Prosecution Insights
Last updated: October 02, 2026
Application No. 18/908,111

CLOUD-BASED CYBER SECURITY AND METHODS OF OPERATION

Final Rejection §102§112
Filed
Oct 07, 2024
Priority
Oct 05, 2023 — provisional 63/542,708
Examiner
ZEE, EDWARD
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
2 (Final)
91%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 91% — above average
91%
Career Allowance Rate
820 granted / 905 resolved
+32.6% vs TC avg
Moderate +10% lift
Without
With
+10.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
18 currently pending
Career history
925
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
26.6%
-13.4% vs TC avg
§102
25.6%
-14.4% vs TC avg
§112
23.6%
-16.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 905 resolved cases

Office Action

§102 §112
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is in response to the correspondence filed on 07/20/26. Claims 1-20 are still pending and have been considered below. Claim Objections The amendments and/or arguments have been considered and are persuasive; thus, the previous claim objection(s) have been withdrawn. Claim Rejections - 35 USC § 112 The amendments and/or arguments have been considered and are persuasive; thus, the previous claim rejection(s) have been withdrawn. Claim Rejections - 35 USC § 102 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claim(s) 1, 2, 4, 5, 11, 14, 15 and 20 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Mradul et al. (2024/0394377). Claim 1: Mradul et al. discloses a cloud security system configured to protect a cloud environment associated with a network, comprising: a cloud asset enumeration component configured to (i) identify a plurality of cloud assets associated with a cloud architecture and (ii) collect information associated with each of the plurality of cloud assets(scans cloud infrastructure to identify sensitive assets by examining metadata and content of the assets) [page 2, paragraph 0021 | page 4, paragraph 0035]; and an asset management component configured to conduct analytics on information associated with the plurality of cloud assets in order to detect misconfiguration of one or more cloud assets of the plurality of cloud assets forming the cloud architecture(assessing and/or reassessing risk score in response to configuration changes to determine asset configuration risk of misconfiguration) [page 4, paragraph 0044 | page 6, paragraph 0057 | page 8, claim 3], wherein the plurality of cloud assets comprises ephemeral, cloud-based components or services(organization’s assets hosted in cloud infrastructure) [page 2, paragraphs 0018-0019]. Claim 2: Mradul et al. discloses the cloud security system of claim 1, wherein the cloud asset enumeration component is further configured to conduct access mapping operations by at least determining which cloud asset of the plurality of cloud assets have access to one or more other cloud assets of the plurality of cloud assets(hierarchical relationships of assets) [page 6, paragraphs 0059-0060]. Claim 4: Mradul et al. discloses the cloud security system of claim 1, wherein the cloud asset enumeration component is further configured to (i) create a group of cloud assets from the plurality of cloud assets and (ii) generate an interactive, customer-specific cloud architecture that represents relatedness and interconnectivity of the group of cloud assets(provide structure for visualization of hierarchical structure) [page 6, paragraphs 0059-0060 | page 7, paragraph 0069]. Claim 5: Mradul et al. discloses the cloud security system of claim 4 communicatively coupled to a cyber security appliance to generate a first Artificial Intelligence (AI) model based on normal or expected behaviors of the group of cloud assets(calculate baseline at-rest risk scores and filtering incidents based on them) [pages 2-3, paragraphs 0023-0024]. Claim 11: Mradul et al. discloses a computerized method comprising: identifying a plurality of cloud assets within a cloud environment of a customer [page 2, paragraph 0021 | page 4, paragraph 0035]; collecting information associated with each of the plurality of cloud assets including metadata associated with a first ephemeral cloud asset of the plurality of cloud assets and metadata associated with a second ephemeral cloud asset of the plurality of cloud assets [page 2, paragraph 0021 | page 4, paragraph 0035]; conducting analytics on the metadata associated with the first ephemeral cloud asset and the metadata associated with the second ephemeral cloud asset in order to detect misconfiguration of the first ephemeral cloud asset or the second ephemeral cloud asset [page 4, paragraph 0044 | page 6, paragraph 0057 | page 8, claim 3]; determining an estimated risk value associated with at least first ephemeral cloud asset and the second ephemeral cloud asset, wherein the estimated risk value associated with the first ephemeral cloud represents a potential risk of the first ephemeral cloud asset being misconfigured and subject to a cyber threat(security posture manager will have obtained configuration risk assessments for sensitive assets and then surfaces the filtered incidents) [page 4, paragraphs 0039 & 0041 & 0044]; generating a visualization of the cloud environment including the first ephemeral cloud asset, the second ephemeral cloud asset, and any relationship links between the first ephemeral cloud asset and the second ephemeral cloud asset along with different visualization of the first ephemeral cloud asset and the second ephemeral cloud asset based on the estimated risk values of the first ephemeral cloud asset and the second ephemeral cloud asset(provide structure for visualization of hierarchical structure and updating visualization of incidents based on calculated risk assessment values) [page 4, paragraph 0041 | page 