Prosecution Insights
Last updated: October 01, 2026
Application No. 19/257,791

MALICIOUS ACTIVITY PROBABILITY DETERMINATIONS FOR AUTONOMOUS SYSTEMS

Non-Final OA §103
Filed
Jul 02, 2025
Priority
Jun 29, 2022 — continuation of 12/373,568
Examiner
SHIN, KYUNG H
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
804 granted / 980 resolved
+24.0% vs TC avg
Moderate +10% lift
Without
With
+10.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
13 currently pending
Career history
995
Total Applications
across all art units

Statute-Specific Performance

§101
14.7%
-25.3% vs TC avg
§103
55.5%
+15.5% vs TC avg
§102
23.7%
-16.3% vs TC avg
§112
5.5%
-34.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 980 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 1. Claims 1 - 20 are pending. Claims 1, 9, 16 are independent. File date 7-2-2025. Double Patenting 2. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Omum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). 3. Initially it should be noted that the present application is a continuation application of application 17/853312, now patent 12,373,568 having the same inventive entity. The Assignee in both applications is the same. The entire disclosures of the instant application and the patent are identical. Claims 1 - 20 are rejected under the judicially created doctrine of nonstatutory type double patenting as being unpatentable over Claims 1 - 20 of U.S. Patent No. 12,373,568. Although the conflicting claims are not identical, they are not patentably distinct from each other. Claims 1, 9, 16 of the instant application (19/257791) are almost the same as Patent (12,373,568) Claims 1, 10, 17. Claim 1 of the 12,373,568 Patent as shown in the table below contains every element of Claim 1 of the instant application and as such the difference is not enough to distinguish the two claims. Claims 1, 9, 16 of the instant application therefore are not patently distinct from the earlier patent claims and as such are unpatentable over nonstatutory-type double patenting. A later patent/application claim is not patentably distinct from an earlier claim, if the later claim is unpatentable over the earlier claim. Application 19/257791 Claim 1 Patent (12,373,568) Claim 1 “a plurality of autonomous systems (ASs), each controlling a respective set of Internet Protocol (IP) addresses” “determine a count of Internet Protocol (IP) addresses controlled by an autonomous system (AS)” and ” generate threat intelligence (TI) signals for a subset of the IP addresses controlled by the AS based on detected malicious activity” “a computing apparatus configured to: retrieve, from one or more data sources, threat intelligence (TI) signals associated with network entities controlled by each autonomous system (AS), the TI signals generated responsive to detected malicious activity originating from or directed to the respective network entities” ” generate threat intelligence (TI) signals for a subset of the IP addresses controlled by the AS based on detected malicious activity” “calculate, for a first AS of the plurality of ASs, a threat intelligence score (TIS) by aggregating the TI signals associated with the network entities controlled by the first AS: “calculate a normalized threat intelligence score (TIS) for the AS based on a sum of the TI signals associated with the IP addresses controlled by the AS and the determined count of the IP addresses controlled by the AS” “determine, for the first AS, a reputation level indicative of a probability that future network activity associated with the first AS is malicious, wherein the reputation level is selected based on comparison of the first AS's TIS to one or more classification thresholds: “determine, based on the normalized TIS for the AS, a probability that activities associated with the IP addresses controlled by the AS are likely to be malicious” “output, to a security management system, data indicative of the reputation level” “output the determined probability that the activities associated with the IP addresses controlled by the AS are likely to be malicious” Claim Rejections - 35 USC § 103 4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claims 1-3, 9, 12, 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Bingham et al. (WO Patent No. WO 2016/164403-A1) in view of Liu et al. (Patent No. CN 116827940-A). Regarding Claim 1, Bingham discloses a system comprising: a computing apparatus (Bingham ¶ 067, ll 1-4: network security data collection, parsing, correlating, and analyzing software, threat intelligence software, and other modules and services may be embodied by instructions stored on such storage systems (memory) and executed by the processor; Some or all of the operations described herein may be performed by processor) configured to: b) retrieve, from one or more data sources, threat intelligence (TI) signals associated with network entities controlled by each autonomous system (AS), the TI signals generated responsive to detected malicious activity originating from or directed to the respective network entities; (Bingham ¶ 021: processing cluster 104 is configured to retrieve a network traffic dataset 106 providing information about IP addresses known to host malicious activity. The network traffic dataset 106 is obtained through the monitoring and correlation of network traffic over one or more ports in the primary network, for example, as described with respect to Figure 2. The network traffic dataset 106 may be used to identify a gross level of potential malicious actors based on the IP addresses between which traffic is exchanged via the primary network.) c) calculate, for a first AS of the plurality of ASs, a threat