Prosecution Insights
Last updated: October 02, 2026
Application No. 19/287,927

INLINE INSPECTION CYBERSECURITY ENFORCEMENT OF MULTIPART FILE TRANSMISSIONS

Non-Final OA §DP
Filed
Aug 01, 2025
Priority
Feb 16, 2023 — continuation of 12/407,651
Examiner
MOORTHY, ARAVIND K
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 10m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
979 granted / 1159 resolved
+24.5% vs TC avg
Moderate +12% lift
Without
With
+12.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
14 currently pending
Career history
1165
Total Applications
across all art units

Statute-Specific Performance

§101
11.7%
-28.3% vs TC avg
§103
40.5%
+0.5% vs TC avg
§102
23.6%
-16.4% vs TC avg
§112
12.3%
-27.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1159 resolved cases

Office Action

§DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 1. This is in response to the communications filed on 01 August 2025. 2. Claims 1-20 are pending in the application. 3. Claims 1-20 have been rejected. Information Disclosure Statement 4. The examiner has considered the information disclosure statement (IDS) filed on 01 August 2025. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. 5. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-22 of U.S. Patent No. 12,407,651 B2 (hereinafter the ‘651 patent). Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are anticipated by the earlier filed claims of the ‘651 patent in that the claims of the ‘651 patent contain all of the limitations of the instant application. Claims 1-20 of the instant application therefore are not patentable distinct from the earlier filed claimed of the ‘651 patent , and as such, are unpatentable for obvious-type double patenting. As to claim 1, the ‘651 patent discloses a method comprising: tracking states of files of multipart file transmissions to facilitate cybersecurity compliance, wherein tracking states of the files comprises [column 14, lines 1-4], based on receipt of a communication indicating an intercepted message of a session and an application identified for the session, updating a data store based on the intercepted message [column 14, lines 5-8]; based on the identified application, determining an action to prevent completion of a multipart file transmission corresponding to the session [column 14, lines 9-11]; and indicating to a network component to stall or allow transmission of the intercepted message based on the determined action [column 14, lines 12-14]; based on receipt of the communication indicating the intercepted message, determining whether a cybersecurity analysis condition is satisfied based on information in the data store corresponding to the multipart file transmission [column 14, lines 15-19]; if the cybersecurity analysis condition is satisfied, obtaining a cybersecurity analysis verdict for a file of the multipart file transmission or a file chunk extracted from the intercepted message [column 14, lines 20-23]; and communicating to a network component that intercepted the intercepted message at least one of a verdict of the cybersecurity analysis and an indication to allow or prevent completion of the multipart file transmission [column 14, lines 24-28]. As to claim 2, the ‘651 patent discloses the method of claim 1, wherein communicating the indication to allow completion of the multipart file transmission comprises determining that the cybersecurity analysis verdict indicates the file as benign or transmission of the file as not violating a cybersecurity policy [column 14, lines 29-35]. As to claim 3, the ‘651 patent discloses the method of claim 1, wherein communicating the indication to prevent completion of the multipart file transmission comprises determining that the cybersecurity analysis verdict indicates the file or a file chunk as malicious or transmission of the file or a file chunk as violating a policy [column 14, lines 36-42]. As to claim 4, the ‘651 patent discloses the method of claim 1, wherein updating the data store based on the intercepted message comprises extracting a file chunk from the intercepted message based on a protocol of the identified application and storing the file chunk in the data store in association with information identifying the session, the multipart file transmission corresponding to the session, and the identified application [column 14, lines 43-50]. As to claim 5, the ‘651 patent discloses the method of claim 1, wherein updating the data store based on the intercepted message comprises determining the intercepted message is a control message based on a protocol of the identified application, and updating the data store to indicate the control message, information identifying the session, information identifying the multipart file transmission corresponding to the session, and a type of the control message [column 14, lines 51-59]. As to claim 6, the ‘651 patent discloses the method of claim 1, wherein determining the action to prevent completion of the multipart file transmission corresponding to the session based on the identified application comprises selecting the action from a plurality of actions based on the identified application, wherein the plurality of actions corresponds to a plurality of protocols of different applications [column 14, lines 60-67]. As to claim 7, the ‘651 patent discloses the method of claim 1, wherein determining whether the cybersecurity analysis condition is satisfied comprises determining whether the file can be reassembled based on information and file chunks in the data store [column 15, lines 1-6]. As to claim 8, the ‘651 patent discloses the method of claim 7, further comprising reassembling the file with the file chunks and information in the data store based on a determination that the cybersecurity