Prosecution Insights
Last updated: August 16, 2026
Application No. 19/074,800

USER ACTIVITY-TRIGGERED URL SCAN

Non-Final OA §103§DP
Filed
Mar 10, 2025
Priority
Jul 09, 2019 — continuation of 11/411,991 +1 more
Examiner
CHAMPAKESAN, BADRI NARAYANAN
Art Unit
Tech Center
Assignee
McAfee LLC
OA Round
1 (Non-Final)
91%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 91% — above average
91%
Career Allowance Rate
352 granted / 386 resolved
+31.2% vs TC avg
Strong +55% interview lift
Without
With
+55.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
23 currently pending
Career history
396
Total Applications
across all art units

Statute-Specific Performance

§101
4.5%
-35.5% vs TC avg
§103
55.5%
+15.5% vs TC avg
§102
10.0%
-30.0% vs TC avg
§112
15.2%
-24.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 386 resolved cases

Office Action

§103 §DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 58-77 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims of U.S. Patent No. 11411991, 12273384. Although the claims at issue are not identical, they are not patentably distinct from each other because the claimed concept is anticipated by the said patents. Instant app. 19074800 Pat. #: 12273384 Pat. #: 11411991 58. (New) A computer-implemented method of protecting a user from phishing attacks, comprising: determining that the user has initiated a command via a web browser that will send information to a target website, wherein the information is of a class that may include sensitive information about the user, and wherein the target website does not have a device-local phishing reputation; after the determining, pausing the command before the information is sent; while the command is paused, getting a new reputation for the target website; and blocking the command if the new reputation is not safe. 59. (New) The method of claim 58, further comprising unpausing the command and allowing the command to complete if the new reputation is positive. 60. (New) The method of claim 58, wherein the new reputation comprises a phishing reputation. 61. (New) The method of claim 58, wherein the new reputation comprises a security reputation. 62. (New) The method of claim 58, wherein the new reputation comprises an enterprise policy reputation. 63. (New) The method of claim 58, wherein the command is an HTML POST operation. 64. (New) The method of claim 58, wherein getting the new reputation comprises performing a device-local analysis of the target website. 65. (New) The method of claim 64, wherein the device-local analysis requires a human perceptible time. 66. (New) The method of claim 58, wherein getting the new reputation comprises querying a cloud service for the new reputation. 67. (New) The method of claim 58, further comprising determining that the target website has a device-local phishing reputation, determining that the device-local phishing reputation is safe, and not pausing the command. 68. (New) The method of claim 58, further comprising querying a local reputation cache to determine if the target website has the device-local phishing reputation. 69. (New) The method of claim 68, further comprising adding the new reputation to the local reputation cache. 70. (New) One or more tangible, nontransitory computer-readable storage media having stored thereon instructions to instruct a processor to: determine that a user has initiated a command via a web browser that will send information to a target website, wherein the information is of a class that includes sensitive information about the user, and wherein the target website does not have a device-local phishing reputation; after the determining, pause the command before the information is sent; while the command is paused, get a new reputation for the target website; and block the command if the new reputation is not safe. 71. (New) The one or more tangible, nontransitory computer-readable storage media of claim 70, further comprising instructions to instruct the processor to unpause the command and allow the command to complete if the new reputation is known safe. 72. (New) The one or more tangible, nontransitory computer-readable storage media of claim 70, wherein the command is an HTML POST operation. 73. (New) The one or more tangible, nontransitory computer-readable storage media of claim 70, wherein getting the new reputation comprises performing a device-local analysis of the target website. 74. (New) The one or more tangible, nontransitory computer-readable storage media of claim 70, further comprising instructions to instruct the processor to query a local reputation cache to determine if the target website has the device-local phishing reputation. 75. (New) The one or more tangible, nontransitory computer-readable storage media of claim 74, further comprising instructions to instruct the processor to add the new reputation to the local reputation cache. 