Prosecution Insights
Last updated: October 04, 2026
Application No. 19/169,569

SYSTEM AND METHOD FOR ELIMINATING DUPLICATE CORRELATION CHAINS OF EVENTS DURING DETECTION OF INFORMATION SECURITY INCIDENTS

Non-Final OA §102
Filed
Apr 03, 2025
Priority
Apr 19, 2024 — RU 2024110880
Examiner
ALMAMUN, ABDULLAH
Art Unit
Tech Center
Assignee
AO Kaspersky Lab
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
327 granted / 419 resolved
+18.0% vs TC avg
Strong +26% interview lift
Without
With
+25.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
15 currently pending
Career history
442
Total Applications
across all art units

Statute-Specific Performance

§101
17.2%
-22.8% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
20.4%
-19.6% vs TC avg
§112
7.7%
-32.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 419 resolved cases

Office Action

§102
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a Non-Final Office Action in response to the communication filed on February 03, 2025. Claims 1-20 have been examined. Drawings The drawings filed on February 03, 2025 are acceptable for examination proceedings. Priority Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). The certified copy has been filed in parent Application No. 19/169569, filed on February 03, 2025. Information Disclosure Statement The information disclosure statement (IDS) submitted on February 03, 2025 was filed after the mailing date of the application 19/169569, filed on February 03, 2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Liu et al. (Chinese Patent Application Publication No.: CN 105471882 A / or “Liu” hereinafter). Regarding claim 1, Liu discloses “A method for eliminating duplicate correlation chains of events during detection of information security incidents, comprising” (Abstract: method and device of network attack detection based on the behavior characteristics of the network attack; and Page 4: lines 34-35): “receiving information from a plurality of computers in the network” (Abstract: collecting original security information from various safety device); “generating an event based on the received information, wherein each generated event contains attributes” (Page 4: lines 38-40, producing from the original security information security event i.e., a “event”; and see also Abstract); “identifying at least one correlation chain [i.e., “a correlation chain is constructed contain at least an IP address/MAC address identifying the computer 110 from which the event originated, the event type, and a timestamp” (see, Applicant’s specification, Para 0049: last few lines)] in a database, wherein, for the first event of each identified correlation chain, attributes are set based on a corresponding correlation rule” (Page 4: lines 38-40, the original security information is converted into a unified format i.e., a “correlation chain” where at least one field i.e., “attributes” contains time field, type field, IP address field etc. and Page 4: lines 44-48: where the security events are associated with rule base i.e., a “corresponding correlation rule”); “comparing the generated event with the first event from each identified correlation chain, including determining the similarity of attributes, and further comprising: merging an event with a correlation chain if the generated event is a duplicate event for the first event in the correlation chain” (Page 5: lines 20-21, the security event is merged with a cluster if similar security event is detected), “and creating a new correlation chain if the attributes of the generated event are not similar to the attributes of the first event in the correlation chain” (Page 5: lines 21-22, the security event is a new security event a new cluster i.e., a “new correlation chain” is created). Regarding claim 2, in view of claim 1, Liu discloses “wherein if the attributes of the generated event are not similar to the first event from at least one correlation chain, then comparing the generated event with subsequent events from each identified correlation chain using other correlation rules” (Page 7: lines 11-21, “Sorting the different types of security events that have the same source IP address and destination IP address and occurred within a monitoring period according to the order of the event generation time to obtain the security event combination; find out whether there are the same security events in the security event association rule base combination, if there is, it is considered that the host corresponding to the destination IP address has been attacked and an alarm will be issued. If not, store these security events in the association rule mining database”). Regarding claim 3 in view of claim 2, Liu discloses “wherein, if the generated event corresponds to the next event from at least one correlation chain, according to the correlation rule, then adding the generated event to the corresponding correlation chain” (Page 5: lines 20-21, the security event is merged with a cluster if similar security event is detected). Regarding claim 4 in view of claim 3, Liu discloses “wherein, if the correlation chain corresponds with the correlation rule, an information security incident is identified” (Page 7: lines 23-27, “For example, it is found that during a monitoring period for the same source IP address and the same destination IP address, Type A security events, Type B security events, and Type C security events occurred sequentially; and there is such an association rule in the association rule base: rule1→rule2 →rule3. If the received type A security event matches rule1 in the rule, type B security event matches rule2, and type C security event matches rule3, it is determined that the host corresponding