Prosecution Insights
Last updated: August 17, 2026
Application No. 18/987,138

PRIORITIZED PATCH MANAGEMENT IN A DATACENTER

Final Rejection §103
Filed
Dec 19, 2024
Examiner
MAHMOUDI, RODMAN ALEXANDER
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
1y 1m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
197 granted / 247 resolved
+21.8% vs TC avg
Strong +17% interview lift
Without
With
+16.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
15 currently pending
Career history
274
Total Applications
across all art units

Statute-Specific Performance

§101
8.5%
-31.5% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
16.0%
-24.0% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 247 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendments This communication is in response to the amendments filed on 9 April 2026: Claims 1-3 and 12-20 are amended. Claims 1-20 are pending. Response to Arguments In response to Applicant’s remarks filed on 9 April 2026: a. Applicant’s arguments regarding the 35 U.S.C. 101 rejection on claims 17-20 have been fully considered and are deemed fully persuasive in view of the amendments. The 35 U.S.C. 101 rejection on claims 17-20 have been withdrawn. b. Applicant’s arguments that Choudha cannot reasonably be stretched to encompass attestation capabilities via a factory-provisioned inventory certificate or classification based on hardware-authenticity validation has been fully considered but is deemed moot in view of the new grounds of rejection presented in this Office Action. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 2 and 9 are rejected under 35 U.S.C. 103 as being unpatentable over Choudha et al. (U.S. PGPub. 2022/0201031), hereinafter Choudha, in view of Young et al. (U.S. PGPub. 2022/0207126), hereinafter Young, in further view of Weiss et al. (U.S. PGPub. 2023/0237642), hereinafter Weiss, in further view of Jarvie et al. (U.S. Patent 8,473,735), hereinafter Jarvie. Regarding claim 1, Choudha teaches A method for managing a datacenter (Choudha, Fig. 1, see “120”, “130”, which comprises a plurality of hardware systems comprised within a datacenter) (Choudha, Paragraph [0069], see “…the monitoring computing device 110 can compute a vulnerability risk distribution and/or a configuration defect risk distribution at a focused level, such as based on departments within an organization, network subnets, and/or physical site locations”, where “physical site locations” is being read as comprising a datacenter) comprising a plurality of Information Handling Systems (IHSs) (Choudha, Paragraph [0025], see “The monitoring computing device 110 can be a single computing device, or multiple computing devices, that host and enable the carrying out the functions…”, where “monitoring computing device 110” is being read as an Information Handling System) (Choudha, Paragraph [0028], see “At the initial system setup, the monitoring computing device 110 is programmed to scan and discover the computing devices 120 in the network 130, as well as prepare the customers’ infrastructure for vulnerability management by ingesting all relevant information about the organization and its infrastructure…”), the method comprising: maintaining profiles for hardware systems operating in the datacenter (Choudha, Fig. 1, see “120”, “130”, which are being read as hardware systems operating in a datacenter) (Choudha, Paragraph [0028], see “At the initial system setup, the monitoring computing device 110 is programmed to scan and discover the computing devices 120 in network 130, as well as prepare the customers’ infrastructure for vulnerability management by ingesting all relevant information about the organization and its infrastructure, classifying it as per the customers’ requirements and industry best practices and configuring the system for IACCR…,” which is being read as maintaining profiles for hardware systems operating in the datacenter), detecting a security threat to one or more of the hardware systems operating in the datacenter (Choudha, Paragraph [0045], see “…the monitoring computing device 110 identifies vulnerability exposure and vulnerability risks to the asset and determine probability of breach to an asset (i.e., a computing device 120 in network 130) owing to vulnerability and attributes such vulnerability to an attacker or an attack…”, which is being read as detecting a security threat to one or more of the hardware systems operating in the datacenter); assigning the security threat a datacenter threat score that characterizes the vulnerability of the datacenter to the security threat based on the hardware systems operating in the datacenter (Choudha, Paragraph [0062], see “…the monitoring computing device 110 ranks each of the computing devices based on the classification of step 210 and the weakness points for each of the computing devices monitored at step 220”) (Choudha, Paragraph [0063], see “The ranking can be on the risk score that is determined by the computing device 110 based on a correlation between the classification and the