76. (New) A computing apparatus, comprising: a processor circuit; a memory; and instructions encoded within the memory to instruct the processor circuit to: determine that a user has initiated a command via a web browser that will send information to a target website, wherein the information is of a class that includes sensitive information about the user, and wherein the target website does not have a device-local phishing reputation; after the determining, pause the command before the information is sent; while the command is paused, get a new reputation for the target website; and block the command if the new reputation is not safe. 77. (New) The computing apparatus of claim 76, wherein the instructions further instruct the processor circuit to unpause the command and allow the command to complete if the new reputation is known safe. 1. A method of protecting a user of a device from phishing attacks, comprising: detecting an attempted hypertext markup language (HTML) POST operation by the user on a website; after detecting the HTML POST operation, pausing the HTML POST operation before the device sends data associated with the HTML POST operation to the website; getting a reputation for the website; and based on determining that the reputation is a good reputation, unpausing the HTML POST operation, or based on determining that the reputation is a bad reputation, taking a remedial action, wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation against policy for an enterprise that the device belongs to or connects to. 2. (Original) The method of claim 1, wherein getting the reputation comprises querying a cloud-based reputation store. 3. (Original) The method of claim 1, wherein getting the reputation comprises analyzing the website for phishing features. 4. (Original) The method of claim 3, wherein analyzing the website for phishing features comprises analyzing the website on the device. 5. (Original) The method of claim 3, wherein analyzing the website for phishing features comprises sending the website or features of the website to a cloud service for analysis. 6. (Original) The method of claim 1, wherein getting the reputation comprises getting a reputation for a uniform resource locator (URL) of the website. 7. (Original) The method of claim 1, wherein determining that the reputation is a good reputation comprises determining that the website has a reputation as a legitimate website. 8. (Original) The method of claim 1, wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation as a phishing website. 9. (Original) The method of claim 1, wherein determining that the reputation is a bad reputation comprises determining that the website has a reputation as a malware website. 10. (Canceled) 11. (Previously Presented) The method of claim 1, wherein the remedial action comprises blocking the website. 12. (Previously Presented) The method of claim 1, wherein the remedial action comprises warning the user. 13. One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to instruct a processor circuit to: intercept an attempted hypertext markup language (HTML) POST operation initiated by a user on a website; after intercepting the HTML POST operation, pause the HTML POST operation before sending any data associated with the HTML POST operation to the website; while the HTML POST operation is paused, get a reputation for the website, wherein the reputation includes a policy for an enterprise; and based on the reputation, determine whether to allow the HTML POST operation or to take a remedial action. 14. (Original) The one or more tangible, non-transitory computer-readable media of claim 13, wherein getting the reputation comprises querying a cloud based reputation store. 15. (Original) The one or more tangible, non-transitory computer-readable media of claim 13, wherein getting the reputation comprises analyzing the website for phishing features. 16. (Original) The one or more tangible, non-transitory computer-readable media of claim 15, wherein analyzing the website for phishing features comprises analyzing the website on a local device. 17. (Original) The one or more tangible, non-transitory computer-readable media of claim 15, wherein analyzing the website for phishing features comprises sending the website or features of the website to a cloud service for analysis. 18 - 24. (Canceled) 25. A computing apparatus, comprising: a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to: intercept a hypertext markup language (HTML) POST operation initiated by a user for a website; suspend the HTML POST operation before the computing apparatus sends data associated with the HTML POST operation to the website; get a reputation for the website, wherein the reputation includes a policy for an enterprise that the computing apparatus connects to; and based on the reputation, determine whether to unsuspend the HTML POST operation or to take a remedial action. 26. (Original) The computing apparatus of claim 25, wherein getting the reputation comprises querying a cloud-based reputation store. 27. (Original) The computing apparatus of claim 25, wherein getting the reputation comprises analyzing the website for phishing features. 28 - 36. (Canceled) 1. A computing apparatus, comprising: a hardware platform comprising a processor and a memory; a network interface; a user-space application comprising instructions to interact with a web site via a uniform resource locator (URL); and a security agent comprising instructions to: intercept an interaction of the user-space application with the web site; determine that the intercepted interaction is a hypertext markup language (HTML) POST operation that will send information to the web site; based at least in part on detecting the HTML POST operation, suspend the interaction; while the interaction is suspended, assign a reputation to the URL comprising analyzing code of the web site for phishing features, wherein assigning the reputation comprises querying a user-configurable scan aggressiveness option, and performing a scan of code of the web site for phishing features according to the user-configurable scan aggressiveness option; and upon determining that phishing features are found, warn a user of the computing apparatus while the interaction is suspended. 