Prosecution Insights
Last updated: August 14, 2026
Application No. 19/020,943

SECURITY POSTURE DETECTION OF A CLOUD ENVIRONMENT

Non-Final OA §103
Filed
Jan 14, 2025
Priority
May 23, 2023 — IN 202311035748 +2 more
Examiner
JHAVERI, JAYESH M
Art Unit
2433
Tech Center
2400 — Computer Networks
Assignee
Proofpoint Inc.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
458 granted / 553 resolved
+24.8% vs TC avg
Strong +31% interview lift
Without
With
+31.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
10 currently pending
Career history
563
Total Applications
across all art units

Statute-Specific Performance

§101
11.3%
-28.7% vs TC avg
§103
44.1%
+4.1% vs TC avg
§102
20.4%
-19.6% vs TC avg
§112
13.6%
-26.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 553 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. DETAILED ACTION Claims 1-20 are pending in this office action. Priority Foreign priority claimed to IN202311035748, filed 05/23/2023. Information Disclosure Statement The information disclosure statements (IDS's) submitted on 08/18/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 6-7, 14-16, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Sobrier et al. (US 12,563,060 B1, Sobrier hereinafter). For claim 1, Newman teaches a computer-implemented method of detecting security posture of a cloud environment (Abstract; para 0006, 0066), the method comprising: detecting a triggering criterion (para 0047, 0023, 0049, 0052 - one or more new databases detected based on new network and new account in the cloud or based on policy associated with discovering of databases, wherein the databases are discovered to be already inventoried or new); in response to the triggering criterion, automatically discovering a plurality of databases in the cloud environment (para 0047-0049, 0052 - one or more new databases detected based on new network and new account in the cloud); deploying a log analyzer microservice on the plurality of databases, each log analyzer microservice, being configured to scan a respective database log that represents database activities on a respective database of the plurality of databases (para 0027-0028, 0038, 0055 - activity data in logs maintained by each of the plurality of databases are monitored or analyzed by service of monitoring proxy); and receiving analysis results from the log analyzer microservice (para 0023, 0030, 0033, 0037-0038, 0042, 0047, 0049, 0052 - result data generation or extraction as logs or audit data, analysis and security result data of database activities based on new network and new account in the cloud or based on policy associated with discovering of databases). Although Newman discloses deploying proxy process as a lightweight service similar to microservice, which may be extended into provisioning of multiple instances of such processes or services as an obvious extension well-known in the art, Newman does not explicitly teach, however Sobrier teaches deploying a plurality of analyzer microservices, receiving analysis results from the plurality of analyzer microservices (col. 4 lines 14-17; col. 16 lines13-22; col. 16 lines 48-54; col. 17 lines 15-22; col. 26 lines 58-62 - microservices for variety of tasks, including data collection and analysis similar to logs or audit analysis and results). Based on Newman in view of Sobrier, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Sobrier in the system of Newman, in order to deploy multiple instances of services or microservices as a lightweight entity implementation thereby improving system’s data logging capabilities in an efficient way to improve system’s features of data analysis and anomaly detection, and making system more secure. For claim 2, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Newman further discloses further comprising: receiving a request to on-board a cloud account in the cloud environment, wherein the cloud account includes the plurality of databases, each respective database, of the plurality of databases, including a database log generator configured to generate the respective database log that represents the database activities on the respective database; and detecting the triggering criterion based on the on-boarding of the cloud account (para 0023, 0030, 0033, 0037-0038, 0042, 0047, 0049, 0052 - result data generation or extraction as logs or audit data, analysis and security result data of database activities based on new network and new account in the cloud or based on policy associated with discovering of databases). For claim 3, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Newman further discloses wherein the respective database log comprises at least one of an audit log or a transaction log (para 0030, 0037-0038, 0047, 0080 - activity data generation into logs or audit data). For claim 6, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Although Newman discloses issues such as malicious query detection (para 0031) potentially leading to data access violations, problem identification and remediation for prevention and correction is part and partial of any data security initiative is widely well-known