identified weakness points of the computing devices”) (Choudha, Paragraph [0066], see “The risk score for the overall system can be determined based on a vulnerability risk score and a configuration defect risk score”); classifying the hardware systems operating in the datacenter based on their relative vulnerability to the security threat (Choudha, Paragraph [0067], see “…the monitoring computing device 110 can categorize identified vulnerabilities as weaponized vulnerabilities or exploited vulnerabilities…The exploits can be exploited within an organization’s industry, within a certain geographic region, for a particular type of computing device, etc…”) (Choudha, Paragraph [0068], see “…the monitoring computing device 110 can categorize identified weaknesses based on parameters such as severity, computing device(s) potentially affected, threat to the computing devices and network as a whole, determined risk, or other parameters”, where “categorize” is being read as classifying the hardware systems operating in the datacenter based on their relative vulnerability to the security threat) (Choudha, Paragraph [0069], see “…the monitoring computing device 110 can compute a vulnerability risk distribution and/or a configuration defect risk distribution at a focused level, such as based on departments within an organization, network subnets, and/or physical site locations”) (Choudha, Paragraph [0072], see “…the monitoring computing device detects a risk of a weakness within one of the computing devices in the network. This can include a presence of a weakness within the computing device or a sufficiently high risk that a weakness will occur. This can be based on the categorization of the weaknesses and the assessments (detected configurations based on scan, rank based in part on the computing device’s roles or functions within the networks, etc.)”); prioritizing patching for each of the hardware systems operating in the datacenter based on a plurality of vulnerability hyperplanes that are identified in the vulnerability classification of the hardware systems operating in the datacenter (Choudha, Paragraph [0058], see “As it performs scans for configuration defects, the monitoring computing device 110 can identify and group computing devices 120 having common configuration defects”, where “identify and group” is being read as comprising vulnerability hyperplanes that are identified based on classification/categorization) (Choudha, Paragraph [0075], see “…the monitoring computing device 110 determines a remediation action based on the detected risk of weakness, the calculated true risk, and the ranking of the computing device…step 250 includes the monitoring computing device 110 classifying vulnerability results into patch installation and configuration change for remediation”, where “determines a remediation action based…the ranking of the computing device” is being read as prioritizing patching for each of the hardware systems in the datacenter based on a plurality of hyperplanes (based on rankings/groupings/categories) that are identified in the vulnerability classification of the hardware systems in the datacenter). Choudha does not teach the following limitation(s) as taught by Young: wherein the profiles identify characteristics of the hardware systems (Young, Paragraph [0057], see “…Such a manifest may be a file that includes an entry for each component installed to an IHS, where the entry may specify various characteristics of the component, such as model numbers and installation locations, and may also specify any unique identifiers associated with the component, such as a MAC address or a serial number…”), wherein the characteristics comprise attestation capabilities via use of a factory-provisioned inventory certificate (Young, FIG. 6, which depicts attestation capabilities via use of a factory-provisioned inventory certificate for a specified profile of an IHS) Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, by implementing techniques of profiles identifying characteristics of the hardware systems, wherein the characteristics comprise attestation capabilities via use of a factory-provisioned inventory certificate, disclosed of Young. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of profiles identifying characteristics of the hardware systems, wherein the characteristics comprise attestation capabilities via use of a factory-provisioned inventory certificate. This allows for better security management by enabling verifiable, tamper-resistant identity and integrity proofs for each system through profiling each system based on an inventory certificate. Young is deemed as analogous art due to the art disclosing techniques of profiles identifying characteristics of the hardware systems, wherein the characteristics comprise attestation capabilities via use of a factory-provisioned inventory certificate (Young, FIG. 6). Choudha as modified by Young do not teach the following limitation(s) as taught by Weiss: wherein profile data collected from the hardware systems is normalized to identify outliers and provide initial groupings of the hardware systems by type (Weiss, Claim 26, see “…wherein if the defect is present providing true state data comprises classifying the component to a class of components responsive to a type of the defect”, which is analogous to identifying outliers (e.g., defect being present) and providing groupings of the hardware systems by type). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, and techniques disclosed of Young, by implementing techniques of the profile data from the hardware system identifying outliers and providing groupings of the hardware systems by type, disclosed of Weiss. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the profile data from the hardware system identifying outliers and providing groupings of the hardware systems by type. This allows for better security management by enabling proactive maintenance, optimized performance and early detection of anomalies. Weiss is deemed as analogous art due to the art disclosing techniques of the profile data from the hardware system identifying outliers and providing groupings of the hardware systems by type (Weiss, Claim 26). Choudha as modified by Young and further modified by Weiss do not teach the following limitation(s) as taught by Jarvie: classifying the hardware systems operating in the datacenter based on their relative vulnerability to the security threat and based in part on whether authenticity of the hardware of the hardware systems may be validated using the factory-provisioned inventory certificate (Jarvie, Column 6, Lines 54 – 59, see “…By way of such detection and comparison, the discovery module can automatically determine, for example, if certificates exist that are not in the inventory stored at data tier 130, or if one or more certificates have a different status (e.g., revoked) than is indicated in the inventory information at data tier 130”, which is analogous to classifying (which is done through determining whether or not a certificate exists) the hardware system based in part on whether authenticity of the hardware systems may be validated using an inventory certificate). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young and techniques disclosed of Weiss, by implementing techniques of classifying the hardware systems based in part on whether authenticity of the hardware may be validated using an inventory certificate, disclosed of Jarvie. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of classifying the hardware systems based in part on whether authenticity of the hardware may be validated using an inventory certificate. This allows for better security management by grouping and prioritizing systems with valid inventory certificates, which reduces risks from tampering and/or theft, whilst improving risk management and cybersecurity posture. Jarvie is deemed as analogous art due to the art disclosing techniques of classifying the hardware systems based in part on whether authenticity of the hardware may be validated using an inventory certificate (Jarvie, Column 6, Lines 54 – 59). Regarding claim 2, Choudha as modified by Young and further modified by Weiss and Jarvie teaches The method of claim 1, wherein the datacenter threat score is generated from Common Vulnerability Scoring System (CVSS) metrics that characterize the vulnerability of the datacenter to security threats (Choudha, Paragraph [0034], see “The data ingested from a vulnerability scanner can include asset data…vulnerability data (CVE, name, description, scanner severity, CPE, target asset, CVSS, exploitability, last scan data…”). Regarding claim 9, Choudha as modified by Young and further modified by Weiss and Jarvie teaches The method of claim 1, wherein the vulnerability hyperplanes segregate the classified hardware systems into prioritized groupings of the hardware systems operating in the datacenter (Choudha, Paragraph [0058], see “As it performs scans for configuration defects, the monitoring computing device 110 can identify and group computing devices 120 having common configuration defects”, where “identify and group” is being read as comprising the vulnerability hyperplanes segregating the classified hardware systems into prioritized groupings) (Choudha, Paragraph [0075], see “…the monitoring computing device 110 determines a remediation action based on the detected risk of weakness, the calculated true risk, and the ranking of the computing device…step 250 includes the monitoring computing device 110 classifying vulnerability results into patch installation and configuration change for remediation”, where “ranking of the computing device” is also being read as segregating the hardware systems into prioritized groupings). Claims 3, 7, and 10-11 are rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Gullikson et al. (U.S. PGPub. 