Prosecution Insights
Last updated: August 06, 2026
Application No. 19/170,825

Automated Detection and Management System for Unauthorized External Service Accounts Using Large Language Models and Email Analysis

Non-Final OA §103§112
Filed
Apr 04, 2025
Priority
Apr 19, 2024 — provisional 63/636,528
Examiner
ELAHIAN, DANIEL
Art Unit
Tech Center
Assignee
Waldo Security LLC
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
32 granted / 43 resolved
+14.4% vs TC avg
Strong +52% interview lift
Without
With
+52.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
11 currently pending
Career history
59
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
73.1%
+33.1% vs TC avg
§102
11.3%
-28.7% vs TC avg
§112
8.8%
-31.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 43 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The present office action is responsive to communication received 4/4/2025. Claims 1-11 are pending. Information Disclosure Statement The information disclosure statements (IDS) submitted on 4/4/2025 was filed after the mailing date of the application no. 19/170,825 on 4/4/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2-11 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1-11 recite multiple instances of “at least one incoming email”, “at least one report”, “at least one edited email” or “at least one filtered email”. The examiner recommends to reconcile the different instances such that one instance is recited in the independent claims, and referred to in the dependent claim as “the at least one incoming email/edited email/report/filtered email” for improved clarity. Claims 2-3 recite “each edited email …”, “each filtered email …” It is not understood what “each” refers to, rendering the claim indefinite. For examination purpose, the limitations will be interpreted as “the at least one edited email”, “the at least one filtered email”. Regarding claim 2 , the claim recites ”at least 30% to 70%”. This language is internally contradictory because the modifier “at least” implies an open-ended floor, while the phrase “30% to 70” defines a bounded range. It is unclear whether the claim limitation encompasses the range of values in between 30% to 70%, values greater than 30%, or a different scope. Therefore, the metes and bounds of the claim are unclear and cannot be determined with certainty. See MPEP § 2173.05(d). The term “unnecessary” in claim 4 is a relative term which renders the claim indefinite. The term “unnecessary” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Regarding claim 4 , the phrases "word count" and “text length” renders the claim indefinite because it is unclear whether the limitations are intended to be distinct measurements or whether they refer to the same metric. The metes and bounds of the claim are unclear and cannot be determined with certainty. See MPEP § 2173.05(d). Claim 4 (and its dependent claims), and additionally claims 9-11 recite “the large language model” (in singular), which lacks antecedent basis and renders the claim indefinite. Claim 10 recites the limitation "the artificial intelligence check fails" in line 2. There is insufficient antecedent basis for this limitation in the claim. The claim is not understood. LLM can be considered a type of AI, AI encompassing many technologies including LLM. The claim will be considered on the merit after the meaning and scope are understood. Correction is kindly requested. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 1 is rejected under 35 U.S.C. 103 as being unpatentable over by Jakobsson et al. (US 20200336451) in view of Seyeditabari et al. (US 20240356948). Regarding claim 1, Jakobsson teaches A system for detecting and managing unauthorized external service accounts using large language models and email analysis comprising: an online server;[the scam detection system described herein comprises standard commercially available server hardware (e.g., a multi-core processor, 4+ Gigabytes of RAM, and one or more Gigabit network interface adapters) and runs typical server-class operating systems (e.g., Linux), as well as Java HTTP server software stack. (Jakobsson et al., paragraph 76)] a computing device; [FIG. 1 is a block diagram illustrating an embodiment of a system for detecting scam. In the example shown, system 100 may be used to detect scam such as business email compromise. (Jakobsson et al., paragraph 71); Fig. 16, user device with browser 1605] at least one incoming email; [At 301, incoming email is accessed, and the contents of the “from” field are determined. (Jakobsson et al., paragraph 442)] at least one edited email;[ Examples of such actions include quarantining the email message, including a portion of the email message in a request, modifying the email message, and marking the email message with a warning. (Jakobsson et al., paragraph 83, modifying the email representing the edited email)] at least one filtered email;[a filtering decision is generated based on the output of the combining logic component. (Jakobsson et al., paragraph 85)] at least one report; [In some embodiments, blocking also includes reporting of the message to an admin, whether individually or in aggregate. (Jakobsson et al., paragraph 450)] the online server comprising user account, an administrator account, [In some embodiments, blocking also includes reporting of the message to an admin, whether individually