Prosecution Insights
Last updated: October 02, 2026
Application No. 19/051,089

EDGE-BASED PACKET PROCESSING FOR APPLICATION RECOGNITION AND INTRUSION DETECTION

Non-Final OA §103
Filed
Feb 11, 2025
Priority
Apr 03, 2024 — provisional 63/574,184
Examiner
LEMMA, SAMSON B
Art Unit
Tech Center
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
809 granted / 917 resolved
+28.2% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
24 currently pending
Career history
936
Total Applications
across all art units

Statute-Specific Performance

§101
20.5%
-19.5% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
19.4%
-20.6% vs TC avg
§112
12.1%
-27.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 917 resolved cases

Office Action

§103
DETAILED ACTION 1. Applicant’s election without traverse of Group I (claims 1-14 and 18-20) in the reply filed on 07/06/2026 is acknowledged. Thus, claims 1-14 and 18-20 are pending and claims 1 and 18 are independent. Notice of Pre-AIA or AIA Status 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority 3. This application filed on 02/11/2025 claims Priority from Provisional Application 63574184, filed on 04/03/2024 Information Disclosure Statement 4. The information disclosure statements (IDS) submitted on 03/06/2025 and 08/11/2025 have been considered. The submission is in-compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto. Drawings 5. The drawings filed on February 11, 2025, are accepted. Specification 6. The specification filed on February 11, 2025, is also accepted. Internet Communications 7. Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, http:/www.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only: (1) Central Fax, which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03. Claim Rejections - 35 USC § 103 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or non-obviousness. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 9. Claims 1-3 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) The following is referring to independent claims 1 and 18: As per independent claim 1, Gurbani discloses a network device, comprising [Para. 0061, “the present invention can be deployed in a SIP proxy server that accepts SIP messages and proxies them downstream. Such a system could also consist of other SIP entities such as back-to-back user agents, user agent server, user agent client, registrar, redirect server, a SIP firewall element or a session border controller” a proxy server, firewall element and session border controller are network devices that receive and process network message]: a processor [Para. 0052, “such an implementation might employ, for example, a processor 402, a memory 404”]; a network interface controller configured to provide access to a network; [Para. 0054, “a network interface 414, such as a network card, which can be provided to interface with a computer network”]and a memory communicatively coupled to the processor, wherein the memory comprises a packet inspection logic configured to [para. 0056, “computer software including instructions or code for performing the methodologies of the invention…, may be stored in one or more of the associated memory devices” and “at least one processor 402 coupled directly or indirectly to memory elements 404 through a system bus 410” The stored software corresponds to packet-inspection logic because it performs message inspection and classification methodology. The system bus provides and corresponds to communicative coupling between memory and processor] : receive at least one packet comprising one or more headers and a payload; generate a sequence of tokens based on the one or more headers and the payload [para. 0006, “when a new SIP message arrives, it can be converted to a similar feature vector by counting the occurrences of n-grams derived from the headers and payload that comprises the new SIP message” and “ message is broken down to a series of 4-byte words”; When a new message arrives corresponds to receiving the network message. This paragraph discloses that the message contains headers and payload. Breaking the message into a series of fixed length words derived from both portions produces the claimed sequence of tokens”] encode the sequence of tokens into a unified representation Para. 0023, “technique is employed to embed a SIP message to a high-dimensional vector space: and 0024, “An embedding function Φ maps all SIP messages X to a |Q|-dimensional vector space “, Mapping the tokenized message into one high-dimensional feature-vector representation teaches encoding the token sequence into a unified representation] provide the unified representation as a shared input to a plurality of classifiers at the edge device [Para. 0021, “processing the feature vector matrix using a plurality of classifiers” and para. 0061, The same feature-vector matrix is processed by the plurality of classifiers. It therefore constitutes their shared inputs. Para. 0061, places that classifier system at the disclosed session border controller or proxy server], and obtain a set of classification results for the received at least one packet as output of the plurality of classifiers [Para. 0021, “processing the feature vector matrix using a plurality of classifiers; combining results generated by the plurality of classifiers to obtain a combined result” Results generated by the individual classifiers constitute a set of classification results]. Gurbani