Prosecution Insights
Last updated: October 02, 2026
Application No. 19/059,036

Network Threat Prediction and Blocking

Non-Final OA §103§112
Filed
Feb 20, 2025
Priority
Jun 22, 2014 — provisional 62/015,436 +3 more
Examiner
TRUVAN, LEYNNA THANH
Art Unit
Tech Center
Assignee
Open Text Corporation
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
2y 1m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
397 granted / 519 resolved
+16.5% vs TC avg
Strong +20% interview lift
Without
With
+20.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
15 currently pending
Career history
540
Total Applications
across all art units

Statute-Specific Performance

§101
7.3%
-32.7% vs TC avg
§103
51.8%
+11.8% vs TC avg
§102
23.2%
-16.8% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 519 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The claim set of claims 1-20, filed on 3/4/2025, is acknowledged and considered. Claims 1-20 are pending. Claims 1, 8, and 15 are independent claims. Priority 3. The present application has relationship to: PRO 62015436, filing date 6/22/2014 CON 14745637, filing date 6/22/2015 DIV 16868669, filing date 5/7/2020 CON 17692901, filing date 3/11/2022 Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 4. Claims 1, 8, and 15 recites the limitation "the related online elements". There is insufficient antecedent basis for this limitation in the claim. Claim 1 (line 20-22), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation. Claim 8 (line 24-25), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation. Claim 15 (line 22-23), recite “the related online elements”, where related online elements was not previously recited, thus, lacks antecedent basis for this limitation. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph: Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. 5. Claims 11, 14 and 18 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claims 11 and 14 recites “the system of claim 8, further comprising: determining”, where the claim is directed to a method step. Thus, is directed towards two different statutory classes. The claim may be amended to recite ‘the system of claim 8, wherein the method further comprising’. Claim 18 recites “the computer program product of claim 15, further comprising: determining” where the claim is a method step, which is directed towards two different statutory classes. This claim may be amend to recite ‘the set of operations further comprising’. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements. Claim Objections 6. Claims 1, 8, and 15 are objected to because of the following informalities: Claim 1 (line), recite “portion of of”, where there is a repetitive term “of”. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 7. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over CP, et al [US 20150121449] in view of Kailash, et al. [US 20150163199]. As per claim 1: CP, et al. teaches a method for predicting and mitigating network threats, comprising: receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node] identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity] querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers] receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host] when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems] querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data referenced by the reputation and relationship tracking server; [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score] determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score] generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations] generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector] sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host] CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”. Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses. Claim 2: CP: para 0034 (i.e. IP address); discussing the method of claim 1, the network activity item comprises at least one of an IP address, a file, a software application, or a URL. Claim 3: CP: para 0020 (File reputation scores can be obtained by querying threat intelligence servers, locally or globally (e.g., in the cloud)); discussing the method of claim 1, wherein the querying to identify the related network activity having the known relationship comprises at least one of traversing a graph database, querying a relational database, or applying natural language processing techniques to textual data. Claim 4: CP: para 0020, 0045; discussing the method of claim 1, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees. Claim 5: CP: para 0031; discussing the method of claim 1, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors. Claim 6: CP: para 0030, 0096 (interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the method of claim 1, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call. Claim 7: CP: para 0020; discussing the method of claim 1, further comprising: determining if the initial reputation is known, and if the initial reputation is unknown, determining the initial reputation. As per claim 8: CP, et al. teaches a system comprising: at least one processor; and [CP: para Fig.9] memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, performs a method comprising: [CP: para Fig. 9, 0030] receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node] identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity] querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers] receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host] when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems] querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score] determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score] generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations] generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector] sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host] CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”. Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses. Claim 9: CP: para 0034 (i.e. IP address); discussing the system of claim 8, the network activity item comprises at least one of an IP address, a file, a software application, or a URL. Claim 10: CP: para 0020 (File reputation scores can be obtained by querying threat intelligence servers, locally or globally (e.g., in the cloud)); discussing the system of claim 8, wherein the querying to identify the related online elements having the known relationship comprises at least one of traversing a graph database, querying a relational database, or applying natural language processing techniques to textual data. Claim 11: CP: para 0020, 0045; discussing the system of claim 8, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees. Claim 12: CP: para 0031; discussing the system of claim 8, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors. Claim 13: CP: para 0030, 0096 (computing devices include interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the system of claim 8, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call. Claim 14: CP: para 0020; discussing the system of claim 8, further comprising: determining if the initial reputation is known, and if the initial reputation is unknown, determining the initial reputation. As per claim 15: CP, et al. teaches a computer program product comprising a non-transitory computer readable medium storing instructions executable by a processor to perform a set of operations for network threat prediction and blocking, the set of operations comprising: receiving, at a first computing device, a network activity log from a security device, wherein the network activity log identifies a network activity over a network; [CP: para 0015; network security device is out-of-band sends network traffic to end host. Para 0027; network security device receive network traffic associated with end host and forward the network traffic to a local or remote destination node. The “first computing device” may be in the form of a host or node] identifying, by the first computing device, a network activity item from the received network activity log, wherein the network activity item is associated with the network activity over the network; [CP: para 0029; network traffic, which is inclusive of packets, frames, signals, data, etc.. Messages, requests, responses, and queries are forms of network traffic, and therefore, may comprise packets, frames, signals, data Network activity can broadly be in the form of traffic which include packets or data of a communication message of the network. Thus, a network activity item may be the message, a query, request or packet that stem of the network traffic activity] querying, by the first computing device, a reputation and relationship tracking server for an initial reputation for the network activity item; [CP: para 0020; File reputation scores (i.e. initial reputation) can be obtained by querying threat intelligence servers] receiving, by the first computing device, the initial reputation from the reputation and relationship tracking server; [CP: para 0025; a bad TI reputation score for an application is provided to an end host] when the initial reputation for the network activity item is malicious; [CP: para 0020; A file reputation score (also referred to herein as `threat intelligence score) can be a score that reflects the likelihood a particular file (i.e., an application or other module) is malicious. File reputation scores can be configured to range, for example, on a scale from benign to malicious, or good to bad. Para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] generating, at the first computing device, a threat vector for the network activity item; [CP: para 0017; Malware include propagation vectors that enable it to spread within an organization's network (e.g., a protected network) or across other networks or computer systems] querying, by the first computing device, the reputation and relationship tracking server to identify related network activity having an identified relationship to the threat vector [CP: para 0020; Threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors such as web, email and network threat data, etc.], the identified relationship based on relationship data [CP: para 0034; endpoint intelligence server of network security device and endpoint intelligence agent of end host cooperate to identify malicious applications associated with network traffic traversing, or attempting to traverse, computing system] determining, by the first computing device, related reputations for the identified related network activity; [CP: para 0146; request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score] determining a portion of of the related reputations for the related online elements that are malicious; [CP: para 0146; where the action is determined based, at least in part, on the other threat intelligence reputation score] generating, by the first computing device, a related threat vector for each related reputation in the portion of the related reputations that is malicious; [CP: para 0020; derive file reputation scores for hashes including correlation with other threat vectors. Para 0165; the endpoint intelligence agent to request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, where the action is determined based, at least in part, on the other threat intelligence reputation score. The threat intelligence reputation score is based on a hash and in part on the other threat intelligence reputation score, suggest the generated related threat vector for the related reputation in the portion of the related malicious reputations] generating, by the first computing device, a malicious list from the threat vector and any related threat vector; and [CP: para 0045; threat intelligence information comprise whitelists or blacklists where a blacklist include hash values of applications and other modules that have been determined to contain malware and/or to engage in malicious behavior. See also para 0098; another example of malicious list. As discussed above, file reputation score (also referred to herein as `threat intelligence score) and threat intelligence servers derive file reputation scores for hashes including