Prosecution Insights
Last updated: August 17, 2026
Application No. 18/115,704

DETECTING MALICIOUS SOFTWARE AND RECOVERING A STORAGE SYSTEM

Non-Final OA §102§103§112
Filed
Feb 28, 2023
Priority
Feb 28, 2022 — provisional 63/314,987 +3 more
Examiner
POPHAM, JEFFREY D
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
NVIDIA Corporation
OA Round
3 (Non-Final)
38%
Grant Probability
At Risk
3-4
OA Rounds
1y 1m
Est. Remaining
62%
With Interview

Examiner Intelligence

Grants only 38% of cases
38%
Career Allowance Rate
177 granted / 471 resolved
-20.4% vs TC avg
Strong +24% interview lift
Without
With
+24.2%
Interview Lift
resolved cases with interview
Typical timeline
4y 7m
Avg Prosecution
25 currently pending
Career history
504
Total Applications
across all art units

Statute-Specific Performance

§101
14.7%
-25.3% vs TC avg
§103
47.4%
+7.4% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
21.2%
-18.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 471 resolved cases

Office Action

§102 §103 §112
Remarks Claims 1-20 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 5/11/2026 has been entered. Response to Arguments Applicant's arguments filed 5/11/2026 have been fully considered but they are not persuasive. With respect to Applicant’s “First” argument regarding Malkov, to the contrary, Malkov discloses overwriting, such as file modifications, encryption, registry changes, etc., as examples, as well as backup, restore, protect backup, replicate, copy, etc., as examples. Malkov deals with virtual instances, virtual machines, virtual disks, and the like, and it is noted that all of the overwriting discussed above may be performed on virtual volumes, such as in the above virtual machines, on the virtual disks, or the like. Therefore, Malkov discloses performing storage operations to fulfill the storage service requests, the storage operations overwriting at least some old data stored in virtual volumes of the plurality of servers with new data as a replacement in the virtual volumes according to the storage service requests, while maintaining the old data in physical storage devices, external to the plurality of SPUs, of the plurality of servers, wherein the virtual volumes are associated with memory within the plurality of SPUs that is distinct from the physical storage devices. With respect to Applicant’s “Second” argument, the claims still include intended use, such as “to analyze the information to detect an indicator of malware activity associated with the virtual volumes”. This is merely exemplary. Applicant’s allegations regarding Bhave are moot as Applicant is only arguing Bhave for subject matter that Bhave is not cited for. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 11-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 11 includes a limitation reading “determining one or more storage service requests indicate old data stored in virtual volumes is to be replaced by new data”. However, the application as originally filed does not appear to contain basis for this determining. Claims 12-20 are rejected at least based on their dependencies. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-7, 10-16, 19, and 20 are rejected under 35 U.S.C. 102(a)(1) and/or 102(a)(2) as being anticipated by Malkov (U.S. Patent Application Publication 2020/0159624). Regarding Claim 1, Malkov discloses a process for operating a storage system including a plurality of servers containing a plurality of SPUs, the process comprising: Receiving a series of storage service requests from a client (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 102, 106-113, 116, 117, 119, 133, 152, and associated figures; backup, copy, store, write, read, execute, log, etc., as examples); Performing storage operations to fulfill the storage service requests, the storage operations overwriting at least some old data stored in virtual volumes of the plurality of servers with new data as a replacement in the virtual volumes according to the storage service requests, while maintaining the old data in physical storage devices, external to the plurality of SPUs, of the plurality of servers, wherein the virtual volumes are associated with memory within the plurality of SPUs that is distinct from the physical storage devices (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures; overwriting, such as file modifications, encryption, registry changes, etc., as examples, as well as backup, restore, protect backup, replicate, copy, etc., as examples. Malkov deals with virtual instances, virtual machines, virtual disks, and the like (e.g., paragraphs 47-51, 86, etc.), and it is noted that all of the overwriting discussed above may be performed on virtual volumes, such as in the above virtual machines, on the virtual disks, or the like); and Reporting information on the storage operations to a cloud based service (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures; information being given to the AI, machine learning, anomaly detection, action, etc., portions of Malkov, for example, determining if anomalous, malware, faithful, etc., as examples), Wherein the cloud based service is to analyze the information to detect an indicator of malware activity associated with the virtual volumes, wherein the old data from the physical storage devices is available to be restored to perform subsequent storage service requests (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures; information being analyzed by the AI, machine learning, anomaly detection, action, etc., portions of Malkov, for example, determining if anomalous, malware, faithful, etc., as examples). Regarding Claim 2, Malkov discloses in response to detecting the indicator of malware activity, the cloud based service instructing the plurality of SPUs to maintain snapshots of the old data in a state before the indicator occurred (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures; backup, restore, protect backup, replicate, copy, etc., as examples). Regarding Claim 3, Malkov discloses training a model using past information on the storage operations (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures; training, creating baselines, monitoring continuously and updating machine learning/AI continuously, etc., as examples); and The cloud based service detecting the