Prosecution Insights
Last updated: October 02, 2026
Application No. 19/207,141

Capturing Importance In A Network Using Graph Theory

Non-Final OA §DP
Filed
May 13, 2025
Priority
Nov 01, 2021 — provisional 63/274,376 +3 more
Examiner
TABOR, AMARE F
Art Unit
Tech Center
Assignee
Darktrace Holdings Limited
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
694 granted / 837 resolved
+22.9% vs TC avg
Strong +23% interview lift
Without
With
+23.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
12 currently pending
Career history
846
Total Applications
across all art units

Statute-Specific Performance

§101
10.7%
-29.3% vs TC avg
§103
61.0%
+21.0% vs TC avg
§102
11.3%
-28.7% vs TC avg
§112
6.2%
-33.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 837 resolved cases

Office Action

§DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority This application is continuation of US Appl. 17/977,621, filed on 10/31/ 2022; now USP 12335293 B2. Claims 1-20, filed on 05/13/2025, are presented for examination. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12335293 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims are similar (almost the same). Please see claim-comparison (of independent claim 1) table below, Instant Application USP 12335293 B2 1. An apparatus, comprising: an importance node module configured to compute, via a mathematical function and use of one or more graphs, an importance of a network node in the one or more graphs based on at least two or more factors that at least include a hierarchy of a user in an organization, a job title of the user in the organization, aggregated account privileges from multiple different network domains for the user, and a level of shared resource access for the user, where the importance node module is further configured to supply the one or more graphs as input into an attack path modeling component, where [[the]] network nodes in a network include both network devices as well as user accounts, where the attack path modeling component is configured to i) understand the importance of a particular network node in the network compared to other network nodes in the network, and ii) determine key pathways within the network and associated vulnerable network nodes in the network that a cyber-attack would use during the cyber-attack, via a modeling of the cyber-attack with at least one of 1) a cyber threat attack simulator and 2) a clone network created in a virtual machine environment of the network under analysis, where the attack path modeling component is configured to understand the importance of the network nodes in the network compared to the other network nodes in the network based on the supplied input from the importance node module; where the importance node module and the attack path modeling component are configured to cooperate to analyze the importance of the network nodes in the network compared to other network nodes in the network, and the key pathways within the network and the vulnerable network nodes in the network that the cyber-attack would use during the cyber-attack in order to provide an intelligent prioritization of a remediation action to remediate the cyber-attack for a first network node from the network protected by an Artificial Intelligence (AI) based cyber security system; a remediation suggester module configured to cooperate with the attack path modeling component to analyze results of the modeling the cyber-attack occurrence for each node in the network and suggest how to perform the intelligent prioritization of a remediation action on the first network node based upon at least an importance of the first network node compared to the other network nodes in at least one of a report and an autonomous remediation action initiated by the remediation suggester to mitigate against the cyber-attack; one or more processing units configured to execute software instructions associated with the importance node module, the attack path modeling component, and the remediation suggester module; and one or more non-transitory storage mediums configured to store at least software associated with the with the importance node module, the attack path modeling component, and the remediation suggester module. 1. An apparatus, comprising: an importance node module configured to compute, via a mathematical function and use of one or more graphs, an importance of a network node in the one or more graphs based on at least two or more factors that at least include a hierarchy of a user in an organization, a job title of the user in the organization, aggregated account privileges from multiple different network domains for the user, and a level of shared resource access for the user, where the importance node module is further configured to supply the one or more graphs as input into an attack path modeling component, where network nodes in a network include both network devices as well as user accounts, where the attack path modeling component is configured to i) understand the importance of a particular network node in the network compared to other network nodes in the network, and ii) determine key pathways within the network and associated vulnerable network nodes in the network that a cyber-attack would use during the cyber-attack, via a modeling of the cyber-attack with at least one of 1) a cyber threat attack simulator and 