Prosecution Insights
Last updated: October 04, 2026
Application No. 18/109,815

SYSTEM FOR DETECTING MALWARES IN A RESOURCES CONSTRAINED DEVICE

Final Rejection §103
Filed
Feb 14, 2023
Priority
Feb 25, 2022 — EU 22305211.9
Examiner
JOHNSON, CARLTON
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Institut Polytechnique De Grenoble
OA Round
4 (Final)
58%
Grant Probability
Moderate
5-6
OA Rounds
10m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
211 granted / 364 resolved
At TC average
Strong +33% interview lift
Without
With
+33.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 6m
Avg Prosecution
13 currently pending
Career history
385
Total Applications
across all art units

Statute-Specific Performance

§101
12.0%
-28.0% vs TC avg
§103
64.6%
+24.6% vs TC avg
§102
13.2%
-26.8% vs TC avg
§112
9.4%
-30.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 364 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 1. This action is in response to application amendments filed on 7-2-2026. 2. Claims 1 - 3, 5 - 13 are pending. Claims 1, 6, 8, 12, 13 are amended. Claims 4, 14 are canceled. Claims 1, 12, 13 are independent. This application was filed on 2-14-2023. Response to Arguments 3. Applicant’s arguments, see Arguments/Remarks Made in an Amendment, filed 2-12-2026, with respect to the rejection(s) in view of Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Bonageri have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Bonageri and Ji. A. Applicant argues on page 7 of Remarks: … The cited references do not teach or suggest "the remote machine learning module is configured to generate a notification for appropriate local action if the received data corresponds to malware". The Examiner respectfully disagrees. Hunt discloses generation of a notification if a determination that malware data is received. (see Hunt paragraph [0048]: User event monitor 180 may receive alerts from other components in the malware detection system.; paragraph [0036]: The scans using the modules of data monitoring program may be scheduled (predefined transmission rate) to ensure the least trade-off impact on real-time application performance versus detection. In an embodiment, scans by data monitoring program may be performed at Boot-up, during software updates, and daily full scan of memory (e.g., cache, ROM, firmware-Bios, flash memory, SRAM, DRAM).; (transmissions at a scheduled or pre-defined rate); paragraph [0044]: Spectral analysis 132 is able to detect code anomalies that may fit signatures of malware in situations where a score based on the attributes and behavior of the code anomaly is above a threshold level for the given malware threat (e.g., suspicious, malicious).) B. Applicant argues on page 8 of Remarks: … The cited references do not teach or suggest "the local machine learning module being configured to send the monitored data stored in the data memory to the remote machine learning module at the predefined transmission rate" or "transmitting the stored monitored data at a predefined transmission rate to a remote server". The Examiner respectfully disagrees. Chen discloses transmitting data between network connected entities (local or remote) at a predefined transmission rate. (see Chen pages 13-14: In the embodiment of the present invention, for any TCP data stream, the transmission rate of the TCP data stream may be the transmission rate of the TCP data stream or the receiving rate of the TCP data stream. The rate characterization value of the TCP data stream may be the transmission rate itself of the TCP data stream, for example, may be the reception rate or transmission rate of the TCP data stream. For any TCP data stream, the rate representation value of the TCP data stream may also be the amount of data of the IP data packet belonging to the TCP data stream received or transmitted within a preset duration.; (transmission and reception rate for network connected device stream communications)) C. Applicant argues on page 8 of Remarks: … Chen does not teach "the local machine learning module being configured to send the monitored data stored in the data memory to the remote machine learning module at the predefined transmission rate" or "transmitting the stored monitored data at a predefined transmission rate to a remote server" … . The Examiner respectfully disagrees. Chen discloses transmitting data between network connected entities (local or remote) at a predefined transmission rate. (see Chen pages 13-14: In the embodiment of the present invention, for any TCP data stream, the transmission rate of the TCP data stream may be the transmission rate of the TCP data stream or the receiving rate of the TCP data stream. The rate characterization value of the TCP data stream may be the transmission rate itself of the TCP data stream, for example, may be the reception rate or transmission rate of the TCP data stream. For any TCP data stream, the rate representation value of the TCP data stream may also be the amount of data of the IP data packet belonging to the TCP data stream received or transmitted within a preset duration.; (transmission and reception rate for network connected device stream communications)) D. Applicant argues on page 9 of Remarks: … The cited references do not teach or suggest "wherein the local machine learning module implements a first malwares detection machine learning algorithm and the remote machine learning module implements a second malwares detection machine learning algorithm being different from the first malwares detection machine learning algorithm and having a malwares detection accuracy