Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. Claims 1-24 have been examined.
Response to Arguments
2. Applicant’s arguments, filed 09/25/2025, with respect to the rejection(s) of claim(s) 1, 9 and 17 under 35 USC 102 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Orhan (U.S. Patent 10,607,011).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
3. Claims 8, 16 and 24 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 8, 16 and 24 recites the limitation "the plurality of types of logs". There is insufficient antecedent basis for this limitation in the claim.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
4. Claims 1-24 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 2A Prong One
Claims 1-24 recite an apparatus, method and computer readable medium of attack information generation. Claim 1 comprises the steps of “determine…the number of occurrences of one or more events” and “determine… whether or not the number of occurrences of that event…satisfies a predetermined condition”; which under its broadest, reasonable interpretation covers a “mental process” that “can be performed in the human mind, or by a human using a pen and paper” (note MPEP 2106.04(a)(2)III). For example, a human can look at logs of events and see which ones occur in most or all of the logs.
Other than reciting, “by a computer”, nothing in the claim elements precludes the steps from being performed in the mind. The claimed invention is described as a concept that is performed in the human mind and applicant is merely claiming that concept performed 1) on a generic computer, or 2) in a computer environment, or 3) is merely using a computer as a tool to perform the concept. Thus, the claim is considered to recite a mental process (note MPEP 2106.04(a)(2)III.C.).
Step 2A Prong Two
Claims 1-24 recite the additional element of “generate attack information associating the target attack with the event”. This is extra-solution activity to the judicial exception (e.g. writing down or outputting the results of the determining step) and does not integrate the abstract idea into a practical application. Claims 1, 9 and 17 recite additional elements of “memory”, “at least one processor”, “a computer” and a “computer readable medium”. This judicial exception is not integrated into a practical application because the additional elements (e.g. processor, memory…) are generic computer components. The use of a generic computer component does not integrate the abstract idea into a practical application because merely reciting the words "apply it" (or an equivalent) with the judicial exception, or merely including instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea, as discussed in MPEP § 2106.05(f) have been identified by the courts as not integrating a judicial exception into a practical application.
Step 2B
Claims 1-24 do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the extra-solution activities and generic computer components being used to perform mental processes are not sufficient to amount to significantly more than the judicial exception. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The additional elements of a generic computer extracting data and sending an alert is well-understood, routine and conventional. There are no additional steps in claims 1-24 which integrate the exception into a practical application by improving the functioning of the computer or implementing the judicial exception with a particular machine. Therefore, claims 1-24 are not patent eligible.
5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
6. Claims 1-2, 4, 9-10, 12, 17-18 and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Orhan (U.S. Patent 10,607,011; hereafter “Orhan”).
For claims 1, 9 and 17, Orhan teaches an attack information generation apparatus, method and computer readable medium comprising:
at least one memory storing instructions (note column 8,lines 4-16, memory stores instructions); and
at least one processor that is configured to execute the instructions (note column 8,lines 4-16, processor executions instructions) to:
determine, for each of a plurality of executions of a target attack, the number of occurrences of one or more events by using a log recorded in an execution period of the target attack (note column 4, lines 18-20, malware applications are run several times and the activity occurrences are collected for each run; column 4, lines 28-31, after multiple runs of each sample are collected, outputs are aggregated and common items are extracted);
determine, for each of the events, whether or not the number of occurrences of that event determined for each of the plurality of executions of the target attack satisfies a predetermined condition (note column 4, line 41 – column 5, line 3, threshold for acceptance of an event to be included in aggregation is determined; e.g. event is determined to be added to the attack profile if it is in 50% of the total number of runs); and
generate attack information associating the target attack with the event whose number of occurrences is determined to satisfy the predetermined condition (note column 5, lines 3-6, an attack profile of the aggregated, common events is generated is considered the signature for the malware family).
For claims 2, 10 and 18, Orhan teaches claims 1, 9 and 17, wherein the predetermined condition is a condition that a statistical value of the numbers of occurrences of the event determined for each of the plurality of executions of the target attack is equal to or larger than a threshold (note column 4, line 41 – column 5, line 3, threshold for acceptance of an event to be included in aggregation is determined; e.g. event is determined to be added to the attack profile if it is in 50% of the total number of runs).
For claims 4, 12 and 20, Orhan teaches claims 1, 9 and 17,
wherein the at least one processor is further configured to:
determine, among a plurality of entries recorded in the execution period of the target attack in the log, entries that have values matching each other or similar to each other in at least one predetermined item as entries representing the same event (note column 4, line 41 – column 5, line 3 and Fig. 3A, determination includes an acceptable time delay threshold; i.e. entries that are similar to each other in time); and
determine, for each of the events, the number of occurrences of that event based on the number of the entries determined as those representing that event (note column 4, line 41 – column 5, line 3 and Fig. 3A, an occurrence count is determined as part of the aggregation).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7. Claims 3, 11 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Orhan as applied to claims 1, 9 and 17 above, and further in view of Herwono et al. (U.S. Patent Application Publication 2022/0092177; hereafter “Herwono”).
For claims 3, 11 and 19, Orhan differs from the claimed invention in that they fail to explicitly teach:
wherein the at least one processor is further configured to:
define the number of occurrences of the event for which there is a corresponding entry in the log in the execution period of the target attack as one; and
define the number of occurrences of the event for which there is no corresponding entry in the log in the execution period of the target attack as zero.