2) a clone network created in a virtual machine environment of the network under analysis, where the attack path modeling component is configured to understand the importance of the network nodes in the network compared to the other network nodes in the network based on the supplied graph input from the importance node module; where the importance node module and the attack path modeling component are configured to cooperate to analyze the importance of the network nodes in the network compared to other network nodes in the network, and the key pathways within the network and the vulnerable network nodes in the network that the cyber-attack would use during the cyber-attack in order to provide an intelligent prioritization of a remediation action to remediate the cyber-attack for a first network node from the network protected by an Artificial Intelligence (AI) based cyber security system; a remediation suggester module configured to cooperate with the attack path modeling component to analyze results of the modeling the cyber-attack occurrence for each node in the network and suggest how to perform the intelligent prioritization of a remediation action on the first network node based upon at least an importance of the first network node compared to the other network nodes in at least one of a report and an autonomous remediation action initiated by the remediation suggester module to mitigate against the cyber-attack; one or more processing units configured to execute software instructions associated with the importance node module, the attack path modeling component, and the remediation suggester module; and one or more non-transitory storage mediums configured to store at least software associated with the importance node module, the attack path modeling component, and the remediation suggester module. Independent claim 10 and claim 20 respectively recite method and computer readable version of claim 1; and claims 2-9 and 11-20 are rejected based on their dependence. Note: Examiner has contacted applicant’s representative office and requested to file terminal disclaimer. Office Action is requested for review (Interview Summary). Allowable Subject Matter Claims 1-20 will be allowed if the above non-statutory DP is overcome; i.e., when terminal disclaimer is filed. A determination for allowance is based on examiner’s thorough search and also based on the patented claims that almost exactly reflect the instant application claims. Pertinent arts found include, US 11695795 B2 directed to an agile security platform for enterprise-wide cyber-security and performing actions of receiving, from an agile security platform, analytical attack graph (AAG) data representative of one or more AAGs, each AAG representing one or more lateral paths within an enterprise network for reaching a target asset from one or more assets within the enterprise network, determining, for each instance of a plurality of instances of the AAG, a graph value representing a measure of hackability of the enterprise network at respective times, providing a profile of the enterprise network based on a set of graph values determined for instances of the AAG, the profile representing changes in graph values over time, determining an effectiveness of one or more security controls based on the profile, and selectively executing one or more remedial actions in response to the effectiveness; and, US 2018/0234435 A1 directed to A cyber-security system and method for proactively predicting cyber-security threats are provided. The method comprises receiving a plurality of security events classified to different groups of events; correlating the plurality of received security events to classify potential cyber-security threats to a set of correlation types; determining a correlation score for each classified potential cyber-security threat; and determining a prediction score for each classified potential cyber-security threat, wherein the prediction score is determined based in part on the correlation score. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. (See PTO—892). For example, US 9516053 B1 is pertinent art directed to Network Security Threat Detection By User/user-entity Behavioral Analysis. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMARE F TABOR whose telephone number is (571) 270-3155. The examiner can normally be reached Mon.—Fri.: 8:00 Am to 5:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMARE F TABOR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

May 13, 2025
Application Filed
Aug 19, 2026
Examiner Interview (Telephonic)
Aug 24, 2026
Non-Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719883
FRAUDULENT HOST DEVICE CONNECTION DETECTION
1y 8m to grant Granted Aug 25, 2026
Patent 12719708
DATA PROCESSING METHOD AND APPARATUS FOR BLOCKCHAIN, DEVICE, MEDIUM, AND PRODUCT
1y 6m to grant Granted Aug 25, 2026
Patent 12684354
METHODS AND APPARATUSES FOR DETERMINING SECURITY ATTACKS IN SOFTWARE-DEFINED NETWORKS
1y 11m to grant Granted Jul 14, 2026
Patent 12670364
TRAINING AND PREDICTION OF HYBRID GRAPH NEURAL NETWORK MODEL
2y 11m to grant Granted Jun 30, 2026
Patent 12665887
METHODS AND SYSTEMS FOR CONTENT DISTRIBUTION
2y 9m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+23.1%)
2y 12m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 837 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month