Prosecution Insights
Last updated: October 02, 2026
Application No. 19/053,216

ARTIFICIAL INTELLIGENCE BASED ANALYST AS AN EVALUATOR

Non-Final OA §101§102
Filed
Feb 13, 2025
Priority
Jan 08, 2021 — provisional 63/135,394 +2 more
Examiner
CHAI, LONGBIT
Art Unit
Tech Center
Assignee
Darktrace Holdings Limited
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
669 granted / 761 resolved
+27.9% vs TC avg
Strong +31% interview lift
Without
With
+31.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
13 currently pending
Career history
772
Total Applications
across all art units

Statute-Specific Performance

§101
16.0%
-24.0% vs TC avg
§103
41.7%
+1.7% vs TC avg
§102
35.0%
-5.0% vs TC avg
§112
6.5%
-33.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 761 resolved cases

Office Action

§101 §102
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Currently pending claims are 1 – 20. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention may be directed to software per se which is directed to non-statutory subject matter. Examiner notes for an apparatus claim, at least one recited element, in the claim body, must be a hardware component; however, the claim may be reasonably interpreted as being not limited to hardware elements according to the disclosure of the specification (SPEC-PG.PUB: Para [0028]: a functional module of an apparatus may take the form of combining software and hardware) and thus the claim may be merely directed to software per se as a non-statutory subject matter for an apparatus claim. It is respectfully suggested by the Examiner to amend the claim limitation in the claim body, for example, to explicitly include (comprise) “at least one hardware processor (or computing device or processor device) configured for:”. Any other claims not addressed are rejected by virtue of their dependency. Claim 19 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter where “A machine readable medium” as recited in the claim, may be reasonably interpreted as being intended to include communication media that include signals / carrier waves which “bear" instructions as claimed according to the disclosure of the specification (SPEC-PG.PUB: Para [0030]: including magnetic, optical electromagnetic). Such embodiments of the "manufacture" are not computer elements which define structural and functional interrelationships between the instructions and the rest of the computer that permit the functionality of the instructions to be realized / executed upon access by a hardware processor. Examiner respectfully suggests an amendment of the claim language such as either (a) “A machine readable storage device” or (b) “A non-transitory machine readable storage medium”. Appropriate correction(s) is (are) required and any other claims not addressed are objected by virtue of their dependency. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. See In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent is shown to be commonly owned with this application. See 37 CFR 1.130(b). Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1 – 20 are rejected under the judicially created doctrine of obviousness-type double patenting as being unpatentable over claims 1 – 20 of U.S. Patent No. 12,238,140. Although the conflicting claims are not identical, they are not patentably distinct from each other because the listed claims of U.S. Patent virtually contain(s) every element of the listed claims of the instant application and thus anticipate the claim(s) of the instant application. Claim(s) of the instant application therefore is/are not patently distinct from the earlier patent claim(s) and as such is/are unpatentable over obvious-type double patenting. A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001)”. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1 – 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Gamble et al. (U.S. Patent 2019/0342307). As per claim 19, Gamble teaches a machine readable medium configured to store instructions and data to be executed by one or more processors, where the instructions, when executed, cause a cyber security appliance to perform steps as follows, comprising: causing a cyber threat analyst module to investigate cyber threat incidents (Gamble: Para [0042] / [0094] / [0105]): , causing the cyber threat analyst module to use a data structure constructed to contain multiple tags to assist in modeling of an expansion of an amount of events subsumed into an ongoing cyber threat attack incident, during the ongoing cyber threat attack incident, to reflect a lifecycle of the ongoing cyber threat attack incident (Gamble: see above & Para [0007], [0060] / [0064] / [0091] / [0061], Para [0099] – [0101] & Para [0065] – [0066] / [0089]: (a) generating an analysis model by a security platform based on an expansion of multiple events (i.e. group of events closely related) represented as a collection of graph forms by (b) automatically generating a graph data structure comprising (e.g.) nodes, edges, links and etc., containing multiple tags to conduct an analysis of attack chains (Gamble: Para [0007] / [0060] / [0099] & Para [0064] – [0066] / [0061]) for determining which map to an active attack of ongoing attack (in progress) (Gamble: Para [0091]) and indicating what phase of an attack lifecycle it corresponds to the malicious attacks (Gamble: Para [0064])); causing the cyber threat analyst module to cooperate with a formatting module to generate both (i) alerts on the disparate events as they happen (Gamble: see above & Para [0062] – [0063] & Para [0093]: analyzing and detecting anomalies in concert to trigger a security alert and besides, extracting additional event data to combine into the security alerts as a whole) and (ii) a visual indication of the scale of the ongoing cyber threat attack incident as mapped by the two or more disparate events with linked information while the ongoing cyber threat attack incident is still happening (Gamble: see above & Para [0105] / [0091] / [0066] / [0096]: additionally, utilizing the link analysis to effectively