correlation with other threat vectors, see para 0020, 0146. Thus, the threat intelligence information includes reputation score include correlation with threat vectors, suggests the black or malicious list is based on threat vector and related vector] sending the malicious list to the security device. [CP: para 0098; if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host] CP discusses if a DLL module is classified as malicious based on the administrator blacklist, then its associated application may also be classified as malicious. The action information can be sent to end host [CP: para 0098]. This suggest sending the malicious list. However, “sending the malicious list to the security device”. Kailash teaches a method includes logging transactions and events associated with users of an enterprise network in a management system on the enterprise network and communicating with a cloud system through a secure connection outside the enterprise network, wherein receiving log data through the secure connection from the cloud system for the at least one user, wherein the log data includes transactions and events associated with the at least one user and associated usage of the cloud-based services and integrating the log data in the management system [Kailash: para 0008]. Referring to FIG. 1, illustrates a distributed security system that includes content processing nodes that proactively detect and preclude the distribution of security threats, e.g., malware, spyware, viruses, trojans, botnets, email spam, data leakage, policy violations, etc. [Kailash: para 0020]. The “security device” may be in the form of a processing node since the processing node proactively detect and preclude the distribution of security threats. Kailash further includes the processing nodes that can communicate with one or more authority nodes. The authority nodes distribute the policy data to the processing nodes and also distribute threat data that includes the classifications of content items according to threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, a list of known phishing sites, list of data leakage prevention terms, etc. The distribution of threat data between the processing nodes and the authority nodes can implemented by push and pull distribution schemes [Kailash: para 0024]. The processing node can use the information in the local detection processing filter to quickly determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. The authority node can also store master threat data. The master threat data can classify content items by threat classifications, e.g., a list of known viruses, a list of known malware sites, spam email domains, list of known or detected phishing sites, data leakage terms, etc. [Kailash: para 0041]. As such, one would be motivated to “sending the malicious list to the security device”, is for security purposes of using the information to determine the presence and/or absence of information, e.g., whether a particular URL has been checked for malware; whether a particular executable has been virus scanned, etc. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Kailash with CP to teach “sending the malicious list to the security device” for the reason to provide the information for using the information to determine the presence and/or absence of information, such as check for malware or viruses. Claim 16: CP: para 0034 (i.e. IP address); discussing the computer program product of claim 15, the network activity item comprises at least one of an IP address, a file, a software application, or a URL. Claim 17: CP: para 0023 (query a threat intelligence server to obtain a file reputation score); discussing the computer program product of claim 15, wherein the known relationship is based on the related network activity being hosted on the same server infrastructure. Claim 18: CP: para 0020, 0045; discussing the computer program product of claim 15, further comprising: determining a degree of separation between the threat vector and the related network activity, wherein the related network activity is identified when the degree of separation is less than a predetermined threshold of separation degrees. Claim 19: CP: para 0031; discussing the computer program product of claim 15, wherein the security device is a firewall, the firewall blocking network traffic associated with any related threat vectors. Claim 20: CP: para 0030, 0096 (computing devices include interfaces employing any suitable connection (wired or wireless) for receiving, transmitting, and/or otherwise communicating data or information in computing system, suggest API call); discussing the computer program product of claim 15, wherein querying the reputation and relationship tracking server comprises making an Application Programming Interface (API) call. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Leynna Truvan whose telephone number is (571)272-3851. The examiner can normally be reached Monday-Friday 9:00AM-5:00PM, EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Leynna Truvan Examiner Art Unit 2435 /L.TT/Examiner, Art Unit 2435 /EDWARD ZEE/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Feb 20, 2025
Application Filed
Aug 25, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750217
SIGN-EFFICIENT ADDITION AND SUBTRACTION FOR STREAMINGCOMPUTATIONS IN CRYPTOGRAPHIC ENGINES
4y 2m to grant Granted Sep 29, 2026
Patent 12744819
FRICTIONLESS SUPPLEMENTARY MULTI-FACTOR AUTHENTICATION FOR SENSITIVE TRANSACTIONS WITHIN AN APPLICATION SESSION
2y 2m to grant Granted Sep 22, 2026
Patent 12726371
METHOD AND APPARATUS FOR CONTROLLING TITLE TO A PHYSICAL OBJECT
3y 3m to grant Granted Sep 01, 2026
Patent 12695616
NON-FUNGIBLE TOKENS FOR VIRTUAL ACCESSORIES DURING VIRTUAL MEETINGS
4y 0m to grant Granted Jul 28, 2026
Patent 12695611
METHODS AND SYSTEMS FOR GENERATING, SUBSCRIBING TO AND PROCESSING ACTION PLANS USING A BLOCKCHAIN
3y 4m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
97%
With Interview (+20.1%)
3y 9m (~2y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 519 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month