DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending. All independent claims are amended.
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 6/17/26 has been entered.
Response to amendments and arguments
Applicant’s arguments in view of the amended limitations of independent claims 1, 12 and 20 are
moot in view of new ground of rejection over newly added prior art Tanaka. See the rejection below.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-10 and 12-20 are rejected under 35 U.S.C. 103 as being unpatentable over Geuk et al (KR 20110087826 A), hereinafter Geuk in view of Augustýn US 20170132413 A1 (here in after Augustyn) and Tanaka et al. US 20250139929 A1 (herein after Tanaka).
Regarding claim 1, Geuk teaches a method of identifying malicious activity in a plurality of sequences of computer instructions (The present invention detects whether or not pre-infection using the virtual machine previously storing the mail having an attached file to an actual system, if it is not known malware to determine whether malicious behavior through behavior analysis relates to a method for defining a new malicious code.), comprising:
identifying a plurality of sequences of computer instructions of interest (Geuk teaches extracting attachments/samples from received e-mail and selecting those attachments for analysis see Abstract; detection module 3a (description of extracting and executing attachments); Fig. 2 description showing mail server - VM);
assigning the plurality of sequences of computer instructions into two or more groups (Geuk teaches grouping behavior profiles and clustering similar behavior using normalized compression distance (NCD) and hierarchical clustering to form groups/classes (classification module 3d; Tables 4–6 and accompanying description of NCD and hierarchical clustering);
executing a virtual machine sandbox for each of the two or more groups (Geuk teaches a Virtual Machine Cluster (VMC 30) and executing attachments in virtual machines to monitor behavior (Abstract; VM cluster 30; Fig. 1–3; reports module 3c);
executing each of the plurality of sequences of computer instructions in the virtual machine sandbox into which the sequence of computer instructions has been assigned (Geuk teaches executing each attachment in an assigned VM to produce behavioral logs and API tracing for that sample (reports module 3c; example API logs and behavior analysis Table 2 (behavioral report example); Table 3 (API log excerpt); and
determining whether each of the groups has at least one executed sequence of computer instructions that is likely malicious (Geuk discloses generating behavior-analysis reports and deriving behavior fingerprints/state-changes; classification module 3d evaluates those fingerprints and clusters to determine which groups represent malicious behavior (classification module 3d; behavior fingerprint discussion). … classification module 3d; behavior fingerprint description (paragraphs describing creation of behavior fingerprints and grouping into classes).
Geuk fails, however Augustyn teaches upon determining whether each of the groups has at least one executed sequence of computer instructions that is likely malicious, identifying sequences of computer instructions that are likely malicious based on group testing results and flagging the identified sequences for further analysis or reporting (pars 21-24: after classification, selecting a filter and placing files into queues corresponding to actions (e.g., analyst queue, automated detection generation); placing files on queues assigned to human analysts for further analysis and automatic generation of detections/reports for files that match filter conditions; …. pars. 66-69, 71-74 classification network event-filter-queue (Fig. 2); placing file into queue block 410; explicit text that “The queue containing the file may be assigned to a human analyst for further analysis” and that “a detection generating filter … a checksum based detection can be automatically be generated” pars. 71-74 (detection generation; queue assignment to an analyst).).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine Geuk’s teaching with Augustýn’s to routing suspicious items to analysts or for automated detection generation and to create analyst events/queues or automated reports (see abstract).
Geuk in view of Augustyn fails to explicitly teach executing multiple instruction sequences together within a common sandbox environment associated with a group.
However, Tanaka teaches wherein the sequences of computer instructions assigned to each group are executed together within a common machine sandbox environment associated with the group and (abstract, pars. 14-16, 53-56: an analysis system that clusters pixels by calculating similarity, assigning pixels to clusters/groups based on similarity and iteratively updating clusters and representative distributions); and
determining whether each of the groups …is likely malicious based on monitored behavior occurring during execution of the sequences of computer instructions assigned to the common sandbox environment associated with the group (Pars. 16, 147, figs 18: grouping data elements (pixels) based on statical similarity, assigning them to clusters, and then analyzing the group as a whole to determine group level properties/changes/anomaly…. dividing unit generates multiple clusters; assigns pixels into clusters/groups based on similarity calculation; executing calculating similarity between representative distribution representing a cluster and distribution of pixel values in the cluster, calculating a distribution for a plurality of pixels in each cluster as … analyzing each cluster/group for change/anomaly… pars. 130-135: anomaly detection unit determining anomaly (condition different from normal) in the clusters… pars. 142-143: small clusters/groups and performing anomaly detection at high speed).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tanaka to modify the system of Geuk as combined with Augustyn to reduce computational overhead and accelerate the detection process as taught by Tanaka (see par. 143).