doesn’t explicitly disclose the following underlined claim limitation: “encode the sequence of tokens into a unified representation by utilizing one or more encoders, including one or more encoders at the edge device” However, Shah discloses the above underlined claim limitations: ”encode the sequence of tokens into a unified representation by utilizing one or more encoders, including one or more encoders at the edge device” [Para. 0062, “A representation of each of these application messages may be input to the encoder structure 500 a” The representation …may be based on various tokenization and/or parameterization techniques” and “the encoding layer 504 outputs corresponding application message vectors in the N-dimensional vector space representing the application message that is input” This teaches an encoder receiving a tokenized message representation and outputting a unified message vector] Gurbani and Shah are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify Gurbani’s existing message-embedding function by applying and using Shah’s encoder such as “encode the sequence of tokens into a unified representation by utilizing one or more encoders, including one or more encoders at the edge device” as taught by Shah to enhance the security of the system by efficiently and effectively protecting users of applications against different attacks.. [See Shah, para. 0004, , “there is a desire to improve upon the inefficiencies and ineffectiveness of WAF or any other rule-based security system for more efficiently and effectively protecting users of applications against such attacks..”] As per independent claim 18, Independent claim 18 is a method version of a device/system claim 1, and has the same scope as independent claim 1. Thus, claim 18 is rejected for same reason as claim 1. As per dependent claim 2, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses the method wherein the sequence of tokens comprises one or more first tokens that are generated based on the one or more headers and one or more second tokens that are generated based on the payload [Para. 0006, “ n-grams derived from the headers and payload” because the n-grams are derived from the headers and payload, they include header derived first tokens and payload derived second tokens]. As per dependent claim 3, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses the method, wherein the payload corresponds to one of plaintext or encrypted text [Para. 0003, “text-based protocol” and para 0006 teaches that the payload is included when constructing the feature vector. This teaches the plaintext alternatives]. 10. Claims 5 and 9 are rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Xuying Meng et al (Meng) (NPL document, titled, "Packet Representation Learning for Traffic Classification" ACM 2022) As per dependent claim 5, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses feature vector” that contains occurrence counts for four-byte words and therefore indicates byte-level pattern. The combination however does not teach, wherein the unified representation indicates a semantic pattern and a byte-level pattern of the received at least one packet. However, Meng discloses wherein the unified representation indicates a semantic pattern of the received at least one packet and byte-level pattern of the received at least one packet [Abstract and paragraph 4, “preserving both semantic and byte patterns of each packet” Gurbani, Shah and Meng are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah by applying additional representation such as, “a semantic pattern of the received at least one packet and byte-level pattern of the received at least one packet” as taught by Meng to enhance the security of the system by retaining byte-level detail while adding a useful shared semantic representation and multi-task learning. [See Meng at least the abstract] As per dependent claim 9, the combination of Gurbani, Shah and Meng discloses the device/method as applied to claim 1 above. Furthermore, Meng discloses wherein the packet inspection logic is further configured to: propagate a feedback from the plurality of classifiers to the one or more encoders; and tune at least one parameter of the one or more encoders based on the propagated feedback. [See abstract and para. 4, “jointly optimized by class labels of multiple tasks” The multiple-task class losses meets feedback from the respective classifier header; propagating those loses through the packet encoding model adjusts its parameters] 11. Claims 8 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Arun Ayyagari et al (Ayyagari) (US Publication No. 20130305357A1, Pub. Date: 11/14/2013) As per dependent claim 8, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses normal and anomalous classification results and acts on those results, but the combination doesn’t disclose: “generate one or more context-aware alerts based on the set of classification results” However , Ayyagari discloses, “generate one or more context-aware alerts based on the set of classification results” [See title, “Context Aware Network Security Monitoring for Threat Detection and para. 0133, “When new transactional sessions are identified that are beyond the statistical bounds of the nominal operational profile baseline, notifications and/or alerts are generated and sent to the network manager for an updated situational awareness,” The alert is context-aware because it is based