2. (Original) The computing apparatus of claim 1, wherein the security agent is further to take a security action based at least in part on the reputation of the URL. 3. (Original) The computing apparatus of claim 1, wherein assigning the reputation to the URL comprises performing a deep security analysis of the web site. 4. (Canceled) 5. The computing apparatus of claim 1, wherein assigning the reputation comprises querying a user feature for a deep analysis flag, and performing deep analysis only if upon determining that the deep analysis flag is set. 6. (Original) The computing apparatus of claim 5, further comprising determining that the deep analysis flag is not set, and warning the user of a potential for data loss because the web site has not been analyzed via deep analysis. 7. (Canceled) 8. The computing apparatus of claim 1, wherein the security agent is further to warn the user upon determining that the user-configurable scan aggressiveness option is set below a threshold. 9. (Original) The computing apparatus of claim 1, wherein the security agent is further to warn the user of potential data loss, and send sensitive information only after receiving confirmation from the user. 10. (Original) The computing apparatus of claim 9, wherein the security agent is further to cache a response from the user in a response cache. 11. (Original) The computing apparatus of claim 10, wherein the security agent is further to: query the response cache; determine that the user has previously permitted sensitive information to be submitted to the web site; and permit the sensitive information to be submitted without requiring a further response from the user. 12. (Original) The computing apparatus of claim 1, wherein assigning the reputation to the web site comprises querying a cloud-based reputation cache, and receiving a reputation for the web site from the cloud-based reputation cache. 13. (Currently Amended) The computing apparatus of claim 12, wherein assigning the reputation to the web site further comprises first querying a local cache of the cloud-based reputation cache, and querying the cloud-based reputation cache only if upon determining that no locally cached reputation exists in the local cache. 14. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions to instruct a processor to: insert or register operating system hooks to enable interception of user-space processes; determine that a user-space process is attempting to interact with an internet resource identified by a uniform resource locator (URL) via a hypertext markup language (HTML) POST operation; suspend the attempt based at least in part on identifying the HTML POST operation; while the attempt is suspended, assign a reputation to the URL, comprising analyzing code of a web site at the URL for phishing features, wherein analyzing the code of the web site comprises querying a user-configurable scan aggressiveness option, and performing a scan of code of the web site for phishing features according to the user-configurable scan aggressiveness option.; and upon determining that phishing features are found, warn a user while the attempt is suspended. 15. (Original) The one or more tangible, non-transitory computer-readable mediums of claim 14, wherein assigning the reputation to the web site comprises querying a cloud-based reputation cache, and receiving a reputation for the web site from the cloud-based reputation cache. 16. (Currently Amended) The one or more tangible, non-transitory computer-readable mediums of claim 15, wherein assigning the reputation to the web site further comprises first querying a local cache of the cloud-based reputation cache, and querying the cloud-based reputation cache only if upon determining that no locally cached reputation exists in the local cache. 17. (Original) The one or more tangible, non-transitory computer-readable mediums of claim 15, wherein assigning the reputation to the web site further comprises determining that a cloud-based reputation from the cloud-based reputation cache is unknown, and triggering a local deep analysis of the internet resource. 18. A computer-implemented method of providing browser-based phishing mitigation for a web site, the method comprising: detecting a user interaction with a web site via the browser, the user interaction comprising a hypertext markup language (HTML) POST operation; suspending the user interaction based at least in part on detecting the HTML POST operation; while the user interaction is suspended, assigning a reputation to the web site, comprising analyzing the web site’s code for phishing features, wherein assigning the reputation comprises querying a user-configurable scan aggressiveness option, and performing a scan of code of the web site for phishing features according to the user-configurable scan aggressiveness option.; and upon determining that phishing features are found, while the user interaction is suspended, warn a user who initiated the user interaction. 19. (Original) The computer-implemented method of claim 18, wherein assigning the reputation to the web site comprises performing a deep security analysis of the web site. 20. The computer-implemented method of claim 19, wherein the deep security analysis comprises analyzing code of the web site for phishing features. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 58 – 62, 64 – 71, 73 – 77 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dixon et al (US 20140331119), hereafter Dix and Palumbo et al (US 20140090055), Pal. Claim 58: Dix teaches a computer-implemented method of protecting a user from phishing attacks, comprising: determining that the user has initiated a command via a web browser that will send information to a target website, ([128, 140, Fig. 4] a user may provide an Internet request (e.g. a search request or URL address request), and a reputation analysis may be performed in conjunction with the request [142] via a Web browser application and a proxy application running on the client). wherein the information is of a class that may include sensitive information about the user, ([354] personal or otherwise sensitive information may be requested during the authentication and validate procedures); and wherein the target website does not have a device-local phishing reputation; ([08, 142] A local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally. [149] the reputation service host does not contain any information about site C. [035] the indicia of the website's reputation may include indicia of a website's reputation for ... a website's reputation for providing phishing); while the command is paused, getting a new reputation for the target website; and blocking the command if the new reputation is not safe. ([037] the user may be prevented from interacting with the website, [99, Fig. 8] The reputation service host may, for example, monitor an address or URL entered into an address bar of a browser application associated with the client, and, after the user has entered the address, the reputation service host provides an alert to the user that the Website that the user is about to interact with has a reputation for downloading spyware, malware, or other unwanted content). Dix is silent on after the determining, pausing the command before the information is sent; But the analogous art Pal teaches after the determining, pausing the command before the information is sent; ([03] suspending said sharing and performing, by the processing device before determining whether or not to allow the sharing). Therefore, it is prima facie obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Dix to pause sending data as taught by Pal so that the security and user experience are improved ([023]). Claim 59: the combination of Dix and Pal teaches the method of claim 58, further comprising unpausing the command and allowing the command to complete if the new reputation is positive. (Dix: [127] allowing the user to enter the URL, having the reputation service host identify the URL, and comparing the URL to known URLs with associated reputation information, and then allowing the browser to continue the action of connecting to the site). Claim 60: the combination of Dix and Pal teaches the method of claim 58, wherein the new reputation comprises a phishing reputation. (Dix: [035] the indicia of the website's reputation may include indicia of a website's reputation for treatment of personal information, of a website's reputation for providing unwanted content, of a website's reputation for providing malware, of a website's reputation for providing spam, of a website's reputation for providing phishing, or of a website's reputation of being a decoy). Claim 61: the combination of Dix and Pal teaches the method of claim 58, wherein the new reputation comprises a security reputation. (Dix: [014] whether the site adheres to common security practices (e.g. uses SSL, etc)). Claim 62: the combination of Dix and Pal teaches the method of claim 58, wherein the new reputation comprises an enterprise policy reputation. (Dix: [177] If the user indicated that the site was a risky e-commerce site, then the user is also given the opportunity to provide additional information about why the site is a risky e-commerce site. For example, the user may be provided with a choice among the following categories: customer service, return policy, shipping time, poor product quality, didn't receive product as advertised, or will shop again). Claim 64: the combination of Dix and Pal teaches the method of claim 58, wherein getting the new reputation comprises performing a device-local analysis of the target website. (Dix: [142] there may also be a local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally). Claim 65: the combination of Dix and Pal teaches the method of claim 64, wherein the device-local analysis requires a human perceptible time. (Dix: [0147] A Web reputation service may involve a real-time database query interface for looking up the reputation of Web sites, programs, Web forms, and other such content. Sites classified, for example as categories such as of "OK", "Adware Distributor", "Risky E-Commerce", and so forth; [0186] Fig. 8 a warning window displayed by the reputation service host in response to detecting a threat on the current Website). Claim 66: the combination of Dix and Pal teaches the method of claim 58, wherein getting the new reputation comprises querying a cloud service for the new reputation. (Dix: [0325] an interactive reputation platform deployed in association with any of the communications identified in connection with Fig. 19. For example, the use of interactive reputation services from a client, a remote site employs such techniques to identify potentially low reputation e-commerce systems... An interactive reputation platform deployed in connection with the communications between a user and the remote site, and the platform monitors potential or actual interactions between the site and the other facilities identified in connection, such as the central processing facilities or e-commerce system). Claim 67: the combination of Dix and Pal teaches the method of claim 58, further comprising determining that the target website has a