higher than the first malwares detection machine learning algorithm". The Examiner respectfully disagrees. Ji discloses data processing utilizing a first malwares detection machine and a second malwares detection machine. Ji discloses a determination of a second malwares detection machine having a higher accuracy than a first malwares detection machine. (see Ji paragraph [0068]: security platform 122 provides a set of machine learning models to data appliance 102 for data appliance 102 to use in conjunction with inline malware detection. The models incorporate features (e.g., n-grams or other features) determined by security platform 122 as corresponding to malicious files. Two example types of such models include linear classification models and non-linear classification models. Examples of linear classification models that can be used by data appliance 102 include logistic regression and linear support vector machines. An example of a non-linear classification model that can be used by data appliance 102 includes a gradient boosting tree (e.g., eXtreme Gradient Boosting (XGBoost)). The non-linear model is more accurate (and is better able to detect obfuscated/disguised malware), but the linear model uses considerably fewer resources on appliance 102 (and is more suitable for efficiently analyzing JavaScript or similar files).) E. Applicant argues on page 10 of Remarks: … The cited references do not teach or suggest "to locally store the monitored data in a memory if the confidence score is lower than the first predefined alert threshold and higher than a second predefined suspicious threshold and do not store the monitored data when the confidence score is lower than the second predefined suspicious threshold" … . The Examiner respectfully disagrees. Suzuki discloses to output data to a memory when priority (confidence score) is less than a first threshold value and higher than a second threshold value. (see Suzuki page 2: outputs log data (first log data) to the first area 13 of the memory 12 when the importance of the log data is higher than a predetermined first threshold, (current value greater than threshold value, store data memory; first threshold greater than second threshold)) F. Applicant argues on page 11 of Remarks: … Neither Suzuki nor Chen are analogous art. The Examiner respectfully disagrees. The claimed invention discloses monitoring transmitted data and a determination of whether the data is processed correctly and securely (detection of malware, secure transmission). Suzuki discloses processing of secure data utilizing threshold parameters. Chen discloses monitoring data and discarding data that does not meet requirements. G. Applicant argues on page 13 of Remarks: … The Office Action Has Failed to Provide a Sufficient Articulated Motivation to Combine Hunt with Suzuki and Chen The Examiner respectfully disagrees. A 103 rejection based on multiple references is a legitimate technique according to the MPEP. The 103 rejection allows portions of the rejection citations for a claimed invention to come from different prior art references. The rejection to each independent and dependent claim includes a citation from the referenced prior art that discloses the basis for the rejection. Each obviousness combination clearly indicates the claim limitation(s) the combined referenced prior art teaches. In addition, a cited passage from the referenced prior art indicates the motivation for the obviousness combination. Each obviousness combination’s disclosure is equivalent to the Applicant’s claim limitation(s) for the claimed invention. Achieved advantage is a valid motivation for the combination of referenced prior art. The rejection of each referenced prior art combination states a motivation for the combination, which translates to an achieved advantage for the combination. H. Applicant argues on page 14 of Remarks: … The Office Action Relies on Impermissible Hindsight The Examiner respectfully disagrees. In response to applicant's argument that there is no suggestion to combine the references, the examiner recognizes that obviousness can only be established by combining or modifying the teachings of the prior art to produce the claimed invention where there is some teaching, suggestion, or motivation to do so found either in the references themselves or in the knowledge generally available to one of ordinary skill in the art. See In re Fine, 837 F.2d 1071, 5 USPQ2d 1596 (Fed. Cir. 1988)and In re Jones, 958 F.2d 347, 21 USPQ2d 1941 (Fed. Cir. 1992). I. Applicant argues on page 4 of Remarks: … The Proposed Combinations Would Render the References Inoperable for Their Intended Purposes The Examiner respectfully disagrees. Furthermore, “the prior art’s mere disclosure of more than one alternative does not constitute a teaching away from any of these alternatives because such disclosure does not criticize, discredit, or otherwise discourage the solution claimed….” In re Fulton, 391 F.3d 1195, 1201, 73 USPQ2d 1141, 1146 (Fed. Cir. 2004) J. Applicant argues on page 16 of Remarks: … Dependent Claims 2 and 3 The Examiner respectfully disagrees. Tamar discloses in an obviousness rejection hardware events related data are hardware events counters. (see Tamir col 4, lines 6-17: the hardware event counters utilized by the techniques described herein can never be reset, and are either invisible or ‘read-only’ to the OS software. Second, the dynamic analysis of trusted hardware counters and the tracking of accessed instruction memory addresses over time; (events counters)) K. Applicant argues on page 16 of Remarks: … Dependent