Prosecution Insights
Last updated: October 02, 2026
Application No. 19/216,988

COMPUTER-IMPLEMENTED METHOD FOR MONITORING A COMPUTER SYSTEM FOR ACCOUNT AND/OR SESSION SECURITY ATTACKS, AND COMPUTER SYSTEM THEREOF

Non-Final OA §103
Filed
May 23, 2025
Priority
Feb 19, 2025 — PO 120055
Examiner
BENGZON, GREG C
Art Unit
2444
Tech Center
2400 — Computer Networks
Assignee
Feedzai - Consultadoria E Inovação Tecnológica S A
OA Round
1 (Non-Final)
58%
Grant Probability
Moderate
1-2
OA Rounds
2y 6m
Est. Remaining
65%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
285 granted / 492 resolved
At TC average
Moderate +7% lift
Without
With
+7.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
40 currently pending
Career history
543
Total Applications
across all art units

Statute-Specific Performance

§101
12.6%
-27.4% vs TC avg
§103
66.1%
+26.1% vs TC avg
§102
4.6%
-35.4% vs TC avg
§112
9.3%
-30.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 492 resolved cases

Office Action

§103
DETAILED ACTION This application has been examined. Claims 1-15 are pending. In order to facilitate communication with the Examiner and expedite the prosecution of the instant application the Applicant is requested to submit written authorization to authorize the USPTO to communicate via electronic mail. The written authorization must be compliant with the language from MPEP § 502.03. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority This application claims benefits of priority from Foreign Application PT120055 filed February 19, 2025. The effective date of the claims described in this application is February 19, 2025. Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/8/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-6,9-12,14-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Khot (USPGPUB 2025/0184341) further in view of Allen (USPGPUB 2026/0156134) Regarding Claim 1 Khot Paragraph 2 disclosed a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events. Khot disclosed (re. Claim 1) a computer-implemented method for monitoring a computer system for account and/or session security attacks,( Khot-Paragraph 2,a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events) wherein the computer system includes a hardware- based computer processor, and a memory configured to store code representing instructions and configured to provide the instructions to the hardware-based computer processor for execution, wherein the computer system provides session logins to a plurality of user devices using a plurality of user accounts, the method comprising: detecting, using the hardware-based computer processor, a plurality of device characteristic, wherein each device characteristic is encoded as a function of the number of session logins for each device characteristic;(Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual) and detecting, using the hardware-based computer processor, a plurality of account characteristics wherein each account characteristic is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts of a plurality of user accounts.(Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.) While Khot substantially disclosed the claimed invention Khot does not disclose (re. Claim 1) displaying, using the hardware-based computer processor, multidimensional security data from said computer system, said multidimensional security data comprising a plurality of dimensions comprising a time dimension, wherein the time dimension is partitioned in time units; While Khot substantially disclosed the claimed invention Khot does not disclose (re. Claim 1) displaying heatmaps. Allen Figure 22A, Paragraph 114 disclosed wherein FIG. 22A shows the unit cell as a hexagon, the user can tilt the gridded data set 2204, and the unit cell will be shown as a cylinder with a hexagon shape with a column height corresponding to the number of network access events. As described above, each unit cell is a colored, 3D visual object that represents a composite score of the anomaly scores associated with zero or more network access events corresponding to the respective network address identifier at the respective time interval. Allen Paragraph 117 disclosed wherein heatmaps are typically displayed as a grid or a matrix of cells. Allen disclosed (re. Claim 1) displaying, using the hardware-based computer processor, multidimensional security data from said computer system, said multidimensional security data comprising a plurality of dimensions comprising a time dimension, wherein the time dimension is partitioned in time units; (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.) Allen disclosed (re. Claim 1) displaying heatmaps. (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights, Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells) Khot and Allen are analogous art because they present concepts and practices regarding monitoring account security and anomalous events. Before the time of the effective filing date of the claimed invention it would have been obvious to combine Allen into Khot. The motivation for the said combination would have been to enable providing a digital fingerprinting (DFP) workflow for cybersecurity, enabling organizations to deeply analyze every account login across the network.