Regarding the system claim 12, claim 12 recites similar limitation as the method claim 1 and rejected based on the same rational as claim 1.
Regarding the system claim 20, Geuk teaches a method of identifying malicious activity in a plurality of sequences of computer instructions, comprising:
identifying a plurality of sequences of computer instructions of interest (discloses extracting attachments or incoming samples and selecting them for analysis (detection module 3a); Abstract; Fig. 1–2 description (selection/extraction of attachments/samples for analysis);
group testing the plurality of sequences of computer instructions in a plurality of virtual machine sandboxes, (Geuk describes executing samples in a virtual machine cluster (VMs) to observe runtime behavior (i.e., dynamic group testing in sandboxes; VM Cluster 30; reports module 3c; Fig. 1–3 (virtual machine based execution/detonation environment); discussion of executing attachments in VMs to gather runtime behavior) each of the plurality of sequences of computer instructions assigned to one of the plurality of virtual machines sandboxes (Geuk teaches assigning and executing individual attachments/samples in VM instances and generating per-sample logs/reports, demonstrating the per-sample assignment to VMs; reports module 3c; Fig. 2–3; Table 2 shows per-sample behavior logs gathered by the VM execution environment);
evaluating a behavior of the group testing the plurality of sequences of computer instructions to identify one or more likely malicious sequences of computer instructions from among the plurality of sequences of computer instructions (classification module 3d; Tables 2–6; NCD/hierarchical clustering discussion and behavior fingerprint generation (classification module 3d and examples). (See Geuk classification module 3d; Tables 4–6; behavior fingerprint description.)); and
While Geuk reports module 3c and classification 3d supply the behavior reports/fingerprints , Geuk fails to explicitly teach, however Augustyn teaches upon determining a sequence of computer instructions is likely malicious, flagging the sequence of computer instructions as likely malicious (pars. 66-69, 71-74; Fig. 2 & Fig. 4 — explicit teaching of filter-queue mapping, placing files into analyst queues for further analysis, and auto-detection/detection generation for matched files.
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine Geuk’s teaching teachings with Augustýn’s for flagging and routing suspicious items to analysts or for automated detection generation and to create analyst events/queues or automated reports (see abstract).
Geuk in view of Augustyn fails to explicitly teach executing multiple instruction sequences together within a common sandbox environment associated with a group.
However, Tanaka teaches wherein the sequences of computer instructions assigned to each group are executed together within a common machine sandbox environment associated with the group and (abstract, pars. 14-16, 53-56: an analysis system that clusters pixels by calculating similarity, assigning pixels to clusters/groups based on similarity and iteratively updating clusters and representative distributions); and
determining whether each of the groups …is likely malicious based on monitored behavior occurring during execution of the sequences of computer instructions assigned to the common sandbox environment associated with the group (Pars. 16, 147, figs 18: grouping data elements (pixels) based on statical similarity, assigning them to clusters, and then analyzing the group as a whole to determine group level properties/changes/anomaly…. dividing unit generates multiple clusters; assigns pixels into clusters/groups based on similarity calculation; executing calculating similarity between representative distribution representing a cluster and distribution of pixel values in the cluster, calculating a distribution for a plurality of pixels in each cluster as … analyzing each cluster/group for change/anomaly… pars. 130-135: anomaly detection unit determining anomaly (condition different from normal) in the clusters… pars. 142-143: small clusters/groups and performing anomaly detection at high speed).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tanaka to modify the system of Geuk as combined with Augustyn to reduce computational overhead and accelerate the detection process as taught by Tanaka (see par. 143).
