Prosecution Insights
Last updated: August 17, 2026
Application No. 19/096,750

Neutralizing malicious activities against databases

Non-Final OA §101§102
Filed
Apr 01, 2025
Priority
Dec 31, 2024 — provisional 63/740,361
Examiner
HO, DAO Q
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Dbdome Ltd.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
569 granted / 685 resolved
+25.1% vs TC avg
Strong +32% interview lift
Without
With
+32.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
34 currently pending
Career history
720
Total Applications
across all art units

Statute-Specific Performance

§101
11.9%
-28.1% vs TC avg
§103
48.2%
+8.2% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
20.4%
-19.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 685 resolved cases

Office Action

§101 §102
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This is a reply to the application filed on 4/1/2025, in which, claim(s) 1-25 are pending. Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Drawings The drawings filed on 04/01/2025 is/are accepted by The Examiner. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 20-25 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claim 20 recites, “A computer-readable storage medium…” from the specification paragraph(s), it states “[0111] A computer program product including a computer-readable storage medium having computer-executable instructions for neutralizing an identified malicious activity performed with respect to a database while occurring is further disclosed...”. Based on cited disclosure above, it is determined that the computer readable medium carrying a signal. In addition, transitory forms of signal transmission through transmission medium such as radio broadcast, electrical signals through a wire, and light pulses through a fiber-optic cable, are embodiments that are not directed to statutory subject matter because those transmissions convey only information encoded in the manner are transitory (In re Nuijten 84 U.S.P.Q.2d 1495). Therefore, the claim(s) recites non-statutory subject matter. Applicants' are suggested to amend the claim by replacing the term “computer-readable storage medium” with “A non-transitory computer-readable storage medium” to overcome the rejection. Dependent claims 21-25 are rejected because these claims depend directly from claim 21 and none of the dependent claims overcome the requirements for a statutory subject matter claim. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1-25 is/are rejected under 35 U.S.C. 101 because the claimed is being directed to non-statutory subject matter. The claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim(s) 1-25 is/are directed to a method and system. The claim(s) do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claimed invention is directed to a judicial exception (i.e. an abstract idea) without significantly more. Based upon consideration of all of the relevant factors with respect to the claims as a whole, claims are held to claim an unpatentable abstract idea, and are therefore rejected as ineligible subject matter under 35 U.S.C. § 101. Inventions for a “new and useful process, machine, manufacture, or composition of matter” generally constitute patent-eligible subject matter. 35 U.S.C. § 101. However, the U.S. Supreme Court has long interpreted 35 U.S.C. § 101 to include implicit exceptions: “[l]aws of nature, natural phenomena, and abstract ideas” are not patentable. Alice Corp. v. CLS Bank Int’1l, 573 U.S. 208,216 (2014). The Supreme Court, in Alice, reiterated the two-step framework previously set forth in Mayo Collaborative Services v. Prometheus Laboratories, Inc., 566 U.S. 66 (2012), “for distinguishing patents that claim laws of nature, natural phenomena, and abstract ideas from those that claim patent- eligible applications of those concepts.” Alice Corp., 573 U.S. at 217. The first step in that analysis is to “determine whether the claims at issue are directed to one of those patent-— ineligible concepts.” Id. If the claims are not directed to a patent-ineligible concept, e.g., an abstract idea, the inquiry ends. Otherwise, the inquiry proceeds to the second step where the elements of the claims are considered “individually and ‘as an ordered combination’” to determine whether there are additional elements that “‘transform the nature of the claim’ into a patent-eligible application.” Id. (quoting Mayo, 566 U.S. at 79, 78). This is “a search for an ‘inventive concept’ - i.e., an element or combination of elements that is ‘sufficient to ensure that the patent in practice amounts to significantly more than a patent upon the [ineligible concept] itself.’” Id. at 217-18 (alteration in original). The USPTO published revised guidance on January 7, 2019, for use by USPTO personnel in evaluating subject matter eligibility under 35 U.S.C. § 101. 2019 REVISED PATENT SUBJECT MATTER ELIGIBILITY GUIDANCE, 84 Fed. Reg. 50 (Jan. 7, 2019) (the “2019 Revised Guidance”). That guidance revised the USPTO's examination procedure with respect to the first step of the Mayo/Alice framework by (1) “[p]roviding groupings of subject matter that [are] considered an abstract idea”; and (2) clarifying that a claim is not “directed to” a judicial exception if the judicial exception is integrated into a practical application of that exception. Id. at 50.1 The first step, as set forth in the 2019 Revised Guidance (i.e., Step 2A), is, thus, a two-prong test. In Step 2A, Prong One, we look to whether the claim recites a judicial exception, e.g., one of the following three groupings of abstract ideas: (1) mathematical concepts; (2) certain methods of organizing human activity, e.g., fundamental economic principles or practices, commercial or legal interactions; and (3) mental processes. See 2019 Revised Guidance, 84 Fed. Reg. at 54; MPEP §§ 2106.04(II) (A) (1), 