Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 02/19/2026 has been entered.
Response to Amendment
Examiner has fully considered Applicant’s amendments to the Claims in the arguments filed on 02/19/2026. Claims 1-13 remain pending in the application. Examiner has withdrawn the previous claim objections in view of the amendments. However, additional claim objections and 112(b) rejections arise.
Response to Arguments
Applicant’s arguments filed 02/19/2026, with respect to the rejections of independent claims 1, 7, and 13 and their corresponding dependent claims under 35 USC 103 have been fully considered and are persuasive. Therefore, the rejections have been withdrawn. However, upon further consideration, new grounds of rejection are made in view of the previously applied combination of Haq and Baumard, in further view of newly applied references from Bernholz et al. (US 20220103581 A1), hereinafter Bernholz, and Townsend (Townsend, K. O. (2021, October 6). What’s in a threat group name? an inside look at the intricacies of nation-state attribution. SecurityWeek. https://www.securityweek.com/whats-threat-group-name-inside-look-intricacies-nation-state-attribution/), hereinafter Townsend. Examiner respectfully submits that Bernholz, in combination with the previously applied references, is sufficient to teach the newly added limitations “wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file, wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group, and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack”; “setting the first content identifier to true”; “and responsive to receiving the approval of the email for the second type of content, setting the second content identifier to true”; and “responsive to setting the first content identifier to true and setting the second content identifier to true, delivering the email to the recipient”. Further, Townsend, in combination with Bernholz and the previously applied references, is sufficient to teach the limitation(s) whose previous rejections relied upon teachings from Rostami-Hesarsorkh (RH) “wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack”.
Claim Objections
Claims 1, 7, and 13 are objected to because of the following informalities:
In Claim 1, the limitation “wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group” could be re-written as: “wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group in response to determining the information on the malicious code does not correspond to a known attack group”, or the like, to clarify that the determination that the APT attack corresponds to an unknown attack group is not a contingent limitation
In Claim 1, the limitation “wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file” should read: ““wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file or the information on the file” for clarity and consistency with the antecedent basis of the file or the information on the file
In Claim 1, the limitation “based on a characteristic clustered through malicious code related clustering for the APT attack” could be re-written as: “based on a characteristic clustered through clustering related to the malicious code for the APT attack”, or the like, to clarify whether the malicious code related clustering is intended to refer to the malicious code used in the APT attack
Claims 7 and 13 recite limitations substantially similar to those of Claim 1, and are objected to for the same reasons as Claim 1
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-13 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
In Claim 1, the limitation(s) “wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group, and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack” is unclear because the limitation creates confusion as to whether it is necessary to make the determination that the information on the malicious code used in the APT attack corresponds to an unknown attack group. Multiple additional limitations appear to require the determination that the malicious code information corresponds to an unknown attack group in order to be relevant. However, the recitation of “the list of APT attack information includes at least one of …” appears to indicate that the determination of an unknown attack group’s connection to the APT attack may not be necessary. Thus, this limitation represents a potential contradiction to the previous limitations, and the scope of the claim is unclear. For examination purposes, the limitation will be interpreted to indicate that, based on the determination of whether the information on the malicious code used in the APT corresponds to an unknown attack group, the list of APT attack information includes a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group. This interpretation is in further view of the objection discussed above, suggesting an amendment to the claim to require that the method includes the determination of either a known or unknown attack group rather than merely one or the other (i.e. the suggested change of “if” to “in response to”).
Claims 7 and 13 recite limitations substantially similar to those of Claim 1, and are rejected for the same reasons as Claim 1
Claim 2-6 and 8-12 are also rejected due to their respective dependence on Claims 1 and 7
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 7-9, and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Haq et al. (US 10735458 B1), hereinafter Haq, in view of Baumard (US 20160078365 A1), hereinafter Baumard, Bernholz et al. (US 20220103581 A1), hereinafter Bernholz, and Townsend (Townsend, K. O. (2021, October 6). What’s in a threat group name? an inside look at the intricacies of nation-state attribution. SecurityWeek. https://www.securityweek.com/whats-threat-group-name-inside-look-intricacies-nation-state-attribution/), hereinafter Townsend.
