Prosecution Insights
Last updated: August 15, 2026
Application No. 19/058,620

PRE-DEPLOYMENT DETECTION AND RESPONSE

Non-Final OA §101§103§112
Filed
Feb 20, 2025
Priority
Feb 20, 2024 — provisional 63/555,823
Examiner
LEE, MICHAEL M
Art Unit
Tech Center
Assignee
Darktrace Holdings Limited
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
229 granted / 273 resolved
+23.9% vs TC avg
Strong +41% interview lift
Without
With
+41.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
28 currently pending
Career history
293
Total Applications
across all art units

Statute-Specific Performance

§101
9.2%
-30.8% vs TC avg
§103
52.8%
+12.8% vs TC avg
§102
8.2%
-31.8% vs TC avg
§112
19.9%
-20.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 273 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a non-final office action in response to applicant’s communication filed on 2/20/2025. Claims 1-20 are pending and being considered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 8/29/2025 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, initialed and dated copy of Applicant’s IDS form 1449 filed as stated above is attached to the instant Office Action. Claim Objections Claim 1 is objected to because of the following informalities: Claim 1 lines 11-12, recites “where instructions implemented in software for the cloud security system and the cloud security system are configured”. The underlined may be typos. Examiner notes, independent claims recite “cloud analysis logic”, however, dependent claims refer to “code analysis logic”. Applicant is suggested to clarify the claim terms. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2-4, 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 2 line 2 recites “the code analysis logic”. There is insufficient antecedent basis for this limitation in the claim. Similarly claims 3 line 1, claim 4 line 1, claim 19 line 2. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-9 are rejected under 35 USC § 101 because the claimed invention is directed to non-statutory subject matter. The claims are not statutory as they are drawn as a whole to a software per se. Claim 1 recites a cloud security platform… comprising: “a cloud analysis logic” and “a cloud security system”. The claim does not fall within at least one of the four categories of patent eligible subject matter because the claim is directed to a software per se. The cloud analysis logic and cloud security system, in light applicant’s specification and recited claims, can be understood being software modules. To overcome the rejection above, applicant is suggested to include at least one hardware component in the claim. Claims 2-9 depend on claim 1, therefore are also rejected with the same reason set forth above. Claims 1-20 are rejected under 35 U.S.C. §101 because the claimed invention is directed to an abstract idea without significantly more. Eligibility Step 2A Prong One: Claim 10 (similarly claim 1, 18) recites “identifying one or more security threats …”, “determining a difference …”, “determining whether the one or more security threats associated with the code submission and the one or more security threats associated with the prior code submission or the production code causes further analysis of content of code …”. These would be interpreted as being analogous to concepts relating to organizing or analyzing information in a way that can be performed mentally or human mental work. Accordingly, the claim recites the abstract idea. The limitation of identifying, determining(s), as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of relating to analysis of code. Nothing in the claim element precludes the step from practically being performed in the mind. Accordingly, the claim recites an abstract idea. Eligibility Step 2A Prong Two: Claims 1, 18 recite additional limitations of “analysis logic”, “security system”, “processors”, “storage medium” to perform the steps of method claim discussed above. The limitations of identifying, determining(s), as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “analysis logic”, “security system”, “processors”, “medium”, nothing in the claim element precludes the steps from practically being performed in the mind. Accordingly, the claims recite an abstract idea. This judicial exception is not integrated into a practical application because the claim only recites the additional limitations of “code submission”, “security threats”, “production code”, which are merely used as generic and well-known terminologies, and they do not amount to significantly more than the abstract idea. In addition, the claims only recite additional elements – “analysis logic”, “security system”, “processors”, “medium”, to perform the identifying, determining(s), steps. The computer system is recited at a high level of generality (i.e., as a generic processor performing a generic computer function of identifying, determining(s)) such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. Eligibility Step 2B: The claim does not recite additional elements sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using computing system to perform the identifying, determining(s) steps amounts to no more than mere instructions to apply the exception using generic computing system. Mere instructions to apply an exception using generic computing machines cannot provide an inventive concept. The claim is not patent