2106.04(a). If so, we next determine, in Step 2A, Prong Two, whether the claim as a whole integrates the recited judicial exception into a practical application of that exception, i.e., whether the additional elements recited in the claim beyond the judicial exception, apply, rely on, or use the judicial exception in a manner that imposes a meaningful limit on the judicial exception, such that the claim is more than a drafting effort designed to monopolize the judicial exception. See 2019 Revised Guidance, 84 Fed. Reg. at 54-55; MPEP §§ 2106.04 (IT) (A) (2), 2106.04(d). Only if the claim (1) recites a judicial exception and (2) does not integrate that exception into a practical application do we conclude that the claim is “directed to” the judicial exception, e.g., an abstract idea. See 2019 Revised Guidance, 84 Fed. Reg. at 54-55; MPEP § 2106.04 (IT) (A) (2). If the claim is determined to be directed to a judicial exception under Step 2A, we next evaluate the additional elements, individually and in combination, in Step 2B, to determine whether they provide an inventive concept, i.e., whether the additional elements or combination of elements amounts to significantly more than the judicial exception itself; only then, is the claim patent eligible. See 2019 Revised Guidance, 84 Fed. Reg. at 56; MPEP § 2106.05. Step One of the Mayo/Alice Framework (2019 Revised Guidance, Step 2A) 2019 Revised Guidance, Step 2A, Prong 1 The abstract idea to which claims 1-25 are directed to is mental process such as concepts performed in the human mind (including an observation, evaluation, judgement, opinion) and mathematical relationships/calculations. In particular, the claims recite the following abstract concepts: “protecting a database, the method comprising neutralizing an identified malicious activity performed with respect to the database while occurring.” (i.e., abstract idea of mental process of detecting, analyzing data, data recognition of malicious activity, and manipulating information are found abstract by the Courts in TLI Comms, Digitech, SmartGene, Bancorp Servs, Electric Power Group, Classen, FairWarning, Cybersource) The Supreme Court and Federal Circuit have identified abstract ideas in patent claims by making comparisons to concepts found in past decisions to be judicial exceptions to eligibility. The 2019 IEG summarizes concepts the courts have considered to be abstract ideas by associating eligibility decisions with judicial descriptors (e.g., “an idea of itself,” “certain methods of organizing human activities”, “mathematical relationships and formulas”) based on common characteristics. These associations define the judicial descriptors in a manner that stays within the confines of the judicial precedent, with the understanding that these associations are not mutually exclusive, i.e., some concepts may be associated with more than one judicial descriptor. The abstract functions of the claims in the case are claim(s) is/are directed to system and method of detecting, analyzing data, data recognition (i.e., abstract idea mental process) and neutralizing as defined by the claimed steps above. The present claims, as a whole, and individual limitations, are reciting abstract concept of detecting and neutralizing of data. As such the claims are analogous to Electric Power Group, Digitech, int. Ventures v. Symantec ‘610 patent, Grams. Looking at the steps of the claims, for each of the claims, data is simply being analyzing, masking and neutralizing which was ruled abstract in: a. Collecting and comparing known information (Classen); b. Comparing information regarding a sample or test subject to a control or target data (Ambry/Myriad CAFC); c. Collecting and analyzing information to detect misuse and notifying a user when misuse is detected (FairWarning); d. Data recognition and storage (Content Extraction); e. Obtaining and comparing intangible data (Cybersource); f. Collecting, selecting, categorizing, analyzing, and displaying certain results of the collection and analysis (Electric Power Group); g. Organizing and manipulating information through mathematical correlations (Digitech); h. Virus Screening (int. Ventures v. Symantec ‘610 patent); i. A mathematical formula for calculating parameters indicating an abnormal condition (Grams). 2019 Revised Guidance, Step 2A, Prong 2 The 2019 Revised Guidance sets forth a non-exhaustive listing of considerations indicative that an additional element or combination of elements may have integrated a recited judicial exception into a practical application. See 2019 Revised Guidance, 84 Fed. Reg. at 55; MPEP § 2106.04(d). In particular, the Guidance describes that an additional element may have integrated the judicial exception into a practical application if, inter alia, the additional element reflects an improvement in the functioning of a computer or an improvement to other technology or a technical field. Id. At the same time, the Guidance makes clear that merely including instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea; adding insignificant extra-solution activity to the judicial exception; or only generally linking the use of the judicial exception to a particular technological environment or field are not sufficient to integrate the judicial exception into a practical application. Id. The abstract functions of the claims in the case are claim(s) is/are directed to system and method of data processing to detect malicious activity (i.e., abstract idea mental process) and neutralizing data as defined by the claimed steps. The claims do not require an arguably inventive set of components, methods, or algorithms. The recitation of masking mechanism to manipulate/replacing/masking the information describes a solution merely at the level of a software. The abstract idea is implemented using generic computing elements (“computers, programs, medium”) and an off the shelf that do not integrate a practical application of the abstract idea in the claims (step 2A, prong 2). Accordingly, even in combination, these additional generic computing elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims recite a mental process, i.e., an abstract idea, and that the additional elements recited in the claim beyond the abstract idea are no more than generic computer components used as tools to perform the recited abstract idea and insignificant extra-solution activity. As such, they do not integrate the abstract idea into a practical application. See Alice Corp., 573 U.S. at 223-24 ("(Wholly generic computer implementation is not generally the sort of ‘additional feature[s] that provides any ‘practical assurance that the process is more than a drafting effort designed to monopolize the abstract idea itself.’” (quoting Mayo, 566 U.S. at 77)); 2019 Revised Guidance, 84 Fed. Reg. at 55 (identifying “an additional element adds insignificant extra-solution activity to the judicial exception” and “an additional element does no more than generally link the use of a judicial exception to a particular technological environment or field of use” as examples in which a judicial exception has not been integrated into a practical application). Step Two of the Mayo/Alice Framework (2019 Revised Guidance, Step 2B) Step 2B: Considering Additional Elements The considerations are whether the claim includes: Improvements to another technology or technical field; Improvements to the functioning of the computer itself; Applying the judicial exception with, or by use of, a particular machine; Effecting a transformation or reduction of a particular article to a different state or thing; Adding a specific limitation other than what is well-understood, routine and conventional in the field, or adding unconventional steps that confine the claim to a particular useful application; Other meaningful limitations beyond generally linking the use of the judicial exception to a particular technological environment; Adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer; Simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception; Adding insignificant extra-solution activity to the judicial exception; Generally linking the use of the judicial exception to a particular technological environment or field of use. The relevant question under Step 2B is whether claim includes an additional element or combination of elements adds specific limitations beyond the judicial exception that are not “well-understood, routine, conventional activity” in the field or simply appends well-understood, routine, conventional activities previously known to the industry to the judicial exception. Here, the additional elements of claim beyond the abstract idea, namely, a “computer hardware”, “programs”, “machine learning model” is a conventional computing equipment and algorithm used in a well-understood, routine, and conventional manner. These additional elements do not provide an inventive concept; rather, they simply append well-understood, routine, conventional activities previously known to the industry to the judicial exception. Applying the test to the claims in the application, the structural elements of the claims, which include a computer when taken in combination with the functional elements claim(s) is/are directed to system and method to identify malicious activity and neutralizing using masking mechanism, together do not offer “significantly more” than the abstract idea itself because the claims do not recite an improvement to another technology or technical field, an improvement to the functioning of any computer itself, or provide meaningful limitations beyond generally linking an abstract idea (neutralizing malicious activity) to a particular technological environment (a general purpose computer and/or environment of the user). When considered as an ordered combination, the Examiner does not find any combination of the additional elements that amounts to more than the sum of the parts. The Examiner finds that the individual elements of the claims are performing their intended roles and functions. In most cases, the additional elements are applied merely to carry out data processing, as discussed above, fall under well-understood, routine, and conventional functions of generic computers in our common day-to-day interactions. Therefore, the claimed interactions of the various generically recited methods/devices lacks an unconventional step that confines the claim to a particular useful application in the sense that the result is equivalent to purely mental activity, e.g., neutralizing malicious activity. Dependent claims do not add an inventive step to the abstract idea of the independent claims and are therefore rejected based on the aforementioned rationale discussed in the rejection. Dependent claims 2-13, 15-19 and 21-25, pertain to replacing statement, masking data without adding any inventive concept or using an unconventional computing element or improving the underlying computer technology. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1-25 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Alberstein (US 20220272121 A1). Regarding claim 1, Alberstein discloses a computer implemented method for protecting a database, the method comprising neutralizing an identified malicious activity performed with respect to the database while occurring (alter the unknown text elements within the text statements to neutralize the text elements or otherwise render harmless any threat the text elements may have posed [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 2, Alberstein discloses the method according to claim 1, wherein the database comprises a data masking mechanism and wherein neutralizing the malicious activity utilizes the data masking mechanism (replacing value with different statement to mask the information [Alberstein; ¶53-58; Figs. 2-4 and associated texts]). Regarding claim 3, Alberstein discloses the method according to claim 1, wherein the malicious activity is generated by a Structured Query Language (SQL) client and comprises an incoming connection currently running a client SQL statement, and wherein the method further comprises altering the structure of the client SQL statement (replacing the SQL statement with different statement, usually perpetrate an injection attack [Alberstein; ¶53-58; Figs. 2-4 and associated texts]). Regarding claim 4, Alberstein discloses the method according to claim 3, wherein altering the structure of the client SQL statement comprises replacing the client SQL statement with a crafted SQL statement (replace with text statement [Alberstein; ¶53-58; Figs. 2-4 and associated texts]). Regarding claim 5, Alberstein discloses the method according to claim 3, wherein the altering of the structure of the client SQL statement is performed such that its result would delay the operation of the SQL client (replace with text statement would cause various results, an attack would cause delay [Alberstein; ¶53-58; Figs. 2-4 and associated texts]). Regarding claim 6, Alberstein discloses the method according to claim 5, wherein altering the structure of the client SQL statement comprises utilizing a function configured to pause the operation of the client SQL statement (replace with text statement would cause various results, an attack would cause delay [Alberstein; ¶53-58; Figs. 2-4 and associated texts]). Regarding claim 7, Alberstein discloses the method according to claim 3, wherein the altering of the structure of the SQL statement is performed such that its result would hold significant memory of the SQL client (overwhelm the memory storage allocation [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 8, Alberstein discloses the method according to claim 3, wherein the altering of the structure of the client SQL statement is performed in a dynamic manner (replace with text statement would cause various results, an attack would cause delay, overwhelm the memory storage allocation [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 9, Alberstein discloses the method according to claim 3, wherein the altering of the structure of the client SQL statement is performed with respect to the client SQL statement and such that the result of the altered SQL statement is related to the client SQL statement (the statement value replaced are related [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 10, Alberstein discloses the method according to claim 3, wherein the database comprises a data masking mechanism and wherein the altering of the structure of the client SQL statement is performed via the data masking mechanism (the data replacement is performed by the protection mechanism [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 11, Alberstein discloses the method according to claim 3, wherein altering the client SQL statement comprises: applying a data masking mechanism of the database on the client SQL statement; and executing a crafted function via the data masking mechanism, the crafted function configured to generate data (perform functions associated with injection detection to secure against an injection attack as described herein and/or as may serve a particular implementation, such as the data replacement is performed by the protection mechanism [Alberstein; ¶15-19, 28-39, 53-58; Figs. 2-4 and associated texts]). Regarding claim 12, Alberstein discloses the method according to claim 1, further comprising identifying the malicious activity (detecting various types of attacks, i.e., injection, overflow, etc., [Alberstein; ¶14; Figs. 2-4 and associated texts]). Regarding claim 13, Alberstein discloses the method according to claim 1, wherein the database is installed on a server, and wherein the neutralizing of the identified malicious activity performed with respect to the database is operated via a monitoring server different from the server (the detection system may be different server from the data structure and other systems [Alberstein; ¶42-44; Figs. e and associated texts]). The requirements for claims 14-25 are substantially the same as rejected claims 1-13. Internet Communications Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, http:ljwww.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only: (1) Central Fax which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAO Q HO whose telephone number is (571)270-5998. The examiner can normally be reached on 7:00am - 5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DAO Q HO/Primary Examiner, Art Unit 2432 1 The MANUAL OF PATENT EXAMINING PROCEDURE (“MPEP”) incorporates the revised guidance and subsequent updates at § 2106 (9th ed. Rev. 10.2019, rev. June 2020).
Read full office action

Prosecution Timeline

Apr 01, 2025
Application Filed
Jul 20, 2026
Non-Final Rejection mailed — §101, §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705321
INTEGRATED IDENTITY MANAGEMENT AND MONITORING SYSTEM, APPARATUS, AND STORAGE MEDIUM
2y 11m to grant Granted Aug 11, 2026
Patent 12705312
THIRD PARTY INTERFACE FOR SYSTEMS PROVIDING ACCESS MANAGEMENT AS A SERVICE
3y 3m to grant Granted Aug 11, 2026
Patent 12689626
GUIDED BACKING SERVICES PROVISIONING FOR CLOUD NATIVE SOFTWARE SYSTEMS
2y 8m to grant Granted Jul 21, 2026
Patent 12640914
METHOD AND SYSTEM FOR A QUANTUM-ENHANCED DECRYPTION PROCESS FOR RSA AND AES ENCRYPTIONS
2y 6m to grant Granted May 26, 2026
Patent 12603778
APPARATUS AND METHOD FOR GENERATING AN NFT VAULT
3y 1m to grant Granted Apr 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+32.3%)
2y 7m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 685 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month