Regarding Claim 1:
Haq teaches a method of processing cyber threat information performed by a processor of a server (Haq – Col. 20, Line 59-63: As described above, based on captured/extracted features the APT detection center 101 using the method 300 may automatically detect APT attacks/objects through the use of previously identified APT object, non-APT objects, and general benign objects; and Col. 9, Line 56-63: As shown, the APT server 107 may include one or more processors 201 and a persistent storage unit 203. The one or more processors 201 and the persistent storage unit 203 are generally used here to refer to any suitable combination of programmable data processing components and data storage that conduct the operations needed to implement the various functions and operations of the APT server 107), the method comprising: receiving, by the processor, a file or information on the file from a user through at least one interface (Haq – Fig. 4A: web interface for a user to input a file to be scanned for APT detection); processing, by the processor, cyber threat information related to the file or the information on the file (Haq – Col. 11, Line 57-61: Referring back to FIG. 3, following receipt, the suspect object is detonated (e.g. processed by virtual execution or other operations to activate the suspect object) at operation 303 to produce raw data describing behavior and characteristics of the suspect object; and Col. 12, Line 29-36: As noted above, detonation of the suspect object at operation 303 produces raw data that describes characteristics and behaviors of the suspect object. For example, the raw data may include details regarding origin of the suspect object stored in metadata, data generated by the suspect object during detonation, data attempted to be accessed by the suspect object (both locally and from remote systems) during detonation, etc.; and Col. 12, Line 61-67 and Col. 13, Line 1-14: After detonation of the suspect object and any dropped objects produced by the suspect object at operation 303, as shown in operation 307, features associated with the suspect and dropped objects may be extracted from the raw data produced at operation 303. In one embodiment, the features characterize the suspect and/or dropped objects. For example, the features may describe behavior of the objects during detonation and/or metadata associated with the objects. … The features provide a comprehensive characterization of an associated object such that a comparison may be performed to determine whether the object is APT malware; and providing, by the processor, the processed cyber threat information to the user through a user interface (Haq – Col. 16, Line 15-30: After flagging the suspect object as APT malware in the APT intelligence database 109, operation 317 may send a warning to the client device 103A (i.e., the original device transmitting the suspect object). The warning informs a user of the client device 103A that the suspect object is APT malware and should be discarded, deleted, or otherwise avoided. In one embodiment, the warning may be a transmission to a component of the web-interface 400. For example, as shown in FIG. 4B, a dialog box 407 of the web-interface 400 may be updated to indicate that the suspect object is APT malware. In other embodiments, other warnings may be transmitted to the client device 103A. For example, email messages, pop-up messages, or other signals may be transmitted between the APT detection center 101 and the client device 103A to represent the warning message), wherein the provided cyber threat information includes [a list of] advanced persistent threat (APT) attack information for an APT attack (Haq – Col. 16, Line 18-20: The warning informs a user of the client device 103A that the suspect object is APT malware).
Haq does not expressly teach a list of [advanced persistent threat (APT) attack information].
However, Baumard teaches and providing the processed cyber threat information to the user through a user interface, wherein the provided cyber threat information includes a list of advanced persistent threat (APT) attack information for an APT attack (Baumard – Paragraph [0062]: The system further includes a communication program 5 (e.g. email application or web browser application) for processing the interactions managed by the operating system 7. When activating the communication program 5 by the other devices 9, a user of the system can display on the display monitor 6, texts, data, signals, pictures or sounds produced by the communication program 5 from data flows delivered by the communication interface 2 and can send to distant communication devices 1, data, signals, texts, pictures or sounds converted by the communication program 5 into data flows that are transmitted by the communication interface 2; and Paragraph [0069]: The display (using the display monitor 6) of scores and results is used when the system and method are used for cybersecurity applications, i.e. when a user or administrator has to watch, audit and/or conduct forensic analysis on a machine or on machine-to-machine interactions; and Paragraph [0070]: This display of the scoring can be integrated to the communication program 5, when the local user is trusted to access such information; or scores can be displayed separately, either on screen 6 or with the use of a secure communication through communication program 4, to a distant display at another location for distant monitoring. An interface in this display is communicating to the user the probabilities of incongruity, hazardous or malevolent behavior, the probability of presence of an Advanced Persistent Threat, and the list, identification and location of all machines, network components, nodes of these network components, where incongruous behaviors, malevolent or hazardous behaviors, or threats have been detected, with all the characteristics of the observed and recorded behaviors).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, further incorporating Baumard to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Baumard’s teaching of a user interface to present the results of processing threat information of a file into Haq’s method for determining APT information in a user-submitted file. This combination would enhance the method by providing a user with any relevant information in detecting and preventing an APT within their network.
The combination of Haq and Baumard does not expressly teach wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file; wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group, and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack.
However, Bernholz teaches wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, (Bernholz – Paragraph [0042]: a threat assessment computer program may receive threat data, such as threat actor and/or threat actor group data, from internal and/or external sources; and Paragraph [0044]: the threat intelligence platform may generate one or more threat actor profiles. In one embodiment, the ingested data may be reviewed, validated, and corroborated to identify malicious cyber activity that appears to be under common control of a single threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc.), wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file (Bernholz – Paragraph [0033]: System 100 may include one or more internal data sources 110 and one or more external data sources 120 that may provide information regarding threat actors and/or threat actor groups. The data may include identities, past attacks, associations, motivations, sponsors, nationalities, and any other information that may be useful in assessing the risk associated with a threat actor or a threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile), wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group (Bernholz – Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc. Threat actor/group profiles may also include salient information germane to the TTPs deployed by the threat actor/group. Industry standard TTP nomenclature may be used), and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack (Bernholz – Paragraph [0049]: Threat Actor Groups may be added to the threat intelligence platform so that data and the TTPs for the threat actor groups may be associated with them. Emerging Threats may not be added to the threat intelligence platform because it is not yet known whether the associated activity is under common control. In embodiments, when Threat Actor Groups are added to the threat intelligence platform, a consistent naming convention may be used).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq and Baumard, further incorporating Bernholz to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bernholz’s analysis of threat information to determine related threat actors and/or threat groups toward more effective system protection into Haq and Baumard’s combined method for determining APT information in a user-submitted file. This additional information enhances the method by gathering and applying important contextual information associated with identified threats useful in bolstering the system’s defense against particular actors, known or unknown.
