Prosecution Insights
Last updated: October 02, 2026
Application No. 18/970,320

SECURITY PLATFORM WITH EXTERNAL INLINE PROCESSING OF ASSEMBLED SELECTED TRAFFIC

Final Rejection §103
Filed
Dec 05, 2024
Priority
Aug 31, 2020 — continuation of 12/200,016
Examiner
BROWN, CHRISTOPHER J
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
1y 7m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
544 granted / 720 resolved
+15.6% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
36 currently pending
Career history
759
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
64.0%
+24.0% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 720 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Examiner has incorporated Kaloroumakis US 2016/0149943 to meet the claims as amended. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 6-8, 11-14, 16-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Anderson US 2021/0160275 in view of Weith US 2017/0359220 in view of Kaloroumakis US 2016/0149943. As per claim 1, Anderson teaches A system comprising: a processor configured to: detect a file payload in a monitored session at a security platform; Anderson teaches proxy a portion of the monitored session to assemble the file payload using an external processing unit; [0040][0050][0051] (teaches a traffic exporter such as a router or firewall) Anderson teaches send the assembled file payload to a plurality of cloud-based security services for analysis based on a security policy; [0032][0040][0050][0051][0052][0057] (teaches network traffic analysis by exporting data to the cloud for a traffic analysis service) Anderson teaches and perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0053] (mitigation actions including blocking or dropping traffic) Anderson teaches filter policies for selection of traffic data for analysis. Weith supplementally teaches perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0025]-[0028] [0031][0039] (teaches security policy data and policies for security data analysis, and mitigation actions) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it more clearly articulates flexible and configurable security policies. Kaloroumakis teaches wherein the file payload includes a file type wherein the file type includes platform, wherein the file payload includes a file type, wherein the file type includes one or more of the following: JavaScript (JS) files, Windows Portable Executable (PE), and/or Word/Portable Document Format (PDF) documents, wherein the file type includes a first file type, a second file type, or a first and second file types; wherein the plurality of cloud-based security services includes a first cloud-based security service and a second cloud-based security service, wherein in the event that the file type corresponds to the first file type, send the file payload to the first cloud-based security service, wherein in the event that the file type corresponds to the second file type, send the file type to the second cloud-based security service; and perform a remedial action based on results of the analysis. [0030][0032][0045][0048] [0050][0051][0055][0059] (teaches a “cloud network” of classification sensors including “file analyzers”; where the file analyzer determines which service based on content and metadata to use/subscribes; including PDF/JAR/PE32/MS Word file types; teaches that some files may only use certain security services, such as PE Scanner for PS32 file type; getting results of security services; tagged as potentially malicious and performing remedial action; quarantine, deletion, alerting user) It would have been obvious to one of ordinary skill in the art before the priority date of the current invention to use the teaching of Kaloroumakis with the prior art because it improves security. [0008][0009] As per claim 2, The system recited in claim 1, Anderson teaches wherein the external processing unit is located in a cloud network of a security service provider. [0051] (teaches cloud service) As per claim 3, The system recited in claim 1, Anderson teaches wherein the external processing unit is located on-premises of an enterprise customer. [0051] (teaches could be on local network) Weith teaches the network is an enterprise network [0026][0027] It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective security for companies. As per claim 4, The system recited in claim 1, Anderson teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis on the assembled file payload. [0052] (multiple security analysis, exfiltration, malware, audit) Weith additionally teaches a plurality of distinct types of security analysis [0027][0028] (malware, spam, content filter, data leakage/exfiltration) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides more comprehensive security. As per claim 6, The system recited in claim 1, Anderson teaches wherein the performing of the remedial action comprises to: block the assembled file payload to prevent the assembled file payload from being sent to an original destination. [0053] (mitigation actions including blocking or dropping traffic) Weith supplementally teaches preventing payload from being sent to an original destination [0028] [0118](deny distribution) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective and user friendly security. As per claim 7, The system recited in claim 1, Weith teaches wherein the performing of the remedial action comprises to: allow the assembled file payload to be sent to an original destination. [0028] (allows distribution of the file payload) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective and user friendly security. As per claim 8, The system recited in claim 1, Weith teaches wherein the performing of the remedial action comprises to: send a modified version of the assembled file payload to