Prosecution Insights
Last updated: August 06, 2026
Application No. 18/903,975

System And Method For Machine Learning Model Determination And Malware Identification

Final Rejection §103
Filed
Oct 01, 2024
Priority
Jul 31, 2015 — provisional 62/199,390 +4 more
Examiner
JAMSHIDI, GHODRAT
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
BLUVECTOR, INC.
OA Round
2 (Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
525 granted / 605 resolved
+28.8% vs TC avg
Strong +15% interview lift
Without
With
+15.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
14 currently pending
Career history
619
Total Applications
across all art units

Statute-Specific Performance

§101
13.3%
-26.7% vs TC avg
§103
48.4%
+8.4% vs TC avg
§102
7.0%
-33.0% vs TC avg
§112
14.7%
-25.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 605 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 1. The text of those sections of Title 35 U.S.C not included in this section can be found in the prior office action. 2. The prior office actions are incorporated herein by reference. In particular, the observations with respect to claim language, and response to previously presented arguments. Claim 19 has been amended. No claims have been added. No claims have been cancelled. Claims 1-20 are pending. Response to Arguments The terminal disclaimer filed on 04/28/2026 is acknowledged and approved. Therefore, the claim DP rejections have been withdrawn. With regards to prior art rejection of claim 1, Applicant argues “receiving data, as described by Symon, is not equivalent to "receiving first information associated with a first plurality of files associated with a first organization," as claimed. Symon's generic description of receiving data does not specify what kind of data is received or any organization that the data is associated with. And Symon especially does not disclose that the received data is associated with a first plurality of files. Further, training a machine learning detection model for a device using network flows that have been labeled as "normal" or "attack," as described by Symon, is not equivalent to "based on the first information and second information associated with a second plurality of files associated with a second organization, training a machine learning model usable by the second organization for classifying files," as claimed. As an initial matter, Symon's machine learning detection model is trained to detect network intrusions-not to classify files. Examiner respectfully disagrees and asserts the under the broadest reasonable interpretation of the claim, the received data could be in form of data files transmitted from a source (e.g., a first organization). Also, the “support or the IT team” in the reference examining the data traffic could be interpreted as the second organization. As for classifying file, detecting intrusion is basically identifying certain data (e.g., data files) that are classified as unwanted. Therefore, Applicant’s argument is not persuasive. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Christopher T. Symons US 20150067857 (hereinafter Symon) in view of Xian- Sheng Hua US 20160217349 (hereinafter Hua). As per claim 1, Symons teaches: A method comprising: receiving first information associated with a first plurality of files associated with a first organization ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is received" Symons: para. 41); based on the first information and second information associated with a second plurality of files associated with a second organization, training a machine learning model usable by the second organization for classifying files ("The device may identify a sufficient (small) number of network flows that are normal and benign activities on their network. In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network. These known behaviors, the normals, and the attacks, are labeled as such for the device, and the machine-learning detection model for the device is then trained either on a separate, more powerful machine, or on the device itself The deployed device then uses this model to make alerting decisions." Symons: para. 40); Symons does not teach; however, Hua discloses: causing output, by the trained machine learning model, of a classification of at least one file associated with the second organization ("the classifying module 120 may compare the second label resulting from classification with the first label associated with the new positive multimedia data item. Based at least in part on identifying the misclassification, the updating module 208 may adjust at least some of the model vectors. For instance, if the classifying module 120 determines that the new positive multimedia data item is incorrectly classified as the second label, the updating module 208 may scale down the model vector associated with the second label and may scale up the model vector associated with the first label." Hua: para. 58). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Symons with the teaching of Hua to meet the preceding limitations. One of ordinary skill in the art would have been motivated to make such modification since such techniques were known at the time of the instant invention and would be applied to further refine the classifier (Hua para. 58). As per claim 2, the rejection of claim 1 is incorporated herein. Symons does not teach; however, Hua discloses: the first information comprises a first feature vector representation of the first plurality of files, and wherein the first feature vector representation comprises non-sensitive data associated with the first organization (Hau: para. 97). As per claim 3, the rejection of claim 1 is incorporated herein. Symons teaches: the first plurality of files is associated with a first plurality of adjudicated classifications ("In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network." Symons: para. 40). As per claim 4, the rejection of claim 1 is incorporated herein. Symons teaches: the training uses at least a portion of each of the first information and the second information to form a training data set, the method further comprising: receiving an indication of an amount of each portion of each of the first information and the second information to be used in the training data set ("Selected semi-supervised learning may depend on the choice of features, choice of event definition, etc. In this disclosure an event is any collection of features that quantify what has occurred in a network, on a host, etc. over a specified period of time. The time period may be an n-second time window or may be based on the period in which a network connection is sustained." Symons: para. 14). As per claim 5, the rejection of claim 1 is incorporated herein. Symons teaches: the first information indicates at least one of a file header property, a component of a file, or a binary sequence (Symons: para. 30). As per claim 6, this claim defines a computing device that corresponds to the method of claim 1 and does not define beyond limitations of claim 1. Therefore, claim 6 is rejected with the same rational as in the rejection of claim 1. As per