Prosecution Insights
Last updated: October 02, 2026
Application No. 18/950,963

ANOMALY DETECTION SYSTEM AND METHODS

Final Rejection §103
Filed
Nov 18, 2024
Examiner
YE, ZI
Art Unit
2455
Tech Center
2400 — Computer Networks
Assignee
Twilio Inc.
OA Round
2 (Final)
85%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
413 granted / 485 resolved
+27.2% vs TC avg
Strong +18% interview lift
Without
With
+17.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 3m
Avg Prosecution
23 currently pending
Career history
503
Total Applications
across all art units

Statute-Specific Performance

§101
10.4%
-29.6% vs TC avg
§103
55.2%
+15.2% vs TC avg
§102
10.0%
-30.0% vs TC avg
§112
10.7%
-29.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 485 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 6, 8, 13, 15, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1). Regarding claim 1, Schreiber teaches a method, comprising: receiving, via one of one or more computing devices, operation data associated with one or more containers providing a service, the operation data comprising current health metrics of the one or more containers; (Fig. 1. Col 2 lines 24-32: A provider network 100 may include a plurality of services 110. These may include services that enable customers of the provider network to create their own applications and services, such as storage services, hardware virtualization services, container services, etc. If an incident occurs that affects one or more of these provider network services, then the applications and services of a large number of customers are potentially affected. Col 4 lines 61-64: incident orchestrator can receive data from one or more monitoring services which includes various performance metrics which characterize the performance of one or more services of provider network.) applying, via one of the one or more computing devices, a machine learning algorithm to operation data associated with the one or more containers; and (Col 12 lines 14-18: providing the performance metric data and the state data to an incident machine learning model, the incident machine learning model trained to predict a cause of incidents affecting the provider network. At numeral 1, incident orchestrator can receive data from one or more monitoring services which includes various performance metrics which characterize the performance of one or more services of provider network. At the beginning of an incident, the metrics of one or more services may begin to degrade.) determining, via one of the one or more computing devices, an occurrence of a new incident. (Col 5 lines 50-54: incident models may include machine learning models which have been trained to identify likely causes of an incident based on current and past performance data from the provider network. Col 5 lines 15-19: Based on these metrics (e.g., a specific metric value, a metric value relative to a minimum threshold or maximum threshold, depending on the metric, etc.), at numeral 2, the incident orchestrator may determine that an incident is occurring.) Schreiber does not explicitly disclose the machine learning algorithm to generate a plurality of scores, the plurality of scores comprising a first score indicating whether an anomaly is present in the operation data associated with the one or more containers; and in response to the first score exceeding a first threshold, determining, via one of the one or more computing devices, that the anomaly is present in the operation data associated with the one or more containers. However, Tholar teaches the machine learning algorithm to generate a plurality of scores, the plurality of scores comprising a first score indicating whether an anomaly is present in the operation data associated with the one or more containers; and ([0004]: using a first machine learning model or algorithm (which may be, e.g., an unsupervised machine learning model), a plurality of signals in decision trees, and calculate anomaly scores based on the decision trees or organization of signals in decision trees.) in response to the first score exceeding a first threshold, determining, via one of the one or more computing devices, that the anomaly is present in the operation data associated with the one or more containers. ([0076]: threshold values and corresponding conditions or criteria may be used for determining anomality. As another example, a second machine learning model and/or protocol or operation may be applied to anomaly scores—such that anomality is predicted based on the score. [0082]: events or context signals may be binarily classified as “suspicious” (e.g., “anomalous”), or as “normal” e.g., based on comparing context scores and/or weighted scores to a predetermined threshold (for example, some embodiments may classify events or signals for which scores above T=0.7 were calculated as “anomalous”, and events or signals for which scores below T were calculated as “normal”).) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber to include above limitations. One would have been motivated to do so because detecting anomalies is of paramount importance in various domains, such as cybersecurity, as they may indicate potential issues, errors, fraudulent activities, or emerging trends that require immediate attention and/or indicate the need for appropriate risk management and planning. As datasets grow in size and complexity, the automatic identification and handling of anomalies within this data have emerged as critical challenges. There is thus a need for intelligent, anomaly detection systems and methods which may make use of complex computational techniques for considering complex patterns in high dimensional, large volumes of data. As taught by Tholar, [0002]. Schreiber and Tholar do not explicitly disclose to generate a second score indicating a likelihood of a new incident impacting the service; and in response to determining that the anomaly is present and the at least one second score exceeding a predefined second threshold, determining, via one of the one or more computing devices, an occurrence of the new incident impacting the service. However, Mann teaches to generate a second score indicating a likelihood of a new incident impacting the service; and in response to determining that the anomaly is present and the at least one second score exceeding a predefined second threshold, determining, via one of the one or more computing devices, an occurrence of the new incident impacting the service. ([0004]: using a predictive causal machine learning model, a predictive causal probability score data object based at least in part on a service incident time associated with the service incident data object, wherein (i) the predictive causal probability score data object describes one or more predictive causal probability scores, (ii) each predictive causal probability score is associated with a particular service change associated with the impacted service identifier or a particular upstream service change associated with each of the one or more upstream service identifiers, and (iii) the predictive causal probability score is indicative of a probability the corresponding service change or upstream service change is a cause contributor of the service incident described by the service incident data object.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber and Tholar to include above limitations. One would have been motivated to do so because existing techniques for determining service incident predictive causal identification have deficiencies and problems. It is desirable for an improved method for determining a predictive causal probability score data object associated with a service incident occurring within a federated service network. As taught by Mann, [0001]-[0002]. Regarding claim 6, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber teaches wherein the current health metrics comprises an increase in at least one of CPU usage or memory usage. (Col 4 line 65 – Col 5 line 19: the performance metrics (also referred to as performance data) may include CPU, memory usage, latency, response time, etc. the metrics of one or more services may begin to degrade. Based on these metrics (e.g., a specific metric value, a metric value relative to a minimum threshold (e.g., increase) or maximum threshold, depending on the metric, etc.), at numeral 2, the incident orchestrator may determine that an incident is occurring.) Same rationales apply to claim 8 (system) and claim 15 (CRM) because they are substantially similar to claim 1 (method). Same rationales apply to claim 13 (system) and claim 20 (CRM) because they are substantially similar to claim 6 (method). Claim(s) 2, 9 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1), and further in view of Mehta (US 20200184355 A1). Regarding claim 2, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber, Tholar and Mann do not explicitly disclose receiving, via one of the one or more computing devices, a request for the plurality of scores; and in response to receiving the request, generating, via one of the one or more computing devices, a dashboard comprising the plurality of scores. However, Mehta teaches receiving, via one of the one or more computing devices, a request for the at least one score; and in response to receiving the request, generating, via one of the one or more computing devices, a dashboard comprising the at least one score. ([0069]: The incident prediction engine then outputs the log data and incident prediction scores to a real-time incident monitoring dashboard, which may be displayed on a user terminal. In this manner, an application owner or system administrator can monitor the log data and incident prediction scores in real time or near real time.