eligible. Dependent claims 2-9, 11-17, 19-20 depend on the rejected independent claim 1, 10, 18 respectively, therefore are also not patent eligible. Examiner Notes Examiner cites particular paragraphs, columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 8, 10, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Hecht et al (US10607015B1, hereinafter, “Hecht”), in view of Dang et al (US20220108020A1, hereinafter, “Dang”). Regarding claim 10, Hecht teaches: A computerized method for cloud security (Hecht, discloses systems and methods for automatically detecting and addressing security risks in code segments, see [Abstract]. And [Col. 5 lines 63-67] FIG. 1 illustrates an exemplary system 100 for detecting and addressing security risks in code segments, consistent with the disclosed embodiments. System 100 may represent an environment in which software code is developed and/or executed, for example in a cloud environment), comprising: identifying one or more security threats associated with a code submission for evaluation (See Fig. 8 at 810-830, [Col. 18 lines 49-51] At step 810, process 800 may include accessing a plurality of code segments developed for execution in a network environment. [Col. 19 lines 18-20] At step 820, process 800 may include automatically identifying a first code segment from the plurality of code segments for analysis. And [Col. 19 lines 38-40] At step 830, process 800 may include automatically performing a first code-level security risk assessment for the first code segment); While Hecht teaches security risk assessment and control for code in cloud environment, but does not specifically teach following, in the same field of endeavor Dang teaches: determining a difference between the one or more security threats associated with the code submission and one or more security threats associated with a prior code submission or production code that pertains, at least in part, to cloud infrastructure modified or created by the code submission; determining whether the one or more security threats associated with the code submission and the one or more security threats associated with the prior code submission or the production code causes further analysis of content of code included in the code submission prior to release as production code (Dang, discloses systems and methods for automating the process of application code vulnerability remediation, See [Abstract] Implementations include building a repository of code revisions as software is checked for security vulnerabilities using or more software analysis tools. In certain implementations, historical code revisions are cataloged and stored in the repository. The revisions may be tokenized and utilized to detect and automatically remediate similar issues when new software packages are submitted to the system. And [0004] Prior to submitting code for production, a software developer can utilize various analysis tools to identify known bugs and vulnerabilities in the code… A need exists for a software code vulnerability remediation solution to address such concerns. And [0020] historical code revisions (i.e., prior code submission or production code) are cataloged and stored in the repository. The revisions may be tokenized and utilized to detect and automatically remediate similar issues when new software packages are submitted to the system. Further see e.g., Fig. 8, and [0067] In block 806, the method 800 includes generating differential listings comprising vulnerability remediation updates to the one or more initial code packages by the one or more software security analysis tools…In block 812, the method 800 includes locating one or more fields of the application code package that include a vulnerability defined by one or more of the generalized remediation tokens). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Dang in the security risk assessment and control of Hecht by detecting security vulnerabilities of software code before submitting for production using or more software analysis tools. This would have been obvious because the person having ordinary skill in the art would have been motivated to detect and automatically remediate issues when new software packages are submitted to the system (Dang, [Abstract]). Regarding claim 1, claim 1 is a system claim that encompasses limitations similar to those limitations of the method claim 10. Therefore, claim 1 is rejected with the same rationale and motivation as applied against claim 10. In addition, Hecht teaches generate a message including information associated with the one or more security threats (Hecht, discloses systems and methods for automatically detecting and addressing security risks in code segments, see [Abstract]. And [Col. 19 lines 38-40] At step 830, process 800 may include automatically performing a first code-level security risk assessment for the first code segment); And Dang teaches a cloud security platform configured to protect a cloud environment, comprising: a cloud analysis logic (Dang, e.g., Fig. 1, Remote Application Security Testing Platform 170); and a cloud security system communicative coupled to the cloud analysis logic (Fig. 1, Vulnerability Remediation System 110). Regarding claim 18, claim 18 is a storage medium claim that encompasses limitations similar to those limitations of the method claim 10. Therefore, claim 18 is rejected with the same rationale