Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on June 29, 2026 has been entered.
Response to Arguments
In pages 1-2 of the remarks, Applicant states that claims 1-4, 7-10, and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl. Applicant states that neither of Palisse or Pohl appear to suggest the amended limitations of "identifying one or more potential cryptographic artefacts from the at least one extracted section of memory; and decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts," as described in independent claims 1 and 7. Applicant further adds that “Examiner asserts that Palisse shows detecting the encryption, and the copy-on-write process of Pohl shows extracting sections of memory that contain cryptographic artefacts”, where this characterization is misunderstood to fit in with the teachings of Pohl and the scope of the claims. Applicant states that “cryptographic artefacts” as recited in the independent claims are not mere “entropy values”, but rather refer to cryptographic materials such as “encryption keys, key schedules” to reverse the encryption process. Applicant further states that the copy-on-write snapshot mechanism of Pohl preserves memory states for forensic analysis but does not identify or extract cryptographic artefacts. Next, that neither of Palisse or Pohl teach or suggest the claimed sequence of “detecting a file being encrypted based on entropy analysis; extracting sections of memory that contain cryptographic artefacts; identifying potential cryptographic artefact candidates from the extracted memory; and decrypting the encrypted file based on the identified cryptographic artefacts”, and that neither of the references would arrive at the claimed invention, where Palisse teaches detecting ransomware attacks based on entropy analysis, while Pohl teaches preserving memory states through copy-on-write mechanisms for data protection. For at least these reasons, Palisse and Pohl fail to “teach or suggest each and every element of claims 1 and 7”. Because claims 1 and 7 are believed to be allowable over the cited art, claims 2-4, 8-10, and 14-16 are believed to be allowable because they depend on claims 1 and 7. Therefore, it is respectfully requested that this rejection be withdrawn.
Examiner disagrees with the Applicant, as firstly, while paragraph [page 12, line 27-page 13, line 7] of the Applicant’s Specification describes the “cryptographic artefacts” as allegedly a “nonce and encryption key”, with the artefacts being “generated at the commencement of the encryption process by the ransomware and are retained in the read/write memory of the associated file write process”, the claim limitations do not make this limitation sufficiently clear. Next, while Palisse in view of Pohl do not expressly mentioned the amended limitation of “and decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts”, Kowalski (US 11463422 B1) teaches said limitation in [Col. 8, lines 11-28] Fig. 1, SPS state information 161 includes sets of cryptographic artifacts that correspond to different transport mechanisms used during SPS. Kowalski provides an example of a first set of cryptographic artifacts included within state information 161 to decrypt messages sent over a first transport mechanism, and a corresponding example of a second set of cryptographic artifacts and a second transport mechanism. Lastly, while Palisse in view of Pohl do not fully describe the teachings of “recovering encryption keys from memory and using those keys to decrypt ransomware-encrypted files”, as described by the Applicant, the use of Kowalski to teach the amended limitation of “and decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts” is taught by storing a cryptographic key stored as part of a session’s state information so that if a message is encrypted with a certain cryptographic key, the same cryptographic key can be used to decrypt the message sent via UDP (user datagram protocol) or the message queue (Kowalski [Col. 3, lines 27-34]). As a result of the rejections being maintained in conjunction with Kowalski to teach the amended limitations of “identifying potential cryptographic artefact candidates from the extracted memory; and decrypting the encrypted file based on the identified cryptographic artefacts” along with all previous limitations, claims 1-4, 7-10, and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski.
In page 3 of the remarks, Applicant states that the following claims were rejected for relying on claims 1 and 7, which are believed to be allowable: Claims 5 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl, further in view of Stolfo and LeCrone; Claim 15 and 17 rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl, further in view of Stolfo; and claims 13 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl, further in view of LeCrone.
Examiner disagrees with the Applicant. As the rejections made on independent claim 1 were maintained under 103 using the references of Palisse in view of Pohl, and additionally Kowalski for the amended limitation of “and decrypting at least one component of the encrypted file […]”, and with no arguments made in particular to any of the aforementioned 103 rejections made in page 3 of the remarks, claims 5 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of Stolfo and LeCrone; Claim 15 and 17 rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of Stolfo; and claims 13 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of LeCrone.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-5, 7-11, 13-18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The term “potential cryptographic artefacts” in claim 1 is a relative term which renders the claim indefinite. The term “potential cryptographic artefacts” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Section [page 6, lines 27-30] describes “potential crypto artefacts” being capable of being identified in an activity flow of Fig. 1 of a “potentially encrypted file”. However, use of the term “potential” can also be determined to mean that no ’artefacts’ are found in the file to assist with the decryption of a component of the encrypted file. Furthermore, Fig. 1 does not have a function that is performed if no ‘artefacts’ are found in the ransomware encrypted file.