The combination of Haq, Baumard, and Bernholz does not expressly teach wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack.
However, Townsend teaches wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack (Townsend – P. 2: Researchers will first detect what looks like malicious behavior happening to one of their customers. They may detect other very similar examples with other customers. This becomes a cluster of activity – but it is still basically an idea. As they dig deeper, the idea of a single entity behind the cluster may become more formalized until the reality of specific group activity cannot be denied. At this point, the group must be named so that the idea has shape; and P. 3: If the cluster evolves into a new group, there will be no existing published research that will give the group a name – so, each research team has the right and responsibility to provide a label for the threat activity it has discovered; and P. 5: CrowdStrike has taken a different approach to naming. Its names are both evocative and more informative, comprising first a catchy prefix followed by an animal with a geographic connotation when the actor is believed to be linked to nation-state. It consequently combines marketing potential with geographic information – Fancy Bear, a Russian state actor, is not easily forgotten, nor is its association with CrowdStrike. Panda is China, Bear is Russia, Chollima is North Korea, Kitten is Iran, Buffalo is Vietnam, and so on. Non-state-affiliated suffixes include Spider for criminal gangs and Jackal for hacktivist groups).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, and Bernholz, further incorporating Townsend to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Townsend’s teaching of various naming conventions for newly identified APT groups or actors into Haq, Baumard, and Bernholz’s combined method for determining APT information in a user-submitted file. Townsend establishes conventional techniques for naming newly identified APT groups that include names generated using words derived from clustered characteristics of the APT groups.
Regarding Claim 2:
The combination of Haq, Baumard, Bernholz, and Townsend teaches the method according to claim 1.
Haq further teaches wherein the file included in the list of APT attack information is classified based on an attack group (Haq – Col. 15, Line 1-7: In one embodiment, the APT classifier 213 may utilize statistical and machine learning to determine whether the suspect object is APT malware. Machine learning refers to a process or system that can learn from data, i.e., be trained to distinguish between “good” and “bad”, or in this case, between APT malware objects and non-APT malware objects; and Col. 17, Line 19-22: Although described above in relation to providing a web-interface 400 for directly informing a user of the status of a suspect object (i.e., whether the suspect object is APT malware, non-APT malware, or non-malware); Examiner’s Comment: The classifications of APT malware, non-APT malware, and non-malware are interpreted to represent the claimed “attack group(s)”).
Baumard further teaches the APT attack information list (Baumard – Paragraph [0062]: The system further includes a communication program 5 (e.g. email application or web browser application) for processing the interactions managed by the operating system 7. When activating the communication program 5 by the other devices 9, a user of the system can display on the display monitor 6, texts, data, signals, pictures or sounds produced by the communication program 5 from data flows delivered by the communication interface 2 and can send to distant communication devices 1, data, signals, texts, pictures or sounds converted by the communication program 5 into data flows that are transmitted by the communication interface 2; and Paragraph [0069]: The display (using the display monitor 6) of scores and results is used when the system and method are used for cybersecurity applications, i.e. when a user or administrator has to watch, audit and/or conduct forensic analysis on a machine or on machine-to-machine interactions; and Paragraph [0070]: This display of the scoring can be integrated to the communication program 5, when the local user is trusted to access such information; or scores can be displayed separately, either on screen 6 or with the use of a secure communication through communication program 4, to a distant display at another location for distant monitoring. An interface in this display is communicating to the user the probabilities of incongruity, hazardous or malevolent behavior, the probability of presence of an Advanced Persistent Threat, and the list, identification and location of all machines, network components, nodes of these network components, where incongruous behaviors, malevolent or hazardous behaviors, or threats have been detected, with all the characteristics of the observed and recorded behaviors).
The motivation to combine the arts is the same as that of Claim 1.
Regarding Claim 3:
The combination of Haq, Baumard, Bernholz, and Townsend teaches the method according to claim 1.
Baumard further teaches wherein the provided cyber threat information includes at least one of Al information, representative hash value information, hashtag (#) information, overview information, hash value information, threat type information, a pattern detection name, attack group information, or attack target country information for the file (Baumard – Paragraph [0070]: An interface in this display is communicating to the user the probabilities of incongruity, hazardous or malevolent behavior, the probability of presence of an Advanced Persistent Threat, and the list, identification and location of all machines, network components, nodes of these network components, where incongruous behaviors, malevolent or hazardous behaviors, or threats have been detected, with all the characteristics of the observed and recorded behaviors; Examiner’s Comment: the collection of information that is communicated to the user is interpreted to represent at least the claimed “overview information”).
The motivation to combine the arts is the same as that of Claim 1.