Claims 6 and 7 The Examiner respectfully disagrees. Roundy discloses in an obviousness rejection the utilization of threshold information to separate known incidents from false positive alerts. (see Roundy paragraph [0050]: thresholds that can be used to separate known incidents from false positive alert identifications; (jdentfy false positives)) L. Applicant argues on page 17 of Remarks: … Dependent Claims 8 The Examiner respectfully disagrees. Zhu discloses in an obviousness rejection a determination of minimizing the amount of data stored for threshold processing. (see Zhu paragraph [0032]: techniques may reduce (e.g., minimize) an amount of intermediate data stored in store(s) of a database ... ; (minimizing the amount of storage associated with processing for threshold)) M. Applicant argues on page 18 of Remarks: … Dependent Claims 9 and 11 The Examiner respectfully disagrees. Saville in an obviousness rejection discloses a determination of the minimum amount of time a process runs before preemption by the operating system. (see Saville col 4, lines 30-42: The thread can be put to sleep before completing its task by the operating system, typically because some other thread, application, or process preempted execution of the thread. Preemption can occur for a number of reasons—some examples include a priority of the other thread, application, or process can be higher than a priority of the thread, the other thread, application, or process can require resources uses by the thread, the thread may have been scheduled to run for a fixed period of time (e.g., a fixed time slice) and the time has expired.; (process preempted by OS due to time slice expiration)) Claim Rejections - 35 USC § 103 4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claims 1, 5, 10, 12, 13 are rejected under 35 U.S.C. 103 as being unpatentable over Hunt et al. (US PGPUB No. 20210110037) in view of Chang et al. (US PGPUB No. 20170316284) and further in view of Suzuki (Patent No. JP 5496377 B1) and Chen et al. (Patent No. WO 2019153931 A1) and Elango et al. (US PGPUB No. 20230102179) and Ji et al. (US PGPUB No. 20230306114). Regarding Claims 1, 12, 13, Hunt discloses a system for detecting malwares in a resources constrained device and a computer implemented method for detecting malwares in a resources constrained device and a computer program product for detecting malwares in a resources constrained device, the system, computer implemented method, and computer program product, comprising: a) a monitoring module, embedded on the device, for measuring, at a predefined adaptable monitoring period, internal hardware events related data, (see Hunt paragraph [0048]: User event monitor 180 may receive alerts from other components in the malware detection system. These alerts include detection of malicious and/or suspicious code confirmed by the spectral analysis module 132 as well as any quarantine responses from the Quarantine Process 190. The contents of the alerts will be logged, conveyed to a user through an interface, or sent to another system for analysis.; paragraph [0036]: The scans using the modules of data monitoring program may be scheduled to ensure the least trade-off impact on real-time application performance versus detection. In an embodiment, scans by data monitoring program may be performed at Boot-up, during software updates, and daily full scan of memory (e.g., cache, ROM, firmware-Bios, flash memory, SRAM, DRAM).) b) a data memory for storing monitored data, (see Hunt paragraph [0045]: Data Store 150 may act as a repository of all data coming from data monitoring program 110 and data analysis module 120. Data Store 150 may contain results about benign, malicious, or suspicious samples from the other components in the system such as data analysis module 120, malware tracker 170, and model training module 160.) c) a machine learning module for providing a confidence score that each monitored data is a malware; (see Hunt paragraph [0042]: calculations to extract entropy transition and value coefficients features for machine and deep learning models. ... enables the spectral analysis module 132 to ingest the extracted and formatted features and perform the classification and scoring analysis (benign, malicious, suspicious) based on the respective detector class.; paragraph [0044]: Spectral analysis 132 is able to detect code anomalies that may fit signatures of malware in situations where a score based on the attributes and behavior of the code anomaly is above a threshold level for the given malware threat (e.g., suspicious, malicious).) and d) a machine learning module, for receiving the stored monitored data at a predefined transmission rate and process the received data to detect if it corresponds to malware. (see Hunt paragraph [0036]: The scans using the modules of data monitoring program may be scheduled to ensure the least trade-off impact on real-time application performance versus detection. In an embodiment, scans by data monitoring program may be performed at Boot-up, during software updates, and daily full scan of memory (e.g., cache, ROM, firmware-Bios, flash memory, SRAM, DRAM).; (transmissions at a scheduled or pre-defined rate); paragraph [0044]: Spectral analysis 132 is able to detect code anomalies that may fit signatures of malware in situations where a score based on the attributes and behavior of the code anomaly is above a threshold level for the given malware threat (e.g., suspicious, malicious).) Furthermore, Hunt discloses wherein the remote machine learning module is configured to generate a notification for