Prosecution Insights
Last updated: October 04, 2026
Application No. 19/095,750

Activity Based Risk Monitoring

Non-Final OA §103
Filed
Mar 31, 2025
Priority
Mar 29, 2024 — provisional 63/571,995 +1 more
Examiner
NOAMAN, BASSAM A
Art Unit
Tech Center
Assignee
Oleria Corporation
OA Round
1 (Non-Final)
79%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
223 granted / 282 resolved
+19.1% vs TC avg
Strong +46% interview lift
Without
With
+46.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
22 currently pending
Career history
295
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
60.4%
+20.4% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 282 resolved cases

Office Action

§103
DETAILED ACTION This Non-Final Office Action is in response to Application filed on 03/31/2025. Claims 1-20 filed on 03/31/2025 are being considered on the merits. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Drawings The drawings filed on 03/31/2025 are accepted. Information Disclosure Statement The information disclosure statements (IDS) submitted on 06/22/20226 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, an initialed and dated copy of Applicant's IDS form 1449 filed 06/22/20226 are attached to the instant Office action. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-2, 8-9 and 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Dysart (US 12621327 B1) in view of Jou (US 20150205954 A1). Regarding claim 1, Dysart teaches a computer-implemented method (Dysart Abstract and Col. 2 line 42-43 “FIG. 2 shows a flow diagram of a method of detecting anomalous activities in an enterprise network”), comprising: establishing a first connection with a data resource system, the data resource system delegated by a domain to control data resources of the domain (Dysart Figure 1 illustrates first connection between assets/resources (101, 102, 103) and backend system 110 delegated by an enterprise/domain to perform the process in Figure 2 and control graphs and subgraphs pertaining to assets in the enterprise as disclosed in Col 5 line 7-15, 37-42); establishing a second connection with a security monitoring system, the security monitoring system providing cybersecurity measures to the domain (Dysart Col. 4 line 2-11 “The cybersecurity components may be distributed across the enterprise network 100 in the form of security appliances that monitor network traffic and enforce network policies, antivirus software running on individual network assets, endpoint agents that run and collect information on network assets, etc. The cybersecurity components 130 may employ conventional algorithms to generate risk assessments of the enterprise network 100.”, where the cybersecurity components 130 provides, via second connection with the assets and the backend system, monitoring and risk assessments to the enterprise/domain); receiving, from the data resource system, metadata related to data access history of the data resources controlled by the data resource system (Dysart Col. 4 line 52-67 and Col. 5 1-3, Col. line 43-48 “In step 201, network attributes of network assets are collected in a backend system. The collected network attributes include an identification of network assets, network interfaces of the network assets, and connections between network interfaces.”, where the attributes of each asset/resources, related to role, characteristics, and identification of the assets, as disclosed in Col. 3 line 55-65, where steps 201-210 are performed for all existing, i.e. historical, and incoming collected events/activities and attributes, collection by a backend system as disclosed in Col. 5 line 43-46); receiving, from the security monitoring system, risk related signals associated with data access activities (Dysart Col. 4 line 63-67 and Col. 5 line 1-3 “The events data of activities may be collected by cybersecurity components as part of an extended detection and response (XDR) system, managed detection and response (MDR) system, on premise monitoring system, or other commercially-available event monitoring system. For example, the events data may be from the XDR system of Trend Micro Incorporated.”, Figure 2 206 where events data of activities are eventually collected at the backend system, where the activities correspond to risk related signals as they play a part in determining risk/anomaly score as illustrated in Figure 2 218-219); generating an access graph comprising graph objects from the metadata received from the data resource system, the access graph comprising the graph objects that are connected by access paths signaling access levels of the data resources controlled by the data resource system (Dysart Col. 5 line 48-58 “In step 202, the collected network attributes are transformed into a network graph that comprises a set of nodes and edges. Network assets are nodes of the network graph. Connections between network interfaces are edges of the network graph. In other words, each node represents a network asset and an edge connecting two nodes represent a connection between network interfaces of two network assets represented by the two nodes. As can be appreciated, the network graph can get very complicated due to the large number of network assets in the enterprise network. ”, Col. 6 line 21-40 “…the activities are transformed into an activity graph. In an activity graph, nodes (i.e. objects) represent logical resources (e.g., users, processes, files, requests) that perform an activity using or through associated network assets. The edges represent causal action or relationship between logical resources, such as a user starting a process, or a process reading/writing to a file or sending a request to another network asset. In step 208, hierarchical subgraphs of the activity graph (“activity subgraphs”) are identified. An activity subgraph is a subset of the activity graph, comprising of a subset of the nodes and a subset of the edges of the activity graph. The activity subgraph maintains the connections that are present in the activity graph. The activity subgraphs are organized in a hierarchical manner, meaning there are multiple hierarchical levels. The causal nature of an activity graph naturally defines a tree-like directed graph, where branches in the tree are subgraphs of the activity graph. The activity subgraphs may thus be readily identified from node connections of the activity graph.”, where the assets/nodes correspond to objects as