Prosecution Insights
Last updated: August 17, 2026
Application No. 19/096,380

Autonomous Agent Generation, Review, And Correction Of Mitigation Plans Against DDoS Attacks In A Shared Infrastructure Computing Environment

Non-Final OA §103§112§DP
Filed
Mar 31, 2025
Priority
Jun 28, 2024 — CIP of 18/759,047 +1 more
Examiner
ALI, AFAQ
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Salesforce Inc.
OA Round
1 (Non-Final)
89%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
126 granted / 141 resolved
+31.4% vs TC avg
Moderate +12% lift
Without
With
+11.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
24 currently pending
Career history
172
Total Applications
across all art units

Statute-Specific Performance

§101
8.8%
-31.2% vs TC avg
§103
50.6%
+10.6% vs TC avg
§102
5.1%
-34.9% vs TC avg
§112
22.5%
-17.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 141 resolved cases

Office Action

§103 §112 §DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action Claims 1-20 are pending Priority This application is a continuation-in-part of U.S. patent application Ser. No. 18/989,305, which is a continuation-in-part of U.S. patent application Ser. No. 18/759,047 filed on Jun. 28, 2024. Therefore, the effective filing date of this application is 06/28/2024. Drawings Applicants’ drawings filed on 03/31/2025 has been inspected and it is in compliance with MPEP 608.02. Specification The specification filed on 03/31/2025 is acceptable for examination proceedings. Information Disclosure Statement The information disclosure statement (IDS) submitted on 03/31/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner. Claim Objections Claims 16 and 19 recite the limitation “instantiating and executing an autonomous AI agent instance an autonomous AI agent platform”. Examiner suggests amending this to “instantiating and executing an autonomous AI agent instance by an autonomous AI agent platform”. Appropriate correction is required. Claims 16 and 19 recite the limitation “method performed at computing services environment” and “performing a method at computing services environment”. Examiner suggests amending this to recite “at a computing services environment”. Appropriate correction is required. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: “… an autonomous AI agent platform configured to” in claims 1 and 8 “… autonomous AI agent instance configured to” in claims 1 and 19 “… a plurality of application-layer web application firewalls … implementing the one or more mitigation policies” in claims 1 and 19 “… the computing services environment is configured to” in claim 12 Because these claim limitation(s) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it is being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. See specification para. [0284, 0285, 0288, 0438] for functional support for autonomous AI agent platform See specification para. [0288, 0281] for hardware support for autonomous agent platform See specification para. [0284, 0287, 0368] for functional support for autonomous AI agent instance See specification para. [0288, 028, 0501] for hardware support for autonomous AI agent instance See specification para. [0352, 0354] for functional support for a plurality of application-layer web application firewalls See specification para. [0089, 0352] for hardware support for a plurality of application-layer web application firewalls See specification para. [0047, 0431-0434] for functional support for computing services environment See specification para. [0086, 0251] for hardware support for computing services environment If applicant does not intend to have these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 16, and 19 recite the limitation "the Internet". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “an Internet”. Appropriate correction is required. Claims 2-15, 17, 18, and 20 depend on claims 1, 16, and 19. Therefore, they also inherit the rejection. Claims 3, 17, and 20 recite the limitation " the one or more configurations schemas". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “the one or more configuration schemas” changing configurations to configuration. Appropriate correction is required. Claims 6 and 18 recite the limitation “a generative language model”. However, claim 1 already recites of “a generative language model”. Examiner suggests amending claims 6 and 18 to “the generative language model”. Appropriate correction is required. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1, 13-16, and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 7, and 11 of U.S. Patent Number US 12,665,926 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter. Current application No. 19/096,380 U.S. Patent Number US 12,665,926 B2 1. A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application gateways receiving a plurality of application-layer request messages from a plurality of sources; an orchestration engine including one or more processors configured to identify an application-layer distributed denial of service attack based on input data characterizing network traffic received at the application gateways and to determine a mitigation plan update to address the application-layer distributed denial of service attack; an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model; a plurality of application-layer web application firewalls corresponding to the plurality of application gateways, the orchestration engine instructing the application-layer web application firewalls to implement the mitigation plan update upon approval by the autonomous AI agent instance, the application-layer web application firewalls implementing the mitigation plan update to prevent a subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. 1. A computing services environment providing computing services by a service provider to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application gateways receiving a plurality of application-layer request messages from a plurality of sources; an orchestration engine including one or more processors configured to determine a plurality of mitigation policies corresponding with the plurality of application gateways based on a classification of a subset of the plurality of application-layer request messages as being sent from a subset of sources associated with a distributed denial of service attack; and a plurality of application-layer web application firewalls corresponding to the plurality of application gateways, and being configured to transition from a deactivated state to an activated state upon receipt of an instruction from the orchestration engine, the plurality of application-layer web application firewalls in an activated state implementing the mitigation policies to prevent a subset of subsequent application-layer request messages from the subset of sources from reaching one or more components of the computing services environment, an application-layer web application firewall of the plurality of application-layer web application firewalls being configured as a container sidecar in a virtual container environment and residing in a cloud computing infrastructure hosted by a public cloud provider other than the service provider, wherein transitioning the web application firewall from a deactivated state to an activated state comprises transmitting a configuration instruction to a container ingress /load balancer to delay routing of traffic to a network endpoint until the container sidecar filters the traffic. 13. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and an application-layer web application firewall of the plurality of application-layer web application firewalls resides in a cloud computing infrastructure hosted by a public cloud provider other than the service provider. 1. … an application-layer web application firewall of the plurality of application-layer web application firewalls being configured as a container sidecar in a virtual container environment and residing in a cloud computing infrastructure hosted by a public cloud provider other than the service provider … 7. (Original) The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider, and wherein the application-layer web application firewall is configured to transition to an activated state upon receipt of an instruction from an application-layer controller. 14. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider. 7. (Original) The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider, and wherein the application-layer web application firewall is configured to transition to an activated state upon receipt of an instruction from an application-layer controller. 15. The computing services environment as recited in claim 1, wherein the plurality of application-layer web application firewalls are arranged in a plurality of different cloud computing architectures, wherein the orchestration engine is further configured to transmit control signals to the plurality of application-layer web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. 11. (Original) The computing services environment as recited in claim 1, wherein the plurality of web application firewalls are arranged in a plurality of different cloud computing architectures, wherein the orchestration engine is further configured to transmit control signals to the plurality of web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. Claims 16 and 19 depend on claim 1. Therefore, claim 16 and 19 are rejected in a similar manner. Claims 1, 10, 11, 16, and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 7 of copending Application No. 18/759,047 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter. This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented. Current application No. 19/096,380 copending Application No. 18/759,047 1. A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application gateways receiving a plurality of application-layer request messages from a plurality of sources; an orchestration engine including one or more processors configured to identify an application-layer distributed denial of service attack based on input data characterizing network traffic received at the application gateways and to determine a mitigation plan update to address the application-layer distributed denial of service attack; an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model; a plurality of application-layer web application firewalls corresponding to the plurality of application gateways, the orchestration engine instructing the application-layer web application firewalls to implement the mitigation plan update upon approval by the autonomous AI agent instance, the application-layer web application firewalls implementing the mitigation plan update to prevent a subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. 1. A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of web servers providing access to a plurality of domains on behalf of the plurality of recipients; a plurality of network ingress paths receiving a plurality of application-layer request messages, each of the plurality of application-layer request messages being received from a respective source of a plurality of sources via a respective ingress path of the plurality of network ingress paths and being directed to a respective domain of the plurality of domains; an orchestration engine including one or more processors configured to: determine a probability that a spike in domain-specific network traffic corresponds to an application-layer distributed denial of service attack for a domain, and upon determining that the probability surpasses a designated threshold, determine a plurality of domain-specific mitigation policies corresponding with the plurality of network ingress paths based on a classification of a subset of the plurality of application-layer request messages as being sent from a subset of the plurality of sources and as being associated with a distributed denial of service attack, the plurality of mitigation policies including one or more rules to prevent a subset of subsequent application-layer request messages from the subset of the sources from reaching one or more components of the computing services environment, the plurality of domain-specific mitigation policies blocking traffic to the domain from a first source and throttling traffic to the domain from a second source; and one or more network controllers configured to implement one or more instructions characterizing the plurality of mitigation policies received from the orchestration engine. 10. The computing services environment recited in claim 1, wherein evaluating the mitigation plan update comprises generating novel text via the generative language model, the novel text indicating whether to accept or reject the mitigation plan update. 7. The computing services environment recited in claim 1, the computing services environment further comprising a generative language model interface configured to generate a report characterizing the application-layer distributed denial of service attack by generating novel text to complete a prompt, the prompt including one or more natural language instructions to generate the novel text, the prompt further including analysis information characterizing the application-layer distributed denial of service attack, the prompt further including mitigation information characterizing the plurality of mitigation policies. 11. The computing services environment recited in claim 10, wherein the novel text includes a natural language description characterizing reasoning for accepting or rejecting the mitigation plan update. 