appropriate local action if the received data corresponds to malware (see Hunt paragraph [0048]: User event monitor 180 may receive alerts from other components in the malware detection system.; paragraph [0036]: The scans using the modules of data monitoring program may be scheduled (predefined transmission rate) to ensure the least trade-off impact on real-time application performance versus detection. In an embodiment, scans by data monitoring program may be performed at Boot-up, during software updates, and daily full scan of memory (e.g., cache, ROM, firmware-Bios, flash memory, SRAM, DRAM).; (transmissions at a scheduled or pre-defined rate); paragraph [0044]: Spectral analysis 132 is able to detect code anomalies that may fit signatures of malware in situations where a score based on the attributes and behavior of the code anomaly is above a threshold level for the given malware threat (e.g., suspicious, malicious).) Hunt does not specifically disclose local machine learning module, embedded on the device, and remote machine learning module, embedded on a remote server. However, Chang discloses wherein a local machine learning module, embedded on the device, and a remote machine learning module, embedded on a remote server. (see Chang paragraph [0032]: the machine learning unit 3 may be disposed in the vehicle 9, or may be disposed in a remote server.; paragraph [0043]: providing the detection unit 2 in a vehicle embedded system (local embedded machine learning system) of the vehicle 9, and by providing the machine learning unit 3 in a server that is wirelessly connected to the detection unit 2 (remote embedded machine learning system)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for local machine learning module, embedded on the device, and remote machine learning module, embedded on a remote server as taught by Chang. One of ordinary skill in the art would have been motivated to employ the teachings of Chang for the benefits achieved from the flexibility of a system enabling the processing of data by locally embedded and remotely embedded systems. (see Chang paragraph [0032]; paragraph [0043]) Furthermore, Hunt discloses wherein to raise an alert. (see Hunt paragraph [0048]: User event monitor 180 may receive alerts from other components in the malware detection system.) Hunt does not specifically disclose local machine learning module configured, wherein if the confidence score is higher than a first predefined alert threshold and to locally store monitored data in memory. However, Suzuki discloses wherein the local machine learning module being configured wherein if the confidence score is higher than a first predefined alert threshold and to locally store the monitored data in a memory. (see Suzuki page 2: outputs log data (first log data) to the first area 13 of the memory 12 when the importance of the log data is higher than a predetermined first threshold, (first threshold greater than baseline value, store data memory)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for local machine learning module configured to if the confidence score is higher than a first predefined alert threshold and to locally store monitored data in memory as taught by Suzuku. One of ordinary skill in the art would have been motivated to employ the teachings of Suzuki for the flexibility achieved from a system that enables predetermined threshold parameters to manage data processing states of a processing environment. (see Suzuki page 2) Hunt does not specifically disclose if the confidence score is lower than first predefined alert threshold and higher than a second predefined suspicious threshold, do not store monitored data. However, Chen discloses wherein if the confidence score is lower than the first predefined alert threshold and higher than a second predefined suspicious threshold and do not store the monitored data. (see Chen page 25: the IP data packet is discarded. If the packet loss rate is greater than the second packet loss threshold and is less than the first packet loss threshold, the IP packet is randomly generated. If the random number is not less than the pre-configured packet threshold, the IP packet is discarded.; (packet discarded or not stored due to values of first and second threshold parameters)) Furthermore, Hunt does not specifically disclose local machine learning module configured to send monitored data to remote machine learning module at predefined transmission rate (network communications). However, Chen discloses wherein the local machine learning module being configured to send the monitored data stored in the data memory to the remote machine learning module at the predefined transmission rate. (see Chen pages 13-14: In the embodiment of the present invention, for any TCP data stream, the transmission rate of the TCP data stream may be the transmission rate of the TCP data stream or the receiving rate of the TCP data stream. The rate characterization value of the TCP data stream may be the transmission rate itself of the TCP data stream, for example, may be the reception rate or transmission rate of the TCP data stream. For any TCP data stream, the rate representation value of the TCP data stream may also be the amount of data of the IP data packet belonging to the TCP data stream received or transmitted within a preset duration.; (transmission and reception rate for network connected device stream communications)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for if the confidence score is lower than first predefined alert threshold and higher than a second predefined suspicious