Regarding claims 2-5, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 1.
Regarding claim 7, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 8-11, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 7.
Regarding claim 13, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 14-18, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 13.
Claim Rejections - 35 USC § 112(a)
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-5, 7-11, 13-18 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
In the independent claim 1, the amended claim limitations of “identifying one or more potential cryptographic artefacts from the at least one extracted section of memory”, and “decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts” in a method for detecting and decrypting a file encrypted by ransomware are described as being performed by the invention of the Applicant. However, in the Specification sections [page 12, lines 23-28], it is described that a ‘cryptographic artefact’ as example the following are allegedly extracted “nonce; encryption key”, and if a file write operation is on a safe list in step 303 in Figure 3, no further action is taken. Otherwise, the memory extract component identifies and extracts the sections to identify the cryptographic artefact, which is the nonce.
Furthermore, in section [page 14, lines 18-30], with respect to Figures 4 and 5, it is described that the nonce has a length and a structure, typically of 8 bytes, 12 bytes, or 16 bytes, used to ensure that plaintext is encrypted differently by each encryption used, and “may be an incremental number which is incremented after each encryption”.
However, as the cryptographic artefact, or nonce/encryption key, can be a random value that can change at different points in time, how the “memory analysis component” identifies a candidate encryption key based on a 32-byte encryption key in section [page 19, line 28-page 16], such as “in the extracted memory segment between [specific] memory locations” is unclear, such as if a user or system defines what type of encryption method is used, or the system can automatically detect an encryption method used by the ransomware. It is also not explained how this invention functions for other encryption methods or algorithms, or even if the nonce or encryption keys cannot be determined. It is insufficient the description provided that provides how the Applicant identifies nonces as well as encryption keys in a consistent manner, especially if the encryption method used by a ransomware stores cryptographic artefacts in a different method, if the artefacts are even present in the ransomware.
Regarding claims 2-5, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 1.
Regarding claim 7, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 8-11, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 7.
Regarding claim 13, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 14-18, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 13.
Claims 1-5, 7-11, 13-18 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention.
In claim 1, the subject matter that is not enabled is the limitations for “identifying one or more potential cryptographic artefacts from the at least one extracted section of memory”, and “decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts”.
One of ordinary skill in the art would be unable to identify one or more potential cryptographic artefacts from at least an extracted section of memory, and using said artefacts to decrypt at least a component of the encrypted file based on the artefacts, or where/how it is obtained and no relationship to the rest of the invention is established with other elements of the claim, as to enable one of ordinary skill in the art to make and use the invention.
The Specification is not enabling for the expression claimed.
To decide whether the disclosure does not satisfy the enablement requirement, and whether any necessary experimentation is undue, the Examiner has weighed in particular the following factors:
The breadth of the invention.
The invention relates to identifying potential cryptographic artefacts in an encrypted file, where the file was encrypted by ransomware, in sections of memory that have been extracted to identify at least one artefact that can be used to decrypt a component of the encrypted file, which corresponds to partial decryption. While section [page 12, lines 23-28] describes a ‘cryptographic artefact’ can be in the form of a “nonce [or] encryption key”, and section [page 18, lines 11-19] describes that a memory analysis component “identif[ies] candidate encryption keys […] segments in the extracted memory that are proximal to candidate nonce memory locations and are sufficiently random may be candidate encryption keys”, stating that randomized byte sequences of a fixed length are “typically constant for each encrypted file”, how this is achieved and explained with a variety of different encryption algorithms is unclear. Therefore, identifying cryptographic artefacts and using the artefacts to decrypt a component of the encryption file is not known in the art.
The nature of the invention.
The basic concept is a method proposed by the Applicant to identify cryptographic artefacts in a file encrypted by ransomware to identify an encryption key and/or a nonce value to decrypt at least a component of the file, to overcome ransomware attacks without having to pay a ransom to attackers for a decryption key.
