Prosecution Insights
Last updated: October 02, 2026
Application No. 19/068,234

Cloud Service Provider (CSP) Event Capture and Processing System

Non-Final OA §101§103§112
Filed
Mar 03, 2025
Priority
Dec 19, 2024 — IN 202441100819
Examiner
ALLEN, BRITTANY N
Art Unit
2169
Tech Center
2100 — Computer Architecture & Software
Assignee
Zscaler Inc.
OA Round
1 (Non-Final)
42%
Grant Probability
Moderate
1-2
OA Rounds
2y 9m
Est. Remaining
80%
With Interview

Examiner Intelligence

Grants 42% of resolved cases
42%
Career Allowance Rate
170 granted / 403 resolved
-12.8% vs TC avg
Strong +38% interview lift
Without
With
+37.8%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
21 currently pending
Career history
436
Total Applications
across all art units

Statute-Specific Performance

§101
17.8%
-22.2% vs TC avg
§103
53.3%
+13.3% vs TC avg
§102
12.8%
-27.2% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 403 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Remarks This action is in response to the application received on 3/3/25. Claims 1-20 are pending in the application. Claims 1-20 are rejected under 35 U.S.C. 112. Claims 1-20 are rejected under 35 U.S.C. 101. Claims 1-9 and 11-19 are rejected under 35 U.S.C. 103 as being unpatentable over Martin et al. (US 2024/0154992), and further in view of Suttle et al. (US 2023/0342179). Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Martin in view of Suttle, and further in view of Sampat et al. (US 2022/0247660). Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 9, 11, and 19 recite the limitation "the change feeds." There is insufficient antecedent basis for this limitation in the claim. The recitation of “a change feed” in the “retrieving” limitation does not require multiple change feeds. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Step 2A, Prong One asks: Is the claim directed to a law of nature, a natural phenomenon (product of nature) or an abstract idea? See MPEP 2106.04 Part I. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. See MPEP 2106.04(a). With respect to claims 1 and 11, the limitation of “analyzing the change feeds to identify modifications of one or more resources”, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, “analyzing” in the context of this claim encompasses the user thinking about data. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. At step 2a, prong two, this judicial exception is not integrated into a practical application. Claim 11 recites a processor to execute the operations, however, this is recited as a high-level of generality (i.e., as a generic processor performing a generic computer function) such that it amounts to no more than mere instructions to apply the exception using a generic computer component. Additionally, the claim recites “retrieving a change feed,” “updating a data store,” and “providing a customer-specific dashboard.” These elements do not integrate the abstract idea into a practical application because they do not impose a meaningful limit on the judicial exception and provide only insignificant extra solution activity that is mere data gathering in conjunction with the abstract idea. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements amount to no more than mere instructions to apply an exception using generic computer components. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept. With respect to “retrieving a change feed”, the courts have found limitations directed towards data gathering to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information). With respect to “updating a data store”, the courts have found limitations directed towards storing to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Electronic recordkeeping, Alice Corp. Pty. Ltd. v. CLS Bank Int'l, 573 U.S. 208, 225, 110 USPQ2d 1984 (2014) (creating and maintaining "shadow accounts") and “storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015). With respect to “providing a customer-specific dashboard”, the courts have found limitations directed towards outputting to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Presenting offers and gathering statistics, OIP Techs., 788 F.3d at 1362-63, 115 USPQ2d at 1092-93. Considering the additional elements individually and in combination and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. The claim is not patent eligible. With respect to claims 2-4 and 12-14, the limitations further define limitations discussed above without integrating the abstract idea into a practical application. With respect to claims 5 and 15, the limitations are directed towards creating a connection via an API. An API is a generic computer component and the limitation amounts to no more than mere instructions to apply the exception using a generic computer component. With respect to claims 6 and 16, the limitations are directed towards “applying filtering logic.” This is a method of organizing human activity that describes managing personal behavior or relationships or interactions between people. See MPEP 2106.04(a)(2) Section II, Part C. With respect to claims 7 and 17, the limitations are directed towards generating real-time notifications. These elements do not integrate the abstract idea into a practical application because they do not impose a meaningful limit on the judicial exception and provide only insignificant extra solution activity that is mere data gathering in conjunction with the abstract idea. The courts have found limitations directed towards outputting to be well-understood, routine, and conventional. See MPEP 2106.05(d)(II). Presenting offers and gathering statistics, OIP Techs., 788 F.3d at 1362-63, 115 USPQ2d at 1092-93. With respect to claims 8 and 18, the limitations are directed towards “performing a full metadata scan” which is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, “performing a full metadata scan” in the context of this claim encompasses the user looking at data. With respect to claims 9, 10, 19, and 20, the limitations further define above discussed components without integrating the abstract idea into a practical application. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-9 and 11-19 are rejected under 35 U.S.C. 103 as being unpatentable over Martin et al. (US 2024/0154992), and further in view of Suttle et al. (US 2023/0342179). With respect to claim 1, Martin teaches the method implemented by a cloud-based system, the method comprising steps of: retrieving a change feed from one or more Cloud Service Providers (CSPs) associated with a customer of the cloud-based system (Martin, pa 0185, Process 1200 begins at step 1201, in which information is obtained about one or more cloud computing events from a cloud computing environment. The information about events may be contained within one or more cloud computing logs, such as logs 115 of FIG. 1); analyzing the change feeds to identify modifications of one or more resources within network environments associated with the customer (Martin, pa 0186, The information about cloud computing event(s) is analyzed in step 1202 to determine if the one or more events are associated with the allocation of storage to a cloud computing resource.), wherein the network environments are provided by the one or more CSPs (Martin, pa 0186, information related to a single event in which storage is attached to a cloud computing resource, such as an "Attach Volume" event in an AWS cloud computing environment may indicate the particular resource requires collection and analysis.); updating a data store of the customer with any new or modified resources based on the analyzing (Martin, pa 0111, The cloud collectors 431 may perform one or more operations on the collected cloud computing event information… filtering, grouping, translating, and enriching messages into data structures and/or jobs associated with data structures such as work jobs or work job messages); and Martin doesn't expressly discuss providing a customer-specific dashboard including analytics for all CSPs associated with the customer of the cloud-based system. Suttle teaches providing a customer-specific dashboard including analytics for all CSPs associated with the customer of the cloud-based system (Suttle, Fig. 2, AGENT dashboard with data from AWS and Azure & pa 0016, The system may also allow for fast access to compliance information for a company's cloud environment via robust dashboarding capability). It would have been obvious at the effective filing date of the invention to a person having ordinary skill in the art to which said subject matter pertains to have modified Martin with the teachings of Suttle because fast access to compliance information for a company's cloud environment (Suttle, pa 0016). With respect to claim 2, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Google Cloud Platform (GCP), and wherein the retrieving includes accessing the customers' GCP Audit Logs (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment… For example, in a Google Cloud Platform (GCP) Cloud the cloud computing log(s) may be a "Cloud Asset Inventory (CAI) Event Stream".). With respect to claim 3, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Amazon Web Services (AWS), and wherein the retrieving includes accessing the customers' AWS CloudTrail Events (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment. For example, in an Amazon Web Services (A WS) Cloud the cloud computing log(s) may be an AWS "CloudTrail" log.). With respect to claim 4, Martin in view of Suttle teaches the method of claim 1, wherein the one or more CSPs includes Microsoft Azure, and wherein the retrieving includes accessing the customers' Azure Activity Logs (Martin, pa 0069, the cloud computing logs are logs of a specific cloud computing environment.… For example, in an Azure cloud, the one or more log(s) may be an "Azure Security Logging and Auditing log" and/or an "Azure platform activity log".). With respect to claim 5, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise creating a connection to the one or more CSPs via Application Programing Interfaces (APIs) associated therewith, and wherein the retrieving is performed via the APIs. With respect to claim 6, Martin in view of Suttle teaches the method of claim 1, wherein the analyzing includes applying filtering logic to identify changes for specific resources in the network environments (Martin, pa 0108, One or more event subscriptions 317 allow information related to cloud computing events to be obtained from the logs 319A and 319B… event subscriptions 317 may be associated with specific event types, and therefore individual event subscriptions obtain certain events from logs 319Aand 319B. For example, event subscriptions 317 may only obtain information about cloud computing events which may or are likely to