threshold, do not store monitored data and local machine learning module configured to send monitored data to remote machine learning module at predefined transmission rate (network communications) as taught by Chen. One of ordinary skill in the art would have been motivated to employ the teachings of Chen for the flexibility of a system that enables network communication utilized a predefined transmission rate. (see Chen pages 13-14) Furthermore, Hunt does specifically disclose local machine learning module implements a first machine learning algorithm and remote machine learning module implements a second machine learning algorithm being different from first machine learning algorithm. However, Elango discloses wherein the local machine learning module implements a first machine learning algorithm and the remote machine learning module implements a second machine learning algorithm being different from the first machine learning algorithm. (see Elango paragraph [0110]: The second machine-learning model may be implemented as a multiple linear regression. Thus, the second machine-learning model is a different machine-learning model type than the first machine-learning model, such that each machine-learning model is specifically tailored and structured to address the data to be provided as input thereto.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for local machine learning module implements a first machine learning algorithm and remote machine learning module implements a second machine learning algorithm being different from first machine learning algorithm as taught by Elango. One of ordinary skill in the art would have been motivated to employ the teachings of Elango for the flexibility of a system that enables multiple processing parameters such as multiple machine learning modes. (see Elango paragraph [0110]) Hunt does not specifically disclose a second malwares detection machine learning algorithm having a detection accuracy higher than the first malwares detection machine learning algorithm. However, Ji discloses wherein a second malwares detection machine learning algorithm having a malwares detection accuracy higher than the first malwares detection machine learning algorithm. (see Ji paragraph [0068]: security platform 122 provides a set of machine learning models to data appliance 102 for data appliance 102 to use in conjunction with inline malware detection. The models incorporate features (e.g., n-grams or other features) determined by security platform 122 as corresponding to malicious files. Two example types of such models include linear classification models and non-linear classification models. Examples of linear classification models that can be used by data appliance 102 include logistic regression and linear support vector machines. An example of a non-linear classification model that can be used by data appliance 102 includes a gradient boosting tree (e.g., eXtreme Gradient Boosting (XGBoost)). The non-linear model is more accurate (and is better able to detect obfuscated/disguised malware), but the linear model uses considerably fewer resources on appliance 102 (and is more suitable for efficiently analyzing JavaScript or similar files).) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for a second malwares detection machine learning algorithm having a detection accuracy higher than the first malwares detection machine learning algorithm as taught by Ji. One of ordinary skill in the art would have been motivated to employ the teachings of Ji for the flexibility of a system that enables more accurate data processing such that a first malwares detection machine learning model to have higher accuracy than a second malwares detection machine learning model. (see Ji paragraph [0068]) Furthermore, Hunt discloses wherein the device comprising a first processor and a first instructions memory having computer executable instructions embodied therewith, the computer executable instructions being executable by the first processor to cause the first processor to perform steps from the monitoring module and the local machine learning module, the remote server comprising a second processor and a second instructions memory having computer executable instructions embodied therewith, the computer executable instructions being executable by the second processor to cause the second processor to perform steps from the remote machine learning module. (see Hunt paragraph [0067]: The computer readable program instructions may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).; (computer executable instruction for monitoring module can operate as a local executable program or as a remote executable program)) Furthermore, for Claim 13, Hunt discloses wherein a computer program product, the computer program product comprising a memory having computer executable instructions embodied therewith, the computer executable instructions being executable by a processor to cause the processor to perform operations. (see Hunt paragraph [0069]: These computer readable program instructions may be provided to a processor of a computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions/acts specified in the flowchart and/or block diagram block or blocks.) Regarding Claim 5, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 1, including the second machine learning algorithm is a time-series machine learning algorithm having a history table for storing a predefined number n of samples, and store the monitored data and at most n consecutive previous monitored data. (see Hunt paragraph [0045]: Data Store 150 may act as a