The present claimed invention provides no limits to identifying a file for the artefacts, as well as decrypting using an artefact based on an extracted memory section.
The state of the prior art.
The Examiner has found no evidence of identifying cryptographic artefacts from an extracted portion of memory, and using the artefacts to decrypt a component of the encrypted file by a ransomware that is so well understood or well known that one of ordinary skill would be able to make the invention without more detailed direction from the inventor. In addition, the Applicant makes no mention of any state in the background section of any papers/publications to demonstrate any level of knowledge in the art regarding identifying artefacts in extracted memory sections relating to encrypted files performed by a ransomware.
The level of one of ordinary skill.
The inventor provides no standard as to how the identification of cryptographic artefacts from an extracted section of memory is performed, as well as the decrypting in the Specification of the Applicant. However, section [page 14, lines 18-30], with respect to Figures 4 and 5, describes that the nonce has a length and a structure, typically of 8 bytes, 12 bytes, or 16 bytes, used to ensure that plaintext is encrypted differently by each encryption used, and “may be an incremental number which is incremented after each encryption”, with the cryptographic artefact capable of being a random value that can change at different points in time, how the “memory analysis component” identifies a candidate encryption key is unclear, especially with regards with different encryption algorithms, including future methods that may not have artefacts present in a format that is easily identifiable. As a result, a person of ordinary skill in the art would not understand how to make or use the invention in relation to the desired identification of cryptographic artefacts in extracted memory sections and decrypting using the artefacts, without undue experimentation.
The level of predictability in the art.
In the Specification of the Applicant, the use of a memory extraction component in the invention, as described in the section [page 19, line 28-page 16] of the Specification, such as “in the extracted memory segment between [specific] memory locations” is unclear, such as if a user or system defines what type of encryption method is used, or the system can automatically detect an encryption method used by the ransomware. There is no explanation as to how cryptographic artefacts are identified in the invention, as well as how decryption of a component of the encrypted file using the artefacts is performed, especially with regard to other encryption algorithms. As a result, the predictability of the art of identifying cryptographic artefacts and decrypting encrypted file components using the artefacts is unpredictable.
The amount of direction provided by the inventor.
The inventor provides no direction whatsoever, to discuss the application or any relationship between the identifying cryptographic artefacts of an encrypted file by ransomware in extracted memory sections, and decrypting a component of the encrypted file using the artefacts.
The existence of working examples.
There are no examples for identifying cryptographic artefacts of an encrypted file by ransomware in extracted memory sections.
The quantity of experimentation needed to make or use the invention based on the content of the disclosure.
The inventor does not go into detail as to how the invention functions in relation to the identifying cryptographic artefacts of an encrypted file by ransomware in extracted memory sections, and decrypting at least a component in the encrypted file in the Specification. As a result, the quantity of undue experimentation needed to make or use the invention based on the content present of the disclosures.
Regarding claims 2-5, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 1.
Regarding claim 7, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 8-11, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 7.
Regarding claim 13, the independent claim is rejected for the same reasons as independent claim 1 as the claim recites similar limitations present in the aforementioned claim.
Regarding claims 14-18, the dependent claims of an independent claim that is relied upon inherit the deficiencies of the independent claim, in this case, claim 13.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 7-10, and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse et al. (US 20200342104 A1), hereinafter Palisse, in view of Pohl et al. (US 10839072), hereinafter Pohl, and Kowalski (US 11463422 B1).
