Prosecution Insights
Last updated: October 01, 2026
Application No. 19/086,624

Storage System-based Enhancement of a Network Monitoring Service that Monitors for Anomalous Outgoing Network Traffic from Within a Managed Network

Non-Final OA §103
Filed
Mar 21, 2025
Priority
Nov 22, 2019 — provisional 62/939,518 +25 more
Examiner
GRACIA, GARY S
Art Unit
Tech Center
Assignee
Pure Storage Inc.
OA Round
1 (Non-Final)
72%
Grant Probability
Favorable
1-2
OA Rounds
1y 10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
408 granted / 571 resolved
+11.5% vs TC avg
Strong +48% interview lift
Without
With
+48.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
22 currently pending
Career history
590
Total Applications
across all art units

Statute-Specific Performance

§101
11.9%
-28.1% vs TC avg
§103
65.8%
+25.8% vs TC avg
§102
11.2%
-28.8% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 571 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restrictions 2. NO restrictions warranted at initial time of filing for patent. Priority 3. Applicant claims domestic priority under 35 USC 119e to provisional application filed on 11/22/2019. Information Disclosure Statement 4. The information disclosure statement (IDS) submitted on 08/14/2025, the submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Oath/Declaration 5. Applicant’s Oath was filed on 03/21/2025. Drawings 6. Applicant’s drawings filed on 03/21/2025 has been inspected and is in compliance with MPEP 608.01. Specification 7. Applicant’s specification filed on 03/21/2025 has been inspected and is in compliance with MPEP 608.02. Claim Objections 8. NO objections warranted at initial time of filing for patent. Remarks 9. Examiner request Applicant review relevant prior art under the conclusion of this office action. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 10. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20170295199 hereinafter Kirti view in view of U.S. Publication No. 20110219451 hereinafter McDougal. As per claim 1, Kirti discloses: A method (para 0004 “Systems and methods for cloud security monitoring and threat intelligence in accordance with embodiments of the invention are disclosed.”) comprising: monitoring, by a storage system, one or more operations performed by a host with respect to data stored within a storage system, the host and the storage system operating within an environment bounded by a managed network (Fig. 1, para 0059 “A system including a cloud security monitoring and control system 102, client devices 106 that can be used to access the cloud security system 102, and cloud services 110 to be monitored in accordance with embodiments of the invention is illustrated in FIG. 1. The cloud security and control system 102 can communicate with cloud application services 110 to retrieve security configurations, application data, and other information and set security controls as will be discussed further below.”); detecting, by the storage system based on the monitoring, an anomaly associated with the one or more operations (para 0061 “In several embodiments, data retrieved by the cloud crawler application 202 is entered into an application catalog database 208 and data retrieved by the data loader application 206 is entered into a landing repository 210 and/or analytics and threat intelligence repository database 211. The data concerning activity information in the analytics repository 211 can be utilized to generate reports that may be presented visually to a system administrator via a user interface and to generate analytics for determining threat level, detecting specific threats, and predicting potential threats.”); and sending, by the storage system based on the detecting the anomaly, metadata descriptive of the anomaly to a network monitoring system configured to perform a network traffic monitoring service (para 0087 “ One class of analytics that may be generated is descriptive or statistical analytics. Statistical data can be generated using a pre-defined set of system queries, such as, but not limited to, MapReduce jobs and Spark and Apache Hive queries. Descriptive analytics can be generated either for a single application or across multiple applications using correlation techniques. Examples of reports that can be generated include, but are not limited to, login statistics (e.g., users with the most failed logins, IP address based login history including consideration of IP reputation, geolocation, and other factors), user statistics (e.g., users with the most resources [files, EC2 machines, etc.], entitlements across clouds, number of changed passwords), activity statistics (e.g., activity of a user across clouds), statistics on key rotation (e.g., whether SSH keys have been rotated within the last 30 days), and resource statistics (e.g., number of folders, files downloaded by users, files downloaded by roaming or mobile users). Trends may be identified, such as login activity within a certain time period, password related support issues based on past history of such issues, or identifying types of mobile devices which see the most activity within a certain time period.”) Kirti does not discloses: network traffic monitoring service with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service McDougal discloses: with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service (para 0025 “In some embodiments, some or all of system 100 may be provided as a service to various agents. For example, an agent analyzing traffic passing through a particular boundary of a network may transmit certain traffic (such as one or more files) to aspects of system 100 for analysis and these or other aspects of system 100 may report to the agent the results of the analysis. As another example, a collaborative environment such as one associated with a cross-domain document management system (e.g., RAYTHEON's CHAIN