Prosecution Insights
Last updated: October 04, 2026
Application No. 18/967,060

DOMAIN REPUTATION SYSTEM

Non-Final OA §103
Filed
Dec 03, 2024
Priority
Jul 28, 2020 — provisional 63/057,729 +1 more
Examiner
ABDULLAH, SAAD AHMAD
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Cequence Security Inc.
OA Round
2 (Non-Final)
74%
Grant Probability
Favorable
2-3
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
63 granted / 85 resolved
+16.1% vs TC avg
Strong +30% interview lift
Without
With
+30.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
27 currently pending
Career history
121
Total Applications
across all art units

Statute-Specific Performance

§101
4.6%
-35.4% vs TC avg
§103
77.1%
+37.1% vs TC avg
§102
6.3%
-33.7% vs TC avg
§112
7.6%
-32.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 85 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION The instant application having Application No. 18/967,060 is presented for examination by the examiner. Claims 21, 28 and 35 have been amended, claims 21-40 have been examined. Response to Arguments Applicant's arguments filed 07/15/2026, with respect to the rejection of claim 21, 28, 35 under 35 U.S.C. §103 have been fully considered and are persuasive. In light of this clarification, prosecution is reopened, and the application is being returned to non-final status. A new rejection under 35 U.S.C. §103 is present bellowed based on new considered prior art. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 21-22, 26, 28-29, 33, 35-36 and 40 are rejected under 35 U.S.C. 103 as being unpatentable over Silva (US 10,681,063 B1), in view of Prakash (US 2020/0092326 A1) and further in view of Rajahram (US 2019/0238544 A1). Regarding Claim 21 Silva discloses: A method comprising: determining the domain that the web asset is in communication with based on the intercepted communication (Silva: Col. 3, ll. 14-20; Col. 4, ll. 30-40; Col. 7, ll. 5-14: teaches a webpage embedding a reference to a script hosted on a third-party domain, and a browser loading the webpage containing the embedded script reference to the script hosted on the third-party domain, thereby determining the domain associated with the web asset); obtaining information that characterizes the domain (Silva: Col. 4, ll. 42-52: teaches a domain reputation database that includes reputation information for domains, wherein the reputation information may take into account several security-related data points including attack surface, sector, geolocation, incident history, and security hygiene, thereby obtaining information that characterizes the domain); and generating a reputation score for the domain based on the obtained information (Silva: Col. 4, ll. 42-52; Col. 5, ll. 33-57: teaches that domain reputation scores may be generated by the security application based on its own assessment of the domains' reputations, using the security-related information characterizing the domain, thereby generating a reputation score for the domain based on the obtained information). Silva teaches determining a domain associated with a web asset based on a webpage embedding a reference to a script hosted on that domain, obtaining information that characterizes that domain, and generating a reputation score for the domain based on that information. However, Silva is silent in explicitly teaching utilizing browser automation with a security scanner browser extension to intercept a communication of a web asset of a website. On the other hand, Prakash teaches utilizing a browser extension configured within a web browser that intercepts a request to access a URL and analyzes webpage content to determine whether the URL is malicious (Prakash: ¶0012). The browser extension receives a requested URL, extracts content from the associated webpage, and prevents access to malicious content, thereby intercepting communication of a web asset of a website. Prakash further teaches that the browser extension operates within a browser environment to automatically monitor and analyze requests, which reasonably corresponds to browser automation of web interactions (Prakash: ¶0018). It would have been obvious to a POSITA to modify Silva to incorporate Prakash's browser extension interception mechanism in order to enable real time monitoring and security analysis of web communications, since browser-based interception of web requests is a well-known and predictable technique for detecting malicious web activity. The combination merely applies a known technique (browser interception via an extension) to a known system (Silva's domain reputation and analysis system) to improve security monitoring, yielding predictable results. Silva in view of Prakash teaches intercepting a communication of a web asset and determining a domain associated with that web asset, but does not expressly teach wherein the communication is sent by the web asset to a domain external to the website. On the other hand, Rajahram teaches that a web browser