Prosecution Insights
Last updated: October 02, 2026
Application No. 19/205,268

ALARM PROCESSING METHOD AND APPARATUS, ELECTRONIC DEVICE, AND COMPUTER-READABLE STORAGE MEDIUM

Non-Final OA §101§112§DP
Filed
May 12, 2025
Priority
Feb 19, 2021 — CN 202110189703.3 +2 more
Examiner
ALMAMUN, ABDULLAH
Art Unit
Tech Center
Assignee
Tencent Technology (Shenzhen) Company Limited
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
327 granted / 419 resolved
+18.0% vs TC avg
Strong +26% interview lift
Without
With
+25.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
15 currently pending
Career history
442
Total Applications
across all art units

Statute-Specific Performance

§101
17.2%
-22.8% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
20.4%
-19.6% vs TC avg
§112
7.7%
-32.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 419 resolved cases

Office Action

§101 §112 §DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a Non-Final Office Action in response to the communication filed on May 12, 2025. Claims 1-20 have been examined. Drawings The drawings filed on May 12, 2025, are acceptable for examination proceedings. Priority Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). The certified copy has been filed in parent Application No. 19/205268, filed on May 12, 2025. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding independent claims 1, 17, and 20, recite the phrase " the plurality of words " on line 6 of claim 1, line 9 of claim 17, and line 2 of claim 20, the claims are indefinite because the phase has not been introduced yet. Dependent claims 2, 3,6, 13, and 18-19 recite the phrase " a plurality of words" at different places throughout the claim, the claims are indefinite because the phase has been introduced previously. Regarding independent claims 1, 17, and 20, recite the phrase " the importance indexes" one line 4 of claim 1, line 7 of claim 17, and line 5 of claim 20, the claims are indefinite because the phase has not been introduced yet. Dependent claims 2, 4, 6, and 18-19 recite the phrase "important indexes" at different places throughout the claim, the claims are indefinite because the phase has been introduced previously. Dependent claims 2-16, and 18-19 inherit the deficiencies of the base claims and therefore are rejected under 35 USC § 112 by virtue of their dependency. Appropriate correction is requested. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. To begin with, claim 1 recites: “…acquiring a plurality of alarm records…; traversing the plurality of words in the plurality of alarm records, … processing the traversed words, … in response …, retaining the first traversed word; and in response …, shielding the second traversed word; determining a similarity between every two of the plurality of alarm records …; and clustering the plurality of alarm records…” The limitation of “…acquiring a plurality of alarm records…; traversing the plurality of words in the plurality of alarm records, … processing the traversed words, retaining the first traversed word; and shielding the second traversed word; performing keyword extraction …; determining a similarity between every two of the plurality of alarm records …; and clustering the plurality of alarm records…” as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “electronic device” nothing in the claim element precludes the step from practically being performed in the mind. For example, but for the “electronic device” language, “acquiring, traversing, retaining, shielding, determining, and clustering” in the context of this claim encompasses the user manually performing the act. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claim recites additional element of – “receiving an alarm query ...” and “perform keyword extraction …”. The electronic device in the step is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of data receiving and data extraction) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using an electronic device to perform the mental steps amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible. The independent claims 17, and 20 recite limitations that are similar to those of claim 1; therefore, rejected under same rational of claim 1. The dependent claims 2-16, and 18-19 which depends on independent claim 1 and 17, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind calculation but for the recitation of generic computer components. Therefore, the dependent claims fail to obviate such rejections and are themselves rejected under this title for they are also abstract ideas. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1, 3-15, 17, and 19-20 are rejected under the judicially created doctrine of obviousness-type double patenting as being unpatentable over claims 1-17 of U.S. Patent No. 12,323,444. Although the conflicting claims are not identical, they are not patentably distinct from each other because all the limitations of claims 1, 3-15, 17, and 19-20 of this instant application are found in claims 1-17 of the patent No. 12,323,444. Therefore, claims 1, 3-15, 17, and 19-20 of this instant application are anticipated by claims 1-17 of Patent 12,323,444, because all the limitation of broader genus claims of this instant application are contained in the narrower species claims of Patent 12,323,444. Application No.19/205268 Patent No. 12,323,444 1. An alarm processing method, performed by an electronic device, the method comprising: receiving an alarm query request for a service, and acquiring a plurality of alarm records of the service; traversing the plurality of words in the plurality of alarm records, and processing the traversed words, comprising: in response to a first traversed word failing to be matched with words of which the importance indexes satisfy an index condition in a security