Prosecution Insights
Last updated: October 02, 2026
Application No. 19/015,125

METHOD FOR CONFIGURING A HONEYPOT

Final Rejection §102§103
Filed
Jan 09, 2025
Priority
Jan 12, 2024 — EU 24 15 1625.1
Examiner
MAYE, AYUB A
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Robert Bosch GmbH
OA Round
2 (Final)
58%
Grant Probability
Moderate
3-4
OA Rounds
2y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
384 granted / 664 resolved
At TC average
Strong +41% interview lift
Without
With
+41.4%
Interview Lift
resolved cases with interview
Typical timeline
4y 6m
Avg Prosecution
22 currently pending
Career history
696
Total Applications
across all art units

Statute-Specific Performance

§101
3.0%
-37.0% vs TC avg
§103
59.5%
+19.5% vs TC avg
§102
16.3%
-23.7% vs TC avg
§112
14.3%
-25.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 664 resolved cases

Office Action

§102 §103
CTNF 19/015,125 CTNF 84351 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claims 1-9 are cancelled and new claims 10-17 have been examined. 07-30-03-h AIA Claim Interpretation 07-30-03 AIA The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 07-30-06 This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “device configured to” in claim 16. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 102 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-07-aia AIA 07-07 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – 07-12-aia AIA (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. 07-15-03-aia AIA Claim (s) 10-11, and 14-17 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by McGrew et al (2024/0333765) . For 10 , McGrew teaches method for configuring a honeypot ( abstract ), comprising the following steps: implementing a honeypot ( McGrew teaches of generated honeypot schemes as McGrew teaches in par.20 ); conducting at least one attack on the honeypot using a large language model ( attack vector generator 222 converts the subgraph 220 of detected malware identified during penetration testing into a plurality of attack vectors utilization of Large Language Model (LLM)-generated honeypot schemes that involve the creation of deceptive documents as McGrew teaches in par.42 and 75 ); ascertaining an assessment of the at least one attack ( McGrew teaches that continuously monitoring for interactions initiated by an interacting party with one or more components of the generated deceptive information, where the interaction is identified as a potential threat to the network as McGrew teaches in par.23 ); and configuring the honeypot depending on the assessment of the at least one attack ( McGrew teaches that in response to the detection of an interaction identified as the potential threat, the method further includes generating one or more remedial measures and policies for the network based on the extracted interaction data, enhancing network security as McGrew teaches in par.27 and 28-32, 78-81 ). For 11 , McGrew further teaches wherein, for ascertaining the assessment of the at least one attack, an assessment with regard to a number of interactions of the large language model with the honeypot takes place ( McGrew teaches that monitoring includes generating one or more contextual labels in accordance with contextual data related to the interactions to distinguish and identify threatening interactions from non-threatening interactions, and retraining the LLM with the one or more contextual labels improving an accuracy level of potential threat detection and effectiveness of the honeypots as McGrew teaches in par.29 and 31 ). For 14 , McGrew further teaches training or retraining the large language model based on examples of exploiting known vulnerabilities ( McGrew teaches that retraining the LLM with the one or more contextual labels improving an accuracy level of potential threat detection and effectiveness of the honeypots as McGrew teaches in par.29 ). For 15 , McGrew further teaches implementing the honeypot for each of a plurality of configurations ( McGrew teaches configuration generator 226 then generates a policy 228 for the prompt generator for implementing the honeypot as McGrew teaches in par.78 ); conducting, for each configuration, at least one attack on the honeypot using the large language model ( McGrew teaches of applying multiple attacks using the large language model as McGrew teaches in par.22-23 and 75 ); ascertaining an assessment of the at least one attack for each configuration; selecting a configuration of the honeypot from the plurality of configurations that provides a best assessment relative of assessments of the others of the plurality of configurations ( McGrew teaches that continuously monitoring for interactions initiated by an interacting party with one or more components of the generated deceptive information, where the interaction is identified as a potential threat to the network as McGrew teaches in par.23 ); and configuring the honeypot according to the selected configuration ( McGrew teaches that in response to the detection of an interaction identified as the potential threat, the method further includes generating one or more remedial measures and policies for the network based on the extracted interaction data, enhancing network security as McGrew teaches in par.27 and 28 ). For 16 , McGrew teaches A honeypot configuration device ( abstract) configured to configure a honeypot, the honeypot configuration device ( abstract ) ( par.23 ) configured to: implement a honeypot ( McGrew teaches of generated honeypot schemes as McGrew teaches in par.20 );; conduct at least one attack on the honeypot using a large language model ( attack vector generator 222 converts the subgraph 220 of detected malware identified during penetration testing into a plurality of attack vectors utilization of Large Language Model (LLM)-generated honeypot schemes that involve the creation of deceptive documents as McGrew teaches in par.42 and 75 ); ascertain an assessment of the at least one attack ( McGrew teaches that continuously monitoring for interactions initiated by an interacting party with one or more components of the generated deceptive information, where the interaction is identified as a potential threat to the network as McGrew teaches in par.23 ); and configure the honeypot depending on the assessment of the at least one attack ( McGrew teaches that in response to the detection of an interaction identified as the potential threat, the method further includes generating one or more remedial measures and policies for the network based on the extracted interaction data, enhancing network security as McGrew teaches in par.27 and 28-32, 78-81) . For 17 , McGrew teaches A non-transitory computer-readable medium on which are stored commands configuring a honeypot, the commands, when executed by a