Regarding claim 2, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 1, Geuk --further comprising:
assigning the plurality of sequences of computer instructions into two or more different groups (Abstract; VM cluster 30; detection module 3a; reports module 3c; classification module 3d; Figs. 1–3; Table 2 (example behavior report), Table 3 (API log).);
executing a virtual machine sandbox for each of the two or more different groups (extracting attachments/samples, running them in VM cluster(s) to generate per-sample behavior logs and fingerprints, and clustering/classifying those behavior outputs to identify malicious groups (reports 3c; classification 3d);
executing each of the plurality of sequences of computer instructions in the virtual machine sandbox into which the sequence of computer instructions has been assigned ((Fig. 1–3, classification module 3d ; … running them in VM cluster(s) to generate per-sample behavior logs and fingerprints, and clustering/classifying those behavior outputs to identify malicious groups (reports 3c; classification 3d); and
determining whether each of the different groups has at least one executed sequence of computer instructions that is likely malicious (classification module 3d; Tables 2–6; NCD/hierarchical clustering discussion and behavior fingerprint generation (classification module 3d and examples). (See Geuk classification module 3d; Tables 4–6; behavior fingerprint description.)).
Regarding the system claim 13, claim 13 recites similar limitation as the method claim 2 and rejected based on the same rational as claim 2.
Regarding claim 3, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 2, Geuk further comprising repeating the assigning the plurality of sequences of computer instructions, the executing a virtual machine sandbox, the executing each of the plurality of sequences of computer instructions, and the determining whether each of the different groups has at least one executed sequence of computer instructions that is likely malicious using different groupings of the plurality of sequences of computer instructions until it is possible to determine whether each of the plurality of sequences of computer instructions is likely malicious (Geuk teaches iterative grouping and re-testing using clustering and classification refinements (Tables 4–6). … classification module 3d; discussion of clustering methods; Tables 4–6 (clustering examples and refinements); Fig. 4 (process flow for analysis and refinements). Geuk describes clustering/grouping and using behavior fingerprints to refine classifications; clustering examples imply iterative regrouping to better separate classes.).
Regarding claim 4, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 3, Geuk further comprising using a group testing algorithm to determine whether each of the plurality of sequences of computer instructions is likely malicious (Geuk uses of group testing algorithms such as NCD and hierarchical clustering (classification module 3d) …. classification module 3d; explicit NCD and hierarchical clustering description; Tables 4–6 (algorithmic examples/results).
… discloses concrete grouping/clustering algorithms (NCD, hierarchical clustering) applied to behavior fingerprints — i.e., group testing algorithm).
Regarding the system claim 15, claim 15 recites similar limitation as the method claim 4 and rejected based on the same rational as claim 4.
Regarding claim 5, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 1, further comprising using group testing to determine whether each of the plurality of sequences of computer instructions is likely malicious (Geuk abstract; reports module 3c; classification module 3d; VM cluster 30; Tables 2–6; Figs. 1–3. … method is a group testing process … grouping, sandbox execution, behavior fingerprinting, clustering—constitutes group testing as claimed).
Regarding the system claim 16, claim 16 recites similar limitation as the method claim 5 and rejected based on the same rational as claim 5.
Regarding claim 6, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 5, wherein using group testing comprises iteratively reassigning groups based on monitored behavior (classification module 3d; hierarchical clustering discussion; Tables 4–6; Fig. 4 (iterative analysis flow) … hierarchical (nested) clustering and shows iterative clustering/refinement procedures based on the behavior fingerprints, which supports nested iterative reassignment.).
Regarding the system claim 17, claim 17 recites similar limitation as the method claim 6 and rejected based on the same rational as claim 6.
Regarding claim 7, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 1, wherein determining whether each of the groups has at least one executed sequence of computer instructions that is likely malicious (Geuk reports module 3c; Table 2 (behavior report example); Table 3 (API log example); Fig. 3 (event flow / logging). … records detailed runtime behavior per sample in VMs and analyzes those logs to form fingerprints for classification) comprises analyzing a behavior of the sequences of computer instructions assigned to each of the virtual machine sandboxes (Augustyn pars. 28-31 — analyzer uses metadata/behavioral inputs). The rational for combining is the same as claim 1 above.
Regarding the system claim 18, claim 18 recites similar limitation as the method claim 7 and rejected based on the same rational as claim 7.