word library, retaining the first traversed word; and in response to a second traversed word successfully matching with one of the words of which the importance indexes satisfy the index condition in the security word library, shielding the second traversed word; performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; and clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters. 1. An alarm processing method, performed by an electronic device, the method comprising: acquiring a plurality of sample attack records of a service, and determining importance indexes corresponding to a plurality of words in the sample attack records on a one-to-one basis, the service being an online service provided by one or more servers to users, the plurality of sample attack records comprising at least source Internet Protocol (IP) addresses and request data of attackers; updating an attack word library according to the plurality of words in the sample attack records and the importance indexes corresponding to the plurality of words in the sample attack records on a one-to-one basis; receiving an alarm query request for the service, and acquiring a plurality of alarm records of the service; (traversing the plurality of words in the plurality of alarm records, and processing the traversed words: when the traversed words fail to be matched with words of which the importance indexes satisfy a second index condition in the security word library, retaining the traversed words; and when the traversed words are successfully matched with the words of which the importance indexes satisfy the second index condition in the security word library, shielding the traversed words) [part of claim 5] performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords, comprising: screening out multiple words of which the importance indexes satisfy a first index condition in the attack word library; and processing a plurality of words in the plurality of alarm records by matching each of the plurality of words with the multiple words from the screening, and using words successfully matched as the attack keywords in the plurality of alarm records; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters; receiving a response processing request for a target alarm record cluster of the plurality of alarm record clusters, the response processing request comprising a blocking or intercepting request; and responding to the response processing request by performing batch blocking or intercepting processing on source IP addresses in the plurality of alarm records in the target alarm record cluster. 2. The method according to claim 1, further comprising: acquiring a plurality of sample attack records of the service, and determining importance indexes corresponding to a plurality of words in the sample attack records on a one-to-one basis; updating the attack word library according to the plurality of words in the sample attack records and the importance indexes corresponding to the plurality of words in the sample attack records on a one-to-one basis, wherein the keyword extraction processing comprises screening out multiple words of which the importance indexes satisfy a first index condition in the attack word library; and processing each of the plurality of words in the plurality of alarm records by matching the plurality of words with the multiple words from the screening, and using words successfully matched as the attack keywords in the plurality of alarm records. 3. The method according to claim 2, wherein screening out the multiple words of which the importance indexes satisfy the first index condition in the attack word library comprises: when the importance indexes of words in the attack word library are positively correlated with an actual importance, performing descending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library; and when the importance indexes of the words in the attack word library are negatively correlated with the actual importance, performing ascending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library. 2. The method according to claim 1, wherein screening out the multiple words of which the importance indexes satisfy the first index condition in the attack word library comprises: when the importance indexes of words in the attack word library are positively correlated with an actual importance, performing descending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library; and when the importance indexes of the words in the attack word library are negatively correlated with the actual importance, performing ascending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library. 4. The method according to claim 2, wherein each of the sample attack records corresponds to an attack type; and determining the importance indexes corresponding to the plurality of words in the sample attack records on the one-to-one basis comprises: traversing the plurality of words in the sample attack records, and processing the traversed words by: determining a total number of sample attack records with the same attack type corresponding to the sample attack records, and using the total number as a first number; determining a number of sample attack records comprising the traversed words in the plurality of sample attack records with the same attack type corresponding to the sample attack records, and using the determined number as a second number; and determining importance indexes of the traversed words based on the first number and the second number. 