DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendments
This is a Final office action in response to applicant’s amendment filed on 6/29/2026.
Claims 1, 5-6 are amended. Claims 7-20 are newly added. Claims 1-20 are pending and considered.
The rejections to claims 1-6 under 35 USC 101 directed to abstract idea without significantly more has been withdrawn in light of applicant’s amendment to claims 1, 5-6.
Response to Arguments
Applicant’s argument regarding claim rejection under 35 USC 101, see pages 8-12 of the Remarks filed 6/29/2026 has been fully considered and is persuasive in light of applicant’s amendment. Therefore, the claim rejection under 35 USC 101 has been withdrawn.
Applicant’s argument, see pages 12-14 of the Remarks filed 6/29/2026 with respect to claims rejected under 35 USC 103 over prior arts of record has been fully considered, and asserted moot in view of current office action of new ground of rejection with newly applied prior arts and applicant’s argument is not fully persuasive.
First, applicant amended claims 1, 5-6, reciting “… (ReDoS), which is a cyberattack targeting the source code of a web application”. Prior art Bai is found to teach this limitation.
Applicant argued prior arts of records Peng and Cook does not teach “synthesize a second regular expression that does not satisfy the condition on a basis of the first regular expression”. See pages 12-14 of the Remarks. Examiner acknowledges applicant’s perspective however respectively disagrees.
Under the broadest reasonable interpretation in light of applicant’s Specification, “synthesize” can be interpreted as making/generating/creating/correcting, etc. Applicant’s Specification states, “the synthesis unit 134 performs correction processing on the regular expression extracted from the source code by the extraction unit 131, that is, a regular expression vulnerable to ReDoS” (Specification, [0040]). Cook teaches methods of refinement of static analysis of program code, in particular, by generating code patches that corrects, replaces problematic segments of code by performing regular-expression matching. In this case, generating patch(es) of code is interpreted as “synthesize”. The code patches, therefore, can be interpreted as the “second regular expression that does not satisfy the condition on a basis of the first regular expression”.
See the updated Claim Rejections under 35 USC 103 below.
Applicant’s further argument regarding dependent claims is moot since applicant’s argument is based on assumption that the independent claims are patentable.
Applicant is encouraged to further include innovative features into the independent claims to advance the case.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-3 and 5-6, 8, 13-14, 16-18, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Peng (CN110928793A, hereinafter, “Peng”), in view of Bai et al (“Runtime Recovery of Web Applications under Zero-Day ReDoS Attacks” In 2021 IEEE Symposium on Security and Privacy (SP), pp. 1575-1588. IEEE, 2021, hereinafter, “Bai”), further in view of Cook et al (US11200144B1-IDS, hereinafter, “Cook”).
Regarding claim 1, similarly claim 5, claim 6, Peng teaches:
A correction device comprising: processing circuitry/A correction method executed by a correction device/A non-transitory computer-readable recording medium storing therein a correction program for causing that causes a computer to execute a process (Peng, discloses a regular expression detecting method, device and a computer readable storage medium for detecting regular expression for improved test efficiency and accuracy against ReDoS attack) configured to/the correction method comprising/comprising:
extract a first regular expression from a source code (Refer to Fig. 1 at steps 101-102, and [0027] step 101, reading the file content to be detected based on the file path to be detected… [0030] Specifically, in this embodiment, based on the file attribute of the local embodiment whether the condition of triggering the positive regular expression detection judgment process, triggering the step 101 only under the condition of meeting the judging condition. And [0031] step 102, in the to-be-detected file content extracting target regular expression);
determine whether the first regular expression satisfies a condition indicating that the first regular expression is vulnerable to Regular Expression Denial of Service (ReDoS) ([0032] Specifically, in this embodiment, the regular expression (Regex, Regular Expression) for realizing the data in the text matching check, in the practical application, when the positive writing check of regular expression has defect or not precise, the attacker can be constructed of special character string to large consumption of system resource of the server, the service server is interrupted or stopped, wherein a typical attack mode is regular expression denial of service attack (ReDoS)), which is a cyberattack targeting the source code of a web application (See Bai below for teaching of limitation in bracket above);
While Peng teaches ReDoS but does not specifically teach which is a cyberattack targeting the source code of a web application, in the same field of endeavor Bai teaches:
(ReDoS), which is a cyberattack targeting the source code of a web application (Bai, discloses runtime recovery of web applications under zero-day ReDoS attacks, see [Title]/ [Abstract]. And see I. INTRODUCTION, page 1576, “We have implemented a system prototype of REGEXNET, and integrated it with HAProxy [22], a widely-used software load balancer, and Node.js [23], a popular web application framework. We believe that REGEXNET can be deployed as a fast, first measure for ReDoS recovery, in addition to the slow process of fixing and rolling out the source code update with human engineers”).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Bai in the regular expression detection of Peng by representing REGEXNET in response to ReDoS attacks in source code. This would have been obvious because the person having ordinary skill in the art would have been motivated for runtime recovery of web applications under zero-day ReDoS attacks (Bai, [Abstract], [Introduction]).
