Prosecution Insights
Last updated: October 02, 2026
Application No. 19/073,103

METHOD AND SYSTEM FOR APPLICATION SECURITY POSTURE MANAGEMENT PRIOR TO ACQUISITION OF SOFTWARE APPLICATIONS

Final Rejection §103
Filed
Mar 07, 2025
Examiner
CHEN, SHIN HON
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Truist Bank
OA Round
2 (Final)
86%
Grant Probability
Favorable
3-4
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
700 granted / 812 resolved
+28.2% vs TC avg
Moderate +13% lift
Without
With
+13.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
25 currently pending
Career history
840
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
44.5%
+4.5% vs TC avg
§102
25.2%
-14.8% vs TC avg
§112
3.9%
-36.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 812 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 have been examined. Information Disclosure Statement The information disclosure statement (IDS) submitted on 8/27/26 is being considered by the examiner. Response to Arguments Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 11-13 and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. U.S. 2024/0143788 (hereinafter Chen) in view of Raghavendran et al. U.S. 11,436,127 (hereinafter Raghavendran). As per claim 1, 11 and 16, Chen discloses a method/system for certifying a level of security vulnerability of a software application from a developer prior to acquisition of the software application by an organization (Chen: Abstract: perform risk assessment of applications), the method/system comprising non-transitory storage device, processor and software security management application to perform the steps of: selecting a security vulnerability test to be performed on the software application (Chen: [0073]-[0075] and [0080]: determine tests to be performed based on security requirements); selecting an additional test to be performed on the software application (Chen: [0075]: update, remove or add security requirement over time); setting, an acceptable level of security vulnerability for the software application as determined by the security vulnerability test (Chen: [0027]: allowance indicator; [0084]: determine scope of evaluation); selecting a tester to perform the security vulnerability test (Chen: [0087]-[0092]); the tester performing the security vulnerability test on the software application (Chen: [0082]-[0092]: testing computer evaluates software based on security test requirements); the tester providing to the developer a full test report of results of the testing including a determined level of security vulnerability of the software application (Chen: [0025]: security evaluation report containing specific tests and rules); and when the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, the tester providing a certification report including verification that the security vulnerability test was performed and that the determined level of security vulnerability is equal to or is less than the acceptable level of security vulnerability, the certification report excluding disclosure of any security vulnerabilities discovered during performance of the security vulnerability test (Chen: [0026] and [0051]: security evaluation summary include brief statement of the main outcome of a security evaluation to indicate whether a development computer can proceed with distributing the evaluated software modules). Chen discloses that developer can submit request to have software/application evaluated. Chen does not explicitly disclose submitting software certification request by organization or software acquirer to be evaluated by third party tester that is distinct from both the developer and the organization, and providing a list of the security vulnerability test to be performed, information to be included in a full test report to the developer and information to be included in a certification report to the organization. However, Raghavendran discloses automated validation and authentication of software module wherein consumer of a software requests an independent third party testing entity to validate a software module from a producer of the software module (Raghavendran: Abstract; col. 2 lines 25-52: requesting independent third party tester to validate software based on various criteria, including security requirement; Fig. 6 and col. 6 line 54 – col. 7 line 26: operations performed by testing entity based on software module and parameters/attributes requested by consumer and producer). It would have been obvious to one having ordinary skill in the art to combine the teachings of Raghavendran and Chen because they are in the same field of endeavor of software/application testing. The motivation to combine would be to offer neutral attestation/certification of software applications instead of reliance on developer’s self-attestation of compliance. As per claim 2, 12 and 17, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified further discloses wherein the full test report includes details of all security vulnerabilities discovered during performance of the security vulnerability test (Chen: [0022]: pre-release report that provides rich feedback to application developer to make application more secure, reliable, efficient and performant; [0025]: security evaluation report shows how application performed in security assessment; Raghavendran: col. 7 lines 15-26). As per claim 3, 13 and 18, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified further discloses wherein the security vulnerability test is a dynamic application security test or an interactive application security test (Chen: [0086]-[0090]). Claims 4-10, 14, 15, 