environment) may utilize this service to check files hosted on the platform for malware.” para 0051 “For example, detection node 310 may be configured to apply behavior-based malware detection schemes while detection node 320 may be configured to apply metadata-based detection schemes where metadata of a file is analyzed.” Para 0081 “ At step 608, in some embodiments, the processing of the message by an e-mail delivery system may be paused. This may be done because the malware detection system operating in an active mode. By pausing the processing of the message, the message may be prevented from being delivered. A copy of the message as well as the attachment may be created and sent to the malware detection system. In various embodiments, the message and the attachment themselves may be sent to the malware detection system without creating a copy. These actions may be performed or facilitated by an agent that communicates both with the malware detection system and the messaging system. In contexts other than e-mail, other underlying processes or services may be paused. For example, if the context is uploading files to a network location, the uploading process may be paused while the system analyzes the files as further described below.”) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Kirti to include network traffic monitoring service with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service, as taught by McDougal. The motivation would have been monitor network traffic in order to provide computer security for host-level malware detection. As per claim 2, Kirti in view of McDougal discloses: The method of claim 1, wherein the one or more operations comprise download operations performed by the host with respect to the data stored within the storage system (Kirti para 0087 “(e.g., number of folders, files downloaded by users, files downloaded by roaming or mobile users). ). As per claim 3, Kirti in view of McDougal discloses: The method of claim 1, wherein the detecting the anomaly associated with the one or more operations comprises detecting that the host downloads more than a threshold amount of data from the storage system during a time period (Kirti para 0089 “Predictive analytics can also include identifying threats based on activity such as a user not accessing a particular cloud application in several months and then showing high activity in the next month or a user downloading one file every week for the past several weeks, demonstrating a potential advanced persistent threat (APT) scenario..”). As per claim 4, Kirti in view of McDougal discloses: The method of claim 1, wherein the detecting the anomaly associated with the one or more operations comprises detecting that the one or more operations include activity that deviates from an expected activity of the host (Kirti para 0089 “In several embodiments of the invention, data collected over time is used to build models of normal behavior (e.g., patterns of events and activity) and flag behavior that deviates from normal as abnormal behavior.”). As per claim 5, Kirti in view of McDougal discloses: The method of claim 4, wherein the expected activity is based on historical operations performed by the host with respect to the storage system (Kirti para 0088 “Another class of analytics that can be generated is predictive and heuristic analytics. These may incorporate machine learning algorithms to generate threat models, such as, but not limited to, deviations from base line expectations, rare and infrequent events, and behavior analytics to derive suspicious behavior of a user.”). As per claim 6, Kirti in view of McDougal discloses: The method of claim 4, wherein the expected activity is based on operations performed by one or more other hosts operating within the environment bounded by the managed network with respect to the storage system (Kirti para 0066 “In some embodiments, analytics can utilize information received from tenant systems that describes threat intelligence provided by the tenant. These sources, that can be referred to as customer base lines 217, can include information such as, but not limited to, specific IP addresses to watch or block, email addresses to watch or block, vulnerable browsers or versions thereof, and vulnerable mobile devices or versions of mobile hardware or software.” Also see paragraph 0088). As per claim 7, Kirti in view of McDougal discloses: The method of claim 1, wherein the detecting the anomaly associated with the one or more operations comprises detecting that the one or more operations include at least one operation performed during an anomalous time period (Kirti para 0089 “Predictive analytics can also include identifying threats based on activity such as a user not accessing a particular cloud application in several months and then showing high activity in the next month or a user downloading one file every week for the past several weeks, demonstrating a potential advanced persistent threat (APT) scenario.”). As per claim 8, Kirti in view of McDougal discloses: The method of claim 7, wherein the anomalous time period comprises at least one of a particular time of day, a particular day of the week, or a particular day of the year (Kirti para 0089 “Predictive analytics can also include identifying threats based on activity such as a user not accessing a particular cloud application in several months and then showing high activity in the next month or a user downloading one file every week for the past several weeks, demonstrating a potential advanced persistent threat (APT) scenario.”). As per claim 9, Kirti in view of McDougal discloses: The method of claim 1, wherein the detecting the anomaly associated with the one or more operations comprises detecting that the host has one or more anomalous attributes (Kirti para 0066 and 0086-0089). As per claim 10, Kirti in view of McDougal discloses: The method of claim 1, wherein the detecting the anomaly associated with the one or more operations is performed using a machine learning model (Kirti para 0023, 0062 and 0088). As per claim 11, Kirti in view of McDougal discloses: The method of claim 1, further comprising: sending, by the storage system to the network monitoring system, telemetry data associated with the one or more operations, the telemetry data usable by the network monitoring system to further inform the network traffic monitoring service (Kirti para 0072 “The software defined security configuration data can be collected by utilizing an API (application programming interface) made available by the cloud application. API's and classes of API's that may be utilized in accordance with embodiments may include REST (Representational State Transfer), J2EE (Java 2 Platform, Enterprise Edition), SOAP (Simple Object Access Protocol), and native programmatic methods (such as native application API's for Java). The information could also be requested using other techniques including scripting languages (such as Python and PHP), deployment descriptors, log files, database connectivity through JDBC (Java Database Connectivity) or REST, and resident applications (cloud beacons) as will be discussed further below. The information that is sent or received can be represented in a variety of formats including, but not limited to, JSON (JavaScript Object Notation), XML (Extensible Markup Language), and CSV (Comma Separated Values).” Para 0083 “In some embodiments of the invention, the data may be received in different formats that are utilized by different cloud applications. For example, the data may be formatted in JSON (JavaScript Object Notation) or other data interchange formats, or may be available as log files or database entries. In further embodiments, the process includes normalizing (408) the data and reformatting the data into a common format for storage in and retrieval from the analytics and threat intelligence repository database 211.”) and (McDougal Para 0050 “In some embodiments, detection nodes 310-330 may conform to an interface standard for applying malware detection. Such an interface may include standards for one or more of the following: specifying the file (including, possibly, a URL) that is to be analyzed configuration parameters for applying the detection scheme, time limit for completing the analysis, format of results, specifying the reason for indicating that an analyzed item is suspect, providing log files, and other suitable items involved with applying malware detection schemes.” The motivation would have been monitor network traffic in order to provide computer security for host-level malware detection.) As per claim 12, Kirti in view of McDougal discloses: The method of claim 11, wherein the telemetry data associated with the one or more operations comprises one or more of data descriptive of the host, data that indicates a quantity of data accessed by the host, data indicative of a type of data stored by the storage system that is accessed by the host, data that indicates a time frame over which the data stored by the storage system was accessed by the host, data indicative of one or more metrics associated with requests performed with respect to the storage system, or data indicative of whether access by the host to the data stored by the storage system is ongoing (Kirti para 0088 “Another class of analytics that can be generated is predictive and heuristic analytics. These may incorporate machine learning algorithms to generate threat models, such as, but not limited to, deviations from base line expectations, rare and infrequent events, and behavior analytics to derive suspicious behavior of a user. Algorithms and profiles can be trained to intelligently predict whether an unusual behavior is a security risk.” Para 0089 “ Predictive analytics can also include identifying threats based on activity such as a user not accessing a particular cloud application in several months and then showing high activity in the next month or a user downloading one file every week for the past several weeks, demonstrating a potential advanced persistent threat (APT) scenario. In several embodiments of the invention, data collected over time is used to build models of normal behavior (e.g., patterns of events and activity) and flag behavior that deviates from normal as abnormal behavior.”). As per claim 13, the implementation of the method of claim 1 will execute the system of claim 13. The claim is analyzed with respect to claim 1. As per claim 14, the claim is analyzed with respect to claim 3. As per claim 15, the claim is analyzed with respect to claim 4. As per claim 16, the claim is analyzed with respect to claim 11. As per claim 17, Kirti discloses: A method (para 0004 “Systems and methods for cloud security monitoring and threat intelligence in accordance with embodiments of the invention are disclosed.”) comprising: monitoring, by a fleet management system configured to manage a fleet of storage systems, operations performed by hosts with respect to data stored within the fleet of storage systems the hosts and the fleet of storage systems operating within an environment bounded by a managed network (Fig. 1 elements 110, para 0059 “Fig. 1, para 0059 “A system including a cloud security monitoring and control system 102, client devices 106 that can be used to access the cloud security system 102, and cloud services 110 to be monitored in accordance with embodiments of the invention is illustrated in FIG. 1. The cloud security and control system 102 can communicate with cloud application services 110 to retrieve security configurations, application data, and other information and set security controls as will be discussed further below.”), detecting, by the fleet management system based on the monitoring, an anomaly associated