3. The method according to claim 1, wherein each of the sample attack records corresponds to an attack type; and determining the importance indexes corresponding to the plurality of words in the sample attack records on the one-to-one basis comprises: traversing the plurality of words in the sample attack records, and processing the traversed words by: determining a total number of sample attack records with the same attack type corresponding to the sample attack records, and using the total number as a first number; determining a number of sample attack records comprising the traversed words in the plurality of sample attack records with the same attack type corresponding to the sample attack records, and using the determined number as a second number; and determining importance indexes of the traversed words based on the first number and the second number. Or 16. The device according to claim 14, wherein each of the sample attack records corresponds to an attack type; and determining the importance indexes corresponding to the plurality of words in the sample attack records on the one-to-one basis comprises: traversing the plurality of words in the sample attack records, and processing the traversed words by: determining a total number of sample attack records with the same attack type corresponding to the sample attack records, and using the total number as a first number; determining a number of sample attack records comprising the traversed words in the plurality of sample attack records with the same attack type corresponding to the sample attack records, and using the determined number as a second number; and determining importance indexes of the traversed words based on the first number and the second number. 5. The method according to claim 4, further comprising: for an attack type, taking words in the sample attack records corresponding to the attack type as words for the attack type; taking an attack type corresponding to an attack keyword with a highest occurrence frequency in the alarm record cluster as a cluster attack type corresponding to the alarm record cluster; and responding to the alarm query request according to the plurality of alarm record clusters and the cluster attack types corresponding to the plurality of alarm record clusters. 4. The method according to claim 3, further comprising: for an attack type, taking words in the sample attack records corresponding to the attack type as words for the attack type; taking an attack type corresponding to an attack keyword with a highest occurrence frequency in the alarm record cluster as a cluster attack type corresponding to the alarm record cluster; and responding to the alarm query request according to the plurality of alarm record clusters and the cluster attack types corresponding to the plurality of alarm record clusters. 6. The method according to claim 1, further comprising: acquiring a plurality of sample security records of the service, and determining importance indexes corresponding to a plurality of words in the sample security records on a one-to-one basis; updating a security word library of the service according to a plurality of words in the sample security records and the importance indexes corresponding to the plurality of words in the sample security records on a one-to-one basis. 5. The method according to claim 1, further comprising: acquiring a plurality of sample security records of the service, and determining importance indexes corresponding to a plurality of words in the sample security records on a one-to-one basis; updating a security word library of the service according to a plurality of words in the sample security records and the importance indexes corresponding to the plurality of words in the sample security records on a one-to-one basis; 7. The method according to claim 1, wherein determining the similarity comprises: performing vector conversion processing on the attack keywords in the plurality of alarm records to obtain representation vectors of the plurality of alarm records, and determining the similarity between the representation vectors respectively corresponding to the different alarm records as the similarity between the different alarm records. 6. The method according to claim 1, wherein determining the similarity comprises: performing any one of following processes: performing vector conversion processing on the attack keywords in the plurality of alarm records to obtain representation vectors of the plurality of alarm records, and determining the similarity between the representation vectors respectively corresponding to the different alarm records as the similarity between the different alarm records;… 8. The method according to claim 1, wherein determining the similarity comprises: determining an intersection and a union between the attack keywords corresponding to two alarm records of the plurality of alarm records, and determining a similarity between the two alarm records based on the number of attack keywords in the intersection and the number of attack keywords in the union. 6. The method according to claim 1, … determining an intersection and a union between the attack keywords corresponding to two alarm records of the plurality of alarm records, and determining a similarity between the two alarm records based on the number of attack keywords in the intersection and the number of attack keywords in the union. 9. The method according to claim 7, wherein performing the vector conversion processing on the attack keywords in the plurality of alarm records comprises: performing mapping processing on the attack keywords in the plurality of alarm records according to a mapping function to obtain a mapping value corresponding to each of the attack keywords; and performing one of following processes: performing numerical value-based ascending sorting processing on a plurality of mapping values, and constructing the representation vectors of the plurality of alarm records by the plurality of mapping values which are consistent with a number set value and sorted top; and constructing the representation vectors of the plurality of alarm records according to the mapping values corresponding to the minimum numerical value among a plurality of numerical values corresponding to a plurality of mapping functions on a one-to-one basis, wherein a total number of the plurality of mapping functions is equal to a number threshold. 