Prosecution Insights
Last updated: October 01, 2026
Application No. 19/169,984

METHOD OF SECURITY INFORMATION VISUALIZATION PROCESSING, ELECTRONIC DEVICE AND STORAGE MEDIUM

Non-Final OA §103§112
Filed
Apr 03, 2025
Priority
Apr 17, 2024 — CN 202410465706.9
Examiner
PLECHA, THADDEUS J
Art Unit
Tech Center
Assignee
Beijing Zitiao Network Technology Co., Ltd.
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
562 granted / 645 resolved
+27.1% vs TC avg
Moderate +10% lift
Without
With
+10.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
15 currently pending
Career history
664
Total Applications
across all art units

Statute-Specific Performance

§101
14.9%
-25.1% vs TC avg
§103
35.1%
-4.9% vs TC avg
§102
6.6%
-33.4% vs TC avg
§112
31.6%
-8.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 645 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The following is a Non-Final Office Action in response to communications received on April 3, 2025. Claims 1-20 are pending and addressed below. Specification For the record, Examiner acknowledges that the Specification submitted on April 3, 2025 has been accepted. Drawings For the record, Examiner acknowledges that the Drawings submitted on April 3, 2025 have been accepted. Claim Objections Claim 17 is objected to under 37 CFR 1.75 as being a substantial duplicate of claim 13. When two claims in an application are duplicates or else are so close in content that they both cover the same thing, despite a slight difference in wording, it is proper after allowing one claim to object to the other as being a substantial duplicate of the allowed claim. See MPEP § 608.01(m). Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 10 and 14 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 10 recites the limitations “the anomaly detail chart” and “the object anomaly information interface”. There is insufficient antecedent basis for these limitations. Claim 14 recites the limitation “the unapplied security measure.” There are multiple different previously recited unapplied security measures and it is unclear as to which particular unapplied security measure the limitation is referring. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-6, 8-10, 12, 13 and 15-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Raj et al. (U.S. Pub. No. 2021/0397903 and hereinafter referred to as Raj) in view of Murray et al. (U.S. Pub. No. 2021/0211472 and hereinafter referred to as Murray). As to claim 1, Raj discloses a method of security information visualization processing, comprising: displaying a security overview dashboard of a user group in response to a security overview display instruction (paragraphs [0024], [0025], [0046], [0075], [0079] and Figs. 13-14, Raj teaches a dashboard displaying security information in response to an admin request, the security information including anomalies, alerts, and user group tracking); displaying anomaly aggregation information in the security overview dashboard (paragraphs [0079]-[0081] and Figs. 13-15, Raj teaches displaying security information on the dashboard where the information is aggregated), wherein the anomaly aggregation information comprises anomaly aggregation data respectively corresponding to a plurality of security scenarios (paragraphs [0075]-[0081] and Figs. 10-15, Raj teaches displaying anomaly information for different scenarios); wherein the anomaly aggregation data corresponding to each security scenario is obtained based on: performing anomaly object identification on a plurality of pieces of log data based on an anomaly identification rule associated with the security scenario, and aggregating anomaly data of obtained anomaly objects (paragraphs [0024], [0025], [0036], [0046], [0075]-[0081], [0085], [0110] and Figs. 10-15, Raj teaches various anomaly detection based on rules and logs such as sign on logs, server logs, firewall logs, etc…); and aggregately displaying, in a display region corresponding to the security scenario, information of a plurality of anomaly categories associated with the security scenario, wherein an anomaly category indicated by the anomaly category information is related to the anomaly identification rule (paragraphs (paragraphs [0024], [0025], [0036], [0046], [0075]-[0081], [0085], [0110] and Figs. 10-15, Raj teaches displaying aggregated anomaly information based on categories where the anomalies are based on rules.). Raj does not specifically disclose displaying anomaly aggregation information and security measure aggregation information in the security overview dashboard (emphasis added); the security measure aggregation information comprises information of a plurality of security measures corresponding to the user group and completion information of the plurality of security measures as claimed. However, Murray does disclose displaying anomaly aggregation information and security measure aggregation information in the security overview dashboard; the security measure aggregation information comprises information of a plurality of security measures corresponding to the user group and completion information of the plurality of security measures (paragraphs [0187], [0332]-[0335] and [0348]-[0349], Murray teaches a dashboard displaying progress of policy implementation and audit compliance resolution.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Raj with the teachings of Murray for displaying security measure aggregation information because this would improve user/admin experience. Claims 19 and 20 recite substantially similar subject matter to claim 1 and are therefore, rejected for similar reasons to claim 1 above. As to claim 2, the combination of teachings between Raj and Murray disclose the method according to claim 1, wherein the security scenario comprises at least one of the group consisting of the following: a content security scenario, an account security protection scenario, or an abnormal account protection scenario (paragraphs [0024], [0036] and [0081], Raj teaches compromised account detection.). As to claim 3, the combination of teachings between Raj and Murray disclose the method according to claim 1, further comprising: receiving a modification instruction for modifying the anomaly identification rule; and modifying the anomaly identification rule according to the modification instruction (paragraphs [0036], [0081] and [0085], Raj teaches customizing weight and decay factors and