Regarding Claim 7:
Haq teaches an apparatus for processing cyber threat information, the apparatus comprising: a database configured to store cyber threat information (Haq – Col. 9, Line 45-47: As shown in FIGS. 1A-1B, the APT detection center 101 may include an APT server 107, an APT intelligence database 109, and one or more APT analysis systems 111); and a server comprising a processor (Haq – Col. 9, Line 45-47: As shown in FIGS. 1A-1B, the APT detection center 101 may include an APT server 107, an APT intelligence database 109, and one or more APT analysis systems 111; and Col. 9, Line 55-58: FIG. 2A shows a component diagram of the APT server 107 according to one embodiment of the invention. As shown, the APT server 107 may include one or more processors 201 and a persistent storage unit 203), wherein: the server receives a file or information on the file from a user through at least one interface (Haq – Fig. 4A: web interface for a user to input a file to be scanned for APT detection); and the processor: processes cyber threat information related to the file or the information on the file (Haq – Col. 11, Line 57-61: Referring back to FIG. 3, following receipt, the suspect object is detonated (e.g. processed by virtual execution or other operations to activate the suspect object) at operation 303 to produce raw data describing behavior and characteristics of the suspect object; and Col. 12, Line 29-36: As noted above, detonation of the suspect object at operation 303 produces raw data that describes characteristics and behaviors of the suspect object. For example, the raw data may include details regarding origin of the suspect object stored in metadata, data generated by the suspect object during detonation, data attempted to be accessed by the suspect object (both locally and from remote systems) during detonation, etc.; and Col. 12, Line 61-67 and Col. 13, Line 1-14: After detonation of the suspect object and any dropped objects produced by the suspect object at operation 303, as shown in operation 307, features associated with the suspect and dropped objects may be extracted from the raw data produced at operation 303. In one embodiment, the features characterize the suspect and/or dropped objects. For example, the features may describe behavior of the objects during detonation and/or metadata associated with the objects. … The features provide a comprehensive characterization of an associated object such that a comparison may be performed to determine whether the object is APT malware; and provides the processed cyber threat information to the user through a user interface (Haq – Col. 16, Line 15-30: After flagging the suspect object as APT malware in the APT intelligence database 109, operation 317 may send a warning to the client device 103A (i.e., the original device transmitting the suspect object). The warning informs a user of the client device 103A that the suspect object is APT malware and should be discarded, deleted, or otherwise avoided. In one embodiment, the warning may be a transmission to a component of the web-interface 400. For example, as shown in FIG. 4B, a dialog box 407 of the web-interface 400 may be updated to indicate that the suspect object is APT malware. In other embodiments, other warnings may be transmitted to the client device 103A. For example, email messages, pop-up messages, or other signals may be transmitted between the APT detection center 101 and the client device 103A to represent the warning message), the provided cyber threat information including [a list of] advanced persistent threat (APT) attack information for an APT attack (Haq – Col. 16, Line 18-20: The warning informs a user of the client device 103A that the suspect object is APT malware).
Haq does not expressly teach a list of [advanced persistent threat (APT) attack information].
However, Baumard teaches and provides the processed cyber threat information to the user through a user interface, wherein the provided cyber threat information includes a list of advanced persistent threat (APT) attack information for an APT attack (Baumard – Paragraph [0062]: The system further includes a communication program 5 (e.g. email application or web browser application) for processing the interactions managed by the operating system 7. When activating the communication program 5 by the other devices 9, a user of the system can display on the display monitor 6, texts, data, signals, pictures or sounds produced by the communication program 5 from data flows delivered by the communication interface 2 and can send to distant communication devices 1, data, signals, texts, pictures or sounds converted by the communication program 5 into data flows that are transmitted by the communication interface 2; and Paragraph [0069]: The display (using the display monitor 6) of scores and results is used when the system and method are used for cybersecurity applications, i.e. when a user or administrator has to watch, audit and/or conduct forensic analysis on a machine or on machine-to-machine interactions; and Paragraph [0070]: This display of the scoring can be integrated to the communication program 5, when the local user is trusted to access such information; or scores can be displayed separately, either on screen 6 or with the use of a secure communication through communication program 4, to a distant display at another location for distant monitoring. An interface in this display is communicating to the user the probabilities of incongruity, hazardous or malevolent behavior, the probability of presence of an Advanced Persistent Threat, and the list, identification and location of all machines, network components, nodes of these network components, where incongruous behaviors, malevolent or hazardous behaviors, or threats have been detected, with all the characteristics of the observed and recorded behaviors).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, further incorporating Baumard to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Baumard’s teaching of a user interface to present the results of processing threat information of a file into Haq’s system for determining APT information in a user-submitted file. This combination would enhance the method by providing a user with any relevant information in detecting and preventing an APT within their network.
The combination of Haq and Baumard does not expressly teach wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file; wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group, and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack.