7. The method according to claim 6, wherein performing the vector conversion processing on the attack keywords in the plurality of alarm records comprises: performing mapping processing on the attack keywords in the plurality of alarm records according to a mapping function to obtain a mapping value corresponding to each of the attack keywords; performing any one of following processes: performing numerical value-based ascending sorting processing on a plurality of mapping values, and constructing the representation vectors of the plurality of alarm records by the plurality of mapping values which are consistent with a number set value and sorted top; and constructing the representation vectors of the plurality of alarm records according to the mapping values corresponding to the minimum numerical value among a plurality of numerical values corresponding to a plurality of mapping functions on a one-to-one basis, wherein a total number of the plurality of mapping functions is equal to a number threshold. 10. The method according to claim 1, wherein clustering the plurality of alarm records according to the similarity comprises: traversing the plurality of alarm records, and processing the traversed alarm records by:determining the numerical maximum similarity between the traversed alarm records and cluster centers of existing alarm record clusters; when the numerical maximum similarity is greater than or equal to a similarity threshold in the alarm query request, adding the traversed alarm records to the alarm record clusters corresponding to the numerical maximum similarity; and when the numerical maximum similarity is less than the similarity threshold, creating a new alarm record cluster, and taking the traversed alarm records as a cluster center of the new alarm record cluster. 8. The method according to claim 1, wherein clustering the plurality of alarm records according to the similarity comprises: traversing the plurality of alarm records, and processing the traversed alarm records by: determining the numerical maximum similarity between the traversed alarm records and cluster centers of existing alarm record clusters; when the numerical maximum similarity is greater than or equal to a similarity threshold in the alarm query request, adding the traversed alarm records to the alarm record clusters corresponding to the numerical maximum similarity; and when the numerical maximum similarity is less than the similarity threshold, creating a new alarm record cluster, and taking the traversed alarm records as a cluster center of the new alarm record cluster. 11. The method according to claim 1, further comprising: taking plurality of alarm records successfully matched with query information comprised in the alarm query request as response alarm records; and presenting father nodes corresponding to the alarm record clusters and child nodes corresponding to the response alarm records in the alarm record clusters, and responding to the alarm query request based on the presented father nodes and child nodes, wherein the query information comprises at least one of an alarm time range, a threat level, a result of whether response processing has been performed, and a result of whether an alarm is false. 9. The method according to claim 1, further comprising: taking the plurality of alarm records successfully matched with query information comprised in the alarm query request as response alarm records; and presenting father nodes corresponding to the alarm record clusters and child nodes corresponding to the response alarm records in the alarm record clusters, and responding to the alarm query request based on the presented father nodes and child nodes, wherein the query information comprises at least one of an alarm time range, a threat level, a result of whether response processing has been performed, and a result of whether an alarm is false. 12. The method according to claim 11, wherein presenting the father node comprises: presenting a father node corresponding to the alarm record cluster and child nodes corresponding to the response alarm records in the alarm record cluster via different presentation parameters, wherein the presentation parameters comprise at least one of color and size; and when the father node corresponding to the alarm record cluster and the child nodes corresponding to the response alarm records in the alarm record cluster are presented, the method further comprises: obtaining the threat levels of the response alarm records corresponding to the child nodes, and presenting the child nodes corresponding to different threat levels through different presentation parameters. 10. The method according to claim 9, wherein presenting the father node comprises: presenting a father node corresponding to the alarm record cluster and child nodes corresponding to the response alarm records in the alarm record cluster via different presentation parameters, wherein the presentation parameters comprise at least one of color and size; and when the father node corresponding to the alarm record cluster and the child nodes corresponding to the response alarm records in the alarm record cluster are presented, the method further comprises: obtaining the threat levels of the response alarm records corresponding to the child nodes, and presenting the child nodes corresponding to different threat levels through different presentation parameters. 