show the relationships between systems (machines) and users, that are connected to security incidents, via an interface application that can display an interface with visual elements corresponding to the security incidents and determine which map to an active attack of ongoing attack (in progress) as well to effectively match an active attack’s actions). As per claim 1 & 10, the claim limitations are met as the same reasons as that set forth in the paragraph above regarding to claim 19 with the exception of the feature(s) of: where a first tag is assigned to a first node when the first node first appears in a first graph in response to a first disparate event (Gamble: see above & Para [0066]: for example, machine A or any other kind of events), where a second tag is assigned to a second node when the second node first appears in the graph in response to the second disparate event (Gamble: see above & Para [0066]: for example, machine B or any other kind of events), where the first node is coupled by a first edge to the second node forming a first group of nodes in the first graph, and where the second node and the first node are connected by the data structure in response to an indication that the cyber threat analyst module has found one or more linking points of information between the first and second disparate events event (Gamble: see above & Para [0066] / [0064]: for example, coupling between two nodes with a link (edge) indicating the respective two events are closely related), where the data structure is configured to maintain the second tag assigned to the second node and the first tag assigned to the first node when the data structure connects both the second node and the first node rather than eliminating or merging at least one of the first tag and the second tag after the data structure connects both (Gamble: see above & Para [0066] / [0064]: see above), where a third tag is assigned to a third node when the third node first appears in the first graph in response to a third disparate event (Gamble: see above & Para [0066]: for example, machine C or any other kind of events), and where the data structure is configured to connect the third node to the first group of nodes when the cyber threat analyst module has found one or more linking points of information between the third disparate event and at least one the first and second disparate events (Gamble: see above & Para [0066] / [0064]: see above). As per claim 2, 11 & 20, Gamble teaches wherein the data structure is implemented as a persistent graph-based structure, and where the cyber threat analyst module has a tag assigning module configured to assign the multiple tags including the first tag, the second tag and the third tag when, respectively, the first disparate event is detected, the second disparate event is detected, and the third disparate event is detected (Gamble: see above & Para [0064] / [0088] / [0093] / [0094]). As per claim 3 & 12, Gamble teaches wherein the formatting module is configured to cooperate with the data structure to generate the visual indication outputted as a graphical representation that shows a timeline of the two or more disparate events with linked information deemed by the cyber threat analyst module to be relevant to the ongoing cyber threat attack incident (Gamble: see above & Para [0060] / [0061] / [0088]: time-line and location), and device locations of where the two or more disparate events with linked information occurred (Gamble: see above & Para [0059] / [0061]), and where the formatting module also has a user interface configured to allow a user to assemble and generate a graphical report on that ongoing cyber attack incident that at least graphically shows the timeline, the two or more disparate events with linking points of information (Gamble: see above & Para [0010] / [0045] / [0064] / [0066] / [0088] / [0099]), and the device locations where the two or more disparate events with linking points of information occurred, where generated visual representations of nodes in the graphical report can be interacted with to pull up additional details on that node (Gamble: see above & Para [0093] / [0061] / [0045] / [0105] / [0064] / [0066] / [0088] / [0099]). As per claim 4 & 13, Gamble teaches wherein a first node in the graphical report is configured to be interacted with to pull up additional details on that node including i) the particular disparate event represented by that node and ii) two or more of details pertinent to the disparate event from a group consisting of i) a type of event associated with that disparate event (Gamble: see above & Para [0093], [0088], [0059] / [0061]), ii) what device was involved with that disparate event, and iii) an analysis of a relationship between the two or more disparate events with linking points of information and how they are related, where the additional details on that node will appear on the user interface in order to keep the graphical report to be presented with less details initially, and thus easier to understand, and then to supply the additional details on the nodes on a node-by-node basis in the graphical report (Gamble: see above & Para [0093] / [0007] / [0062] – [0066] and Para [0045] / [0099] / [0105]: analyzing and detecting anomalies in concert to trigger a security alert and besides, extracting additional event data to combine into the security alerts as a whole). As per claim 5 & 14, Gamble teaches to conduct the investigation on cyber threat incidents attacking a system protected by the cyber security appliance by having at least one of i) an API to one or more additional third party cyber security protection tools and ii) a routine to gather additional information from one or more additional third party cyber security protection tools in order to evaluate a quality of at least one of 1) alerts coming from the one or more additional third party cyber security protection tools, 2) third-party data coming from the one or more additional third party cyber security protection tools, and 3) any combination of