Prosecution Insights
Last updated: October 02, 2026
Application No. 19/092,414

COMBINED MACHINE LEARNING AND FORMAL TECHNIQUES FOR NETWORK TRAFFIC ANALYSIS

Non-Final OA §103
Filed
Mar 27, 2025
Priority
May 27, 2021 — provisional 63/202,117 +1 more
Examiner
SHAW, PETER C
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
427 granted / 560 resolved
+16.3% vs TC avg
Strong +36% interview lift
Without
With
+35.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
28 currently pending
Career history
605
Total Applications
across all art units

Statute-Specific Performance

§101
11.6%
-28.4% vs TC avg
§103
51.9%
+11.9% vs TC avg
§102
20.3%
-19.7% vs TC avg
§112
12.3%
-27.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 560 resolved cases

Office Action

§103
DETAILED ACTION Claims 1-20 are pending in this action. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 3/27/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 4-6 and 8-9, 11-12, 14, 17-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (US PGPUB No. 2019/0260778) [hereinafter “Chen ‘778”] in view of Miller et al. (US PGPUB No. 2019/0188212) [hereinafter “Miller”]. As per claim 1, Chen ‘778 teaches a method comprising: generating a first plurality of vectors representing corresponding ones of a plurality of traffic log entries generated by a firewall for a network, wherein generating the first plurality of vectors (Examiner Note: first plurality of vectors are interpreted to be equivalent to the “spoofing attack detector” see Abstract and [0053]) comprises, determining a plurality of unique values recorded in the plurality of traffic log entries (Abstract, extracting features from traffic log data); generating a second plurality of vectors representing corresponding ones of the plurality of unique values, wherein each of the second plurality of vectors corresponds to one of the plurality of unique values (Abstract, training and testing vectors are generated based on extracted features); for each traffic log entry of the plurality of traffic log entries, determining a subset of the second plurality of vectors that correspond to those of the plurality of unique values recorded in the traffic log entry (Abstract, training and testing spoofing attack detector by comparing traffic log data with second set of vectors) and aggregating the subset of vectors to generate a corresponding one of the first plurality of vectors ([0036], aggregating learned parameters which make up the parameters for an anomaly, i.e. what is detected by a spoofing attack detector see also [0053]). Chen ‘778 does not explicitly teach clustering the first plurality of vectors into a plurality of clusters; and analyzing network traffic detected for the network based on the plurality of clusters. Miller teaches clustering the first plurality of vectors into a plurality of clusters ([0006], grouping anomalous samples into clusters); and analyzing network traffic detected for the network based on the plurality of clusters ([0007], using the clusters to analyze data traffic flows for anomalies). At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 with the teachings of Miller, clustering the first plurality of vectors into a plurality of clusters; and analyzing network traffic detected for the network based on the plurality of clusters, to provide further insight and context into the determination of anomaly and malicious attack in traffic data. As per claim 4, the combination of Chen ‘778 and Miller teaches the method of claim 1, wherein clustering the first plurality of vectors into the plurality of clusters comprises clustering the first plurality of vectors with k-means clustering (Miller; [0076], clustering anomalous features using a k-means clustering technique). As per claim 5, the combination of Chen ‘778 and Miller teaches the method of claim 1, further comprising, based on analyzing the plurality of clusters, determining that one or more of the first plurality of vectors represent potentially anomalous network traffic of the network (Miller; [0007], labeling individual anomalous samples in a cluster as potentially anomalous based on detecting the cluster). As per claim 6, the combination of Chen ‘778 and Miller teaches the method of claim 5, wherein determining that the one or more vectors represent potentially anomalous network traffic of the network comprises, for each vector of the one or more vectors, determining that a distance between the vector and a centroid of a respective one of the plurality of clusters exceeds a threshold (Miller; [0076[, determining distance from a centroid in K-mean clustering). As per claim 8, the combination of Chen ‘778 and Miller teaches the method of claim 1, wherein aggregating the subset of vectors comprises averaging or summing the subset of vectors (Miller; [0011], averaging the features values which are represented by feature vectors see [0030]). As per claim 9, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale. As per claim 11, the substance of the claimed invention is identical or substantially similar to that of claim 5. Accordingly, this claim is rejected under the same rationale. As per claim 12, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale. As per claim 14, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale. As per claim 17, the substance of the claimed invention is identical or substantially similar to that of claims 5 and 6. Accordingly, this claim is rejected under the same rationale. As per claim 18, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale. As per claim 20, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale Claims 2-3, 10 and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Chen ‘778 and Miller in view of Sjogren et al. (WO-2020049087-A1) [hereinafter “Sjogren”]. As per claim 2, the combination of Chen ‘778 and Miller teaches the