Herwono teaches:
wherein the at least one processor is further configured to:
define the number of occurrences of the event for which there is a corresponding entry in the log in the execution period of the target attack as one (note paragraph [0090], the occurrence of an attribute in an event log is assigned a binary value of “1” or “0”); and
define the number of occurrences of the event for which there is no corresponding entry in the log in the execution period of the target attack as zero (note paragraph [0090], the occurrence of an attribute in an event log is assigned a binary value of “1” or “0”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the attack profile generation of Orhan and the use of a binary values to determine the occurrence of events of Herwono. It would have been obvious because combining prior art elements according to known methods would yield the predictable results of generating an attack profile for malware by aggregating events from activity logs (Orhan) where the occurrence of the event is defined by either a binary value of 1 or 0 (Herwono).
8. Claims 5-6, 8, 13-14, 16, 21-22 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Orhan as applied to claims 1, 9 and 17 above, and further in view of Ijiro et al. (U.S. Patent Application Publication 2020/0342095; hereafter “Ijiro”).
For claims 5, 13 and 21. Orhan teaches claims 1, 9 and 17, wherein the at least one processor is further configured to:
determine a length of the execution period of the target attack (note column 5, lines 36-37, target applications are fun for a predetermined period of time);
Orhan differs from the claimed invention in that they fail to teach:
and include this length of the execution period in the attack information.
Ijiro teaches:
and include this length of the execution period in the attack information (note paragraphs [0254]-[0255], detection rule includes a representative value of the attack duration).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the attack profile generation of Orhan and the detection rule including attack duration information of Ijiro. It would have been obvious because combining prior art elements according to known methods would yield the predictable results of generating an attack profile for malware by aggregating events from activity logs (Orhan) where the attack profile includes duration information (Ijiro).
For claims 6, 14 and 22, the combination of Orhan and Ijiro teaches claims 5, 13 and 21, wherein the length of the execution period of the target attack included in the attack information is a statistical value of lengths of execution periods of the target attack that has been carried out a plurality of times (note paragraphs [0248] and [0255] of Ijiro, representative value of attack duration in detection rule may be an average duration of the plurality of attack durations).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the attack profile generation of Orhan and the detection rule including attack duration information of Ijiro. It would have been obvious because combining prior art elements according to known methods would yield the predictable results of generating an attack profile for malware by aggregating events from activity logs (Orhan) where the attack profile includes duration information (Ijiro).
For claims 8, 16 and 24, the combination of Orhan and Ijiro teaches claims 1, 9 and 17, wherein the at least one processor is further configured to:
determine the number of occurrences of each of the events for each of the plurality of types of logs (note paragraphs [0095]-[0097], [0122]-[0125] and [0149]-[0150] of Ijiro, log type is determined; groups of generated from log types; number of pieces of log information is counted in each log group); and
include, in the attack information, the type of log from which an entry indicating the event has been extracted (note paragraphs [0264] of Ijiro, detection rule includes log type information).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the attack profile generation of Orhan and the detection rule including log type information of Ijiro. It would have been obvious because combining prior art elements according to known methods would yield the predictable results of generating an attack profile for malware by aggregating events from activity logs (Orhan) where the activity logs are identified by a plurality of log types and attack profile includes log type information (Ijiro).
9. Claims 7, 15 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Orhan as applied to claims 1, 9 and 17 above, and further in view of Rafique et al. (“FIRMA: Malware Clustering and Network Signature Generation with Mixed Network Behaviors”; hereafter “Rafique”).
For claims 7, 15 and 23, Orhan teaches a plurality of test environments (note column 5, lines 34-36, several virtual machines and/or sandboxes), but fails to explicitly teach:
wherein at least two of the plurality of executions of the target attack are carried out in test environments different from each other.
Rafique teaches:
wherein at least two of the plurality of executions of the target attack are carried out in test environments different from each other (note page 149, 3 Malware Execution, the same binary is run multiple times with different configurations).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the attack profile generation of Orhan and the use of different test environment configurations of Rafique. One of ordinary skill would have been motivated to combine Orhan and Rafique because it would improve the effectiveness of the profile generation because it may be necessary to run malware with different test environment configurations in order for it to produce an output (note page 149, 3 Malware Execution of Rafique).
Conclusion
10. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
El-Ghali et al. (“Intrusion Detection Using Signatures Extracted from Execution Profiles”) discloses extracting signatures using chromosomes which are events gathered from a profiling phase that have been determined to be in a percentage number of exploit runs compared to total number of exploit and safe runs (note page 19, 3.1-3.2).
Park et al. (“Deriving Common Malware Behavior through Graph Clustering”) discloses generating a signature using a weighted common graph of system calls collected during object execution (note pages 498-499).
Satish et al. (U.S. Patent Application Publication 2011/0271341) discloses monitoring API calls during execution of software samples(note paragraphs [0035]-[0037]) and clustering the behavior using a measure of similarity (note paragraphs [0040]-[0041]) to then generate signatures (note paragraph [0048]).
Shulman-Peleg et al. (U.S. Patent Application Publication 2019/0036978) discloses intercepting events in a learning environment and including events that appear in a threshold percentage of attack profiles (note paragraph [0078]).
11. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVID J PEARSON whose telephone number is (571)272-0711. The examiner can normally be reached 8:30 - 6:00 pm; Monday through Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571)270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
DAVID J. PEARSON
Primary Examiner
Art Unit 2407
/David J Pearson/Primary Examiner, Art Unit 2407