both (Gamble: see above & Para [0007] / [0050] / [0017]), by correlating the alerts reported from the one or more additional third party cyber security protection tools to a results of the investigation on the cyber threat incidents attacking the system conducted by the cyber threat analyst module (Gamble: see above & Para [0012] / [0042] / [0046]), where the cyber threat analyst module is configured to cooperate with the formatting module to generate a validity understanding of a fidelity of alerts that were fed to the cyber threat analyst module from third-party tools by correlating whether those alerts were actually part of a particular cyber attack incident, or whether those alerts were not part of any cyber attack incident (Gamble: see above & Para [0063] / [0050] / [0074] / [0088]); and thus, deemed a false positive (Gamble: see above & Para [0058] / [0101]: based on the severity of the event and associated probability metrics, as a security event, to be a false positive). As per claim 6 & 15, Gamble teaches where in the first tag corresponds to a first initial event identifier tag and the second tag corresponds to a second initial event identifier tag, wherein the data structure to contain the multiple tags is configured to allow the cyber threat analyst module to utilize the multiple tags as the cyber threat analyst module accumulates information about a particular event occurring in an ongoing cyber attack incident (Gamble: see above & Para [0060] / [0090]), and then assign a first group tag to the first and second disparate events with linking points of information as the linking points are found to be likely between the first disparate event and the second disparate event to tie these events as likely related while still retaining initial information contained in both the first initial event identifier tag assigned to the first disparate event and the second initial event identifier tag assigned to the second disparate event (Gamble: see above & Para [0060] / [0090]), and where the cyber threat analyst module is configured to use the retained initial information contained in at least one of the first initial event identifier tags assigned to the first disparate event and the second initial event identifier tag assigned to the second disparate event to link pieces of information contained in at least one of the first initial event identifier tag and the second initial event identifier tag with the third disparate event when the third disparate event has not yet been confirmed as being related to the first group tag assigned to the first disparate event and the second disparate (Gamble: see above & Para [0060], [0088] – [0090]); and thus, the multiple tags preserve original information captured in the initial event identifier tag so that the cyber threat analyst module still can go back and piece information together via use of the information in the multiple tags (Gamble: see above & Para [0060] / [0087] / [0090] / [0096]). As per claim 7 & 16, Gamble teaches where the data structure is configured to connect two or more nodes determined to be related by the cyber threat analyst module via one or more mechanisms consisting of 1) by adding a group tag that indicates that the nodes are related (Gamble: see above & Para [0090] / [0095] / [0099]), and 2) by performing a calculation of relatedness and using at least one of a software pointer and other tracking mechanism that indicates that the nodes are related (Gamble: see above & Para [0088] / [0094] / [0095]). As per claim 8 & 17, Gamble teaches where the formatting module is configured to 1) apply a plurality of different colors to convey commonality and differences between a plurality of generated visual representations in the graphical report corresponding to the two or more disparate events with linking points of information to assist in an understanding of the graphical report as well (Gamble: see above & Para [0045] / [0094] / [0095] / [0099]) as 2) present the visual representations positionally within a network in relation to other devices involved in the cyber threat attack and/or geographically in relation to other devices involved in the cyber threat attack (Gamble: see above & Para [0059] / [0061] / [0066]). As per claim 9 & 18, Gamble teaches wherein the cyber threat analyst module is configured to investigate the cyber threat incidents by cooperation with one or more of the group consisting of: one or more artificial intelligence models trained on how human cyber security analysts conduct an investigation on a possible set of cyber threats hypotheses, one or more scripts outlining how to conduct an investigation on a possible set of cyber threats hypotheses (Gamble: see above & Para [0011] / [0014] / [0016] / [0055] / [0102] / [0105]), and one or more rules-based models on how to conduct an investigation on a possible set of cyber threats hypotheses (Gamble: see above & Para [0011] / [0014] / [0055] / [0102] / [0105]). Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. --------------------------------------------------- /Longbit Chai/ Longbit Chai E.E. Ph.D. Primary Examiner, Art Unit 2431 No. #2614 – 2026 ---------------------------------------------------
Read full office action

Prosecution Timeline

Feb 13, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §101, §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748870
Dynamically Controlling Access to Linked Content in Electronic Communications
2y 0m to grant Granted Sep 29, 2026
Patent 12750403
INITIAL SECURITY ACTIVATION FOR MEDIUM ACCESS CONTROL LAYER
2y 0m to grant Granted Sep 29, 2026
Patent 12732478
Systems, Methods And Apparatus For Local Area Network Isolation
2y 11m to grant Granted Sep 08, 2026
Patent 12732542
UNIFIED DEVICE MANAGEMENT ENGINE IN A DEVICE MANAGEMENT SYSTEM
2y 5m to grant Granted Sep 08, 2026
Patent 12719891
REALTIME EVENT DETECTION
1y 7m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+31.2%)
2y 8m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 761 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month