Prosecution Insights
Last updated: October 01, 2026
Application No. 19/048,924

SYSTEMS AND METHODS FOR ANALYZING CHATBOT COMMUNICATION SESSIONS TO REDUCE ESCALATION

Non-Final OA §103§DOUBLEPATENT
Filed
Feb 09, 2025
Priority
Nov 24, 2021 — continuation of 12/224,968
Examiner
HUSSAIN, IMAD
Art Unit
Tech Center
Assignee
Verizon Communications Inc.
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
489 granted / 597 resolved
+21.9% vs TC avg
Strong +16% interview lift
Without
With
+15.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
15 currently pending
Career history
605
Total Applications
across all art units

Statute-Specific Performance

§101
15.5%
-24.5% vs TC avg
§103
48.5%
+8.5% vs TC avg
§102
16.4%
-23.6% vs TC avg
§112
10.6%
-29.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 597 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Application 19/048,924 is a continuation of Application 17/456,386 (now US Patent 12,224,968 B2), originally filed 11/24/2021. Claims 1-20 are currently pending in Application 19/048,924. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,224,968 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the patent claims anticipate the pending claims (i.e., the limitations of the pending claims are disclosed by the patent claims, although not necessarily using the same phrasing). See also the table below. US Patent 12,224,968 B2 Pending Application Claims 1. A method performed by a device, the method comprising: receiving session data of a communication session between an artificial intelligence (AI) communication device and a first user device; analyzing the session data to determine one or more portions of the session data; identifying a portion, of the one or more portions, for processing based on one or more criteria associated with the portion, wherein the portion includes a plurality of entries including communications from the first user device and communications from the AI communication device; analyzing the plurality of entries to identify an entry including information regarding an escalation, wherein the escalation indicates that the first user device has been connected to a second user device; analyzing one or more additional entries of the plurality of entries, in a reverse chronological order, to determine a category associated with a cause of the escalation, wherein analyzing the one or more additional entries comprises: analyzing a first next entry. preceding the entry, when the first next entry includes a first communication from the first user device and a second communication from the Al communication device and identifying a second next entry, preceding the first next entry, when the first next entry does not include the first communication and the second communication; and causing the AI communication device to be configured to address the cause of the escalation based on information regarding the one or more additional entries and information identifying the category. 2. The method of claim 1, wherein the AI communication device executes a chatbot, wherein receiving the session data comprises: receiving messages exchanged between the chatbot and the first user device, wherein the plurality of entries includes a subset of messages of the messages exchanged between the chatbot and the first user device, and wherein analyzing the plurality of entries comprises: analyzing the subset of messages to identify a message including the information indicating the escalation. 3. The method of claim 1, wherein the entry and the one or more additional entries are provided in a chronological order in the session data, wherein the one or more additional entries are provided prior to the entry, and wherein analyzing the one or more additional entries includes: analyzing the one or more additional entries in the reverse chronological order to determine the category associated with the cause of the escalation. 4. The method of claim 3, wherein the one or more criteria include a topic, wherein the first communication includes a request that includes information associated with the topic, wherein the second communication includes a response that includes information indicating that the AI communication device has identified a plurality of possible responses to the request, and wherein analyzing the one or more additional entries comprises determining the category based on the information associated with the topic. 5. The method of claim 1, wherein the portion is a first portion and the one or more criteria include a first topic, wherein identifying the portion for processing comprises: determining that the first topic is a subtopic of a second topic associated with a second portion of the one or more portions; and identifying the portion for processing based on determining that the first topic is a subtopic of the second topic. 6. The method of claim 1, wherein analyzing the session data comprises: analyzing the session data to identify at least one of: a period of time between a communication from the first user device and a communication from the AI communication device, a request to communicate with the second user device, or an indication of a graphical user interface being provided to the first user device after a threshold amount of time following initiation of the communication session. 7. The method of claim 1, wherein identifying the portion for processing comprises: identifying the portion based on the portion including: information indicating that the first user device has been connected to the second user device, information indicating that the first user device has provided a request to be connected to the second user device, or information indicating that the AI communication device has provided a suggestion, to the first user device, indicating that the first user device is to be connected to the second user device. 8. A device, comprising: one or more processors configured to: receive session data regarding a communication session that includes a plurality of messages exchanged between a chatbot and a first user device; identify a portion of the session data, of one or more portions of the session data, for processing based on one or more criteria associated with the portion of the session data, wherein the portion of the session data includes a plurality of entries including messages from the first user device and messages from the chatbot; analyze the plurality of entries to identify a particular entry including escalation information regarding an escalation, wherein the escalation information indicates that the first user device has been connected to a second user device; analyze one or more additional entries, in a reverse chronological order, to determine a cause of the escalation, wherein, to analyze the one or more additional entries, the one or more processors are to: analyze a first next entry, preceding the particular entry, when the first next entry includes a first message from the first user device and a second message from the chatbot, and identify a second next entry, preceding the first next entry, when the first next entry does not include the first message and the second message; and cause the chatbot to be trained to address the cause and prevent another escalation, associated with the cause, during a subsequent communication session involving the chatbot, wherein the chatbot is trained based on first information regarding the cause and second information regarding one of the first next entry of the second next entry of the one or more additional entries. 