device-local phishing reputation, determining that the device-local phishing reputation is safe, and not pausing the command. (Dix: [08] the provision of a real time database query interface for lookup up the reputation of Web content, such as a Web site, an executable application, a script, a Web form, and so forth; the caching of the results of this real time database locally on client computers to improve performance. [142] there may also be a local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally, [169] A site might be certified as safe to use based on the site having various other characteristics such as the site's popularity according to available reputation services [141] the system (e.g. the reputation service host) allows the information to be provided). Claim 68: the combination of Dix and Pal teaches the method of claim 58, further comprising querying a local reputation cache to determine if the target website has the device-local phishing reputation. (Dix: [142] there may also be a local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally, [289] The client may cache information locally as it is looked up). Claim 69: the combination of Dix and Pal teaches the method of claim 68, further comprising adding the new reputation to the local reputation cache. (Dix: [08] the caching of the results of this real time database locally on client computers to improve performance; [142] This information may be cleared out of the cache, or modified, when new threat information is associated with stored information or there is a change in the reputation status of a site, or for other such reasons). Claim 70: Dix teaches one or more tangible, nontransitory computer-readable storage media having stored thereon instructions to instruct a processor to [309, Fig. 18]: determine that a user has initiated a command via a web browser that will send information to a target website, wherein the information is of a class that includes sensitive information about the user, and wherein the target website does not have a device-local phishing reputation; while the command is paused, get a new reputation for the target website; and block the command if the new reputation is not safe. ([140, Fig. 4] a user may provide an Internet request (e.g. a search request or URL address request), and a reputation analysis may be performed in conjunction with the request [142] via a Web browser application and a proxy application running on the client; [354] personal or otherwise sensitive information may be requested during the authentication and validate procedures; [08, 142] A local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally. [149] the reputation service host does not contain any information about site C. [035] the indicia of the website's reputation may include indicia of a website's reputation for ... a website's reputation for providing phishing; [99, Fig. 8] The reputation service host may, for example, monitor an address or URL entered into an address bar of a browser application associated with the client, and, after the user has entered the address, the reputation service host provides an alert to the user that the Website that the user is about to interact with has a reputation for downloading spyware, malware, or other unwanted content). Dix is silent on after the determining, pause the command before the information is sent; But the analogous art Pal teaches after the determining, pause the command before the information is sent; ([03] suspending said sharing and performing, by the processing device before determining whether or not to allow the sharing). Therefore, it is prima facie obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Dix to pause sending data as taught by Pal so that the security and user experience are improved ([023]). Claim 71: the combination of Dix and Pal teaches the one or more tangible, nontransitory computer-readable storage media of claim 70, further comprising instructions to instruct the processor to unpause the command and allow the command to complete if the new reputation is known safe. (Dix: [127] allowing the user to enter the URL, having the reputation service host identify the URL, and comparing the URL to known URLs with associated reputation information, and then allowing the browser to continue the action of connecting to the site). Claim 73: the combination of Dix and Pal teaches the one or more tangible, nontransitory computer-readable storage media of claim 70, wherein getting the new reputation comprises performing a device-local analysis of the target website. (Dix: [142] there may also be a local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally). Claim 74: the combination of Dix and Pal teaches the one or more tangible, nontransitory computer-readable storage media of claim 70, further comprising instructions to instruct the processor to query a local reputation cache to determine if the target website has the device-local phishing reputation. (Dix: [142] there may also be a local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally. [035] the indicia of the website's reputation may include indicia of a website's reputation for ... of a website's reputation for providing phishing). Claim 75: the combination of Dix and Pal teaches the one or more tangible, nontransitory computer-readable storage media of claim 74, further comprising instructions to instruct the processor to add the new reputation to the local reputation cache. (Dix: [08] the caching of the results of this real time database locally on client computers to improve performance; [142] This