Prosecution Insights
Last updated: August 18, 2026
Application No. 18/952,190

MONITORING AND CLASSIFICATION OF ACTIVITY REQUESTED DURING PRIVILEGED SESSIONS

Final Rejection §103
Filed
Nov 19, 2024
Priority
Nov 29, 2022 — CIP of 11/818,119 +1 more
Examiner
CHAI, LONGBIT
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
CyberArk Software Ltd.
OA Round
2 (Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
661 granted / 752 resolved
+29.9% vs TC avg
Strong +31% interview lift
Without
With
+31.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
14 currently pending
Career history
768
Total Applications
across all art units

Statute-Specific Performance

§101
16.1%
-23.9% vs TC avg
§103
41.6%
+1.6% vs TC avg
§102
34.9%
-5.1% vs TC avg
§112
6.5%
-33.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 752 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Currently pending claims are 1 – 8 & 11 – 21. Response to Arguments Applicant's arguments with respect to the subject matter of the instant claims have been fully considered but are not persuasive. As per claim 1, Applicant asserts prior-art(s) fails to teach the newly added claim elements such as (a) analyzing the at least one action includes inputting an indication of the at least one action into a trained model configured to generate an indication of whether the at least one action is a human-initiated action as an output, and (b) the trained model being selected from a plurality of trained models based on the characteristic of the native client (Remarks: page 8). Examiner respectfully disagrees with the following rationale. Regarding the argument of (a) – (a-1) Examiner notes according to MPEP 2111 of the broadest and reasonable claim interpretations, applicant’s argument has no merit since the alleged limitation such as “exactly and specifically what is an indication of the at least one action to be inputted into a trained model” has not been specifically recited into the claim. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). (a-2) In light of that, Examiner notes Xu teaches inputting behavior data of a log-in request (e.g.) as an indication of the at least one action into a deep learning trained model to generate whether the at least one action is a human-initiated action or automated process (Xu: Col. 3 Line 1 – 13) to match the recited claim language. Regarding the argument of (b) – (b-1) Examiner notes according to MPEP 2111 of the broadest and reasonable claim interpretations, applicant’s argument has no merit since the alleged limitation such as “exactly what are a plurality of trained models the recited trained model to be selected from” has not been specifically recited into the claim. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). (b-2) In light of that, Examiner notes Xu teaches applying a plurality of different behavior data of requests to deep learning techniques to generate a plurality of respective trained models (Xu: Col. 3 Line 1 – 3) to identify whether the action of the request is a human-initiated action. As such, each of a trained model is indeed associated with (selected from) a plurality of respective trained models based on the particular behavior data indicative of a particular characteristic of a native client (Xu: Col. 3 Line 1 – 12) to match the recited claim language. Thereby, Applicant's arguments are respectfully traversed. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the exclaimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1 – 5, 7, 8, 12 – 13 & 16 – 21 are rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Xu et al. (U.S. Patent 11,483,324). As per claim 1 & 13, Sade teaches a non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for classifying network session activities, the operations comprising: identifying a session between a network identity and a network resource, the session being established using a native client associated with the network identity, wherein the native client is associated with a native communication protocol; (Sade: Figure 2B / E-2000 & Col. 2 Line 9 – 12, Col. 7 Line 24 – 27, Col. 3 Line 60 – 67, Col. 5 Line 20 – 23, Col. 4 Line 45 – 57 and Col. 11 Line 21 – 25: (a) a user / client (networking identity) sends a request to access a network resource of target service (Sade: Figure 2B / E-2000 & Col. 2 Line 9 – 12 and Col. 7 Line 24 – 27); (b) a proxy entity of CMS (Credential Management System) authenticates the user / client (network identity) based on an authentication credential sent in the request (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23), wherein (b-1) the CMS proxy entity can be an endpoint device located on which the user / client resides, which constitutes as one type of a native client (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23) – besides, the user / client resides at the endpoint device, which also constitutes another type of native client respective to a server viewpoint, (b-2) the authentication credential can be sent in the request via (e.g.) a Kerberos protocol (i.e. a native communication protocol) (Sade: Col. 3 Line 60 – 67 and Col. 5 Line 20 – 23) and (b-3) the CMS proxy entity (i.e. native client) communicates with an authentication service and operates transparently with the target service (i.e. network resource) (Sade: Figure 2B / E-2000). monitoring at least one message conveyed during the session to identify at least one first data element associated with the session, the at least one message being associated with the native