claim 7, this claim defines a computing device that corresponds to the method of claim 2 and does not define beyond limitations of claim 2. Therefore, claim 7 is rejected with the same rational as in the rejection of claim 2. As per claim 8, this claim defines a computing device that corresponds to the method of claim 3 and does not define beyond limitations of claim 3. Therefore, claim 8 is rejected with the same rational as in the rejection of claim 3. As per claim 9, this claim defines a computing device that corresponds to the method of claim 4 and does not define beyond limitations of claim 4. Therefore, claim 9 is rejected with the same rational as in the rejection of claim 4. As per claim 10, this claim defines a computing device that corresponds to the method of claim 5 and does not define beyond limitations of claim 5. Therefore, claim 10 is rejected with the same rational as in the rejection of claim 5. As per claim 11, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 1 and does not define beyond limitations of claim 1. Therefore, claim 11 is rejected with the same rational as in the rejection of claim 1. As per claim 12, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 2 and does not define beyond limitations of claim 2. Therefore, claim 12 is rejected with the same rational as in the rejection of claim 2. As per claim 13, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 3 and does not define beyond limitations of claim 3. Therefore, claim 13 is rejected with the same rational as in the rejection of claim 3. As per claim 14, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 4 and does not define beyond limitations of claim 4. Therefore, claim 14 is rejected with the same rational as in the rejection of claim 4. As per claim 15, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 5 and does not define beyond limitations of claim 5. Therefore, claim 15 is rejected with the same rational as in the rejection of claim 5. As per claim 16, Symons teaches: A system comprising: receive first information associated with a first plurality of files associated with a first organization ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is received" Symons: para. 41); based on the first information and second information associated with a second plurality of files associated with a second organization, train a machine learning model usable by the second organization for classifying files ("The device may identify a sufficient (small) number of network flows that are normal and benign activities on their network. In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network. These known behaviors, the normals, and the attacks, are labeled as such for the device, and the machine-learning detection model for the device is then trained either on a separate, more powerful machine, or on the device itself The deployed device then uses this model to make alerting decisions." Symons: para. 40); at least one second computer device configured to: send, to the at least one first computing device, the first information ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is received." Symons: para. 41). Symons does not teach; however, Hua discloses: cause output, by the trained machine learning model, of a classification of at least one file associated with the second organization ("the classifying module 120 may compare the second label resulting from classification with the first label associated with the new positive multimedia data item. Based at least in part on identifying the misclassification, the updating module 208 may adjust at least some of the model vectors. For instance, if the classifying module 120 determines that the new positive multimedia data item is incorrectly classified as the second label, the updating module 208 may scale down the model vector associated with the second label and may scale up the model vector associated with the first label." Hua: para. 58). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Symons with the teaching of Hua to meet the preceding limitations. One of ordinary skill in the art would have been motivated to make such modification since such techniques were known at the time of the instant invention and would be applied to further refine the classifier (Hua para. 58). As per claim 17, the rejection of claim 16 is incorporated herein. Symons does not teach; however, Hua discloses: the first information comprises a first feature vector representation of the first plurality of files, and wherein the first feature vector representation comprises non-sensitive data associated with the first organization (Hau: para. 97). As per claim 18, the rejection of claim 16 is incorporated herein. Symons teaches: the first plurality of files is associated with a first plurality of adjudicated classifications ("In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network." Symons: para. 40). As per claim 19, the rejection of claim 16 is incorporated herein. Symons teaches: the training uses at least a portion of each of the first information and the second information to form a training data set, wherein the at least one first computing device is further configured to: receive an indication of an amount of each portion of each of the first information and the second information to be used in the training data set ("Selected semi- supervised learning may depend on the choice of features, choice of event definition, etc. In this disclosure an event is any collection of features that quantify what has occurred in a network, on a host, etc. over a specified period of time. The time period may be an n-second time window or may be based on the period in which a network connection is sustained." Symons: para. 14). As per claim 20, the rejection of claim 16 is incorporated herein. Symons teaches: the first information indicates at least one of a file header property, a component of a file, or a binary sequence (Symons: para. 30). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHODRAT JAMSHIDI whose telephone number is (571)270-1956. The examiner can normally be reached 10:00-6:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 5712723862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GHODRAT JAMSHIDI/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Oct 01, 2024
Application Filed
Feb 02, 2026
Non-Final Rejection mailed — §103
Apr 28, 2026
Response Filed
Jul 02, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12670759
Digital Certificate and Reservation
1y 11m to grant Granted Jun 30, 2026
Patent 12634136
SHARING CRYPTOGRAPHIC MATERIAL
2y 7m to grant Granted May 19, 2026
Patent 12632529
AUTHENTICATION SYSTEM, AUTHENTICATION METHOD, AND NON-TRANSITORY RECORDING MEDIUM
1y 11m to grant Granted May 19, 2026
Patent 12615157
FACILITY USAGE CONTROL APPARATUS, SYSTEM, METHOD, AND COMPUTER READABLE MEDIUM
2y 5m to grant Granted Apr 28, 2026
Patent 12556407
DIGITAL SIGNATURE
9m to grant Granted Feb 17, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
99%
With Interview (+15.2%)
2y 2m (~4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 605 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month