in the art, Newman does not appear to explicitly disclose, however Sobrier discloses detecting at least one database issue based on the at least one of a performance criterion or a security criterion, wherein generating the action signal comprises controlling a remedial action component to perform a remedial action relative to the database issue (col. 4 lines 4-17; col. 5 lines 44-50). Based on Newman in view of Sobrier, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Sobrier in the system of Newman, in order to utilize database issue mitigation and remediation which is very well-known in database security, thereby securing database system for further prevention of issues thereby improving secure data availability. For claim 7, Newman in view of Sobrier teaches the claimed subject matter as discussed above in the method of claim 6. Newman further discloses wherein the at least one database issue comprises a malicious query (para 0005, 0031). For claim 14, Newman teaches a computing system, comprising: at least one processor; and memory storing instructions executable by the at least one processor, wherein the instructions, (Fig. 1-2; Abstract; para 0006-0007, 0019-0021, 0066), when executed, cause the computing system to: detect a triggering criterion (para 0047, 0023, 0049, 0052 - one or more new databases detected based on new network and new account in the cloud or based on policy associated with discovering of databases, wherein the databases are discovered to be already inventoried or new); in response to the triggering criterion, automatically discover a plurality of databases in the cloud environment (para 0047-0049, 0052 - one or more new databases detected based on new network and new account in the cloud); configure an orchestration engine to deploy a log analyzer microservice on the plurality of databases, each log analyzer microservice, being configured to scan a respective database log that represents database activities on a respective database of the plurality of databases (para 0027-0028, 0038, 0055 - activity data in logs maintained by each of the plurality of databases are monitored or analyzed by service of monitoring proxy); and receive analysis results from the log analyzer microservice (para 0023, 0030, 0033, 0037-0038, 0042, 0047, 0049, 0052 - result data generation or extraction as logs or audit data, analysis and security result data of database activities based on new network and new account in the cloud or based on policy associated with discovering of databases). Although Newman discloses deploying proxy process as a lightweight service similar to microservice, which may be extended into provisioning of multiple instances of such processes or services as an obvious extension well-known in the art, Newman does not explicitly teach, however Sobrier teaches deploying a plurality of analyzer microservices, receiving analysis results from the plurality of analyzer microservices (col. 4 lines 14-17; col. 16 lines13-22; col. 16 lines 48-54; col. 17 lines 15-22; col. 26 lines 58-62 - microservices for variety of tasks, including data collection and analysis similar to logs or audit analysis and results). Based on Newman in view of Sobrier, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Sobrier in the system of Newman, in order to deploy multiple instances of services or microservices as a lightweight entity implementation thereby improving system’s data logging capabilities in an efficient way to improve system’s features of data analysis and anomaly detection, and making system more secure. For claim 15, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Newman further discloses further comprising instructions, when executed, further cause the computing system to: receive a request to on-board a cloud account in the cloud environment, wherein the cloud account includes the plurality of databases, each respective database, of the plurality of databases, including a database log generator configured to generate the respective database log that represents the database activities on the respective database; and detect the triggering criterion based on the on-boarding of the cloud account (para 0023, 0030, 0033, 0037-0038, 0042, 0047, 0049, 0052 - result data generation or extraction as logs or audit data, analysis and security result data of database activities based on new network and new account in the cloud or based on policy associated with discovering of databases). For claim 16, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Newman further discloses wherein the respective database log comprises at least one of an audit log or a transaction log (para 0030, 0037-0038, 0047, 0080 - activity data generation into logs or audit data). For claim 19, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Although Newman discloses issues such as malicious query detection (para 0031) potentially leading to data access violations, problem identification and remediation for prevention and correction is part and partial of any data security initiative is widely well-known in the art, Newman does not appear to explicitly disclose, however