information may be cleared out of the cache, or modified, when new threat information is associated with stored information or there is a change in the reputation status of a site, or for other such reasons). Claim 76: Dix teaches a computing apparatus, comprising: a processor circuit; a memory; and instructions encoded within the memory to instruct the processor circuit to [309, Fig. 18]: determine that a user has initiated a command via a web browser that will send information to a target website, wherein the information is of a class that includes sensitive information about the user, and wherein the target website does not have a device-local phishing reputation; while the command is paused, get a new reputation for the target website; and block the command if the new reputation is not safe. ([140, Fig. 4] a user may provide an Internet request (e.g. a search request or URL address request), and a reputation analysis may be performed in conjunction with the request [142] via a Web browser application and a proxy application running on the client; [354] personal or otherwise sensitive information may be requested during the authentication and validate procedures; [08, 142] A local cache on the client device such that the frequently/recently accessed content has its reputation, or indicia of its reputation, stored locally. [149] the reputation service host does not contain any information about site C. [035] the indicia of the website's reputation may include indicia of a website's reputation for ... a website's reputation for providing phishing; [99, Fig. 8] The reputation service host may, for example, monitor an address or URL entered into an address bar of a browser application associated with the client, and, after the user has entered the address, the reputation service host provides an alert to the user that the Website that the user is about to interact with has a reputation for downloading spyware, malware, or other unwanted content). Dix is silent on after the determining, pause the command before the information is sent; But the analogous art Pal teaches after the determining, pause the command before the information is sent; ([03] suspending said sharing and performing, by the processing device before determining whether or not to allow the sharing). Therefore, it is prima facie obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Dix to pause sending data as taught by Pal so that the security and user experience are improved ([023]). Claim 77: the combination of Dix and Pal teaches the computing apparatus of claim 76, wherein the instructions further instruct the processor circuit to unpause the command and allow the command to complete if the new reputation is known safe. (Dix: [127] allowing the user to enter the URL, having the reputation service host identify the URL, and comparing the URL to known URLs with associated reputation information, and then allowing the browser to continue the action of connecting to the site). Claim(s) 63, 72 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dix and Pal as applied to claims above, and further in view of Wyn-Harris; Jeremy (US 20130133048), Wyn. Claim 63: the combination of Dix and Pal teaches the method of claim 58, but is silent on wherein the command is an HTML POST operation. But analogous art Wyn teaches wherein the command is an HTML POST operation. ([355] request may be in the form of a Java remote method invocation, an HTTP POST request (a URL request)). Therefore, it is prima facie obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined inventions of Dix and Pal to use HTML Post as taught by Wyn thereby preventing an imposter from making pre-recordings of one or more of the prompted actions [356]. Claim 72: the combination of Dix and Pal teaches the one or more tangible, nontransitory computer-readable storage media of claim 70, but is silent on wherein the command is an HTML POST operation. But analogous art Wyn teaches wherein the command is an HTML POST operation. ([355] request may be in the form of a Java remote method invocation, an HTTP POST request (a URL request)). Therefore, it is prima facie obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combined inventions of Dix and Pal to use HTML Post as taught by Wyn thereby preventing an imposter from making pre-recordings of one or more of the prompted actions [356]. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See form PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Badri Champakesan whose telephone number is (571)270-3867. The examiner can normally be reached M-F: 8.30am-4.30pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BADRINARAYANAN /Primary Examiner, Art Unit 2494.
Read full office action

Prosecution Timeline

Mar 10, 2025
Application Filed
Jul 17, 2026
Non-Final Rejection mailed — §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689639
DETECTING ANOMALOUS NETWORK BEHAVIOR IN OPERATIONAL TECHNOLOGY PROTOCOLS
3y 0m to grant Granted Jul 21, 2026
Patent 12689636
TECHNIQUES FOR INCIDENT RESPONSE AND STATIC ANALYSIS REPRESENTATION IN COMPUTING ENVIRONMENTS
1y 8m to grant Granted Jul 21, 2026
Patent 12676868
Pattern Analysis Threat Identification
2y 12m to grant Granted Jul 07, 2026
Patent 12675561
MODULAR DATA CENTER
1y 11m to grant Granted Jul 07, 2026
Patent 12675758
NESTED MODEL STRUCTURES FOR THE PERFORMANCE OF COMPLEX TASKS
1y 8m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
91%
Grant Probability
99%
With Interview (+55.4%)
2y 4m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 386 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month