Prosecution Insights
Last updated: October 02, 2026
Application No. 19/246,193

MACHINE-LEARNING TECHNIQUES FOR DETECTION OF UNAUTHORIZED ACCESS OF INTERACTIVE COMPUTING ENVIRONMENT FUNCTIONS

Non-Final OA §103
Filed
Jun 23, 2025
Priority
Aug 05, 2020 — provisional 63/061,748 +3 more
Examiner
WALIULLAH, MOHAMMED
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Kount Inc.
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
1y 0m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
641 granted / 739 resolved
+28.7% vs TC avg
Moderate +11% lift
Without
With
+11.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
23 currently pending
Career history
756
Total Applications
across all art units

Statute-Specific Performance

§101
7.7%
-32.3% vs TC avg
§103
62.6%
+22.6% vs TC avg
§102
4.8%
-35.2% vs TC avg
§112
11.7%
-28.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 739 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a non-statutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Instant application 19/246,193 US 12368748 B2 1. A method implemented by an online security analysis system, the method comprising: identifying, by the online security analysis system, a set of conversion factors for a categorical value that is associated with an access request from a client device to an online system, wherein at least one conversion factor in the set of conversion factors is determined based on historical data associated with past access requests having the categorical value; identifying, based on the set of conversion factors, an occurrence feature related to occurrences of the categorical value and an aggregated feature related to aggregated values of a numerical feature of the past access requests; generating, by the online security analysis system, an embedding vector that includes multiple vector values respectively representing the occurrence feature, the aggregated feature, and a present numerical value of the numerical feature, the present numerical value being associated with the access request; applying, by the online security analysis system, a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the access request based on the embedding vector; and transmitting the prediction data, by the online security analysis system, to the online system for use in controlling access of the client device to a function of the online system. 3. The method of claim 2, further comprising modifying, by the online security analysis system, the set of conversion factors to include i) a combination of the present numerical value and the aggregated value ratio and ii) a combination of the categorical value with the occurrence ratio. 1. A method implemented by an online security analysis system, the method comprising: identifying, by the online security analysis system, a set of conversion factors for a categorical value that is associated with an access request from a client device to an online system, wherein the set of conversion factors is determined based on historical data associated with past access requests having the categorical value; identifying, based on the set of conversion factors, an occurrence feature related to occurrences of the categorical value and an aggregated feature related to aggregated values of a numerical feature of the past access requests; generating, by the online security analysis system, an embedding vector that includes the occurrence feature, the aggregated feature, and a present numerical value of the numerical feature, the present numerical value being associated with the access request; modifying, by the online security analysis system, the set of conversion factors to include i) a combination of the present numerical value and an aggregated value ratio included in the aggregated feature and ii) a combination of the categorical value with an occurrence ratio included in the occurrence feature; applying, by the online security analysis system, a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the access request based on the embedding vector; and transmitting the prediction data, by the online security analysis system, to the online system for use in controlling access of the client device to a function of the online system. 9. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause a computing device to perform operations, the operations comprising: identifying a conversion factor for a categorical value that is associated with an access request from a client device to an online system, wherein the conversion factor is determined based on historical data associated with past access requests having the categorical value; identifying, based on the conversion factor, an aggregated feature related to aggregated values of a numerical feature of the past access requests; generating an embedding vector that includes multiple vector values respectively representing the aggregated feature and a present numerical value of the numerical feature, the present numerical value being associated with the access request; applying a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the access request based on the embedding vector; and transmitting the prediction data to the online system for use in controlling access of the client device to a function of the online system. 12. The non-transitory computer-readable storage medium of claim 11, the operations further comprising modifying the conversion factor to include a combination of the present numerical value and the aggregated value ratio. 8. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause a computing device to perform operations, the operations comprising: identifying a conversion factor for a categorical value that is associated with an access request from a client device to an online system, wherein the conversion factor is determined based on historical data associated with past access requests having the categorical value; identifying, based on the conversion factor, an aggregated feature related to aggregated values of a numerical feature of the past access requests; generating an embedding vector that includes the aggregated feature and a present numerical value of the numerical feature, the present numerical value being associated with the access request; modifying the conversion factor to include a combination of the present numerical value and an aggregated value ratio included in the aggregated feature; applying a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the access request based on the embedding vector; and transmitting the prediction data to the online system for use in controlling access of the client device to a function of the online system. 16. A system comprising: a processing device; and a memory device in which instructions executable by the processing device are stored for configuring the processing device for: identifying a conversion factor for a categorical value that is associated with an access request from a client device to an online system, wherein the conversion factor is determined based on historical data associated with past access requests having the categorical value; responsive to one or more of (i) receiving an updated classification for the access request, or (ii) determining that a quantity of the access request combined with the past access requests exceeds a threshold quantity of access requests, modifying the conversion factor to include an occurrence feature that describes occurrences of the categorical value in the access request combined with the past access requests; receiving an additional access request from the client device to the online system, the additional access request having the categorical value; generating an embedding vector that includes the occurrence feature of the modified conversion factor and an aggregation feature related to aggregated values of a numerical feature of the past access requests wherein the embedding vector includes multiple vector values respectively representing the occurrence feature and the aggregated feature; applying a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the additional access request based on the embedding vector; and transmitting the prediction data to the online system for use in controlling access of the client device to a function of the online system. 18. The system of claim 16, wherein modifying the conversion factor to include the occurrence feature comprises combining the categorical value with an occurrence ratio for the categorical feature. 14. A system comprising: a processing device; and a memory device in which instructions executable by the processing device are stored for configuring the processing device for: identifying a conversion factor for a categorical value that is associated with an access request from a client device to an online system, wherein the conversion factor is determined based on historical data associated with past access requests having the categorical value; responsive to one or more of (i) receiving an updated classification for the access request, or (ii) determining that a quantity of the access request combined with the past access requests exceeds a threshold quantity of access requests, modifying the conversion factor to include an occurrence feature that describes occurrences of the categorical value in the access request combined with the past access requests, wherein modifying the conversion factor to include the occurrence feature comprises combining the categorical value with an occurrence ratio for the occurrence feature; receiving an additional access request from the client device to the online system, the additional access request having the categorical value; generating an embedding vector that includes the occurrence feature of the modified conversion factor; applying a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the additional access request based on the embedding vector; and transmitting the prediction data to the online system for use in controlling access of the client device to a function of the online system. 15. The system of claim 14, the processing device further configured for: identifying, based on an additional conversion factor for the categorical value, an aggregation feature related to aggregated values of a numerical feature of the past access requests, wherein the generated embedding vector further includes the aggregation feature. Claims 1-20 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-17 of U.S. Patent No. US 12368748 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because similar limitations with minor obvious variations. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2,7-11,15-17, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Kirti et al(US 20150319185 A1:IDS supplied) in view of Iyer et al(US 20230245197 A1:IDS supplied). With regards to claim 1, 9, Kirti discloses, A method implemented by an online security analysis system, the method comprising: identifying, by the online security analysis system, a set of conversion factors for a categorical value that is associated with an access request from a client device to an online system, ([0068] In many embodiments of the invention, various types of algorithms can be particularly useful for analyzing the data. … For example, a threat can be identified based on an account accessing one or more files or failing a series of login attempts from an IP address that is flagged (by a third party feed or otherwise) as malicious. In a similar way, a threat can also be based on different patterns of activity in one cloud or across multiple clouds over a series of time. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values…. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values. Normalizing the data in the processes discussed above may include reformatting the data such that it is comparable, have the same meaning, and/or bear the same significance and relevance between different clouds. Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. However, a series of failed logins with user accounts associated with a user across multiple clouds may indicate a concerted effort to crack the user's password and therefore set off an alarm. Clustering and regression algorithms can be used to categorize data and find common patterns… n several embodiments of the invention, data collected over time is used to build models of normal behavior (e.g., patterns of events and activity) and flag behavior that deviates from normal as abnormal behavior. After one or more flagged event or activity is characterized as a true or false positive (e.g., by user feedback), the information can be provided back to one or more machine learning algorithms to automatically modify parameters of the system.); identifying, based on the set of conversion factors, an occurrence feature related to occurrences of the categorical value and an aggregated feature related to aggregated values of a numerical feature of the past access requests; ([0068]; . In a similar way, a threat can also be based on different patterns of activity in one cloud or across multiple clouds over a series of time. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values. Normalizing the data in the processes discussed above may include reformatting the data such that it is comparable, have the same meaning, and/or bear the same significance and relevance between different clouds. Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. [0098] Daily (or periodic) aggregation processes may be run intraday. Feature vectors may include, but are not limited to, count of number of logins, count of number of distinct IP addresses used for login, maximum distance between any two IP addresses used by a user within a 24 hour time period, count of number of distinct browsers used in connections to the cloud application within a 24 hour time period, and other similar measures. Feature vectors may be aggregated by application and/or by user per cloud application.); generating, by the online security analysis system, an embedding vector that includes multiple vector values respectively representing the occurrence feature, (0098] Daily (or periodic) aggregation processes may be run intraday. Feature vectors may include, but are not limited to, count of number of logins, count of number of distinct IP addresses used for login, maximum distance between any two IP addresses used by a user within a 24 hour time period, count of number of distinct browsers used in connections to the cloud application within a 24 hour time period, and other similar measures. Feature vectors may be aggregated by application and/or by user per cloud application. Table 4 below shows example daily aggregation matrix vectors in accordance with embodiments of the invention. Table 5 below lists sample values for some daily aggregation matrix vectors in accordance with embodiments of the invention.), the aggregated feature ([0068]; Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. However, a series of failed logins with user accounts associated with a user across multiple clouds may indicate a concerted effort to crack the user's password and therefore set off an alarm. Clustering and regression algorithms can be used to categorize data and find common patterns. For example, a clustering algorithm can put data into clusters by aggregating all entries of users logging in from a mobile device. ), and a present numerical value of the numerical feature, the present numerical value being associated with the access request ([0039] The data entered into a landing repository 210 may be in different formats and/or have different ranges of values—this data may be reformatted and/or structured before being moved to the analytics repository 211. The data concerning activity information in the analytics repository 211 can be utilized to generate reports that may be presented visually to a system administrator via a user interface and to generate analytics for determining threat level, detecting specific threats, and predicting potential threats.[0062];[0068]; Table 5); applying, by the online security analysis system, a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the access request based on the embedding vector (FIG 5 508 and associated text; [0035]; n several embodiments, the cloud security monitoring and control system analyzes information about user activity in one or more clouds using machine learning and other algorithms to perform threat detection and to provide recommendations concerning appropriate responses to different categories of threat. [0099] Activity data, generated statistics, feature vectors, and other information such as those discussed above may be used in behavior analytics to determine the likelihood of various threats); and transmitting the prediction data, by the online security analysis system, to the online system for use in controlling access of the client device to a function of the online system ([0125]; An alert and/or other information concerning an identified threat can be sent to an entity external to the cloud security system such as a tenant's internal IT (information technology) workflow management system or third party incident management automation system for remediation and/or tracking.). Kirti does not exclusively but Iyer teaches, wherein at least one conversion factor in the set of conversion factors is determined based on historical data associated with past access requests having the categorical value([0007] In another aspect, the computing device is configured to, in response to receiving the real-time signals of the event occurring from the user device and prior to obtaining the set of historical data, determine an interaction category based on the interaction parameters and compute an interaction score based on the interaction category. The computing device is also configured to, in response to the interaction score being above a threshold, designate the interaction parameters as features for the machine learning model. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Kirti’s method/product/system with teaching of Iyer in order for generating personalized recommendations based on real-time signals of a session and more particularly to determining a probability of affinity or conversion using real-time signals to guide recommendations of existing database entries (Iyer[0001]). With regards to claim 2, 11, Kirti further discloses, wherein the occurrence feature includes one or more of a counted categorical value ([0005] In a further embodiment, the activity data includes a count of the number of unique internet protocol (IP) addresses used by a user account per day.) or an occurrence ratio, and wherein the aggregated feature includes one or more of an aggregated numerical value or an aggregated value ratio ([0035] Turning now to the drawings, systems and methods for cloud security monitoring and control are illustrated. Tenants are organizations whose members include users of cloud services offered by cloud providers. Users may have individual accounts with cloud providers and tenants may have enterprise accounts with cloud providers that encompass or aggregate a number of individual user accounts.). With regards to claim 7, Kriti further discloses, wherein the categorical value is a first value of a categorical feature, and an additional conversion factor is associated with a second value of the categorical feature ([0068]; As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values…. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values. Normalizing the data in the processes discussed above may include reformatting the data such that it is comparable, have the same meaning, and/or bear the same significance and relevance between different clouds.). With regards to claim 8, 15, 20 Kirti further discloses, wherein generating the prediction data associated with the additional access request further comprises: receiving a prediction output from the machine-learning model([0043]; The threat detection and prediction analytics application 212 can generate analytics using machine learning and other algorithms to identify and predict security threats from patterns of activity and behavioral models. ); comparing the prediction output to a security threshold ([0067]; [0067] Another class of analytics that can be generated is predictive and heuristic analytics. These may incorporate machine learning algorithms to generate threat models, such as, but not limited to, deviations from base line expectations, rare and infrequent events, and behavior analytics to derive suspicious behavior of a user. ); and generating the prediction data based on the comparison of the prediction output to the security threshold ([0120] The threat model(s) can be used to determine (508) the likelihood of anomalous activity such as, but not limited to, using behavior analytics algorithms as discussed further above. In addition, a risk score can be generated for users in each cloud application. The risk scores can be used to prioritize remediation actions, such as, but not limited to, resetting passwords, restricting access from foreign countries, and/or suspending accounts, as will be discussed further below.). With regards to claim 10, the operations further comprising: identifying, based on an additional conversion factor for the categorical value ([0062] Reformatting the data may include categorizing and structuring the data into the common format. In several embodiments of the invention, the database is adaptive to structural changes and new values by running automated processes to check for changed data. In some embodiments, a cloud crawler application (as discussed further above) recognizes differences in the structure or values of the data retrieved and the changes are implemented in the application catalog database 208 and/or analytics and threat intelligence repository database 211. System reports may be pre-generated (410) by jobs that are scheduled to run on the data set.)), an occurrence feature related to occurrences of the categorical value ([0098] Daily (or periodic) aggregation processes may be run intraday. Feature vectors may include, but are not limited to, count of number of logins, count of number of distinct IP addresses used for login, maximum distance between any two IP addresses used by a user within a 24 hour time period, count of number of distinct browsers used in connections to the cloud application within a 24 hour time period, and other similar measures. Feature vectors may be aggregated by application and/or by user per cloud application), wherein the generated embedding vector further includes the occurrence feature ([0068]; Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. However, a series of failed logins with user accounts associated with a user across multiple clouds may indicate a concerted effort to crack the user's password and therefore set off an alarm. Clustering and regression algorithms can be used to categorize data and find common patterns. For example, a clustering algorithm can put data into clusters by aggregating all entries of users logging in from a mobile device.). With regards to claim 16, Kirti discloses, A system comprising: a processing device (FIG 1 202); and a memory device in which instructions executable by the processing device are stored for configuring the processing device (FIG 2 200) for: identifying a conversion factor for a categorical value that is associated with an access request from a client device to an online system (0068] In many embodiments of the invention, various types of algorithms can be particularly useful for analyzing the data. … For example, a threat can be identified based on an account accessing one or more files or failing a series of login attempts from an IP address that is flagged (by a third party feed or otherwise) as malicious. In a similar way, a threat can also be based on different patterns of activity in one cloud or across multiple clouds over a series of time. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values…. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values. Normalizing the data in the processes discussed above may include reformatting the data such that it is comparable, have the same meaning, and/or bear the same significance and relevance between different clouds. Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. However, a series of failed logins with user accounts associated with a user across multiple clouds may indicate a concerted effort to crack the user's password and therefore set off an alarm. Clustering and regression algorithms can be used to categorize data and find common patterns… n several embodiments of the invention, data collected over time is used to build models of normal behavior (e.g., patterns of events and activity) and flag behavior that deviates from normal as abnormal behavior. After one or more flagged event or activity is characterized as a true or false positive (e.g., by user feedback), the information can be provided back to one or more machine learning algorithms to automatically modify parameters of the system.), receiving an additional access request from the client device to the online system ([0040] The aggregation of activity information in the analytics repository 211 concerning access patterns and other event statistics enables the system to establish baselines of user behavior. Machine learning techniques can then be applied to detect threats and provide recommendations concerning how to respond to threats. Note: when compared against baseline suggest additional accesses), the additional access request having the categorical value ([0058] More specific types of activity data can include, but are not limited to, login and logout statistics (including attempts and successes), IP addresses used to access the application, devices used to access the application, and cloud resources that were accessed (including, but not limited to, files and folders in a file management cloud application [such as Box], employees and contractors in a human resource cloud application [such as Workday], and contacts and accounts in a customer relationship management cloud application [such as Salesforce]).[0068] For example, a threat can be identified based on an account accessing one or more files or failing a series of login attempts from an IP address that is flagged (by a third party feed or otherwise) as malicious. In a similar way, a threat can also be based on different patterns of activity in one cloud or across multiple clouds over a series of time. As discussed further above, activity data from different clouds may be in different formats or with different possible values or ranges of values. Normalizing the data in the processes discussed above may include reformatting the data such that it is comparable, have the same meaning, and/or bear the same significance and relevance between different clouds.); generating an embedding vector that includes the occurrence feature of the modified conversion factor ([0098] Daily (or periodic) aggregation processes may be run intraday. Feature vectors may include, but are not limited to, count of number of logins, count of number of distinct IP addresses used for login, maximum distance between any two IP addresses used by a user within a 24 hour time period, count of number of distinct browsers used in connections to the cloud application within a 24 hour time period, and other similar measures. Feature vectors may be aggregated by application and/or by user per cloud application. Table 4 below shows example daily aggregation matrix vectors in accordance with embodiments of the invention. Table 5 below lists sample values for some daily aggregation matrix vectors in accordance with embodiments of the invention.); and an aggregation feature related to aggregated values of a numerical feature of the past access requests([0062] Reformatting the data may include categorizing and structuring the data into the common format. In several embodiments of the invention, the database is adaptive to structural changes and new values by running automated processes to check for changed data. In some embodiments, a cloud crawler application (as discussed further above) recognizes differences in the structure or values of the data retrieved and the changes are implemented in the application catalog database 208 and/or analytics and threat intelligence repository database 211. System reports may be pre-generated (410) by jobs that are scheduled to run on the data set.) wherein the embedding vector includes multiple vector values respectively representing the occurrence feature(0098] Daily (or periodic) aggregation processes may be run intraday. Feature vectors may include, but are not limited to, count of number of logins, count of number of distinct IP addresses used for login, maximum distance between any two IP addresses used by a user within a 24 hour time period, count of number of distinct browsers used in connections to the cloud application within a 24 hour time period, and other similar measures. Feature vectors may be aggregated by application and/or by user per cloud application. Table 4 below shows example daily aggregation matrix vectors in accordance with embodiments of the invention. Table 5 below lists sample values for some daily aggregation matrix vectors in accordance with embodiments of the invention.), and the aggregated feature (([0068]; Thus, algorithms can aggregate and compare data from different clouds in meaningful ways. For