to the target IP address has suffered a combination of attacks and an alarm is issued”). Regarding claim 5, in view of claim 1, Liu discloses “wherein the information from the computers in the network includes at least information about an unauthorized network connection, registration of a new device on the network, disconnection of the sensor or controller, and/or unauthorized access to the computer” (Page 4: lines 19-25, the behavior data i.e., the “information” may include honey pot technology, intrusion detection technology etc.). Regarding claim 6, in view of claim 1, Liu discloses “wherein the similarity of the event attributes is determined according to the correlation rule during a timeout” (Page 4: lines 44-48, monitoring period for security events are utilized). Regarding claim 7, in view of claim 1, Liu discloses “wherein the attributes of the event comprise at least a source of the event, a type of event, and/or a timestamp” (Page 4: lines 38-40, the original security information is converted into a unified format i.e., a “correlation chain” where at least one field i.e., “attributes” contains time field, type field, IP address field etc.). Regarding claim 8, in view of claim 7, Liu discloses “wherein the sources of the event includes the security features installed on the computers and/or the security software” (Page 5: lines 50-56, the source of the events could be “…firewall, an intrusion detection system, a vulnerability library, antivirus software, and a host monitoring system”). Regarding claim 9, claim 9 is directed to a system corresponding to the method recited in claim 1. Claim 9 is similar in scope to claim 1, and is therefore, rejected under similar rationale. Regarding claim 10, claim 10 is directed to a system corresponding to the method recited in claim 2. Claim 10 is similar in scope to claim 2, and is therefore, rejected under similar rationale. Regarding claim 11, claim 11 is directed to a system corresponding to the method recited in claim 3. Claim 11 is similar in scope to claim 3, and is therefore, rejected under similar rationale. Regarding claim 12, claim 12 is directed to a system corresponding to the method recited in claim 4. Claim 1 2is similar in scope to claim 4, and is therefore, rejected under similar rationale. Regarding claim 13, claim 13 is directed to a system corresponding to the method recited in claim 5. Claim 13 is similar in scope to claim 5, and is therefore, rejected under similar rationale. Regarding claim 14, claim 14 is directed to a system corresponding to the method recited in claim 6. Claim 14 is similar in scope to claim 6, and is therefore, rejected under similar rationale. Regarding claim 15, claim 15 is directed to a system corresponding to the method recited in claim 7. Claim 15 is similar in scope to claim 7, and is therefore, rejected under similar rationale. Regarding claim 16, claim 16 is directed to a system corresponding to the method recited in claim 8. Claim 16 is similar in scope to claim 8, and is therefore, rejected under similar rationale. Regarding claim 17, claim 17 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 1. Claim 17 is similar in scope to claim 1, and is therefore, rejected under similar rationale. Regarding claim 18, claim 18 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 2. Claim 18 is similar in scope to claim 2, and is therefore, rejected under similar rationale. Regarding claim 19, claim 19 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 3. Claim 19 is similar in scope to claim 3, and is therefore, rejected under similar rationale. Regarding claim 20, claim 20 is directed to a non-transitory computer readable medium corresponding to the method recited in claim 4. Claim 20 is similar in scope to claim 4, and is therefore, rejected under similar rationale. Relevant Prior Arts The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Freitas et al. (US 20260006048 A1) discloses “… alerts are correlated based on shared attributes, such as an IP address, username, or session identifier. Correlations may be filtered based on domain knowledge and threat intelligence. The remaining correlations are used to construct a graph that represents an incident. Alerts are represented in the graph as vertices while correlations are represented as edges. The graph is pruned of redundant correlations, resulting in a streamlined representation of the incident”. (Abstract). Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULLAH ALMAMUN whose telephone number is (571) 270-3392. The examiner can normally be reached on 8 AM - 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ABDULLAH ALMAMUN/Examiner, Art Unit 2431 /JEREMIAH L AVERY/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Apr 03, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739641
ATTACKER IDENTIFICATION DURING SMALL DATA TRANSMISSION
2y 8m to grant Granted Sep 15, 2026
Patent 12739137
METHOD FOR PROVIDING A RANDOM FOR A CRYPTOGRAPHIC ALGORITHM, RELATED METHOD FOR PROCESSING A DATA AND COMPUTER PROGRAM
2y 9m to grant Granted Sep 15, 2026
Patent 12726489
ATTACK RISK ASSESSMENT SYSTEM OF AN ADVANCED PERSISTENT THREAT AND THE OPERATION METHOD
3y 9m to grant Granted Sep 01, 2026
Patent 12719678
TRAINING NEURAL NETWORKS WITH NON-POLYNOMIAL ELEMENTS FOR HOMOMORPHIC ENCRYPTION COMPUTATIONS USING SUB-NETWORKS AND MULTI-LOSS
3y 5m to grant Granted Aug 25, 2026
Patent 12712715
INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, COMPUTER PROGRAM PRODUCT, AND INFORMATION PROCESSING SYSTEM
2y 2m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+25.8%)
3y 3m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 419 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month