9. The device of claim 8, wherein the one or more processors, to receive the session data regarding the communication session, are configured to: receive a transcript of the communication session, and wherein, prior to identifying the portion of the session data, the one or more processors are further configured to: perform data processing on the transcript of the communication session to at least one of: remove one or more characters, or identify a beginning of the communication session and an ending of the communication session. 10. The device of claim 8, wherein the portion of the session data is a first portion of the session data, and wherein the one or more processors, to identify the portion of the session data, are configured to: analyze the first portion of the session data, using a natural language processing technique, to determine a first topic associated with the first portion of the session data; analyze a second portion of the session data, of the one or more portions of the session data, using the natural language processing technique, to determine a second topic associated with the second portion of the session data; determine a first priority associated with the first topic and a second priority associated with the second topic; and identify the first portion of the session data for processing based on determining the first priority and the second priority. 11. The device of claim 10, wherein the one or more processors, to identify the first portion of the session data, are configured to: determine that the first priority is higher than the second priority; and identify the first portion of the session data for processing based on determining that the first priority exceeds the second priority. 12. The device of claim 8, wherein the first-particular entry and the one or more additional entries are provided in a chronological order in the session data, wherein the one or more additional entries are provided prior to the particular entry, wherein the one or more processors, to analyze the one or more additional entries to determine the cause of the escalation, are configured to: analyze the one or more additional entries, in the reverse chronological order, to determine the cause of the escalation after identifying the particular entry. 13. The device of claim 8, wherein the one or more processors, to analyze the one or more additional entries, are configured to: analyze the one of the first next entry of the second next entry based on determining that the one of the first next entry or the second next entry includes the first message from the first user device and the second message from the chatbot, wherein the chatbot is trained based on a machine learning model, used by the chatbot being trained to determine responses to request messages that caused escalations, and wherein the machine learning model is trained using historical data that includes the first message. 14. The device of claim 8, wherein the one or more criteria include at least one of a topic or a period of time; wherein the one or more processors are further configured to: receive information identifying the topic; and wherein the one or more processors, to identify the portion of the session data, are configured to: analyze the portion of the session data, using a natural language processing technique, to determine that the portion of the session data is associated with the topic. 15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to: receive session data regarding a communication session that includes a plurality of messages exchanged between a chatbot and a first user device; identify a portion of the session data, of one or more portions of the session data, for processing based on one or more criteria associated with the portion of the session data, wherein the portion of the session data includes a plurality of entries including messages from the first user device and messages from the chatbot; analyze the plurality of entries to identify an entry including escalation information regarding an escalation, wherein the escalation indicates that the first user device has been connected to a second user device; analyze one or more additional entries, of the plurality of entries, to determine a cause of the escalation, wherein the one or more additional entries are analyzed in a reverse chronological order, wherein the one or more instructions to analyze the one or more additional entries comprise one or more instructions to: analyze a first next entry, preceding the entry, when the first next entry includes a first message from the first user device and a second message from the chatbot, and identify a second next entry, preceding the first next entry, when the first next entry does not include the first message and the second message; and cause the chatbot to be trained to address the cause during a subsequent communication session involving the chatbot, wherein the chatbot is trained based on information identifying the one or more additional entries and information regarding the cause of the escalation. 16. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry does not include the first message and the second message; and analyze the second next entry based on determining that the second next entry includes the first message device and the second message. 17. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: obtain one or more rules associated with identifying information regarding causes of escalations; and analyze the one or more additional entries to determine the cause of the escalation based on the one or more rules. 18. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to: analyze the session data to identify at least one of: a period of time between a communication from the first user device and a communication from the chatbot, a request to communicate with the second user device, or an indication of a graphical user interface being provided to the first user device after a threshold amount of time following initiation of the communication session; and identify the one or more portions of the session data based on analyzing the session data. 19. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the plurality of entries, cause the device to: identify the entry based on the entry including: information indicating that the first user device has been connected to the second user device, information indicating that the first user device has provided a request to be connected to the second user device, or information indicating that the chatbot has provided a suggestion, to the first user device, indicating that the first user device is to be connected to the second user device. 20. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to: receive a transcript of the communication session, and perform data processing on the transcript of the communication session to at least one of: remove one or more words or one or more characters, or identify a beginning of the communication session and an ending of the communication session. 1. A method performed by a device, the method comprising: identifying an entry, of a plurality of entries, that includes information regarding an escalation during communications between two devices; analyzing one or more additional entries of the plurality of entries to determine a cause of the escalation, wherein analyzing the one or more additional entries comprises: analyzing a first next entry preceding the entry, or analyzing a second next entry preceding the first next entry; and causing one of the two devices to be configured to address the cause of the escalation based on information regarding the one or more additional entries. 2. The method of claim 1, further comprising: receiving session data regarding the communications; pre-processing the session data to remove information that does not provide insight with respect to determining the cause of the escalation; and identifying the entry, in the session data, after pre-processing the session data. 3. The method of claim 2, further comprising: analyzing the session data to identify a period of time between a communication from a first device of the two devices and a communication from a second device of the two devices; and identifying a first portion of the session data and a second portion of the session data based on the period of time, wherein the one or more additional entries are included in one of the first portion or the second portion. 4. The method of claim 2, further comprising: determining a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data; determining that the first priority exceeds the second priority; and analyzing the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries. 5. The method of claim 1, wherein analyzing the one or more additional entries comprises: analyzing the first next entry when the first next entry includes a request and one or more responses to the request; and identifying the second next entry when the first next entry does not include the request and the one or more responses. 6. The method of claim 1, wherein analyzing the one or more additional entries comprises: obtaining one or more rules, wherein the one or more rules indicate that: the one or more additional entries are to be analyzed in a reverse chronological order, and entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed; and analyzing the one or more additional entries based on the one or more rules. 7. The method of claim 1, wherein causing the one of the two devices to be configured to address the cause of the escalation comprises: determining a response to a request that caused the escalation; and causing the one of the two devices to be configured to address the cause of the escalation based on the response. 8. A device, comprising: one or more processors configured to: identify an entry, of a plurality of entries, that includes information regarding an escalation, wherein the plurality of entries includes communications between two devices; analyze one or more additional entries of the plurality of entries to determine a cause of the escalation, wherein, to analyze the one or more additional entries, the one or more processors are configured to: analyze a first next entry preceding the entry or analyze a second next entry preceding the first next entry; and cause a particular device of the two devices to be configured to address the cause of the escalation based on information regarding the one or more additional entries. 9. The device of claim 8, wherein the one or more processors are further configured to: determine a category associated with the cause of the escalation based on information included in a communication that caused the escalation; and cause the particular device to be configured to address the cause of the escalation based on information identifying the category. 10. The device of claim 8, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant. 11. The device of claim 8, wherein, to analyze the one or more additional entries, the one or more processors are configured to: obtain one or more rules, wherein the one or more rules indicate that: the one or more additional entries are to be analyzed in a reverse chronological order, entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed, or a particular entry that is nearest to the entry is an entry that includes information regarding the cause of the escalation; and analyze the one or more additional entries based on the one or more rules. 12. The device of claim 8, wherein the one or more processors, to analyze the one or more additional entries, are configured to: analyze the first next entry when the first next entry includes a request and one or more responses to the request; and identify the second next entry when the first next entry does not include the request and the one or more responses to the request. 13. The device of claim 8, wherein the particular device includes a communication device and another device of the two devices includes a first user device, and wherein the one or more processors identify the entry based on the entry including: information indicating that the first user device has been connected to a second user device, information indicating that the first user device has provided a request to be connected to the second user device, or information indicating that the communication device has provided a suggestion, to the first user device, indicating that the first user device is to be connected to the second user device. 