example, a series of failed logins with a particular user account in one cloud may be deemed not to be a threat. However, a series of failed logins with user accounts associated with a user across multiple clouds may indicate a concerted effort to crack the user's password and therefore set off an alarm. Clustering and regression algorithms can be used to categorize data and find common patterns. For example, a clustering algorithm can put data into clusters by aggregating all entries of users logging in from a mobile device.). applying a machine-learning model to the embedding vector, the machine-learning model configured to generate prediction data associated with the additional access request based on the embedding vector (FIG 5 508 and associated text; [0035]; n several embodiments, the cloud security monitoring and control system analyzes information about user activity in one or more clouds using machine learning and other algorithms to perform threat detection and to provide recommendations concerning appropriate responses to different categories of threat. [0099] Activity data, generated statistics, feature vectors, and other information such as those discussed above may be used in behavior analytics to determine the likelihood of various threats); and transmitting the prediction data to the online system for use in controlling access of the client device to a function of the online system ([0125]; An alert and/or other information concerning an identified threat can be sent to an entity external to the cloud security system such as a tenant's internal IT (information technology) workflow management system or third party incident management automation system for remediation and/or tracking). Kirti does not exclusively but Iyer teaches, wherein the set of conversion factors is determined based on historical data associated with past access requests having the categorical value ([0007] In another aspect, the computing device is configured to, in response to receiving the real-time signals of the event occurring from the user device and prior to obtaining the set of historical data, determine an interaction category based on the interaction parameters and compute an interaction score based on the interaction category. The computing device is also configured to, in response to the interaction score being above a threshold, designate the interaction parameters as features for the machine learning model). responsive to one or more of (i) receiving an updated classification for the access request, or (ii) determining that a quantity of the access request combined with the past access requests exceeds a threshold quantity of access requests, modifying the conversion factor to include an occurrence feature that describes occurrences of the categorical value in the access request combined with the past access requests ([0007] In another aspect, the computing device is configured to, in response to receiving the real-time signals of the event occurring from the user device and prior to obtaining the set of historical data, determine an interaction category based on the interaction parameters and compute an interaction score based on the interaction category. The computing device is also configured to, in response to the interaction score being above a threshold, designate the interaction parameters as features for the machine learning model); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify Kirti’s method/product/system with teaching of Iyer in order for generating personalized recommendations based on real-time signals of a session and more particularly to determining a probability of affinity or conversion using real-time signals to guide recommendations of existing database entries (Iyer[0001]). With regards to claim 17, Kirti further discloses, the processing device further configured for: identifying, based on an additional conversion factor for the categorical value, ([0062] Reformatting the data may include categorizing and structuring the data into the common format. In several embodiments of the invention, the database is adaptive to structural changes and new values by running automated processes to check for changed data. In some embodiments, a cloud crawler application (as discussed further above) recognizes differences in the structure or values of the data retrieved and the changes are implemented in the application catalog database 208 and/or analytics and threat intelligence repository database 211. System reports may be pre-generated (410) by jobs that are scheduled to run on the data set.) Allowable Subject Matter Claims 3-6, 12-14, 18-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 8271372 B1, US 11798090 B1. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMED WALIULLAH whose telephone number is (571)270-7987. The examiner can normally be reached 8.30 to 430 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached on 1-571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOHAMMED WALIULLAH/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Jun 23, 2025
Application Filed
Aug 05, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750377
DEPLOYING HANDWRITING RECOGNITION SERVERS FOR DIFFERENT SECURITY LEVELS
3y 10m to grant Granted Sep 29, 2026
Patent 12737495
Machine Learning Training with Enforced Differential Privacy Using Secure Multi-Party Computation
2y 2m to grant Granted Sep 15, 2026
Patent 12732374
HARDWARE VIRTUALIZED TPM INTO VIRTUAL MACHINES
2y 0m to grant Granted Sep 08, 2026
Patent 12722600
TERMINAL DEVICE AND METHOD PROCESSING OF DATA FOR TERMINAL DEVICE
3y 2m to grant Granted Sep 01, 2026
Patent 12726370
PSEUDO-HOMOMORPHIC AUTHENTICATION OF USERS WITH BIOMETRY
2y 8m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
98%
With Interview (+11.0%)
2y 4m (~1y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 739 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month