indicator of malware activity based on a difference between the model and the information reported by the plurality of SPUs (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures; comparing baseline to current, detecting anomalies based on trained data and current data, etc., as examples). Regarding Claim 4, Malkov discloses analyzing blocks of data written by performance of the storage operations, the information reported to the cloud based service indicating results from the plurality of SPUs analyzing the blocks of data (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures; any analysis, such as logging performance of the functions, logging requests, traffic logging, indicating backups that occurred, restores that occurred, etc., as examples). Regarding Claim 5, Malkov discloses a storage system comprising: One or more storage nodes, each storage node including (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 102, 106-113, 116, 117, 119, 133, 152, and associated figures; any device, virtual machine, service, etc., that includes the below, for example): A server (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 102, 106-113, 116, 117, 119, 133, 152, and associated figures; server, service software/hardware, VM etc., for example); A storage device (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 102, 106-113, 116, 117, 119, 133, 152, and associated figures); and A plurality of SPUs connected to the storage device being external to the plurality of SPUs, the plurality of SPUs operating the storage device to physically store data of one or more virtual volumes and providing storage services to clients using the data of the one or more virtual volumes, wherein the storage services overwrite of at least some old data stored in the one or more virtual volumes with new data as a replacement in the virtual volumes according to requests from the client, while maintaining the old data in the storage device, wherein the virtual volumes are associated with memory within the plurality of SPUs that is distinct from the storage device (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures); and A cloud based infrastructure in communication with the plurality of SPUs, the cloud based infrastructure being configured to analyze information that the plurality of SPUs provide about the one or more virtual volumes and based on the analysis of information, to direct the plurality of SPUs to maintain snapshots in the old data within the storage device that permit recovery of data after a ransomware attack (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures; as above, with virtual volumes, such as VMs, backups, snapshots, etc., for example). Regarding Claim 6, Malkov discloses that the information that the plurality of SPUs provides indicate patterns of storage operations targeting the one or more virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-120, 128-165, 170-173, and associated figures; patterns in data, for example). Regarding Claim 7, Malkov discloses that the information that the plurality of SPUs provides include test results from analysis of data blocks written to the one or more virtual volumes by the plurality of SPUs (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-120, 128-165, 170-173, and associated figures; instance firewall logs, machine learning portion which can be on a service processing unit, which analyzes data and then provides the information to the next level (e.g., action), etc., as examples). Regarding Claim 10, Malkov discloses that the analysis of the information includes detecting an anomaly by comparing the information to a model that results from a machine learning process trained using past information associated with the one or more virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures). Regarding Claim 11, Malkov discloses a computer-implemented method comprising: Determining one or more storage service requests indicate old data stored in virtual volumes is to be replaced by new data (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures; determining overwriting, such as file modifications, encryption, registry changes, etc., as examples); Overwriting the old data stored in virtual volumes with the new data as a replacement in the virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures; overwriting, such as file modifications, encryption, registry changes, etc., as examples); Maintaining, at least upon performance of the overwriting, the old data in physical storage devices external to a plurality of storage processing units (SPUs) including memory associated with the virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures; backup, restore, protect backup, replicate, copy, etc., as examples); and Reporting information associated with the virtual volumes to a cloud-based service able to detect, using the information, an indicator of malware activity associated with the virtual volumes, the old data in the physical storage devices being available to be restored for performing subsequent storage service requests (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures; information being given to the AI, machine learning, anomaly detection, action, etc., portions of Malkov, for example, determining if anomalous, malware, faithful, etc., as examples). Regarding Claim 12, Malkov disclose that the plurality of SPUs at least partially operate the physical storage devices (Exemplary Citations: for example, Abstract, Paragraphs 4, 5, 9, 12, 13, 15, 90, 95, 100-102, 104-119, 121, 128-134, 152-165, 170-173, and associated figures). Regarding Claim 13, Malkov discloses that the information is reported to the cloud-based service from the plurality of SPUs (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures). Regarding Claim 14, Malkov discloses that the plurality of SPUs and the physical storage devices are contained within a plurality of respective servers (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 102, 106-113, 116, 117, 119, 133, 152, and associated figures). Regarding Claim 15, Malkov discloses the information indicate patterns of storage operations targeting the one or more virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-120, 128-165, 170-173, and associated figures). Regarding Claim 16, Malkov discloses that