Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to an application filed July 2, 2025. Claims 1-20 are pending in this application.
Double Patenting
The nonstatutory obviousness double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-20 are rejected on the ground of nonstatutory obviousness double patenting as being unpatentable over claims 1-20 of patent document no. 12,375,523 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims are directed to the same subject matter of determining a target page is a phishing page. A side-by-side analysis of the first independent claim(s) of the instant application and the copending application(s) has been included below. The portions are related to subject matter which are obvious, and do not further define over the subject matter of one another. Therefore, the subject matter of both claim sets are not distinct from one another and yields an obviousness-type double patenting rejection. This is NOT a provisional double patenting rejection since patent document (12,375,523 B2) has been issued while the instant application is pending.
Here is the following side-by-side analysis of the first independent claim in each application:
Instant Application ‘262
1. A system for detecting phishing attacks, comprising:
a processor;
a memory storing a database of legitimate pages; and
a phishing detection module configured to:
obtain a representation of a source page from the database of legitimate pages;
identify a target page rendered by a browser that matches the representation of the source page;
compare a domain name of the target page with a domain name of the source page; and
determine that the target page is a phishing page based on the comparison of domain names and the matching of the representation.
Patent No. ‘523
1. A method comprising:
obtaining a selection of one or more page elements from a plurality of page elements of a legitimate page, wherein the one or more page elements are selected from the plurality of page elements as they are estimated to represent a visual appearance of the legitimate page better than other page elements of the legitimate page;
generating one or more respective representations of the one or more page elements, wherein a representation of the one or more respective representations represents a selected page element of the one or more page elements, wherein the representation is configured to be used for acquiring the selected page element in different pages;
obtaining, at a client device, a target page, wherein the client device is operated by a user and enabling the user to interact with the target page;
determining a match between the legitimate page and the target page, the match is determined based on a score of a visual similarity measurement between the legitimate page and the target page being greater than a threshold, wherein the score of the visual similarity measurement is based on an outcome of performing an acquisition in the target page, of the one or more page elements, or portion thereof, using the one or more respective representations;
classifying the target page as a phishing attack based on the match, whereby detecting the phishing attack; and
performing a responsive action in response to said detecting the phishing attack.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Gupta et al. (US 2014/0359760 A1).
With respect to claim 1, Gupta discloses a system for detecting phishing attacks (Abstract), comprising:
a processor (Abstract, processor);
a memory storing a database of legitimate pages ([0041] and Claim 17, memory storing webpage database) ; and
a phishing detection module configured to:
obtain a representation of a source page from the database of legitimate pages ([0022], obtain visual information of a legitimate webpage stored in a database);
identify a target page rendered by a browser that matches the representation of the source page ([0015] and [0022], calculating a measure of similarity between legitimate webpage and suspected webpage);
compare a domain name of the target page with a domain name of the source page ([0010], URL similarity and domain name probability); and
determine that the target page is a phishing page based on the comparison of domain names and the matching of the representation ([0010]-[0011], phishing webpages are identified based on heuristic results).
With respect to claim 2, Gupta discloses the system of Claim 1, wherein the representation of the source page comprises representations of selected elements within the source page ([0014]-[0015], extract page elements for visual inspection for visual similarity between legitimate webpage and suspected webpage).
With respect to claim 3, Gupta discloses the system of Claim 2, wherein the representations of selected elements comprise at least one of: Document Object Model (DOM) representations, contextual representations, or visual attribute representations ([0014]-[0015]).
With respect to claim 4, Gupta discloses the system of Claim 1, wherein identifying the target page that matches the representation of the source page comprises determining a visual similarity measurement between the target page and the source page ([0015]).
With respect to claim 5, Gupta discloses the system of Claim 4, wherein the visual similarity measurement is based on a successful acquisition of one or more page elements in the target page using the representation of the source page ([0015]).
With respect to claim 6, Gupta discloses the system of Claim 1, wherein the phishing detection module is further configured to:
analyze a certificate associated with the target page to determine if the certificate was issued by a trusted certification authority ([0085]).
With respect to claim 7, Gupta discloses the system of Claim 6, wherein the phishing detection module is configured to classify the target page as a phishing page if the certificate was not issued by a trusted certification authority, regardless of the visual similarity measurement ([0085]).
With respect to claim 8, Gupta discloses the system of Claim 1, wherein the phishing detection module is further configured to:
perform a responsive action in response to determining that the target page is a phishing page ([0102]).
With respect to claim 9, Gupta discloses the system of Claim 8, wherein the responsive action comprises at least one of:
displaying a warning to a user, blocking user interaction with the target page, or redirecting the user to a safe website ([0102]).
With respect to claim 10, Gupta discloses the system of Claim 1, wherein the phishing detection module is configured to identify the target page as matching the representation of the source page even if the target page is in a different language than the source page ([0014]-[0015]).
With respect to claim(s) 11-20, the method of claim(s) 11-20 does/do not limit or further define over the system of claim(s) 1-10. The limitations of claim(s) 11-20 is/are essentially similar to the limitations of claim(s) 1-10. Therefore, claim(s) 11-20 is/are rejected for the same reasons as claim(s) 1-10. Please see rejection above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ESTHER B. HENDERSON whose telephone number is (571)270-3807. The examiner can normally be reached Monday-Friday 6a-2p ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at 571-270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ESTHER B. HENDERSON/Primary Examiner, Art Unit 2458 September 16, 2026