intelligence score (TIS) by aggregating the TI signals associated with the network entities controlled by the first AS; (Bingham ¶ 038, ll 1-8: generates a neighborhood score for each of the internet neighborhoods of the IP address and normalizes the reputation score based on the neighborhood scores for the internet neighborhoods; the reputation score is a normalized reputation score for the IP address taking into account the activity of the IP address and the activity of other uses that may be influencing a perceived threat level of the IP address; ¶ 035, ll 1-12: To ensure that an IP address is not assigned a reputation score that is inherited based upon the activities of other users, a neighborhood score for an internet neighborhood of the IP address is generated; The internet neighborhood represents a collection of IP addresses related to the IP address at issue and may be a netblock, an AS, a region, a country, and/or other collections of IP addresses) d) determine, for the first AS, a reputation level indicative of a probability that future network activity associated with the first AS is malicious, wherein the reputation level is selected based on comparison of the first AS's TIS to one or more classification thresholds; (Bingham ¶ 035, ll 1-12: The reputation score represents a confidence level in a likelihood of whether an IP address engages in or is otherwise susceptible to malicious activity; The higher the score, the higher the confidence that the IP address engages in or is otherwise susceptible to malicious activity; (confidence level indicates a probability that activities associated with IP address are malicious activities)) and e) output, to a security management system, data indicative of the reputation level. (Bingham ¶ 040, ll 1-3: user may query the processing cluster to obtain (for display) the reputation score and/or the reputation profile for one or more IP addresses to facilitate responding to network threats without limiting the network activity of legitimate end users; (request output of reputation score parameters)) Bingham does not explicitly disclose for a) a plurality of autonomous systems (ASs), each controlling a respective set of Internet Protocol (IP) addresses. However, Liu discloses: a) a plurality of autonomous systems (ASs), each controlling a respective set of Internet Protocol (IP) addresses. (Liu page 8, ll 21-37: address pool may include M allocated bit addresses (i.e., bit bits), where M may be a positive integer; For ease of explanation, the number M of allocated bit addresses of the address pool (e.g., the address pool 21D shown in FIG. 2) in the embodiment of the present application may take 10 as an example, and may specifically include the allocated bit address 0, the allocated bit address 1, ..., and the allocated bit address 9; page 012, ll 14-23: it needs to determine the address pool associated with the service server, so as to respectively obtain the numerical value of each allocation bit address in the M allocation bit addresses (total count of addresses in pool) from the address pool, taking the distribution bit address with updated value as the distributed address, and taking the distribution bit address with initial value as the address to be distributed; the bitmap server can count the address number of the allocated address, so as to determine the difference between the address number of the allocated address and M (total count of addresses in pool), and take the difference as the address number to be allocated of the address pool) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for a) a plurality of autonomous systems (ASs), each controlling a respective set of Internet Protocol (IP) addresses as taught by Liu. One of ordinary skill in the art would have been motivated to employ the teachings of Liu for the benefits achieved from a system that enables the flexibility and efficiency of partitioning the set of IP addresses into multiple pools of IP addresses. (Liu page 8, ll 21-37; page 012, ll 14-23) Regarding Claim 2, Bingham-Liu discloses the system of claim 1, wherein aggregating the TI signals comprises applying one or more weights based on at least one of: an activity type, a severity score, or a geographic origin of the network entity. (Bingham ¶ 034, ll 1-15: reputation score may involve weighting threat attributes of the security data to identify and/or predict the presence of malicious activity; a processing cluster can assign a weight to each threat attribute that corresponds to a nature of the associated threat, including a type of activity and a source of data indicating the activity; a machine learning system can assign a weight or dynamically readjust a weight for threat attributes; a machine learning system may track future activity and effects of that activity compared to the assigned weights for that activity to dynamically adjust weights for similar activity; (selected: an activity type)) Regarding Claim 3, Bingham-Liu discloses the system of claim 1, wherein the TIS is calculated using a logistic transformation applied to a weighted sum of the TI signals. (Bingham ¶ 034, ll 1-15: reputation score may involve weighting threat attributes of the security data to identify and/or predict the presence of malicious activity; processing cluster can assign a weight to each threat attribute that corresponds to a nature of the associated threat, including a type of activity and a source of data indicating the activity; a machine learning system can assign a weight or dynamically readjust a weight for threat attributes; machine learning system may track future activity and effects of that activity compared to the assigned weights for that activity