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber, Tholar and Mann to include above limitations. One would have been motivated to do so because there is a need for an improved system and method of log monitoring which can minimize delay associated with finding and diagnosing computer system outages and other incidents. The incident prediction engine then outputs the log data and incident prediction scores to a real-time incident monitoring dashboard, which may be displayed on a user terminal. In this manner, an application owner or system administrator can monitor the log data and incident prediction scores in real time or near real time. As taught by Mehta, [0005] and [0069]. Same rationales apply to claim 9 (system) and claim 16 (CRM) because they are substantially similar to claim 2 (method). Claim(s) 3, 10 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1), and further in view of Rai (US 20180357556 A1). Regarding claim 3, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber, Tholar and Mann do not explicitly disclose retraining, via one of the one or more computing devices, the machine learning algorithm based on the new incident. However, Rai teaches retraining, via one of the one or more computing devices, the machine learning algorithm based on the new incident. ([0043]: When machine learning models are used for anomaly detection, user feedback (e.g., to identify an anomaly or not) can be added as an additional feature in the full context view and used to retrain the machine learning model, thus allowing user feedback to influence future prediction.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber, Tholar and Mann to include above limitations. One would have been motivated to do so because When machine learning models are used for anomaly detection, user feedback (e.g., to identify an anomaly or not) can be added as an additional feature in the full context view and used to retrain the machine learning model, thus allowing user feedback to influence future prediction. As taught by Rai, [0043]. Same rationales apply to claim 10 (system) and claim 17 (CRM) because they are substantially similar to claim 3 (method). Claim(s) 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1), and further in view of Lee (US 20160226894 A1). Regarding claim 4, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber, Tholar and Mann do not explicitly disclose wherein the at least second score is determinative of a likelihood of the occurrence of the new incident and an incident type. However, Lee teaches wherein the at least second score is determinative of a likelihood of the occurrence of the new incident and an incident type. ([0022]: If the acquired data is checked as abnormal attack data by the abnormality detection module, the attack type classification module may calculate a similarity with the prestored abnormal attack model to determine whether the acquired data belongs to a new type of attack. [0072]: the attack type classification module calculates a similarity between the input feature vector and the abnormal attack models of the intrusion detection learning model that is previously learned by the system.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber, Tholar and Mann to include above limitations. One would have been motivated to do so because there is an increasing demand for an intelligence intrusion detection system and a method thereof, capable of performing adaptive intrusion detection proactively coping with a new type of attack and capable of training a classifier model using a small volume of training data. As taught by Lee, [0014]. Same rationales apply to claim 11 (system) and claim 18 (CRM) because they are substantially similar to claim 4 (method). Claim(s) 5, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1), and further in view of Nikolov (US 20070156834 A1). Regarding claim 5, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber, Tholar and Mann do not explicitly disclose wherein the service comprises at least one of a messaging service, a voice service, an identity verification service, or a customer support service. However, Nikolov teaches wherein the service comprises at least one of a messaging service, a voice service, an identity verification service, or a customer support service. ([0011]: FIG. 1 (prior art) shows a physical machine having container instances that each provide a messaging service.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber, Tholar and Mann to include above limitations. One would have been motivated to do so because it is well-known in the art that container instances are used to provide messaging service. As taught by Nikolov, [0003]-[0011]. Same rationales apply to claim 12 (system) and claim 19 (CRM) because they are substantially similar to claim 5 (method). Claim(s) 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Schreiber (US 11595243 B1) in view of Tholar (US 20250106231 A1), and in view of Mann (US 20230198865 A1), and further in view of Chang (US 9009825 B1). Regarding claim 7, Schreiber, Tholar and Mann teach the method of claim 1. Schreiber, Tholar and Mann do not explicitly disclose determining, via one of the one or more computing devices, a baseline for the current health metrics of the one or more containers, the baseline comprising a standard deviation, wherein determining that the anomaly is present comprises determining that a change in the current health metrics of the one or more containers exceeds the standard deviation of the baseline. However, Chang teaches determining, via one of the one or more computing devices, a baseline for the current health metrics of the one or more containers, the baseline comprising a standard deviation, wherein determining that the anomaly is present comprises determining that a change in the current health metrics of the one or more containers exceeds the standard deviation of the baseline. (Col 1 lines 25-33: The anomaly detector extracts values for a category of measure from the monitoring data and processes the values to generate a processed value. The anomaly detector predicts an expectation value (e.g., baseline) of the category of measure based at least on time decayed residual processed values. Col 7 lines 11-13: the expectation value is a baseline that is generated based on the decayed residual processed values and the processed value. Col 6 lines 1-5: The anomaly discoverer calculates the standard deviation of the current processed value from the current and previous baselines to determine if the current processed value is an anomaly.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Schreiber, Tholar and Mann to include above limitations. One would have been motivated to do so because Events in a computer network may be stored and analyzed to detect security events, such as leakage of sensitive data and unauthorized access to the computer network. Unfortunately, analyzing logged events takes time and is relatively complex because of the large volume of data associated with the events. It is desirable for an improved methods and apparatus for detecting anomaly events at near real time in computer networks. As taught by Chang, Background and Summary. Same rationales apply to claim 14 (system) because it is substantially similar to claim 7 (method). Response to Arguments Applicant’s arguments, see pages 8-11, filed 07/22/2026, with respect to the rejection(s) of claims 1-20 under 35 U.S.C. § 103 have been fully considered but are moot in view of new ground(s) of rejection. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZI YE whose telephone number is (571)270-1039. The examiner can normally be reached Monday - Friday, 8:00am - 4:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Emmanuel Moise can be reached at 5712723865. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ZI YE/Primary Examiner, Art Unit 2455
Read full office action

