Prosecution Insights
Last updated: October 02, 2026
Application No. 19/088,929

SYSTEMS AND METHODS FOR IDENTIFYING NETWORK OPERATIONS THAT ARE INDICATIVE OF AT LEAST ONE CYBERSECURITY EVENT WHEN MONITORING NETWORK ACTIVITY

Non-Final OA §102§103§DOUBLEPATENT
Filed
Mar 24, 2025
Priority
Jan 08, 2025 — continuation of 19/014,212
Examiner
GADALLA, HANY S
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
73%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
138 granted / 190 resolved
+14.6% vs TC avg
Strong +36% interview lift
Without
With
+35.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
21 currently pending
Career history
205
Total Applications
across all art units

Statute-Specific Performance

§101
8.1%
-31.9% vs TC avg
§103
56.6%
+16.6% vs TC avg
§102
15.6%
-24.4% vs TC avg
§112
14.2%
-25.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 190 resolved cases

Office Action

§102 §103 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION The present office action is responsive to communications received on 03/24/2025. Status of Claims Claims 1-20 are pending. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1-20 of copending Application No. 19/014,212. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims are anticipated by the co-pending application there might be slight difference in language like replacing the term “anomaly” from the co-pending application with “changepoint” in the instant application. This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1-3, 5, 8-9, 12, 15-16 and 18 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Nantel (US 20170163673 A1) hereinafter referred to as Nantel. With respect to claim 1, Nantel discloses: A system for identifying changepoints that are indicative of at least one cybersecurity event when monitoring network activity represented by a plurality of network operations, the system comprising: one or more processors; (Nantel Fig. 4 illustrates identifying changepoints of malware and attacks [cybersecurity] for different network operation, see Nantel ¶68-69). and one or more non-transitory, computer-readable mediums having instructions recorded thereon that, when executed by the one or more processors, cause the one or more processors to perform operations comprising: (Nantel ¶79-81 teach the recited hardware). receiving a dataset representing a plurality of network operations involving at least one cybersecurity event, each network operation of the plurality of network operations occurring at a point in time within a period of time; (Nantel ¶62-63 68-69, Fig. 3-4 illustrate collecting datasets of operations involving network security events within or in a period of time and event “customized Timing settings”). providing the dataset to a changepoint classification model to cause the changepoint classification model to generate an output comprising a set of changepoint annotations indicating one or more changepoints, each changepoint annotation of the set of changepoint annotations corresponding to a network operation of the plurality of network operations; (Nantel ¶58 teaches classification and categorization of threats of the network operations using threat processing computation algorithm [model] and Nantel ¶68-69 teach generating an output of illustrated circles [annotations of changepoints] for different network operations). annotating each network operation of a set of network operations with a label indicating a changepoint type from among a plurality of changepoint types, wherein at least one changepoint type is indicative of the at least one cybersecurity event; (Nantel ¶58 teaches classification and categorization [annotating and labeling] of the cybersecurity threats). receiving user input indicating changepoint types for filtering the set of network operations; (Nantel ¶59 recites “a selected subset of the particular period of time in which to zoom into for further details, and in response to the indication regarding the selected subset, present a list of threats of the plurality of threats corresponding to the selected subset”. See also, Nantel ¶75 “threat filtering parameters can be received, wherein the information can include one or more types of threats to be extracted from the database, parameters of the threats, network-level details of the threats, time interval of detection of the threats, and source-destination details of the threats, among other like criteria/conditions.”) in response to receiving the user input, filtering the set of network operations based on the label of each network operation and the user input to determine a subset of network operations that are classified as the at least one cybersecurity event; (Nantel ¶76 “At step 720, threat information is extracted [subset] from a threat database based on the threat filtering parameters.”). and generating a graphical user interface (GUI) based on the subset of network operations, the GUI indicating an alert that the subset of network operations represents changepoints that are indicative of the at least one cybersecurity event. (Nantel Fig. 4 and Fig. 7 step 730 teach presenting via a GUI the subset of anomalies). Claim 15 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 1. With respect to claim 2, Nantel discloses: A method comprising: receiving a dataset representing a plurality of network operations, (Nantel ¶70 and 72 teach Nantel Fig. 5-6 of identifying anomalous network operations involving plurality of network operations of apps to detect attacks and malware cyberthreats). each network operation of the plurality of network operations occurring at a point in time within a period of time; (Nantel Fig. 3 illustrates collecting information of operations occurring at a certain point or duration within a timeframe). determining that a set of network operations from the plurality of network operations that represent changepoints based on an attribute represented by the set of network operations; (Nantel ¶73 teaches collecting traffic data and determining anomalies) annotating each network operation of the set of network operations with a label indicating a changepoint type from among a plurality of changepoint types; (Nantel ¶73 teaches collecting traffic data and determining anomalies and labeling them with color coding based on their level of threat) receiving user input indicating at least one