and motivation as applied against claim 10. In addition, Hecht teaches a non-transitory storage medium including software that, when executed by one or more processors (Hecht, discloses systems and methods for automatically detecting and addressing security risks in code segments, see [Abstract]. e.g., Fig. 2, Processor and Memory, Scanning Analysis Component, and [Claim 1] A non-transitory computer readable medium). Regarding claim 8, Hecht-Dang combination teaches the cloud security platform of claim 1, Hecht further teaches: further comprising a cyber security appliance communicatively coupled to the cloud, the cyber security appliance is configured to provide a mapping including at least information associated with the one or more security threats for training of artificial intelligence (Al) models utilized for identifying security threats associated with network communications over a network communicatively coupled to the cloud environment ([Col. 18 lines 4-22] the anomaly detection mode may use AI or machine learning for building the user or code segment profiles, and/or detecting anomalies. For example, a model may be developed to detect abnormal behavior by one or more users or code segments. A set of training data may be developed containing one or more of user profile data, code segments, code segment data, and/or risk scores or factors. Various features may be extracted from the data and fed to a training algorithm to learn which features correspond to an anomaly in the system. For example, known security breaches or employee errors may be provided to the training algorithm. A model may then be developed using a suitable machine learning algorithm (e.g., a logistic regression, a linear regression model, a lasso regression analysis, a random forest model, a K-Nearest Neighbor (KNN) model, a K-Means model, a decision tree, a cox proportional hazards regression model, a Naïve Bayes model, a Support Vector Machines (SVM) model, gradient boosting algorithms, etc.)). Claims 2-4, 9, 11-14, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Hecht-Dang as applied above to claim 1, 10 respectively, further in view of Kwatra et al (US20240086190A1, hereinafter, “Kwatra”). Regarding claim 2, Hecht-Dang combination teaches the cloud security platform of claim 1, The combination of Hecht-Dang does not specifically teach the following, in the same field of endeavor Kwatra teaches: wherein the code submission is infrastructure as code (laC) code and the code analysis logic is a component of a Continuous Integration and Continuous Deployment (Cl/CD) pipeline (Kwatra, discloses systems and methods of automating software development, security, and operations, [Abstract] a plurality of infrastructure as code files specifying a configuration of a runtime environment for a deployable image of source code in a continuous integration and continuous delivery pipeline for a cloud platform. And [0016] receive source code written for a serverless function and API gateway and CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service, the events that trigger the function and the resources of a runtime environment). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Kwatra in the security risk assessment and control of Hecht-Dang by implementing software development with CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service. This would have been obvious because the person having ordinary skill in the art would have been motivated for automating software development, security, and operations (Kwatra, [Abstract], [0001-0002]). Regarding claim 11, Hecht-Dang combination teaches the computerized method of claim 10, The combination of Hecht-Dang does not specifically teach the following, in the same field of endeavor Kwatra teaches: wherein the code submission is infrastructure as code (laC) code (Kwatra, discloses systems and methods of automating software development, security, and operations, [Abstract]. And [0016] receive source code written for a serverless function and API gateway and CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service, the events that trigger the function and the resources of a runtime environment). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Kwatra in the security risk assessment and control of Hecht-Dang by implementing software development with CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service. This would have been obvious because the person having ordinary skill in the art would have been motivated for automating software development, security, and operations (Kwatra, [Abstract], [0001-0002]). Regarding claim 12, Hecht-Dang-Kwatra combination teaches the computerized method of claim 11, Kwatra further teaches: wherein the identifying of the one or more security threats is conducted by code analysis logic within a Continuous Integration and Continuous Deployment (Cl/CD) pipeline (e.g., [0016] receive source code written for a serverless function and API gateway and CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service, the events that trigger the function and the resources of a runtime environment). Same motivation as presented in claim 11 would apply. Regarding claim 3, similarly claim 13, Hecht-Dang-Kwatra combination teaches the cloud security platform of claim 2, the computerized method of claim 12, Kwatra further teaches: wherein the code analysis logic comprises