Prosecution Insights
Last updated: October 01, 2026
Application No. 19/206,012

INTRUSION DETECTION USING ROBUST SINGULAR VALUE DECOMPOSITION

Non-Final OA §103§DP
Filed
May 12, 2025
Priority
May 25, 2018 — continuation of 11/108,795 +1 more
Examiner
ZEE, EDWARD
Art Unit
Tech Center
Assignee
AT&T Intellectual Property I L.P.
OA Round
1 (Non-Final)
91%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 91% — above average
91%
Career Allowance Rate
820 granted / 905 resolved
+30.6% vs TC avg
Moderate +10% lift
Without
With
+10.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
17 currently pending
Career history
925
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
26.6%
-13.4% vs TC avg
§102
25.6%
-14.4% vs TC avg
§112
23.6%
-16.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 905 resolved cases

Office Action

§103 §DP
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is in response to the correspondence filed on 05/12/25. Claims 1-20 are still pending and have been considered below. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 6-8, 13-15 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Segev et al. (10,148,680) in view of Salunke et al. (2018/0039555). Claim 1: Segev et al. discloses a method comprising: creating an anomaly detection model(anomaly detection system detecting undesirable events using a dataset of MDDPs) [column 3, lines 55-65 | column 4, lines 15-25 & 45-55] including a singular value matrix(matrix of singular value A) [column 4, lines 55-65 | column 5, lines 5-20] and a data pattern matrix from a matrix of historical network traffic data(anomaly detection system receives input from a variety of sources including historian/network traffic data, which can be organized in a matrix and used as a training set for the anomaly detection system) [column 10, lines 25-35 | column 15, lines 5-25]; storing the singular value matrix and the data pattern matrix of the anomaly detection model(constructing a dictionary D and an embedded spaced based on received MDDPs) [column 4, lines 40-50]; receiving streaming network traffic data(streamed data) [column 4, lines 1-10]; performing a log transform on the streaming network traffic data(each newly arrived MDDP is processed through the training/detection process which includes storing a logarithmic value of the NAMDDP) [column 14, lines 45-55 | column 27, lines 50-60]; applying the anomaly detection model to a matrix of the streaming network traffic data(online detection functions) [column 25, lines 55-67 | column 26, lines 1-20]; and detecting at least one anomalous pattern in the streaming network traffic data based on patterns identified by the anomaly detection model(classify MDDP/NAMDDP as abnormal) [column 27, lines 45-55 | column 28, lines 10-20]; but does not explicitly disclose associating the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address. However, Salunke et al. discloses a similar invention [page 6, paragraph 0075] and further discloses associating the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address(example information includes IP address) [page 8, paragraph 0093]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the disclosure of Segev et al. with the additional features of Salunke et al., in order to leverage learned behavior to generate baselines that are tailored to the specific environment under examination, as suggested by Salunke et al. [page 2, paragraph 0035]. Claim 6: Segev et al. and Salunke et al. disclose the method of claim 1, and Segev et al. further discloses further comprising: scoring a severity of the at least one anomalous pattern in the streaming network traffic data(MDDP parameters of the anomalies are scored from strong to weak) [column 13, lines 5-15 | column 14, lines -35-45]. Claim 7: Segev et al. and Salunke et al. disclose the method of claim 6, and Segev et al. further discloses wherein the severity of the at least one anomalous pattern in the streaming network traffic data is scored based on the patterns identified by the anomaly detection model [column 13, lines 5-15 | column 14, lines -35-45]. Claim 8: Segev et al. discloses a system comprising: a memory [column 12, lines 5-15]; a network interface [column 12, lines 20-30]; and one or more processors in communication with the memory and the network interface, the one or more processors configured to [column 12, lines 35-45]: create an anomaly detection model [column 3, lines 55-65 | column 4, lines 15-25 & 45-55] including a singular value matrix [column 4, lines 55-65 | column 5, lines 5-20] and a data pattern matrix from a matrix of historical network traffic data [column 10, lines 25-35 | column 15, lines 5-25]; store the singular value matrix and the data pattern matrix of the anomaly detection model [column 4, lines 40-50]; receive streaming network traffic data [column 4, lines 1-10]; perform a log transform on the streaming network traffic data [column 14, lines 45-55 | column 27, lines 50-60]; apply the anomaly detection model to a matrix of the streaming network traffic data [column 25, lines 55-67 | column 26, lines 1-20]; and detect at least one anomalous pattern in the streaming network traffic data based on patterns identified by the anomaly detection model [column 27, lines 45-55 | column 28, lines 10-20]; but does not explicitly disclose associate the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address. However, Salunke et al. discloses a similar invention [page 6, paragraph 0075] and further discloses associate the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address [page 8, paragraph 0093]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the disclosure of Segev et al. with the additional features of Salunke et al., in order to leverage learned behavior to generate baselines that are tailored to the specific environment under examination, as suggested by Salunke