Prosecution Insights
Last updated: August 06, 2026
Application No. 18/335,014

MALICIOUS SCRIPT DETECTION

Final Rejection §103§112
Filed
Jun 14, 2023
Priority
Oct 31, 2017 — provisional 62/579,267 +1 more
Examiner
KORSAK, OLEG
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
BLUVECTOR, INC.
OA Round
4 (Final)
86%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
828 granted / 968 resolved
+27.5% vs TC avg
Moderate +8% lift
Without
With
+8.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
35 currently pending
Career history
997
Total Applications
across all art units

Statute-Specific Performance

§101
6.8%
-33.2% vs TC avg
§103
36.7%
-3.3% vs TC avg
§102
24.6%
-15.4% vs TC avg
§112
12.5%
-27.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 968 resolved cases

Office Action

§103 §112
DETAILED ACTION Response to Amendment This action is in response to amendment filed June 25, 2026 for the application # 18/335,014 filed on June 14, 2023. Claims 1-20 are pending and are directed toward MALICIOUS SCRIPT DETECTION. Any claim objection/rejection not repeated below is withdrawn due to Applicant's amendment. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Response to Arguments Applicant’s arguments with regards to claims 1-20 have been fully considered, but they are moot because of new grounds of rejection. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), first paragraph: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 3, 11 and 19 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for pre-AIA the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 3, 11 and 19, include the limitation “the network packet data comprises one or more data streams”, and the Applicant’s amendment does not point to the original specification as providing support for the limitation. Nowhere in the specification does Applicant use term “the network packet data comprises one or more data streams”. Applicant disclosure has support only for the opposite “reconstructing network streams from their constituent packets”. Consequently, Examiner considers Applicant was not in possession of the claimed invention at the time of the filing date. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 3, 11 and 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. the new limitation “the network packet data comprises one or more data streams” of claims 3, 11 and 19 is unclear, specifically a relation between “data streams” and “network streams” is not defined. For purposes of applying prior art the cited limitations were construed as the same. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5, 8, 10-13, and 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe et al. (US 10,635,813, Filed Oct. 6, 2017), in view of Vincent et al. (US 2015/0096022, Apr. 2, 2015), hereinafter referred to as Saxe and Vincent. As per claim 1, Saxe teaches a method comprising: receiving a The malware detection device 100 can be configured to receive a file (e.g., file 124 described herein) from the communication network and store the received file in the memory 120. Saxe, Column 3, lines 49-52); Saxe implicitly teaches a network packet, because file 124 received from communication network, Vincent explicitly teaches network packet (the network tap 840 monitors and copies the network data without an appreciable decline in performance of the server device 810, the client device 830, or the communication network 820. The network tap 840 may copy any portion of the network data, for example, any number of data packets from the network data. Vincent, [0072]); Saxe in view of Vincent are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Saxe in view of Vincent. This would have been desirable because if a user is trying to download a file over a network, the file is extracted from the network traffic and analyzed in the virtual machine. The results of the analysis aids in determining whether the file is malicious. The two-phase malware detection solution may detect numerous types of malware and, even malware missed by other commercially available approaches. (Vincent, [0006]). determining, based on execution of at least a portion of the code, one or more features associated with the code (The code includes code to cause the processor to identify the file as malicious based on the first information within at least one fragment from the first set of fragments and the second information within at least one fragment from the second set of fragments. Saxe, Column 3, lines 24-29); Vincent further teaches emulating execution (Emulation analysis module 104 is communicatively coupled to controller 106, static analysis 102, dynamic analysis module 103, malware classifier 105, and intelligence store 110. In one embodiment, emulation analysis module 104 is configured to emulate operations associated with the processing of a particular specimen in context with an emulated computer application (rather than a "real" application, as may be run in a virtual machine in the dynamic analysis) or in context with an emulated dynamic library. As an optional feature, emulation analysis module 104 may provide the list of functions and other features on which malware checks can be applied in later analyses, and/or information regarding a suitable operating environment to be employed in a virtual machine for dynamic analysis. Vincent, [0047]). Saxe in view of Vincent are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Saxe in view of Vincent. This would have been desirable because the emulation analysis module 104 may identify a particular version of an application having a vulnerability targeted the specimen, and the dynamic analysis will then employ that particular version within the virtual environment. This may lead to additional malware indicators and information regarding an attack (Vincent, [0047]). And Saxe in view of Vincent further teaches causing, based on a determination by a machine learning model that the one or more features are associated with one or more malicious behaviors (The method includes analyzing each fragment from the second set of fragments using the machine