Prosecution Insights
Last updated: October 02, 2026
Application No. 19/096,234

PROGRESSIVE AUGMENTATION OF THREAT TIMELINE VISUALIZATION

Non-Final OA §102§DOUBLEPATENT
Filed
Mar 31, 2025
Priority
Aug 23, 2024 — provisional 63/686,406
Examiner
KORSAK, OLEG
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
SOPHOS Limited
OA Round
1 (Non-Final)
86%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
840 granted / 980 resolved
+27.7% vs TC avg
Moderate +8% lift
Without
With
+7.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
20 currently pending
Career history
1001
Total Applications
across all art units

Statute-Specific Performance

§101
6.7%
-33.3% vs TC avg
§103
36.8%
-3.2% vs TC avg
§102
24.7%
-15.3% vs TC avg
§112
12.3%
-27.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 980 resolved cases

Office Action

§102 §DOUBLEPATENT
DETAILED ACTION This communication is responsive to the application # 19/096,234 filed on March 31, 2025. Claims 1-20 are pending and are directed toward PROGRESSIVE AUGMENTATION OF THREAT TIMELINE VISUALIZATION. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Drawings Figures 1-12 should be designated by a legend such as --Prior Art-- because only that which is old is illustrated. Compare with FIG. 1-7, 11-15 of US 2021/0397738. See MPEP § 608.02(g). Corrected drawings in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. The replacement sheet(s) should be labeled “Replacement Sheet” in the page header (as per 37 CFR 1.84(c)) so as not to obstruct any portion of the drawing figures. If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. The drawings FIG. 13 and 15 are objected to because of poor quality. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being unpatentable over Samosseiko et al. (US 2023/0247048, Pub. Date: Aug. 3, 2023), hereinafter referred to as Samosseiko. As per claim 1, Samosseiko teaches a computer program product for visualizing threat data (1412-DISPLAY TIMELINE, Samosseiko, FIG.14), the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of: storing event data from an enterprise network in a data lake for long term storage (An event stream of events and related data in the stream service 1104 may be organized using schemas that are stored in a schema registry 1112 or similar resource available to various entities interacting with the stream service 1104 and/or data lake 1108. Samosseiko, [0153]), the data lake organized into a plurality of temporal partitions (While indicated as directly coupled to the threat management facility 1310, the one or more data lakes 1308 may be remotely or locally managed resources configured to store telemetry queries collected from endpoints and servers. Samosseiko, [0182]), and the data lake optimized for long term storage of unstructured data (The transformer 1106 may also or instead transmit transformed event data to the data lake 1108 for long-term storage ( e.g., one week, one month, one year, etc.). Samosseiko, [0156]); storing a plurality of lineages in a data store for the enterprise network, each of the plurality of lineages associated with a security event detected on an endpoint of the enterprise network (In general, the stream service 1104 may include any suitable event stream processing storage or technology, or any similar hardware and/or software layer suitable for storing, managing, processing, and querying streams of events as contemplated herein, or otherwise supporting event-driven information. Samosseiko, [0155]), wherein the data store is optimized for query performance and short term storage and wherein the data store has a lower query latency than the data lake (In general, the transformer 1106 may transmit transformed event data back to the stream service 1104 for short-term usage (e.g., one hour, one day, seven days, etc.) by the listeners 1110 or high-speed access by the query engine 1114. Samosseiko, [0156]), each lineage including: an identifier for a process associated with a corresponding one of the security events (For example, the system 300 may usefully implement globally unique device identifiers, user identifiers, application identifiers, data identifiers, Samosseiko, [0080]), a time stamp for the process (The event vectors 810 may be time stamped or otherwise labeled by the threat management facility 812 to record chronology, Samosseiko, [0114]), and process data for a plurality of additional processes causally related to the process (The filter 322 may also or instead be configured to report causal information that causally relates collections of events to one another. Samosseiko, [0078]); receiving an input from a user of a selected lineage from the plurality of lineages (The threat management facility 308 may generally include an application programming interface 310 to third party services 320, a user interface 312 for access to threat management and network administration functions, and a number of threat detection tools 314. Samosseiko, [0071]); displaying a graphical representation of the selected lineage to the user as a threat timeline visualization (the computer program product may include code that causes the one or more computing devices to perform the step of displaying a timeline of a plurality of indicators of breach from the first and second sets of indicators of breach in a user interface interactively coupled to information about the plurality of indicators of breach. Samosseiko, [0006]); and progressively updating the threat timeline visualization with data from the data lake (The user interface 1500 may include a timeline 1506 showing a temporal distribution of the indicators of breach. The timeline may show timestamps of the indicators of breach along a selected time frame. The timestamp may be shown to the nearest minute, hour, day, month, or any other suitable unit of time. Samosseiko, [0209]). As per claim 2, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes periodically querying the data lake