However, Bernholz teaches wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, (Bernholz – Paragraph [0042]: a threat assessment computer program may receive threat data, such as threat actor and/or threat actor group data, from internal and/or external sources; and Paragraph [0044]: the threat intelligence platform may generate one or more threat actor profiles. In one embodiment, the ingested data may be reviewed, validated, and corroborated to identify malicious cyber activity that appears to be under common control of a single threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc.), wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file (Bernholz – Paragraph [0033]: System 100 may include one or more internal data sources 110 and one or more external data sources 120 that may provide information regarding threat actors and/or threat actor groups. The data may include identities, past attacks, associations, motivations, sponsors, nationalities, and any other information that may be useful in assessing the risk associated with a threat actor or a threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile), wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group (Bernholz – Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc. Threat actor/group profiles may also include salient information germane to the TTPs deployed by the threat actor/group. Industry standard TTP nomenclature may be used), and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack (Bernholz – Paragraph [0049]: Threat Actor Groups may be added to the threat intelligence platform so that data and the TTPs for the threat actor groups may be associated with them. Emerging Threats may not be added to the threat intelligence platform because it is not yet known whether the associated activity is under common control. In embodiments, when Threat Actor Groups are added to the threat intelligence platform, a consistent naming convention may be used).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq and Baumard, further incorporating Bernholz to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bernholz’s analysis of threat information to determine related threat actors and/or threat groups toward more effective system protection into Haq and Baumard’s combined method for determining APT information in a user-submitted file. This additional information enhances the method by gathering and applying important contextual information associated with identified threats useful in bolstering the system’s defense against particular actors, known or unknown.
The combination of Haq, Baumard, and Bernholz does not expressly teach wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack.
However, Townsend teaches wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack (Townsend – P. 2: Researchers will first detect what looks like malicious behavior happening to one of their customers. They may detect other very similar examples with other customers. This becomes a cluster of activity – but it is still basically an idea. As they dig deeper, the idea of a single entity behind the cluster may become more formalized until the reality of specific group activity cannot be denied. At this point, the group must be named so that the idea has shape; and P. 3: If the cluster evolves into a new group, there will be no existing published research that will give the group a name – so, each research team has the right and responsibility to provide a label for the threat activity it has discovered; and P. 5: CrowdStrike has taken a different approach to naming. Its names are both evocative and more informative, comprising first a catchy prefix followed by an animal with a geographic connotation when the actor is believed to be linked to nation-state. It consequently combines marketing potential with geographic information – Fancy Bear, a Russian state actor, is not easily forgotten, nor is its association with CrowdStrike. Panda is China, Bear is Russia, Chollima is North Korea, Kitten is Iran, Buffalo is Vietnam, and so on. Non-state-affiliated suffixes include Spider for criminal gangs and Jackal for hacktivist groups).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, and Bernholz, further incorporating Townsend to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Townsend’s teaching of various naming conventions for newly identified APT groups or actors into Haq, Baumard, and Bernholz’s combined method for determining APT information in a user-submitted file. Townsend establishes conventional techniques for naming newly identified APT groups that include names generated using words derived from clustered characteristics of the APT groups.
Regarding Claim 8:
Rejection of claim 7 is incorporated. In addition, Claim 8 is an apparatus claim with limitations corresponding to those of method Claim 2. Therefore, Claim 8 is rejected with the same combination and rationale as that of the rejection of Claim 2.
Regarding Claim 9:
Rejection of claim 7 is incorporated. In addition, Claim 9 is an apparatus claim with limitations corresponding to those of method Claim 3. Therefore, claim 9 is rejected with the same combination and rationale as that of the rejection of Claim 3.
Regarding Claim 13:
Haq teaches a non-transitory computer-readable storage medium storing a cyber threat information processing program that comprises computer instructions for (Haq – Col. 3, Line 29-39: Logic (or engine) may be in the form of one or more software modules, such as executable code in the form of an executable application, an application programming interface (API), a subroutine, a function, a procedure, an applet, a servlet, a routine, source code, object code, a shared library/dynamic load library, or one or more instructions. These software modules may be stored in any type of a suitable non-transitory storage medium, or transitory storage medium (e.g., electrical, optical, acoustical or other form of propagated signals such as carrier waves, infrared signals, or digital signals)): receiving a file or information on the file from a user through at least one interface (Haq – Fig. 4A: web interface for a user to input a file to be scanned for APT detection); processing cyber threat information related to the file or the information on the file (Haq – Col. 11, Line 57-61: Referring back to FIG. 3, following receipt, the suspect object is detonated (e.g. processed by virtual execution or other operations to activate the suspect object) at operation 303 to produce raw data describing behavior and characteristics of the suspect object; and Col. 12, Line 29-36: As noted above, detonation of the suspect object at operation 303 produces raw data that describes characteristics and behaviors of the suspect object. For example, the raw data may include details regarding origin of the suspect object stored in metadata, data generated by the suspect object during detonation, data attempted to be accessed by the suspect object (both locally and from remote systems) during detonation, etc.; and Col. 12, Line 61-67 and Col. 13, Line 1-14: After detonation of the suspect object and any dropped objects produced by the suspect object at operation 303, as shown in operation 307, features associated with the suspect and dropped objects may be extracted from the raw data produced at operation 303. In one embodiment, the features characterize the suspect and/or dropped objects. For example, the features may describe behavior of the objects during detonation and/or metadata associated with the objects. … The features provide a comprehensive characterization of an associated object such that a comparison may be performed to determine whether the object is APT malware); and providing the processed cyber threat information to the user through a user interface (Haq – Col. 16, Line 15-30: After flagging the suspect object as APT malware in the APT intelligence database 109, operation 317 may send a warning to the client device 103A (i.e., the original device transmitting the suspect object). The warning informs a user of the client device 103A that the suspect object is APT malware and should be discarded, deleted, or otherwise avoided. In one embodiment, the warning may be a transmission to a component of the web-interface 400. For example, as shown in FIG. 4B, a dialog box 407 of the web-interface 400 may be updated to indicate that the suspect object is APT malware. In other embodiments, other warnings may be transmitted to the client device 103A. For example, email messages, pop-up messages, or other signals may be transmitted between the APT detection center 101 and the client device 103A to represent the warning message), wherein the provided cyber threat information includes [a list of] advanced persistent threat (APT) attack information for an APT attack (Haq – Col. 16, Line 18-20: The warning informs a user of the client device 103A that the suspect object is APT malware).