with at least one operation included in the operations (para 0061 “In several embodiments, data retrieved by the cloud crawler application 202 is entered into an application catalog database 208 and data retrieved by the data loader application 206 is entered into a landing repository 210 and/or analytics and threat intelligence repository database 211. The data concerning activity information in the analytics repository 211 can be utilized to generate reports that may be presented visually to a system administrator via a user interface and to generate analytics for determining threat level, detecting specific threats, and predicting potential threats.”); sending, by the fleet management system based on the detecting the anomaly, metadata descriptive of the anomaly to a network monitoring system configured to perform a network traffic monitoring service (para 0087 “ One class of analytics that may be generated is descriptive or statistical analytics. Statistical data can be generated using a pre-defined set of system queries, such as, but not limited to, MapReduce jobs and Spark and Apache Hive queries. Descriptive analytics can be generated either for a single application or across multiple applications using correlation techniques. Examples of reports that can be generated include, but are not limited to, login statistics (e.g., users with the most failed logins, IP address based login history including consideration of IP reputation, geolocation, and other factors), user statistics (e.g., users with the most resources [files, EC2 machines, etc.], entitlements across clouds, number of changed passwords), activity statistics (e.g., activity of a user across clouds), statistics on key rotation (e.g., whether SSH keys have been rotated within the last 30 days), and resource statistics (e.g., number of folders, files downloaded by users, files downloaded by roaming or mobile users). Trends may be identified, such as login activity within a certain time period, password related support issues based on past history of such issues, or identifying types of mobile devices which see the most activity within a certain time period.”) Kirti does not discloses: network traffic monitoring service with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service McDougal discloses: with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service (para 0025 “In some embodiments, some or all of system 100 may be provided as a service to various agents. For example, an agent analyzing traffic passing through a particular boundary of a network may transmit certain traffic (such as one or more files) to aspects of system 100 for analysis and these or other aspects of system 100 may report to the agent the results of the analysis. As another example, a collaborative environment such as one associated with a cross-domain document management system (e.g., RAYTHEON's CHAIN environment) may utilize this service to check files hosted on the platform for malware.” para 0051 “For example, detection node 310 may be configured to apply behavior-based malware detection schemes while detection node 320 may be configured to apply metadata-based detection schemes where metadata of a file is analyzed.” Para 0081 “ At step 608, in some embodiments, the processing of the message by an e-mail delivery system may be paused. This may be done because the malware detection system operating in an active mode. By pausing the processing of the message, the message may be prevented from being delivered. A copy of the message as well as the attachment may be created and sent to the malware detection system. In various embodiments, the message and the attachment themselves may be sent to the malware detection system without creating a copy. These actions may be performed or facilitated by an agent that communicates both with the malware detection system and the messaging system. In contexts other than e-mail, other underlying processes or services may be paused. For example, if the context is uploading files to a network location, the uploading process may be paused while the system analyzes the files as further described below.”) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Kirti to include network traffic monitoring service with respect to outgoing network traffic from the managed network, wherein the metadata is usable by the network monitoring system to perform the network traffic monitoring service, as taught by McDougal. The motivation would have been monitor network traffic in order to provide computer security for host-level malware detection. As per claim 18, Kirti in view of McDougal discloses: The method of claim 17, further comprising: collecting, by the fleet management system, telemetry data from the fleet of storage systems, the telemetry data associated with the operations performed by the hosts with respect to the data stored within the fleet of storage systems; and3 sending, by the fleet management system, the telemetry data to the network monitoring system, the telemetry data useable by the network monitoring system to perform the network traffic monitoring service (Kirti para 0072 “The software defined security configuration data can be collected by utilizing an API (application programming interface) made available by the cloud application. API's and classes of API's that may be utilized in accordance with embodiments may include REST (Representational State Transfer), J2EE (Java 2 Platform, Enterprise Edition), SOAP (Simple Object Access Protocol), and native programmatic methods (such as native application API's for Java). The information could also be requested using other techniques including scripting languages (such as Python and PHP), deployment descriptors, log files, database connectivity through JDBC (Java Database Connectivity) or REST, and resident applications (cloud beacons) as will be discussed further below. The