executes web assets, including images, scripts, and frames, to form a web page, wherein the web assets are provided from third-party domain servers external to the website (Rajahram: ¶0024: "web browser 110 also executes assets such as images, scripts, frames, and the like, to form a web page (e.g., web assets 145(1)-(N) from third-party domain servers 140(1)-(N)...)"). Rajahram further teaches that an interception engine intercepts third-party domain calls generated by the web assets, the calls being sent from the browser to the third-party domain servers (Rajahram: ¶0029-¶0031), and that a reporting engine receives a violation notice indicating the one or more third-party domains used to render the web request, thereby identifying the domain external to the website from the intercepted communication (Rajahram: ¶0039). It would have been obvious to a POSITA at the time of the invention to further modify the combined system of Silva and Prakash to incorporate Rajahram's teaching of intercepting communications generated by embedded web assets directed to external third-party domains, because Rajahram is directed to the same field of browser-based security monitoring of network communications as Silva and Prakash. Applying Rajahram's known asset-to-external-domain interception technique within the domain reputation scoring framework of Silva and Prakash yields the predictable result of confirming the domain evaluated for reputation scoring is external to the website containing the web asset. The motivation to combine would be to ensure browser-level interception captures communications generated by embedded third-party assets specifically, rather than top-level navigation requests alone. Regarding Claim 22 Silva discloses: The method of claim 21 further comprising: comparing the obtained information to a database that indicates malicious domains; and wherein: generating the reputation score for the domain based on the obtained information comprises generating the reputation score for the domain based on the comparison (Silva Col 7, Lin 29 - Col 8, Lin 27: teaches identifying reputation scores for domains from a database and generating a risk score based on those scores, and determining whether the generated score exceeds a threshold to classify a script as malicious, thereby comparing obtained domain information to a database indicative of malicious domains and generating a reputation score based on the comparison.). Regarding Claim 26 Silva discloses: The method of claim 21 wherein: obtaining the information that characterizes the domain comprises determining a relationship pattern between the web asset and the domain; and generating the reputation score for the domain based on the obtained information comprises generating the reputation score based on the relationship pattern between the web asset and the domain (Silva Col 6, Lin 57 - Col 7, Lin 41: teaches detecting a webpage embedding a script hosted on a third party domain and compiling a list of domains associated with the script, thereby determining a relationship pattern between the web asset and domains, and generating a risk score based on reputation scores of those associated domains, thereby generating a reputation score based on the relationship pattern.). Regarding Claim 28 Claim 28 is directed to a system corresponding to the computer implemented method in claim 21. Claim 28 is similar in scope to claim 21 and is therefore rejected under similar rationale. Regarding Claim 29 Claim 29 is directed to a system corresponding to the computer implemented method in claim 22. Claim 29 is similar in scope to claim 22 and is therefore rejected under similar rationale. Regarding Claim 33 Claim 33 is directed to a system corresponding to the computer implemented method in claim 26. Claim 33 is similar in scope to claim 26 and is therefore rejected under similar rationale. Regarding Claim 35 Claim 35 is directed to computer readable media instructions corresponding to the computer implemented method in claim 21. Claim 35 is similar in scope to claim 21 and is therefore rejected under similar rationale. Regarding Claim 36 Claim 36 is directed to computer readable media instructions corresponding to the computer implemented method in claim 22. Claim 36 is similar in scope to claim 22 and is therefore rejected under similar rationale. Regarding Claim 40 Claim 40 is directed to computer readable media instructions corresponding to the computer implemented method in claim 26. Claim 40 is similar in scope to claim 26 and is therefore rejected under similar rationale. Claims 23-25, 30-32, 37-39 is/are rejected under 35 U.S.C. 103 as being unpatentable over Silva (US 10,681,063 B1), in view of Prakash (US 2020/0092326 A1), in view of Rajahram (US 2019/0238544 A1) as applied to claims 21, 28 and 35 and in further view of Schmidtler (US 20200349430 A1). Regarding Claim 23 Silva in view of Prakash and Rajahram teaches intercepting web asset communications to identify