Regarding claim 8, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 1, further comprising identifying sequences of the plurality of the computer instruction sequences determined likely to be malicious to a user (Augustyn teaches queueing to analysts / detection generation: pars. 66-69 (placing files into analyst queues); pars. 71-74 (automatic detection generation, reporting); Fig. 4 & claim 19). The rational for combining is the same as claim 1 above.
Regarding claim 9, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 1, further comprising selecting the plurality of sequences of computer instructions of interest using static analysis (Geuk discloses detection module 3a (preprocessing and sample selection); and Augustyn also teaches Fig. 3 / table 300 (file metadata: file hash 302, static information 308, sources 312); 35-44 (static data and selection/filtering). The rational for combining is the same as claim 1 above.
Regarding claim 10, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 9, further comprising adjusting time spent executing each of the plurality of sequences of computer instructions in the virtual machine sandbox into which the sequence of computer instructions has been assigned based on the static analysis (Geuk teaches adjusting execution parameters based on static analysis results (longer execution for suspicious samples. Augustyn: Fig.3/table 300 and 35-44 (static metadata); 74-78 (re-scheduling/prioritization mechanics)). Augustyn teaches using static metadata to prioritize/route and reschedule files.
It would have been obvious to one ordinary skill in the art before the effective filing date of the invention to combine Augustyn’s teachings of static metadata to prioritize/route and reschedule files to adjust processing parameters (e.g., length of dynamic analysis) based on static risk indicators.
Regarding claim 14, Geuk in view of Augustyn and Tanaka teaches the computerized system of claim 13, the stored set of program instructions further operable when executed on the processor to repeat (Geuk flow diagrams and clustering descriptions show an iterative analytic process. Aug provides explicit system workflow control constructs (queues, resubmission, scheduling) suitable to implement the repeat‑until termination loop in a real system … Fig. 4 (process flow/analysis diagram); classification module 3d description (iterative analysis steps); Tables 4–6 (examples of refinement)), until it is possible to determine whether each of the plurality of sequences of computer instructions is likely malicious (Geuk pars. 74-78 (re-evaluation / resubmission / reprocessing when filters/rules change; scheduling/resubmission mechanics) … iterative clustering and analytic flows that refine classifications (classification module 3d; Fig.4; Tables 4–6) — teaching iterative analysis to improve per-sample classification.):
the assigning the plurality of sequences of computer instructions, the executing a virtual machine sandbox (Geuk classification module 3d; NCD / hierarchical clustering description; Tables 4–6; discussion of grouping strategies and grouping parameters.);
the executing each of the plurality of sequences of computer instructions (Geuk VM Cluster 30; reports module 3c; Figs. 1–3 (virtual machine cluster that runs samples in sandboxes; per-VM execution)); and
the determining whether each of the different groups has at least one executed sequence of computer instructions that is likely malicious using different groupings of the plurality of sequences of computer instructions (Geuk classification module 3d; behavior fingerprint description; Tables 2–6; discussion of how clusters/groups exhibiting malicious actions are identified … generating behavior fingerprints and grouping/clustering samples to identify which clusters/groups are associated with malicious behaviors (classification module 3d; Tables 4–6) … using different grouping : classification module 3d; Tables 4–6; Fig. 4; discussion of hierarchical clustering, NCD and grouping parameter variation).
Regarding claim 19, Geuk in view of Augustyn and Tanaka teaches the computerized system of claim 12, the stored set of program instructions further operable when executed on the processor to use [static]- analysis to adjust at least one of a time spent executing each of the plurality of sequences of computer instructions in the virtual machine sandbox into which the sequence of computer instructions has been assigned (Geuk VM Cluster 30; reports module 3c; detection module 3a; Fig. 1–3; Table 2 (behavior report example) … describes executing samples in VMs, collecting runtime logs/API traces and generating behavior fingerprints (reports module 3c; Table 2). This establishes per-sample dynamic execution and the framework where execution time/dwell could be controlled and assigning the plurality of sequences of computer instructions into two or more groups (Geuk pars. 25-30] — preprocessing selection; adaptable execution/grouping parameters). Augustine explicitly teaches static analysis (Static metadata and filters: Aug — Fig. 3 / table 300 and pars. 35-44 (describing static file metadata such as file hash, static attributes, sources, and other static indicators used in filtering/selection …. prioritization / processing parameter control: Aug — pars. 46-56 (discusses event prioritization and filter-based routing and handling); Aug —pars. 74-78 (resubmission/reprocessing when rules change, and scheduling … control of processing behavior (prioritization, rescheduling, applying different filters/workflows) based on static metadata.))).
