Prosecution Insights
Last updated: August 17, 2026
Application No. 19/208,089

THREAT MITIGATION SYSTEM AND METHOD

Non-Final OA §103§DOUBLEPATENT
Filed
May 14, 2025
Priority
Nov 23, 2020 — provisional 63/117,180 +2 more
Examiner
SAADOUN, HASSAN
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
ReliaQuest Holdings LLC
OA Round
1 (Non-Final)
92%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 92% — above average
92%
Career Allowance Rate
259 granted / 283 resolved
+33.5% vs TC avg
Minimal -0% lift
Without
With
+-0.4%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
9 currently pending
Career history
289
Total Applications
across all art units

Statute-Specific Performance

§101
12.8%
-27.2% vs TC avg
§103
49.2%
+9.2% vs TC avg
§102
4.4%
-35.6% vs TC avg
§112
16.3%
-23.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 283 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION 4This office action is in response to the application filed on 05/14/2025. Claims 61-78 are pending and are examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/12/2025 was filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Priority Applicant’s benefit claim is hereby acknowledged of the U.S patent application No. 18/318,338, filed on 05/16/2023, which is a continuation of the U.S patent application No. 17/532,764, filed on 11/22/2021, which papers have been placed on record in the file. Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, or 365(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119(e) as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994) The disclosure of the prior-filed provisional application No. 63/117,180 fails to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. Specifically, None of limitations of Claims 69, 78 and 87. Therefore Claims 69, 78 and 87 do not receive benefit of an earlier filing date. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 61-87 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 31-60 of patent No. 12,328,342, claims 1-30 of patent No. 11,659,007 and claims 1, 3-11, 13-21 and 23-30 of patent 11,483,337. Although the claims at issue are not identical, they are not patentably distinct from each other because, claims 61-87 of the present application would have been obvious over claims 31-60 of patent No. 12,328,342, claims 1-30 of patent No. 11,659,007 and claims 1, 3-11, 13-21 and 23-30 of patent 11,483,337 because each element of the present application is anticipated by the claims of those patents. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was. Claims 61-63, 65-72, 74-81 and 83-87 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy et al. (U.S. Pub. No. 2017/0006058 A1, referred to as Murphy) in view of Crabtree et al. (U.S. Pub. No. 2018/0241767 A1, referred to as Crabtree). Regarding claims 61, 70 and 79, Murphy teaches: A computer-implemented method, executed on a computing device (Murphy: Fig. 1, item 10; ¶ 0016, “In FIG. 1, there is shown threat intelligence process 10. Threat intelligence process 10 may be implemented as a server-side process, a client-side process, or a hybrid server-side/client-side process”), comprising: defining a unified query on the a unified platform concerning the plurality of security-relevant subsystems (Murphy: Fig. 1; Fig. 2, steps 100, 102; 110, 120; ¶ 0005; ¶ 0029, “threat intelligence process 10 may receive 102 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) and may store 104 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) into one or more database tables for subsequent processing.”; ¶ 0037, “Determining 120 a source for each of the plurality of raw threat data) (defining)”); defining a plurality of subsystem-specific queries on the unified platform concerning the plurality of security-relevant subsystems (Murphy: Fig. 1; Fig. 2, steps 100, 102; 110, 120; ¶ 0005; ¶ 0029, “threat intelligence process 10 may receive 102 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) and may store 104 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) into one or more database tables for subsequent processing.”; ¶ 0037, “Determining 120 a source for each of the plurality of raw threat data)”), including denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries (Murphy: Fig. 1; Fig. 2, step 112; ¶ 0033, “Deduplicating 112 the plurality of raw threat data definitions: For example, threat intelligence process 10 may process 110 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) to deduplicate 112 any redundant pieces of data included within raw threat data definitions 34, 36, 38, 40. For example, if two or more of raw threat data definitions 34, 36, 38, 40 identify the same IP address as being a threat, threat intelligence process 10 may deduplicate 112 raw threat data definitions 34, 36, 38, 40 to remove the duplicate IP address.” (EN: denormalizing)); and providing the plurality of subsystem-specific queries to the plurality