disclosed in Cpl. 2 line 10-25); aggregating the metadata from the data resource system, the risk related signals from the security monitoring system, and data associated with the access graph to generate one or more normalized risk signals (Dysart Col. 4 line 20-21 “A risk assessment may be for a particular network asset or an aggregation of risk assessments for a group of network assets.”, Col. 6 line 50-67 and Col. 7 line 1-8 “In step 210, the activity subgraphs are aligned to the network subgraphs (which now includes clusters) to generate an alignment graph based on network assets associated with activities in the activity subgraphs. By alignment, it is meant that an activity subgraph and a network subgraph with similar network assets are mapped to each other. In one embodiment, similarity between an activity subgraph and a network subgraph for alignment purposes is determined by calculating their Jaccard similarity value, and the activity subgraph is aligned to the network subgraph that yields the best Jaccard similarity value. An activity subgraph is discarded (i.e., not aligned) when it is not similar to any of the network subgraphs, i.e., the Jaccard similarity value is zero. As can be appreciated, other suitable similarity algorithm other than Jaccard similarity may also be employed to perform the alignment…given a network subgraph having a first set of network assets consisting of computer A and computer B, and an activity subgraph having a second set of network assets consisting of computer A downloading from computer C, the intersection of the first and second sets is computer A, and the union of the first and second sets is computers A, B, and C. In that example, the Jaccard similarity value between the network and activity subgraphs is the number of intersection elements divided by the number of union elements, i.e., ⅓ (i.e., A/(A+B+C))…It is to be noted that steps 201-210 are performed for all existing and incoming collected events data and collected network attributes.”, where the data of the network assets and their attributes pertaining to the network subgraph and the activities pertaining to the activity subgraph are put together for the eventual similarity calculation, where the process in Figure 2 is iterative process, where the graphs are updated as disclosed in Col. 7 line 13-26, Col. 8 line 1-2 “In step 215, the activity subgraph is scored to generate an activity score (i.e. normalized risk signal)”); identifying, based on the one or more normalized risk signals, a cybersecurity risk-related instance that is associated with the at least one of the access paths in the access graph (Dysart “…step 215, the activity subgraph is scored to generate an activity score, which is based on the total hit counts. The activity score may be: 1/total samples; newly added activity subgraph sample/total samples; etc., where “total samples” is the total hit counts. In step 216, the activity score is compared to an activity threshold. In step 216 to step 217, the activity subgraph is detected to be normal when the activity score is equal to or greater than the activity threshold. In step 216 to 218, the activity subgraph is detected to be an anomaly when the activity score is less than the activity threshold.”, where the anomaly is identified based on the activity score compared to a threshold and associated with the hit counts and alignment in the subgraphs); and generating an alert of the cybersecurity risk-related instance in the access graph (Col. 8 line 21—27 “In step 219, an alert is raised in response to detecting the anomaly. The alert may be a notification displayed as a message on a display screen, an email message, or other way to inform security personnel of the enterprise network to further investigate the anomaly. For example, the alert may be a risk assessment that is overlayed on nodes of the network graph on a visualization.”), Dysart does not explicitly disclose the limit below. Jou discloses wherein the alert allows a user to adjust access privilege of a data resource associated with the cybersecurity risk-related instance (Jou [0066] “…risk scores may be adjusted automatically or based on operator input. Adjusting risk scores based on operator input may be explicit, for example by directly tuning the risk scores by an administrator, or implicit, for example by adjusting the risk scores based on input or actions. For example, if security personnel dismisses an alert of a potential undesirable event and indicates that the reason is that the underlying file is deemed unimportant, the risk score for that file may be lowered. If, on the other hand, security personnel adds a file to a watch list or performs other security activities around that file, then the risk score may be raised. In some embodiments, the raise may persist even after the security watch or security activities cease.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Dysart to incorporate the teaching of Jou to utilize the above feature, with the motivation of managing risks and customizing what is important based on these adjustments, as recognized by (Jou Abstract and [0043]). Regarding claim 8, claim 8 recites similar limitations to claim 1, therefore rejected with the same rationale/motivation applied to claim 1. Regarding claim 15, claim 15 recites similar limitations to claim 1, therefore rejected with the same rationale/motivation applied to claim 1. Regarding claim 2, Dysart in view of Jou teaches the computer-implemented method of claim 1, wherein the graph objects comprise (1) a plurality of named entity nodes, (2) a plurality of application account nodes, and (3) a plurality of resource nodes, wherein (1) a named entity node represents a named entity associated with an organization, (2) an application account node represents an application account associated with the domain, and (3) a resource node represents a data resource associated with the domain (Dysart Col. 3 line 25-54 “The enterprise network 100 (i.e. organization having plurality of named assets/nodes) includes a plurality of network assets 101, 102, 103, etc. that may be deployed across a plurality of geographical regions, a plurality of geographical zones in each geographical region, and one or more subnets in each zone (i.e. domain). A region may be a country, and a zone may be a part of the country (e.g., state, province). The enterprise network 100 is divided into regions, zones, and subnets