learning model to identify within each fragment from the second set of fragments second information potentially relevant to whether the file is malicious. Saxe, Column 2, lines 61-66), output of a message indicating that the a network packet is associated with the one or more malicious behaviors (Specifically, the master machine learning model 112 generates a binary output indicating whether the information related to the set of fragments is malicious or not. Saxe, Column 8, lines 63-66). As per claim 2, Saxe in view of Vincent teaches the method of claim 1, wherein the one or more malicious behaviors comprise at least one of: redirecting a browser of the user device to a website, causing the user device to download malicious software, causing the user device to communicate with a computing device, or access to an operating system of the user device (Some other types of malware can include program code designed to illegally gather users' personal and/or financial credentials, monitor users' web browsing, display unsolicited advertisements, redirect affiliate marketing revenues and/or the like. Saxe, Column 1, lines 22-26). As per claim 3, Saxe in view of Vincent teaches the method of claim 1, wherein the network packet comprises one or more data streams, the method further comprising combining segments from the one or more data streams into a single data stream comprising the portion of the code and generic code that is associated with common functions to enable emulation of the execution of at least a portion of the code (The dynamic analysis module 882 may flag the suspicious network content as malicious network content according to the observed behavior during processing of the content within the virtual machine. The reporting module 884 may issue alerts indicating the presence of malware, and using pointers and other reference information, identify the packets of the network content containing the malware. This information may include all or an appropriate portion of that stored for the network content in the intelligence store 110. Vincent, [0084]). Saxe in view of Vincent are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Saxe in view of Vincent. This would have been desirable because There may be multiple dynamic analysis modules 882 to simulate multiple streams of network content. The dynamic analysis module 882 may be configured to monitor the virtual machine for indications that the suspicious network content is in fact malicious network content. (Vincent, [0083]). As per claim 4, Saxe in view of Vincent teaches the method of claim 1, wherein emulating the execution of the least the portion of the code provides an indication of a same function as execution of the code by the user device (In the training mode, the master machine learning model 112 can function as a differentiable model. The master machine learning model can learn and/or be trained to identify and/or determine whether information associated with a set of fragments provides an indication of whether the file is malicious or not ( e.g., identifies information that is potentially relevant to determining whether the file is malicious. Saxe, Column 8, lines 43-50, see also cause the computing platform to implement an analyzer configured to convert a script into pseudocode, the script being related to the executable file, and monitor an emulation process of the pseudocode, a script emulator configured to sequentially emulate the pseudocode and write emulation results to an emulator operation log, and a machine code emulator configured to emulate the pseudocode if a transition from pseudocode to machine code is detected by the analyzer, wherein the analyzer is further configured to analyze the emulator operation log to determine if the executable file is malicious. Vincent, [0008]). As per claim 5, Saxe in view of Vincent teaches the method of claim 1, wherein the machine learning model is based on at least one of: a support vector machine, a Bayesian belief network, a neural network, or a decision tree (The inspector machine learning model 114 can be any suitable type of machine learning model such as, for example, a neural network, a decision tree model, a random forest model, a deep neural network and/or the like. Saxe, Column 6, lines 34-38). As per claim 8, Saxe in view of Vincent teaches the method of claim 1, wherein the code is written in a scripting language (For example, the file can be at least one of a Hypertext Markup Language (HTML) file(s), a JavaScript file(s), or a Hypertext Preprocessor (PHP) file(s ), and/or the like. The file 124 can include a software code, a webpage(s), a data file(s), a model file(s), a source file(s), a script(s), a process(es), a binary executable file(s), Saxe, Column 4, lines 6-13). Claims 9, 10-13, and 16-19 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Claims 6, 14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe et al. (US 10,635,813, Filed Oct. 6, 2017), in view of Vincent et al. (US 2015/0096022, Apr. 2, 2015), in view of KEJRIWAL et al. (US 2011/0289582, Pub. Date: Nov. 24, 2011), hereinafter referred to as Saxe, Vincent and KEJRIWAL. As per claim 6, Saxe in view of Vincent teaches the method of claim 1, but does not teach obfuscation, KEJRIWAL however teaches wherein the one or more features comprise at least one of: an obfuscated variable name, a number of updates to a variable name exceeding a first threshold, an obfuscated Uniform Resource Locator (URL) protocol, an obfuscated scripting language keyword, an obfuscated scripting language reserved word, or entropy of a string exceeding a second threshold ([0115] One such attack creates large number of objects to exploit an opportunity. This could be simply caught by counting number of CreateElement executions and flag if the count is above threshold. [0116] Second pattern: Large memory write with Unicode characters [0117] Decoded/Deobfuscatedcontents: fromCharCode( ), unescape( ) functions are traced that are highly used by attackers today to decode contents at some point. [0118] Document.write attacks: Check the contents javascript is about to