DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 11/13/2025 has been entered.
Response to Amendment / Arguments
Regarding claims rejected under 35 USC 112(b):
Applicant’s amendment is considered to have overcome the applied rejection. Therefore, the rejection has been withdrawn.
Regarding claims rejected under 35 USC 103:
Applicant’s amendment is considered to have overcome the applied rejection. However, upon further consideration, a new ground(s) of rejection is made in view of Scheideler (US 2022/0269949 A1).
Where Applicant argues that “there is no mention in Ulasen that the analysis includes analyzing network traffic produced from execution of the malware in the sandbox,” it is noted that at least [0004] and [0034] of Ulasen concern network packets carrying malicious functionality and dynamic features including operations with a network. Additionally, the newly discovered Scheideler reference includes characteristics such as a malware sample calling a known CNC server in [0062], where characteristics include observed behavior from execution in sandboxes as in [0056].
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 5-11, and 14-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ulasen (US 2023/0205877 A1) in view of Scheideler (US 2022/0269949 A1) and Ouzan (US 11,507,673 B1).
Regarding claim 1, Ulasen discloses: A method for breach and attack simulation, the method comprising: detonating malware within a [test environment] (e.g., threat analysis server 306 in FIG. 3);
Refer to at least [0029]-[0030] of Ulasen with respect to object data collection of a sample using the threat analysis server. The sample is run as an application.
analyzing one or more impacts of the malware based on detonating the malware within the [test environment];
Refer to at least [0029]-[0030] of Ulasen with respect to recording information about the activity of the application during runtime, and obtaining static analysis information. Extracted feature information examples include API call sequences, operations with files, and other such impacts as per [0034] of Ulasen.
generating, based on analyzing the one or more impacts of the malware, an executable malware emulation file;
Refer to at least [0009], [0019], and [0026] of Ulasen with respect to data synthesis for creating synthetic malware objects for testing purposes.
wherein generating the executable malware emulation file includes performing dynamic analysis of the malware as the malware executes in the [test environment],
Refer to at least 310 and 312 in FIG. 3, and [0029] of Ulasen with respect to performing dynamic analysis of the object sample. Dynamic features are extracted.
including analyzing network traffic produced from execution of the malware,
Refer to at least [0034] of Ulasen with respect to operations with a network as part of dynamic features.
performing static analysis of the malware without executing the malware, and
Refer to at least 314 in FIG. 3, [0021], and [0029] of Ulasen with respect to static analysis of the object sample, the static analysis being concerned with what can be known before runtime.
generating, based on the static and dynamic analysis, [an object] that, upon execution, produces [a feature set having features of the static and dynamic analysis feature sets];
Refer to at least [0019] and FIG. 4-5 of Ulasen with respect to creating new malware objects.
Refer to at least [0032]-[0034] of Ulasen with respect to synthesized feature sets comprising mixed static and dynamic features taken from the respective sets.
executing the malware emulation file on an endpoint system featuring [a security system];
Refer to at least [0019] of Ulasen with respect to using the synthetic malware objects to test the detection capabilities of existing computer security systems.
analyzing the performance of the [security system] in response to executing the malware emulation file; and
Refer to at least [0019] of Ulasen with respect to rating the detection capabilities of the existing computer security systems.
Although Ulasen discloses testing and rating security systems with synthetic malware objects, Ulasen does not fully specify: the test environment further comprising a sandbox; the generated object further comprising a binary file; the produced feature set further comprising an execution chain that includes operations used by the malware to gain unauthorized access to systems or exfiltrate data; the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test; analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test. However, Ulasen in view of Scheideler discloses: the test environment further comprising a sandbox;
Refer to at least [0056] of Scheideler with respect to malware sample characteristics including “observed behavior from execution in sandboxes, samples from the field, etc.”
the produced feature set further comprising an execution chain that includes operations used by the malware to gain unauthorized access to systems or exfiltrate data.
Refer to at least [0056]-[0063] and [0080] of Scheideler with respect to “us[ing] ML techniques to create a multitude of malware with similar characteristics as the samples exhibit,” where characteristics include “a sample calling a known CNC server, e.g., clientService.sin_addr.s_addr=inet_addr(“http://431tryme.sharkservers.co.uk/yahooimg/iq20000”).”
The teachings of Ulasen and Scheideler both concern synthetic malware generation for security systems, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen to further implement creating synthetic malware with similar operations (e.g., calling a known CNC server) for at least the purpose of producing more true-to-life malware samples for security testing (i.e., testing actual malware behavior rather than arbitrarily mutated sample code introducing characteristics unrelated to security concerns). It further would have been obvious to utilize a sandbox for the test environment because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art (i.e., dynamic malware analysis using a sandbox).