Regarding claim 1, Palisse discloses ‘a method of detecting a file encrypted by ransomware in a computing device, comprising’ ([0026]-[0041] Process of encryption detection method is described in this section of Palisse, with [0026] stating an 'encryption detection method' and listing the process in order.):
‘identifying a file write operation for a file on the computing device’ ([0028] File write requests are retrieved, and the requests comprise a character string to be written as an argument.);
‘determining if a predetermined number of bytes of the file is stored in a memory buffer on the computing device’ ([0028]-[0029] As a file write request is being emitted from a thread 20 in Fig. 1 or Fig. 2 to a file identified by IdF, as stated in paragraph [0095], in an instruction 22 in a user thread 20, wherein the user thread corresponds to a memory buffer on the computing device of the applicant, as the user thread 20 sends a write request to a memory manager 16 as the user thread holds the instructions, and then receives a request return 26 as to whether or not the request has been executed as explained in paragraph [0072], and file identifier IdF 36 designates the file 8 to be written to by write request 24. [0130] Fig. 3, which is the behavioral analysis module 302 of Fig. 2, comprises an extraction operation 318 in paragraph [0128], has an extraction operation 318 ensure that the write request takes effect in the header Ent00 of the file identified as IdF, and the header Ent00 is in an identified file IdF that is in a user thread 20, which corresponds to a memory buffer of the applicant.);
‘determining an entropy value of the predetermined number of bytes in the memory buffer’ ([0029] A first deviation quantity is calculated according to a part of a character string which relates to a header of the file identified as IdF, along with a statistical model for header writing. [0034] A critical quantity is derived from a first deviation quantity, to which the critical quantity corresponds to the entropy value of the predetermined number of bytes in a memory buffer of the applicant, as paragraph [0047]-[0048] state that a second deviation quantity is derived from a first deviation quantity and quantification quantity of the randomness, and using a second deviation as a critical quantity. Therefore, a critical value corresponds to the entropy value of the applicant.);
‘comparing the determined entropy value of the predetermined number of bytes to a first predetermined threshold’ ([0035] A user thread 20 is neutralized if a critical quantity exceeds a first threshold, to which the first threshold corresponds to the first predetermined threshold of the applicant. [0203] Fig. 5 shows a diagram of decision module 304, wherein behavioral value S, wherein in step 340, the behavioral value S is compared with a first threshold, and if it exceeds the first threshold, the thread is neutralized.);
Palisse does expressly disclose, but Pohl teaches ‘wherein if the determined entropy value exceeds the first predetermined threshold, information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation and contains cryptographic artefacts’ ([Col. 6, lines 52-56] Fig. 1, step 106, if entropy value is greater than or equal to a threshold, perform copy-on-write process to copy-on-write storage area. As stated in [Col. 3, lines 60-62], a copy-on-write process creates a copy of the original file that can be modified, instead of overwriting it, corresponding to extracting at least one section of memory relating to file write operation, the write operation is performed to a copy-on-write storage area for the file, with the entropy of the file in memory corresponding to cryptographic artefacts, as the entropy of a value is considered as the randomness of the file, in which a completely encrypted file has a high entropy value, as described in [Col. 3, lines 43-56]. The copy-on-write storage area corresponds to a memory extract component, in conjunction with the copy-on-write process.).
“identifying one or more potential cryptographic artefacts from the at least one extracted section of memory” ([Col. 3, lines 60-62], a copy-on-write process creates a copy of the original file that can be modified, instead of overwriting it, the write operation is performed to a copy-on-write storage area for the file, with the entropy of the file in memory corresponding to cryptographic artefacts.);
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse and Pohl before them, to include Pohl’s “information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation and contains cryptographic artefacts” and “identifying one or more potential cryptographic artefacts from the at least one extracted section of memory” in Palisse’s method performing “detecting a file encrypted by ransomware in a computing device”. One would have been motivated to make such a combination to increase efficiency by having the file continue to be in existence, even if the ransomware attack has occurred that would modify the files, as taught by Pohl [Col. 4, lines 26-35].
Palisse in view of Pohl does not appear to teach or suggest, but Kowalski teaches the limitation of “and decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts” ([Col. 8, lines 11-28] Fig. 1, SPS state information 161 includes sets of cryptographic artifacts that correspond to different transport mechanisms used during SPS. Kowalski provides an example of a first set of cryptographic artifacts included within state information 161 to decrypt messages sent over a first transport mechanism, and a corresponding example of a second set of cryptographic artifacts and a second transport mechanism.);
Therefore, one of ordinary skill in the art would have been capable of applying this known method of "and decrypting at least one component of the encrypted file based on the identified potential cryptographic artefacts" in a method of detecting a file encrypted by ransomware in a computing device and the results would have been predictable to one of ordinary skill in the art. The one of ordinary skill in the art would have been motivated to store a cryptographic key stored as part of a session’s state information so that if a message is encrypted with a certain cryptographic key, the same cryptographic key can be used to decrypt the message sent via UDP (user datagram protocol) or the message queue (Kowalski [Col. 3, lines 27-34]).