dynamically write on the page. Heurisitics/pattern applied: [0119] iframe 'src' should be pointing the domain other than origin (host) domain. This is rather common, such as in case "widget" like bookmarking appended on the page which are appended dynamically via javascript to iframe. We overcome this by tracing if the iframe contents have been decoded before which is a pretty good indicator of malicous contents. However sometimes these write could be via <script> tag or <img> tag both of which load and pointed contents on page load event itself. [0120] eval: check eval which is javascript evaluation function and executes javascript code passed as a string argument. These contents could be checked for presence of the malicious keywords, or large Unicode strings for shellcode, vulnerable clsid etc. In addition if these contents are decoded before, that gives a pretty good indication of the malicious contents. KEJRIWAL, [0115]-[0120]). Saxe in view of Vincent in view of KEJRIWAL are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Saxe in view of Vincent in view of KEJRIWAL. This would have been desirable because it is the observation of the applicant that most malicious web-based activity involves javascript. Detecting and blocking malicious javascript is essential for preventing web-based compromises. Most malicious javascript is obfuscated, which renders static analysis, such as signature matching, approaches ineffective (KEJRIWAL, [0002]). Claims 14 and 20 have limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Claims 7 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Saxe et al. (US 10,635,813, Filed Oct. 6, 2017), in view of Vasudevan et al. (Cobra: Fine-grained Malware Analysis using Stealth Localized-executions, Proceedings of the 2006 IEEE Symposium on Security and Privacy, 15 pages). As per claim 7, Saxe in view of Vincent teaches the method of claim 1, wherein emulating the execution of the at least the portion of the code comprises emulating execution (Emulation analysis module 104 is communicatively coupled to controller 106, static analysis 102, dynamic analysis module 103, malware classifier 105, and intelligence store 110. In one embodiment, emulation analysis module 104 is configured to emulate operations associated with the processing of a particular specimen in context with an emulated computer application (rather than a "real" application, as may be run in a virtual machine in the dynamic analysis) or in context with an emulated dynamic library. As an optional feature, emulation analysis module 104 may provide the list of functions and other features on which malware checks can be applied in later analyses, and/or information regarding a suitable operating environment to be employed in a virtual machine for dynamic analysis. Vincent, [0047]), but does not teach branches, Vasudevan however teaches one or more branches associated with the portion of the code to cause evaluation of the portion of the code to both true and false cases (In some cases, where block creation terminates because a predefined number of non-CTIs were reached, Cobra treats the block as ending with an unconditional branch/jump instruction and creates a corresponding xfer-stub. Figure 3b shows the xfer-stub implementations for conditional and unconditional CTIs on the IA-32 (and compatible) processors. For unconditional CTIs the corresponding xfer-stub simply performs an unconditional jump (JMP) into the BCXE. For conditional CTIs, the xfer-stub translates a conditional into a conditional and an explicit JMP. This ensures that the BCXE gets control for both situations where the conditional evaluates to true and false. Vasudevan, page 5). Saxe in view of Vincent in view of Vasudevan are analogous art to the claimed invention, because they are from a similar field of endeavor of systems, components and methodologies for providing secure communication between computer systems. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Saxe in view of Vincent in view of Vasudevan. This would have been desirable because This is particularly true with polymorphism [56, 47] and metamorphism [48] that are techniques employed by most if not all current generation malware. Also it is impossible to statically analyze certain situations due to undecidability (eg. indirect branches). Further, static code analysis also has limitations related to code obfuscation, a technique used by malware to prevent their analysis and detection (Vasudevan, page 1). Claim 15 has limitations similar to those treated in the above rejection, and are met by the references as discussed above, and are rejected for the same reasons of obviousness as used above. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLEG KORSAK whose telephone number is (571)270-1938. The examiner can normally be reached on 5:00 AM- 4:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OLEG KORSAK/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Show 13 earlier events
May 21, 2025
Response after Non-Final Action
May 21, 2025
Response after Non-Final Action
Feb 11, 2026
Response after Non-Final Action
Mar 24, 2026
Request for Continued Examination
Mar 27, 2026
Response after Non-Final Action
Apr 01, 2026
Non-Final Rejection mailed — §103, §112
Jun 25, 2026
Response Filed
Jul 10, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694270
TRAINING DETECTION MODEL USING OUTPUT OF LANGUAGE MODEL APPLIED TO EVENT INFORMATION
3y 1m to grant Granted Jul 28, 2026
Patent 12689529
SENSOR SECURED BY PHYSICAL UNCLONABLE FUNCTION (PUF)
3y 3m to grant Granted Jul 21, 2026
Patent 12689629
METHOD FOR VERIFYING SECURITY TECHNOLOGY DEPLOYMENT EFFICACY ACROSS A COMPUTER NETWORK
2y 1m to grant Granted Jul 21, 2026
Patent 12683796
SYSTEMS AND METHODS FOR CRYPTOGRAPHIC AUTHENTICATION OF CONTACTLESS CARDS
2y 11m to grant Granted Jul 14, 2026
Patent 12683935
QUANTUM READY INTELLIGENT SECURITY GATEWAY
2y 9m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
86%
Grant Probability
94%
With Interview (+8.3%)
2y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 968 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month