scanning logic configured to scan the laC code for security threats that pertain to an analysis of information associated with the laC code including an entity that uploaded the laC code into the CI/CD pipeline and contents of the laC code including one or more misconfigurations or vulnerabilities identified within the contents of the laC code ([0044] For example, storage 224 may store playbooks 234, each a type of IaC code 232 file written in YAML that include declarations specifying the final state infrastructure to provision for the runtime environment. Storage 224 may store other types of pipeline configuration files 238 that are used during CI/CD delivery on cloud platforms such as configuration files for artifacts, stack template files, roles files, and project object model (pom) files for example. Storage 224 may also store runtime processing logs 242 that may be scanned to diagnose the cause of CI/CD pipeline failures such as incorrect syntax, incorrect variable values, job failures and so forth). Same motivation as presented in claim 2, 12 would apply. Regarding claim 4, similarly claim 14, Hecht-Dang-Kwatra combination teaches the cloud security platform of claim 3, the computerized method of claim 13, Kwatra further teaches: wherein the code analysis logic further comprises link detection logic communicatively coupled to the scanning logic, the link detection logic is configured to determine, based on a code identity associated with the laC code, existing or proposed cloud components affected by the laC code ([0066] For example, company A may define a way to check and block a serious new vulnerability that allows an attacker to download all the customer data from a web database. As company A shares this solution with the crowdsourced data aggregator on the blockchain, their cryptocurrency address is linked to this submission. Company B decides to include that submission within their environment. A week later, the intrusion detection system of company B detects a failed attack from someone trying to hack into the database which was prevented by the submission shared by company A). Same motivation as presented in claim 2, 12 would apply. Regarding claim 9, Hecht-Dang combination teaches the cloud security platform of claim 1, The combination of Hecht-Dang does not specifically teach the following, in the same field of endeavor Kwatra teaches: wherein the cloud security system is configured to communicate with security services each adapted to protect a corresponding cloud network, the cloud security system is configured to collect information associated with security threats pertaining to cloud environments within the corresponding cloud network to validate findings regarding the one or more security threats by the cloud service system (Kwatra, discloses systems and methods of automating software development, security, and operations, [Abstract]. And [0017] the methods, systems, and program products used in embodiments of the present disclosure incorporate security/policy compliance into a DevSecOps pipeline by crowdsourcing compliance recommendations to common compliance security/policy issues (e.g., threats, vulnerabilities) and using a reward system (e.g., a reputation score) to recognize useful recommendations. The crowdsourced compliance recommendations are used as training data to train a cognitive engine to generate compliance code for input source code. The trained cognitive engine can, in turn, generate compliance code for a given set of serverless cloud computing code. The reward system can employ a blockchain to track individual compliance recommendations and reward contributors of the compliance recommendations based on success of the compliance recommendations against actual security/policy issues). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Kwatra in the security risk assessment and control of Hecht-Dang by implementing software development with CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service. This would have been obvious because the person having ordinary skill in the art would have been motivated for automating software development, security, and operations (Kwatra, [Abstract], [0001-0002]). Regarding claim 19, Hecht-Dang combination teaches the non-transitory storage medium of claim 18, The combination of Hecht-Dang does not specifically teach the following, in the same field of endeavor Kwatra teaches: wherein the identifying of the one or more security threats is conducted by code analysis logic within a Continuous Integration and Continuous Deployment (Cl/CD) pipeline (e.g., [0016] receive source code written for a serverless function and API gateway and CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service, the events that trigger the function and the resources of a runtime environment). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Kwatra in the security risk assessment and control of Hecht-Dang by implementing software development with CI/CD pipeline configuration files, including infrastructure as code (IaC) files specifying configuration of the cloud service. This would have been obvious because the person having ordinary skill in the art would have been motivated for automating software development, security, and operations (Kwatra, [Abstract], [0001-0002]). Allowable Subject Matter Claims 5-7, 15-17, 20 are objected to as being dependent upon a rejected base claim(s), but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims as well as resolving of the identified issues of formalities and concerns under 35 USC 101 presented in this office action. The following is a statement of reasons for the indication of allowable subject matter: Claim 5 depends on claim 4 which depends on claim 3 which depends on claim 2 which depends on claim 1, further specifies “wherein the cloud security system comprises scanning ingestion logic communicatively coupled to the scanning logic and the link detection logic, the scanning ingestion logic is configured to (i) identify a cloud identity based on both the code identity and metadata included in the message from the code analysis logic, and (ii) generate a mapping that includes at least information associated with the one or more security threats and the cloud identity, wherein the cloud identity operates to identify one or more cloud components within the cloud environment protected by a cyber security platform affected by the one or more security threats”. Claim 6 depends on claim 5, further specifies “wherein the cloud security system further comprises security threat assessment logic configured to conduct a comparison between the mapping and one or more mappings associated with prior evaluations of code associated with the cloud identity including production code directed to the one or more cloud components associated with the cloud identity”. Claim 7 depends on claim 6, further specifies “wherein the cloud security system further comprises graph builder logic to generate a visualization of the one or more cloud components to be rendered by a graphical user interface (GUI) control unit deployed within a cyber security appliance”. Claim 15 depends on claim 14 which depends on claim 13 which depends on claim 12 which depends on claim 11 which depends on claim 10, further specifies “identifying a cloud identity corresponding to a code identity of the laC code; and generating a mapping that includes at least information associated with the one or more security threats and the cloud identity, wherein the cloud identity operates to identify one or more cloud components within the cloud infrastructure affected by the one or more security threats associated with a code submission”. Claim 16 depends on claim 15, further specifies “conducting a comparison between the mapping and one or more mappings associated with prior evaluations of code associated with the cloud identity including production code directed to the one or more cloud components within the cloud infrastructure”. Claim 17 depends on claim 16, further specifies “generating a visualization of the one or more cloud components to be rendered by a graphical user interface (GUI) control unit deployed within a cyber security appliance”. Claim 20 depends on claim 18, further specifies “scanning ingestion logic configured to (i) identify a cloud identity based on code identity and metadata included in the message, and (ii) generate a mapping that includes at least information associated with the one or more security threats and the cloud identity, wherein the cloud identity operates to identify one or more cloud components affected by the one or more security threats; and security threat assessment logic configured to conduct a comparison between the mapping and one or more mappings associated with prior evaluations of code associated with the cloud identity including production code directed to the one or more cloud components associated with the cloud identity, wherein the comparison identifies differences between the mapping and the one or more mappings to indicate whether additional security threats are caused by the code submission”. The prior arts identified, Hecht, Dang, Kwatra, Dinh, Philip, either singularly or in combination fails to anticipate or render obvious the claimed limitations of claims shown above. Citation of References The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action: Dinh et al (US11514171B2) discloses method for receiving code for computer programming, determining whether at least a portion of the code comprises at least one vulnerability, and comparing at least the portion of the code comprising the at least one vulnerability to a knowledge base. Philip (US20230214209A1) discloses method for monitoring and detecting security vulnerabilities in software code to be executed in a continuous integration and continuous delivery (CI/CD) environment. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL M LEE/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Feb 20, 2025
Application Filed
Jul 13, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706924
TECHNIQUES FOR DETECTING PERSISTENT DIGITAL ASSETS ON AN EXTERNAL ATTACK SURFACE
2y 9m to grant Granted Aug 11, 2026
Patent 12689611
Prioritization For Time-Deterministic Firewalls
1y 12m to grant Granted Jul 21, 2026
Patent 12676884
Spoofed UDP Packet Detection
2y 2m to grant Granted Jul 07, 2026
Patent 12671994
INTEGRITY PROTECTION FAILURE HANDLING METHOD AND APPARATUS, AND USER EQUIPMENT
3y 7m to grant Granted Jun 30, 2026
Patent 12665914
VEHICLE SECURITY ANALYSIS APPARATUS, AND METHOD AND PROGRAM STORAGE MEDIUM
2y 4m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+41.0%)
2y 9m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 273 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month