operation, the resolution resiliency application determines that an authoritative name server has begun recovering from a degraded state or receives a flush list update from the authoritative name server. In response, the resolution resiliency application performs operation(s) that modify a query rate and/or a cache. The query rate specifies a frequency associated with DNS queries transmitted to the first authoritative name server. The cache stores DNS record(s) received from the first authoritative name server. As to claim 4. The combine system of Liu232 and Huq disclose the invention substantially as applied above including, wherein the first telemetry cache and the second telemetry cache are toggled between an active cache and an inactive cache (Huq, [0138]-[0145], records are extracted interchangeably between first and second cache). As to claim 5. The combine system of Liu232 and Huq disclose the invention substantially as applied above including, wherein at a particular time the first telemetry cache is configured as the active cache and the second telemetry cache is configured as the inactive cache (Huq, [0138]-[0145], records are extracted interchangeably between first and second cache). As to claim 13. The combine system of Liu232 and Huq and Kala disclose the invention substantially as applied above including, wherein sending the cached ADNS telemetry data to the cloud security service (Liu232, [0036]) comprises: communicate, during a particular time interval, to the cloud service ADNS telemetry data stored in the cache (Liu232, [0036]); and store, during a particular time interval, ADNS telemetry information in the active cache in response to the ADNS local cache being queried and hit during the particular time interval (Liu232, [0036]. Active and inactive cache interpreted and first telemetry cache and second telemetry cache as disclosed by Huq reference.). Claim(s) 6-9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232” in view of Huque et al. (Pub. No.: US 2018/0375716 A1, hereinafter “Huq” and further in view of Kawahito et al. (Pub. No.: US 2019/0377822 A1), hereinafter “Kawa”. As to claim 6. The combine system of Liu232 and Huq disclose the invention substantially as applied above. Liu232 and Haq are silent to disclose explicitly, wherein the first telemetry cache and the second telemetry cache are toggled according to a predefined time interval. Kawa discloses a similar concept in the same field of endeavor including, wherein the first telemetry cache and the second telemetry cache are toggled according to a predefined time interval (Kawa, [0044], Upon elapse of the aforesaid predefined time window, the role of the first cache area is swapped with the role of the second cache area.). Therefore, before the effective filing date of the instant application it would have been obvious to one of the ordinary skilled in the art to incorporate the teachings of “Kawa” into those of “Liu232 and Huq” to provide a first cache area and a second cache area on a cache memory in a data processing system comprising a database repository and the cache memory for the database repository. The computer enables, in at least part of the first time window, synchronization between the database repository and the second cache area. The computer enables, upon elapse of the first time window, synchronization between the first cache area and the database repository. As to claim 7. The combine system of Liu232, Huq and Kawa disclose the invention substantially as applied above including, wherein the predefined time interval is 1 second (Kawa, [0044], describes a predefined time window, therefore it is merely an intended use to change the interval as needed.). As to claim 8. The combine system of Liu232, Huq and Kawa disclose the invention substantially as applied above including, wherein the predefined time interval is updated at run time via a command input (Huq, [0007], indiscriminately extending TTLs increases the amount of time that the recursive resolver exposes users to potentially invalid records. TTL can be modified as per design choice). As to claim 9. The combine system of Liu232, Huq and Kawa disclose the invention substantially as applied above including, wherein the predefined time interval is less than or equal to 5 seconds (Kawa, [0044], describes a predefined time window, therefore it is merely an intended use to change the interval as needed.). Claim(s) 10-12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232” in view of Huque et al. (Pub. No.: US 2018/0375716 A1, hereinafter “Huq” and further in view of Kalamatianos et al. (Pat. No.: US 9021207 B2), hereinafter “Kala”. As to claim 10. The combine system of Liu232 and Huq disclose the invention substantially as applied above. Liu232 however is silent to disclose explicitly, wherein a size of the active cache and the inactive cache is configurable. Kala discloses a similar concept in the same field of endeavor including, wherein a size of the active cache and the inactive cache is configurable (Kala, abstract, the cache size is increased based on a measured processor performance metric, such as an eviction rate of the cache. In some embodiments, the cache size is increased at regular intervals until a maximum size is reached.). Therefore, before the effective filing date of the instant application it would have been obvious to one of the ordinary skilled in the art to incorporate the teachings of “Kala” into those of “Liu232 and Huq” to provide a in response to a processor core exiting a low-power state, a cache is set to a minimum size so that fewer than all of the cache's entries are available to store data, thus reducing the cache's power consumption. Over time, the size of the cache can