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Raghavendran and further in view of Dongle et al. U.S. 2025/0139252 (hereinafter Dongle). As per claim 4, 14 and 19, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified does not explicitly disclose when the determined level of security vulnerability exceeds the acceptable level of security vulnerability, the developer makes at least one change to the software application and the method returns to the step of the tester performing the security vulnerability test. However, Dongle discloses providing vulnerability test result to developer to further improve the application for retesting (Dongle: Figs. 3-4; [0081]-[0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities. As per claim 5, 15 and 20, Chen as modified discloses the limitations according to Claims 1, 11 and 16 respectively. Chen as modified does not explicitly disclose a step of selecting an additional test to be performed on the software application by the tester, the additional test being one of unit testing, dynamic application security testing, interactive application security testing, regression testing, integration testing, user acceptance testing, and performance testing. However, Dongle discloses performing additional vulnerability tests and iteratively improve and retest (Dongle: [0083]; [0090]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities. As per claim 6, Chen as modified discloses the method according to Claim 5. Chen as modified does not explicitly disclose when the results of the testing indicate that the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, performing the additional test on the software application and including results of the additional test in the full test report. However, Dongle discloses performing additional vulnerability tests and iteratively improve and retest (Dongle: Figs. 3-4; [0081]-0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities. As per claim 7, Chen as modified discloses the method according to Claim 1. Chen as modified does not explicitly disclose a step of selecting additional tests to be performed on the software application by the tester and, when the results of the testing indicate that the determined level of security vulnerability equals or is less than the acceptable level of security vulnerability, performing the additional tests on the software application and including results of the additional tests in the full test report (Dongle: Figs. 3-4; [0081]-0084]). It would have been obvious to one having ordinary skill in the art to iteratively test until vulnerability level is acceptable because the references are in the same field of endeavor. The motivation to combine would be to provide actionable feedback for developers to mitigate and address application vulnerabilities to meet required security level. As per claim 8, Chen as modified discloses the method according to Claim 7. Chen as modified further discloses including after each of the additional tests is performed checking whether all of the additional tests were performed (Dongle: Figs. 3-4; [0081]-0084]). Same rationale applies here as above in rejecting claim 7. As per claim 9, Chen as modified discloses the method according to Claim 7. Chen as modified further discloses when the results of the testing for each of the additional tests indicate that a determined level of security vulnerability equals or is less than an acceptable level of security vulnerability, including results of the additional test in the full test report and selecting another of the additional tests to be performed (Dongle: Figs. 3-4; [0081]-[0084]; [0090]). Same rationale applies here as above in rejecting claim 7. As per claim 10, Chen as modified discloses the method according to Claim 9. Chen as modified further discloses wherein the certification report includes verification that the additional tests were performed and that the software application equals or is less than the acceptable level of security vulnerability for each of the additional tests (Chen: Figs. 3-4; [0081]-[0084]; [0090]). Same rationale applies here as above in rejecting claim 7 for iteratively testing and correct application vulnerability. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Kabir et al. U.S. 12,561,448 discloses method for simulating application breaches. Gupta U.S. 9,268,672 discloses automated test case generation for applications using third party application tester. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHIN-HON (ERIC) CHEN/ Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Mar 07, 2025
Application Filed
Jun 10, 2026
Non-Final Rejection mailed — §103
Aug 20, 2026
Interview Requested
Aug 26, 2026
Examiner Interview Summary
Aug 26, 2026
Applicant Interview (Telephonic)
Sep 02, 2026
Response Filed
Sep 09, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744671
SYSTEM AND METHOD FOR AN ELECTRONIC IDENTITY BROKERAGE
2y 3m to grant Granted Sep 22, 2026
Patent 12737449
APPARATUS AND METHOD FOR HANDLING STASHING TRANSACTIONS
2y 11m to grant Granted Sep 15, 2026
Patent 12737462
DETECTION OF INDIRECT PROMPT INJECTION ATTACKS WITH MALICIOUS INSTRUCTIONS DETECTION MODELS
2y 4m to grant Granted Sep 15, 2026
Patent 12726498
METHOD TO DETECT VULNERABLE INTERNET SERVICES VIA CHANGES TO GLOBAL PORT-SCANNING TRAFFIC
2y 5m to grant Granted Sep 01, 2026
Patent 12688329
INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, AND STORAGE MEDIUM
1y 12m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
86%
Grant Probability
99%
With Interview (+13.4%)
2y 9m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 812 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month