or in aggregate. (Jakobsson et al., paragraph 450, Admin)] [at 301 it is determined that an email address E1 is used for sending an email to a protected account (Jakobsson et al., paragraph 443, user account)] [The collected data is then assessed using risk data assessment engine 112 and in some embodiments, stored to database 114 (Jakobsson et al., paragraph 75, storage database)] the computing device comprising a processing device and a communication module; [a message such as an email is received over a network (such as the Internet) via interface 102. (Jakobsson et al., paragraph 72)] the communication module being in remote communication with the online server; [While example embodiments involving email are described below, the techniques described herein can variously be adapted to accommodate any type of communication channel, such as chat, (e.g., instant messaging (IM)), text (e.g., short message service (SMS)), etc., as applicable. (Jakobsson et al., paragraph 31); user communicates with mail server thru the Internet, using a web browser (paragraph 460)] the user account providing at least one incoming email; [a message such as an email is received over a network (such as the Internet) via interface 102. (Jakobsson et al., paragraph 72)] and the administrator account receiving at least one report from the online server. [In some embodiments, blocking also includes reporting of the message to an admin, whether individually or in aggregate. (Jakobsson et al., paragraph 450, admin receiving a reporting)] Jakobsson fails to explicitly disclose a large language model. However in an analogous art Seyeditabari discloses a large language model. [the inference analysis engine 104 is configured to send the email to the large ML model fraud detection engine 106 for further/final classification before passing the final classification of the email to the customer. (Seyeditabari et al., paragraph 21)] [the LLM can be a type of artificial intelligence (AI) algorithm that uses deep learning techniques (e.g., deep neural network models) and large datasets to perform natural language processing (NLP) tasks by recognizing natural language content of the email (Seyeditabari et al., paragraph 21,the large ML is a LLM)] Jakobsson and Seyeditabari are considered to be analogous to the claimed invention because they are in the same field of email analysis. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Jakobsson to incorporate the teachings of Seyeditabari et al. to include a large language model, in order to detect and identify fraudulent emails as soon as possible with accuracy when handling large volumes of emails. (Seyeditabari et al., paragraph 11)] Claims 2-3 are rejected under 35 U.S.C. 103 as being unpatentable over by Jakobsson et al. (US 20200336451) in view of Seyeditabari et al. (US 20240356948) in further view of Liu et al. (US 20240086727). Regarding claim 2, Jakobsson in view of Seyeditabari discloses the system for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 1, each edited email being associated with each incoming email provided by the user account; [ Examples of such actions include quarantining the email message, including a portion of the email message in a request, modifying the email message, and marking the email message with a warning. (Jakobsson et al., paragraph 83)] each filtered email being associated with each edited email processed by the online server; [At 298, an action is performed in response to determining that the risk associated with delivery of the email message to the recipient exceeds the threshold. Examples of such actions include quarantining the email message, including a portion of the email message in a request, modifying the email message, and marking the email message with a warning. (Jakobsson et al., paragraph 83)] [when an input email is evaluated, a filtering decision is generated based on the output of the combining logic component. (Jakobsson et al., paragraph 85, after analysis of the delivery of the email address the email may be modified and then a filtering decision is generated when the input email is finished being evaluated)] Jakobsson in view of Seyeditabari fails to explicitly disclose each filtered email being at least 30% to 70% shorter in text length compared to each associated edited email. However in an analogous art Liu discloses each filtered email being at least 30% to 70% shorter in text length compared to each associated edited email. [the computer can optionally request the user to provide a percentage amount (e.g., 30%) that the computer can reduce the input data set size by to train the machine learning model. It should be noted that 30% is intended as an example only and not as a limitation on illustrative embodiments. In other words, the computer can reduce the size of the input data set by any amount (e.g., 5%, 10%, 15%, 20%, 25%, or the like). Alternatively, the computer can automatically determine the percentage amount to reduce the size of the input data set.. (Liu et al., paragraph 63);] Jakobsson, Seyeditabari, and Liu are considered to be analogous to the claimed invention because they are in the same field of email or data. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Jakobsson/ Seyeditabari to incorporate the teachings of Liu et al. to include each filtered email being at least 30% to 70% shorter in text length compared to each associated edited email, in order to improve the efficiency of machine learning model processing reduced size documents (Liu et al., paragraph 4)] Regarding claim 3, Jakobsson in view of Seyeditabari discloses the system for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 1, but fails to explicitly disclose wherein each edited email being processed if containing less than 700 words. However in an analogous art Liu discloses wherein each edited email being processed if containing less than 700 words. [ (Liu et al., paragraph 63)] Jakobsson, Seyeditabari, and Liu are considered to be analogous to the claimed invention because they are in the same field of email analysis. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Jakobsson/ Seyeditabari to incorporate the teachings of Liu et al. to include each filtered email being at least 30% to 70% shorter in text length compared to each associated edited email, in order to improve the efficiency of machine learning model processing reduced size documents (Liu et al., paragraph 4)] Claims 4-9 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over by Jakobsson et al. (US 20200336451) in view of Bruss et al. (US 10397272) and in further view of Liu et al. (US 20240086727). Regarding claim 4, Jakobsson teaches a method for detecting and managing unauthorized external service accounts using large language models and email analysis comprising: providing, using a user account, at least one incoming email; [a message such as an email is received over a network (such as the Internet) via interface 102. (Jakobsson et al., paragraph 72)] [the risk assessment/classification is based on determining whether the email message is associated with a deceptive sender. (Jakobsson et al., paragraph 72)] compiling, using the online server, findings from the at least one filtered email being processed; [when an input email is evaluated, a filtering decision is generated based on the output of the combining logic component. (Jakobsson et al., paragraph 85, after analysis of the delivery of the email address the email may be modified and then a filtering decision is generated when the input email is finished being evaluated)] [in this example, 904 corresponds to quarantining or marking the message up. In some embodiments, the decision of whether to quarantine or mark up is based on additional determinations and preferences set by the user or an admin associated with the user; where the user corresponds to the party who is the recipient of the email. At 905, the email is blocked. In some embodiments, blocking also includes reporting of the message to an admin, whether individually or in aggregate. (Jakobsson et al., paragraph 450, all the findings are using to create a reporting so the combining of findings into report can be interpreted to be the compiling of findings from the email)] and sending, using the online server, at least one report to the administrator account. [In some embodiments, blocking also includes reporting of the message to an admin, whether individually or in aggregate. An aggregate reporting can notify the admin of how many messages sent from or to a particular user were blocked, or what fraction of such messages was blocked. (Jakobsson et al., paragraph 450, reporting to admin)] [ In addition, the system can flag the email as abusive, and this flagged email can be forwarded to an admin, or used for system training purposes, or both. (Jakobsson et al., paragraph 455)] Jakobsson fails to explicitly disclose removing, using an online server, unnecessary content from the at least one incoming email; filtering, using the online server, the text length of the at least one edited email; submitting, using the online server, at least one filtered email to the large language model. However in an analogous art Bruss discloses removing, using an online server, unnecessary content from the at least one incoming email; filtering, using the online server, the text length of the at least one edited email; [In some cases, pre-processing of email training data may be performed to remove portions of emails from the training (e.g., image embeddings). (Bruss et al., 9:23-26)] submitting, using the online server, at least one filtered email to the large language model (Bruss 4:36-44); Jakobsson and Bruss are considered to be analogous to the claimed invention because they are in the same field of email analysis. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Jakobsson to incorporate the teachings of Bruss et al. to include removing, using an online server, unnecessary content from the at least one incoming email, because it would contribute to identifying malicious emails. (Bruss et al., 9:14-26)] Jakobsson in view of Bruss fails to explicitly disclose filtering at least one edited email based on word count. However in an analogous art Liu discloses filtering at least one edited email based on word count; [the computer can optionally request the user to provide a percentage amount (e.g., 30%) that the computer can reduce the input data set size by to train the machine learning model. It should be noted that 30% is intended as an example only and not as a limitation on illustrative embodiments. In other words, the computer can reduce the size of the input data set by any amount (e.g., 5%, 10%, 15%, 20%, 25%, or the like). Alternatively, the computer can automatically determine the percentage amount to reduce the size of the input data set. (Liu et al., paragraph 63)] Jakobsson, Bruss, and Liu are considered to be analogous to the claimed invention because they are in the same field of email analysis. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Jakobsson and Bruss to incorporate the teachings of Liu et al. to include filtering at least one edited email based on word count in order to improve the efficiency of machine learning model processing reduced size documents (Liu et al., paragraph 4)]. Regarding claim 5, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 4 comprising filtering, using the online sever, at least one incoming email based on email domains. [Bruss et al., column 9, lines 27-37), see claim 4 motivation to combine with Bruss] Regarding claim 6, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 4, comprising processing, using the online server, at least one edited email if the text length of the edited email is less is than 700 words. [see Liu et al., paragraph 63): although a length less than 700 words is not explicitly taught, Liu emphasizes reducing the input (email) at a desired percentage from the original using ML (training data); therefore it would have been obvious to a skilled artisan to process the email if the length is less than 700 words as claimed without undue experimentation and with a reasonable expectation of success] Regarding claim 7, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 6 comprising filtering, using the online server, at least one edited email if the text length of the edited email is more than 150 words (see rejection of claim 6, applying the same logic from the teachings of Liu). Regarding claim 8, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 7 comprising reducing, using the online server, the text length of at least one edited email by at least 30% to 70% (see rejection of claim 6, applying the same logic from the teachings of Liu). Regarding claim 9, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 7, comprising sending, using the online server, at least one edited email to the large language model without reducing the text length if the text length is below 150 words [see Liu et al., paragraph 63): although a length less below 150 words is not explicitly taught, Liu emphasizes reducing the input (email) at a desired percentage from the original before using ML; therefore it would have been obvious to a skilled artisan to process the email if the length is less than 150 words as claimed without undue experimentation and with a reasonable expectation of success.] Regarding claim 11, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 4 comprising: analyzing, using the online server, at least one filtered email with respect to the large language model; storing, using a storage database, the findings processed by the large language model within the online server; and accessing, using the storage database, the findings within the report generated by the online server. [(Bruss et al., column 3, lines 45-60)]. Regarding claim 10, Jakobsson in view of Bruss in further view of Liu discloses the method for detecting and managing unauthorized external service accounts using large language models and email analysis as claimed in claim 4 comprising resubmitting, using the online server, at least one filtered email to the large language model if the artificial intelligence check fails. [not addressed at this time)] Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Su et al. (US 8424091) discloses a property filter which allows for grouping emails according to their length, allowing emails of particular lengths to be filtered out. Heinemeyer et al. (US 12519831) discloses an AI adversary red team configured to pen-test email and/or network defenses implemented by a cyber threat defense system used to protect an organization and all its entities. AI models are trained with machine learning on contextual knowledge of the organization and configured to identify data points from the contextual knowledge including language-based data, email/network connectivity and behavior pattern data, and historic knowledgebase data. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL ELAHIAN whose telephone number is (703) 756-1284. The examiner can normally be reached on Monday – Friday from 7:30am to 5pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at telephone number 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /D.E./DANIEL ELAHIAN, Examiner, Art Unit 2407 /Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 7/24/2026
Read full office action

Prosecution Timeline

Apr 04, 2025
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699802
OBSCURING ELEMENTS BASED ON USER INPUT
4y 1m to grant Granted Aug 04, 2026
Patent 12688302
MODULAR SECURITY EVALUATION OF SOFTWARE ON DEVICES
2y 11m to grant Granted Jul 21, 2026
Patent 12675597
KEY UPDATE USING COMPARISON OF TRANSFORMED FEATURE SETS FOR EXTENDED REALITY PRIVACY
3y 4m to grant Granted Jul 07, 2026
Patent 12670247
DETERMINING INTEGRITY-DRIVEN ERROR TYPES IN MEMORY BUFFER DEVICES
3y 1m to grant Granted Jun 30, 2026
Patent 12664287
SYSTEMS AND METHODS FOR DETERMINING VULNERABILITY CRITICALITY
2y 5m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+52.4%)
2y 11m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 43 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month