While Peng further teaches determining a recommended correction data (refer to Fig. 4 and [0060] In addition, it should also be noted that, after further capable of determining that the regular expression in this embodiment, writing rules based on criteria determining a recommended correction data), Peng-Bai combination does not specifically teach the following, in the same field of endeavor Cook teaches:
and synthesize a second regular expression that does not satisfy the condition on a basis of the first regular expression (Cook, discloses systems and methods for refinement of static analysis of program code for refinement against flaws, security vulnerabilities, see [Abstract]. And [Col. 8 lines 31-33] additional analysis 150 using regular-expression pattern matching (e.g., using the grep tool) may be performed. And [Col. 11 lines 33-41] the static analysis refinement system 100 may automatically generate one or more code patches that corrects one or more problems and may then replace the problematic segment(s) of code with the code patch(es) (i.e., second regular expression), e.g., without user input accepting or rejecting the code patch(es)… the system 100 may thus generate modified program source code 560 that includes one or more code patches to the original code 160).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Cook in the regular expression detection of Peng-Bai by refinement of program code with static analysis. This would have been obvious because the person having ordinary skill in the art would have been motivated to refine program code against flaws and security vulnerabilities (Cook, [Abstract], Background).
Regarding claim 2, similarly claim 13, claim 17, Peng-Bai-Cook combination teaches the correction device according to claim 1, the correction method according to claim 5, the non-transitory computer-readable recording medium according to claim 6,
Peng further teaches: wherein the processing circuitry is further configured to convert the source code into a syntax analysis tree, and extract a regular expression restored on a basis of a variable extracted from the syntax analysis tree as the first regular expression ([0039] In this embodiment one embodiment optionally, regular expression test rule is a standard grammar rule, based on the preset regular expression test rule, the positive target expression to compile accuracy detection comprises: based on the preset standard grammar rules, the target regular expression syntax analysis, regular expressions based on the syntax analysis result detection target writing accuracy).
Regarding claim 3, similarly claim 14, claim 18, Peng-Bai-Cook combination teaches the correction device according to claim 1, the correction method according to claim 5, the non-transitory computer-readable recording medium according to claim 6,
Cook further teaches: wherein the processing circuitry is further configured to: generate a first set that is a set of character strings accepted by the first regular expression and a second set that is a set of character strings rejected by the first regular expression, and synthesize a second regular expression that is a regular expression obtained by replacing range characters in the first regular expression with a predetermined syntax, that is, a regular expression that accepts a character string of the first set and rejects the character string of the second set ([Col. 11 lines 28-37] As shown in FIG. 5, the static analysis refinement system 100 may include a component 140 for automated code patching. In one embodiment, the correction(s) to the source code may be presented to a user as a suggestion, e.g., via a user interface, and user input may be solicited to accept or reject the recommendation. In one embodiment, the static analysis refinement system 100 may automatically generate one or more code patches that corrects one or more problems and may then replace the problematic segment(s) of code with the code patch(es)). Same motivation as presented in claim 1, 5, 6 would apply.