on departure form a contextual baseline and is generated from the anomaly results.] Gurbani, Shah and Ayyagari are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah by applying additional mechanism such as, “generate one or more context-aware alerts based on the set of classification results” as taught by Ayyagari to enhance the security of the system by converting anomaly results into actionable situational-awareness alerts thereby mitigating cyber threat [See Ayyagari, para. 0133, “notifications and/or alerts are generated and sent to the network manager for an updated situational awareness, and the initiation of further analysis is enabled. Once a transactional session is determined to be an anomalous behavior that may lead to a cyber threat, mitigating steps are initiated”] As per dependent claim 20, dependent claim 20 is a method version of a device/system claim 8, and has the same scope as independent claim 8. Thus, claim 20 is rejected for same reason as claim 8. 12. Claims 10 is rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Yue Cao (Cao) (US Publication No. 20220248270 A1, Pub. Date: 08/04/2022) As per dependent claim 10, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses implementation in a network device including a session border controller [Para. 0061, “the present invention can be deployed in a SIP proxy server that accepts SIP messages and proxies them downstream. Such a system could also consist of other SIP entities such as back-to-back user agents, user agent server, user agent client, registrar, redirect server, a SIP firewall element or a session border controller” a proxy server, firewall element and session border controller are network devices that receive and process network message] but the combination of Gurbani and Shah doesn’t disclose: “wherein the network device corresponds to an access point in the network” However, Cao discloses, “wherein the network device corresponds to an access point in the network” [See para. 0008, “The method is performed by a wireless access point”.] Gurbani, Shah and Cao are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah by applying additional mechanism such as, “wherein the network device corresponds to an access point in the network” as taught by Cao to classify packets at the access point through which the packets already pass [See Cao, para. 0002, “method for classifying network data packets by hardware with classifier identifiers”] 13. Claims 11-13 are rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Sriram Vasudevan et al (Vasudevan) (US Publication No. 20210204152 A1, Pub. Date: 07/01/2021) As per dependent claim 11, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses plurality of classifiers collectively determines message validity. The combination of Gurbani and Shah does not teach designating one classifier for application recognition and another for intrusion detection. The combination of Gurbani and Shah doesn’t discloses, wherein a first classifier of the plurality of classifiers corresponds to an application recognition classifier and a second classifier of the plurality of classifiers corresponds to an intrusion detection classifier. However, Vasudevan teaches a first classifier of the plurality of classifiers corresponds to an application recognition classifier and a second classifier of the plurality of classifiers corresponds to an intrusion detection classifier [Para. 0007, “an anomaly detector and traffic classifier and para. 0005 and claim 1, an anomaly detector comprising a machine learning model trained to predict whether data traffic patterns differ from a set of observed traffic patterns present in a set of training data; and a traffic classifier comprising a machine learning model trained to predict a quality of service (QoS) class for network connections or data flows] Gurbani, Shah and Vasudevan are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah by applying additional mechanism such as, “wherein a first classifier of the plurality of classifiers corresponds to an application recognition classifier and a second classifier of the plurality of classifiers corresponds to an intrusion detection classifier” as taught by Vasudevan to allow the classification models to be automatically updated and refined as new traffic patterns are encountered [Para. 0006, Vasudevan, in this manner, there is a flow of communication between the traffic classifiers and model training system, allowing the classification models to be automatically updated and refined as new traffic patterns are encountered”]. As per dependent claim 12, the combination of Gurbani, Shah and Vasudevan discloses the device/method as applied to claim 11 above. Furthermore, Vasudevan discloses, wherein the set of classification results includes an application recognition result indicating an application associated with the received at least one packet and an intrusion detection result indicating whether the received at least one packet is a legitimate packet or an anomalous packet [Para. 0005 and 0007 and claim 1, “the traffic classifier includes at least two machine-learning-based models, an anomaly detector and a traffic classifier. The anomaly detector examines traffic (e.g., packet statistics) to identify traffic that appears to be different from the classes of traffic that the traffic classifier is trained to identify. Non-anomalous traffic is then classified by the traffic classifier