an original destination. [0028] (distributing a cleaned version of the file payload) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective and user friendly security. As per claim 11, Anderson teaches a method, comprising: detecting a file payload in a monitored session at a security platform; and proxy a portion of the monitored session to assemble the file payload using an external processing unit; [0040][0050][0051] (teaches a traffic exporter such as a router or firewall) Anderson teaches send the assembled file payload to a plurality of cloud-based security services for analysis based on a security policy; [0032][0040][0050][0051][0052][0057] (teaches network traffic analysis by exporting data to the cloud for a traffic analysis service) Anderson teaches and perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0053] (mitigation actions including blocking or dropping traffic) Anderson teaches filter policies for selection of traffic data for analysis. Weith supplementally teaches perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0025]-[0028] [0031][0039] (teaches security policy data and policies for security data analysis, and mitigation actions) It would have been obvious to one of ordinary skill in the art before the effective filing data of the current application to use the teaching of Weith with the prior art because it more clearly articulates flexible and configurable security policies. Kaloroumakis teaches wherein the file payload includes a file type wherein the file type includes platform, wherein the file payload includes a file type, wherein the file type includes one or more of the following: JavaScript (JS) files, Windows Portable Executable (PE), and/or Word/Portable Document Format (PDF) documents, wherein the file type includes a first file type, a second file type, or a first and second file types; wherein the plurality of cloud-based security services includes a first cloud-based security service and a second cloud-based security service, wherein in the event that the file type corresponds to the first file type, send the file payload to the first cloud-based security service, wherein in the event that the file type corresponds to the second file type, send the file type to the second cloud-based security service; and perform a remedial action based on results of the analysis. [0030][0032][0045][0048] [0050][0051][0055][0059] (teaches a “cloud network” of classification sensors including “file analyzers”; where the file analyzer determines which service based on content and metadata to use/subscribes; including PDF/JAR/PE32/MS Word file types; teaches that some files may only use certain security services, such as PE Scanner for PS32 file type; getting results of security services; tagged as potentially malicious and performing remedial action; quarantine, deletion, alerting user) It would have been obvious to one of ordinary skill in the art before the priority date of the current invention to use the teaching of Kaloroumakis with the prior art because it improves security. [0008][0009] As per claim 12, The method of claim 11, Anderson teaches wherein the external processing unit is located in a cloud network of a security service provider. [0051] (teaches cloud service) As per claim 13, The method of claim 11, Anderson teaches wherein the external processing unit is located on-premises of an enterprise customer. [0051] (teaches could be on local network) Weith teaches the network is an enterprise network [0026][0027] It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective security for companies. As per claim 14, The method of claim 11, Anderson teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis on the assembled file payload. [0052] (multiple security analysis, exfiltration, malware, audit) Weith additionally teaches a plurality of distinct types of security analysis [0027][0028] (malware, spam, content filter, data leakage/exfiltration) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides more comprehensive security. As per claim 16, Anderson teaches A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for: detecting a file payload in a monitored session at a security platform; and proxy a portion of the monitored session to assemble the file payload using an external processing unit; [0040][0050][0051] (teaches a traffic exporter such as a router or firewall) Anderson teaches send the assembled file payload to a plurality of cloud-based security services for analysis based on a security policy; [0032][0040][0050][0051][0052][0057] (teaches network traffic analysis by exporting data to the cloud for a traffic analysis service) Anderson teaches and perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0053] (mitigation actions including blocking or dropping traffic) Anderson teaches filter policies for selection of traffic data for analysis. Weith supplementally teaches perform a remedial action based on results of the analysis and based on the security policy; and a memory coupled to the processor and configured to provide the processor with instructions. [0025]-[0028] [0031][0039] (teaches security policy data and policies for security data analysis, and mitigation actions) It would have been obvious to one of ordinary skill in the art before the effective filing data of the current application to use the teaching of Weith with the prior art because it more clearly articulates flexible and configurable security policies. Kaloroumakis teaches wherein the file payload includes a file type wherein the file type includes platform, wherein the file payload includes a file type, wherein the file type includes one or more of the following: JavaScript (JS) files, Windows Portable Executable (PE), and/or Word/Portable Document Format (PDF) documents, wherein the file