7. The computing services environment recited in claim 1, the computing services environment further comprising a generative language model interface configured to generate a report characterizing the application-layer distributed denial of service attack by generating novel text to complete a prompt, the prompt including one or more natural language instructions to generate the novel text, the prompt further including analysis information characterizing the application-layer distributed denial of service attack, the prompt further including mitigation information characterizing the plurality of mitigation policies. Claims 16 and 19 depend on claim 1. Therefore, claim 16 and 19 are rejected in a similar manner. Claims 1, 4, 12-16, and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 5, 8, 9, 11, 12, and 15 of copending Application No. 18/989,305 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter. This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented. Current application No. 19/096,380 copending Application No. 18/989,305 1. A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application gateways receiving a plurality of application-layer request messages from a plurality of sources; an orchestration engine including one or more processors configured to identify an application-layer distributed denial of service attack based on input data characterizing network traffic received at the application gateways and to determine a mitigation plan update to address the application-layer distributed denial of service attack; an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model; a plurality of application-layer web application firewalls corresponding to the plurality of application gateways, the orchestration engine instructing the application-layer web application firewalls to implement the mitigation plan update upon approval by the autonomous AI agent instance, the application-layer web application firewalls implementing the mitigation plan update to prevent a subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. 1. A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application gateways receiving a plurality of application-layer request messages from a plurality of sources; an autonomous agent platform configured to instantiate and execute an autonomous agent to evaluate network traffic associated with a portion of the computing services environment, the autonomous agent being configured to (1) transmit, to a generative language model, an input prompt including a natural language instruction to classify traffic data characterizing the network traffic as corresponding or not corresponding to an application-layer distributed denial of service attack, and (2) receive, from the generative language model, a prompt completion identifying the application-layer distributed denial of service attack; an orchestration engine including one or more processors configured to determine a mitigation policy corresponding with one or more of the plurality of application gateways based on (1) identification of the application-layer distributed denial of service attack and (2) historical data indicating effectiveness of the mitigation policy and a plurality of application-layer web application firewalls corresponding to the plurality of application gateways and implementing the mitigation policy to prevent a subset of subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. 4. The computing services environment recited in claim 1, wherein evaluating the mitigation plan update comprises transmitting an input prompt to the generative language model for completion and receiving a completed prompt from the generative language model. 9. The computing services environment recited in claim 1, wherein identification of the application-layer distributed denial of service attack involves transmitting an input prompt to a generative language model for completion and receiving a completed prompt from the generative language model. 10. The computing services environment recited in claim 1, wherein evaluating the mitigation plan update comprises generating novel text via the generative language model, the novel text indicating whether to accept or reject the mitigation plan update. 5. (Original) The computing services environment recited in claim 1, wherein the autonomous agent is configured to determine novel thought text characterizing a virtual thought explaining why the network traffic is indicative of the application-layer distributed denial of service attack. 12. The computing services environment recited in claim 10, wherein the computing services environment is configured to elicit feedback from a human agent regarding the novel text, and wherein the mitigation plan update is implemented based on the feedback. 8. The computing services environment recited in claim 1, wherein identification of the application-layer distributed denial of service attack depends in part upon text-based instructions provided by a human agent via a chat interface. 13. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and an application-layer web application firewall of the plurality of application-layer web application firewalls resides in a cloud computing infrastructure hosted by a public cloud provider other than the service provider. 11. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and an application-layer web application firewall of the plurality of application-layer web application firewalls resides in a cloud computing infrastructure hosted by a public cloud provider other than the service provider. 14. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider. 12. The computing services environment recited in claim 1, wherein the computing services environment is provided by a service provider, and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider. 15. The computing services environment as recited in claim 1, wherein the plurality of application-layer web application firewalls are arranged in a plurality of different cloud computing architectures, wherein the orchestration engine is further configured to transmit control signals to the plurality of application-layer web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. 15. The computing services environment as recited in claim 1, wherein the plurality of application-layer web application firewalls are arranged in a plurality of different cloud computing architectures, wherein the orchestration engine is further configured to transmit control signals to the plurality of application-layer web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. Claims 16 and 19 depend on claim 1. Therefore, claim 16 and 19 are rejected in a similar manner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5, 10-17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over DORON (US-20180255094-A1), in view of MURPHY (US-20240291853-A1), and further in view of DEVARAJAN (US-20200259792-A1), hereinafter DORON-MURPHY-DEVARAJAN. Regarding claim 1, DORON teaches “A computing services environment providing computing services to a plurality of recipients via the Internet, the computing services environment comprising: a plurality of application [gateways] receiving a plurality of application-layer request messages from a plurality of sources; ([DORON, para. 0032] “FIG. 1 is an example network diagram of a multi-cloud architecture 100 utilized to describe the various disclosed embodiments. The multi-cloud architecture 100 includes a plurality of cloud computing platforms 110-1 through 110-N”) ([DORON, para. 0033] “Each of the cloud computing platforms 110-1 through 110-N, and the datacenter 120 executes a protected application 160 which is the protected entity. As noted above, a protected application 160 may be a web application, a cloud hosted application”) ([DORON, para. 0045] “The EUDs 210 are configured to access a protected application 160 … The access to the protected application 160 is through a network, such as the Internet, by means of a web browser or web application and the like installed on a EUD 210.”) ([DORON, para. 