Haq does not expressly teach a list of [advanced persistent threat (APT) attack information].
However, Baumard teaches and providing the processed cyber threat information to the user through a user interface, wherein the provided cyber threat information includes a list of advanced persistent threat (APT) attack information for an APT attack (Baumard – Paragraph [0062]: The system further includes a communication program 5 (e.g. email application or web browser application) for processing the interactions managed by the operating system 7. When activating the communication program 5 by the other devices 9, a user of the system can display on the display monitor 6, texts, data, signals, pictures or sounds produced by the communication program 5 from data flows delivered by the communication interface 2 and can send to distant communication devices 1, data, signals, texts, pictures or sounds converted by the communication program 5 into data flows that are transmitted by the communication interface 2; and Paragraph [0069]: The display (using the display monitor 6) of scores and results is used when the system and method are used for cybersecurity applications, i.e. when a user or administrator has to watch, audit and/or conduct forensic analysis on a machine or on machine-to-machine interactions; and Paragraph [0070]: This display of the scoring can be integrated to the communication program 5, when the local user is trusted to access such information; or scores can be displayed separately, either on screen 6 or with the use of a secure communication through communication program 4, to a distant display at another location for distant monitoring. An interface in this display is communicating to the user the probabilities of incongruity, hazardous or malevolent behavior, the probability of presence of an Advanced Persistent Threat, and the list, identification and location of all machines, network components, nodes of these network components, where incongruous behaviors, malevolent or hazardous behaviors, or threats have been detected, with all the characteristics of the observed and recorded behaviors).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, further incorporating Baumard to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Baumard’s teaching of a user interface to present the results of processing threat information of a file into Haq’s stored instructions for determining APT information in a user-submitted file. This combination would enhance the method by providing a user with any relevant information in detecting and preventing an APT within their network.
The combination of Haq and Baumard does not expressly teach wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file; wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group, and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack.
However, Bernholz teaches wherein information on a malicious code used in the APT attack is determined to correspond to an unknown attack group if the information on the malicious code is not determined to correspond to a known attack group, (Bernholz – Paragraph [0042]: a threat assessment computer program may receive threat data, such as threat actor and/or threat actor group data, from internal and/or external sources; and Paragraph [0044]: the threat intelligence platform may generate one or more threat actor profiles. In one embodiment, the ingested data may be reviewed, validated, and corroborated to identify malicious cyber activity that appears to be under common control of a single threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc.), wherein the unknown attack group includes an unknown attacker generating an attack action for the APT attack based on the file (Bernholz – Paragraph [0033]: System 100 may include one or more internal data sources 110 and one or more external data sources 120 that may provide information regarding threat actors and/or threat actor groups. The data may include identities, past attacks, associations, motivations, sponsors, nationalities, and any other information that may be useful in assessing the risk associated with a threat actor or a threat actor group; and Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile), wherein the list of APT attack information includes at least one of a list of APT attack information for the known attack group or a list of APT attack information for the unknown attack group (Bernholz – Paragraph [0047]: Where the observed activity aligns to a pre-existing threat actor profile, it may be attributed to the extant threat actor profile. When the observed activity appears to be unique and not otherwise associated with a previously observed actor, the threat intelligence platform may generate a new threat actor/group profile. Threat actor/group profiles may include multiple categories for assessment including, for example, the operational motivation of the actor, the capability and sophistication of the actor, the countries or regions targeted by the actor, the industry sectors targeted by the actor, etc. Threat actor/group profiles may also include salient information germane to the TTPs deployed by the threat actor/group. Industry standard TTP nomenclature may be used), and wherein the list of the APT attack information for the unknown attack group includes the name of the unknown attack group for the APT attack (Bernholz – Paragraph [0049]: Threat Actor Groups may be added to the threat intelligence platform so that data and the TTPs for the threat actor groups may be associated with them. Emerging Threats may not be added to the threat intelligence platform because it is not yet known whether the associated activity is under common control. In embodiments, when Threat Actor Groups are added to the threat intelligence platform, a consistent naming convention may be used).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq and Baumard, further incorporating Bernholz to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bernholz’s analysis of threat information to determine related threat actors and/or threat groups toward more effective system protection into Haq and Baumard’s combined method for determining APT information in a user-submitted file. This additional information enhances the method by gathering and applying important contextual information associated with identified threats useful in bolstering the system’s defense against particular actors, known or unknown.