(Allen-Paragraph 31) Khot-Allen disclosed (re. Claim 1) displaying, using the hardware-based computer processor, a plurality of device heatmaps for each time unit,(Allen-Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells, Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns) wherein each device heatmap corresponds to a device characteristic of the user devices, (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.) wherein each device heatmap is encoded as a function of the number of session logins for each device characteristic; (Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual) and displaying, using the hardware-based computer processor, a plurality of account heatmaps for each time unit, (Allen-Paragraph 117, heatmaps are typically displayed as a grid or a matrix of cells) wherein each account heatmap corresponds to a characteristic of the user accounts, wherein each account heatmap is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts of a plurality of user accounts. (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.) Regarding Claim 14 Claim 14 (re. non-transitory computer-readable medium) recites substantially similar limitations as Claim 1. Claim 14 is rejected on the same basis as Claim 1. Khot-Allen disclosed (re. Claim 14) a user interface for monitoring a computer system for account take-over. (Khot-Paragraph 2,a threat detection system that can detect sophisticated attacks including attacks associated with account compromise and takeover events) Regarding Claim 15 Claim 15 (re. system) recites substantially similar limitations as Claim 1. Claim 15 is rejected on the same basis as Claim 1. Regarding Claim 2 Khot-Allen disclosed (re. Claim 2) wherein each account heatmap is encoded as a function of a change occurring, or not, to one characteristic of the one or more user accounts (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device to those typically observed for older devices registered with the account. These signals include but are not limited to: IP, location, ISP, etc. Examples of location data include city, state, country, region, and geographic coordinate information, among other location information.) and also encoded as a function of the one characteristic of the one or more user accounts having been marked as restricted.(Khot-Paragraph 25, In the event the login event is classified as an anomalous event, one or more computer security actions can be taken. For example, the login event can be blocked, the user account can be suspended) Regarding Claim 3 Khot-Allen disclosed (re. Claim 3) wherein said heatmaps for a same time unit are stacked perpendicularly to the time dimension.(Allen-Paragraph 89, the DFP system 1500 can identify a bucket name, a filename prefix, a start date, an end date, and any filter function on what data is read from the object bucket 1502.Paragraph 116, The hexagon grid represents network events, with anomalous events binned, colored, and sorted by row and time. The grid view can be reformatted in the settings menu. The most recent time stamp starts on the left.) Regarding Claim 4 Khot-Allen disclosed (re. Claim 4) displaying a time window selector, receiving user interaction from said time window selector, (Allen-Paragraph 120, the number of events can vary depending on “Time Bin Per Hexagon” values set in default settings or a settings menu 2212 ) and updating displayed heatmaps with the selected time window, wherein the time window selector includes an adjustable time dimension granularity, including an automatically adjustable time dimension granularity as a function of the selected time window, wherein the automatically adjustable time dimension granularity is a function of the selected time window duration. Regarding Claim 5 Khot-Allen disclosed (re. Claim 5) displaying a horizontal bar chart aligned with time dimension, and displaying a session amount per time dimension unit.( Allen-Paragraph 89, the DFP system 1500 can identify a bucket name, a filename prefix, a start date, an end date, and any filter function on what data is read from the object bucket 1502. Regarding Claim 6 Khot-Allen disclosed (re. Claim 6) displaying said plurality of device heatmaps arranged parallel to the time dimension, (Allen-Paragraph 114, gridded data set 2204 of unit cells are grouped or organized by the subset of network address identifiers as the nineteen rows, time intervals as columns, colors as a configurable anomaly score indicator, and a number of network access events as column heights.) wherein each device heatmap is aligned with a time dimension unit, and displaying number of logins for all the user devices. (Khot-Paragraph 96, the threat detection platform 100 may examine sign-in activities to establish characteristics (e.g., in terms of location, time, frequency) that can then be used to establish whether a single sign-in activity is unusual or a combination of sign-in activities is unusual) Regarding Claim 9 Khot-Allen disclosed (re. Claim 9) an aggregated device heatmap, wherein the aggregated device heatmap is encoded as a function of the number of session logins for a plurality of device characteristics, wherein the plurality of device characteristics is an aggregation of each device characteristic for each of the plurality of device heatmaps.