Regarding claim 8, similarly claim 16, claim 20, Peng-Bai-Cook combination teaches the correction device according to claim 1, the correction method according to claim 5, the non-transitory computer-readable recording medium according to claim 6,
Cook further teaches: wherein the processing circuitry is further configured to output the second regular expression ([Col. 11 lines 33-41] the static analysis refinement system 100 may automatically generate one or more code patches that corrects one or more problems and may then replace the problematic segment(s) of code with the code patch(es) (i.e., second regular expression), e.g., without user input accepting or rejecting the code patch(es)… the system 100 may thus generate modified program source code 560 that includes one or more code patches to the original code 160). Same motivation as presented in claim 1, 5, 6 would apply.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Peng Bai-Cook as applied above to claim 1, further in view of Blumenfeld et al (US12101346B1, hereinafter, “Blumenfeld”).
Regarding claim 7, Peng-Bai-Cook combination teaches the correction device according to claim 1,
The combination of Peng-Bai-Cook does not specifically teach, in the same field of endeavor Blumenfeld teaches:
wherein the condition indicating that the first regular expression is vulnerable to ReDoS is that the first regular expression operates in greater than linear time on a regular expression engine with respect to a length of a character string to be matched (Blumenfeld, discloses method for assessing a regular expression for vulnerability to ReDoS attacks, see [Abstract]. And [Col. 2 lines 3-7] ReDoS is an algorithmic complexity attack against regular expression matching. In a ReDOS attack, an adversary submits a string that causes a regex matching algorithm to do quadratic, or even exponential work, relative to the length of the input. And [Col. 7 lines 36-39] Referring to FIG. 3, a hyper-vulnerable NFA 310 (i.e. exponential run-time in the number of repetitions of the vulnerable string) regex is detectable by the disclosed approach).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Blumenfeld in the regular expression detection of Peng-Bai-Cook by assessing a regular expression for vulnerability to ReDoS attacks. This would have been obvious because the person having ordinary skill in the art would have been motivated to assess a regular expression for vulnerability to ReDOS attacks by evaluating a string defined by ordered set of characters from an alphanumeric input device to determine if resource consumption constitutes a ReDOS attack (Blumenfeld, [Abstract], SUMMARY).
Allowable Subject Matter
Claims 4, 9-12, 15, 19 are objected to as being dependent upon a rejected base claim(s), but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims as well as resolving of any outstanding informalities presented in this office action.
The following is a statement of reasons for the indication of allowable subject matter:
Claim 4 (similarly claim 15, claim 19) depends on claim 3 (claim 14, claim 18) which depends on claim 1 (claim 5, claim 6), further specifies “wherein the processing circuitry is further configured to convert the first regular expression into a nondeterministic finite automaton, generate a set of character strings obtained by a path reaching an acceptance state among paths on the nondeterministic finite automaton as the first set, and generate a set of character strings obtained by a path not reaching the acceptance state among the paths on the nondeterministic finite automaton as the second set”.
Claim 9 depends on claim 1, further specifies “wherein the processing circuitry is further configured to synthesize the second regular expression by creating a template in which a range character in the first regular expression is replaced with a placeholder, and assigning a predetermined syntax to the placeholder”.
Claim 10 depends on claim 9, further specifies “wherein the processing circuitry is further configured to search for an assignment of a range character to the placeholder included in the template using a satisfiability modulo theories solver”.
Claim 11 depends on claim 9, further specifies “wherein the processing circuitry is further configured to hold a priority queue of templates in which a template closer to the first regular expression is given a higher priority, and to preferentially extract a template having a highest priority among the templates held in the priority queue”.
Claim 12 depends on claim 4, further specifies “wherein the processing circuitry is further configured to construct the nondeterministic finite automaton using a Thompson construction method, and to replace a backreference in a capture with a regular expression in the capture referred to by the backreference”.
The prior arts identified, Peng, Bai, Cook, Namjoshi, Li, Sullivan, either singularly or in combination fails to anticipate or render obvious the claimed limitations of claims shown above.
Citation of References
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action:
Liu et al (“Revealer: Detecting and exploiting regular expression denial-of-service vulnerabilities" In 2021 IEEE Symposium on Security and Privacy (SP), pp. 1468-1484. IEEE, 2021) discloses methods to model vulnerable regex patterns generated by popular regex engines and craft attack strings accordingly.
Thummalapenta et al (US20100058475A1) discloses method to combine static analysis, source code instrumentation and feedback-guided fuzz testing to automatically detect resource exhaustion denial of service attacks in software and generate inputs of coma for vulnerable code segments.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is
reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL M LEE/Primary Examiner, Art Unit 2436