0060] “requested domain hosted in the cloud computing platform 110. For example, a request to a domain www.mysite.com”) an orchestration engine including one or more processors configured to identify an application-layer distributed denial of service attack based on input data characterizing network traffic received at the application gateways and to determine a mitigation plan update to address the application-layer distributed denial of service attack; ([DORON, para. 0043] “The defense platform 140 includes a mitigation resource 250, a detector 260, and a controller 280.”) ([DORON, para. 0057] “In an embodiment, the mitigation resource 250 is communicatively connected to the ADC 270. Upon detection of the potential attack, the controller 280 may be configured to cause a DNS diversion from a normal path of traffic from the EUDs 210 to the mitigation resources 250.”) ([DORON, para. 0059] “The controller 280 is configured to control the traffic diversion to and from the platforms 110 and 140 as well all the mitigation functionalities. Specifically, in an embodiment, upon detection of a potential attack, the controller 280 is configured to signal a detected attack to the mitigation resource 250. The controller 280 is further configured to cause DNS traffic redirection from EUDs 210 to the defense platform 140 and, in particular, to the mitigation resource 250. The mitigation resource 250 is configured to clean the traffic by executing one or more mitigation actions”) ([DORON, para. 0061] “the mitigation resource 250 may be configured to determine when a previously detected flood DDoS attack is terminated. Upon such determination, the controller 280 returns to a peace mode of operation, i.e., DNS traffic redirection is terminated and the DNS operation is returned to its original operation”) [Examiner’s note: Examiner is interpreting the controller 280 as the orchestration engine and redirecting traffic to the mitigation resource to be cleaned as a mitigation policy] … a plurality of application-layer web application [firewalls] corresponding to the plurality of application [gateways], the orchestration engine instructing the application-layer web application [firewalls] to implement the mitigation plan …, the application-layer web application [firewalls] implementing the mitigation plan update to prevent a subsequent application-layer request messages from a subset of the sources from reaching one or more components of the computing services environment. ([DORON, para. 0057] “In an embodiment, the mitigation resource 250 is communicatively connected to the ADC 270. Upon detection of the potential attack, the controller 280 may be configured to cause a DNS diversion from a normal path of traffic from the EUDs 210 to the mitigation resources 250. That is, when the DNS diversion has occurred, instead of flowing the traffic to the protected cloud-hosted application 160, traffic from the EUDs 210 is diverted to the defense platform 140.”) ([DORON, para. 0058] “The mitigation resource 250 performs one or more mitigation actions on the traffic and forwards legitimate clean traffic back toward the protected application 160 through the ADC 270.”) ([DORON, para. 0059] “The controller 280 is configured to control the traffic diversion to and from the platforms 110 and 140 as well all the mitigation functionalities. Specifically, in an embodiment, upon detection of a potential attack, the controller 280 is configured to signal a detected attack to the mitigation resource 250.”) ([DORON, para. 0060] “the DNS traffic redirection (for diverting traffic originally directed to the cloud computing platform 110 to the defense platform 140) includes automatically modifying a DNS record entry to point to a virtual IP (VIP) address representing a resource in the defense platform 140 and not to an IP address of the requested domain hosted in the cloud computing platform 110. For example, a request to a domain “www.mysite.com” would be replaced with “po.mysite.clouddetectorner””) ([DORON, para. 0101] “the mitigation resource cleans the traffic by removing malicious traffic”). However, DORON does not teach of “a plurality of application gateways … a plurality of application-layer web application firewalls … an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model; … implement the mitigation plan update upon approval by the autonomous AI agent instance”. In analogous teaching MURPHY teaches “… an autonomous AI agent platform configured to instantiate and execute an autonomous AI agent instance configured to determine whether to approve or reject the mitigation plan update by evaluating the mitigation plan update via a generative language model; ([MURPHY, para. 0009] “a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event within the computing platform; an executor subsystem configured to iteratively process the mitigation plan using a generative AI model to generate an output, wherein the executor subsystem is configured to utilize several loops and/or nested loops to generate the output; and an output formatter subsystem configured to format the output and generate a summarized human-readable report for the initial notification, wherein: the output formatter subsystem is configured to utilize a large language model to generate the summarized human-readable report for the initial notification”) ([MURPHY, para. 0173] “Further and when executing 912 a remedial action plan, threat mitigation process 10 may autonomously execute 920 a threat mitigation plan (shutting down the stream and closing the port) when e.g., threat mitigation process 10 assigns 908 a “severe” threat level”) ([MURPHY, para. 0776] “The threat mitigation platform (e.g., threat mitigation platform 2900) may include an executor subsystem (e.g., executor subsystem 2910) configured to iteratively process the mitigation plan (e.g., mitigation plan 2906) using a generative AI model (e.g., generative AI model 302) to generate an output (e.g., output 2912).”) ([MURPHY, para. 0418] “Active Agents: In addition to monitoring, active agents can take predefined actions when a threat is detected, such as blocking traffic, isolating affected network segments, or directly interacting with the threat to mitigate its impact.”) … implement the mitigation plan update upon approval by the autonomous AI agent instance ([MURPHY, para. 0418] “Active Agents: In addition to monitoring, active agents can take predefined actions when a threat is detected, such as blocking traffic, isolating affected network segments, or directly interacting with the threat to mitigate its impact.”) ([MURPHY, para. 0776] “The threat mitigation platform (e.g., threat mitigation platform 2900) may include an executor subsystem (e.g., executor subsystem 2910) configured to iteratively process the mitigation plan (e.g., mitigation plan 2906) using a generative AI model”) Thus, given the teaching of MURPHY, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of autonomous AI agent by MURPHY into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON. One of ordinary skill in the art would have been motivated to do so because MURPHY recognizes the need to address complex attacks ([MURPHY, para. 0003] “there is a constant battle occurring