Prosecution Timeline

Nov 18, 2024
Application Filed
Apr 22, 2026
Non-Final Rejection mailed — §103
Jul 07, 2026
Interview Requested
Jul 20, 2026
Applicant Interview (Telephonic)
Jul 20, 2026
Examiner Interview Summary
Jul 22, 2026
Response Filed
Aug 11, 2026
Final Rejection mailed — §103
Sep 30, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739199
EFFICIENT RESOURCE MANAGEMENT FOR ROLE-BASED TRAFFIC SEGMENTATION IN AN OVERLAY NETWORK
2y 0m to grant Granted Sep 15, 2026
Patent 12732564
CROSS-MOBILE NETWORK OPERATOR SERVER
2y 4m to grant Granted Sep 08, 2026
Patent 12732421
SYSTEM AND APPLICATION FOR DYNAMIC CUSTOMER EXPERIENCE
2y 1m to grant Granted Sep 08, 2026
Patent 12683811
ENCRYPTED PHYSICALLY UNCLONABLE FUNCTION CIRCUIT HELPER DATA
4y 3m to grant Granted Jul 14, 2026
Patent 12671627
COMPUTING POWER NETWORK NODE EVALUATION AND OPERATION METHOD AND APPARATUS
1y 10m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+17.8%)
2y 3m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 485 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month