information that is sent or received can be represented in a variety of formats including, but not limited to, JSON (JavaScript Object Notation), XML (Extensible Markup Language), and CSV (Comma Separated Values).” Para 0083 “In some embodiments of the invention, the data may be received in different formats that are utilized by different cloud applications. For example, the data may be formatted in JSON (JavaScript Object Notation) or other data interchange formats, or may be available as log files or database entries. In further embodiments, the process includes normalizing (408) the data and reformatting the data into a common format for storage in and retrieval from the analytics and threat intelligence repository database 211.”) and (McDougal Para 0050 “In some embodiments, detection nodes 310-330 may conform to an interface standard for applying malware detection. Such an interface may include standards for one or more of the following: specifying the file (including, possibly, a URL) that is to be analyzed configuration parameters for applying the detection scheme, time limit for completing the analysis, format of results, specifying the reason for indicating that an analyzed item is suspect, providing log files, and other suitable items involved with applying malware detection schemes.” The motivation would have been monitor network traffic in order to provide computer security for host-level malware detection.) As per claim 19, Kirti in view of McDougal discloses: The method of claim 17, wherein the detecting the anomaly associated with the at least one operation comprises detecting that a host included in the hosts interacts with a threshold number of storage systems included in the fleet of storage systems with a threshold number of operations within a threshold amount of time (Kirti para 0064 “As will be discussed in greater detail below, the user identity repository 209 can also be utilized to facilitate user tracking and profile across multiple cloud applications. In addition, collecting information about user behavior across multiple cloud services enables the system to, when a threat is detected based upon behavior on one or more cloud services, preemptively alert a system administrator with respect to threats on other cloud services and/or proactively secure other services on which a user maintains data by applying remedial measures, such as adding additional steps to authentication, changing passwords, blocking a particular IP address or addresses, blocking email messages or senders, or locking accounts.” Para 0089 “ Predictive analytics can also include identifying threats based on activity such as a user not accessing a particular cloud application in several months and then showing high activity in the next month or a user downloading one file every week for the past several weeks, demonstrating a potential advanced persistent threat (APT) scenario.”). As per claim 20, Kirti in view of McDougal discloses: The method of claim 17, wherein the detecting the anomaly associated with the at least one operation comprises detecting that a host included in the hosts originates from an anomalous geographic region (Kirti para 0087-0089, For example, one or more services may contribute information concerning a particular IP address, such as a reputation (e.g., known for having software vulnerabilities, a host of malicious software, or source of attacks) and/or a geographic location associated with the IP address.). Conclusion 11. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Publication No. 20150371043 discloses on paragraph 0056 “If it is determined at steps S7 and S8 that none of the metadata extracted from the electronic file matches with any of the metadata stored on the server for a popular file, the subsequent steps of the method form a process that may be used to decide if the file should be added to a list of popular files. In the case that the file is added to the list of popular files for which data and/or metadata may be available to the server 3, an association with an official site may be available for the electronic file for future download requests. At step S16 the number of instances that the electronic file has been queried in a predetermined preceding time period is counted. The queries that are counted may be download requests from users, and the predetermined time period may be, for example, 14 days. At step S17 it is determined whether a hit count (the hit count is the number of times that the electronic file has been encountered in the predetermined electronic period) has reached a popularity threshold, where the popularity threshold is a minimum hit count.” Any inquiry concerning this communication or earlier communications from the examiner should be directed to GARY S GRACIA whose telephone number is (571)270-5192. The examiner can normally be reached Monday-Friday 9am-6pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GARY S GRACIA/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Mar 21, 2025
Application Filed
Aug 18, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750243
SYSTEMS AND METHODS FOR PRESERVING PRIVACY OF A REGISTRANT IN A DOMAIN NAME SYSTEM ("DNS")
3y 3m to grant Granted Sep 29, 2026
Patent 12748873
SYSTEMS AND METHODS FOR DATA CLASSIFICATION AND GOVERNANCE
3y 5m to grant Granted Sep 29, 2026
Patent 12743501
DEVICE, METHOD, AND SYSTEM TO DETERMINE AN ACCESS TO A TRUSTED EXECUTION ENVIRONMENT
3y 9m to grant Granted Sep 22, 2026
Patent 12737487
METHOD FOR MANAGING ACCESS TO A FILE FOR NON-VOLATILE MEMORY
1y 6m to grant Granted Sep 15, 2026
Patent 12730915
SYSTEM AND METHOD FOR AUTHENTICATION USING TOKENIZATION OF A RESOURCE PRIOR TO RESOURCE ALLOCATION
3y 3m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+48.0%)
3y 4m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 571 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month