to dynamically adjust weights for similar activity); ¶ 029, ll 1-8: agent extracts, ingests, and imports the security data and/or the other data into the processing cluster, where the security data and/or the other data is transformed, aggregated, parsed, and assigned relevancy values and locations for storage in the database) Liu discloses a determined count of IP addresses control by an AS as stated above. Regarding Claim 9, Bingham discloses a method comprising: a) retrieving, from one or more data sources, threat intelligence (TI) signals associated with network entities, the TI signals generated responsive to detected malicious activity originating from or directed to the respective network entities; (Bingham ¶ 021: processing cluster 104 is configured to retrieve a network traffic dataset 106 providing information about IP addresses known to host malicious activity. The network traffic dataset 106 is obtained through the monitoring and correlation of network traffic over one or more ports in the primary network, for example, as described with respect to Figure 2. The network traffic dataset 106 may be used to identify a gross level of potential malicious actors based on the IP addresses between which traffic is exchanged via the primary network.) b) calculating, for a first AS of a plurality of ASs, a threat intelligence score (TIS) by aggregating the TI signals associated with the network entities controlled by the first AS; (Bingham ¶ 038, ll 1-8: generates a neighborhood score for each of the internet neighborhoods of the IP address and normalizes the reputation score based on the neighborhood scores for the internet neighborhoods; the reputation score is a normalized reputation score for the IP address taking into account the activity of the IP address and the activity of other uses that may be influencing a perceived threat level of the IP address; ¶ 035, ll 1-12: To ensure that an IP address is not assigned a reputation score that is inherited based upon the activities of other users, a neighborhood score for an internet neighborhood of the IP address is generated; The internet neighborhood represents a collection of IP addresses related to the IP address at issue and may be a netblock, an AS, a region, a country, and/or other collections of IP addresses) c) determining, for the first AS, a reputation level indicative of a probability that future network activity associated with the first AS is malicious, wherein the reputation level is selected based on comparison of the first AS's TIS to one or more classification thresholds; (Bingham ¶ 035, ll 1-12: The reputation score represents a confidence level in a likelihood of whether an IP address engages in or is otherwise susceptible to malicious activity; The higher the score, the higher the confidence that the IP address engages in or is otherwise susceptible to malicious activity; (confidence level indicates a probability that activities associated with IP address are malicious activities)) and d) outputting, to a security management system, data indicative of the reputation level associated with at least the first AS. (Bingham ¶ 040, ll 1-3: user may query the processing cluster to obtain (for display) the reputation score and/or the reputation profile for one or more IP addresses to facilitate responding to network threats without limiting the network activity of legitimate end users; (request output of reputation score parameters)) Bingham does not explicitly disclose for a) network entities controlled by each autonomous system (AS) (multiple ASs). However, Liu discloses wherein for a) network entities controlled by each autonomous system (AS). (Liu page 8, ll 21-37: address pool may include M allocated bit addresses (i.e., bit bits), where M may be a positive integer; For ease of explanation, the number M of allocated bit addresses of the address pool (e.g., the address pool 21D shown in FIG. 2) in the embodiment of the present application may take 10 as an example, and may specifically include the allocated bit address 0, the allocated bit address 1, ..., and the allocated bit address 9; page 012, ll 14-23: it needs to determine the address pool associated with the service server, so as to respectively obtain the numerical value of each allocation bit address in the M allocation bit addresses (total count of addresses in pool) from the address pool, taking the distribution bit address with updated value as the distributed address, and taking the distribution bit address with initial value as the address to be distributed; the bitmap server can count the address number of the allocated address, so as to determine the difference between the address number of the allocated address and M (total count of addresses in pool), and take the difference as the address number to be allocated of the address pool) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for a) network entities controlled by each autonomous system (AS) as taught by Liu. One of ordinary skill in the art would have been motivated to employ the teachings of Liu for the benefits achieved from a system that enables the flexibility and efficiency of partitioning the set of IP addresses into multiple pools of IP addresses. (Liu page 8, ll 21-37; page 012, ll 14-23) Regarding Claim 12, Bingham-Liu discloses the method of claim 9, wherein calculating the TIS comprises applying a logistic transformation to a function of the TI signals and a scaled count of Internet Protocol (IP) addresses associated with the TI signals. (Bingham ¶ 034, ll 1-15: reputation score can involve weighting threat attributes of the security data to identify and/or predict the presence of malicious activity; a processing