for illustration purposes only. As can be appreciated, an enterprise network may be divided into different network partitions or segments depending on the particulars of the enterprise network. A network asset is a computing component that has an associated network interface for network communication. The network asset is addressable by way of its network interface address, such as its Internet Protocol (IP) address. The network asset may comprise a hardware computing component, such as a server computer, desktop computer, network appliance (e.g., network address translation (NAT) computer, load balancer (LB) computer, router, gateway), database server, network attached storage, cloud computing infrastructure (e.g., Amazon Web Services™ platform), etc. The network asset may also comprise a virtual computing component that runs on a hardware computing component. For example, the network asset may be a virtual machine instance that is addressable on a virtual computer network that is part of the enterprise network 100.”, where there are different types of assets/nodes illustrated in Figure 1, which are addressable, and belong to the enterprise/organization, where the different types are in different regions and subnets, corresponding to domains). Regarding claim 9, claim 9 recites similar limitations to claim 2, therefore rejected with the same rationale/motivation applied to claim 2. Regarding claim 16, claim 16 recites similar limitations to claim 2, therefore rejected with the same rationale/motivation applied to claim 2. Claims 3, 10 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Dysart (US 12621327 B1) in view of Jou (US 20150205954 A1) and Prabhu (US 11397808 B1). Regarding claim 3, Dysart in view of Jou teaches the computer-implemented method of claim 2. Dysart in view of Jou does not explicitly disclose the limitation below. Prabhu discloses wherein each access path comprises a set of edges connecting a respective name entity node and a respective resource node, and a thickness of each of the set of edges illustrates an access activity level of the respective edge (Prabhu illustrates in Figure 2 labeled nodes, and Figure 11 graph of nodes/entities and trail or edges between the nodes, score of a trails and their momentums corresponding to thickness of these trails, Col. 2 line 50-56 “ The execution graph comprises a plurality of nodes and a plurality of edges connecting the nodes, each node represents an entity comprising a process or an artifact, each edge represents an event associated with the entity, and each execution trail is associated with a subset of the nodes and edges of the execution graph.”, Col. 13 line 40-67 “To further understand how trail risk transfer is performed, the concept of “risk momentum” will now be explained. Risk momentum is a supplemental metric that describes the risk that has accumulated thus far beyond a current local trail. In other words, it is the total combined score for the global trail. An example of risk momentum is illustrated in FIG. 11. As shown, Local Trail A, Local Trail B, and Local Trail C are connected to form a continuous global execution trail. Using the techniques described above, Local Trail A is assigned a risk score of 0.3 and Local Trail B has a risk score of 3.5. Traversing the global execution trail, the risk momentum at Local Trail B is 0.3, which is the accumulation of the risk scores of preceding trails (i.e., Local Trail A). Going further, the risk momentum at Local Trail C is 3.8, which is the accumulation of the risk scores of preceding Local Trails A and B. It is possible that a local execution trail does not exhibit any risky behavior, but its preceding trails have accumulated substantial risky behaviors. In that situation, the local execution trail has a low (or zero) risk score but has a high momentum. For example, referring back to FIG. 11, Local Trail C has a risk score of zero, but has a risk momentum of 3.8. For this reason, both the risk momentum and risk score are considered when transferring risk to an artifact.”, where the momentum is associated with access activity and their associated risk traversing the trail). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Dysart in view of Jou to incorporate the teaching of Prabhu to utilize the above feature, with the motivation of understanding and analyzing the transfer of risks across nodes and edges , as recognized by (Prabhu Col. 13 line 40-67). Regarding claim 10, claim 10 recites similar limitations to claim 3, therefore rejected with the same rationale/motivation applied to claim 3. Regarding claim 17, claim 17 recites similar limitations to claim 3, therefore rejected with the same rationale/motivation applied to claim 3. Allowable Subject Matter Claim 4-7, 11-13 and 18-20 objected to as being dependent upon a rejected base claim but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: None of the prior arts of record, individually or in reasonable combination, discloses the limitations recited in the aforementioned claims, in conjunction with the base claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Suh (US 20220292137 A1) discloses method, apparatus, and computer program for providing cyber security by using a knowledge graph. Gill (US 10019677 B2) discloses automatic identification of control violations and mapping of controls to risks. comprehensive risk analysis, visualization and exception handling. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BASSAM A NOAMAN whose telephone number is (571)272-2705. The examiner can normally be reached Monday-Friday 8:30 AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BASSAM A NOAMAN/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Mar 31, 2025
Application Filed
Sep 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739270
INTELLIGENT WORKFLOW FOR PROTECTING SERVERS FROM OUTSIDE THREATS
4y 7m to grant Granted Sep 15, 2026
Patent 12739115
PROTOCOLS WITH NOISY RESPONSE-BASED CRYPTOGRAPHIC SUBKEYS
2y 0m to grant Granted Sep 15, 2026
Patent 12730867
METHOD AND SYSTEM FOR AUTHENTICATION
3y 11m to grant Granted Sep 08, 2026
Patent 12732343
ACCOUNT OPENING METHODS, SYSTEMS, AND APPARATUSES
2y 9m to grant Granted Sep 08, 2026
Patent 12732344
AUTHORITY MANAGEMENT METHOD
2y 9m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+46.2%)
2y 9m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 282 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month