be increased to account for heightened processor activity, thus ensuring that processing efficiency is not significantly impacted by a reduced cache size. As to claim 11. The combine system of Liu232, Huq and Kala disclose the invention substantially as applied above including, wherein the active cache and the inactive cache respectively have sufficient space to store 10240 entries (Kala, abstract, the cache size is increased based on a measured processor performance metric, such as an eviction rate of the cache. In some embodiments, the cache size is increased at regular intervals until a maximum size is reached. And it is merely an intended use to change the cache storage as needed.). As to claim 12. The combine system of Liu232, Huq and Kala disclose the invention substantially as applied above including, wherein the active cache and the inactive cache respectively have sufficient space to store a predefined number of entries (Kala, abstract, the cache size is increased based on a measured processor performance metric, such as an eviction rate of the cache. In some embodiments, the cache size is increased at regular intervals until a maximum size is reached. And it is merely an intended use to change the cache storage as needed.). Claim(s) 14-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232” in view of Huque et al. (Pub. No.: US 2018/0375716 A1, hereinafter “Huq” and further in view of Chen et al. (Pat. No.: US 6128648), hereinafter “Chen”. As to claim 14. The combine system of Liu232 and Huq disclose the invention substantially as applied above. Liu232 and Huq however are silent to disclose explicitly, wherein communicating, during a particular time interval, to the cloud service ADNS telemetry data stored in the inactive cache comprises: determine that the particular time interval expired; in response to determining that the particular time interval expired, identify entries in the inactive cache that were not successfully communicated to the cloud security service during the time interval; and discard the entries in the inactive cache that were not successfully communicated to the cloud security service. Cheng discloses a similar concept in the same field of endeavor including, determine that the particular time interval expired (Cheng, col.2, lines 53-55, the server maintains for each group an object update history of the past W broadcast intervals, consisting of a list of object IDs and their most recent update times,); in response to determining that the particular time interval expired, identify entries in the inactive cache that were not successfully communicated to the cloud security service during the time interval (Cheng, col.2 lines 49-58, To retain the cold objects in a group that have not been updated, the server maintains for each group an object update history of the past W broadcast intervals, consisting of a list of object IDs and their most recent update times, and the most recent update time of the group. Periodically, the server broadcasts an invalidation report containing the last w broadcast intervals of object update history.); and discard the entries in the inactive cache that were not successfully communicated to the cloud security service (Cheng, col.3 lines 1-5, Thus, in GCORE cache invalidation is accomplished by an asymmetrical approach where a server periodically broadcasts invalidation reports and a remote computer can check its cache validity after disconnection and reconnection.). Therefore, before the effective filing date of the instant application it would have been obvious to one of the ordinary skilled in the art to incorporate the teachings of “Cheng” into those of “Liu232 and Huq” to provide a communications system and method include an efficient cache invalidation technique which allows a computer to relocate and to disconnect without informing the server. The server partitions the entire database into a number of groups. The server also dynamically identifies recently updated objects in a group and excludes them from the group when checking the validity of the group. If these objects have already been included in the most recent invalidation broadcast, the remote computer can invalidate them in its cache before checking the group validity with the server. With the recently updated objects excluded from a group, the server can conclude that the cold objects in the group can be retained in the cache, and validate the rest of the group. As to claim 15. The combine system of Liu232, Huq and Cheng disclose the invention substantially as applied above including, in response to expiration of the particular time interval, provide to a cloud security service information determined based at least in part on the entries in the inactive cache that were not successfully communicated to the cloud security service during the particular time interval (Cheng, col.3 lines 1-5, Thus, in GCORE cache invalidation is accomplished by an asymmetrical approach where a server periodically broadcasts invalidation reports and a remote computer can check its cache validity after disconnection and reconnection. This is also a well know practice as evident by Cheshire et al. US 20050044355 A1, paragraph [0009]). As to claim 16. The combine system of Liu232, Huq and Cheng disclose the invention substantially as applied above including, statistics about the entries not being sent to the cloud security service during the particular time interval (Cheng, col.5, lines 29-40, (16) FIG. 6 shows the flow chart of query processing by a remote computer 1. Upon receiving a new bcast.sub.-- report, the computer 1 first invalidates its cache contents based on this report 650. If this computer 1 has been disconnected and this is the first bcast-report it receives after wake up and latest.sub.