It would have been obvious to one ordinary skill in before the effective filing date of the claimed invention to combine the teachings of Augustýn to allocate longer dynamic analysis time to more suspicious items and pre-partition incoming samples so high-risk samples are assigned to smaller, higher-priority groups (or dedicated sandboxes) for faster isolation.
Claim(s) 11 is rejected under 35 U.S.C. 103 as being unpatentable over Geuk in view of Augustyn, and Tanaka and further in view of MONSONEGO et al. US 20200257797 A1 (herein after Monsonego).
Regarding claim 11, Geuk in view of Augustyn and Tanaka teaches the method of identifying malicious activity in a plurality of sequences of computer instructions of claim 9. The combination of Geuk in view of Augustyn and Tanaka teach adjusting assigning the plurality of sequences of computer instructions into two or more groups, suech that sequences of computer instructions determined more likely to be malicious and grouping into smaller sized groups of sequences of computer instructions than sequences of computer instructions determined more likely to be benign (Pars. 16, 147, figs 18: grouping data elements (pixels) based on statical similarity, assigning them to clusters, and then analyzing the group as a whole to determine group level properties/changes/anomaly…. dividing unit generates multiple clusters; assigns pixels into clusters/groups based on similarity calculation; executing calculating similarity between representative distribution representing a cluster and distribution of pixel values in the cluster, calculating a distribution for a plurality of pixels in each cluster as … analyzing each cluster/group for change/anomaly… pars. 130-135: anomaly detection unit determining anomaly (condition different from normal) in the clusters… pars. 142-143: small clusters/groups and performing anomaly detection at high speed).
It would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Tanaka to modify the system of Geuk as combined with Augustyn to reduce computational overhead and accelerate the detection process as taught by Tanaka (see par. 143).
Geuk in view of Augustyn and Tanaka fails to explicitly teach grouping based on static analysis. However, Monsonego teaches: adjusting assigning the plurality of sequences of computer instructions into two or more groups based on the static analysis (Obtaining group/identity definitions and using them as contextual/static data: pars. 23-29; 111-116; flowcharts FIG. 11/12 description (methods 1102/1106/1108 … Filtering groups and using group definitions as inputs: pars. 258-264 (maxSuitableGroupSize/minSuitableGroupSize and filtering out groups for computation … obtains static group definitions and uses them (static directory data) to form the basis for subsequent grouping/score computations; this is a direct static-analysis source for group assignment), such that sequences of computer instructions determined more likely to be malicious using static analysis are grouped into smaller-sized groups of sequences of computer instructions than sequences of computer instructions determined more likely to be benign (Smaller groups contribute more to similarity/intimacy score; explicit score functions and relationship between group size and score: pars. 288-296; 298-305 (formulas and explanation; e.g., I(k) = 1 − 0.99 × log_maxGroupSize |k| and discussion that smaller group → higher intimacy contribution; CGIS/PGIS/peerSimilarityScore formulas at pars. 298-305 … mathematical/algorithmic teaching that smaller groups are given larger weight (and that group size cut-offs are used to exclude large groups)[Wingdings font/0xE0] condition that higher-static-risk items be placed in smaller groups (functionally, smaller groups are treated as higher-significance). … pars. 23-29; 258-264; 288-296: (fetching group definitions, exclusion by size, using group size in scoring). … input data is static identity/group membership; its scoring uses group size directly — this is a static-analysis source for assignment decisions that the claim requires).
Therefore, it would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Monsonego within the teachings of Geuk in view of Augutyn and Tanaka to place statically higher-risk items into smaller groups (for higher-priority or dedicated processing), because doing so is a routine optimization to improve triage efficiency and isolation of likely malicious items.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 20160021174 A1 Monitor sequences of system calls to detect anomaly and clusters and comparing clusters etc.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ELENI A SHIFERAW whose telephone number is (571)272-3867. The examiner can normally be reached 7-3:30 M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497