et al. [page 2, paragraph 0035]. Claim 13: Segev et al. and Salunke et al. disclose the system of claim 8, and Segev et al. further discloses wherein the one or more processors are further configured to: score a severity of the at least one anomalous pattern in the streaming network traffic data [column 13, lines 5-15 | column 14, lines -35-45]. Claim 14: Segev et al. and Salunke et al. disclose the system of claim 13, and Segev et al. further discloses wherein the severity of the at least one anomalous pattern in the streaming network traffic data is scored based on the patterns identified by the anomaly detection model [column 13, lines 5-15 | column 14, lines -35-45]. Claim 15: Segev et al. discloses a non-transitory computer-readable storage medium storing instructions which, when executed by a processor, cause the processor to perform operations, the operations comprising: creating an anomaly detection model [column 3, lines 55-65 | column 4, lines 15-25 & 45-55] including a singular value matrix [column 4, lines 55-65 | column 5, lines 5-20] and a data pattern matrix from a matrix of historical network traffic data [column 10, lines 25-35 | column 15, lines 5-25]; storing the singular value matrix and the data pattern matrix of the anomaly detection model [column 4, lines 40-50]; receiving streaming network traffic data [column 4, lines 1-10]; performing a log transform on the streaming network traffic data [column 14, lines 45-55 | column 27, lines 50-60]; applying the anomaly detection model to a matrix of the streaming network traffic data [column 25, lines 55-67 | column 26, lines 1-20]; and detecting at least one anomalous pattern in the streaming network traffic data based on patterns identified by the anomaly detection model [column 27, lines 45-55 | column 28, lines 10-20]; but does not explicitly disclose associating the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address. However, Salunke et al. discloses a similar invention [page 6, paragraph 0075] and further discloses associating the at least one anomalous pattern in the streaming network traffic data with at least one internet protocol address [page 8, paragraph 0093]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the disclosure of Segev et al. with the additional features of Salunke et al., in order to leverage learned behavior to generate baselines that are tailored to the specific environment under examination, as suggested by Salunke et al. [page 2, paragraph 0035]. Claim 20: Segev et al. and Salunke et al. disclose the non-transitory computer-readable storage medium of claim 15, and Segev et al. further discloses wherein the operations further comprise: scoring a severity of the at least one anomalous pattern in the streaming network traffic data [column 13, lines 5-15 | column 14, lines -35-45]. Allowable Subject Matter Claims 2-5, 9-12 and 16-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 11,108,795. Although the claims at issue are not identical, they are not patentably distinct from each other because both inventions are directed to a substantially similar technique of creating and applying an anomaly detection model to detect anomalous patterns in streaming network traffic data, which specifically includes a singular value matrix and a data pattern matrix from a matrix of historical network traffic data. Furthermore, Examiner notes that each and every limitation of the instant claims appear to be substantially anticipated by the corresponding patented claims. Therefore, Examiner respectfully submits that the instant claims and the patented claims are not directed to patentably distinct inventions; thus, properly rejected on the grounds of nonstatutory double patenting. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,301,598. Although the claims at issue are not identical, they are not patentably distinct from each other because both inventions are directed to a substantially similar technique of creating and applying an anomaly detection model to detect anomalous patterns in streaming network traffic data, which specifically includes a singular value matrix and a data pattern matrix from a matrix of historical network traffic data. Furthermore, Examiner notes that each and every limitation of the instant claims appear to be substantially anticipated by the corresponding patented claims. Therefore, Examiner respectfully submits that the instant claims and the patented claims are not directed to patentably distinct inventions; thus, properly rejected on the grounds of nonstatutory double patenting. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Dupont et al. (2012/0137367). Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDWARD ZEE whose telephone number is (571)270-1686. The examiner can normally be reached Monday-Friday 9AM-5PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EDWARD ZEE/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

May 12, 2025
Application Filed
Aug 10, 2026
Non-Final Rejection mailed — §103, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743504
FILTERING FOR HARMFUL GENERATIVE ARTIFICIAL INTELLIGENCE RESULTS
2y 10m to grant Granted Sep 22, 2026
Patent 12737446
RELATIONSHIP AND ATTRIBUTE MANAGEMENT USING DECENTRALIZED IDENTIFIERS
3y 1m to grant Granted Sep 15, 2026
Patent 12707260
NETWORK REPOSITORY FUNCTION SERVICES ACCESS AUTHORIZATION
2y 7m to grant Granted Aug 11, 2026
Patent 12682073
SYSTEM AND METHOD FOR IDENTIFICATION OF SECURITY VULNERABILITIES USING ARTIFICIAL INTELLIGENCE-BASED ANALYSIS OF COMPUTING ENVIRONMENT LOGS
2y 5m to grant Granted Jul 14, 2026
Patent 12683987
DYNAMIC NETWORK SECURITY FOR INDUSTRIAL SYSTEMS
2y 4m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
91%
Grant Probability
99%
With Interview (+10.4%)
2y 4m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 905 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month