The combination of Haq, Baumard, and Bernholz does not expressly teach wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack.
However, Townsend teaches wherein a name of the unknown attack group is determined using a combination of at least one word generated based on a characteristic clustered through malicious code related clustering for the APT attack (Townsend – P. 2: Researchers will first detect what looks like malicious behavior happening to one of their customers. They may detect other very similar examples with other customers. This becomes a cluster of activity – but it is still basically an idea. As they dig deeper, the idea of a single entity behind the cluster may become more formalized until the reality of specific group activity cannot be denied. At this point, the group must be named so that the idea has shape; and P. 3: If the cluster evolves into a new group, there will be no existing published research that will give the group a name – so, each research team has the right and responsibility to provide a label for the threat activity it has discovered; and P. 5: CrowdStrike has taken a different approach to naming. Its names are both evocative and more informative, comprising first a catchy prefix followed by an animal with a geographic connotation when the actor is believed to be linked to nation-state. It consequently combines marketing potential with geographic information – Fancy Bear, a Russian state actor, is not easily forgotten, nor is its association with CrowdStrike. Panda is China, Bear is Russia, Chollima is North Korea, Kitten is Iran, Buffalo is Vietnam, and so on. Non-state-affiliated suffixes include Spider for criminal gangs and Jackal for hacktivist groups).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, and Bernholz, further incorporating Townsend to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Townsend’s teaching of various naming conventions for newly identified APT groups or actors into Haq, Baumard, and Bernholz’s combined method for determining APT information in a user-submitted file. Townsend establishes conventional techniques for naming newly identified APT groups that include names generated using words derived from clustered characteristics of the APT groups.
Claim(s) 4 and 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Haq, in view of Baumard, Bernholz, Townsend, and Mahmoud et al. (Mahmoud, M., Mannan, M., & Youssef, A. (2023). APTHunter: Detecting advanced persistent threats in early stages. Digital Threats: Research and Practice, 4(1), 1–31. https://doi.org/10.1145/3559768), hereinafter Mahmoud.
Regarding Claim 4:
The combination of Haq, Baumard, Bernholz, and Townsend teaches the method according to claim 1.
The combination of Haq, Baumard, Bernholz, and Townsend does not expressly teach wherein the provided cyber threat information includes an association graph for the APT attack information.
However, Mahmoud teaches wherein the provided cyber threat information includes an association graph for the APT attack information (Mahmoud – P. 11:2: Provenance data analysis. Provenance data analysis is a promising approach to tackle these APT-specific challenges (e.g., see [44, 51, 52]). System event logs are parsed into a whole system provenance graph that provides the causal dependency between system subjects (e.g., processes) and objects (e.g., files and sockets). Given all of the artifacts of an attack, an analyst may find the root cause by issuing a backward tracing query on the provenance graph [35, 41, 43, 44]; and P. 11:9: When a provenance query triggers an alert, and an event matches in the whole system provenance graph, the resulting alert shows the context of the match. The context is represented by a graph showing the evolution of events between different system entities involved in the attack behavior).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, Bernholz, and Townsend, further incorporating Mahmoud to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Mahmoud’s teaching to present APT attack information in the form of graph highlighting the attack context upon detecting an APT attack into Haq, Baumard, Bernholz, and Townsend’s combined method for determining APT information in a user-submitted file. This combination would enhance the method by providing a user with further contextual information helpful for stopping ongoing attacks and preventing future attacks.
Regarding Claim 10:
Rejection of claim 7 is incorporated. In addition, Claim 10 is an apparatus claim with limitations corresponding to those of method Claim 4. Therefore, Claim 10 is rejected with the same combination and rationale as that of the rejection of Claim 4.
Claim(s) 5 and 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Haq, in view of Baumard, Bernholz, Townsend, and Loman et al. (US 20180039776 A1), hereinafter Loman.
Regarding Claim 5:
The combination of Haq, Baumard, Bernholz, and Townsend teaches the method according to claim 1.
The combination of Haq, Baumard, Bernholz, and Townsend does not expressly teach wherein the provided cyber threat information includes a code information table for the file.