Ulasen-Scheideler does not specify: the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test; analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test; the generated object further comprising a binary file. However, Ulasen-Scheideler in view of Ouzan discloses: the security systems further comprising an endpoint system featuring an endpoint detection and response (EDR)-under-test;
Refer to at least FIG. 1 of Ouzan concerning endpoints 1-N having respective agents.
analyzing the performance of the security system further comprising analyzing the performance of the EDR-under-test; reporting one or more test results based on analyzing the performance of the EDR-under-test;
Refer to at least 132-148 in FIG. 2, Col. 2, Ll. 66-Col. 3, Ll. 5, and Col. 9, Ll. 26-65 of Ouzan with respect to “a cyber-attack emulation system compris[ing] multiple software agents ‘agents’) and a backend subsystem (‘backend’). The agents are deployed in endpoints such as workstations and servers of the target system, and are configured to apply emulated cyber-attacks specified by the backend, assess results of the attacks, and report back to the backend.” Additionally, a final report is prepared for a user.
the generated object further comprising a binary file.
Refer to at least Col. 6, Ll. 28-41 of Ouzan with respect to generated attack code comprising a binary file. The attack code is generated from code snippets associated with malware.
The teachings of Ouzan likewise concern malware emulation for testing security systems, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen-Scheideler to further implement a cyber-attack emulation system and testing as in Ouzan for at least the reasons discussed in Col 2, Ll. 55-66 of Ouzan (i.e., testing customer systems; “[s]uch an iterative, adaptive process is highly effective in predicting the true performance of the target system's security controls against unknown real-world cyber threats”). It further would have been obvious to generate an attack code binary file for malware objects because the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., the cited portion of Ouzan specifies substitution any suitable format).
Regarding claim 5, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein the execution chain includes leveraging at least one instance of process injection technique.
Refer to at least [0070]-[0074] of Scheideler with respect to leveraging injection techniques.
The claim would have been obvious because the substitution of one known element for another (attack features—e.g., [0034] of Ulasen) would have yielded predictable results to one of ordinary skill in the art at the time (i.e., additional features to synthesize with; improved testing because of breadth of samples).
Regarding claim 6, it is rejected for substantially the same reasons as claims 1 and 3 above (i.e., the citations and obviousness rationale; [0056] of Scheideler).
Regarding claim 7, it is rejected for substantially the same reasons as claim 1 above (e.g., Col. 6, Ll. 28-41 of Ouzan).
Regarding claim 8, it is rejected for substantially the same reasons as claims 1 and 2 above (i.e., the citations—e.g., 312 and 314 in FIG. 3 of Ulasen).
Regarding claim 9, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein reporting one or more test results based on analyzing the performance of the EDR-under-test comprises reporting a success or a failure of the EDR-under-test to detect and/or respond to the malware.
Refer to at least Col. 10, Ll. 65-Col. 11, Ll. 24 of Ouzan with respect to reporting attack success / failure by the respective endpoint and agent.
This claim would have been obvious for substantially the same reasons as claim 1 above.
Regarding claim 10, Ulasen-Scheideler-Ouzan discloses: The method of claim 1, wherein executing the executable malware emulation file on an endpoint system executing an endpoint detection and response (EDR)-under-test comprises executing the executable malware emulation file on a virtual machine configured for a target test network.
Refer to at least Col. 4, Ll. 45-55 of Ouzan with respect to the endpoints and servers comprising virtual machines.
This claim would have been obvious for substantially the same reasons as claim 1 above.
Regarding independent claim 11, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations and obviousness rationale).
Regarding claims 14-20, they are substantially similar to elements of claims 1 and 5-10 above, and are therefore likewise rejected.
Claim(s) 3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Ulasen-Scheideler-Ouzan as applied to claims 1, 5-11, and 14-20 above, and further in view of Pruzinec (“KUBO: A Framework for Automated Efficacy Testing of Anti-virus Behavioral Detection with Procedure-Based Malware Emulation”).
Regarding claim 3, Ulasen-Scheideler-Ouzan does not fully specify: wherein generating the executable malware emulation file comprises generating the executable malware emulation file such that, upon execution, the executable malware emulation file causes a plurality of steps of a kill chain for the malware. However, Ulasen-Scheideler-Ouzan in view of Pruzinec discloses: wherein generating the executable malware emulation file comprises generating the executable malware emulation file such that, upon execution, the executable malware emulation file causes a plurality of steps of a kill chain for the malware.
Refer to at least [0034] of Ulasen with respect to synthesizing malware objects with features such as API call sequences and operations with files.
Refer to at least section 2.3 of Pruzinec with respect to threat emulation having linked attack procedures under a correct context; section 3.2.3 of Pruzinec with respect to coordination data about the attack chain as context.
The teachings of Pruzinec likewise concern malware emulation for testing security systems, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Ulasen-Scheideler-Ouzan to further implement attack chain context for at least the reasons discussed in 2.3 of Pruzinec (i.e., incoherently emulated attacks reduce the overall usefulness of testing).
Regarding claim 13, it is substantially similar to claim 3 above, and is therefore likewise rejected.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432
/V.S/ Examiner, Art Unit 2432