of security-relevant subsystems (Murphy: Fig. 2; steps 128-136; ¶ 0040- ¶ 0041). Murphy does not explicitly disclose, however Crabtree teaches: wherein one or more of the plurality of subsystem-specific queries has a defined execution schedule (Crabtree: Fig. 9; ¶ 0049; Fig. 10; ¶ 0050; Fig. 3, Item 310; ¶ 0043, “FIG. 3 is a system diagram, illustrating the connections between crucial components, according to an aspect of the invention. Core components include a scheduling task engine 310 which will run any processes and continue with any steps desired by the client, as described in further methods and diagrams in the disclosure. Tasks may be scheduled to run at specific times, or run for certain given amounts of time, which is commonplace for task scheduling software and systems in the art”). It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Murphy by Crabtree to have scheduling task engine capable of performing scheduling and running different processes such as gathering information to have a system capable of recording comprehensive, total data about potential network threats for network security scoring purposes. (Crabtree: ¶ 0004). Regarding claims 62, 71 and 80, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy does not explicitly disclose, however Crabtree teaches: wherein the defined execution schedule is a default execution schedule configured to be revisable by a third-party (Crabtree: ¶ 0008, “the system further comprises a task scheduling engine comprising at least a processor, a memory, and a plurality of programming instructions stored in the memory and operating on the processor, wherein the programmable instructions, when operating on the processor, cause the processor to schedule computer tasks and programs to run at certain intervals (EN: a default execution schedule).”; Fig. 3, Item 310; ¶ 0043, “according to an aspect of the invention. Core components include a scheduling task engine 310 which will run any processes and continue with any steps desired by the client (EN: revisable by a third-party)”). Same motivation as claims 61, 70 and 79. Regarding claims 63, 72 and 81, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy does not explicitly disclose, however Crabtree teaches: wherein the defined execution schedule includes one or more of: a defined execution time; a defined execution date; a defined execution frequency; and a defined execution scope (Crabtree: Fig. 3, Item 310; ¶ 0043, “as described in further methods and diagrams in the disclosure. Tasks may be scheduled to run at specific times (EN: a defined execution time), or run for certain given amounts of time, which is commonplace for task scheduling software and systems in the art.”). Same motivation as claims 61, 70 and 79. Regarding claims 65, 74 and 83, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy teaches: wherein denormalizing the unified query to define a subsystem-specific query for each of the plurality of security-relevant subsystems, thus defining the plurality of subsystem-specific queries includes: translating a syntax of the unified query to a syntax of each of the plurality of subsystem-specific queries (Murphy: Fig. 1; Fig. 2, steps 114; 116; ¶ 0034; ¶ 0035,”Converting 116 the plurality of raw threat data definitions into a common format: For example, threat intelligence process 10 may process 110 the plurality of raw threat data definitions (e.g., raw threat data definitions 34, 36, 38, 40) to convert 116 raw threat data definitions 34, 36, 38, 40 into a common format. (EN: translating)”). Regarding claims 66, 75 and 84, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy teaches: receiving a plurality of subsystem-specific results sets from the plurality of security-relevant subsystems that were generated in response to the plurality of subsystem-specific queries (Murphy: Fig, 2, Items 100-108; ¶ 0029- ¶ 0030, “specific keywords 42 that were defined 106 may concern a specific type of attack that has been/will be carried out, a specific company/organization that has been/will be targeted for attack, and a specific/known hacker. And once defined 106, threat intelligence process 10 may search 108 for specific keywords 42 within social network trader source 26.” (EN: specific results sets)). Regarding claims 67, 76 and 85, the combination of Murphy and Crabtree teaches all the features of claims 66, 75 and 84, as outlined above. Murphy teaches: normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set; (Murphy: Fig. 2, Items 128, 130; ¶ 0040, “threat intelligence process 10 may combine 128 the plurality of processed threat data definitions (e.g., processed threat data definitions 44, 46, 48, 50) to form master threat data definition 52 and may format 130 master threat data definition 52 into a format that is compatible with the one or more client electronic devices.”); and providing the unified result set to a third-party (Murphy: Fig. 