-- bcast.sub.-- time<bcast.sub.-- report.time 651, it then sends its latest.sub.-- bcast.sub.-- time and its group IDs to the server 2 for validity checking 652. It then waits for the validity results from the server 2 and invalidates its cache 653. Then the computer 1 processes all the queries 654. If objects cannot be found in the local cache (not shown), it sends requests to the server 254.). As to claim 17. The combine system of Liu232, Huq and Cheng disclose the invention substantially as applied above including, wherein the information comprises aggregated statistical information for the entries in the inactive cache that were not successfully communicated to the cloud security service during the particular time interval (Cheng, col.5, lines 29-40, (16) FIG. 6 If this computer 1 has been disconnected and this is the first bcast-report it receives after wake up and latest.sub.-- bcast.sub.-- time<bcast.sub.-- report.time 651, it then sends its latest.sub.-- bcast.sub.-- time and its group IDs to the server 2 for validity checking 652. It then waits for the validity results from the server 2 and invalidates its cache 653. Then the computer 1 processes all the queries 654. If objects cannot be found in the local cache (not shown), it sends requests to the server 254.). Claim(s) 18-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu et al. (Pub. No.: US 2023/0130232 A1), hereinafter “Liu232” in view of Zhou et al. (Pub. No.: US 2024/0179117 A1), hereinafter “Zhou”. As to claim 18. Liu232, disclose the invention substantially as applied above. Liu232, however are silent to disclose explicitly, wherein the ADNS telemetry cache stores the ADNS telemetry data in a key-value mapping. Zhou discloses a similar concept in the same field of endeavor including, wherein the ADNS telemetry cache stores the ADNS telemetry data in a key-value mapping (Zhou, [0015], the DNS response information is stored in the DNS local cache as a key/value pair such that the key portion of the key/value pair is a primary key for the DNS response and the value portion of the key/value pair is the DNS response.). Therefore, before the effective filing date of the instant application it would have been obvious to one of the skilled in the art to incorporate the teachings of “Zhou” into those of “Liu232” to provide a method for using a host DNS local cache to enable DNS resolution during network connectivity issues. In examples, a DNS request from a virtual environment executing on a host device is received by a DNS forwarder implemented within the host device. The DNS forwarder determines that a DNS resolver external to the host device is unreachable to provide a DNS response for a domain name in the DNS request. In response to determining the DNS resolver is unreachable, the DNS forwarder identifies a DNS response corresponding to the domain name within a DNS local cache implemented within the host device. As to claim 19. The combine system of Liu232, and Zhou disclose the invention substantially as applied above including, wherein a key in the key-value mapping corresponds to a cache line, and a value in the key-value mapping stores information pertaining to a number of query hits during a particular time interval (Zhou, [0014], all the DNS related information is available, and can be extracted from DNS history or lookup table. DNS entries have a time stamp as well and applying related filter one can easily extract time related DNS queries.). Claim(s) 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu232, and Zhou as applied above and further in view of Eisenreich et al. (Pub. No.: US 2016/0171039 A1), hereinafter “Eisen”. As to claim 20. The combine system of Liu232, and Zhou disclose the invention substantially as applied above. Liu232 and Huq however are silent to disclose explicitly, wherein a key for an entry in the key-value mapping stores a concatenated string comprising rrname information, rrtype information, rrdata information, verdict information, and action information. Eisen however discloses a similar concept in the same field on endeavor including, wherein a key for an entry in the key-value mapping stores a concatenated string comprising rrname information, rrtype information, rrdata information, verdict information, and action information (Eisen, [0017], the hash generator 124 can generate a concatenated key value which is a concatenation of the primary key field values included in the SQL INSERT query. The hash generator 124 can apply a hash function to the concatenated key value to create a new hash value corresponding to the record to be inserted. Therefore, replacing the generic primary-key fields in the reference with specific DNS related fields is simply a design choice). Therefore, before the effective filing date of the instant application it would have been obvious to one of the skilled in the art to incorporate the teachings of “Eisen” into those of “Liu232, and Zhou” to provide a system for identifying a record to include in a table, the record associated with two or more primary key fields that are concatenated to create a concatenated key, wherein the table includes one or more hash columns for storing hash identifiers; applying a hash function to the concatenated key to create a new hash value; determining whether a record in the table has a hash value matching the new hash value; in response to determining that a hash value of a record matches the new hash value and the concatenated key of the identified record does not match the concatenated key of any existing record, adding a counter to the new hash value to generate a unique hash ID; and storing the record, including the unique hash ID, in the