14. The device of claim 8, wherein the one or more processors are further configured to: receive session data regarding the communications; pre-process the session data to remove information that does not provide insight with respect to determining the cause of the escalation; and identify the entry after pre-processing the session data. 15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device, cause the device to: identify an entry, of a plurality of entries, that includes information regarding an escalation during communications between two devices; analyze one or more additional entries of the plurality of entries to determine a cause of the escalation, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: analyze a first next entry preceding the entry, or analyze a second next entry preceding the first next entry; and cause a particular device of the two devices to be configured to address the cause of the escalation based on information regarding the one or more additional entries. 16. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry includes a request and one or more responses to the request; and analyze the first next entry based on determining that the first entry includes the request and the one or more responses. 17. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry does not include the request and one or more responses to the request; identify the second next entry based on determining that the first entry does not include the request and the one or more responses; and analyze the second next entry. 18. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to: receive session data regarding the communications; determine a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data; determine that the first priority exceeds the second priority; and analyze the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries. 19. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to determine a response to a request that caused the escalation; and cause the particular device to be configured to address the cause of the escalation based on the response. 20. The non-transitory computer-readable medium of claim 15, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Das (US 2022/0309250 A1) in view of Waghorn (US 2019/0081963 A1). Regarding claims 1, 8, and 15, Das discloses A method performed by a device (Das: Claim 9, “A method performed by one or more processing resources of one or more computer systems…”), the method comprising/A device comprising one or more processors (Das: Claim 1, “A system comprising: a processing resource…”) configured to/A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device (Das: Claim 12, “A non-transitory machine readable medium storing instructions, which when executed by a processing resource of a computer system…”), cause the device to: identify an entry, of a plurality of entries, that includes information regarding an escalation (Das: Paragraph [0034], “associated learning from escalated cases”, and Paragraph [0068], “information is extracted from a CRM application (e.g., CRM application 330). For example, statistical information may be obtained regarding the number of escalated product support cases due to unrecognized customer issues by a chatbot (e.g., chatbot 345), ongoing manual labeling of product support issues being performed by human agents (e.g., agents 301), for example, as a result of product support cases escalated from the chatbot (e.g., chatbot 345), and/or unsatisfactory issue resolution by the chatbot”), wherein the plurality of entries includes communications between two devices (Das: Paragraph [0068], “unsatisfactory issue resolution by the chatbot”; the chatbot runs on one device that communicates with the user/customer’s device); analyze one or more additional entries of the plurality of entries to determine a cause of the escalation (Das: Paragraph [0070], “At block 640, a retraining or refreshing of the classification models may be triggered. According to one embodiment, emerging product issue categories may be learned from the escalated cases by artificially boosting (e.g., disproportionately representing) the proportion of escalated cases in the training dataset”), and cause a particular device of the two devices to be configured to address the cause of the escalation based on information regarding the one or more additional entries (Das: Paragraph [0071], “it is determined whether a number of escalated cases due to the chatbot being unable to recognize customer issue descriptions exceeds a threshold. If so, processing branches to block 640; otherwise, processing continues with decision block 660. A relatively large number of customer issues being unrecognizable by the chatbot may be indicative of a need for retraining/refreshing the word association models for the product lines at issue. For example, the “other” category being among the top 3 to 7 of the total number of categories may be used as a trigger condition for retraining/refreshing the word association models for the product lines at issue”). Das does not explicitly disclose that to analyze the one or more additional entries, the one or more processors are configured to: analyze a first next entry preceding the entry or analyze a second next entry preceding the first next entry. However, Waghorn teaches that to analyze the one or more additional entries, the one or more processors are configured to: analyze a first next entry preceding the entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”) or analyze a second next entry preceding the first next entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”). Das and Waghorn are analogous art in the same field of endeavor as the instant invention as all are drawn to root cause analysis and resolution. The differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains; that is, it would have been obvious to incorporate Waghorn’s reverse node traversal into the system of Das to allow to pinpointing the exact, initial cause of the problem to be resolved. Das-Waghorn teaches 2. The method of claim 1, further comprising: receiving session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); pre-processing the session data to remove information that does not provide insight with respect to determining the cause of the escalation (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identifying the entry, in the session data, after pre-processing the session data (Waghorn: Paragraph [0085], “to determine a root cause of the beacon or trigger event”). Das-Waghorn teaches 3. The method of claim 2, further comprising: analyzing the session data to identify a period of time between a communication from a first device of the two devices and a communication from a second device of the two devices (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identifying a first portion of the session data and a second portion of the session data based on the period of time, wherein the one or more additional entries are included in one of the first portion or the second portion (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”). Das-Waghorn teaches 4. The method of claim 2, further comprising: determining a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); determining that the first priority exceeds the second priority (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search); and analyzing the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search). Das-Waghorn teaches 5. The method of claim 1, wherein analyzing the one or more additional entries comprises: analyzing the first next entry when the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and identifying the second next entry when the first next entry does not include the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”). Das-Waghorn teaches 6. The method of claim 1, wherein analyzing the one or more additional entries comprises: obtaining one or more rules, wherein the one or more rules indicate that (Waghorn: Paragraph [0121], “the root cause analysis may attempt to identify a pattern in the event graph using cause identification rules”): the one or more additional entries are to be analyzed in a reverse chronological order, and entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and analyzing the one or more additional entries based on the one or more rules (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Das-Waghorn teaches 7. The method of claim 1, wherein causing the one of the two devices to be configured to address the cause of the escalation comprises: determining a response to a request that caused the escalation (Das: Claim 5, “the instructions further cause the system to update the plurality of supported issue categories for a particular product line to include emerging issue categories observed within escalated product support cases by retraining a particular word association model of the plurality of word association models corresponding to the particular product line based on a training dataset in which the escalated product supported cases are disproportionally represented”; determining the human/escalated response is inherent or implicit in the retraining procedure); and causing the one of the two devices to be configured to address the cause of the escalation based on the response (Das: Claim 5, “the instructions further cause the system to update the plurality of supported issue categories for a particular product line to include emerging issue categories observed within escalated product support cases by retraining a particular word association model of the plurality of word association models corresponding to the particular product line based on a training dataset in which the escalated product supported cases are disproportionally represented”; the model is retrained to be able to resolve similar issues without the need for escalation to a human). Das-Waghorn teaches 9. The device of claim 8, wherein the one or more processors are further configured to: determine a category associated with the cause of the escalation based on information included in a communication that caused the escalation (Das: Paragraph [0014], “Embodiments described herein seek to address various of the issues described above by making use of a novel classification approach to map a real-time textual expression customer intent to a product issue category and a just-in-time labeling approach, independently or in combination”); and cause the particular device to be configured to address the cause of the escalation based on information identifying the category (Das: Paragraph [0014], “Embodiments described herein seek to address various of the issues described above by making use of a novel classification approach to map a real-time textual expression customer intent to a product issue category and a just-in-time labeling approach, independently or in combination”, and Claim 5, “the instructions further cause the system to update the plurality of supported issue categories for a particular product line to include emerging issue categories observed within escalated product support cases by retraining a particular word association model of the plurality of word association models corresponding to the particular product line based on a training dataset in which the escalated product supported cases are disproportionally represented”; the model is retrained based on the category information). Das-Waghorn teaches 10. The device of claim 8, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant (Das: Paragraph [0068], “unsatisfactory issue resolution by the chatbot”; the chatbot runs on one device that communicates with the user/customer’s device). Das-Waghorn teaches 11. The device of claim 8, wherein, to analyze the one or more additional entries, the one or more processors are configured to: obtain one or more rules, wherein the one or more rules indicate that (Waghorn: Paragraph [0121], “the root cause analysis may attempt to identify a pattern in the event graph using cause identification rules”): the one or more additional entries are to be analyzed in a reverse chronological order, entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed, or a particular entry that is nearest to the entry is an entry that includes information regarding the cause of the escalation (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and analyze the one or more additional entries based on the one or more rules (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Das-Waghorn teaches 12. The device of claim 8, wherein the one or more processors, to analyze the one or more additional entries, are configured to: analyze the first next entry when the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and identify the second next entry when the first next entry does not include the request and the one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”) . Das-Waghorn teaches 13. The device of claim 8, wherein the particular device includes a communication device and another device of the two devices includes a first user device, and wherein the one or more processors identify the entry based on the entry including: information indicating that the first user device has been connected to a second user device, information indicating that the first user device has provided a request to be connected to the second user device, or information indicating that the communication device has provided a suggestion, to the first user device, indicating that the first user device is to be connected to the second user device (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and Paragraph [0106], “the security event may be a security compromise event related to a specific threat, e.g., an event related to computer-based malware including without limitation a virus, spyware, adware, a Trojan, an intrusion, an advanced persistent threat, spam, a policy abuse, an uncontrolled access”) . Das-Waghorn teaches 14. The device of claim 8, wherein the one or more processors are further configured to: receive session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); pre-process the session data to remove information that does not provide insight with respect to determining the cause of the escalation (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identify the entry after pre-processing the session data (Waghorn: Paragraph [0085], “to determine a root cause of the beacon or trigger event”). Das-Waghorn teaches 16. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and analyze the first next entry based on determining that the first entry includes the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Das-Waghorn teaches 17. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry does not include the request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); identify the second next entry based on determining that the first entry does not include the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and analyze the second next entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Das-Waghorn teaches 18. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to: receive session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); determine a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); determine that the first priority exceeds the second priority (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); and analyze the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search). Das-Waghorn teaches 19. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to determine a response to a request that caused the escalation (Das: Claim 5, “the instructions further cause the system to update the plurality of supported issue categories for a particular product line to include emerging issue categories observed within escalated product support cases by retraining a particular word association model of the plurality of word association models corresponding to the particular product line based on a training dataset in which the escalated product supported cases are disproportionally represented”; determining the human/escalated response is inherent or implicit in the retraining procedure); and cause the particular device to be configured to address the cause of the escalation based on the response (Das: Claim 5, “the instructions further cause the system to update the plurality of supported issue categories for a particular product line to include emerging issue categories observed within escalated product support cases by retraining a particular word association model of the plurality of word association models corresponding to the particular product line based on a training dataset in which the escalated product supported cases are disproportionally represented”; the model is retrained to be able to resolve similar issues without the need for escalation to a human). Das-Waghorn teaches 20. The non-transitory computer-readable medium of claim 15, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant (Das: Paragraph [0068], “unsatisfactory issue resolution by the chatbot”; the chatbot runs on one device that communicates with the user/customer’s device). Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rabinovich (US 2023/0108637 A1) in view of Waghorn (US 2019/0081963 A1). Regarding claims 1, 8, and 15, Rabinovich discloses A method performed by a device (Rabinovich: Claim 8, “method”), the method comprising/A device comprising one or more processors (Rabinovich: Claim 1, “system, comprising a processor”) configured to/A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a device (Rabinovich: Claim 18, “computer program product… executable by a processor…”), cause the device to: identify an entry, of a plurality of entries, that includes information regarding an escalation (Rabinovich: Claim 1, “receive a bot design and escalation logs associated with a chat bot configured based on the bot design; compute a similarity score between each of a plurality of bot response nodes in the bot design and the escalation logs; and generate a sorted list of the bot response nodes in the bot design based on the similarity scores”), wherein the plurality of entries includes communications between two devices (Rabinovich: Claim 1, “receive a bot design and escalation logs associated with a chat bot configured based on the bot design; compute a similarity score between each of a plurality of bot response nodes in the bot design and the escalation logs; and generate a sorted list of the bot response nodes in the bot design based on the similarity scores”; the chatbot runs on one device that communicates with the user/customer’s device); analyze one or more additional entries of the plurality of entries to determine a cause of the escalation (Rabinovich: Paragraph [0016], “content that is frequently found in escalation logs that is also modeled in a bot may be used to highlight potential pain points related to processes aimed for automation, but not being exploited as such at full capacity. The fixing, revision, or extension of such design items may bring an immediate impact on bot containment, which refers to the ability of a bot to successfully complete a conversation without escalation”), and cause a particular device of the two devices to be configured to address the cause of the escalation based on information regarding the one or more additional entries (Rabinovich: Paragraph [0016], “content that is frequently found in escalation logs that is also modeled in a bot may be used to highlight potential pain points related to processes aimed for automation, but not being exploited as such at full capacity. The fixing, revision, or extension of such design items may bring an immediate impact on bot containment, which refers to the ability of a bot to successfully complete a conversation without escalation”). Rabinovich does not explicitly disclose that to analyze the one or more additional entries, the one or more processors are configured to: analyze a first next entry preceding the entry or analyze a second next entry preceding the first next entry. However, Waghorn teaches that to analyze the one or more additional entries, the one or more processors are configured