communication protocol (Sade: see above & Col. 3 Line 60 – 67, Col. 4 Line 45 – 57 and Col. 11 Line 21 – 25: the CMS proxy entity authorizes the user / client using the user / client’s authentication credential to access the network resource of target service, wherein the client’s authentication credential associated with the access request constitutes a first data element). However, Sade does not disclose expressly analyzing the at least one first data element to identify a characteristic of the native client. Xu (& Sade) teaches analyzing the at least one first data element to identify a characteristic of the native client (Sade: see above) || (Xu: FIG. 1 & Col. 6 Line 48 – 53 and Col. 3 Line 1 – 12 / Line 27 – 31: (a) a user (networking identity) sends a Login request to access a network resource of target service and transmit the request over the network (Xu: FIG. 1 & Col. 6 Line 48 – 53); and (b) providing a network security system for anomaly detection by utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that characterizes a client device of a plurality of client devices (i.e. as a particular type of client device) (Xu: Col. 3 Line 1 – 12 / Line 27 – 31). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of analyzing the at least one first data element to identify a characteristic of the native client because Xu teaches to alternatively, effectively and securely provide a network security system to detect a malicious activity by utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein the training data can be classified as behavior data generated by a human-user as well as behavior data generated by automated-user (i.e. automated request) in association with a plurality of different requests for generating a likelihood score to determine whether the action of the access request is a human-initiated action or automated-process (Xu: see above & Col. 3 Line 1 – 12, Col. 20 Line 11 – 18 & Col. 8 Line 51 – 58) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities (see above). monitoring the at least one message conveyed during the session to identify at least one second data element associated with the session, the at least one second data element being associated with at least one action requested by the network identity (Xu: see above & Col. 3 Line 1 – 12 / Line 27 – 31: providing a network security system for anomaly detection by utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that indicates whether the activities were determined to be legitimate (i.e. human-initiated) or automated process – i.e. feedback the previous analysis result into the model for analysis such that one action includes inputting an indication, generated from a configured trained model as an analyzed result of a request action including whether the action is legitimate or automated (i.e. a human-initiated action or not) – this is also consistent with the disclosure of the instant specification (SPEC-PG.PUB: Para [0015]); and analyzing the at least one action and the characteristic of the native client to determine, for each action of the at least one action, whether the action is a human-initiated action (Sade: see above) || (Xu: see above & Col. 3 Line 1 – 12, Col. 20 Line 11 – 18 & Col. 8 Line 51 – 58: providing a machine learning / training model, wherein the training data can be classified as behavior data generated by a human-user as well as behavior data generated by automated-user (i.e. automated request) in association with a plurality of different requests for generating a likelihood score to determine whether the action of the access request is a human-initiated action or automated-process), wherein analyzing the at least one action includes inputting an indication of the at least one action into a trained model configured to generate an indication of whether the at least one action is a human-initiated action as an output (Xu: see above & Col. 3 Line 1 – 13): (a-1) Examiner notes according to MPEP 2111 of the broadest and reasonable claim interpretations, applicant’s argument has no merit since the alleged limitation such as “exactly and specifically what is an indication of the at least one action to be inputted into a trained model” has not been specifically recited into the claim. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). (a-2) In light of that, Examiner notes Xu teaches inputting behavior data of a log-in request (e.g.) as an indication of the at least one action into a deep learning trained model to generate whether the at least one action is a human-initiated action or automated process (Xu: Col. 3 Line 1 – 13) to match the recited claim language. the trained model being selected from a plurality of trained models based on the characteristic of the native client (Xu: see above & Col. 3 Line 1 – 12): (b-1) Examiner notes according to MPEP 2111 of the broadest and reasonable claim interpretations, applicant’s argument has no merit since the alleged limitation such as “exactly what are a plurality of trained models the recited trained model to be selected from” has not been specifically recited into the claim. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). (b-2) In light of that, Examiner notes Xu teaches applying a plurality of different behavior data of requests to deep learning techniques to generate a plurality of respective trained models (Xu: Col. 3 Line 1 – 3) to identify whether the action of the request is a human-initiated action. As such, each of a trained model is indeed associated with (selected from) a plurality of respective trained models based on the particular behavior data indicative of a particular characteristic of a native client (Xu: Col. 3 Line 1 – 12) to match the recited claim language. As per claim 2, 5, 7 – 8, the instant claim is directed to a claimed content having functionality corresponding to the Claims 1, and are rejected by a similar rationale. As per claim 3, Sade as modified teaches wherein the characteristic of the native client includes at least one of: a type of the native client or a version of the native client (Xu: Col. 3 Line 1 – 12 / Line 27 – 31: providing a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that characterizes a client device of a plurality of client devices (i.e. as a particular type of client device) (Xu: Col. 3 Line 1 – 12 / Line 27 – 31)). As per claim 4 & 19, Sade as modified teaches wherein identifying the characteristic of the native client includes generating a score indicating a likelihood of the native client being associated with one or more native client identities (Sade: see above) || (Xu: Col. 3 Line 1 – 12, Col. 20 Line 11 – 18 & Col. 8 Line 51 – 58: utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein the training data can be classified as behavior data generated by a human-user as well as behavior data generated by automated-user (i.e. automated request) in association with a plurality of requests for generating a likelihood score to determine whether the action of the access request is a human-initiated action or automated-process. move up As per claim 12, Sade as modified teaches receiving feedback associated with the determination whether the at least one action is a human-initiated action and training the trained model based on the feedback (Xu: see above & Xu: Col. 3 Line 1 – 12 / Line 27 – 31: utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that indicates whether the activities were determined to be legitimate (i.e. human-initiated) or automated process – i.e. feedback the previous analysis result into the model for analysis such that one action includes inputting an indication, generated from a configured trained model as an analyzed result of a request action including whether the action is legitimate or automated (i.e. a human-initiated action or not) – this is also consistent with the disclosure of the instant specification (SPEC-PG.PUB: Para [0015]). As per claim 16, Sade as modified teaches wherein the at least one first data element includes an indication of a type of the at least one action and wherein the characteristic of the native client is determined based at least in part on the type of the at least one action (Xu: Col. 3 Line 1 – 12 / Line 27 – 31: providing a network security system for anomaly detection by utilizing a machine learning / training model (e.g. deep-learning techniques) including a behavior model, wherein one input parameters of a set of aggregated behavior data used for modeling analysis can include the data that characterizes a client device of a plurality of client devices (i.e. as a particular type of client device) and also include the data that indicates whether the activities were determined to be legitimate (i.e. human-initiated) or automated process (i.e. the at least one action)). As per claim 17, Sade as modified teaches wherein the at least one action includes a plurality of actions and wherein the at least one second data element includes an order in which the plurality of actions are requested (Sade: see above) || (Xu: see above & Col. 11 Line 1 – 8: for example, a series of mouse input event as the second data element associated with an order of the plurality of actions are requested) (Xu: Col. 11 Line 1 – 5)). As per claim 18, Sade as modified teaches wherein the at least one second data element includes a timing in which the at least one action is requested (Sade: see above) || (Xu: see above & Col. 11 Line 1 – 8: for example, a series of mouse input event as the second data element associated with an order of the plurality of actions are requested as well as a timing of a time-stamp along with its 2-dimensinal (x, y) coordinate) (Xu: Col. 11 Line 6 – 8)). As per claim 20, Sade as modified teaches comparing the likelihood to a threshold and generating, based on the comparison, an output identifying the action for analysis by a user (Sade: see above) || (Xu: see above & Col. 19 Line 21 – 29: a threshold associated with a likelihood score to differentiate the level between Moderate and Strong). As per claim 21, Sade as modified teaches performing one or more control actions associated with the action based on a determination that the action is a human-initiated action (Sade: see above) || (Xu: see above & Col. 20 Line 29 – 43: upon detection that indicates the action is a human-initiated action, the network security system instructs the server system to process the particular request). Claims 6 & 11 are rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Xu et al. (U.S. Patent 11,483,324), and in view of Alon et al. (U.S. Patent 2024/0406058). As per claim 6 & 11, Alon (& Sade as modified) teaches wherein the trained model is a large language model (Sade | Xu: see above) || (Alon: Para [0153] & Para [0030]: for streamlined anomaly detection, providing an AI service (e.g., an inference service) as a machine learning models executed by calling upon (e.g., as an API call) an inference service (e.g., an inference server) to execute machine learning model(s) and software implementing advanced processing as well as inferencing pipeline (Alon: Para [0153]) and the learning model can include a generative AI with large language model (Alon: Para [0030]). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification that the trained model is a large language model because Alon teaches to alternatively, effectively and securely, for streamlined anomaly detection, provide an AI service (e.g., an inference service) as a machine learning models executed by calling upon (e.g., as an API call) an inference service (e.g., an inference server) to execute machine learning model(s) and software implementing advanced processing as well as inferencing pipeline and the learning model can include a generative AI with large language model (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities (see above). Claim 14 is rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Xu et al. (U.S. Patent 11,483,324), and in view of Sirov et al. (U.S. Patent 2023/0164043). As per claim 14, Sirov (& Sade as modified) teaches wherein the characteristic of the native client is determined based at least in part on the number of open connections (Sade: see above & Col. 15 Line 38 – 39: a native client identifies a particular target service and determines corresponding required privileged credential for authentication) || (Sirov: Para [0034] & Para [0041]: using a trained machine learning model that can be inferenced on monitoring network traffic flows to classify and identify a predetermined target service (Sirov: Para [0034]) by extracting a data traffic session connection attribute such as the number and handling of open connections associated with the requested target service along with the client device (Sirov: Para [0041]). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of determining the characteristic of the native client based at least in part on the number of open connections because Sirov teaches to alternatively, effectively and securely utilize a trained machine learning model that can be inferenced on monitoring network traffic flows to classify and identify a predetermined target service by extracting a data traffic session connection attribute such as the number and handling of open connections associated with the requested target service along with the client device (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities and a native client identifies a particular target service so as to determine the corresponding required privileged credential for authentication (see above). Claim 15 is rejected under 35 U.S.C.103 as being unpatentable over Sade et al. (U.S. Patent 10,116,658), in view of Xu et al. (U.S. Patent 11,483,324), in view of Sirov et al. (U.S. Patent 2023/0164043), and in view of Brown et al. (U.S. Patent 11,734,713). per claim 15, Brown (& Sade as modified) teaches wherein the characteristic of the native client is determined based at least in part on the timing in which connections of the native client are opened (Sade: see above: authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities) || (Brown: Col. 16 Line 39 – 43 & Col. 17 Line 1 – 2: (a) a security entity can differentiate between fraudulent and authentic behavior by using messages and leveraging its own data having the metrics for training an authentic neural network (model) (Brown: Col. 16 Line 39 – 43) and (b) one of the metrics that inputs into the neural network model for analysis can be a timing threshold regarding how long does a client device hold open connection until termination (Brown: Col. 17 Line 1 – 2)). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of determining the characteristic of the native client based at least in part on the timing in which connections of the native client are opened because Brown teaches to alternatively, effectively and securely differentiate between fraudulent and authentic behavior by using messages and leveraging its own data having the metrics for training an authentic neural network (model) and (b) one of the metrics that inputs into the neural network model for analysis can be a timing threshold regarding how long does a client device hold open connection until termination (see above) within the Sade’s system of authorizing the user / client using the user / client’s authentication credential to access the network resource of target service and detecting anomaly / malicious activities (see above). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. --------------------------------------------------- /Longbit Chai/ Longbit Chai E.E. Ph.D. Primary Examiner, Art Unit 2431 No. #2585 – 2026 ---------------------------------------------------
Read full office action

Prosecution Timeline

Nov 19, 2024
Application Filed
Apr 03, 2026
Non-Final Rejection mailed — §103
Jul 06, 2026
Response Filed
Jul 21, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12707261
METHOD AND SYSTEM FOR AUTHENTICATION OF RF DEVICE
2y 4m to grant Granted Aug 11, 2026
Patent 12683807
BLOCKCHAIN FOR THE CONNECTED HOME
1y 8m to grant Granted Jul 14, 2026
Patent 12665932
MIDDLEBOX SECURITY IN A WIRELESS NETWORK
2y 3m to grant Granted Jun 23, 2026
Patent 12665905
INCREMENTAL MICRO-SEGMENTATION SYSTEM AND INCREMENTAL MICRO-SEGMENTATION METHOD
1y 11m to grant Granted Jun 23, 2026
Patent 12666257
SYSTEM AND METHOD OF DEVICE DEPLOYMENT
1y 8m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+31.2%)
2y 8m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 752 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month