cluster can assign a weight to each threat attribute that corresponds to a nature of the associated threat, including a type of activity and a source of data indicating the activity; a low weight may be assigned to threat attributes related to port 80 (i.e., the default port for insecure Internet connection) because it is common to have traffic on port 80; Conversely, a higher weight may be assigned to threat attributes related to other ports with lower traffic activity because any traffic on through such ports is rare, which may be indicative of malicious activity; (scaling parameter analogous to weighting threat attributes); ¶ 029, ll 1-8: agent extracts, ingests, and imports the security data and/or the other data into the processing cluster, where the security data and/or the other data is transformed, aggregated, parsed, and assigned relevancy values and locations for storage in the database)) Regarding Claim 15, Bingham-Liu discloses the method of claim 9, further comprising outputting the data only when the reputation level is below a predefined threshold. (Bingham ¶ 042, ll 1-7: threat analytics generate a determination of a threshold for filtering network traffic or otherwise responding to malicious activity based on the reputation score; network traffic exchanged with IP addresses having a reputation score above a threshold (e.g., 50%) may be filtered, with the threshold set using the threat analytics; threshold may be set based on various factors, including, without limitation, business practices, vulnerability to malicious activities) (Bingham ¶ 040, ll 1-3: user may query the processing cluster to obtain the reputation score and/or the reputation profile for one or more IP addresses to facilitate responding to network threats without limiting the network activity of legitimate end users; (request output of reputation score parameters)) Regarding Claim 16, Bingham discloses a non-transitory computer-readable medium storing instructions that, when executed by one or more processors (Bingham ¶ 067, ll 1-4: network security data collection, parsing, correlating, and analyzing software, threat intelligence software, and other modules and services may be embodied by instructions stored on such storage systems (memory) and executed by the processor; Some or all of the operations described herein may be performed by processor), cause the one or more processors to: a) retrieve, from one or more data sources, threat intelligence (TI) signals associated with network entities, the TI signals generated responsive to detected malicious activity originating from or directed to the respective network entities; (Bingham ¶ 021: processing cluster 104 is configured to retrieve a network traffic dataset 106 providing information about IP addresses known to host malicious activity. The network traffic dataset 106 is obtained through the monitoring and correlation of network traffic over one or more ports in the primary network, for example, as described with respect to Figure 2. The network traffic dataset 106 may be used to identify a gross level of potential malicious actors based on the IP addresses between which traffic is exchanged via the primary network.) b) calculate, for a first AS of a plurality of ASs, a threat intelligence score (TIS) by aggregating the TI signals associated with the network entities controlled by the first AS; (Bingham ¶ 038, ll 1-8: generates a neighborhood score for each of the internet neighborhoods of the IP address and normalizes the reputation score based on the neighborhood scores for the internet neighborhoods; the reputation score is a normalized reputation score for the IP address taking into account the activity of the IP address and the activity of other uses that may be influencing a perceived threat level of the IP address; ¶ 035, ll 1-12: To ensure that an IP address is not assigned a reputation score that is inherited based upon the activities of other users, a neighborhood score for an internet neighborhood of the IP address is generated; The internet neighborhood represents a collection of IP addresses related to the IP address at issue and may be a netblock, an AS, a region, a country, and/or other collections of IP addresses) c) determine, for the first AS, a reputation level indicative of a probability that future network activity associated with the first AS is malicious, wherein the reputation level is selected based on comparison of the first AS's TIS to one or more classification thresholds; (Bingham ¶ 035, ll 1-12: The reputation score represents a confidence level in a likelihood of whether an IP address engages in or is otherwise susceptible to malicious activity; The higher the score, the higher the confidence that the IP address engages in or is otherwise susceptible to malicious activity; (confidence level indicates a probability that activities associated with IP address are malicious activities)) and d) output data indicative of the reputation level associated with at least the first AS to a security management system. (Bingham ¶ 040, ll 1-3: user may query the processing cluster to obtain (for display) the reputation score and/or the reputation profile for one or more IP addresses to facilitate responding to network threats without limiting the network activity of legitimate end users; (request output of reputation score parameters)) Bingham does not explicitly disclose for a) network entities controlled by each autonomous system (AS) (multiple ASs). However, Liu discloses wherein for a) network entities controlled by each autonomous system (AS). (Liu page 8, ll 21-37: address pool may include M allocated bit addresses (i.e., bit bits), where M may be a