to: analyze a first next entry preceding the entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”) or analyze a second next entry preceding the first next entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”). Rabinovich and Waghorn are analogous art in the same field of endeavor as the instant invention as all are drawn to root cause analysis and resolution. The differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains; that is, it would have been obvious to incorporate Waghorn’s reverse node traversal into the system of Rabinovich to allow to pinpointing the exact, initial cause of the problem to be resolved. Rabinovich-Waghorn teaches 2. The method of claim 1, further comprising: receiving session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); pre-processing the session data to remove information that does not provide insight with respect to determining the cause of the escalation (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identifying the entry, in the session data, after pre-processing the session data (Waghorn: Paragraph [0085], “to determine a root cause of the beacon or trigger event”). Rabinovich-Waghorn teaches 3. The method of claim 2, further comprising: analyzing the session data to identify a period of time between a communication from a first device of the two devices and a communication from a second device of the two devices (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identifying a first portion of the session data and a second portion of the session data based on the period of time, wherein the one or more additional entries are included in one of the first portion or the second portion (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”). Rabinovich-Waghorn teaches 4. The method of claim 2, further comprising: determining a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); determining that the first priority exceeds the second priority (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search); and analyzing the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search). Rabinovich-Waghorn teaches 5. The method of claim 1, wherein analyzing the one or more additional entries comprises: analyzing the first next entry when the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and identifying the second next entry when the first next entry does not include the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”). Rabinovich-Waghorn teaches 6. The method of claim 1, wherein analyzing the one or more additional entries comprises: obtaining one or more rules, wherein the one or more rules indicate that (Waghorn: Paragraph [0121], “the root cause analysis may attempt to identify a pattern in the event graph using cause identification rules”): the one or more additional entries are to be analyzed in a reverse chronological order, and entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and analyzing the one or more additional entries based on the one or more rules (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Rabinovich-Waghorn teaches 7. The method of claim 1, wherein causing the one of the two devices to be configured to address the cause of the escalation comprises: determining a response to a request that caused the escalation (Rabinovich: Paragraph [0016], “The processor can compute a similarity score between each of a number of bot response nodes in the bot design and the escalation logs. The processor can further generate a sorted list of the bot response nodes in the bot design based on the similarity scores”); and causing the one of the two devices to be configured to address the cause of the escalation based on the response (Rabinovich: Paragraph [0016], “the fixing, revision, or extension of such design items may bring an immediate impact on bot containment, which refers to the ability of a bot to successfully complete a conversation without escalation”). Rabinovich-Waghorn teaches 9. The device of claim 8, wherein the one or more processors are further configured to: determine a category associated with the cause of the escalation based on information included in a communication that caused the escalation (Rabinovich: Claim 3, “wherein the processor is to cluster the escalation logs based on topic and modify the bot design to include a generated topic in response to detecting that a cluster of escalation logs does not exceed a second threshold lower than the threshold and detecting that the generated topic is not out-of-scope”); and cause the particular device to be configured to address the cause of the escalation based on information identifying the category (Rabinovich: Claim 3, “wherein the processor is to cluster the escalation logs based on topic and modify the bot design to include a generated topic in response to detecting that a cluster of escalation logs does not exceed a second threshold lower than the threshold and detecting that the generated topic is not out-of-scope”). Rabinovich-Waghorn teaches 10. The device of claim 8, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant (Rabinovich: Claim 1, “chat bot”). Rabinovich-Waghorn teaches 11. The device of claim 8, wherein, to analyze the one or more additional entries, the one or more processors are configured to: obtain one or more rules, wherein the one or more rules indicate that (Waghorn: Paragraph [0121], “the root cause analysis may attempt to identify a pattern in the event graph using cause identification rules”): the one or more additional entries are to be analyzed in a reverse chronological order, entries, that include a communication from a first device of the two devices and a communication from a second device the two devices, are to be analyzed, or a particular entry that is nearest to the entry is an entry that includes information regarding the cause of the escalation (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”); and analyze the one or more additional entries based on the one or more rules (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Rabinovich-Waghorn teaches 12. The device of claim 8, wherein the one or more processors, to analyze the one or more additional entries, are configured to: analyze the first next entry when the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and identify the second next entry when the first next entry does not include the request and the one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”) . Rabinovich-Waghorn teaches 13. The device of claim 8, wherein the particular device includes a communication device and another device of the two devices includes a first user device, and wherein the one or more processors identify the entry based on the entry including: information