processor ( par.32 ), causing the processor to perform the following steps: implementing a honeypot ( McGrew teaches of generated honeypot schemes as McGrew teaches in par.20 ); conducting at least one attack on the honeypot using a large language model ( attack vector generator 222 converts the subgraph 220 of detected malware identified during penetration testing into a plurality of attack vectors utilization of Large Language Model (LLM)-generated honeypot schemes that involve the creation of deceptive documents as McGrew teaches in par.42 and 75 ); ascertaining an assessment of the at least one attack ( McGrew teaches that continuously monitoring for interactions initiated by an interacting party with one or more components of the generated deceptive information, where the interaction is identified as a potential threat to the network as McGrew teaches in par.23 ); and configuring the honeypot depending on the assessment of the at least one attack ( McGrew teaches that in response to the detection of an interaction identified as the potential threat, the method further includes generating one or more remedial measures and policies for the network based on the extracted interaction data, enhancing network security as McGrew teaches in par.27 and 28-32, 78-81) . Claim Rejections - 35 USC § 103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-23-aia AIA The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 07-21-aia AIA Claim (s) 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over McGrew et al (2024/0333765) in views of Lu et al (CN 116886446) . McGrew teaches all the limitations as previously set forth except for wherein the configuring of the honeypot depending on the assessment of the at least one attack includes ascertaining whether the assessment of the at least one attack is above a specified threshold value and, in response to the assessment of the at least one attack not being above the specified threshold value, changing a behavior of the honeypot to a state in which the honeypot was when the large language model no longer made progress on the attack. Lu teaches that wherein the configuring of the honeypot depending on the assessment of the at least one attack includes ascertaining whether the assessment of the at least one attack is above a specified threshold value and, in response to the assessment of the at least one attack not being above the specified threshold value, changing a behavior of the honeypot to a state in which the honeypot was when the large language model no longer made progress on the attack (Lu teaches detection behaviour of the target large language model triggered by the access operation of the target client in the target time window that the target large language model will be triggered when the access frequency of the same client exceeds the set access frequency threshold and under the condition that the access frequency threshold is not exceeded as Lu teaches in par.18). It would have been obvious to one ordinary skill in the art before effective filling date to modify McGrew to include specified threshold value as taught and suggested by Lu for the purpose of collecting the behavior characteristic parameter corresponding to each triggered preset detection behavior; obtaining all target interaction data between the target client and the target large language model in the target time window and determining whether the target client is performing the automatic attack (Lu, abstract) . 07-21-aia AIA Claim (s) 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over McGrew et al (2024/0333765) in views of Kawasaki et al (2018/0375897) . McGrew teaches all the limitations as previously set forth and McGrew further teaches that wherein the conducting the at least one attack on the honeypot includes generating, by the large language model (McGrew teaches in par.22-23). However, McGrew fails to teach that at least one input for a command line interface that the honeypot simulates, and feeding the at least one generated input into the simulated command line interface. Kawasaki teaches at least one input for a command line interface that the honeypot simulates, and feeding the at least one generated input into the simulated command line interface (Kawasaki teaches honey pots responding to commands and the commands are entered via interface as Kawasaki teaches in par.16-17, 20 and 32). It would have been obvious to one ordinary skill in the art before effective filling date to modify McGrew to include command line interface as taught and suggested by Kawasaki for the purpose of spares the valuable assets, and the honeypots may be monitored for attacks, so that computer and network administrators may be alerted of attacks in progress (Kawasaki, par.16) . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See prior arts cited in PTO 892 . Any inquiry concerning this communication or earlier communications from the examiner should be directed to AYUB A MAYE whose telephone number is (571)270-5037. The examiner can normally be reached Monday-Friday 9AM-5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AYUB A MAYE/Examiner, Art Unit 2436 /SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436 Application/Control Number: 19/015,125 Page 2 Art Unit: 2436 Application/Control Number: 19/015,125 Page 3 Art Unit: 2436 Application/Control Number: 19/015,125 Page 4 Art Unit: 2436 Application/Control Number: 19/015,125 Page 5 Art Unit: 2436 Application/Control Number: 19/015,125 Page 6 Art Unit: 2436 Application/Control Number: 19/015,125 Page 7 Art Unit: 2436 Application/Control Number: 19/015,125 Page 8 Art Unit: 2436 Application/Control Number: 19/015,125 Page 9 Art Unit: 2436 Application/Control Number: 19/015,125 Page 10 Art Unit: 2436
Read full office action

Prosecution Timeline

Jan 09, 2025
Application Filed
Apr 13, 2026
Non-Final Rejection mailed — §102, §103
Jul 09, 2026
Response Filed
Sep 29, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12665876
System and method for server monitoring and problem resolution for electronic mail messages
3y 8m to grant Granted Jun 23, 2026
Patent 12625987
METHOD AND SYSTEM FOR EXECUTING A SECURE FILE-LEVEL RESTORE FROM A BLOCK-BASED BACKUP
3y 9m to grant Granted May 12, 2026
Patent 12574211
PERSONAL PRIVATE KEY ENCRYPTION DEVICE
3y 10m to grant Granted Mar 10, 2026
Patent 12574247
DEVICE FOR COMPUTING SOLUTIONS OF LINEAR SYSTEMS AND ITS APPLICATION TO DIGITAL SIGNATURE GENERATIONS
3y 4m to grant Granted Mar 10, 2026
Patent 12547740
INFORMATION PROCESSING DEVICES AND INFORMATION PROCESSING METHODS
3y 2m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
58%
Grant Probability
99%
With Interview (+41.4%)
4y 6m (~2y 9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 664 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month