Prosecution Insights
Last updated: August 17, 2026
Application No. 19/179,170

THREAT MITIGATION SYSTEM AND METHOD

Non-Final OA §101§103§DP
Filed
Apr 15, 2025
Priority
Feb 23, 2023 — provisional 63/486,617 +1 more
Examiner
HAILU, TESHOME
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
ReliaQuest Holdings LLC
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
555 granted / 711 resolved
+20.1% vs TC avg
Strong +24% interview lift
Without
With
+23.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
14 currently pending
Career history
730
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
56.3%
+16.3% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
7.7%
-32.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 711 resolved cases

Office Action

§101 §103 §DP
DETAILED ACTION This office action is in response to the original application filed on April 15, 2025. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-30 are pending. Claim Objections Claims 1, 11 and 21 objected to because of the following informalities: claims 1, 11 and 21 claims “AI” in line 7, 9 and 8 respectively. This term should be written as “Artificial Intelligence (AI)” at least once in each independent claims. Appropriate correction is required. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-30 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-21 of U.S. Patent No. 12,388,863. Although the claims at issue are not identical, they are not patentably distinct from each other because the instant application and ‘863 is directed to a method for mitigating a threat that utilize a universal query language. Claims 1-30 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-27 of U.S. Patent No. 12,355,807. Although the claims at issue are not identical, they are not patentably distinct from each other because the instant application and ‘807 is directed to a method for mitigating a threat that utilize a universal query language. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 11-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claims 11-20 are directed to a computer program product residing on a computer readable medium. Examiner respectfully asserts that the claimed subject matter does not fall with the statutory class listed in 35 U.S.C. 101. The specification defines the computer readable medium as any kind of readable medium (i.e., see paragraph 788) and therefore, it could be interpreted as a communication media which does not fall within one of the four statutory classes of 101. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-2, 4-5, 7-12, 14-15, 17-22, 24-25 and 27-30 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy (US Pub. No. 2021/0160258) in view of Huang (US Pub. No. 2021/0185039). As per claim 1 Murphy discloses: A computer-implemented method executed on a computing device comprising: establishing connectivity with a plurality of security-relevant subsystems within a computing platform; (paragraph 5 of Murphy, establishing connectivity with a plurality of security-relevant subsystems within a computing platform). Receiving an initial notification of a security event from one of the security- relevant subsystems, wherein the initial notification includes a computer-readable language portion that defines one or more specifics of the security event; (paragraph 99 of Murphy, threat mitigation process 10 may be configured to obtain and combine information from multiple security-relevant subsystem to generate a security profile for computing platform 60. For example, threat mitigation process 10 may obtain 300 first system-defined platform information (e.g., system-defined platform information 232) concerning a first security-relevant subsystem (e.g., the number of operating systems deployed) within computing platform 60 and may obtain 302 at least a second system-defined platform information (e.g., system-defined platform information 234) concerning at least a second security-relevant subsystem (e.g., the number of antivirus systems deployed) within computing platform 60) and (paragraph 193 of Murphy, threat mitigation process 10 may be configured to receive updated threat event information for security-relevant subsystems 226. For example, threat mitigation process 10 may receive 1100 updated threat event information 270 concerning computing platform 60, wherein updated threat event information 270 may define one or more of: updated threat listings; updated threat definitions; updated threat methodologies; updated threat sources; and updated threat strategies. Threat mitigation process 10 may enable 1102 updated threat event information 270 for use with one or more security-relevant subsystems 226 within computing platform 60). Processing the initial notification using a generative Al model and one or more tools to define one or more recommended actions, (paragraph 92 of Murphy, threat mitigation process 10 may include probabilistic process 56 (e.g., an artificial intelligence/machine learning process) that may be configured to process information (e.g., information 58), wherein examples of information 58 may include but are not limited to platform information (e.g., structured or unstructured content) that may be scanned to detect security events (e.g., access auditing; anomalies; authentication; denial of services; exploitation; malware; phishing; spamming; reconnaissance; and/or web attack) within a monitored computing platform (e.g., computing platform 60)). Automatically generating a playbook to effectuate at least one of the recommended actions; and processing the playbook to address at least a portion of the security event. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Murphy teaches the method of processing and executing remedial action to mitigate the threat (see paragraph 166 of Murphy) but fails to disclose: Wherein the one or more tools include one or more of: a decompression tool to decompress a compressed initial notification; and an identification tool to identify an owner of a domain associated with the initial notification. However, in the same field of endeavor, Huang teaches this limitation as, (paragraph 307 of Huang, optionally, if the security group association information is compressed, the synchronization node may receive the compressed security group association information, and decompress the compressed security group association information to obtain the security group association information. For example, the synchronization node may receive security group association information in a zip format, and decompress the security group association information in the zip format to obtain the security group association information). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Murphy and include the above limitation using the teaching of Huang in order to enhance the security of computing system by decompressing the received compressed security information and obtain the security information (see paragraph 57 of Huang). Claims 11 and 21 are rejected under the same reason set forth in rejection of claim 1. As per claim 2 Murphy in view of Huang discloses: The computer-implemented method of claim 1 wherein receiving an initial notification of a security event from one of the security-relevant subsystems includes: receiving the initial notification of the security event from an agent executed on one of the security-relevant subsystems. (Paragraph 99 of Murphy, threat mitigation process 10 may be configured to obtain and combine information from multiple security-relevant subsystem to generate a security profile for computing platform 60. For example, threat mitigation process 10 may obtain 300 first system-defined platform information (e.g., system-defined platform information 232) concerning a first security-relevant subsystem (e.g., the number of operating systems deployed) within computing platform 60 and may obtain 302 at least a second system-defined platform information (e.g., system-defined platform information 234) concerning at least a second security-relevant subsystem (e.g., the number of antivirus systems deployed) within computing platform 60). Claims 12 and 22 are rejected under the same reason set forth in rejection of claim 2. As per claim 4 Murphy in view of Huang discloses: The computer-implemented method of claim 1 wherein processing the initial notification using a generative AI model one or more tools to define one or more recommended actions includes: processing the initial notification using the generative AI model, the one or more tools, and a formatting script to define the one or more recommended actions for the initial notification. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Claims 14 and 24 are rejected under the same reason set forth in rejection of claim 4. As per claim 5 Murphy in view of Huang discloses: The computer-implemented method of claim 4 wherein processing the initial notification using a generative AI model, one or more tools, and a formatting script to define one or more recommended actions includes: utilizing prompt engineering to define one or more recommended actions for the initial notification. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Claims 15 and 25 are rejected under the same reason set forth in rejection of claim 5. As per claim 7 Murphy in view of Huang discloses: The computer-implemented method of claim 1 wherein processing the initial notification using a generative AI model and one or more tools to define one or more recommended actions includes: utilizing several loops and/or nested loops to define one or more recommended actions for the initial notification. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Claims 17 and 27 are rejected under the same reason set forth in rejection of claim 7. As per claim 8 Murphy in view of Huang discloses: The computer-implemented method of claim 1 wherein automatically generating a playbook to effectuate at least one of the recommended actions includes: automatically generating a playbook based, at least in part, upon best practices defined via artificial intelligence. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report) and (paragraph 92 of Murphy, threat mitigation process 10 may include probabilistic process 56 (e.g., an artificial intelligence/machine learning process) that may be configured to process information (e.g., information 58), wherein examples of information 58 may include but are not limited to platform information (e.g., structured or unstructured content) that may be scanned to detect security events (e.g., access auditing; anomalies; authentication; denial of services; exploitation; malware; phishing; spamming; reconnaissance; and/or web attack) within a monitored computing platform (e.g., computing platform 60)). Claims 18 and 28 are rejected under the same reason set forth in rejection of claim 8. As per claim 9 Murphy in view of Huang discloses: The computer-implemented method of claim 1 wherein the playbook defines a set of procedures and/or guidelines configured to at least partially address the security event. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Claims 19 and 29 are rejected under the same reason set forth in rejection of claim 9. As per claim 10 Murphy in view of Huang discloses: The computer-implemented method of claim 9 wherein processing the playbook to address at least a portion of the security event includes: performing the set of procedures and/or guidelines defined within the playbook. (Paragraph 166 of Murphy, once assigned 910 a threat level, threat mitigation process 10 may execute 912 a remedial action plan (e., remedial action plan 252) based, at least in part, upon the assigned threat level) and (paragraph 168 of Murphy, when executing 912 a remedial action plan, threat mitigation process 10 may generate 916 a security event report (e.g., security event report 254) based, at least in part, upon the artifacts (e.g., artifacts 250) gathered 904; and provide 918 the security event report). Claims 20 and 30 are rejected under the same reason set forth in rejection of claim 10. Claims 3, 13 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy (US Pub. No. 2021/0160258) in view of Huang (US Pub. No. 2021/0185039) and further in view of Rockwell (US Pub. No. 2005/0254654). As per claim 3: The combination of Murphy and Huang teaches the method of processing and executing remedial action to mitigate the threat (see paragraph 166 of Murphy) but fails to disclose: The computer-implemented method of claim 1 wherein the one or more tools further includes a decoding tool to decode an encoded initial notification. However, in the same field of endeavor, Rockwell teaches this limitation as, (paragraph 39 of Rockwell, the security event server 45 also receives mobile platform security logs. The security event server 45 decodes the security logs and creates security events). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Murphy and Huang to include the above limitation using the teaching of Rockwell in order to enhance the computing system by decoding and creating the security events (see paragraph 39 of Rockwell). Claims 13 and 23 are rejected under the same reason set forth in rejection of claim 3. Claims 6, 16 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy (US Pub. No. 2021/0160258) in view of Huang (US Pub. No. 2021/0185039) and further in view of Linton (US Pub. No. 2021/0273954). As per claim 6: The combination of Murphy and Huang teaches the method of processing and executing remedial action to mitigate the threat (see paragraph 166 of Murphy) but fails to disclose: The computer-implemented method of claim 1 wherein processing the initial notification using a generative AI model and one or more tools to define one or more recommended actions includes: processing the initial notification using a large language model. However, in the same field of endeavor, Linton teaches this limitation as, (paragraph 70 of Linton, still referring to step 530, in an embodiment, the SIEM program module 420 uses self-supervision comparable to that used to train very large language models such and BERT and GPT-2 to train the deep neural network backbone to predict a next network or system event in a time series) and (paragraph 1 of Linton, aspects of the present invention generally relate to computing devices and, more particularly, to methods and systems for artificially intelligent security incident and event management using an attention-based deep neural network and transfer learning). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Murphy and Huang to include the above limitation using the teaching of Linton in order to enhance the computing system by using artificially intelligent security incident and event management using attention based deep neural network learning (see paragraph 1 of Linton). Claims 16 and 26 are rejected under the same reason set forth in rejection of claim 6. Conclusion The prior art made or record and not relied upon is considered pertinent to applicant’s disclosure is North (US Pub. No. 2018/0307833). Noeth discloses: Provided is an intrusion detection technique configured to: obtain kernel-filter criteria indicative of which network traffic is to be deemed potentially malicious, determine that a network packet is resident in a networking stack, access at least part of the network packet, apply the kernel-filter criteria to the at least part of the network packet and, based on applying the kernel-filter criteria, determining that the network packet is potentially malicious, associate the network packet with an identifier of an application executing in userspace of the operating system and to which or from which the network packet is sent, and report the network packet in association with the identifier of the application to an intrusion-detection agent executing in userspace of the operating system of the host computing device, the intrusion-detection agent being different from the application to which or from which the network packet is sent. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TESHOME HAILU whose telephone number is (571)270-3159. The examiner can normally be reached M-F 8 a.m. - 5 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TESHOME HAILU/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Apr 15, 2025
Application Filed
Jul 14, 2026
Non-Final Rejection mailed — §101, §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705496
METHOD AND APPARATUS FOR AUTOMATICALLY GENERATING WELDING PROCEDURE SPECIFICATION USING MACHINE LEARNING ALGORITHMS
2y 10m to grant Granted Aug 11, 2026
Patent 12705609
System, Method, and Computer Program Product for Secure Data Distribution
1y 12m to grant Granted Aug 11, 2026
Patent 12695636
PROOF OF DATA RETENTION WITH BLOCKCHAIN
1y 11m to grant Granted Jul 28, 2026
Patent 12694044
DATA PROCESSING SYSTEMS AND METHODS FOR AUTOMATICALLY DETECTING AND DOCUMENTING PRIVACY-RELATED ASPECTS OF COMPUTER SOFTWARE
1y 7m to grant Granted Jul 28, 2026
Patent 12688294
VIRTUAL TRUSTED PLATFORM MODULE IMPLEMENTATION METHOD AND RELATED APPARATUS
3y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+23.5%)
3y 3m (~1y 11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 711 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month