2023/0110056), hereinafter Gull. Regarding claim 3, Choudha as modified by Young and further modified by Weiss and Jarvie do not teach the following limitation(s) as taught by Gull: The method of claim 2, wherein the CVSS metrics are utilized as inputs to an Adaptive Neuro Fuzzy Inference System (ANFIS) that generates the datacenter threat score as an output (Gull, Paragraph [0007], see “…provide input data to one or more behavior models to generate an anomaly score…”, where “input data” is analogous to comprising CVSS metrics and where “anomaly score” is analogous to threat score as an output) (Gull, Paragraph [0027], see “Examples of machine-learning models include…adaptive neuro-fuzzy inference systems…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss and techniques disclosed of Jarvie, by implementing techniques of utilizing an Adaptive Neuro Fuzzy Inference System that generates a threat score as output, disclosed of Gull. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of utilizing an Adaptive Neuro Fuzzy Inference System that generates a threat score as output. This allows for a better hybrid AI approach that combines the learning capability of neural networks with the interpretability of fuzzy logic. Gull is deemed as analogous art due to the art disclosing techniques of utilizing an Adaptive Neuro Fuzzy Inference System that generates a threat score as output (Gull, Paragraph [0007]). Regarding claim 7, Choudha as modified by Young and further modified by Weiss and Jarvie do not teach the following limitation(s) as taught by Gull: The method of claim 1, wherein the hardware systems operating in the datacenter are classified according to the vulnerability to the security threat through operation of a Random Forest Classifier (Gull, Paragraph [0007], see “…provide input data to one or more behavior models to generate an anomaly score…”) (Gull, Paragraph [0137], see “…the classifier trainer 520 generates a trained classifier 522, such as a random forest classifier…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss and techniques disclosed of Jarvie, by implementing techniques of classifying the hardware systems through operation of a Random Forest Classifier, disclosed of Gull. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of classifying the hardware systems through operation of a Random Forest Classifier. This allows for higher accuracy of threat assessment and a more robust performance on large datasets, ultimately allowing for efficient, scalable classification of complex, high-dimensional hardware. Gull is deemed as analogous art due to the art disclosing techniques of classifying the hardware systems through operation of a Random Forest Classifier (Gull, Paragraph [0137]). Regarding claim 10, Choudha as modified by Young and further modified by Weiss and Jarvie do not teach the following limitation(s) as taught by Gull: The method of claim 9, wherein the vulnerability hyperplanes are identified through operation of a Support Vector Classifier (Gull, Paragraph [0027], see “Examples of machine-learning models include…support vector machines”, which is analogous to utilizing a support vector classifier/machine to identify hyperplanes). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss and techniques disclosed of Jarvie, by implementing techniques of identifying the vulnerability hyperplanes through operation of a Support Vector Classifier, disclosed of Gull. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of identifying the vulnerability hyperplanes through operation of a Support Vector Classifier. This allows for a more powerful, robust method for detecting threats by constructing optimal decision boundaries between normal and malicious activities using the support vector classification. Gull is deemed as analogous art due to the art disclosing techniques of identifying the vulnerability hyperplanes through operation of a Support Vector Classifier (Gull, Paragraph [0027]). Regarding claim 11, Choudha as modified by Young and further modified by Weiss, Jarvie and Gull teaches The method of claim 10, wherein vectors used by the Support Vector Classifier in classifying the hardware systems operating in the datacenter into one of the prioritized groupings comprise an important of respective hardware systems to overall datacenter operations (Choudha, Paragraph [0043], see “The criticality risk scoring of asset categories identified within or of a computing device 120 in the network 130 can refer to the relative importance of the computing device 120 to the functions of the collective network 130 and/or within an organization, innately relative to the organization…”). Claims 4-5 are rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Gull, in further view of Jose et al. (U.S. PGPub. 2022/0022344), hereinafter Jose. Regarding claim 4, Choudha as modified by Young and further modified by Weiss, Jarvie and Gull do not teach the following limitation(s) as taught by Jose: The method of claim 3, wherein the CVSS metrics comprise a first target distribution metric for IHS server hardware systems that are operating in the datacenter (Jose, Paragraph [0003], see “The operation of an HIS may be characterized by metrics that provide a measurable aspect of the IHS’s operation…Using the metric data collected by a telemetry system, the operation of an IHS may be monitored and managed remotely”, which is analogous to comprising a distribution metric for IHS server hardware systems that are operating in the datacenter). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss, techniques disclosed of Jarvie and techniques disclosed of Gull, by implementing techniques of the CVSS metrics comprising a metric for IHS server hardware systems in the datacenter, disclosed of Jose. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the CVSS metrics comprising a metric for IHS server hardware systems in the datacenter. This allows for better security management for IHS server hardware systems in the datacenter by utilizing target distribution metrics for the server hardware systems, ultimately enabling data centers to prioritize patching, assess risk, and align the server hardware systems with compliance standards. Jose is deemed as analogous art due to the art disclosing techniques of the CVSS metrics comprising a metric for IHS server hardware systems in the datacenter (Jose, Paragraph [0003]). Regarding claim 5, Choudha as modified by Young and further modified by Weiss, Jarvie and Gull do not teach the following limitation(s) as taught by Jose: The method of claim 3, wherein the CVSS metrics comprise a second target distribution metric for network switch hardware systems that are operating in the datacenter (Jose, Paragraph [0065], see “…the use of a telemetry system for the identification of an anomalous network zone within a rack of a data center…Servers may report metric information that relates the number of bytes of data transmitted by each port of a network controller of a server…administrators may investigate whether issues with a network switch of rack number seven are causing the servers in this rack to be provided with limited network transmission bandwidth”, which is analogous to comprising a distribution metric for network switch hardware systems that are operating in the datacenter). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss, techniques disclosed of Jarvie and techniques disclosed of Gull, by implementing techniques of the CVSS metrics comprising a metric for network switch hardware systems in the datacenter, disclosed of Jose. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the CVSS metrics comprising a metric for network switch hardware systems in the datacenter. This allows for better security management for network switch hardware systems in the datacenter by utilizing target distribution metrics for the network switches, ultimately enabling data centers to prioritize patching, assess risk, and align the network switches with compliance standards. Jose is deemed as analogous art due to the art disclosing techniques of the CVSS metrics comprising a metric for network switch hardware systems in the datacenter (Jose, Paragraph [0065]). Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Jose. Regarding claim 6, Choudha as modified by Young and further modified by Weiss and Jarvie do not teach the following limitation(s) as taught by Jose: The method of claim 1, wherein the hardware systems operating within the datacenter comprise the plurality of IHSs and a plurality of network switches (Jose, Paragraph [0007], see “…systems are provided for utilizing telemetry data to identify zones within a data center. The systems may include: a plurality of IHSs (Information Handling Systems)…”) (Jose, Paragraph [0028], see “…the rack may include a network switch, or other network routing device…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss and techniques disclosed of Jarvie, by implementing techniques of the hardware systems operating within the datacenter comprising a plurality of IHSs and a plurality of network switches, disclosed of Jose. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the hardware systems operating within the datacenter comprising a plurality of IHSs and a plurality of network switches. This allows for high-performance computing, low latency communication, and robust scalability by utilizing a plurality of IHSs and network switches in a datacenter. Jose is deemed as analogous art due to the art disclosing techniques of the hardware systems operating within the datacenter comprising a plurality of IHSs and a plurality of network switches (Jose, Paragraphs [0007] and [0028]). Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Gull, in further view of ARZANI et al. (U.S. PGPub. 