into the predetermined categories the traffic classifier is trained to predict, while the anomalous traffic is handled separately. The anomalous traffic, or at least statistics and/or metadata for the traffic, is stored and can used to update the training of both the anomaly detector and the traffic classifier”]. As per dependent claim 19 dependent claim 19 is a method version of a device/system claim 12, and has the same scope as independent claim 12. Thus, claim 19 is rejected for same reason as claim 12. As per dependent claim 13, the combination of Gurbani, Shah and Vasudevan discloses the device/method as applied to claim 12 above. Furthermore, Vasudevan discloses, wherein the application recognition result is obtained as the output of the first classifier and the intrusion detection result is obtained as the output of the second classifier [At least para. 0007, 0005 and claim 1, “the traffic classifier includes at least two machine-learning-based models, an anomaly detector and a traffic classifier. The anomaly detector examines traffic (e.g., packet statistics) to identify traffic that appears to be different from the classes of traffic that the traffic classifier is trained to identify. Non-anomalous traffic is then classified by the traffic classifier into the predetermined categories the traffic classifier is trained to predict, while the anomalous traffic is handled separately. The anomalous traffic, or at least statistics and/or metadata for the traffic, is stored and can used to update the training of both the anomaly detector and the traffic classifier”] 14. Claims 14 is rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Shyam SREEVALSAN et al (SREEVALSAN) (US Publication No. 20200274815 A1, Pub. Date: 08/27/2020) As per dependent claim 14, the combination of Gurbani and Shah discloses the device/method as applied to claim 1 above. Furthermore, Gurbani discloses trained classifiers. The combination of Gurbani and Shah does not teach “wherein the plurality of classifiers corresponds to adaptive classifiers that re-learn based on the set of classification results” However , SREEVALSAN discloses, “wherein the plurality of classifiers corresponds to adaptive classifiers that re-learn based on the set of classification results” [para. 0114, “For example, if the 80th percentile of the model confidence histogram drops below a certain predetermined threshold then the system may trigger a re-training action for the model.” And para. 0054, 0062 and 0115 teaches that models are monitored, updated or retrained. And para. 0115, “If an existing model is found to be requiring an update or re-training, the learning process may be repeated for that particular model with necessary changes in data collection, data processing, processing selection or training or the like.] Gurbani, Shah and SREEVALSAN are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah by applying additional mechanism such as, “wherein the plurality of classifiers corresponds to adaptive classifiers that re-learn based on the set of classification results” as taught by SREEVALSAN to enhance the security of the system and maintain classifier accuracy as network traffic pattern change. [Para. 0115, SREEVALSAN “If an existing model is found to be requiring an update or re-training, the learning process may be repeated for that particular model with necessary changes in data collection, data processing, processing selection or training or the like.”]. 15. Claims 6-7 are rejected under 35 U.S.C. 103 as being unpatentable over Vijay K. Gurbani et al (Gurbani) (US Pub. No. 20130054816 A1, Pub. Date: Feb 28, 2013) in view of Dishant Shah et al (Shah) (US Pub. No. 20210185066 A1, Pub. Date: June. 17, 2021) and further in view of Xuying Meng et al (Meng) (NPL document, titled, "Packet Representation Learning for Traffic Classification" ACM 2022) and further in view of Jianfeng Gao et al (Gao) (US Publication No. 20170032035 A1, Pub. Date: 02/02/2017) As per dependent claim 6, the combination of Gurbani , Shah and Meng discloses the device/method as applied to claim 5 above. Furthermore, Gurbani on para. 0006 discloses that the four-byte word occurrence “represented as a feature vector” the entries associated with the four byte words corresponds to the claim second byte-level representation. However Gurbani does not expressly disclose the a first semantic representation. The combination of Gurbani, Shah and Meng does not teach “a first representation indicating the semantic pattern of the received at least one packet” However, Gao discloses, “a first representation indicating the semantic pattern of the received at least one packet” [para. 0071, “semantic representation layer for a shared representation and see also para. 0070 and 0072] Gurbani, Shah, Meng and Gao are analogous arts and are in the same field of endeavor as they are directed to detecting anomalous messages in networks. It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system of Gurbani, Shah and Meng by applying additional mechanism such as, ““a first representation indicating the semantic pattern of the received at least one packet” as taught by Gao to enhance the security of the system and retain byte level detail while adding a useful shared semantic representation and multi-task learning [Para. 0070-0071, See Gao “semantic representation layer for a shared representation”]. As per dependent claim 7, the combination of Gurbani, Shah, Meng and Gao discloses the device/method as applied to claim 6 above. Furthermore, Gurbani discloses the method, wherein a second representation of the one or more second representations correspond to a token of the sequence of tokens. [Para. 0006, “occurrences of each such word” in the feature vector. Each vector entry therefore corresponds to a particular four-byte n-gram token] Allowable Subject Matter Claim 4 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. 