type includes a first file type, a second file type, or a first and second file types; wherein the plurality of cloud-based security services includes a first cloud-based security service and a second cloud-based security service, wherein in the event that the file type corresponds to the first file type, send the file payload to the first cloud-based security service, wherein in the event that the file type corresponds to the second file type, send the file type to the second cloud-based security service; and perform a remedial action based on results of the analysis. [0030][0032][0045][0048] [0050][0051][0055][0059] (teaches a “cloud network” of classification sensors including “file analyzers”; where the file analyzer determines which service based on content and metadata to use/subscribes; including PDF/JAR/PE32/MS Word file types; teaches that some files may only use certain security services, such as PE Scanner for PS32 file type; getting results of security services; tagged as potentially malicious and performing remedial action; quarantine, deletion, alerting user) It would have been obvious to one of ordinary skill in the art before the priority date of the current invention to use the teaching of Kaloroumakis with the prior art because it improves security. [0008][0009] As per claim 17, The computer program product recited in claim 16, Anderson teaches wherein the external processing unit is located in a cloud network of a security service provider. [0051] (teaches cloud service) As per claim 18, The computer program product recited in claim 16, Anderson teaches wherein the external processing unit is located on-premises of an enterprise customer. [0051] (teaches could be on local network) Weith teaches the network is an enterprise network [0026][0027] It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides effective security for companies. As per claim 19, The computer program product recited in claim 16, Anderson teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis on the assembled file payload. [0052] (multiple security analysis, exfiltration, malware, audit) Weith additionally teaches a plurality of distinct types of security analysis [0027][0028] (malware, spam, content filter, data leakage/exfiltration) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Weith with the prior art because it provides more comprehensive security. Claim(s) 5, 15, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Anderson US 2021/0160275 in view of Weith US 2017/0359220 in view of Harris US 2010/0083380 As per claim 5, The system recited in claim 1, Anderson and Weith fail to teach the following: Harris teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis in parallel on the assembled file payload. [0063] (parallel distinct security analysis operations) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Harris with the prior art because it is more efficient for security. As per claim 15, The method of claim 11, Anderson and Weith fail to teach the following: Harris teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis in parallel on the assembled file payload. [0063] (parallel distinct security analysis operations) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Harris with the prior art because it is more efficient for security. As per claim 20, The computer program product recited in claim 16, Anderson and Weith fail to teach the following: Harris teaches wherein the plurality of cloud-based security services perform a plurality of distinct types of security analysis in parallel on the assembled file payload. [0063] (parallel distinct security analysis operations) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Harris with the prior art because it is more efficient for security. Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Anderson US 2021/0160275 in view of Weith US 2017/0359220 in view of Rowett US 2005/0216770. As per claim 9, The system recited in claim 1, Anderson and Weith fail to teach the following: Rowett teaches wherein the performing of the remedial action comprises to: send a modified version of the assembled file payload to an original destination, wherein the modified version of the assembled file payload includes an added watermark. [0174] (teaches adding a watermark to content/files after processing by intrusion detection system) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Rowett with the prior art because it more clearly informs the user of security procedures. Claim(s) 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Anderson US 2021/0160275 in view of Weith US 2017/0359220 in view of Ward US 2011/0252474 As per claim 10, The system recited in claim 1, Anderson and Weith fail to teach the following: Ward teaches wherein performing of the remedial action comprises to: send an encrypted version of the assembled file payload to an original destination. [0040] (teaches sending an encrypted file to target) It would have been obvious to one of ordinary skill in the art before the effective filing date of the current application to use the teaching of Ward with the prior art because it protects the recipient from malware. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Dec 05, 2024
Application Filed
May 05, 2026
Non-Final Rejection mailed — §103
Jun 01, 2026
Applicant Interview (Telephonic)
Jun 01, 2026
Examiner Interview Summary
Jun 25, 2026
Response Filed
Sep 09, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719928
SYSTEM AND METHOD FOR ADAPTIVE DECEPTION ORCHESTRATION
2y 0m to grant Granted Aug 25, 2026
Patent 12712905
EVALUATING NETWORK FLOW RISKS
3y 11m to grant Granted Aug 18, 2026
Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~1y 7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 720 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month