13. The method according to claim 12, wherein presenting the father node comprises: determining the size of the father node corresponding to the alarm record cluster according to the number of the response alarm records in the alarm record cluster and the size of the child nodes corresponding to the response alarm records, wherein the sizes of the child nodes corresponding to different response alarm records are the same, and the size of the father node is different from the size of the child nodes; presenting the father node corresponding to the alarm record cluster according to the size of the father node; and presenting the child nodes corresponding to the response alarm records in the alarm record cluster in the father node according to the size of the child nodes. 11. The method according to claim 10, wherein presenting the father node comprises: determining the size of the father node corresponding to the alarm record cluster according to the number of the response alarm records in the alarm record cluster and the size of the child nodes corresponding to the response alarm records, wherein the sizes of the child nodes corresponding to different response alarm records are the same, and the size of the father node is different from the size of the child nodes; presenting the father node corresponding to the alarm record cluster according to the size of the father node; and presenting the child nodes corresponding to the response alarm records in the alarm record cluster in the father node according to the size of the child nodes. 14. The method according to claim 13, wherein the presenting the child nodes comprises: presenting a plurality of child nodes subjected to uniform distribution processing in the father node; or presenting a plurality of child nodes subjected to uniform distribution processing and random offset processing in the father node. 12. The method according to claim 11, wherein the presenting the child nodes comprises: performing any one of the following processing: presenting a plurality of child nodes subjected to uniform distribution processing in the father node; and presenting a plurality of child nodes subjected to uniform distribution processing and random offset processing in the father node. 15. The method according to claim 11, further comprising: performing summary extraction processing on a plurality of response alarm records in the alarm record cluster to obtain summary information about the father node corresponding to the alarm record cluster; presenting the summary information of a previewed father node in response to a preview operation for a presented father node; and presenting the response alarm records respectively corresponding to a plurality of child nodes of the selected father node in response to a selection operation for a presented father node. 13. The method according to claim 9, further comprising: performing summary extraction processing on a plurality of response alarm records in the alarm record cluster to obtain summary information about the father node corresponding to the alarm record cluster; presenting the summary information of a previewed father node in response to a preview operation for any presented father node; and presenting the response alarm records respectively corresponding to a plurality of child nodes of the selected father node in response to a selection operation for any presented father node. 16. The method according to claim 15, further comprising: receiving a response processing request for one of the alarm record clusters; and performing response processing on a plurality of alarm records in one of the alarm record clusters, and responding to a response processing request based on a response processing result. 17. An electronic device, comprising: a memory, configured to store executable instructions; and a processor, coupled with the memory and configured, when the executable instructions being executed, to implement: receiving an alarm query request for a service, and acquiring a plurality of alarm records of the service; traversing the plurality of words in the plurality of alarm records, and processing the traversed words, comprising: in response to a first traversed word failing to be matched with words of which the importance indexes satisfy an index condition in a security word library, retaining the first traversed word; and in response to a second traversed word successfully matching with one of the words of which the importance indexes satisfy the index condition in the security word library, shielding the second traversed word; performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; and clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters. 14. An electronic device, comprising: a memory, configured to store executable instructions; and a processor, coupled with the memory and configured, when executing the executable instructions, to perform: second number of a service, and determining importance indexes corresponding to a plurality of words in the sample attack records on a one-to-one basis, the service being an online service provided by one or more servers to users, the plurality of sample attack records comprising at least source IP addresses and request data of attackers; updating an attack word library according to the plurality of words in the sample attack records and the importance indexes corresponding to the plurality of words in the sample attack records on a one-to-one basis; receiving an alarm query request for the service, and acquiring a plurality of alarm records of the service; performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords, comprising: screening out multiple words of which the importance indexes satisfy a first index condition in the attack word library; and processing a plurality of words in the plurality of alarm records by matching each of the plurality of words with the multiple words from the screening, and using words successfully matched as the attack keywords in the plurality of alarm records; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters; receiving a response processing request for a target alarm record cluster of the plurality of alarm record clusters, the response processing request comprising a blocking or intercepting request; and responding to the response processing request by performing batch blocking or intercepting processing on source IP addresses in the plurality of alarm records in the target alarm record cluster. 