also configurable thresholds.). As to claim 4, the combination of teachings between Raj and Murray disclose the method according to claim 3, wherein the security overview dashboard comprises an anomaly identification rule configuration entry; and the receiving the modification instruction for modifying the anomaly identification rule comprises: receiving the modification instruction sent based on an operation on the anomaly identification rule configuration entry (paragraphs [0036], [0085] and [0085], Raj teaches customizing weight and decay factors and also configurable thresholds.). As to claim 5, the combination of teachings between Raj and Murray disclose the method according to claim 1, further comprising: displaying an anomaly detail chart corresponding to the security scenario in response to an anomaly detail viewing instruction for the security scenario (paragraphs [0076]-[0084] and Figs. 10-15, Raj teaches drill-down details for anomalies); wherein the anomaly detail chart comprises an anomaly distribution map within a preset time period and a list of anomaly objects (paragraphs [0076]-[0084] and Figs. 10-15, Raj teaches anomaly trends over a period); and the list of anomaly objects comprises information of a plurality of anomaly objects (paragraphs [0076]-[0084] and Figs. 10-15, Raj teaches a list of anomalies.). As to claim 6, the combination of teachings between Raj and Murray disclose the method according to claim 5, wherein a first viewing control for viewing the anomaly detail chart of the security scenario is further displayed in the security overview dashboard; and the method further comprises: receiving the anomaly detail viewing instruction triggered by performing a preset operation on the first viewing control of the security scenario (paragraphs [0076]-[0084] and Figs. 10-15, Raj teaches drill-down details for anomalies by clicking a button.). As to claim 8, the combination of teachings between Raj and Murray disclose the method according to claim 5, further comprising: displaying an object anomaly information interface of a target anomaly object in response to receiving an anomaly object detail display instruction triggered based on an anomaly object detail control; wherein the target anomaly object is an anomaly object indicated by the anomaly object detail display instruction, and the object anomaly information interface comprises anomaly detail information corresponding to the target anomaly object (paragraphs [0075]-[0084] and Figs. 10-15, Raj teaches drill-down details for specific anomalies.). As to claim 9, the combination of teachings between Raj and Murray disclose the method according to claim 1, further comprising: displaying anomaly disposal information for performing anomaly disposal on an anomaly object, wherein the anomaly disposal information is configured to handle an anomaly corresponding to at least one anomaly object (paragraphs [0155], [0187], [0332]-[0335] and [0348]-[0349], Murray teaches presenting recommendations to fix anomalies.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 10, the combination of teachings between Raj and Murray disclose the method according to claim 9, wherein the anomaly disposal information is displayed in the anomaly detail chart or in the object anomaly information interface (paragraphs [0155], [0187], [0332]-[0335] and [0348]-[0349], Murray teaches presenting recommendations to fix anomalies.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 12, the combination of teachings between Raj and Murray disclose the method according to claim 9, wherein the disposal information comprises a disposal control for the anomaly object; and the method further comprises: performing a target disposal operation for the anomaly object in response to receiving a trigger operation performed on the disposal control, the target disposal operation being associated with the disposal control (paragraphs [0079] and [0084], Raj teaches paragraphs automated actions. paragraphs [0155], [0187], [0332]-[0335] and [0348]-[0349], Murray teaches presenting recommendations to fix anomalies.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 13, the combination of teachings between Raj and Murray disclose the method according to claim 1, wherein the security measure aggregation information comprises: applied security measures and unapplied security measures displayed in different regions of the security overview dashboard (paragraphs [0161]-[0162], [0287] and [0332]-[0335], Murray teaches display implemented and not implemented fixes as well as progress of fixes.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 15, the combination of teachings between Raj and Murray disclose the method according to claim 2, wherein the security measure aggregation information comprises: applied security measures and unapplied security measures displayed in different regions of the security overview dashboard (paragraphs [0161]-[0162], [0287] and [0332]-[0335], Murray teaches display implemented and not implemented fixes as well as progress of fixes.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 16, the combination of teachings between Raj and Murray disclose the method according to claim 3, wherein the security measure aggregation information comprises: applied security measures and unapplied security measures displayed in different regions of the security overview dashboard (paragraphs [0161]-[0162], [0287] and [0332]-[0335], Murray teaches display implemented and not implemented fixes as well as progress of fixes.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 17, the combination of teachings between Raj and Murray disclose the method according to claim 1, wherein the security measure aggregation information comprises: applied security measures and unapplied security measures displayed in different regions of the security overview dashboard (paragraphs [0161]-[0162], [0287] and [0332]-[0335], Murray teaches display implemented and not implemented fixes as well as progress of fixes.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 18, the combination of teachings between Raj and Murray disclose the method according to claim 4, wherein the security measure aggregation information comprises: applied security measures and unapplied security measures displayed in different regions of the security overview dashboard (paragraphs [0161]-[0162], [0287] and [0332]-[0335], Murray teaches display implemented and not implemented fixes as well as progress of fixes.