Prosecution Insights
Last updated: August 17, 2026
Application No. 19/013,710

VULNERABILITY DETECTION AND MANAGEMENT

Non-Final OA §103
Filed
Jan 08, 2025
Examiner
DOAN, TRANG T
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
522 granted / 630 resolved
+24.9% vs TC avg
Strong +17% interview lift
Without
With
+16.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
22 currently pending
Career history
657
Total Applications
across all art units

Statute-Specific Performance

§101
15.3%
-24.7% vs TC avg
§103
35.5%
-4.5% vs TC avg
§102
19.8%
-20.2% vs TC avg
§112
19.7%
-20.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 630 resolved cases

Office Action

§103
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 1/8/2025. Claims 1-20 are pending for consideration. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Information Disclosure Statement The information disclosure statement (IDS) submitted on 4/20/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3, 6-11 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Montgomery et al. (US 10514905) (hereinafter Montgomery) in view of Gilbert et al. (US 9197663) (hereinafter Gilbert). Regarding claim 1, Montgomery discloses a method, comprising: receiving recording a first asset identifier of the first asset as linked to the first package (Montgomery: paragraphs (16-18 and 31), “each enterprise may configure its compliance reports (essentially which conda packages or software libraries are to be included in the compliance report) to the packages that they use and the report can be customized to focus on just the software the enterprise wants to monitor”… “to ensure that the authenticity of each conda package and the information contained in each conda package. In the embodiment shown in FIG. 2, the sources used to generate the conda packages may include PyPl and github”…“The method may then distribute the conda packages and compliance report together as a bundle”); comparing a first inventory of the package repository against a first report of identified vulnerabilities (Montgomery: paragraphs (16-17 and 22-25), “In this embodiment shown in FIG. 2, the sources used to generate the compliance reports may include Common Vulnerabilities and Exposures (CVE) catalogs which are each a catalog of known security threats. Each catalog is sponsored by the United States Department of Homeland Security (DHS), and threats are divided into two categories: vulnerabilities and exposures. In the example with the NumPy open source program, FIG. 5 illustrates an example of a CVE report for the same open source NumPy program and the report shows a score and the vulnerability types that may be used, in part, to determine if NumPy is out of compliance”… “When the system sends the compliance reports and conda packages to the enterprise customer, the Anaconda Enterprise system 108B can look at historic customer usage of any packages that are flagged in the new incoming compliance report”); determining the first package is a first vulnerable package when the first package is included in the first report (Montgomery: paragraphs (14-17 and 22-25), “While monitoring and controlling of the one or more assets (APP1, . . . , APPN), the AE engine 108 may track each asset, determine if/when each asset is out of compliance and perform remediation on each asset. For purposes of illustration, out of compliance means out of compliance from a computer security/malware/security threat standpoint, but the system may be used to track other types of compliance of the asset.”…“For each identified out of compliance application or cloud service, the method may determine if there is a new package to fix the compliance issues (310)”); mapping the first vulnerable package to the first asset based on the first asset identifier (Montgomery: paragraphs (8 and 16-17), “a NumPy open source program is identified as an out of compliance application from a security standpoint. FIG. 4 illustrates an example of a conda package for an open source NumPy program. ... For example, user application 1 may be comprised of packages such as NumPy, scipy, scikit-learn and many others along with custom user code and each package may be an asset whose compliance is monitored and an asset that can be remediated in the package is out of compliance”… “In this embodiment shown in FIG. 2, the sources used to generate the compliance reports may include Common Vulnerabilities and Exposures (CVE) catalogs which are each a catalog of known security threats. Each catalog is sponsored by the United States Department of Homeland Security (DHS), and threats are divided into two categories: vulnerabilities and exposures. In the example with the NumPy open source program, FIG. 5 illustrates an example of a CVE report for the same open source NumPy program and the report shows a score and the vulnerability types that may be used, in part, to determine if NumPy is out of compliance.”); determining the first asset is a first affected asset (Montgomery: paragraphs (22-24), “For each identified out of compliance application or cloud service, the method may determine if there is a new package to fix the compliance issues…If it is determined that there is not a fix for the out of compliance application/cloud service, the method may shut down the out of compliance application/cloud service and alert the owner of the out of compliance application/cloud service or the entity site owner.”); mapping the first affected asset to a first user account (Montgomery: paragraphs (22-24), “For each identified out of compliance application or cloud service, the method may determine if there is a new package to fix the compliance issues…If it is determined that there is not a fix for the out of compliance application/cloud service, the method may shut down the out of compliance application/cloud service and alert the owner of the out of compliance application/cloud service or the entity site owner.”); and providing a first notification about the first vulnerable package and the first affected asset to a user of the first user account (Montgomery: paragraphs (22-24), “alert the owner of the out of compliance application/cloud service or the entity site owner”). Montgomery does not explicitly disclose the following limitation which is disclosed by Gilbert, receiving an indication that a first package has been downloaded (Gilbert: paragraphs (14, 16 and 96), “When a software package is downloaded and/or executed (e.g., when execution of the software package is initiated) by client computer 105, data relating to the software package may be sent to malware detection server”… “The client computer may send the identifying data to malware detection server 110 in response to the corresponding software package being downloaded to the client computer, in response to execution of the software package being initiated on the client computer, and/or in response to any other suitable event.”). Montgomery and Gilbert are analogous art because they are from the same field of endeavor, data protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Montgomery and Gilbert before him or her, to modify the system of Montgomery to include receiving an indication that a first package has been downloaded of Gilbert. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results. Regarding claim 2, Montgomery as modified discloses further comprising: adding the first vulnerable package to a retraction report (Montgomery: paragraphs (17 and 22-25), “For each identified out of compliance application or cloud service, the method may determine if there is a new package to fix the compliance issues (310) wherein the new package is part of the materials that were distributed to each enterprise site 108 and the engine 108C in the example in FIG. 2. If it is determined that there is not a fix for the out of compliance application/cloud service, the method may shut down the out of compliance application/cloud service and alert the owner of the out of compliance application/cloud service or the entity site owner (312) and the method is completed for that particular out of compliance application/cloud service”); and triggering a retraction of the first vulnerable package from the package repository by sending the retraction report (Montgomery: paragraphs (17 and 22-25). Regarding claim 3, Montgomery as modified discloses wherein receiving the indication that the first package has been successfully downloaded by the first asset (Gilbert: paragraph 14, “When a software package is downloaded and/or executed (e.g., when execution of the software package is initiated) by client computer 105, data relating to the software package may be sent to malware detection server 110.”) comprises receiving a first access log of the package repository including a record of: a request for the first package by the first asset; the first asset identifier of the first asset; a package identifier of the first package; and a status indication of a successful download of the first package by the first asset (Gilbert: paragfaphs (9, and 36), “using visual and/or non-visual elements of the software package to assess the threat presented by the software.”… “the non-visual elements can include data identifying a publisher, filenames, external function calls, registered operating system functions, operating system filenames, registry key, system file value, application filenames, library filenames, file size, provider, vendor tags and path names. The visual elements can include an icon, which may be presented in raster format (e.g., in the format of an .ico file, a .jpg file, an .img file, a .tiff file, a .gif file, a .bmp file, or a .png file) or in a vector format. In certain implementations the size of the visual information is less than 1 megabyte. The visual elements and non-visual elements may be each extracted from separate components of the software package.”). The same motivation to modify Montgomery in view of Gilbert, as applied in claim 1 above, applies here. Regarding claim 6, Montgomery as modified discloses wherein the first asset comprises a plurality of assets (Montgomery: paragraph (14), “While monitoring and controlling of the one or more assets (APP1, . . . , APPN), the AE engine 108 may track each asset, determine if/when each asset is out of compliance and perform remediation on each asset. For purposes of illustration, out of compliance means out of compliance from a computer security/malware/security threat standpoint,”). Regarding claim 7, Montgomery as modified discloses further comprising: receiving an indication of a recommended mitigation or remediation for the first vulnerable package (Montgomery: paragraphs (14-17)); and including, in the first notification, the recommended mitigation or remediation (Montgomery: paragraphs (14-17), “During the remediation, the AE engine 108 may perform several action as described below. Note that each of the actions of the AE engine 108 are performed automatically based on the distributed conda packages and compliance reports so that the AE engine 108 can automatically keep each asset in compliance and handle any compliance issues as described below. The disclosed system 100 shown in FIG. 1 integrates vulnerability information and tracking of assets to permit the remediation of out of compliance assets in various manners.”… “For example, user application 1 may be comprised of packages such as NumPy, scipy, scikit-learn and many others along with custom user code and each package may be an asset whose compliance is monitored and an asset that can be remediated in the package is out of compliance.”). Regarding claim 8, Montgomery as modified discloses further comprising, prior to including the recommended mitigation or remediation in the first notification, verifying the recommended mitigation or remediation for the first affected asset (Montgomery: paragraphs (24-25 and 30-31), “The AE 108B can then take down the application with the old version of NumPy, rebuild it with the new package, run automated tests to verify that the application works properly and then redeploy it automatically. In one embodiment, the method may use the distributed conda packages for the particular application to “re-solve” the packages to integrate the fix. For example, the user may use the open source conda command line tool infrastructure to “re-solve” the packages that enables a user to update all of the packages in an application to the latest version of all packages and rebundle the application for execution or distribution.”). Regarding claim 9, Montgomery as modified discloses further comprising: monitoring the first affected asset (Montgomery: paragraphs (22-25)); determining to manage the first vulnerable package (Montgomery: paragraphs (22-25)); and providing a second notification to the user of the first user account (Montgomery: paragraphs (22-25), “For each identified out of compliance application or cloud service, if it is determined that there is a fix for the out of compliance application/cloud service, the method may generate a new application that includes the fix (314). For example, in the AI model