repository of all data coming from data monitoring program 110 and data analysis module 120. Data Store 150 may contain results about benign, malicious, or suspicious samples from the other components in the system such as data analysis module 120, malware tracker 170, and model training module 160. Data store 150 may contain histories of activity of specific programs, specific states of the computing device, or any other relevant activity logs that can be referred to, or used by model training module 160, to improve spectral detector 132.; paragraph [0048]: User event monitor 180 may receive alerts from other components in the malware detection system. These alerts include detection of malicious and/or suspicious code confirmed by the spectral analysis module 132 as well as any quarantine responses from the Quarantine Process 190. The contents of the alerts will be logged, conveyed to a user through an interface, or sent to another system for analysis.; paragraph [0036]: The scans using the modules of data monitoring program may be scheduled to ensure the least trade-off impact on real-time application performance versus detection. In an embodiment, scans by data monitoring program may be performed at Boot-up, during software updates, and daily full scan of memory (e.g., cache, ROM, firmware-Bios, flash memory, SRAM, DRAM).; paragraph [0032]: techniques may reduce (e.g., minimize) an amount of intermediate data stored locally in store(s) of a database ... )) Hunt does not specifically disclose when the confidence score is lower than first predefined alert threshold and higher than second predefined suspicious threshold, store monitored data. However, Chen discloses wherein the local machine learning module is furthermore configured to, when the confidence score is lower than the first predefined alert threshold and higher than the second predefined suspicious threshold, store the monitored data and at most n consecutive previous monitored data having a confidence score lower than the second predefined suspicious threshold. (see Chen page 25: If the second packet loss rate threshold is greater than the first packet loss rate threshold, a random number Y is generated for the IP data packet, and if Y is not less than X, the IP data packet is determined to be discarded, ... , Since 50 (Y) is smaller than the packet loss threshold 60 (X), the IP data packet is not discarded (IP data packet is stored).) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for when the confidence score is lower than first predefined alert threshold and higher than second predefined suspicious threshold, store monitored data as taught by Chen. One of ordinary skill in the art would have been motivated to employ the teachings of Chen for the flexibility of a system that enables multiple machine learning models including local and remote machine learning models to be utilized in the processing of data within a network environment. (see Chen page 25) Regarding Claim 10, Hunt-Chang-Suzuki-Chen-Elango-Jii discloses the system for detecting malwares according to claim 1, comprising a data limiter module configured for scaling monitored data to a normalized range. (see Hunt paragraph [0050]: This captured information will be sent to module 120 for extraction and data normalization. Module 120 will then store the ID tags in the Data Store 150 and send the extracted features to the spectral analysis module 132 for analysis and scoring.; (normalization of captured data, normalization range)) 6. Claims 2, 3 are rejected under 35 U.S.C. 103 as being unpatentable over Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Ji and Tamir et al. (US Patent No. 9,842,209). Regarding Claim 2, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares of claim 1. Hunt does not specifically disclose hardware events related data are hardware events counters. However, Tamir discloses wherein internal hardware events related data are hardware events counters. (see Tamir col 4, lines 6-17: the hardware event counters utilized by the techniques described herein can never be reset, and are either invisible or ‘read-only’ to the OS software. Second, the dynamic analysis of trusted hardware counters and the tracking of accessed instruction memory addresses over time; (events counters)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for hardware events related data are hardware events counters as taught by Tamir. One of ordinary skill in the art would have been motivated to employ the teachings of Tamir for the benefits achieved from a system that enables a more resilient system due to the utilization of hardware event counters. (see Tamir col 4, lines 6-17; col 4, lines 40-43) Regarding Claim 3, Hunt-Chang-Suzuki-Chen-Elanjo-Ji-Tamir discloses the system for detecting malwares of claim 2. Hunt does not specifically disclose dedicated hardware performance counters configured to store hardware events counters and being inaccessible by operating system. However, Tamir discloses wherein furthermore comprising dedicated hardware performance counters configured to store hardware events counters and being inaccessible by the operating system of the device. (see Tamir col 4, lines 6-17: the hardware event counters utilized by the techniques described herein can never be reset, and are either invisible or ‘read-only’ to the OS software (inaccessible to OS). Second, the dynamic analysis of trusted hardware counters and the tracking of accessed instruction memory addresses over time; (invisible, counters inaccessible by OS)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for dedicated hardware