for supplemental information related to the selected lineage (Samosseiko, [0057]). As per claim 3, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes selecting one of the plurality of temporal partitions based on the identifier and the time stamp for the selected lineage and querying the one of the plurality of temporal partitions based on the identifier for the selected lineage (Samosseiko, [0058]). As per claim 4, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes receiving a user selection of one of the plurality of additional processes in the selected lineage and querying the data lake for supplemental data relating to the one or more of the plurality of additional processes (Samosseiko, [0070]). As per claim 5, Samosseiko teaches the computer program product of claim 1, wherein progressively updating the threat timeline visualization includes progressively updating the threat timeline visualization to include supplemental event data for at least a predetermined time window around a time of the time stamp for the selected lineage (Samosseiko, [0153]). As per claim 6, Samosseiko teaches the computer program product of claim 1, wherein each lineage in the data store is associated with a corresponding endpoint in the enterprise network, and wherein progressively updating the threat timeline visualization includes progressively updating the threat timeline visualization for the selected lineage with event data from the data lake for one or more other endpoints associated with the enterprise network (Samosseiko, [0152]). As per claim 7, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of updating the threat timeline visualization with reputation data for at least one of the process and one or more of the plurality of additional processes (Samosseiko, [0048]). As per claim 8, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of updating the threat timeline visualization with a natural language description of a relationship between the process and one or more of the plurality of additional processes (Samosseiko, [0172]). As per claim 9, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the steps of: receiving a detection of a threat associated with the selected lineage; generating a natural language explanation of the detection; and updating the threat timeline visualization with the natural language explanation of the detection (Samosseiko, [0172]). As per claim 10, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of supplementing the threat timeline visualization with one or more low severity detections within a temporal window around a corresponding security event associated with the selected lineage (scoring the plurality of malicious breaches to provide a ranking of severity; and selecting one of the customers for notification based on based on the ranking of severity. Samosseiko, [0009]). As per claim 11, Samosseiko teaches the computer program product of claim 1, further comprising code that performs the step of supplementing the threat timeline visualization with a predetermined number of unique events detected on a corresponding one of the endpoints associated with the selected lineage (Samosseiko, FIG. 15). Claims 12-20 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of anticipation as used above. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1-20 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of copending Application No. 19/096,196. Although the conflicting claims are not identical, they are not patentably distinct from each other because all elements of claims 1-20 of the instant application correspond to elements of claims 1-20 of Application No. 19/096, 196. The above claims of the present application would have been obvious over claims 1-20 of Application No. 19/096, 196 because each element of the claims of the present application is anticipated by the claims of the Application No. 19/096, 196 and as such are unpatentable for obviousness-type double patenting (In re Goodman (CAFC) 29 USPQ2D 2010 (12/3/1993)). Claims 1-20 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of copending Application No. 19/096,152. Although the conflicting claims are not identical, they are not patentably distinct from each other because all elements of claims 1-20 of the instant application correspond to elements of claims 1-20 of Application No. 19/096,152. The above claims of the present application would have been obvious over claims 1-20 of Application No. 19/096,152 because each element of the claims of the present application is anticipated by the claims of the Application No. 19/096,152 and as such are unpatentable for obviousness-type double patenting (In re Goodman (CAFC) 29 USPQ2D 2010 (12/3/1993)). This is a provisional nonstatutory double patenting rejection. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLEG KORSAK whose telephone number is (571)270-1938. The examiner can normally be reached on 5:00 AM- 4:00 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OLEG KORSAK/ Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Mar 31, 2025
Application Filed
Aug 17, 2026
Non-Final Rejection mailed — §102, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748862
FUNCTION-BASED SERVICE FRAMEWORK BASED ON TRUSTED EXECUTION ENVIRONMENT
4y 0m to grant Granted Sep 29, 2026
Patent 12748734
CANONICAL TRANSFORMATIONS USING MACHINE LEARNING LANGUAGE MODEL
3y 3m to grant Granted Sep 29, 2026
Patent 12749073
SYSTEMS AND METHODS FOR USER AUTHORIZATION AND ACCESS TO SERVICES USING CONTACTLESS CARDS
2y 6m to grant Granted Sep 29, 2026
Patent 12750208
MANAGING ENCRYPTION KEYS FOR CONTENT
2y 3m to grant Granted Sep 29, 2026
Patent 12748835
METHOD FOR SECURELY OPERATING A SOFTWARE COMPONENT
2y 0m to grant Granted Sep 29, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
86%
Grant Probability
93%
With Interview (+7.6%)
2y 6m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 980 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month