introduce security risks into the cloud computing environment 310). With respect to claim 7, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise generating real-time notifications based on the analyzing (Martin, pa 0159, display the determined security actions on a user interface of the information security system for an administrator of the system to analyze). With respect to claim 8, Martin in view of Suttle teaches the method of claim 1, wherein the steps comprise performing a full metadata scan of a resource based on the analyzing (Martin, pa 0158, Process 900 then proceeds to step 903 in which it is determined whether a security action is to be taken at least in part by analyzing the data and the supplemental data. & Suttle, pa 0007, identifying, by a processor, at least one of a creation of a cloud resource or a change to a configuration of the cloud resource (step 105); scanning, by the processor and in real-time, the configuration of the cloud resource, in response to the identifying (step 110); & pa 0022, “AGENT Scanner” may add additional capability in enriching the resource information by collecting resource metadata beyond what is provided by AWS by default as a service offering. For example, the resource state, annotations, tags, resource properties, etc. This data may allow the AGENT to take actions which are not by-default available in AWS services including, for example, triggering an auto remediation workflow, generating ServiceNow ITSM or checking if the non-compliant resource has an associated security exception.). With respect to claim 9, Martin in view of Suttle teaches the method of claim 8, wherein the full metadata scan is performed in response to one or more specific events identified in the change feeds (Martin, pa 0119, cloud worker 433B may determine additional analysis of the cloud computing event may be needed and therefore the event information is passed to security processing module 436.). With respect to claims 11-19, the limitations are essentially the same as claims 1-9, and are rejected for the same reasons. Claims 10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Martin in view of Suttle, and further in view of Sampat et al. (US 2022/0247660). With respect to claim 10, Martin in view of Suttle teaches the method of claim 8, as discussed above. Sampat teaches identifying malicious activity in response to a number of resources being altered surpassing a threshold (Sampat, pa 0066, the number of times a process restarted, changed, or crashed may be determined. A process that has been restarted more than a threshold number of times within the aggregation interval may indicate malicious activity associated with the process.). It would have been obvious at the effective filing date of the invention to a person having ordinary skill in the art to which said subject matter pertains to have modified Martin in view of Suttle with the teachings of Sampat because it indicates computing units that may be have malicious activity (pa 0019 & 0066). With respect to claim 20, the limitations are essentially the same as claim 10, and are rejected for the same reasons. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Pandurangi et al. (US 2022/0046059) teaches a cloud security posture management system for analyzing misconfigurations in cloud systems. Sobrier et al. (US 12,425,428) teaches activity monitoring of a cloud compute environment for security issues. Jim, Md Majadul Islam. "Cloud security posture management automating risk identification and response in cloud infrastructures." Academic Journal on Science, Technology, Engineering & Mathematics Education 4.3 (2024): 10-69593. This reference discusses a cloud security posture management system for automating risk identification and response in cloud infrastructures. Gujjala, Praveen Kumar Reddy. "Scalable and Intelligent Centralized Alerting Frameworks for Multi-Region Cloud Environments." International Journal of Scientific Research in Computer Science, Engineering and Information Technology (2024). This reference discusses a centralized alerting framework for enterprise cloud environments. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRITTANY N ALLEN whose telephone number is (571)270-3566. The examiner can normally be reached M-F 9 am - 5:00 pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Sherief Badawi can be reached at 571-272-9782. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRITTANY N ALLEN/ Primary Examiner, Art Unit 2169
Read full office action

Prosecution Timeline

Mar 03, 2025
Application Filed
Jul 06, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737358
Query Plan Adaptation Using Query Plan Fragments
2y 7m to grant Granted Sep 15, 2026
Patent 12711105
THREAD SAFE LOCK-FREE CONCURRENT WRITE OPERATIONS FOR USE WITH MULTI-THREADED IN-LINE LOGGING
2y 10m to grant Granted Aug 18, 2026
Patent 12705232
SYSTEMS AND METHODS FOR MANAGING OFFLINE DATABASE ACCESS
2y 11m to grant Granted Aug 11, 2026
Patent 12705216
STANDARDIZING A FILE FORMAT FOR QBM EXCHANGE AND INTEROPERABILITY
2y 6m to grant Granted Aug 11, 2026
Patent 12688094
GENERATING DIFFS BETWEEN ARCHIVES USING A GENERIC GRAMMAR
3y 6m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
42%
Grant Probability
80%
With Interview (+37.8%)
4y 4m (~2y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 403 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month