Regarding claim 2, Palisse in view of Pohl and Kowalski teach the method of claim 1 as recited above. Palisse also discloses the limitation of ‘monitoring an operation of the computing device to identify the file write operation’ ([0073] Kernel of a system executes a system probe 30, or HIDS probe. The HIDS probe duplicates the system calls of the user threads 20 without being detectable by a user thread 20, and will not execute the requests, including the write requests identified by Palisse.).
Regarding claim 3, Palisse in view of Pohl and Kowalski teach the method of claim 1 as recited above. Palisse also discloses the limitation of ‘in which determining the entropy value is based on a Shannon entropy or a modified Shannon entropy’ ([0170] Fig. 4, behavioral analysis module 302 can comprise a second branch, and in block 332, the calculation of randomness is determined to be behavioral value S in a request-value pair 314, denoted as (RE, S), as shown in Fig. 5 as well. It includes a calculation of chi-square (χ_2) as well based on randomness. [0187] Chi-square (χ_2) is preferred to Shannon's entropy, but Shannon's entropy can be used nevertheless in some cases.).
Regarding claim 4, Palisse in view of Pohl and Kowalski teach the method of claim 1 as recited above. Palisse also discloses the limitation of ‘in which if the determined entropy value does not exceed the first predetermined threshold, the method further comprises: comparing the determined entropy value to a second predetermined threshold, wherein the second predetermined threshold is lower than the first predetermined threshold’ ([0203] Fig. 5, decision module 304 has a test operation 348 contains a comparison for a second threshold 350, where behavioral value S fails to exceed the first threshold 342 in operation 340, as stated in paragraph [0208]. Critical value is compared to a second threshold, with the second threshold in paragraph [0014], and a second threshold is less than a first threshold in paragraph [0011]. [0214] First and second thresholds can be utilized for the indicator chi-square (χ_2), and corresponds to comparing the entropy values of the applicant with a second predetermined threshold.).
Regarding claim 7, Palisse in view of Pohl and Kowalski recites similar limitations to claim 1 as recited above. Palisse also discloses ‘a computing device comprising:’ ([0063]-[0064] Computer 1 of the invention).
‘a processor’ ([0063]-[0064] Computer 1 of the invention comprises a machine 2, comprising a central processing unit (CPU) 4 and a mass memory 6 for storing files, and CPU cooperates with an operating system 10, comprising core or kernel, and programs. Claim 1 states that the encryption detection device comprise a computer with a CPU, and cooperates with the kernel, and executing by the CPU, carries out the functions of the invention.);
‘and a memory buffer’ ([0028] A user thread 20, wherein the user thread corresponds to a memory buffer on the computing device of the applicant, as the user thread 20 sends a write request to a memory manager 16 as the user thread holds the instructions, and then receives a request return 26 as to whether or not the request has been executed as explained in paragraph [0072].);
Regarding claim 8, Palisse in view of Pohl and Kowalski teach the computing device of claim 7 as recited above. Palisse also discloses the limitations also present in dependent claim 2 recited above.
Regarding claim 9, Palisse in view of Pohl and Kowalski teach the computing device of claim 7 as recited above. Palisse also discloses the limitations also present in dependent claim 3 recited above.
Regarding claim 10, Palisse in view of Pohl and Kowalski teach the computing device of claim 7 as recited above. Palisse also discloses the limitations also present in dependent claim 4 recited above.
Regarding claim 14, Palisse in view of Pohl and Kowalski teach the method of claim 1 as recited above. Palisse also discloses “which the information provided may include one or more of the process name, the process identifier (PID), the filename of file being written, and the determined entropy value” ([0034] A critical value corresponds to the determined entropy value. [0095] File identifier (idF) designates the file concerned by a write request 24, corresponding to a filename of file being written in Fig. 2. Process identifier (PID) idP can also be provided, stated in [0098], which can also name the process.).
Regarding claim 16, Palisse in view of Pohl and Kowalski teach the computing device of claim 7 as recited above. Palisse also discloses the limitations also present in dependent claim 14 recited above.
Claims 5 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of Stolfo (US 10673884 B2), and LeCrone et al. (US 20210103490 A1), hereinafter LeCrone.