18. The device according to claim 17, wherein the processor is further configured to implement: acquiring a plurality of sample attack records of the service, and determining importance indexes corresponding to a plurality of words in the sample attack records on a one-to-one basis; updating the attack word library according to the plurality of words in the sample attack records and the importance indexes corresponding to the plurality of words in the sample attack records on a one-to-one basis, wherein the keyword extraction processing comprises screening out multiple words of which the importance indexes satisfy a first index condition in the attack word library; and processing each of the plurality of words in the alarm records by matching the plurality of words with the multiple words from the screening, and using words successfully matched as the attack keywords in the alarm records. 19. The device according to claim 18, wherein the processor is further configured to implement: when the importance indexes of words in the attack word library are positively correlated with an actual importance, performing descending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library; and when the importance indexes of the words in the attack word library are negatively correlated with the actual importance, performing ascending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library. 15. The device according to claim 14, wherein the processor is further configured to: when the importance indexes of words in the attack word library are positively correlated with an actual importance, performing descending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library; and when the importance indexes of the words in the attack word library are negatively correlated with the actual importance, performing ascending sorting processing on the plurality of words in the attack word library based on the importance indexes to obtain a plurality of words sorted top in the attack word library. 20. A non-transitory computer-readable storage medium, storing executable instructions, wherein when being executed, the executable instructions causes a processor to implement: receiving an alarm query request for a service, and acquiring a plurality of alarm records of the service; traversing the plurality of words in the plurality of alarm records, and processing the traversed words, comprising:in response to a first traversed word failing to be matched with words of which the importance indexes satisfy an index condition in a security word library, retaining the first traversed word; andin response to a second traversed word successfully matching with one of the words of which the importance indexes satisfy the index condition in the security word library, shielding the second traversed word;performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; and clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters. 17. A non-transitory computer-readable storage medium, storing executable instructions, wherein when being executed, the executable instructions causes a processor to implement: acquiring a plurality of sample attack records of a service, and determining importance indexes corresponding to a plurality of words in the sample attack records on a one-to-one basis, the service being an online service provided by one or more servers to users, the plurality of sample attack records comprising at least source IP addresses and request data of attackers; updating an attack word library according to the plurality of words in the sample attack records and the importance indexes corresponding to the plurality of words in the sample attack records on a one-to-one basis; receiving an alarm query request for the service, and acquiring a plurality of alarm records of the service; performing keyword extraction processing on the plurality of alarm records according to an attack word library of the service to obtain attack keywords, comprising: screening out multiple words of which the importance indexes satisfy a first index condition in the attack word library; and processing a plurality of words in the plurality of alarm records by matching each of the plurality of words with the multiple words from the screening, and using words successfully matched as the attack keywords in the plurality of alarm records; determining a similarity between every two of the plurality of alarm records according to the attack keywords in the plurality of alarm records; clustering the plurality of alarm records according to the similarity to obtain a plurality of alarm record clusters; receiving a response processing request for a target alarm record cluster of the plurality of alarm record clusters, the response processing request comprising a blocking or intercepting request; and responding to the response processing request by performing batch blocking or intercepting processing on source IP addresses in the plurality of alarm records in the target alarm record cluster Claims 1-17 of Patent No. 12,323,444 contain every element of claims 1, 3-15, 17, and 19-20 of the instant application and thus anticipate the claims of the instant application. Claims of