analysis condition is satisfied [column 15, lines 7-11]. As to claim 9, the ‘651 patent discloses the method of claim 1, wherein determining whether a cybersecurity analysis condition is satisfied comprises determining whether a cybersecurity analysis verdict has been obtained for at least one of the multiple file chunks that constitute the file [column 15, lines 12-17]. As to claim 10, the ‘651 patent discloses a non-transitory machine-readable medium having stored thereon program code, the program code comprising instructions to: based on an identification of an application for a first session of multiple sessions for a multipart file transmission of a file, determine a prevent action to prevent completion of the multipart file transmission [column 12, lines 64-67]; instruct an intermediary network component to allow transmission or stall transmission of a first message in the first session based, at least in part, on the prevent action [column 13, lines 1-4]; obtain from the first message a first chunk of a plurality of chunks that constitutes the file and first metadata of the first chunk [column 13, lines 5-7]; update a data store to indicate the first chunk and the first metadata [column 13, lines 8-9]; determine whether a cybersecurity analysis condition is satisfied based on information in the data store corresponding to the file [column 13, lines 10-12]; based on a determination that the cybersecurity analysis condition is satisfied, supply the first chunk or the file for cybersecurity analysis [column 13, lines 13-15]; and communicate to the intermediary network component at least one of a verdict of the cybersecurity analysis and an indication to allow or prevent completion of the multipart file transmission [column 13, lines 16-19]. As to claim 11, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the program code further comprises instructions to: parse, based on a protocol of the identified application, at least one of a header and a payload of the first message to obtain the first chunk and the first metadata [column 13, lines 21-23]. As to claim 12, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the instructions to determine the prevent action comprise instructions to determine whether stalling transmission of a control message or a file chunk will prevent completion of the multipart file transmission based on a protocol of the identified application [column 13, lines 24-28]. As to claim 13, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the instructions to determine the prevent action comprise the instructions to determine the prevent action also based on configuration information [column 13, lines 29-30]. As to claim 14, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the prevent action comprises stalling transmission of a subset of chunks that constitute a file to a recipient endpoint, stalling transmission of a control message that indicates completion of a multipart file transmission, stalling transmission of an acknowledgement message, and stalling transmission to a recipient endpoint of a control message for reassembling chunks into a file [column 13, lines 31-38]. As to claim 15, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the instructions to communicate an indication to allow completion of the multipart file transmission is based on the verdict indicating that the file is benign or that transmission of the file does not violate a policy [column 13, lines 39-43]. As to claim 16, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the instructions to communicate an indication to prevent completion of the multipart file transmission is based on the verdict indicating that the file or the first chunk is malicious or that transmission of the file or the first chunk violates a policy [column 13, lines 44-48]. As to claim 17, the ‘651 patent discloses the non-transitory machine-readable medium of claim 10, wherein the program code further comprises instructions to: obtain the other chunks of the plurality of chunks and corresponding metadata from other messages in the other ones of the multiple sessions [column 13, lines 50-52]; and update the data store to indicate the other chunks and corresponding metadata [column 13, lines 53-54], wherein the instructions to determine whether the cybersecurity analysis condition is satisfied based on information in the data store corresponding to the file comprise instructions to determine whether the file can be reassembled based on chunks and metadata in the data store [column 13, lines 55-59]. As to claim 18, the ‘651 patent discloses an apparatus comprising: a processor [column 12, lines 64-67]; a set of one or more machine-readable medium having program code stored thereon, the program code executable by the processor to cause the apparatus to [column 12, lines 64-67], based on an identification of an application for a first session of multiple sessions for a multipart file transmission of a file, determine a prevent action to prevent completion of the multipart file transmission [column 12, lines 64-67]; instruct an intermediary network component to allow transmission or stall transmission of a first message in the first session based, at least in part, on the prevent action [column 13, lines 1-4]; obtain from the first message a first chunk of a plurality of chunks that constitutes the file and first metadata of the first chunk [column 13, lines 5-7]; update a data store to indicate the first chunk and the first metadata [column 13, lines 8-9]; determine whether a cybersecurity analysis condition is satisfied based on information in the data store corresponding to the file [column 13, lines 10-12]; based on a determination that the cybersecurity analysis condition is satisfied, supply the first chunk or the file for