Regarding claim 5, Palisse in view of Pohl and Kowalski teaches the method of claims 1 and 4 as recited above. Palisse in view of Pohl does not appear to disclose, but Stolfo teaches “determining an ASCII frequency count to the predetermined number of bytes” ([Col. 10, lines 49-Col. 11, line 11] Fig. 2, step S216 has a statistical distribution that is generated for each of the partitions created from length distribution, where the frequency distribution of ASCII characters is contained in a payload, and is described as a file in section [Col. 7, lines 35-40].)
“comparing the determined ASCII frequency count to a predetermined ASCII frequency count threshold” ([Col. 16, lines 59-62] Character frequency distribution is taken into account when determining computation being larger than a threshold.)
“wherein if the determined ASCII frequency count exceeds the predetermined parameter threshold” ([Col. 16, lines 59-62] Character frequency distribution is taken into account when determining computation/distance being larger than a threshold. [Col. 17, lines 21-24] Fig. 10, S432, when server determines the distance exceeds threshold, payload is identified as anomalous.);
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse and Stolfo before them, to include Stolfo’s “determining an ASCII frequency count to the predetermined number of bytes” and “comparing the determined ASCII frequency count to a predetermined ASCII frequency count threshold” in Palisse’s method performing “detecting a file encrypted by ransomware in a computing device”. One would have been motivated to make such a combination to increase efficiency as a frequency count chart can show which characters show up most frequency, with the most frequent character showing up on the left side of the chart in a rank order, as stated in [Col. 11, lines 30-43].
Palisse in view of Stolfo does not appear to disclose, but Pohl teaches ‘and wherein if the determined value exceeds the first predetermined threshold, information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation’ ([Col. 6, lines 52-56] Fig. 1, step 106, if entropy value is greater than or equal to a threshold, perform copy-on-write process to copy-on-write storage area. As stated in [Col. 3, lines 60-62], a copy-on-write process creates a copy of the original file that can be modified, instead of overwriting it, corresponding to extracting at least one section of memory relating to file write operation. The copy-on-write storage area corresponds to a memory extract component, in conjunction with the copy-on-write process).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse and Pohl before them, to include Pohl’s “information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation” in Palisse’s method performing “detecting a file encrypted by ransomware in a computing device”. One would have been motivated to make such a combination to increase efficiency by having the file continue to be in existence, even if the ransomware attack has occurred that would modify the files, as taught by Pohl [Col. 4, lines 26-35]
Palisse in view of Pohl and Stolfo does not appear to disclose, but LeCrone teaches the method of ‘do not exceed the predetermined parameter threshold’ ([0121] Fig. 27, if entropy of a file is less than a threshold, go to step 1006, but then the invention determines if an encrypt flag is set, and if it is set, when data is not meant to be encrypted as determined by step 1004, an encryption anomaly is indicated in step 1008.).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse, Pohl, Stolfo and LeCrone before them, to include LeCrone’s ‘do not exceed the predetermined parameter threshold’ in Palisse’s limitation of ‘and wherein if the determined one or more parameters exceed the predetermined parameter threshold, flagging the file associated with the file write operation indicated that the file is encrypted by ransomware’ in claim 5 and method performing ‘detecting a file encrypted by ransomware in a computing device’. One would have been motivated to make such a combination to enhance security by verifying a file that the indication of step 1004 in Fig. 27 is correct, as otherwise, a file that has an encrypt flag set and has a low entropy can infiltrate the system and proceed to execute the ransomware in the system of a user, as stated in LeCrone [0122].
Regarding claim 11, Palisse in view of Pohl and Kowalski teach the computing device of claim 7 as recited above. Palisse in view of Pohl and Kowalski further in view of LeCrone also teach the limitations also present in dependent claim 5 recited above.
Claims 15 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of Stolfo.