associated domains and generate domain reputation or risk scores based on information obtained from those domains. However, Silva in view of Prakash and Rajahram is silent in explicitly teaching that the obtained information that characterizes the domain comprises at least one of a name server used by the domain, an IP address hosting the domain, or a hosting provider reputation associated with the domain, and generating the reputation score based on at least one of these specific infrastructure level attributes. On the other hand, Schmidtler teaches obtaining detailed domain attribute data, including IP address information, registrar information (which encompasses DNS/name server data), and certificate/hosting information, collected from sources such as WHOIS and DNS, and using such information as features for generating a domain reputation score via a trained model (Schmidtler ¶¶0052, 0056, 0082). Schmidtler further teaches that these domain attributes are used as inputs to a domain reputation prediction model to evaluate and assign a reputation score to the domain (Schmidtler ¶¶0058, 0076). It would have been obvious to a person of ordinary skill in the art at the time of the invention to modify the system of Silva in view of Prakash and Rajahram to incorporate the domain attribute features taught by Schmidtler, including name server information, IP address hosting information, and hosting related attributes, when generating the domain reputation score, because incorporating additional domain infrastructure data is a known technique to improve the accuracy, reliability, and robustness of domain reputation assessment in cybersecurity systems. Such a modification merely involves the predictable use of known domain features to enhance an existing reputation scoring mechanism and would have yielded no more than predictable results. Regarding Claim 24 Silva in view of Prakash and Rajahram teaches intercepting web asset communications (e.g., via a browser extension) to identify associated domains and generate domain reputation or risk scores based on information obtained from those domains. However, Silva in view of Prakash and Rajahram is silent in explicitly teaching to determine an association between an Internet Protocol (IP) address of the domain and a malicious activity, and generating the reputation score based on that association. On the other hand, Schmidtler teaches collecting domain attribute data including IP address information and domain profile data including historical records of malicious activity (e.g., detected threats from user event logs and scanning), and using these together to generate a domain reputation score (Schmidtler ¶¶0052–0053, 0082). Schmidtler further teaches that domain names resolve to IP addresses and that IP address related information and metadata are used to determine the reputation of a host (Schmidtler ¶¶0104–0105). Thus, Schmidtler teaches associating IP address information with observed malicious activity and using that association as part of generating a domain reputation score. It would have been obvious to a person of ordinary skill in the art at the time of the invention to modify the system of Silva in view of Prakash and Rajahram to incorporate the IP address analysis of Schmidtler, including associating IP address information with malicious activity when generating a domain reputation score, because incorporating infrastructure indicators such as IP threat associations is a known technique to improve the accuracy and reliability of domain reputation assessment in cybersecurity systems. Such a modification represents a predictable use of prior art elements according to their established functions. Regarding Claim 25 Silva in view of Prakash and Rajahram teaches intercepting web asset communications to identify associated domains and generate domain reputation or risk scores based on information obtained from those domains. However Silva in view of Prakash and Rajahram is silent in explicitly teaching that the obtained information that characterizes the domain comprises at least one of an age of the domain and registration information for the domain, and generating the reputation score based on at least one of these attributes. On the other hand, Schmidtler teaches collecting domain attribute data from publicly available sources such as WHOIS and DNS, including registrar information and domain creation date, where the creation date corresponds to the age of the domain (Schmidtler ¶¶0056, 0082). Schmidtler further teaches that such domain attribute data is used as input to a domain reputation prediction model to generate a domain reputation score (Schmidtler ¶¶0057, 0081). It would have been obvious to a person of ordinary skill in the art at the time of the invention to modify the system of Silva in view of Prakash and Rajahram to incorporate the use of domain registration information and domain age as taught by Schmidtler when generating the domain reputation