positive integer; For ease of explanation, the number M of allocated bit addresses of the address pool (e.g., the address pool 21D shown in FIG. 2) in the embodiment of the present application may take 10 as an example, and may specifically include the allocated bit address 0, the allocated bit address 1, ..., and the allocated bit address 9; page 012, ll 14-23: it needs to determine the address pool associated with the service server, so as to respectively obtain the numerical value of each allocation bit address in the M allocation bit addresses (total count of addresses in pool) from the address pool, taking the distribution bit address with updated value as the distributed address, and taking the distribution bit address with initial value as the address to be distributed; the bitmap server can count the address number of the allocated address, so as to determine the difference between the address number of the allocated address and M (total count of addresses in pool), and take the difference as the address number to be allocated of the address pool) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for a) network entities controlled by each autonomous system (AS) as taught by Liu. One of ordinary skill in the art would have been motivated to employ the teachings of Liu for the benefits achieved from a system that enables the flexibility and efficiency of partitioning the set of IP addresses into multiple pools of IP addresses. (Liu page 8, ll 21-37; page 012, ll 14-23) Regarding Claim 17, Bingham-Liu discloses the computer-readable medium of claim 16, wherein the instructions further cause the processor(s) to apply weights to the TI signals based on at least one of: activity type, severity level, or geographic location. (Bingham ¶ 034, ll 1-15: reputation score may involve weighting threat attributes of the security data to identify and/or predict the presence of malicious activity; a processing cluster can assign a weight to each threat attribute that corresponds to a nature of the associated threat, including a type of activity and a source of data indicating the activity; a machine learning system can assign a weight or dynamically readjust a weight for threat attributes; a machine learning system may track future activity and effects of that activity compared to the assigned weights for that activity to dynamically adjust weights for similar activity; (selected: an activity type)) Regarding Claim 18, Bingham-Liu discloses the computer-readable medium of claim 16, wherein the instructions further cause the processor(s) to: determine a count of Internet Protocol (IP) addresses controlled by a respective AS; and apply a scaling parameter to the count of IP addresses. (Bingham ¶ 034, ll 1-15: reputation score can involve weighting threat attributes of the security data to identify and/or predict the presence of malicious activity; a processing cluster can assign a weight to each threat attribute that corresponds to a nature of the associated threat, including a type of activity and a source of data indicating the activity; a low weight may be assigned to threat attributes related to port 80 (i.e., the default port for insecure Internet connection) because it is common to have traffic on port 80; Conversely, a higher weight may be assigned to threat attributes related to other ports with lower traffic activity because any traffic on through such ports is rare, which may be indicative of malicious activity; (scaling parameter analogous to weighting threat attributes)) Regarding Claim 19, Bingham-Liu discloses the computer-readable medium of claim 16, wherein the instructions further cause the processor(s) to calculate the TIS using a logistic transformation. (Bingham ¶ 029, ll 1-8: agent extracts, ingests, and imports the security data and/or the other data into the processing cluster, where the security data and/or the other data is transformed, aggregated, parsed, and assigned relevancy values and locations for storage in the database) 6. Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Bingham in view of Liu and further in view of Bogren et al. (US PGPUB No. 20220232031). Regarding Claim 4, Bingham-Liu discloses the system of claim 1. Bingham does not explicitly disclose classification thresholds comprise percentile ranges derived from a distribution of TIS values across the plurality of ASs. However, Bogren disclose wherein the classification thresholds comprise percentile ranges derived from a distribution of TIS values across the plurality of ASs. (Bogren ¶ 059: security scoring function 230 (e.g., scoring logic 238) may apply corresponding technique TE weights 332 to technique scores 322 to generate threat level scores 340 for each technique or category. The threat level scores (e.g., a technique score 322 with an applied technique TE weight 332) may be presented for individual techniques, for groups of techniques (e.g., a tactic), or for particular vendors (e.g., partner system 150). In one implementation, the threat level scores for each technique may be summed to generate an overall threat level score 340. The overall threat level score may be correlated to a percentage, number range (e.g., from 1 to 1000), letter (e.g., A, B, C, D, F), or a descriptive assessment (poor, average, good, excellent, etc.).) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for classification thresholds comprise percentile ranges derived from a distribution of TIS values across the plurality of ASs as taught by Bogren. One of ordinary skill in the art would have been motivated to employ the teachings of Bogren for the benefits achieved from the flexibility of a system that enables the utilization of multiple parameters such as percentile ranges derived from distribution of threat values in the processing of security related information. (Bogren ¶ 059) 7. Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Bingham in view of Liu and further in view of Reybok,JR et al. (US PGPUB No. 20170171231, “referred to as Reybok”). Regarding Claim 5, Bingham-Liu discloses the system of claim 1. Bingham does not explicitly disclose store historical TIS values associated with a respective AS, and determine trends in reputation level over time based on the historical TIS values. However, Reybok discloses wherein the computing apparatus is further configured to: store historical TIS values associated with a respective AS; and determine trends in reputation level over time based on the historical TIS values. (Reybok ¶ 098: Note that while two base scores are identified as contributing to the aggregate score for a particular threat, in other embodiments, the aggregate only can be used, or alternatively, many more base scores than two can be used, with a weighted combination of those scores used to produce the aggregate. As noted by numeral 961, the relational database (955) also stores historical scores indexed by client network or group, permitting trend analysis (e.g., velocity computation, to determine if the threat or a threat pattern is becoming more or less likely over time); this information can then play a part in thresholding and specification of actions to be taken, as discussed earlier.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for store historical TIS values associated with a respective AS, and determine trends in reputation level over time based on the historical TIS values as taught by Reybok. One of ordinary skill in the art would have been motivated to employ the teachings of Reybok for the benefits achieved from the flexibility of a system that enables the utilization of multiple parameters such as historical threat values in the processing of security related information. (Reybok ¶ 098) 8. Claims 6, 11, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Bingham in view of Liu and further in view of Stein et al. (US Patent No. 10,440,042). Regarding Claim 6, Bingham-Liu discloses the system of claim 1. Bingham does not explicitly disclose the output comprises a notification including metadata associated with the first AS and an indication of risk level. However, Stein discloses wherein the output comprises a notification including metadata associated with the first AS and an indication of risk level. (Stein col 2: a classification system is programmed to determine one or more domains associated with an AS. For a given domain associated with an AS, the classification system can extract one or more features from the domain. Using machine learning techniques, the classification system can apply a classifier to the extracted features in order to determine a risk priority score for the domain. The domain and its risk priority score can be placed into a scanner priority queue. A scanner system can then retrieve domains from the scanner priority queue, based upon the risk priority score, in order to prioritize scanning for domains that have a higher risk priority score. The scanner system may then scan a domain to collect data regarding the domain, including data related to whether the domain contains malicious content (metadata) and/or vulnerabilities to malicious attacks performed by third parties. In an embodiment, the scan results may be sent to a reporting system that can store the scan results and/or generate reports or notifications (a notification sent for security personnel to review)regarding the scan results.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for the output comprises a notification including metadata associated with the first AS and an indication of risk level.as taught by Stein. One of ordinary skill in the art would have been motivated to employ the teachings of Stein for the benefits achieved from the flexibility of a system that enables multiple parameters such as notifications including metadata to be utilized processing security information. (Stein col 2) Regarding Claim 11, Bingham-Liu discloses the method of claim 9. Bingham does not explicitly disclose reputation level comprises transmitting an alert to a remote monitoring console for review by security personnel. However, Stein discloses wherein outputting the reputation level comprises transmitting an alert to a remote monitoring console for review by security personnel. (Stein col 2: a classification system is programmed to determine one or more domains associated with an AS. For a given domain associated with an AS, the classification system can extract one or more features from the domain. Using machine learning techniques, the classification system can apply a classifier to the extracted features in order to determine a risk priority score for the domain. The domain and its risk priority score can be placed into a scanner priority queue. A scanner system can then retrieve domains from the scanner priority queue, based upon the risk priority score, in order to prioritize scanning for domains that have a higher risk priority score. The scanner system may then scan a domain to collect data regarding the domain, including data related to whether the domain contains malicious content and/or vulnerabilities to malicious attacks performed by third parties. In an embodiment, the scan results may be sent to a reporting system that can store the scan results and/or generate reports or notifications (an alert sent for security personnel to review) regarding the scan results.