between bad actors that want to attack computing platforms and good actors who try to prevent the same. Unfortunately, the complexity of such computer attacks in constantly increasing, so technology needs to be employed that understands the complexity of these attacks and is capable of addressing the same.”) ([MURPHY, para. 0005] “In one implementation, a threat mitigation platform includes: an agent subsystem configured to generate an initial notification concerning a security event within a computing platform; a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address, in whole or in part, the security event”) In analogous teaching DEVARAJAN teaches of “a plurality of application gateways ([DEVARAJAN, para. 0007] “The present disclosure relates to a cloud-based Intrusion Prevention System (IPS).”) ([DEVARAJAN, para. 0049] “In an embodiment, each of the processing nodes 110 may include Internet gateways and one or more servers, and the processing nodes 110 may be distributed through a geographic region”) ([DEVARAJAN, para. 0054] “In an embodiment, an enterprise gateway may be configured so that user requests are routed through the processing node 110 by establishing a communication tunnel between the enterprise gateway and the processing node 110.”) … a plurality of application-layer web application firewalls ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls. … the firewall systems and methods are described implemented through or in conjunction with a distributed, cloud-based security system and the firewall systems and methods can be integrated with sandboxing”) ([DEVARAJAN, para. 0057] “The enterprise 200 may, for example, include a firewall (FW) 202 protecting an internal network that may include one or more enterprise servers 216 … Another firewall 203 may protect an enterprise subnet that can include user computers 206 and 208”) ([DEVARAJAN, para. 0092] “The firewall 602, through the cloud system 500, can offer granular Layer 3 (L3) through Layer 7 (L7) control of applications, in a multi-tenant cloud infrastructure. This also includes integrated logging functionality, giving customers visibility into applications down to the L3 applications running on their networks.”) Thus, given the teaching of DEVARAJAN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of firewalls and gateways DEVARAJAN into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON-MURPHY. One of ordinary skill in the art would have been motivated to do so because DEVARAJAN recognizes the need to improve network protection ([DEVARAJAN, para. 0006] “there is a need for next-generation firewall systems and methods that can adapt to the evolving network.”) ([DEVARAJAN, para. 0007] “The present disclosure relates to a cloud-based Intrusion Prevention System (IPS). A cloud-based IPS enables IPS threat protection where traditional IPS systems cannot”) Regarding claim 16, this claim recites of a method that performs the features of independent claim 1. Therefore, claim 16 is rejected in a similar manner as in the rejection of claim 1. Regarding claim 19, this claim recites of a non-transitory computer readable media having instructions stored thereon for performing a method that implements the features of claim 1. Therefore, claim 19 is rejected in a similar manner as in the rejection of claim 1. Regarding claim 2, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. DORON further teaches “wherein the mitigation plan update identifies the subset of the sources. ([DORON, para. 0057] “In an embodiment, the mitigation resource 250 is communicatively connected to the ADC 270. Upon detection of the potential attack, the controller 280 may be configured to cause a DNS diversion from a normal path of traffic from the EUDs 210 to the mitigation resources 250. That is, when the DNS diversion has occurred, instead of flowing the traffic to the protected cloud-hosted application 160, traffic from the EUDs 210 is diverted to the defense platform 140.”) ([DORON, para. 0064] “the telemetric data used for detecting flood DDoS attacks may include … a total number of concurrent active TCP connections established between the EUDs 210 and the edge entity 231 or between the EUDs 210 and the server 165”) Regarding claims 3, 17, and 20, DORON-MURPHY-DEVARAJAN teach all limitations of claims 1, 16, and 19. MURPHY further teaches “wherein the mitigation plan update is provided in accordance with one or more configuration schemas, and wherein schema information characterizing the one or more configurations schemas are provided to the generative language model, and wherein evaluating the mitigation plan update comprises determining whether the mitigation plan update complies with the one or more configuration schemas. ([MURPHY, para. 0437] “For example, in a web application that uses a large language model to generate content based on user inputs, a formatting script might: … such as code generation or creating structured data from unstructured text, the script might include rules or templates to format the output in a specific syntax or schema.”) ([MURPHY, para. 0442] “These formatting scripts (e.g., formatting script 304) may help integrate large language models into broader applications or workflows, ensuring that the interaction between human users and the AI is as seamless and effective as possible.”) ([MURPHY, abstract] “a generative AI-based planner subsystem configured to receive the initial notification and generate a mitigation plan to address”) ([MURPHY, para. 0443] “a formatting script (e.g., formatting script 304) to produce a summarized human-readable report (e.g., summarized human-readable report 306) for the initial notification (e.g., initial notification 298), threat mitigation process 10 may iteratively process 1908 the initial notification (e.g., initial notification 298) using a large language model (e.g., large language model 308).”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 4, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. MURPHY further teaches “wherein evaluating the mitigation plan update comprises transmitting an input prompt to the generative language model for completion and receiving a completed prompt from the generative language model. ([MURPHY, para. 0436] “A formatting script (e.g., formatting script 304) may include a set of instructions or codes configured to structure, preprocess, or format data (input or output) in a way that's optimal for interaction with or processing by a large language model. This can include tasks like cleaning data, structuring prompts”) ([MURPHY, para. 0459] “Once the prompts (e.g., formatting script 304) have been designed and fine-tuned, they are used to train or fine-tune the large language model.”) ([MURPHY, para. 0461] “When iteratively processing 1906 the initial notification (e.g., initial notification 298) using a generative AI model (e.g., generative AI model 302) and a formatting script (e.g., formatting script 304) to produce a summarized human-readable report (e.g., summarized human-readable report 306) for the initial notification (e.g., initial notification 298), threat mitigation process 10 may iteratively process 1912 the initial notification (e.g., initial notification 298) using the