score, because domain age and registration data are well known indicators of domain trustworthiness and are commonly used in cybersecurity systems to improve the accuracy and reliability of domain reputation assessment. Such a modification represents a predictable use of prior art elements according to their established functions. Regarding Claim 30 Claim 30 is directed to a system corresponding to the computer implemented method in claim 23. Claim 30 is similar in scope to claim 23 and is therefore rejected under similar rationale. Regarding Claim 31 Claim 31 is directed to a system corresponding to the computer implemented method in claim 24. Claim 31 is similar in scope to claim 24 and is therefore rejected under similar rationale. Regarding Claim 32 Claim 32 is directed to a system corresponding to the computer implemented method in claim 25. Claim 32 is similar in scope to claim 25 and is therefore rejected under similar rationale. Regarding Claim 37 Claim 37 is directed to computer readable media instructions corresponding to the computer implemented method in claim 23. Claim 37 is similar in scope to claim 23 and is therefore rejected under similar rationale. Regarding Claim 38 Claim 38 is directed to computer readable media instructions corresponding to the computer implemented method in claim 24. Claim 38 is similar in scope to claim 24 and is therefore rejected under similar rationale. Regarding Claim 39 Claim 39 is directed to computer readable media instructions corresponding to the computer implemented method in claim 25. Claim 39 is similar in scope to claim 25 and is therefore rejected under similar rationale. Claims 27 and 34 is/are rejected under 35 U.S.C. 103 as being unpatentable over Silva (US 10,681,063 B1), in view of Prakash (US 2020/0092326 A1), in view of Rajahram (US 2019/0238544 A1) as applied to claims 21 and 28 and in further view of Phillips (US 20180026944 A1). Regarding Claim 27 Silva in view of Prakash and Rajahram teaches intercepting web asset communications to identify associated domains and generate domain reputation or risk scores based on information obtained from those domains. However, Silva in view of Prakash and Rajahram is silent in explicitly teaching generating a content security policy based on the reputation score of the domain and deploying the content security policy to protect the website. On the other hand, Phillips teaches evaluating security risk values associated with network entities (e.g., remote addresses and traffic types), generating a security policy (firewall policy rule) based on the evaluated risk values, and deploying/implementing the policy to control traffic and protect a system (Phillips ¶¶0080–0083; ¶0092). Phillips further teaches enforcing such policies by allowing or blocking traffic based on whether the computed risk exceeds a threshold, thereby protecting the underlying machine or network resource. It would have been obvious to a person of ordinary skill in the art at the time of the invention to modify the system of Silva in view of Prakash and Rajahram to generate and deploy a security policy based on the domain reputation score as taught by Phillips, because using risk or reputation scores to dynamically generate and enforce security policies is a well-known technique for protecting computing systems from malicious or untrusted sources. Such a modification represents a predictable use of prior art elements according to their established functions. Regarding Claim 34 Claim 34 is directed to a system corresponding to the computer implemented method in claim 27. Claim 34 is similar in scope to claim 27 and is therefore rejected under similar rationale. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAAD ABDULLAH whose telephone number is 571-272-1531. The examiner can normally be reached on Monday-Friday 9am-5pm EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, LYNN FIELD can be reached on 571-272-2092. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SAAD AHMAD ABDULLAH/ Examiner, Art Unit 2431 /SHIN-HON (ERIC) CHEN/ Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Dec 03, 2024
Application Filed
Jan 23, 2025
Response after Non-Final Action
Apr 21, 2026
Non-Final Rejection mailed — §103
Jul 15, 2026
Response Filed
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732510
Dynamic Message Analysis Platform for Enhanced Enterprise Security
2y 10m to grant Granted Sep 08, 2026
Patent 12712890
Cybersecurity Typing and Inferencing
2y 9m to grant Granted Aug 18, 2026
Patent 12683985
METHOD OF DETECTING SEQUENCE-BASED INTRUSION BY USING DBC FILE
2y 12m to grant Granted Jul 14, 2026
Patent 12676898
Method and Framework for Internet of Things Network Security
4y 5m to grant Granted Jul 07, 2026
Patent 12665877
ONION ROUTING NETWORK FOR SMART HOMES
3y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+30.4%)
2y 11m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 85 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month