(Allen-Paragraph 113, The GUI dashboard 2200 includes an area chart 2202 showing the total network traffic volume. An area chart, also known as an area graph, is a type of data visualization used to display the magnitude or proportion of different data series over time or along a continuous axis. It is commonly used to illustrate the cumulative effect or trend of multiple variables.) Regarding Claim 10 Khot-Allen disclosed (re. Claim 10) an aggregated account heatmap, wherein the aggregated account heatmap is encoded as a function of an aggregation of characteristics of the user accounts, wherein the aggregated account heatmap is encoded as a function of a change occurring, or not, to one or more characteristics of the user accounts. (Allen-Paragraph 113, The GUI dashboard 2200 includes an area chart 2202 showing the total network traffic volume. An area chart, also known as an area graph, is a type of data visualization used to display the magnitude or proportion of different data series over time or along a continuous axis. It is commonly used to illustrate the cumulative effect or trend of multiple variables.) Regarding Claim 11 Khot-Allen disclosed (re. Claim 11) displaying an indicator representing an added device, (Khot-Paragraph 50, a newly added “trusted device” indeed belongs to the purported legitimate user. Additional signals such as locations for where login and MFA authentication is happening now vs. the established behavior for the user can be examined….new device adding event, a comparison can be made of the signals observed from the new device) wherein the indicator is placed perpendicularly to the time dimension and adjacent to the device heatmap for a time unit where the device has been added. Regarding Claim 12 Khot-Allen disclosed (re. Claim 12) detecting a user input at one time unit of one heatmap and, if detected, highlighting the heatmaps of the corresponding time unit. (Allen-Paragraph 116,Clicking on a hexagon can open the details menu 2206.) Claim(s) 7-8,13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Khot (USPGPUB 2025/0184341) further in view of Allen (USPGPUB 20260156134) further in view of OToole (USPGPUB 2021/0216928) Regarding Claim 7 Allen Paragraph 116 disclosed wherein clicking on a hexagon can open the details menu 2206. While Khot-Allen substantially disclosed the claimed invention Khot-Allen does not disclose (re. Claim 7) detecting a user hover point over any part of a time unit partition and high-lighting the hovered time unit partition. OToole Paragraph 118 disclosed a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time. OToole disclosed (re. Claim 7) detecting a user hover point over any part of a time unit partition and high-lighting the hovered time unit partition. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.) Khot,Allen and OToole are analogous art because they present concepts and practices regarding monitoring account security and anomalous events. Before the time of the effective filing date of the claimed invention it would have been obvious to combine OToole into Khot. The motivation for the said combination would have been to enable a threat summary panel 401 giving a user more information about the key events that contributed to the risk score of the asset at that point in time. (OToole-Paragraph 118) Regarding Claim 8 Khot-Allen-OToole disclosed (re. Claim 8) detecting a user hover point over any part of a time unit partition, and displaying a hovering pop-up comprising data about the hovered time unit partition. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.) Regarding Claim 13 Khot-Allen-OToole disclosed (re. Claim 13) detecting a user hover point over any of the highlighted time unit heatmaps (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.) and, if detected, displaying a hovering pop- up comprising data about the hovered time unit; including detecting a user hover point over any of the highlighted time unit heatmaps of a device characteristic heatmap and, if detected, displaying a hovering pop-up comprising a labelled value for the corresponding hovered device characteristic. (OToole-Paragraph 118,a threat summary information element that displays when a user's cursor is hovered over an individual threat on asset risk timeline card 304. A threat summary panel 401 displays, giving a user more information about the key events that contributed to the risk score of the asset at that point in time.) Conclusion Examiner’s Note: In the case of amending the claimed invention, Applicant is respectfully requested to indicate the portion(s) of the specification which dictate(s) the structure relied on for proper interpretation and also to verify and ascertain the metes and bounds of the claimed invention. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GREG C BENGZON whose telephone number is (571)272-3944. The examiner can normally be reached on Monday - Friday 8 AM - 4:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John Follansbee can be reached on (571) 272-3964. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GREG C BENGZON/ Primary Examiner, Art Unit 2444
Read full office action

Prosecution Timeline

May 23, 2025
Application Filed
Aug 25, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739100
PRIVATE DATA SHARING SYSTEM
1y 9m to grant Granted Sep 15, 2026
Patent 12719746
SCALING FOR SPLIT-NETWORKING DATAPATH
1y 9m to grant Granted Aug 25, 2026
Patent 12646026
System and Method for Automated Cross-Application and Infrastructure Dependency Mapping
6y 4m to grant Granted Jun 02, 2026
Patent 12634123
Random Trigger for Automatic Key Rotation
3y 8m to grant Granted May 19, 2026
Patent 12634347
Systems and methods for detecting and remediating inconsistent tags in cloud-native networks
2y 7m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
58%
Grant Probability
65%
With Interview (+7.0%)
3y 11m (~2y 6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 492 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month