performance counters configured to store hardware events counters and being inaccessible by operating system as taught by Tamir. One of ordinary skill in the art would have been motivated to employ the teachings of Tamir for the benefits achieved from a system that enables a more resilient system due to the utilization of hardware event counters. (see Tamir col 4, lines 6-17; col 4, lines 40-43) 7. Claims 6, 7 are rejected under 35 U.S.C. 103 as being unpatentable over Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Ji and Roundy et al. (US PGPUB No. 20170093902). Regarding Claim 6, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 1. Hunt does not specifically disclose first predefined alert threshold is determined in such a way that monitored data for which an alert is raised has a predetermined amount of false positives. However, Roundy discloses wherein the first predefined alert threshold is determined in such a way that the monitored data for which an alert is raised by the local machine learning module includes a predetermined amount of false positives corresponding to normal applications. (see Roundy paragraph [0050]: thresholds that can be used to separate known incidents from false positive alert identifications) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for first predefined alert threshold is determined in such a way that monitored data for which an alert is raised has a predetermined amount of false positives as taught by Roundy. One of ordinary skill in the art would have been motivated to employ the teachings of Roundy for the enhance data processing enabling the system to better distinguish false positives. (see Roundy paragraph [0050]) Regarding Claim 7, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 6. Hunt does not specifically disclose that an amount, equal to said predetermined amount of false positives, of confidence scores corresponding to normal applications are above the first predefined alert threshold. However, Roundy discloses wherein the first predefined alert threshold is determined after the local machine learning module is trained in such a way that an amount, equal to said predetermined amount of false positives, of confidence scores of training data corresponding to normal applications are above the first predefined alert threshold. (see Roundy paragraph [0050]: thresholds that can be used to separate known incidents from false positive alert identifications) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for that an amount, equal to said predetermined amount of false positives, of confidence scores corresponding to normal applications are above the first predefined alert threshold as taught by Roundy. One of ordinary skill in the art would have been motivated to employ the teachings of Roundy for the enhance data processing enabling the system to better distinguish false positives. (see Roundy paragraph [0050]) 8. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Ji and Zhu et al. (US PGPUB No. 20220092067) and Roundy et al. (US PGPUB No. 20170093902). Regarding Claim 8, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 1, wherein data stored that is not malware. (see Hunt paragraph [0042]: calculations to extract entropy transition and value coefficients features for machine and deep learning models. ... enables the spectral analysis module 132 to ingest the extracted and formatted features (non-malware processed data) and perform the classification and scoring analysis (benign, malicious, suspicious) based on the respective detector class.; paragraph [0044]: Spectral analysis 132 is able to detect code anomalies that may fit signatures of malware in situations where a score based on the attributes and behavior of the code anomaly is above a threshold level for the given malware threat (e.g., suspicious, malicious).) Hunt discloses minimize amount of data storage to minimize the amount of data to a predefined amount. However, Zhu discloses wherein the second predefined suspicious threshold is determined in such a way to minimize the amount of monitored data that correspond to a malware, to a predefined amount. (see Zhu paragraph [0032]: techniques may reduce (e.g., minimize) an amount of intermediate data stored in store(s) of a database ... ) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for to minimize the amount of data to a predefined amount as taught by Zhu. One of ordinary skill in the art would have been motivated to employ the teachings of Zhu for the efficient usage of data storage by minimizing the amount of data stored locally. (see Zhu paragraph [0032]) Hunt does not specifically disclose monitored data that has a confidence score higher than the second predefined suspicious threshold. However, Suzuki discloses wherein monitored data that has a confidence score higher than the second predefined suspicious threshold. (see Suzuki page 2: outputs log data (first log data) to the first area 13 of the memory 12 when the importance of the log data is higher than a predetermined first threshold, (first threshold greater than baseline value, store data memory)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for monitored data that has a confidence score higher than the second predefined suspicious threshold as taught by Suzuku. One of ordinary skill in the art would have been motivated to employ the teachings of Suzuki for the flexibility achieved from a system that enables predetermined threshold parameters to manage data processing states of a processing environment. (see Suzuki page 2) Roundy discloses monitored data that does not correspond to malware (see Roundy paragraph [0050]: thresholds that can be used to separate known incidents from false positive alert identifications; (jdentfy false positives)) as stated above. 9. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Ji and Saville, III (US Patent No. 9,507,637). Regarding Claim 9, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 1. Hunt does not specifically disclose each process must run on the device before being preempted by operating system. However, Saville wherein the predetermined monitoring period is equal to at most half a minimum amount of time each process must run on the device before being preempted by the operating system of the device. (see Saville col 4, lines 30-42: The thread can be put to sleep before completing its task by the operating system, typically because some other thread, application, or process preempted execution of the thread. Preemption can occur for a number of reasons—some examples include a priority of the other thread, application, or process can be higher than a priority of the thread, the other thread, application, or process can require resources uses by the thread, the thread may have been scheduled to run for a fixed period of time (e.g., a fixed time slice) and the time has expired.; (process preempted by OS due to time slice expiration)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for each process must run on the device before being preempted by operating system as taught by Saville. One of ordinary skill in the art would have been motivated to employ the teachings of Saville for enhanced process management protocols such as execution time slice expiration when a currently executing process has utilized its execution time slice and a next process is given execution control. (see Saville col 4, lines 30-42) 10. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Hunt in view of Chang and further in view of Suzuki and Chen and Elango and Ji and Kueny (US PGPUB No. 20040185582) and Horie (US PGPUB No. 20100020964). Regarding Claim 11, Hunt-Chang-Suzuki-Chen-Elango-Ji discloses the system for detecting malwares according to claim 10. Hunt does not specifically disclose wherein maximum value of the monitored data, minimum value of the monitored data, calculate scaled data. However, Kueny discloses wherein the data limiter module is configured to: determine integer values a and b such that a is at least equal to the maximum value of the monitored data, b is at most equal to the minimum value of the monitored data and a-b is equal to a power of two, calculate the scaled data. (see Kueny paragraph [0040]: the vertical range of the data, whether calculated or observed, is scaled according to the maximum and minimum values contained within it.; paragraph [0073]: Every spectrum, whether a calculated spectrum or an observed spectrum, is scaled according to the maximum and minimum R.sub.ivalues contained within it.; (minimum value, maximum data, scaled data)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for maximum value of the monitored data, minimum value of the monitored data, calculate scaled data as taught by Kueny. One of ordinary skill in the art would have been motivated to employ the teachings of Kueny for the flexibility of a system that enables the utilization of multiple types of data included within data processing. (see Kueny paragraph [0040]; paragraph [0073]) Hunt does not specifically disclose wherein calculate the data y as y=(x-b).2®°, where x is the monitored data and a-b=2°. However, Horie discloses wherein calculate the data y as y=(x-b).2®°, where x is the monitored data and a-b=2°. (see Horie paragraph [0026]: In the key generation method according to the second aspect of the present invention, said quadratic-hyperbolic function may be given by the following expression: y=(x-b)/(x.sup.2+cx-a),) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Hunt for wherein calculate the data y as y=(x-b).2®°, where x is the monitored data and a-b=2° as taught by Horie. One of ordinary skill in the art would have been motivated to employ the teachings of Horie for the flexibility of a system that enables the processing of monitoring data and the generation of scaled data. (see Horie paragraph [0026]) Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CARLTON JOHNSON whose telephone number is (571)270-1032. The examiner can normally be reached Work: 12-9PM (most days). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CJ/ August 24, 2026 /SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Show 2 earlier events
Jun 25, 2025
Response Filed
Oct 21, 2025
Final Rejection mailed — §103
Jan 20, 2026
Response after Non-Final Action
Feb 12, 2026
Request for Continued Examination
Feb 24, 2026
Response after Non-Final Action
Apr 03, 2026
Non-Final Rejection mailed — §103
Jul 02, 2026
Response Filed
Sep 08, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724718
CRYPTOGRAPHIC COMPUTATIONS FOR MEMORY REGIONS
2y 8m to grant Granted Sep 01, 2026
Patent 12683769
ENCRYPTED SEARCH WITH A PUBLIC KEY
3y 2m to grant Granted Jul 14, 2026
Patent 12666269
METHODS AND SYSTEMS FOR ALLOWING DEVICE TO SEND AND RECEIVE DATA
4y 1m to grant Granted Jun 23, 2026
Patent 12664253
AUTOMATED ONLINE POLICY GENERATION FOR ZERO-TRUST ARCHITECTURES
3y 1m to grant Granted Jun 23, 2026
Patent 12626261
SYSTEM AND METHOD FOR AUTOMATED SCAM DETECTION
1y 0m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
58%
Grant Probability
91%
With Interview (+33.0%)
4y 6m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 364 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month