Sobrier discloses detecting at least one database issue based on the at least one of a performance criterion or a security criterion, wherein generating the action signal comprises controlling a remedial action component to perform a remedial action relative to the database issue (col. 4 lines 4-17; col. 5 lines 44-50). Based on Newman in view of Sobrier, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Sobrier in the system of Newman, in order to utilize database issue mitigation and remediation which is very well-known in database security, thereby securing database system for further prevention of issues thereby improving secure data availability. For claim 20, Newman in view of Sobrier teaches the claimed subject matter as discussed above in the system of claim 19. Newman further discloses wherein the at least one database issue comprises a malicious query (para 0005, 0031). Claims 4-5, 8, 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Sobrier et al. (US 12,563,060 B1, Sobrier hereinafter), and further in view of Royal et al. (US 2024/0126607 A1, Royal hereinafter). For claim 4, Newman in view of Sobrier teaches the claimed subject matter as discussed above in the method of claim 3. Newman in view of Sobrier do not appear to explicitly disclose, however Royal discloses wherein the respective database log comprises a slow query log that records details of queries that take more than a threshold amount of time to execute on the respective database (para 0013, 0035-0040, 0054, 0069, 0137; Fig. 4D - query response time as workload or performance characteristic which is triggered due to slower queries or longer response time which are first logged or recorded pertaining to execution metrics that are more than threshold amount). Based on Newman in view of Sobrier and Royal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Royal in the system of Newman in view of Sobrier, in order to utilize database logging and analysis processes which are very well-known in the database query security, performance and optimization, thereby incorporating proactive anomaly detection for sensitive databases and thus securing the database system. For claim 5, Newman in view of Sobrier and Royal teaches the claimed subject matter as discussed above in the method of claim 4. Newman further discloses wherein each log analyzer microservice is configured to analyze the respective database log based on one or more of: a query execution time, a sensitive data profile wherein each log analyzer microservice is configured to analyze the respective database log based on one or more of: a query execution time, a sensitive data profile, a user permission associated with a data access request in the respective database, or a time series pattern of queries representing at least one of a query count, a query type, or a query user (para 0004, 0051). Additionally (although not a required claim limitation), Newman in view of Sobrier do not appear to explicitly disclose, however Royal discloses wherein each log analyzer microservice is configured to analyze the respective database log based on a query execution time (Fig. 4D; para 0013, 0035-0040, 0054, 0069 - query execution response time as workload or performance characteristic). For claim 8, Newman in view of Sobrier teaches the claimed subject matter as discussed above in the method of claim 7. Newman in view of Sobrier do not appear to explicitly disclose, however Royal discloses wherein the malicious query comprises a query to sensitive data that is executed more than a threshold number of times (para 0013, 0035-0040, 0054, 0069, 0137; Fig. 4D - number of queries or transactions as workload or performance characteristic, which are first logged or recorded pertaining to execution metrics that are more than threshold amount). Based on Newman in view of Sobrier and Royal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Royal in the system of Newman in view of Sobrier, in order to utilize various database access and response metrics which are very well-known in the database query security, performance and optimization, thereby incorporating proactive anomaly detection for sensitive databases and thus securing the database system. For claim 17, Newman in view of Sobrier teaches the claimed subject matter as discussed above in the system of claim 16. Newman in view of Sobrier do not appear to explicitly disclose, however Royal discloses wherein the respective database log comprises a slow query log that records details of queries that take more than a threshold amount of time to execute on the respective database (para 0013, 0035-0040, 0054, 0069, 0137; Fig. 4D - query response time as workload or performance characteristic which is triggered due to slower queries or longer response time which are first logged or recorded pertaining to execution metrics that are more than threshold amount). Based on Newman in view of Sobrier and Royal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Royal in the system of Newman in view of Sobrier, in order to utilize database logging and analysis processes which are very well-known in the