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Raj and Murray as applied to claim 5 above, and further in view of Kiang et al. (U.S. Pub. No. 2014/0026181 and hereinafter referred to as Kiang). As to claim 7, the combination of teachings between Raj and Murray disclose the method according to claim 5. The combination of teachings between Raj and Murray does not specifically disclose wherein the security scenario is a content security scenario, and the list of anomaly objects comprises at least one piece of anomalous content whose content state is a to-be-concerned state; wherein the content state comprises the to-be-concerned state and a no-need-to-concern state, and the content state of the content is determined according to a content state determination rule as claimed. However, Kiang does disclose wherein the security scenario is a content security scenario, and the list of anomaly objects comprises at least one piece of anomalous content whose content state is a to-be-concerned state; wherein the content state comprises the to-be-concerned state and a no-need-to-concern state, and the content state of the content is determined according to a content state determination rule (paragraphs [0154], [0162], [0180], [0201] and Figs. 40-44, Kiang teaches a quarantine folder for review (i.e. to-be-concerned state) and restored/false positive designation (i.e. no-need-to-concern state).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified invention of Raj with the teachings of Kiang for having to-be-concerned state and a no-need-to-concern state because this would improve user/admin experience. Claim(s) 11 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Raj and Murray as applied to claims 9 and 13 above, and further in view of Zettel, II et al. (U.S. Pub. No. 2019/0268354 and hereinafter referred to as Zettel). As to claim 11, the combination of teachings between Raj and Murray disclose the method according to claim 9. The combination of teachings between Raj and Murray does not specifically disclose wherein the anomaly disposal information comprises a disposal guiding control, and the method further comprises: receiving a disposal policy display instruction triggered by performing a preset operation on the disposal guiding control, and displaying a disposal policy information interface for the anomaly object, the disposal policy information interface comprising a disposal entry; and entering a disposal interface in response to an operation on the disposal entry, the disposal interface being used for disposing the anomaly object as claimed. However, Zettel does disclose wherein the anomaly disposal information comprises a disposal guiding control, and the method further comprises: receiving a disposal policy display instruction triggered by performing a preset operation on the disposal guiding control, and displaying a disposal policy information interface for the anomaly object, the disposal policy information interface comprising a disposal entry; and entering a disposal interface in response to an operation on the disposal entry, the disposal interface being used for disposing the anomaly object (paragraphs [0081], [0082] and [0100], Zettel teaches user selectable security incident resolution in a GUI.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified invention of Raj with the teachings of Zettel for displaying a disposal policy information interface for the anomaly object because this would improve user/admin experience and increase security. As to claim 14, the combination of teachings between Raj and Murray disclose the method according to claim 13. The combination of teachings between Raj and Murray does not specifically disclose further comprising: displaying an application prompt control corresponding to an unapplied security measure for the unapplied security measures; and displaying an application interface corresponding to an unapplied security measure in response to a trigger operation performed on the application prompt control of the unapplied security measure, the application interface being configured to apply the unapplied security measure to information security protection of the user group as claimed. However, Zettel does disclose further comprising: displaying an application prompt control corresponding to an unapplied security measure for the unapplied security measures; and displaying an application interface corresponding to an unapplied security measure in response to a trigger operation performed on the application prompt control of the unapplied security measure, the application interface being configured to apply the unapplied security measure to information security protection of the user group (paragraphs [0085], [0086], [0100] and [0101], Zettel teaches user selectable security incident resolution in a GUI for tasks that have not been completed.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified invention of Raj with the teachings of Zettel for displaying a disposal policy information interface for the anomaly object because this would improve user/admin experience and increase security. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to THADDEUS J PLECHA whose telephone number is (571)270-7506. The examiner can normally be reached M-F 8-4:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /THADDEUS J PLECHA/Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Apr 03, 2025
Application Filed
Aug 18, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744811
ANOMALY DETECTION-BASED ATTENTION PURIFICATION GRAPH DEFENSE METHOD
1y 10m to grant Granted Sep 22, 2026
Patent 12737335
METHODS AND SYSTEMS FOR SECURING DATA CLONING AND SHARING OPTIONS ON DATA WAREHOUSES
3y 7m to grant Granted Sep 15, 2026
Patent 12717940
USING MACHINE-LEARNING MODELS TO DETERMINE GRADUATED LEVELS OF ACCESS TO SECURED DATA FOR REMOTE DEVICES
1y 10m to grant Granted Aug 25, 2026
Patent 12689663
CROSS-PLANE MONITORING INTENT AND POLICY INSTANTIATION FOR NETWORK ANALYTICS AND ASSURANCE
1y 10m to grant Granted Jul 21, 2026
Patent 12683977
SYSTEMS AND METHODS FOR IDENTIFYING SECURITY REQUIREMENTS IN A ZTNA SYSTEM
1y 10m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
97%
With Interview (+10.2%)
2y 5m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 645 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month