generative AI model (e.g., generative AI model 302),”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 5, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. MURPHY further teaches “wherein evaluating the mitigation plan update via a generative language model comprises providing the generative language model with a natural language description of a purpose of the mitigation plan update and a natural language instruction to determine whether the mitigation plan update is consistent with the natural language description. ([MURPHY, para. 0399] “As is known in the art, a large language model is an artificial intelligence system that is trained on massive amounts of text data to generate human-like responses to natural language inputs.”) ([MURPHY, para. 0457] “The prompts (e.g., formatting script 304) can take a variety of forms, including natural language queries, prompts with specific keywords or phrases, or a combination of both.”) ([MURPHY, para. 0488] “These LLMs can perform various natural language processing tasks, such as answering questions”) ([MURPHY, para. 0604] “When processing 2306 the initial notification (e.g., initial notification 298) using a generative AI model (e.g., generative AI model 302) and a formatting script (e.g., formatting script 304) to produce a summarized human-readable report (e.g., summarized human-readable report 306) for the initial notification (e.g., initial notification 298), threat mitigation process 10 may process 2310 the initial notification (e.g., initial notification 298) using a large language model (e.g., large language model 308).”) ([MURPHY, para. 0610] “Threat mitigation process 10 may automatically execute 2316 some or all of the recommended next steps to define one or more recommended actions. Further and when automatically executing 2316 some or all of the recommended next steps to define one or more recommended actions, threat mitigation process 10 may automatically perform 2318 one or more investigative operations concerning the security event.”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 10, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. MURPHY further teaches “wherein evaluating the mitigation plan update comprises generating novel text via the generative language model, the novel text indicating whether to accept or reject the mitigation plan update. ([MURPHY, para. 0512] “Threat mitigation process 10 may prompt 2108 a user (e.g., analyst 256) to provide feedback concerning the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306). And (if provided), threat mitigation process 10 may receive 2110 feedback concerning the summarized human-readable report (e.g., summarized human-readable report 306) from a user (e.g., analyst 256). For example, the user (e.g., analyst 256) may be asked to give “thumbs-up/thumbs-down” feedback concerning the quality of the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306). In the event that the feedback provided is e.g., marginal or poor … And (if feedback is provided), threat mitigation process 10 may utilize 2112 the feedback to revise the above-described formatting script (e.g., formatting script 304) so that the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306) may be tailored based upon such feedback.”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 11, DORON-MURPHY-DEVARAJAN teach all limitations of claim 10. MURPHY further teaches “wherein the novel text includes a natural language description characterizing reasoning for accepting or rejecting the mitigation plan update. ([MURPHY, para. 0548] “Below is an example of such a summarized human-readable report (e.g., summarized human-readable report 306) for EVENTS 1-2: … Impact on the Organization: The events indicate that a user is attempting to modify a role in the AWS IAM service, which could potentially grant additional privileges to the user and associated IP address. … Recommend Actions: Selective shutdown/suspension of user account(s).”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 12, DORON-MURPHY-DEVARAJAN teach all limitations of claim 10. MURPHY further teaches “wherein the computing services environment is configured to elicit feedback from a human agent regarding the novel text, and wherein the mitigation plan update is implemented based on the feedback. ([MURPHY, para. 0512] “Threat mitigation process 10 may prompt 2108 a user (e.g., analyst 256) to provide feedback concerning the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306). And (if provided), threat mitigation process 10 may receive 2110 feedback concerning the summarized human-readable report (e.g., summarized human-readable report 306) from a user (e.g., analyst 256). For example, the user (e.g., analyst 256) may be asked to give “thumbs-up/thumbs-down” feedback concerning the quality of the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306). In the event that the feedback provided is e.g., marginal or poor … And (if feedback is provided), threat mitigation process 10 may utilize 2112 the feedback to revise the above-described formatting script (e.g., formatting script 304) so that the (above-illustrated) summarized human-readable report (e.g., summarized human-readable report 306) may be tailored based upon such feedback.”) The same motivation to modify DORON with MURPHY as in the rejection of claim 1 applies. Regarding claim 13, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. DORON further teaches “wherein the computing services environment is provided by a service provider, ([DORON, para. 0035] “The protection of the application 160 hosted in the multi-cloud architecture 100 against flood DDoS attacks is performed by means of the defense platform 140. In an embodiment, the defense platform 140 is a cloud computing platform managed by a cloud security vendor (or managed security service provider) that is not one of the service providers of the cloud computing platforms 110-1 through 110-N.”) DEVARAJAN further teaches “… and an application-layer web application firewall of the plurality of application-layer web application firewalls resides in a cloud computing infrastructure hosted by a public cloud provider other than the service provider. ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls … providing a software-based cloud solution, such as a Virtualized Network Function (VNF) in the cloud. The firewall systems and methods support application awareness to identify application regardless of port, protocol, evasive tactic, or Secure Sockets Layer (SSL)”) ([DEVARAJAN, para. 0084] “the cloud system 500 can be multi-tenant in that it operates with multiple different customers (enterprises), each possibly including different policies and rules. One advantage of the multi-tenancy and a large volume of users is the zero-day/zero-hour protection in that a new vulnerability can be detected and then instantly remediated across the entire cloud system 500.”) ([DEVARAJAN, para. 0092] “The firewall 602, through the cloud system 500, can offer granular Layer 3 (L3) through Layer 7 (L7) control of applications, in a multi-tenant cloud infrastructure. The same motivation to modify DORON-MURPHY with DEVARAJAN as in the rejection of claim 1 applies. Regarding claim 14, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. DORON further teaches “wherein the computing services environment is provided by a service provider, ([DORON, para. 0035] “The protection of the application 160 hosted in the multi-cloud architecture 100 against flood DDoS attacks is performed by means of the defense platform 140. In an embodiment, the defense platform 140 is a cloud computing platform managed by a cloud security vendor (or managed security service provider) that is not one of the service providers of the cloud computing platforms 110-1 through 110-N.”) DEVARAJAN further teaches “… and wherein an application-layer web application firewall of the plurality of application-layer web application firewalls is hosted by the service provider. ([DEVARAJAN, para. 0046] “the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls … providing a software-based cloud solution, such as a Virtualized Network Function (VNF) in the cloud. The firewall systems and methods support application awareness to identify application regardless of port, protocol, evasive tactic, or Secure Sockets Layer (SSL)”) ([DEVARAJAN, para. 0084] “the cloud system 500 can be multi-tenant in that it operates with multiple different customers (enterprises), each possibly including different policies and rules. One advantage of the multi-tenancy and a large volume of users is the zero-day/zero-hour protection in that a new vulnerability can be detected and then instantly remediated across the entire cloud system 500.”) The same motivation to modify DORON-MURPHY with DEVARAJAN as in the rejection of claim 1 applies. Regarding claim 15, , DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. DEVARAJAN further teaches “wherein the plurality of application-layer web application firewalls are arranged in a plurality of different cloud computing architectures, ([DEVARAJAN , para. 0046] “Also, the present disclosure relates to a multi-tenant cloud-based firewall. The firewall systems and methods can operate overlaid with existing branch office firewalls or routers as well as eliminate the need for physical firewalls.”) ([DEVARAJAN , para. 0057] “The enterprise 200 may, for example, include a firewall (FW) 202 protecting an internal network that may include one or more enterprise servers 216, a lightweight directory access protocol (LDAP) server 212, and other data or data stores 214. Another firewall 203 may protect an enterprise subnet that can include user computers 206 and 208”) wherein the orchestration engine is further configured to transmit control signals to the plurality of application-layer web application firewalls via one or more network controllers, wherein the control signals are dependent upon the cloud computing architectures. ([DEVARAJAN , para. 0095] “The firewall 602 also can provide basic stateful firewall functionality for common Layer 3 (L3) applications, allowing for the configuration of any one of these applications to traverse through the firewall 602. The user will now be capable of managing and controlling which protocols and applications are allowed through the firewall 602 and which ones are dropped.”) ([DEVARAJAN , para. 0126] “The policy engine 694 is configured to enforce Web and firewall policies and to send the traffic 680 to the Internet 504.”) ([DEVARAJAN , para. 0165] “As described herein, the cloud firewall 602 is implemented by the cloud system 500 and/or the distributed security system 100, via the cloud node 502 or the processing node 110. The cloud firewall 602 provides a proxy-based firewall architecture, and FIG. 28 illustrates functional modules for supporting such architecture.”) The same motivation to modify DORON-MURPHY with DEVARAJAN as in the rejection of claim 1 applies. Claims 7 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over DORON-MURPHY-DEVARAJAN in view of EDWARDS (US-20250373642-A1), hereinafter DORON-MURPHY-DEVARAJAN-EDWARDS. Regarding claim 7, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. However, DORON-MURPHY-DEVARAJAN does not teach “wherein evaluating the mitigation plan update comprises performing retrieval-augmented generation to supply the autonomous AI agent instance with contextual information as an input to determining whether to approve or reject the mitigation plan update” In analogous teaching EDWARDS teaches “wherein evaluating the mitigation plan update comprises performing retrieval-augmented generation to supply the autonomous AI agent instance with contextual information as an input to determining whether to approve or reject the mitigation plan update. ([EDWARDS, para. 0055] “The command line interpretation service 44, though, implements several counter-measures to mitigate negative impacts. The command line interpretation service 44, for example, utilizes prompt engineering (such as explained with reference to FIG. 11) to prompt the large language model 90 to reply in a specific, structured format.”) ([EDWARDS, para. 0055] “The command line interpretation service 44, for example, may fine-tune the machine learning model 70 and associated weighting factors. The command line interpretation service 44 may also utilize retrieval-augmented generation, whereby a new command line 28 or process tree 40 initiates a search of the command line interpretation service database 80 for similar, historical entries. The historical service records, in other words, may be retrieved and used as additional data points for informing the translation of the new command line 28 or process tree 40.”) ([EDWARDS, para. 0059] “The command line interpretation service 44, then, may inspect these historical cybersecurity service records and recommend, or suggest, historical remediations to current true positive cybersecurity detections 30.”) Thus, given the teaching of EDWARDS, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of evaluating the mitigation plan update by EDWARDS into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON-MURPHY-DEVARAJAN. One of ordinary skill in the art would have been motivated to do so because EDWARDS recognizes the need to efficiently address abnormality ([EDWARDS, para. 0003] “The cybersecurity command line interpretation service enables an elegantly simple and fast pre-screening of command lines. The cybersecurity command line interpretation service provides a much faster, initial assessment that easily manages the ever-increasing reports of suspiciousness from the client devices.”) Regarding claim 8, DORON-MURPHY-DEVARAJAN teach all limitations of claim 1. However, DORON-MURPHY-DEVARAJAN does not teach “wherein the autonomous AI agent platform is configured to determine the mitigation plan update by correcting a rejected mitigation plan update.” In analogous teaching EDWARDS teaches “wherein the autonomous AI agent platform is configured to determine the mitigation plan update by correcting a rejected mitigation plan update. ([EDWARDS, para. 0051] “The human expert cybersecurity analyst 102, for example, may agree with or approve the model-generated command line interpretation 72 and the cybersecurity prediction 48. The human expert cybersecurity analyst 102, however, may disagree with, reject, and/or even override the model-generated command line