indicating that the first user device has been connected to a second user device, information indicating that the first user device has provided a request to be connected to the second user device, or information indicating that the communication device has provided a suggestion, to the first user device, indicating that the first user device is to be connected to the second user device (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and Paragraph [0106], “the security event may be a security compromise event related to a specific threat, e.g., an event related to computer-based malware including without limitation a virus, spyware, adware, a Trojan, an intrusion, an advanced persistent threat, spam, a policy abuse, an uncontrolled access”) . Rabinovich-Waghorn teaches 14. The device of claim 8, wherein the one or more processors are further configured to: receive session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); pre-process the session data to remove information that does not provide insight with respect to determining the cause of the escalation (Waghorn: Paragraph [0085], “The data log 322 may be used to create an event graph or other snapshot of the activity on the endpoint 310, e.g., for a period of time surrounding a beacon or trigger event”); and identify the entry after pre-processing the session data (Waghorn: Paragraph [0085], “to determine a root cause of the beacon or trigger event”). Rabinovich-Waghorn teaches 16. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry includes a request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and analyze the first next entry based on determining that the first entry includes the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Rabinovich-Waghorn teaches 17. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, that cause the device to analyze the one or more additional entries, cause the device to: determine that the first next entry does not include the request and one or more responses to the request (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); identify the second next entry based on determining that the first entry does not include the request and the one or more responses (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”); and analyze the second next entry (Waghorn: Paragraph [0178], “As described above, for example, this may include traversing an event graph among a sequence of causal events in reverse chronological order to a root cause”, and see also Paragraph [0125], “the method 400 may include traversing the event graph forward from an identified or presumed cause of the security event to identify one or more other ones of the computing objects affected by the cause”). Rabinovich-Waghorn teaches 18. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to: receive session data regarding the communications (Waghorn: Paragraph [0085], “The data recorder 320 may continuously record any activity occurring on the endpoint 310 for predetermined periods of time before overwriting previously recorded data. Thus, the data log 322 may include a continuous data feed of events 314. When an event 314 is detected that is a beacon or trigger event (such as a file detection, a malicious traffic detection, or the like), the data log 322 may be saved and transmitted to an analysis facility 340 or the like for analysis”); determine a first priority associated with a first portion of the session data and a second priority associated with a second portion of the session data (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); determine that the first priority exceeds the second priority (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”); and analyze the first portion based on the first priority exceeding the second priority, wherein the first portion includes the one or more additional entries (Waghorn: Paragraphs [0110], “prioritizing”, and [0148], “The data recorder may have a prioritized list of logical locations, and may record additional data based on the prioritized list of logical locations”; implicit or inherent in the prioritization of data to search). Rabinovich-Waghorn teaches 19. The non-transitory computer-readable medium of claim 15, wherein the one or more instructions, when executed by the one or more processors, further cause the device to determine a response to a request that caused the escalation (Rabinovich: Paragraph [0016], “The processor can compute a similarity score between each of a number of bot response nodes in the bot design and the escalation logs. The processor can further generate a sorted list of the bot response nodes in the bot design based on the similarity scores”); and cause the particular device to be configured to address the cause of the escalation based on the response (Rabinovich: Paragraph [0016], “the fixing, revision, or extension of such design items may bring an immediate impact on bot containment, which refers to the ability of a bot to successfully complete a conversation without escalation”). Rabinovich-Waghorn teaches 20. The non-transitory computer-readable medium of claim 15, wherein the particular device includes a chatbot, a voicebot, or a virtual assistant (Rabinovich: Claim 1, “chat bot”). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Naidu (US 2022/0232126 A1) describes a chatbot agent escalation system. Any inquiry concerning this communication or earlier communications from the examiner should be directed to IMAD HUSSAIN whose telephone number is (571)270-3628. The examiner can normally be reached Monday-Friday 0900-1700 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal Divecha can be reached at (571) 272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /IMAD HUSSAIN/Primary Examiner, Art Unit 2453
Read full office action

Prosecution Timeline

Feb 09, 2025
Application Filed
Aug 24, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701094
MESSAGING PROCESSING METHOD, APPARATUS, AND ELECTRONIC DEVICE
2y 7m to grant Granted Aug 04, 2026
Patent 12665868
SYSTEMS AND METHODS FOR OBTAINING DATA DURING A LIVE INTERACTION
2y 9m to grant Granted Jun 23, 2026
Patent 12659790
SYSTEMS AND METHODS OF TRANSMISSION OF DATA UNIT SETS BY QUALITY-OF-SERVICE LEVEL
2y 10m to grant Granted Jun 16, 2026
Patent 12652262
DYNAMIC ALLOCATION OF MESSAGING RESOURCES IN SOFTWARE AS A SERVICE MESSAGING PLATFORM
2y 6m to grant Granted Jun 09, 2026
Patent 12647355
MESSAGE ENCAPSULATION AND DE-ENCAPSULATION METHOD AND DEVICE, STORAGE MEDIUM, AND ELECTRONIC DEVICE
2y 11m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
98%
With Interview (+15.8%)
3y 1m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 597 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month