the instant application therefore are not patently distinct from the earlier patent claims and as such are unpatentable over obvious-type double patenting. A later application/patent claim is not patentably distinct from an earlier claim if the later claim anticipated by the earlier claim. “A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness-type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001). Accordingly, absent a terminal disclaimer, claims 1, 3-15, 17, and 19-20 were properly rejected under the doctrine of obviousness-type double patenting.” (In re Goodman (CA FC) 29 USPQ2d 2010 (12/3/1993). Allowable Subject Matter Claims 1-20 would be allowable if rewritten or amended to overcome the rejection(s) under 112 Second, 101 (Alice), and Double Patenting set forth in this Office action. The following is an examiner’s statement of reasons for allowance: Regarding independent claims 1, 17, and 20: The closest prior art Walthers et al. (US 2020/0013070 A1) discloses obtaining incident report attributes by utilizing a group of pre-defined set of values (Walthers, Para 0039: lines 29-31). The second closest prior art Rathod et al. (US 2020/0202302 A1) discloses “…request sensitive data from the data subject 16. Along with a request, the DCDM 8 can provide the conformance certificate that verifies the integrity of the DCDM 8. Upon receiving the request, the data subject 16 and the DCDM 8 can mutually validate each other” (Para 0010:14-35). The third closest prior art Baskar Jayaraman (US 2020/0349199 A1) discloses similarities between the input text string and each of the text string in the database calculated (Jayaraman, Para 0177) and identifies a relevant subset of the pre-calculated vector representation (Jayaraman, Para 0008). However, the prior arts alone or in combination fails to teach or suggest the claimed limitation of independent claims 1, 17, and 20 “...acquiring a plurality of sample security records of the service, and determining importance indexes corresponding to a plurality of words in the sample security records on a one-to-one basis; updating a security word library of the service according to a plurality of words in the sample security records and the importance indexes corresponding to the plurality of words in the sample security records on a one-to-one basis; after obtaining the plurality of alarm records of the service, the method further comprises: traversing the plurality of words in the alarm records, and processing the traversed words: when the traversed words fail to be matched with words of which the importance indexes satisfy a second index condition in the security word library, retaining the traversed words; and when the traversed words are successfully matched with the words of which the importance indexes satisfy the second index condition in the security word library, shielding the traversed words” along with other limitations independent claims 1, 17, and 20. For this reason, the specific claim limitations recited in the independent claims 1, 17, and 20 taken as whole are allowed. The dependent claims 2-16, and 18-19 which are dependent on the above independent claims 1, 17, and 20 being further limiting to the independent claim, definite and enabled by the specification are also allowed. Any comments considered necessary by applicant must be submitted Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance”. Relevant Prior Arts The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Hideki Yamanaka (US 20070206770 A1) discloses “Incidents handled by the same agent are extracted from the incident information, and the most similar incidents are coupled to form a cluster. A general lexical analysis technology based on vector similarity can be used to determine the similarity of contents of incidents. In this manner, the most similar incidents or clusters are coupled to form a cluster tree”(Para 0048). Jayaraman et al. (US 20200089765 A1) discloses “…word vectors could be determined based on text in incident reports (e.g., incident reports related to IT (information technology) incidents in a managed IT infrastructure) and the word vectors could be used to determine similarity within a set of incident reports, e.g., to find solved incidents that are similar to newly received incident reports, or to identify clusters of related incident reports in order to identify ongoing issues within an IT system” (Para 003). Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULLAH ALMAMUN whose telephone number is (571) 270-3392. The examiner can normally be reached on 8 AM - 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ABDULLAH ALMAMUN/Examiner, Art Unit 2431 /LYNN D FEILD/Supervisory Patent Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

May 12, 2025
Application Filed
Sep 14, 2026
Non-Final Rejection mailed — §101, §112, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739641
ATTACKER IDENTIFICATION DURING SMALL DATA TRANSMISSION
2y 8m to grant Granted Sep 15, 2026
Patent 12739137
METHOD FOR PROVIDING A RANDOM FOR A CRYPTOGRAPHIC ALGORITHM, RELATED METHOD FOR PROCESSING A DATA AND COMPUTER PROGRAM
2y 9m to grant Granted Sep 15, 2026
Patent 12726489
ATTACK RISK ASSESSMENT SYSTEM OF AN ADVANCED PERSISTENT THREAT AND THE OPERATION METHOD
3y 9m to grant Granted Sep 01, 2026
Patent 12719678
TRAINING NEURAL NETWORKS WITH NON-POLYNOMIAL ELEMENTS FOR HOMOMORPHIC ENCRYPTION COMPUTATIONS USING SUB-NETWORKS AND MULTI-LOSS
3y 5m to grant Granted Aug 25, 2026
Patent 12712715
INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, COMPUTER PROGRAM PRODUCT, AND INFORMATION PROCESSING SYSTEM
2y 2m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+25.8%)
3y 3m (~1y 11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 419 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month