the information include results of tests, by the plurality of SPUs, on data blocks written to the one or more virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-120, 128-165, 170-173, and associated figures). Regarding Claim 19, Malkov discloses training a model using past information associated with the virtual volumes (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures); and Detecting, using the cloud-based service, the indicator based on a difference between the model and the information (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-165, 170-173, and associated figures). Regarding Claim 20, Malkov discloses responsive to detection of the indicator, instructing, using the cloud-based service, the plurality of SPUs to maintain snapshots of the old data in a state before the malware activity occurred (Exemplary Citations: for example, Abstract, Paragraphs 9, 12, 13, 90, 95, 100-102, 104-119, 128-134, 152-165, 170-173, and associated figures). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 8, 9, 17, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Malkov in view of Bhave (U.S. Patent Application Publication 2018/0307839). Regarding Claim 8, Malkov discloses that ransomware detection includes determining compressibility, entropy, or encryption of the data blocks (Exemplary Citations: for example, Paragraphs 15, 158, 165, and associated figures; ransomware encrypts data and mass encryption is detected, for example); But may not explicitly disclose that the test results indicate such. Bhave, however, discloses that the test results indicate one or more of compressibility, entropy, or encryption of the data blocks (Exemplary Citations: for example, Abstract, Paragraphs 18, 26, 38-45, 48-51, 54-57, 59, and associated figures; generate entropy scores to determine if ransomware is present, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the ransomware detection techniques of Bhave into the data protection system of Malkov in order to provide additional techniques by which malware may be detected, to detect ransomware that is random or encrypted or compressed, to provide an efficient approach of detecting ransomware and resolving damages due to the ransomware, and/or to increase security in the system. Regarding Claim 9, Malkov does not appear to explicitly disclose that the information represents a histogram of the test results. Bhave, however, discloses that the information represents a histogram of the test results (Exemplary Citations: for example, Abstract, Paragraphs 18, 26, 38-45, 48-51, 54-57, 59, and associated figures; histogram, for example). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the ransomware detection techniques of Bhave into the data protection system of Malkov in order to provide additional techniques by which malware may be detected, to detect ransomware that is random or encrypted or compressed, to provide an efficient approach of detecting ransomware and resolving damages due to the ransomware, and/or to increase security in the system. Regarding Claim 17, Malkov discloses that ransomware detection includes determining compressibility, entropy, or encryption of the data blocks (Exemplary Citations: for example, Paragraphs 15, 158, 165, and associated figures; ransomware encrypts data and mass encryption is detected, for example); But may not explicitly disclose that the test results indicate such. Bhave, however, discloses that the test results indicate one or more of compressibility, entropy, or encryption of the data blocks (Exemplary Citations: for example, Abstract, Paragraphs 18, 26, 38-45, 48-51, 54-57, 59, and associated figures). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the ransomware detection techniques of Bhave into the data protection system of Malkov in order to provide additional techniques by which malware may be detected, to detect ransomware that is random or encrypted or compressed, to provide an efficient approach of detecting ransomware and resolving damages due to the ransomware, and/or to increase security in the system. Regarding Claim 18, Malkov does not appear to explicitly disclose that the information represents a histogram of the test results. Bhave, however, discloses that the information represents a histogram of the test results (Exemplary Citations: for example, Abstract, Paragraphs 18, 26, 38-45, 48-51, 54-57, 59, and associated figures). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the ransomware detection techniques of Bhave into the data protection system of Malkov in order to provide additional techniques by which malware may be detected, to detect ransomware that is random or encrypted or compressed, to provide an efficient approach of detecting ransomware and resolving damages due to the ransomware, and/or to increase security in the system. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jeffrey D Popham whose telephone number is (571)272-7215. The examiner can normally be reached Monday through Friday 9:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey D. Popham/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 5 earlier events
Mar 11, 2025
Applicant Interview (Telephonic)
Mar 17, 2025
Response after Non-Final Action
Mar 17, 2025
Response Filed
Jul 11, 2025
Response Filed
Feb 05, 2026
Final Rejection mailed — §102, §103, §112
May 11, 2026
Request for Continued Examination
May 21, 2026
Response after Non-Final Action
Jun 16, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12671985
ACCESS AND MOBILITY MANAGEMENT FUNCTION RELOCATION DUE TO SECURITY GATEWAY OVERLOAD/FAILURE
3y 10m to grant Granted Jun 30, 2026
Patent 12481750
A METHOD OF PROCESSING TRANSACTIONS FROM AN UNTRUSTED SOURCE
5y 2m to grant Granted Nov 25, 2025
Patent 12425407
Identity And Access Management Using A Decentralized Gateway Computing System
2y 10m to grant Granted Sep 23, 2025
Patent 12380240
PROTECTING SENSITIVE DATA IN DOCUMENTS
4y 10m to grant Granted Aug 05, 2025
Patent 12326934
DETECTING SUSPICIOUS ACTIVATION OF AN APPLICATION IN A COMPUTER DEVICE
4y 5m to grant Granted Jun 10, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
38%
Grant Probability
62%
With Interview (+24.2%)
4y 7m (~1y 1m remaining)
Median Time to Grant
High
PTA Risk
Based on 471 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month