table. Claim(s) 21-24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Liu232, and Zhou and further in view of Jiang et al. (Pub. No.: US 2023/0362176 A1), hereinafter “Jiang”. As to claim 22. The combine system of Liu232, and Zhou disclose the invention substantially as applied above. Liu232 and Huq however are silent to disclose explicitly, wherein an entry in the key-value mapping corresponds to a non-existent domain (NXDomain) for a DNS query processed during a particular time interval, a key for the entry comprises information pertaining to the NXDomain, and a value for the entry comprises information pertaining to a number of query hits during the particular time interval. Jiang however discloses a similar concept in the same field of endeavor, wherein an entry in the key-value mapping corresponds to a non-existent domain (NXDomain) for a DNS query processed during a particular time interval, a key for the entry comprises information pertaining to the NXDomain, and a value for the entry comprises information pertaining to a number of query hits during the particular time interval (Jiang, [0025], Generally, an NXDOMAIN (e.g., an NXDOMAIN response received in response to a DNS query for a given domain name) is a condition or error that can be indicated for an Internet domain name that is unable to be resolved using the DNS servers (e.g., invalid domain name) or that the Internet domain name is not yet registered. In some cases, an NXDOMAIN can also be indicated due to a network or DNS server problem and [0053], a threshold number of attempted hits (e.g., queries for attempted connections, such as during a predefined period of time) by hosts (e.g., infected with the identified malware performing in the wild).). Therefore, before the effective filing date of the instant application it would have been obvious to one of the skilled in the art to incorporate the teachings of “Jiang” into those of “Liu232, and Zhou” to provide a system and method for locating DGA compromised IP addresses is provided. A domain name system (DNS) stream is received. The DNS stream is classified into DGA generated domains using a machine learning classifier to generate a classification output. User behavior profiling is performed to enhance the classification output. A verdict is generated based on the user behavior profiling of the classification output including identifying a compromised source IP address associated with a detected DGA malware attack. As to claim 21. The combine system of Liu232, Zhou and Jiang disclose the invention substantially as applied above including, wherein a value for an entry in the key-value mapping stores (i) an ADNS local cache hit count for the associated domain during a particular time interval, (Jiang, [0062], DNS data to identify a threshold number of NXDOMAIN responses received at firewall 300 within a predetermined period of time/interval.), (ii) a first timestamp indicating a time at which the ADNS local cache was first queried for the domain during the particular time interval (Jiang, [0062], DNS data to identify a threshold number of NXDOMAIN responses received at firewall 300 within a predetermined period of time/interval. All DNS queries recorded with time stamp.), and (iii) a second timestamp indicating a time at which the ADNS local cache was last queried for the domain during the particular time interval(Jiang, [0062], DNS data to identify a threshold number of NXDOMAIN responses received at firewall 300 within a predetermined period of time/interval. All DNS queries recorded with time stamp.). As to claim 23. The combine system of Liu232, Zhou and Jiang disclose the invention substantially as applied above including wherein the key for the entry associated with the NXDomain comprises a concatenated string comprising domain information, server IP information, and address information (Jiang, [0025], DNS server can translate the domain name into an IP address, such as 172.16.254.1 (for IPv4) and 2001:db8:0:1234:0:567:8:1 (for IPv6) and indicated for an Internet domain name that is unable to be resolved using the DNS servers (e.g., invalid domain name) or that the Internet domain name is not yet registered. In some cases, an NXDOMAIN can also be indicated due to a network or DNS server problem.). As to claim 24. Is rejected for same rationale as applied to claim 21 above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Please see the attached PTO-892. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAUQIR HUSSAIN whose telephone number is (571)270-1247. The examiner can normally be reached M-F 7:00 - 8:00 with IFP. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached at 571 272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Tauqir Hussain/Primary Examiner, Art Unit 2446
Read full office action

Prosecution Timeline

Sep 24, 2024
Application Filed
Mar 12, 2026
Non-Final Rejection mailed — §102, §103
Jun 12, 2026
Response Filed
Jul 24, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743547
Method, Device, Equipment and Medium for False-Report Elimination
2y 5m to grant Granted Sep 22, 2026
Patent 12744832
SYSTEMS AND METHODS FOR ENSURING CONTINUED ACCESS TO MEDIA OF A PLAYLIST DESPITE GEOGRAPHIC CONTENT RESTRICTIONS
1y 9m to grant Granted Sep 22, 2026
Patent 12739165
COMMUNICATION SYSTEM
1y 11m to grant Granted Sep 15, 2026
Patent 12726423
INFERRING QOE DEGRADATION FROM IMPLICIT SIGNALS IN USER BEHAVIOR
3y 5m to grant Granted Sep 01, 2026
Patent 12724869
DATA LINK LAYER AUTHENTICITY AND SECURITY FOR AUTOMOTIVE COMMUNICATION SYSTEM
2y 8m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+25.8%)
3y 0m (~12m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 829 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month