changepoint type to filter the set of network operations; (in light of Nantel ¶73 regarding receiving user input additionally Nantel ¶75 teaches “At step 710, information regarding one or more threat filtering parameters can be received, wherein the information can include one or more types of threats to be extracted from the database, parameters of the threats, network-level details of the threats, time interval of detection of the threats, and source-destination details of the threats, among other like criteria/conditions.”) in response to receiving the user input, filtering the set of network operations based on the label of each network operation and the at least one changepoint type to determine a subset of network operations that are classified as cybersecurity events; (Nantel ¶76 “At step 720, threat information is extracted from a threat database based on the threat filtering parameters.” Wherein Nantel Fig. 3 illustrates filtration based on “threat level” or “priority threats”). and generating a graphical user interface (GUI) based on the subset of network operations, the GUI indicating an alert that the subset of network operations represents changepoints that are indicative of cybersecurity events. (Nantel ¶76 “At step 730, the extracted information in a form of a historical graph can be presented illustrating a number of threats, by type during a particular period of time, for example.”) With respect to claim 3, Nantel discloses: The method of claim 2, wherein determining that the set of network operations from the plurality of network operations that represent changepoints comprises: providing the dataset to a model to cause the model to generate an output, the output comprising a set of changepoint annotations indicating each network operation of the set of network operations represents at least one changepoint; (Nantel ¶24 discloses annotating by labeling the treats with different labels such as “threat logs can include information regarding each of multiple observed threats including one or more of a severity, a type, time, and source-destination attributes.” And the output comprising changepoints is illustrated in Fig. 4, ¶68-69). and segmenting the set of network operations from the plurality of network operations based on each network operation of the set of network operations corresponding to an changepoint annotation of the set of changepoint annotations. (Nantel Fig. 4, ¶68-69 explain segmented data according to different factors such as IPs operations and corresponding changes [changepoints] over time of the labeled threat(s) event(s)). Claim 16 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 3. With respect to claim 5, Nantel discloses: The method of claim 2, wherein annotating each network operation of the set of network operations with the label indicating the changepoint type from among a plurality of changepoint types comprises: determining an evaluation window of a period of time that encompasses a point in time at which each network operation is executed; (Nantel Fig. 3 illustrates clustering by many parameters which also comprise “last one hour” or event “CustomizeTiming Settings”). determining that one or more different network operations of the set of network operations are executed at points in time within the period of time and correspond to changepoints; and annotating each network operation within the period of time with a label to indicate that each network operation is a changepoint having the changepoint type. (Nantel ¶58-59 and 63-64 teach determining point in time execution and grouping of threats). Claim 18 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 5. With respect to claim 8, Nantel discloses: The method of claim 2, wherein the period of time comprises a first period of time, the method further comprising: obtaining a historical dataset representing a historical network operations, each historical network operation occurring at a point in time within a second period of time that is different form the first period of time; (Nantel Fig. 3 illustrates that any period of time can be selected which can be adjusted to reflect any number of traffic monitoring within any specific period of time). comparing at least one aspect of the historical network operations to the plurality of network operations; (Nantel ¶24 teaches comparing the obtained data with “historical logs” which “can be updated in real-time”). and updating the set of network operations in response to comparing the at least one aspect of the historical network operations to the plurality of network operations. (Nantel ¶24 teaches comparing the obtained data with “historical logs” which “can be updated in real-time”). With respect to claim 9, Nantel discloses: The method of claim 8, wherein comparing the at least one aspect of the historical network operations to the plurality of network operations comprises: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern indicative of a cyclic changepoint, the method further comprising: annotating the subset of network operations with a label indicating that each network operation represents the cyclic changepoint. (Nantel ¶22 teaches using analyzed events of “the extracted [historical] information in a form of a historical graph illustrating a number of threats [changepoints] by type during a particular period of time [cyclic/seasonal].”) With respect to claim 12, Nantel discloses: The method of claim 8, wherein comparing the at least one aspect of the historical network operations to the plurality of network operations comprises: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, the method further comprising: annotating the subset of network operations with a label indicating that each network operation represents a seasonal changepoint. (Nantel ¶22 teaches using analyzed events of “the extracted [historical] information in a form of a historical graph illustrating a number of threats by type during a particular period of time [seasonal].”) Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 4 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nantel as applied to claim 1-3, 5, 8-9, 12, 15-16 and 18 above, and further in view of Kakde et al. (US 9536208 B1) hereinafter referred to as Kakde. With respect to claim 4, Nantel discloses: The method of claim 3, Nantel does not explicitly disclose: wherein providing the dataset to a model to cause the model to generate the output comprises: executing a kernel function based on the dataset to transition the dataset from a first dimension to a second dimension, and wherein segmenting the set of network operations from the plurality of network operations comprises: segmenting the set of network operations based on the dataset transitioning from the first dimension to the second dimension. However, Kakde in an analogous art discloses: wherein providing the dataset to a model to cause the model to generate the output comprises: executing a kernel function based on the dataset to transition the dataset from a first dimension to a second dimension, (Kakde Fig. 8 step 806 using kernel function step 810 trim outliers [from first dimensions to a second dimension]). and wherein segmenting the set of network operations from the plurality of network operations comprises: segmenting the set of network operations based on the dataset transitioning from the first dimension to the second dimension. (Langford Fig. 8 steps 824, 826, 828, 830 and 832 teach trimming outliers and segmenting the values based on kernel parameters). Therefore it would have been obvious to one of ordinary skill in the art before the effective fling date of the claimed invention to modify Nantel wherein providing the dataset to a model to cause the model to generate the output comprises: executing a kernel function based on the dataset to transition the dataset from a first dimension to a second dimension, and wherein segmenting the set of network operations from the plurality of network operations comprises: segmenting the set of network operations based on the dataset transitioning from the first dimension to the second dimension as disclosed by Kakde to remove noise and outliers to reduce for better machine learning (see Kakde 9:35-55). Claim 17 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 4. Claim(s) 6-7 and 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nantel as applied to claim 1-3, 5, 8-9, 12, 15-16 and 18 above, and further in view of Ertoz et al (US 20060161592 A1) hereinafter referred to as Ertoz. With respect to claim 6, Nantel discloses: The method of claim 2, Nantel does not explicitly disclose: determining that a second subset of network operations are not changepoints; and annotating each network operation of the second subset of network operations as not being changepoints. However, Ertoz in an analogous art discloses: wherein the subset of network operations comprises a first subset of network operations, the method further comprising: determining that a second subset of network operations are not changepoints; and annotating each network operation of the second subset of network operations as not being changepoints. (Ertoz ¶28 labels [annotating] local anomalies as “local anomalies--records that are anomalous with respect to their immediate neighbors [subset of network operations], rather than to the entire dataset” which means they are determined as not being changepoints to the entire dataset and labeled accordingly). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel wherein the subset of network operations comprises a first subset of network operations, the method further comprising: determining that a second subset of network operations are not changepoints; and annotating each network operation of the second subset of network operations as not being changepoints as disclosed by Ertoz because detecting a second subset of operations comprising local anomalies by definition is local and not pertaining to the cluster as understood from Ertoz ¶28. Claim 19 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 6. With respect to claim 7, Nantel discloses: The method of claim 2, further comprising: Nantel does not explicitly disclose: determining that a subset of network operations from the set of network operations are noise; and updating the subset of network operations by removing each network operation of the subset of network operations from the set of network operations in response to determining that the subset of network operations are noise. However, Ertoz in an analogous art discloses: determining that a subset of network operations from the set of network operations are noise; (Ertoz ¶28 “If all information-bearing features are removed [not labeled] from a data set, a histogram of pairwise distances would be flat, like white noise.”). and updating the subset of network operations by removing each network operation of the subset of network operations from the set of network operations in response to determining that the subset of network operations are noise. (Ertoz ¶28 teaches the histogram shows the bumps of data to differentiate anomalies). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel with determining that a subset of network operations from the set of network operations are noise; and updating the subset of network operations by removing each network operation of the subset of network operations from the set of network operations in response to determining that the subset of network operations are noise as disclosed by Ertoz to identify anomalies without noise (see Ertoz ¶28). Claim 20 recites One or more non-transitory, computer-readable mediums and while it has slight difference in language it recites similar matter and therefore rejected based on the same rationale as claim 7. Claim(s) 10-11 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nantel as applied to claim 1-3, 5, 8-9, 12, 15-16 and 18 above, and further in view of Garvey et al. (US 20200258005 A1) hereinafter referred to as Garvey. With respect to claim 10, Nantel discloses: The method of claim 8, wherein comparing the at least one aspect of the historical network operations to the plurality of network operations comprises: Nantel does not explicitly disclose: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations. However, Garvey in an analogous art discloses: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations. (Garvey ¶28-29 teaches pattern from subset of traffic resembles noise and removing noise). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel with determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations as disclosed by Garvey to eliminate noise from classification process (see Garvey ¶28). With respect to claim 11, Nantel discloses: The method of claim 8, wherein comparing the at least one aspect of the historical network operations to the plurality of network operations comprises: Nantel does not explicitly disclose: comparing a set of aspects of the historical network operations to the plurality of network operations to determine a pattern indicative of a cyclic changepoint represented by the historical network operations and the plurality of network operations; and the method further comprising: annotating the subset of network operations with a label indicating that each network operation represents the cyclic changepoint in response to comparing the set of aspects of the historical network operations to the plurality of network operations. However, Garvey in an analogous art discloses: comparing a set of aspects of the historical network operations to the plurality of network operations to determine a pattern indicative of a cyclic changepoint represented by the historical network operations and the plurality of network operations; and the method further comprising: annotating the subset of network operations with a label indicating that each network operation represents the cyclic changepoint in response to comparing the set of aspects of the historical network operations to the plurality of network operations. (Garvey ¶88 teaches “A seasonal-aware anomaly detection and training system that uses the summary data to train and evaluate anomaly detectors, accounting for seasonal highs, seasonal lows” using seasonal patterns to identify and classify threats). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel with comparing a set of aspects of the historical network operations to the plurality of network operations to determine a pattern indicative of a cyclic changepoint represented by the historical network operations and the plurality of network operations; and the method further comprising: annotating the subset of network operations with a label indicating that each network operation represents the cyclic changepoint in response to comparing the set of aspects of the historical network operations to the plurality of network operations as disclosed by Garvey to detect and classify seasonal anomalies (see Garvey ¶88). With respect to claim 13, Nantel discloses: The method of claim 8, wherein comparing the at least one aspect of the historical network operations to the plurality of network operations comprises: Nantel does not explicitly disclose: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations. However, Garvey in an analogous art discloses: determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations. (Garvey ¶28-29 teaches pattern from subset of traffic resembles noise and removing noise). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel with determining a pattern represented by the historical network operations based on the at least one aspect of the historical network operations; and determining that a subset of network operations from the set of network operations satisfy the pattern, and wherein updating the set of network operations comprises: removing the subset of network operations from the set of network operations as disclosed by Garvey to eliminate noise from classification process (see Garvey ¶28). Claim(s) 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Nantel as applied to claim 1-3, 5, 8-9, 12, 15-16 and 18 above, and further in view of Ashley (US 9444829 B1) hereinafter referred to as Ashley. With respect to claim 14, Nantel discloses: The method of claim 2, wherein the changepoint type comprises an incomplete network operation changepoint, and wherein determining that the set of network operations from the plurality of network operations represent changepoints comprises: Nantel does not explicitly disclose: identifying network operations of the plurality of network operations comprising one or more fields that are incomplete; and determining the set of network operations represent changepoints in response to identifying the network operations comprising the one or more fields that are incomplete. However, Ashley in an analogous art discloses: identifying network operations of the plurality of network operations comprising one or more fields that are incomplete; and determining the set of network operations represent changepoints in response to identifying the network operations comprising the one or more fields that are incomplete. (Ashley 5:40-65 teach anomaly detection and identification comprising detection of incomplete fields where data is unavailable). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Nantel wherein identifying network operations of the plurality of network operations comprising one or more fields that are incomplete; and determining the set of network operations represent changepoints in response to identifying the network operations comprising the one or more fields that are incomplete as disclosed by Ashley to identify incomplete fields that can be of a security threat (see Ashley 5:40-65). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Vasic et al. (US 20230362180 A1) ¶41 teaches inliers confidence checker to classify anomalous data compared to expected values. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HANY S GADALLA whose telephone number is (571)272-2322. The examiner can normally be reached Mon to Fri 8:00AM - 4:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HANY S. GADALLA/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Mar 24, 2025
Application Filed
Sep 17, 2026
Non-Final Rejection mailed — §102, §103, §DOUBLEPATENT
Sep 29, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744680
INFORMATION PROCESSING APPARATUS, METHOD, AND SYSTEM
2y 3m to grant Granted Sep 22, 2026
Patent 12744667
PROOF OF MEDIA METADATA INTEGRITY ON HASHGRAPH
1y 7m to grant Granted Sep 22, 2026
Patent 12730912
DATABASE SERVICE EXECUTION METHODS AND APPARATUSES
1y 9m to grant Granted Sep 08, 2026
Patent 12717924
METHODS AND SYSTEMS FOR INTELLIGENT DATA SLICE MONITORING
3y 6m to grant Granted Aug 25, 2026
Patent 12717889
MUTUAL AUTHENTICATION SYSTEM AND METHOD
2y 4m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+35.5%)
2y 10m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 190 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month