Regarding claim 15, Palisse in view of Pohl and Kowalski teach the method of claims 1 and 4 as recited above. Palisse also discloses “wherein if a length does not exceed the predetermined parameter threshold” ([0203] Fig. 5, decision module 304 has a test operation 348 contains a comparison for a second threshold 350, where behavioral value S fails to exceed the first threshold 342 in operation 340.);
Palisse does not disclose, but Stolfo teaches “in which if the determined entropy value exceeds the second predetermined threshold, the method further comprises: determining a maximum ASCII string length related to the predetermined number of bytes” ([Col. 12, lines 1-2] Fig. 6A, payload signature string 150 includes plurality of ASCII characters. [Col. 18, lines 52-57] String edit distance tests for equivalence of strings and signature string.);
“and comparing the determined maximum ASCII string length to a predetermined maximum ASCII string length threshold” ([Col. 17, lines 15-19] Fig. 10, S428, a comparison is made if string edit distance is greater than the threshold, being the signature string. In this case, a payload signature string is compared to a payload received.);
“wherein if the determined maximum ASCII string length exceeds the predetermined parameter threshold” ([Col. 17, lines 21-24] Fig. 10, S432, when server determines the distance exceeds threshold, payload is identified as anomalous.);
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse and Stolfo before them, to include Stolfo’s “determining a maximum ASCII string length related to the predetermined number of bytes” and “comparing the determined maximum ASCII string length to a predetermined maximum ASCII string length threshold” in Palisse’s method performing “detecting a file encrypted by ransomware in a computing device”. One would have been motivated to make such a combination to enhance security as the longest common string will be found in payloads or files that are considered anomalous, as it can indicate a malicious action in the payload, as stated in [Col. 17, lines 39-52].
Palisse in view of Stolfo does not appear to teach, but Pohl teaches ‘information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation’ ([Col. 6, lines 52-56] Fig. 1, step 106, if entropy value is greater than or equal to a threshold, perform copy-on-write process to copy-on-write storage area. As stated in [Col. 3, lines 60-62], a copy-on-write process creates a copy of the original file that can be modified, instead of overwriting it, corresponding to extracting at least one section of memory relating to file write operation.).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse and Pohl before them, to include Pohl’s “information associated with the file write operation is provided to a memory extraction component to identify and extract at least one section of a memory that relates to the file write operation” in Palisse’s method performing “detecting a file encrypted by ransomware in a computing device”. One would have been motivated to make such a combination to increase efficiency by having the file continue to be in existence, even if the ransomware attack has occurred that would modify the files, as taught by Pohl [Col. 4, lines 26-35].
Regarding claim 17, Palisse in view of Pohl and Kowalski teach the method of claims 7 and 10 as recited above. Palisse in view of Pohl and Kowalski further in view of Stolfo also teach the limitations also present in dependent claim 15 recited above.
Claim 13 and 18 is rejected under 35 U.S.C. 103 as being unpatentable over Palisse in view of Pohl and Kowalski, further in view of LeCrone.
Regarding claim 13, Palisse in view of Pohl and Kowalski recites similar limitations to claim 1 as recited above. Palisse in view of Pohl does not appear to disclose, but LeCrone teaches the method of ‘computer program product comprising computer readable executable code for implementing the method comprising:’ ([0129] Software implementations of the invention include executable code stored in a non-transitory computer-readable medium, which is execute by one or more processors, which corresponds to a computer program product of the applicant to perform the processes of the invention.).
Accordingly, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of Palisse, Pohl, and LeCrone before them, to include LeCrone’s ‘computer program product comprising computer readable executable code’ in Palisse’s function of performing ‘identifying a file write operation for a file on the computing device’. One would have been motivated to make such a combination to increase efficiency by having a physical media such as a disk, SD card, hard drive, or otherwise a tangible or non-transitory computer-readable medium to store the invention and have the instructions be executed by a processor of the invention, as taught by LeCrone [0129].
Regarding claim 18, Palisse in view of Pohl and Kowalski and LeCrone teach the computer program product of claim 13 as recited above. Palisse also discloses the limitations also present in dependent claim 14 recited above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Kumar et al. (US 20200177385 A1, "SYSTEM AND METHOD FOR PROTECTION OF MULTIPART SYSTEM APPLICATIONS USING A CRYPTOGRAPHICALLY PROTECTED PACKAGE, A PACKAGE MAP AND A PACKAGE OBJECT STORE FOR DECRYPTION AND VERIFICATION AT RUNTIME ON THE TARGET DEVICE PLATFORM")
Allen et al. (US 20200403905 A1, "SERVERLESS PACKET PROCESSING SERVICE WITH ISOLATED VIRTUAL NETWORK INTEGRATION")
Clouthier et al. (US 6583887 B1, "Method And Apparatus For Data Compression")
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TOMMY MARTINEZ whose telephone number is (703)756-5651. The examiner can normally be reached at Tommy.Martinez@uspto.gov on Monday thru Friday 8AM-4PM ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571) 272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/T.M./ Examiner, Art Unit 2496 /JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496