database query security, performance and optimization, thereby incorporating proactive anomaly detection for sensitive databases and thus securing the database system. For claim 18, Newman in view of Sobrier and Royal teaches the claimed subject matter as discussed above in the system of claim 17. Newman further discloses wherein each log analyzer microservice is configured to analyze the respective database log based on one or more of: a query execution time, a sensitive data profile, a user permission associated with a data access request in the respective database, or a time series pattern of queries representing at least one of a query count, a query type, or a query user (para 0004, 0051). Additionally (although not a required claim limitation), Newman in view of Sobrier do not appear to explicitly disclose, however Royal discloses wherein each log analyzer microservice is configured to analyze the respective database log based on a query execution time (Fig. 4D; para 0013, 0035-0040, 0054, 0069 - query execution response time as workload or performance characteristic). Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Sobrier et al. (US 12,563,060 B1, Sobrier hereinafter), and further in view of Jha et al. (US 2024/0020391 A1, Jha hereinafter). For claim 9, Newman in view of Sobrier teaches the claimed subject matter as discussed above. Newman in view of Sobrier do not appear to explicitly disclose, however Jha discloses determining that the database activities match a pre-defined risk signature (Fig. 4B, 4C; para 0019, 0023, 0035-0038 - vulnerability or risk signature associated with various activities related to database and other system access violations). Based on Newman in view of Sobrier and Jha, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Jha in the system of Newman in view of Sobrier, in order to utilize well-known security elements such as signatures as identification means for determining risk factors associated with various system activities, thereby securing system components. Claim 10, 12 are rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Jha et al. (US 2024/0020391 A1, Jha hereinafter). For claim 10, Newman teaches a computer-implemented method of detecting security posture of a cloud environment (Abstract; para 0006, 0066), the method comprising: receiving a request to analyze a database in a cloud environment; parsing a database query log corresponding to the database to obtain a parser result, wherein the database query log includes a set of log entries representing database queries on the respective database (para 0008, 0027-0028, 0038, 0049, 0055 - monitoring proxy is requested to be instantiated for analyzing activity data in logs maintained by each of the plurality of databases are monitored or analyzed by service of monitoring proxy, wherein the logs are analyzed and parsed or checked for further determinations based on queries), and each log entry of the set of log entries identifies a requestor and a target dataset on the database (para 0023, 0047-0049, 0052, 0062, 0064, 0077 - one or more new databases detected based on new network and new account in the cloud, wherein one or more new databases and the respective datasets accessed by the requesting user); and generating an analysis result representing the one or more query instance and generating an output representing the analysis results (para 0023, 0030, 0033, 0037-0038, 0042, 0047, 0049, 0052 - result data generation or extraction as logs or audit data, analysis and security result data of database activities based on new network and new account in the cloud or based on policy associated with discovering of databases). Newman does not appear to explicitly disclose, however Jha discloses based on parsing the database query log, identifying one or more query instance that match a pre-defined risk signature; generating an analysis result representing the one or more query instance that match the pre-defined risk signature; and generating an output of analysis (Fig. 4B, 4C; para 0019, 0023, 0035-0038, 0060, 0063 - determining and outputting vulnerability or risk signature associated with various activities related to database including queries and other system access violations based on log parsing). Based on Newman in view of Jha, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Jha in the system of Newman, in order to utilize well-known security elements such as signatures as identification means for determining risk factors associated with various system activities, thereby securing system components. For claim 12, Newman in view of Jha teaches the claimed subject matter as discussed above. Newman further discloses analyzing the respective database log based on a sensitive data profile (para 0004, 0051). Newman does not appear to explicitly disclose, however Jha discloses wherein the pre-defined risk signature comprises one or more of: a query execution time, a sensitive data profile, or a user permission associated with a data access in the respective database (Fig. 4B, 4C; para 0019, 0035-0038, 0045-0046, 0060, 0063, 0073 - determining and outputting vulnerability or risk signature associated with various activities related to database including queries and other system access violations, wherein the signature is associated with request execution time, data access including permission for unrestricted access). Based on Newman in view of Jha, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Jha in the system of Newman, in order to utilize well-known security elements such as signatures as identification means for determining risk factors associated with various system activities such as data access, thereby securing system components. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Jha et al. (US 2024/0020391 A1, Jha hereinafter), and further in view of Royal et al. (US 2024/0126607 A1, Royal hereinafter). For claim 11, Newman in view of Jha teaches the claimed subject matter as discussed above. Newman does not appear to explicitly disclose, however Jha discloses the pre-defined risk signature (Fig. 4B, 4C; para 0019, 0023, 0035-0038, 0060, 0063 - determining and outputting vulnerability or risk signature associated with various activities related to database including queries and other system access violations based on log parsing). Newman in view of Jha do not appear to explicitly disclose, however Royal discloses wherein the pre-defined risk signature defines a threshold level of access attempts of sensitive data by a particular requestor (para 0013, 0026, 0035-0040, 0054, 0069, 0137; Fig. 4D - number of queries or transactions as workload or performance characteristic, which are first logged or recorded pertaining to execution metrics considering operations such as restricted data access that are more than threshold amount). Based on Newman in view of Jha and Royal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Royal in the system of Newman in view of Jha, in order to utilize well-known security elements such as signatures as identification means for determining risk factors associated with various system activities, and to utilize various database access and response metrics which are very well-known in the database query security, performance and optimization, thereby incorporating proactive anomaly detection for sensitive databases and thus securing the database system. Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Newman et al. (US 2022/0239681 A1, Newman hereinafter), in view of Jha et al. (US 2024/0020391 A1, Jha hereinafter), and further in view of Sobrier et al. (US 12,563,060 B1, Sobrier hereinafter). For claim 13, Newman in view of Jha teaches the claimed subject matter as discussed above. Although Newman discloses issues such as malicious query detection (para 0031) potentially leading to data access violations, problem identification and remediation for prevention and correction is part and partial of any data security initiative is widely well-known in the art, Newman and Jha do not appear to explicitly disclose, however Sobrier discloses detecting at least one database issue based on at least one of a performance criterion or a security criterion; and performing a remedial action relative to the database issue (col. 4 lines 4-17; col. 5 lines 44-50). Based on Newman in view of Jha and Sobrier, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Sobrier in the system of Newman and Jha, in order to utilize database issue mitigation and remediation which is very well-known in database security, thereby securing database system for further prevention of issues thereby improving secure data availability. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. (1) Dinerstein; Yosef - US-20180084007-A1 (performing a security action with regard to an access token); (2) Sreenivasan; Balakrishnan - US-20230018975-A1 (method for governing risk actions); (3) Mork; Peter - US-20110271146-A1 (client application requesting to access a resource based on access tokens); (4) Chang; Hyunseok - US-20210058424-A1 - are cited to show methods, computer program products and systems pertinent to database logging, problem detection and remediation. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAYESH JHAVERI whose telephone number is (571)270-7584. The examiner can normally be reached on Mon-Fri 9 AM to 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAYESH M JHAVERI/Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Jan 14, 2025
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689512
SIGNAL PROTECTION AND RETRIEVAL BY NON-LINEAR ANALOG MODULATION
1y 9m to grant Granted Jul 21, 2026
Patent 12682088
POLICY CONSISTENCY VERIFICATION APPARATUS, POLICY CONSISTENCY VERIFICATION METHOD, AND POLICY CONSISTENCY VERIFICATION PROGRAM
2y 6m to grant Granted Jul 14, 2026
Patent 12670255
GENERATION DEVICE, GENERATION METHOD, AND GENERATION PROGRAM
2y 1m to grant Granted Jun 30, 2026
Patent 12652282
EVENT BASED AUTHENTICATION
1y 7m to grant Granted Jun 09, 2026
Patent 12627653
SECURED DIRECT ACCESS FOR CUSTOMER SERVICE
2y 4m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+31.1%)
2y 5m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 553 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month