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for reputation level comprises transmitting an alert to a remote monitoring console for review by security personnel as taught by Stein. One of ordinary skill in the art would have been motivated to employ the teachings of Stein for the benefits achieved from the flexibility of a system that enables multiple parameters such as notifications including metadata to be utilized processing security information. (Stein col 2) Regarding Claim 20, Bingham-Liu discloses the non-transitory computer-readable medium of claim 19. Bingham does not explicitly disclose trigger an access control update based on the reputation level of the first AS. However, Stein discloses wherein the instructions further cause the one or more processors to trigger an access control update based on the reputation level of the first AS. (Stein col 16: the system architecture and processes disclosed herein are capable of identifying domains that contain malicious content and/or vulnerabilities to malicious attacks. As one particular example, classification system 110 determines a risk priority score for each domain name associated with an AS. Scanner system 130 may then use the risk priority score, as stored in scanner priority queue 120, to prioritize scanning for domain names that have a higher risk (updated risk score used to determine access); col 2: a classification system is programmed to determine one or more domains associated with an AS. For a given domain associated with an AS, the classification system can extract one or more features from the domain. Using machine learning techniques, the classification system can apply a classifier to the extracted features in order to determine a risk priority score for the domain. The domain and its risk priority score can be placed into a scanner priority queue. A scanner system can then retrieve domains from the scanner priority queue, based upon the risk priority score, in order to prioritize scanning for domains that have a higher risk priority score. The scanner system may then scan a domain to collect data regarding the domain, including data related to whether the domain contains malicious content and/or vulnerabilities to malicious attacks performed by third parties. In an embodiment, the scan results may be sent to a reporting system that can store the scan results and/or generate reports or notifications (an alert sent for security personnel to review) regarding the scan results.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for trigger an access control update based on the reputation level of the first AS as taught by Stein. One of ordinary skill in the art would have been motivated to employ the teachings of Stein for the benefits achieved from the flexibility of a system that enables multiple parameters such as notifications including metadata to be utilized processing security information. (Stein col 2) 9. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Bingham in view of Liu and further in view of Jalan et al. (US PGPUB No. 20180083997). Regarding Claim 7, Bingham-Liu discloses the system of claim 1. Bingham does not explicitly disclose security management system configured to automatically apply a security policy in response to the received reputation level. However, Jalan discloses wherein the security management system is configured to automatically apply a security policy in response to the received reputation level. (Jalan ¶ 028: The system 200 may further include a mitigation device 240. The mitigation device 240 may be operable to receive a service request from the client. The service request may include one or more data packets. The mitigation device 240 may be operable to automatically apply, based on the security threat score, a security policy to the client. Furthermore, based on the security threat score, a quality of service is provided to the client.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for security management system configured to automatically apply a security policy in response to the received reputation level as taught by Jalan. One of ordinary skill in the art would have been motivated to employ the teachings of Jalan for the benefits achieved from the flexibility of a system that enables the automatic application of a security policy based on a particular threat score. (Jalan ¶ 028) 10. Claims 8, 10, 13, 14 are rejected under 35 U.S.C. 103 as being unpatentable over Bingham in view of Liu and further in view of Kolman et al. (US Patent No. 10,003,607). Regarding Claim 8, Bingham-Liu discloses the system of claim 1. Bingham does not explicitly disclose generate a histogram of the plurality of ASs based on their respective TIS values; and using the histogram, determine the classification thresholds. However, Kolman discloses wherein the computing apparatus is further configured to: generate a histogram of the plurality of ASs based on their respective TIS values; and using the histogram, determine the classification thresholds. (Kolman col 10, ll 9-23: A given feature risk score based on both user and group risk scores is illustratively generated by generating a user risk score for a given one of the extracted features utilizing the corresponding user histogram, generating a group risk score for the given one of the extracted features utilizing the corresponding group histogram, and combining the user risk score and the group risk score to generate a feature risk score for the given extracted feature; This is repeated for each of at least a subset of the extracted features) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for generate a histogram of the plurality of ASs based on their respective TIS values; and using the histogram, determine the classification