cybersecurity analysis [column 13, lines 13-15]; and communicate to the intermediary network component at least one of a verdict of the cybersecurity analysis and an indication to allow or prevent completion of the multipart file transmission [column 13, lines 16-19]. As to claim 19, the ‘651 patent discloses the apparatus of claim 18, wherein the program code further comprises instructions to: parse, based on a protocol of the identified application, at least one of a header and a payload of the first message to obtain the first chunk and the first metadata [column 13, lines 21-23]. As to claim 20, the ‘651 patent discloses the apparatus of claim 18, wherein the instructions to determine the prevent action comprise the instructions being executable to determine whether stalling transmission of a control message or a file chunk will prevent completion of the multipart file transmission based on a protocol of the identified application [column 13, lines 24-28]. Allowable Subject Matter 6. Claims 1-20 are allowed over the prior art. The following is an examiner’s statement of reasons for allowance: The closest prior art to the instant application is Sun et al US 2020/0236124 A1 (hereinafter Sun). Sun is directed towards data management and a computer system that may evaluate network traffic to extract and group data objects based on their content satisfying similarity criteria, and to identify baseline behavior with respect to those data objects [abstract]. Sun teaches monitoring intra-network traffic without modifying it [0058]. Sun teaches preventing transmission of a data object [0058]. Sun teaches data-based segmentation [0104]. Sun teaches a data store [0064]. Sun teaches an enforcer module that can verify if a data object has the desired behavior and/or content [0102]. Sun teaches if the results of classification or policies indicate that the data object is anomalous further transmission of the data object will be prevented [0102]. However, with respect to independent claim 1 the applicant has incorporated (from the parent application) the allowable limitations of “based on receipt of a communication indicating an intercepted message of a session and an application identified for the session, updating a data store based on the intercepted message”, “if the cybersecurity analysis condition is satisfied, obtaining a cybersecurity analysis verdict for a file of the multipart file transmission or a file chunk extracted from the intercepted message” and “communicating to a network component that intercepted the intercepted message at least one of a verdict of the cybersecurity analysis and an indication to allow or prevent completion of the multipart file transmission”. With respect to independent claims 10 and 18 the applicant has incorporated (from the parent application) the allowable limitations of “based on receipt of a communication indicating an intercepted message of a session and an application identified for the session, updating a data store based on the intercepted message”, “based on the identified application, determining an action to prevent completion of a multipart file transmission corresponding to the session”, “if the cybersecurity analysis condition is satisfied, obtaining a cybersecurity analysis verdict for a file of the multipart file transmission or a file chunk extracted from the intercepted message” and “communicating to a network component that intercepted the intercepted message at least one of a verdict of the cybersecurity analysis and an indication to allow or prevent completion of the multipart file transmission”. Any claims not directly addressed are allowed on the virtue of their dependency. Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.” Relevant Prior Art 7. The following references have been considered relevant by the examiner: A. Hua et al US 2022/0385730 A1 directed to a rules engine that determines whether a content asset such as a movie is allowed to be downloaded to a device, such as for offline viewing [abstract]. B. Ahuja et al US 2018/0288094 A1 directed to techniques for inserting and configuring interface microservices at computer systems in response security policy changes affecting servers hosted by the computer systems [0001]. C. Crofton et al US 2017/0331893 A1 directed to aggregation and management of cloud storage to leverage third-party storage policies [abstract]. D. Tuvell et al US 2015/0347753 A1 directed to provide malware protection for one or more client mobile platforms in communication with a management server via a mobile network [abstract]. Conclusion 8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARAVIND K MOORTHY whose telephone number is (571)272-3793. The examiner can normally be reached M-F 4:30-3:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ARAVIND K MOORTHY/ Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

Aug 01, 2025
Application Filed
Sep 17, 2026
Non-Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750671
SYSTEM AND METHODS FOR DATA SECURITY USING DISTANCE MEASUREMENT
2y 0m to grant Granted Sep 29, 2026
Patent 12749081
SYSTEM AND METHOD FOR DYNAMIC NETWORK INFRASTRUCTURE, PROOF OF ACHIEVEMENT, AND CONTEXTUAL NFT GENERATION
1y 7m to grant Granted Sep 29, 2026
Patent 12750356
MOBILE DEVICE ENABLED DESKTOP TETHERED AND TETHERLESS AUTHENTICATION
1y 7m to grant Granted Sep 29, 2026
Patent 12726350
ZERO-TRUST REMOTE ATTESTATION SERVICE DEPLOYMENT SYSTEM BASED ON CONFIDENTIAL VIRTUAL MACHINE
1y 3m to grant Granted Sep 01, 2026
Patent 12719886
SYSTEM AND METHOD OF DETECTING MULTIFACTOR AUTHORIZATION ATTACK
3y 6m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
97%
With Interview (+12.2%)
3y 0m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1159 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month