2, Items 128-132; ¶ 0040; ¶ 0041, “Once properly formatted, threat intelligence process 10 may provide 132 master threat data definition 52 to one or more client electronic devices (e.g., client electronic devices 22, 24) (EN: third-party)”). Regarding claims 68, 77 and 86, the combination of Murphy and Crabtree teaches all the features of claims 67, 76 and 85, as outlined above. Murphy teaches: wherein normalizing the plurality of subsystem-specific results sets received from the plurality of security-relevant subsystems to define a unified result set includes: 100H&K Docket No.: 122680.00xxx(a)Holland & Knight LLP Assignee: ReliaQuest Holdings, LLC10 St. James Avenue Inventor: Murphy et al.Boston, MA 02116-3889translating a syntax of each of the plurality of subsystem-specific results sets to a syntax of the unified result set (Murphy: Fig. 2, Items 128, 130; ¶ 0040, “threat intelligence process 10 may combine 128 the plurality of processed threat data definitions (e.g., processed threat data definitions 44, 46, 48, 50) to form master threat data definition 52 and may format 130 master threat data definition 52 into a format that is compatible with the one or more client electronic devices.” (EN: translating)). Regarding claims 69, 78 and 87, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy teaches: wherein the plurality of security- relevant subsystems includes one or more of: CDN (i.e., Content Delivery Network) systems; DAM (i.e., Database Activity Monitoring) systems; UBA (i.e., User Behavior Analytics) systems; MDM (i.e., Mobile Device Management) systems; IAM (i.e., Identity and Access Management) systems; DNS (i.e., Domain Name Server) systems; Antivirus systems; operating systems; data lakes; data logs; security-relevant software applications; security-relevant hardware systems; and resources external to the computing platform (Murphy: Fig. 1, Items 26-32; ¶ 0032, “threat intelligence process 10 may import 100 threat data from a plurality of threat data sources, thus generating a plurality of raw threat data definitions. Examples of these threat data sources may include but are not limited to one or more of: social network trader source 26; public honeypot server 28; private honeypot server 30; and open source threat feed 32 (EN: resources external to the computing platform)”). Claims 64, 73 and 82 are rejected under 35 U.S.C. 103 as being unpatentable over Murphy in view of Crabtree and further in view of Kamal (U.S. Pub. No. 2011/0125642 A1, referred to as Kamal). Regarding claims 64, 73 and 82, the combination of Murphy and Crabtree teaches all the features of claims 61, 70 and 79, as outlined above. Murphy does not explicitly disclose, however Kamal teaches: determining that one or more of the plurality of subsystem-specific queries failed to execute properly, thus defining one or more failed subsystem-specific queries (Kamal: ¶ 0068, “In the example embodiment, a connection to an instance of database subsystem 415 may become inoperable after a period of inactivity. A subsequent attempt to use the connection will fail introducing a delay”); and reexecuting the one or more failed subsystem-specific queries (Kamal: ¶ 0068, “account data access system 425 re-establishes the connection to the instance of database subsystem 415 or re-executes the query in another instance of database subsystem 415. To prevent inactivity-induced failures, account data access system 425 detects inactivity in a connection to an instance of database subsystem 415 and, in response, executes a “keep-alive” query in that instance of database subsystem 415”). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN SAADOUN whose telephone number is (571)272-8408. The examiner can normally be reached Mon-Fri 9:00-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mehrmanesh Amir can be reached at 571-2703351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HASSAN SAADOUN/Examiner, Art Unit 2435 /AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

May 14, 2025
Application Filed
Jul 24, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12684003
APPROACHES TO INGESTING INFORMATION REGARDING DIGITAL ACTIVITIES PERFORMED ACROSS DIFFERENT SERVICES AND USING THE SAME FOR DETECTING THREATS
2y 2m to grant Granted Jul 14, 2026
Patent 12681830
DYNAMIC SYSTEM RESOURCE-SENSITIVE MODEL SOFTWARE AND HARDWARE SELECTION
1y 10m to grant Granted Jul 14, 2026
Patent 12659338
CYBER SECURITY RESTORATION ENGINE
2y 10m to grant Granted Jun 16, 2026
Patent 12652295
ARRANGEMENT AND A METHOD OF THREAT DETECTION IN A COMPUTING DEVICE OR A COMPUTER NETWORK
2y 6m to grant Granted Jun 09, 2026
Patent 12652297
AUTOMATIC RISK REMEDIATION IN MULTI-CLOUD ENVIRONMENT
1y 10m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
92%
Grant Probability
91%
With Interview (-0.4%)
2y 1m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 283 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month