thresholds. as taught by Kolman. One of ordinary skill in the art would have been motivated to employ the teachings of Kolman for the benefits achieved from a system that provides for the generation of histogram in the processing of threat analysis information. (Kolman col 10, ll 9-23) Regarding Claim 10, Bingham-Liu discloses the method of claim 9. Bingham does not explicitly disclose generating a histogram of the plurality of ASs based on their respective TIS values and using the histogram to determine the classification thresholds. However, Kolman discloses wherein further comprising generating a histogram of the plurality of ASs based on their respective TIS values and using the histogram to determine the classification thresholds. (Kolman col 10, ll 9-23: A given feature risk score based on both user and group risk scores is illustratively generated by generating a user risk score for a given one of the extracted features utilizing the corresponding user histogram, generating a group risk score for the given one of the extracted features utilizing the corresponding group histogram, and combining the user risk score and the group risk score to generate a feature risk score for the given extracted feature; This is repeated for each of at least a subset of the extracted features) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for generating a histogram of the plurality of ASs based on their respective TIS values and using the histogram to determine the classification thresholds as taught by Kolman. One of ordinary skill in the art would have been motivated to employ the teachings of Kolman for the benefits achieved from a system that provides for the generation of histogram in the processing of threat analysis information. (Kolman col 10, ll 9-23) Regarding Claim 13, Bingham-Liu discloses the method of claim 9, Bingham does not explicitly disclose grouping the ASs into reputation categories based on their respective TIS values. However, Kolman discloses wherein further comprising grouping the ASs into reputation categories based on their respective TIS values. (Kolman col 10, ll 9-23: A given feature risk score based on both user and group risk scores is illustratively generated by generating a user risk score for a given one of the extracted features utilizing the corresponding user histogram, generating a group risk score for the given one of the extracted features utilizing the corresponding group histogram, and combining the user risk score and the group risk score to generate a feature risk score for the given extracted feature; This is repeated for each of at least a subset of the extracted features) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for grouping the ASs into reputation categories based on their respective TIS values as taught by Kolman. One of ordinary skill in the art would have been motivated to employ the teachings of Kolman for the benefits achieved from a system that provides for the generation of histogram in the processing of threat analysis information. (Kolman col 10, ll 9-23) Regarding Claim 14, Bingham-Liu-Kolman discloses the method of claim 13. Bingham does not explicitly disclose generating a histogram of the ASs, and assigning reputation levels to the ASs based on the histogram. However, Kolman discloses wherein further comprising: generating a histogram of the ASs; and assigning reputation levels to the ASs based on the histogram. (Kolman col 10, ll 9-23: A given feature risk score based on both user and group risk scores is illustratively generated by generating a user risk score for a given one of the extracted features utilizing the corresponding user histogram, generating a group risk score for the given one of the extracted features utilizing the corresponding group histogram, and combining the user risk score and the group risk score to generate a feature risk score for the given extracted feature; This is repeated for each of at least a subset of the extracted features) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bingham for generating a histogram of the ASs, and assigning reputation levels to the ASs based on the histogram as taught by Kolman. One of ordinary skill in the art would have been motivated to employ the teachings of Kolman for the benefits achieved from a system that provides for the generation of histogram in the processing of threat analysis information. (Kolman col 10, ll 9-23) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kyung H Shin whose telephone number is (571)272-3920. The examiner can normally be reached M - F: 12pm - 8pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon H Hwang can be reached at 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KYUNG H SHIN/ 9-10-2026Primary Examiner, Art Unit 2447
Read full office action

Prosecution Timeline

Jul 02, 2025
Application Filed
Sep 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732518
LOG ANOMALY DETECTION USING TEMPORAL-ATTENTIVE DYNAMIC GRAPHS
3y 1m to grant Granted Sep 08, 2026
Patent 12710977
USE OF GRAPH NEURAL NETWORKS TO CLASSIFY, GENERATE, AND ANALYZE SYNTHETIC CYBER SECURITY INCIDENTS
2y 7m to grant Granted Aug 18, 2026
Patent 12712727
Providing Customers Visibility Into Security And Compliance Of Services In A Customer Cloud Infrastructure Environment
2y 3m to grant Granted Aug 18, 2026
Patent 12712810
RECURSIVE BITSTRING STRUCTURE ADDRESSING
2y 3m to grant Granted Aug 18, 2026
Patent 12706835
SMART LINK AGGREGATION AND/OR SELECTION FOR WEB TRAFFIC
2y 3m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
92%
With Interview (+10.5%)
2y 11m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 980 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month