interpretation 72 and/or the cybersecurity prediction 48. The human expert cybersecurity analyst 102, in simple words, may consider the model-generated command line interpretation 72 and/or the cybersecurity prediction 48 as incorrect or wrong. The command line interpretive feedback 126 may thus represent a denial or override, and the command line interpretive feedback 126 may further include an explanation or reasoning. The command line interpretation service 44 (perhaps using the API 150) may thus store and log the command line interpretive feedback 126 to the command line interpretation service database 80 as historical service records. So, in subsequent queries, whenever the command line interpretation service 44 retrieves the historical service records (as previously explained), the command line interpretation service 44 will retrieve the command line interpretive feedback 126 for the same/similar command line 28 and/or process tree 40.”) ([EDWARDS, para. 0059] “The command line interpretation service 44, then, may inspect these historical cybersecurity service records and recommend, or suggest, historical remediations to current true positive cybersecurity detections 30. The command line interpretation service 44, for example, may search historical remediations taken by the human expert cybersecurity analysts 102 (as logged by the command line interpretation service database 80). The command line interpretation service 44 may search for, retrieve, and return these historical, expert remediations most similar to new cybersecurity detections 30. “) The same motivation to modify DORON-MURPHY-DEVARAJAN with EDWARDS as seen in the rejection of claim 7 applies. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over DORON-MURPHY-DEVARAJAN-EDWARDS in view of BROWN (US-20240037497-A1). Regarding claim 9, DORON-MURPHY-DEVARAJAN-EDWARDS teach all limitations of claim 8. However, DORON-MURPHY-DEVARAJAN-EDWARDS does not teach “wherein correcting the rejected mitigation plan update comprises evaluating the rejected mitigation plan update with a second autonomous AI agent instance”. In analogous teaching BROWN teaches “wherein correcting the rejected mitigation plan update comprises evaluating the rejected mitigation plan update with a second autonomous AI agent instance. ([BROWN, para. 0009] “inputting, by the computing system, the second item listing data as input to the at least one model, receiving, by the computing system, output from the at least one model indicating a second suggested remediation for the second item listing data, determining, by the computing system, that the second suggested remediation does not satisfy the auto-remediation criteria … receiving, by the computing system from the user device, user input indicating (i) a rejection of the second suggested remediation and (ii) identification of a user-defined remediation for the flagged item listing data, implementing, by the computing system, the user-defined remediation to update the flagged item listing data, and training, by the computing system, the at least one model to identify the user-defined remediation as a remediation for the other item listing data that does not satisfy the auto-remediation criteria. ”) ([BROWN, para. 0094] “Those suggested remediations can then be automatically implemented by the computer system 102 or flagged and reviewed by the relevant user at a user device, such as the user device 104 described in FIG. 1A.”) ([BROWN, para. 0171] “the computer system can train one or more of the models described herein with the user override such that the models generate output that aligns with the user override. Therefore, the models may be continuously improved such that they provide suggestions more in line with expectations of the relevant user and the online retail environment.”) Thus, given the teaching of BROWN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of evaluating the rejected mitigation plan update with a second autonomous AI agent instance by BROWN into the teaching of a computing services environment providing computing services to a plurality of recipients by DORON-MURPHY-DEVARAJAN-EDWARDS. One of ordinary skill in the art would have been motivated to do so because BROWN recognizes the need to auto remediate issues efficiently ([BROWN, para. 0026] “The disclosed techniques, on the other hand, provide an automated and quick approach for auditing the item listing data and auto-remediating issues or changes in the item listing data, which otherwise may not be feasible by a human reviewer. The disclosed techniques can remove potential human error and reduce an amount of time needed to audit and remediate item listing data across the different systems.”) Allowable Subject Matter Claims 6 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims, and if all other rejections are overcome. Pertinent Art The prior art made of record and not relied upon is considered pertinent to Applicant’s disclosure. REDDY (US-20200389489-A1): This prior art teaches of a device in a network receives an attack mitigation request regarding traffic in the network. The device causes an assessment of the traffic, in response to the attack mitigation request. The device determines that an attack detector associated with the attack mitigation request incorrectly assessed the traffic, based on the assessment of the traffic. The device causes an update to an attack detection model of the attack detector, in response to determining that the attack detector incorrectly assessed the traffic. KONDA (US-20200067974-A1): This prior art teaches of cooperative mitigation of distributed denial of service attacks originating in local networks are disclosed. An example local network router disclosed herein includes a mitigator to mitigate a distributed denial of service attack detected by an Internet service provider, the distributed denial of service attack associated with network traffic originating from a first device connected to a local network. The example local network router also includes a threat signaling server to identify the first device based on first information received from a threat signaling client of the Internet service provider, the first information describing the distributed denial of service attack. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.A./ 07/09/2026 /AFAQ ALI/Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Mar 31, 2025
Application Filed
Jul 14, 2026
Non-Final Rejection mailed — §103, §112, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689649
DETERMINING ADDITIONAL SIGNALS FOR DETERMINING CYBERSECURITY RISK
1y 12m to grant Granted Jul 21, 2026
Patent 12665926
System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
1y 9m to grant Granted Jun 23, 2026
Patent 12639404
Authorization of Access Rights Licenses
2y 2m to grant Granted May 26, 2026
Patent 12627679
CYBER SECURITY SYSTEM APPLYING NETWORK SEQUENCE PREDICTION USING TRANSFORMERS
2y 3m to grant Granted May 12, 2026
Patent 12585791
ENCRYPTED COMMUNICATION METHOD AND ELECTRONIC DEVICE
3y 7m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+11.7%)
2y 5m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 141 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month