6, paragraphs 0059-0060 | page 7, paragraph 0069]. Claim 14: Mradul et al. discloses the computerized method of claim 11, wherein the collecting of the information associated with each of the plurality of cloud assets further comprises (i) creating a group of ephemeral cloud assets including the first ephemeral cloud asset and the second ephemeral cloud asset from the plurality of cloud assets and (ii) generating an interactive, customer-specific cloud architecture visualization that represents relatedness and interconnectivity of the group of ephemeral cloud assets [page 6, paragraphs 0059-0060 | page 7, paragraph 0069]. Claim 15: Mradul et al. discloses the computerized method of claim 14 further comprising: providing information to a cyber security appliance to generate a first Artificial Intelligence (AI) model based on normal or expected behaviors of the group of ephemeral cloud assets [pages 2-3, paragraphs 0023-0024]. Claim 20: Mradul et al. discloses a non-transitory storage medium including software that, upon execution by a processor, is configured to protect a cloud environment associated with a network by detection of misconfigurations of a cloud asset or potential cyber threat against the cloud asset, the software comprises: a cloud asset enumeration component configured to (i) identify a plurality of cloud assets associated with a cloud architecture and (ii) collect information associated with each of the plurality of cloud assets [page 2, paragraph 0021 | page 4, paragraph 0035]; and an asset management component configured to conduct analytics on information associated with the plurality of cloud assets in order to detect misconfiguration of one or more cloud assets of the plurality of cloud assets forming the cloud architecture [page 4, paragraph 0044 | page 6, paragraph 0057 | page 8, claim 3], wherein the plurality of cloud assets comprises ephemeral, cloud-based components or services [page 2, paragraphs 0018-0019]. Allowable Subject Matter Claims 3, 6-10, 12, 13 and 16-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Response to Arguments Applicant's arguments filed 07/20/26 have been fully considered but they are not persuasive. Applicant argues that the prior art does not disclose “ephemeral cloud assets”, as claimed; in particular, Applicant appears to contend that the “assets” of Mradul et al. only amount to data that is either program code and/or data that is not program code, whereas the claimed “ephemeral cloud assets” are transient, short-lived infrastructure components that may include but not limited to a variety of elements described in Applicant’s specification. Initially, Examiner notes that the portion(s) of the Specification referenced by Applicant describe examples of what an ephemeral cloud asset can include, but does not appear to provide an explicit definition of what an ephemeral cloud asset must be interpreted as; thus, Examiner respectfully submits that the implementations described in the Specification are not necessarily required, nor are they the only possible interpretations, based on the current claim language. Examiner also notes that the term “ephemeral” does not necessarily provide a definite threshold or degree as to what is or is not considered “short-lived” since it is generally relative in nature; thus, Examiner respectfully submits that the claim language, as currently recited, does not necessarily require an interpretation where the asset is automatically activated and/or discarded based on varying workloads. In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., the claimed ephemeral cloud assets are transient, short-lived infrastructure components, which are spun up and spun down, etc.) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Examiner further notes that since the assets of Mradul et al. are understood as either data that is program code or data that is not program code, they would appear to be similar in nature to at least some of the provided examples from Applicant’s specification, such as the policies, roles, certificates, virtual machines, or the likes; in particular, these elements are all reasonably understood by one of ordinary skill in the art as some form of data that is either program code or not program code. Therefore, Examiner respectfully disagrees and submits that the prior art does in fact disclose the allegedly deficient features as the assets of Mradul et al. appear to be functionally equivalent to at least some of examples described in Applicant’s own disclosure. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDWARD ZEE whose telephone number is (571)270-1686. The examiner can normally be reached Monday-Friday 9AM-5PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EDWARD ZEE/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Oct 07, 2024
Application Filed
Jun 03, 2026
Non-Final Rejection mailed — §102, §112
Jul 20, 2026
Response Filed
Sep 15, 2026
Final Rejection mailed — §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743504
FILTERING FOR HARMFUL GENERATIVE ARTIFICIAL INTELLIGENCE RESULTS
2y 10m to grant Granted Sep 22, 2026
Patent 12737446
RELATIONSHIP AND ATTRIBUTE MANAGEMENT USING DECENTRALIZED IDENTIFIERS
3y 1m to grant Granted Sep 15, 2026
Patent 12707260
NETWORK REPOSITORY FUNCTION SERVICES ACCESS AUTHORIZATION
2y 7m to grant Granted Aug 11, 2026
Patent 12682073
SYSTEM AND METHOD FOR IDENTIFICATION OF SECURITY VULNERABILITIES USING ARTIFICIAL INTELLIGENCE-BASED ANALYSIS OF COMPUTING ENVIRONMENT LOGS
2y 5m to grant Granted Jul 14, 2026
Patent 12683987
DYNAMIC NETWORK SECURITY FOR INDUSTRIAL SYSTEMS
2y 4m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
91%
Grant Probability
99%
With Interview (+10.4%)
2y 4m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 905 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month