2020/0244674), hereinafter Arzani. Regarding claim 8, Choudha as modified by Young and further modified by Weiss, Jarvie and Gull do not teach the following limitation(s) as taught by Arzani: The method of claim 7, wherein the Random Forest Classifier utilizes as inputs the datacenter threat score and the profiles maintained for the hardware systems operating in the datacenter (Arzani, Paragraph [0083], see “…The evaluation agent 224 can include one or more of the following…a classifier, a confidence score generator, and an output interface…the evaluation may include a random forest analysis using evaluation trees created by the trainer…the classifier 504 may…provide for what type of compromise was observed based on previous evaluations”, which is analogous to the random forest classifier utilizing inputs such as confidence (risk, threat, anomaly) scores, profiles maintained for systems, configurations maintained for systems, etc.) (Arzani, Paragraph [0122], see “…The classifier 504 can execute random forest analysis with collected data from a collection agent 212…The random forest algorithm traverses one or more evaluation trees to determine if the communication patterns of the virtual machines 204 are similar to communication patterns or features in the data structure 672, which characterizes past compromised virtual machines 204…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss, techniques disclosed of Jarvie and techniques disclosed of Gull, by implementing techniques of the random forest classifier utilizing threat scores and configuration profiles as inputs, disclosed of Arzani. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the random forest classifier utilizing threat scores and configuration profiles as inputs. This allows for a more accurate, automated, and robust threat detection by combining multiple decision trees, ultimately reducing false positives through ensemble learning. Arzani is deemed as analogous art due to the art disclosing techniques of the random forest classifier utilizing threat scores and configuration profiles as inputs (Arzani, Paragraph [0083]). Claims 12-13, 16-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Parthasarathy et al. (U.S. PGPub. 2023/0078359), hereinafter Parth. Regarding claim 12, the claim is rejected under the same reasoning as claim 1. However, claim 12 includes additional subject matter cited wherein the characteristics comprise a manufacturer, a model, an operating system, firmware, and patch history, which is taught by Parth, Paragraph [0032], see “…Some examples of device attributes can include a device model, a device manufacturer, an OS type, an OS version, a firmware version, a memory size…” and Paragraph [0077], see “…the limits can be determined automatically by the ISDS 160 based on default settings or previous software deployments”, which is analogous to comprising patch history on previous software patch deployments. Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Choudha, techniques disclosed of Young, techniques disclosed of Weiss, and techniques disclosed of Jarvie, by implementing techniques of the profile characteristics comprising a manufacturer, a model, an operating system, firmware and patch history, disclosed of Parth. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for prioritized patch management in a datacenter, comprising of the profile characteristics comprising a manufacturer, a model, an operating system, firmware and patch history. This allows for better security management and operational management by providing a complete, verifiable record of a hardware systems identity, configuration and security posture. Parth is deemed as analogous art due to the art disclosing techniques of the profile characteristics comprising a manufacturer, a model, an operating system, firmware and patch history (Parth, Paragraphs [0032] and [0077]). Regarding claims 13 and 18, the claims are rejected under the same reasoning as claim 2. Regarding claims 16 and 20, the claims are rejected under the same reasoning as claim 9. Regarding claim 17, the claim is rejected under the same reasoning as claim 12. Claims 14 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Parth, in further view of Jose. Regarding claims 14 and 19, the claims are rejected under the same reasoning as claim 6. Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Choudha, in view of Young, in further view of Weiss, in further view of Jarvie, in further view of Parth, in further view of Gull. Regarding claim 15, the claim is rejected under the same reasoning as claim 7. Conclusion Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office Action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Dec 19, 2024
Application Filed
Apr 07, 2026
Non-Final Rejection mailed — §103
Apr 09, 2026
Response Filed
Aug 03, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705332
METHOD FOR VERIFYING THE AUTHENTICITY OF AN ACTUATOR COMMAND
3y 0m to grant Granted Aug 11, 2026
Patent 12694092
PRE-REGISTRATION OF AUTHENTICATION DEVICES
2y 0m to grant Granted Jul 28, 2026
Patent 12651053
APP PROFILE VERIFICATION SETUP
2y 0m to grant Granted Jun 09, 2026
Patent 12645780
VEHICLE CONTROL DEVICE, SYSTEM, AND METHOD
2y 0m to grant Granted Jun 02, 2026
Patent 12647432
Quantification of Adversary Tactics, Techniques, and Procedures using Threat Attribute Groupings and Correlation
1y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
96%
With Interview (+16.7%)
2y 9m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 247 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month