17. The following is examiner’s statements of reasons for allowance: The above prior arts of record including the rest of the cited prior arts including the prior arts cited in the IDS either taken alone or in combination neither anticipates nor renders obvious the claimed subject matter of the instant application that is taken as a whole including the following limitation recited in dependent claim 4 “ wherein based on the payload corresponding to the encrypted text, generating the one or more second tokens comprises: converting the encrypted text into one or more codes; and tokenizing the one or more codes to generate the one or more second tokens.” For this reason, the specific claim limitations recited in dependent claim 4 taken as whole would be allowed if the current rejection set forth in this office action is overcome. Conclusion 18. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. a. US Publication No. 20080262990 A1 Kapoor et al discloses flow processing facility, which uses a set of artificial neurons for pattern recognition, such as a self-organizing map, in order to provide security and protection to a computer or computer system supports unified threat management based at least in part on patterns relevant to a variety of types of threats that relate to computer systems, including computer networks. Flow processing for switching, security, and other network applications, including a facility that processes a data flow to address patterns relevant to a variety of conditions are directed at internal network security, virtualization, and web connection security. A flow processing facility for inspecting payloads of network traffic packets detects security threats and intrusions across accessible layers of the IP-stack by applying content matching and behavioral anomaly detection techniques based on regular expression matching and self-organizing maps. Exposing threats and intrusions within packet payload at or near real-time rates enhances network security from both external and internal sources while ensuring security policy is rigorously applied to data and system resources. Intrusion Detection and Protection (IDP) is provided by a flow processing facility that processes a data flow to address patterns relevant to a variety of types of network and data integrity threats that relate to computer systems, including computer networks. b. US Publication No. 20110214157 A1 Korsunsky et al discloses a network apparatus for preventing denial of service attacks, comprising, at least one network processor module having at least one processor, at least one interface to receive and forward a stream of data packets in a network, and instructions to cause the at least one processor to recognize one or more data packets in the stream of data packets that contain data, including subscriber profile information, for processing by a denial of service security application executing on the network apparatus by applying a denial of service detection and/or prevention policy to the data, and directing the stream of data packets to at least one flow processor module for executing the denial of service security application based on the subscriber profile information and the denial of service detection and/or prevention policy. c. US Publication No. 20150052601 A1 White et al discloses rapid filtering of opaque data traffic. According to one method, the method includes receiving a packet containing a payload. The method also includes analyzing a portion of the payload for determining whether the packet contains compressed or encrypted data. The method further includes performing, if the packet contains compressed or encrypted data, at least one of sending the packet to an opaque traffic analysis engine for analysis, discarding the packet, logging the packet, or marking the packet d. See the other cited prior arts. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMSON B LEMMA whose telephone number is 571-272-3806. The examiner can normally be reached on M-F 8am-10pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shaw Yin Chen can be reached on to 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SAMSON B LEMMA/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Feb 11, 2025
Application Filed
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748896
PHYSICAL UNCLONABLE FUNCTION DEVICE AND METHOD
2y 4m to grant Granted Sep 29, 2026
Patent 12732520
GENERATION DEVICE, GENERATION METHOD, AND GENERATION PROGRAM
2y 0m to grant Granted Sep 08, 2026
Patent 12719874
SECURITY MANAGEMENT OF TRUSTED NETWORK FUNCTIONS
1y 8m to grant Granted Aug 25, 2026
Patent 12712643
SYSTEM AND METHOD FOR NETWORK DISTRIBUTION OF QUANTUM ENTANGLEMENT
1y 11m to grant Granted Aug 18, 2026
Patent 12694098
SYSTEMS AND METHODS FOR MANAGING STATE
1y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+11.2%)
2y 9m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 917 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month