method of claim 1. The combination of Chen ‘778 and Miller does not explicitly teach extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values, wherein the weight matrix comprises the second plurality of vectors. Sjogren teaches extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values (Page 42, para. 1, weight matrices used to combine intermediary observational data with target input data), wherein the weight matrix comprises the second plurality of vectors (See id., weight matrices are combined with intermediary values to create intermediary representation). At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 and Miller with the teachings of Sjogren, extracting a weight matrix of a hidden layer of a neural network trained on pairs of the plurality of unique values as context and target values, wherein the weight matrix comprises the second plurality of vectors, to provide further insight and context into the determination of anomaly and malicious attack in traffic data. As per claim 3, the combination of Chen ‘778, Miller and Sjorgen teaches the method of claim 2 wherein determining the subset of the second plurality of vectors that correspond to those of the plurality of unique values recorded in the traffic log entry (Sjorgen; Page 3, para. 2, applying anomaly detection to network traffic anomalies) comprises determining a set of vectors corresponding to rows of the weight matrix that represent those of the plurality of unique values recorded in the traffic log entry (Sjorgen; Page 42, para. 2, x is a n-dimensional row vector, i.e. a set of n row vectors which can represent image data or traffic data see Page 3 applying this anomaly detection to network traffic anomalies), wherein aggregating the subset of vectors comprises aggregating the set of vectors corresponding to the rows of the weight matrix (Sjorgen; Page 42, para. 2, aggregating the set of vectors into an intermediary representation based on the weight matrix). As per claim 10, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale. As per claim 15, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale. As per claim 16, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale. Claims 7, 13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Chen ‘778 and Miller in view of Chen et al. (US PGPUB No. 2018/0329932) [hereinafter “Chen ‘932”]. As per claim 7, the combination of Chen ‘778 and Miller teaches the method of claim 1. The combination of Chen ‘778 and Miller teaches determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values. Chen ‘932 teaches determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values ([0082], deduplicating anomaly features from network traffic used to generate alerts see also claim 22). At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Chen ‘778 and Miller with the teachings of Chen ‘932, determining values recorded for each of a plurality of fields of the plurality of traffic log entries and deduplicating the values to obtain the plurality of unique values, to provide further insight and context into the determination of anomaly and malicious attack in traffic data. As per claim 13, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale. As per claim 19, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Lin et al. (US PGPUB No. 2012/0278021), Addepalli et al. (US PGPUB No. 2017/0257388), Vasseur et al. (US PGPUB No. 2017/0310691), Kimura et al. (US PGPUB No. 2022/0156529), Sampath et al. ("Adaptive Firewall System with Dynamic Rules Generation for Network Security," 2026 4th (ICSCSS), Coimbatore, India, 2026, pp. 1200-1208, doi: 10.1109/ICSCSS69635.2026.11646076), Chentoufi et al. ("An Approach for intrusion detection using machine learning algorithms," 2023 10th International Conference on Wireless Networks and Mobile Communications (WINCOM), Istanbul, Turkiye, 2023, pp. 1-6, doi: 10.1109/WINCOM59760.2023.10322882), Qiu et al. ("Anomaly detection using data clustering and neural networks," 2008 IEEE International Joint Conference on Neural Networks (IEEE World Congress on Computational Intelligence), Hong Kong, China, 2008, pp. 3627-3633, doi: 10.1109/IJCNN.2008.4634317) and Ismail et al. ("A Novel Method for Unsupervised Anomaly Detection Using Unlabelled Data," 2008 International Conference on Computational Sciences and Its Applications, Perugia, Italy, 2008, pp. 252-260, doi: 10.1109/ICCSA.2008.70) all disclose various aspects of the claimed invention including clustering anomaly vectors and detectors for increasing context accuracies in anomaly detection. Any inquiry concerning this communication or earlier communications from the examiner should be directed to PETER C SHAW whose telephone number is (571)270-7179. The examiner can normally be reached Max Flex. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /PETER C SHAW/Primary Examiner, Art Unit 2493 September 17, 2026
Read full office action

Prosecution Timeline

Mar 27, 2025
Application Filed
Sep 21, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743514
METHOD FOR DETECTING RANSOMWARE-ENCRYPTED FILE, STORAGE MEDIUM AND ELECTRONIC DEVICE
1y 9m to grant Granted Sep 22, 2026
Patent 12739625
METHOD AND APPARATUS TO DELIVER MULTIPLE NAS CONTAINERS VIA A SINGLE ACCESS STRATUM MESSAGE
2y 6m to grant Granted Sep 15, 2026
Patent 12739645
IDENTIFYING ROGUE WIRELESS DEVICES USING MAC ADDRESS ROTATION TECHNIQUES
1y 11m to grant Granted Sep 15, 2026
Patent 12732817
UE DISCOVERY MESSAGE PROTECTION METHOD AND APPARATUS, COMMUNICATION DEVICE, AND STORAGE MEDIUM
2y 1m to grant Granted Sep 08, 2026
Patent 12732350
QUANTUM KEY DISTRIBUTION NETWORK AND QUANTUM-SECURED COMMUNICATION NETWORK INCLUDING THE ABOVE
2y 1m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+35.6%)
3y 5m (~1y 11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 560 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month