example below, the AI model may use the open source NumPy program and NumPy 1.16.0 (that is currently being used by the AI model) has a security vulnerability as described above. The system sends out a new version of NumPy (v1.16.2 for example) which fixes this CVE. The AE 108B can then take down the application with the old version of NumPy, rebuild it with the new package, run automated tests to verify that the application works properly and then redeploy it automatically. In one embodiment, the method may use the distributed conda packages for the particular application to “re-solve” the packages to integrate the fix. For example, the user may use the open source conda command line tool infrastructure to “re-solve” the packages that enables a user to update all of the packages in an application to the latest version of all packages and rebundle the application for execution or distribution”). Regarding claim 10, claim 10 discloses a method claim that is substantially equivalent to the method of claim 1. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 10 and rejected for the same reasons. Montgomery as modified further discloses monitoring and controlling of the one or more assets and packages (Montgomery: paragraphs (13-14, 2627 and 30), “Each enterprise site 108 may have an anaconda enterprise (AE) module 108B that is coupled to the store 108A and retrieves the distributed conda package(s) and the compliance reports... For example, the AE module 108B may be installed on and implemented using GPU-enabled nodes.. Each enterprise site 108 may also have one or more assets, such as applications or cloud services or packages, (APP1, . . . , APPN) that are monitored and controlled by the AE engine 108. The process and method described below works the same way for an application as for a cloud service.”… “The method processes 308-320 may be configured by an administrator to be automatic as soon as a new compliance data report is received. Alternatively, the processes 308-320 may be manually controlled by the admin or application owner. In another embodiment, the method may be configured to simply alert the application/cloud service owner and wait for the owner to provide instructions including fixing the application/cloud service and redeploying it as described above.”). Gilbert further discloses monitoring and identifying malware for more than one software packages (Gilbert: paragraphs (17, 30 and 96), “malware detection server 110 may maintain an index of data identifying software packages”… “software package index 510 may include a software package identifier (e.g., a cryptographic hash of an executable file), the software package's publisher, the software package's signature (e.g., authentication credentials), the software package's trust level, and/or any other suitable data. In some embodiments, the software package's trust level may depend, at least in part, on the reputation of the software package's provider (e.g., the website from which the software was downloaded), the reputation of the software package's publisher, the severity of any malware known to be included in the software package, the severity of any security vulnerabilities known to be associated with the software package, the date when the software package was first identified, the duration of the time period for which the software package has been available, the prevalence of the software package, and/or any other suitable information”). Regarding claim 11, claim 11 discloses a system claim that is substantially equivalent to the method of claims 1 and 2. Therefore, the arguments set forth above with respect to claims 1 and 2 are equally applicable to claim 11 and rejected for the same reasons. Regarding claim 16, Montgomery as modified discloses wherein the mitigation or remediation includes at least one of: recommended steps (Montgomery: paragraphs (22-24)); a link to a new version of the vulnerable package (Montgomery: paragraphs (22-24)); a link to a patch to the vulnerable package; or a link to a replacement package for the vulnerable package (Montgomery: paragraphs (22-24), “the Enterprise monitoring, scheduling and remediation engine 108C processes the compliance reports and conda packages to understand which projects and deployed applications have compliance issues (such as security vulnerabilities) and if there is a new package which fixes the compliance issue. When the system sends the compliance reports and conda packages to the enterprise customer, the Anaconda Enterprise system 108B can look at historic customer usage of any packages that are flagged in the new incoming compliance report. At that time, if a new conda package is available that fixes the issue, the system may update the application. The output would be audit logs and alerts to application owners of the changes made..”.. “The system sends out a new version of NumPy (v1.16.2 for example) which fixes this CVE. The AE 108B can then take down the application with the old version of NumPy, rebuild it with the new package, run automated tests to verify that the application works properly and then redeploy it automatically.”). Allowable Subject Matter Claims 17-20 are allowed. Claims 4-5 and 12-15 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: As to claims 4-5 and 12-15, none of the art of reference, discloses, individually or in reasonable combination, the features recited in claims 9-15 if written in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRANG T DOAN whose telephone number is (571)272-0740. The examiner can normally be reached Monday-Friday 7-4 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRANG T DOAN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Jan 08, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705389
MITIGATING PRIVATE DATA LEAKAGE IN A FEDERATED LEARNING SYSTEM
3y 8m to grant Granted Aug 11, 2026
Patent 12706738
SYSTEMS AND METHODS FOR DECENTRALIZED DATA DISTRIBUTION
1y 8m to grant Granted Aug 11, 2026
Patent 12699811
Computer-implemented method for the secure preparation of a property transfer document
4y 3m to grant Granted Aug 04, 2026
Patent 12683773
CONTROL DEVICE, QUANTUM CRYPTOGRAPHIC COMMUNICATION SYSTEM, CONTROL METHOD, AND COMPUTER PROGRAM PRODUCT
2y 10m to grant Granted Jul 14, 2026
Patent 12671996
UPGRADING CONTROL PLANE NETWORK FUNCTIONS WITH PROACTIVE ANOMALY DETECTION CAPABILITIES
2y 8m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+16.9%)
3y 4m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 630 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month