However, Loman teaches wherein the provided cyber threat information includes a code information table for the file (Loman – Paragraph [0197]: As shown in step 1304, the method 1300 may include receiving a report of a possible ROP exploit from the security measure. In general, the ROP report may include any information useful for evaluating the event(s) causing the report. For example, this may include contextual information for the possible ROP exploit such as path information for one or more files associated with the possible ROP exploit and branch information for one or more processes associated with the possible ROP exploit; and Paragraph [0198]: As shown in step 1306, the method 1300 may include normalizing the report to isolate machine-specific variations in the path information and the branch information ... By way of a non-limiting example, FIG. 14 provides an example of branch information in a non-normalized report 1402 and a normalized report 1404; and Figure 14: non-normalized and normalized reports of file behavior indicating a potential attack).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, Bernholz, and Townsend, further incorporating Loman to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Loman’s teaching to observe and report file path information to determine abnormal file activity indicating a potential ATP attack into Haq, Baumard, Bernholz, and Townsend’s combined method for determining APT information in a user-submitted file. This combination would also enhance the method by providing a user with further contextual information helpful for stopping ongoing attacks and preventing future attacks.
Regarding Claim 11:
Rejection of claim 7 is incorporated. In addition, Claim 11 is an apparatus claim with limitations corresponding to those of method Claim 5. Therefore, Claim 11 is rejected with the same combination and rationale as that of the rejection of Claim 5.
Claim(s) 6 and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Haq, in view of Baumard, Bernholz, Townsend, and Oprea et al. (US 10122742 B1), hereinafter Oprea.
Regarding Claim 6:
The combination of Haq, Baumard, Bernholz, and Townsend teaches the method according to claim 1.
The combination of Haq, Baumard, Bernholz, and Townsend does not expressly teach wherein the provided cyber threat information includes a similar information table for the file.
However, Oprea teaches wherein the provided cyber threat information includes a similar information table for the file (Oprea – Col. 3, Line 58-63: Although not explicitly shown in FIG. 1, one or more input-output devices such as keyboards, displays or other types of input-output devices may be used to support one or more user interfaces to the enterprise SOC 102, as well as to support communication between the enterprise SOC 102 and other related systems and devices not explicitly shown; and Col. 5, Line 7-10: The network interface 116 allows the threat detection and remediation system 110 to communicate over the network 106 with the client devices 104, and illustratively comprises one or more conventional transceivers; and Col. 11, Line 1-18: Some embodiments can start with a set of whitelisted or known software modules previously classified as benign or legitimate, and attempt to detect malicious or potentially malicious software modules that impersonate the whitelisted software modules. Filename impersonation, for example, may be successfully used by some attackers to evade detection. For instance, certain advanced persistent threat (APT) campaigns may use filenames of key system processes for evasion, such as svchost.exe, Iexplore.exe, or Wiinzf21.dll. ZeroAccess, a family of rootkits, can overwrite certain functions of system files such as services.exe to load malicious routines. Detecting such malware in isolation is difficult, but may be successfully detected in some embodiments through host data analysis in an enterprise environment where such software modules are significantly different from legitimate software modules that they try to impersonate; and Col. 21, Line 15-22: Table 1300 in FIG. 13 has columns identifying the dataset (Dataset), the filename cluster (Filename), the number of blacklisted modules in the filename cluster (#BL), the number of outliers classified as malicious (#Mal), the number of outliers classified as suspicious or potentially malicious (#Susp), the number of outliers that remain unknown or unclassified (#UK), and the anomalous features for the outliers (Anomalous features); and Figure 13: a table illustrating similar files which have been evaluated as potentially contributing to an APT).
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Haq, Baumard, Bernholz, and Townsend, further incorporating Oprea to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Oprea’s teaching to generate a table of similar files upon detecting outliers according to a collection of features contributing to a weighted threat ranking of the files into Haq, Baumard, Bernholz, and Townsend’s combined method for determining APT information in a user-submitted file. This combination would also enhance the method by providing a more context to detected potential malicious activity along with providing information on files similar to that which was the initial focus of the investigation.
Regarding Claim 12:
Rejection of claim 7 is incorporated. In addition, Claim 12 is an apparatus claim with limitations corresponding to those of method Claim 6. Therefore, Claim 12 is rejected with the same combination and rationale as that of the rejection of Claim 6.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Son et al. (Son, K., Kim, B., & Lee, T. (2020). Cyber-attack group analysis method based on association of cyber-attack information. KSII Transactions on Internet and Information Systems, 14(1). https://doi.org/10.3837/tiis.2020.01.015) teaches various techniques for associating cyber-attacks and related information with particular attackers and groups of attackers
Vanderlee (Vanderlee, K. (2020, December 17). DebUNCing attribution: How Mandiant Tracks Uncategorized Threat Actors | mandiant | google cloud blog. Google. https://cloud.google.com/blog/topics/threat-intelligence/how-mandiant-tracks-uncategorized-threat-actors) teaches identification and naming of unknown or previously uncategorized groups related to APT attacks
Lee et al. (US 20190370395 A1) teaches an apparatus for classifying APT attack groups by extracting features of groups, training a model with the extracted features, and implementing the model to determine a group associated with observed activity
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS JOSEPH DILUZIO whose telephone number is (703)756-1229. The examiner can normally be reached Mon - Fri -- 7:30 AM - 5 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NICHOLAS JOSEPH DILUZIO/Examiner, Art Unit 2498
/YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498