DETAILED ACTION
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
2. Claims 1-20 are pending. Claims 1, 9 and 17 are independent.
3. The IDS submitted on 11/14/2024 has been considered.
Claim Objections
4. Claims 3-5, 11-13, 19 and 20 are objected to as being dependent upon rejected base claims, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Claim Rejections - 35 USC § 103
5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7. Claims 1, 2, 6-10 and 14-18 are rejected under 35 U.S.C. 103 as being unpatentable over Khan (US PG Pub. 2023/0122784) in view of in view of Friedrichs (US PG Pub. 2014/0165203) and further in view of Powers (US PG Pub. 2022/0124069).
As regarding claims 1, 9 and 17, Khan discloses A system, comprising:
a processor [para. 156] configured to:
parse code of a sample including packages and function names [para. 30, 69-70 and 77; generating database of supply chain inventory table 132 and maintaining a dependent package table 128 by parsing CSP data including libraries];
filter standard type packages and vendor type packages from the code of the sample to obtain main type packages [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128], comprising to:
classify the packages of the sample into main type, standard type, and vendor type [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128]; and
filter the standard type packages and the vendor type packages from the packages to obtain the main type packages [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128];
generate a signature using a hash for the sample based on the main type packages [para. 69; calculating signature of the package]; and
Khan does not explicitly disclose that the hash is a fuzzy hash; However, Friedrichs discloses it [para. 51 and 74].
It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Khan’s hash to further comprise a fuzzy hash, as disclosed by Friedrichs, as an alternative hash for determining similarity, instead of determining exact match, between two hash values.
Khan does not explicitly disclose limitation determine whether the sample is malware using the signature and a similarity score threshold; However, Powers discloses it [col. 4 lines 26-41].
It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Khan’s system to further comprise the missing claim limitation, as disclosed by Powers, in order to determine whether there is a malware by determining how close the suspicious score is to a pre-determined threshold of a malware.
Khan also discloses a memory coupled to the processor and configured to provide the processor with instructions [para. 156-157 and 164].
As regarding claims 2, 10 and 18, Khan further discloses The system of claim 1, wherein the parsing of the code of the sample comprises to: parse a table of the sample to extract the packages and the function names [para. 69].
As regarding claims 6 and 14, Powers further discloses The system of claim 1, wherein the determining whether the sample is malware using the signature and the similarity score threshold comprises to: compare the signature with a signature associated with a known malware to obtain a similarity score [col. 4 lines 26-41].
As regarding claims 7 and 15, Powers further discloses The system of claim 6, wherein the determining whether the sample is malware using the signature and the similarity score threshold further comprises to: determine whether the similarity score is equal to or exceeds the similarity score threshold; and in the event that the similarity score is equal to or exceeds the similarity score threshold, determine that the sample is malware [col. 4 lines 26-41].
As regarding claims 8 and 16, Powers further discloses The system of claim 7, wherein the determining whether the sample is malware using the signature and the similarity score threshold further comprises to: determine whether the similarity score is equal to or exceeds the similarity score threshold; and in the event that the similarity score fails to equal or exceed the similarity score threshold, determine that the sample is benign [col. 4 lines 26-41].
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to THONG P TRUONG whose telephone number is (571)270-7905. The examiner can normally be reached on M-F 8:30AM - 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 57127267986798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/THONG TRUONG/
Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433