Prosecution Insights
Last updated: August 17, 2026
Application No. 18/947,986

METHOD AND SYSTEM FOR AUTOMATICALLY GENERATING MALWARE SIGNATURE

Non-Final OA §103
Filed
Nov 14, 2024
Priority
Feb 07, 2022 — continuation of 12/174,959
Examiner
TRUONG, THONG P
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
1y 10m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
408 granted / 495 resolved
+22.4% vs TC avg
Strong +15% interview lift
Without
With
+15.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
16 currently pending
Career history
514
Total Applications
across all art units

Statute-Specific Performance

§101
11.0%
-29.0% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
24.2%
-15.8% vs TC avg
§112
8.3%
-31.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 495 resolved cases

Office Action

§103
DETAILED ACTION 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 2. Claims 1-20 are pending. Claims 1, 9 and 17 are independent. 3. The IDS submitted on 11/14/2024 has been considered. Claim Objections 4. Claims 3-5, 11-13, 19 and 20 are objected to as being dependent upon rejected base claims, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 103 5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 7. Claims 1, 2, 6-10 and 14-18 are rejected under 35 U.S.C. 103 as being unpatentable over Khan (US PG Pub. 2023/0122784) in view of in view of Friedrichs (US PG Pub. 2014/0165203) and further in view of Powers (US PG Pub. 2022/0124069). As regarding claims 1, 9 and 17, Khan discloses A system, comprising: a processor [para. 156] configured to: parse code of a sample including packages and function names [para. 30, 69-70 and 77; generating database of supply chain inventory table 132 and maintaining a dependent package table 128 by parsing CSP data including libraries]; filter standard type packages and vendor type packages from the code of the sample to obtain main type packages [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128], comprising to: classify the packages of the sample into main type, standard type, and vendor type [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128]; and filter the standard type packages and the vendor type packages from the packages to obtain the main type packages [para. 69; separating code-level packages, platform-level packages and vendor packages into each row in the dependent package table 128]; generate a signature using a hash for the sample based on the main type packages [para. 69; calculating signature of the package]; and Khan does not explicitly disclose that the hash is a fuzzy hash; However, Friedrichs discloses it [para. 51 and 74]. It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Khan’s hash to further comprise a fuzzy hash, as disclosed by Friedrichs, as an alternative hash for determining similarity, instead of determining exact match, between two hash values. Khan does not explicitly disclose limitation determine whether the sample is malware using the signature and a similarity score threshold; However, Powers discloses it [col. 4 lines 26-41]. It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Khan’s system to further comprise the missing claim limitation, as disclosed by Powers, in order to determine whether there is a malware by determining how close the suspicious score is to a pre-determined threshold of a malware. Khan also discloses a memory coupled to the processor and configured to provide the processor with instructions [para. 156-157 and 164]. As regarding claims 2, 10 and 18, Khan further discloses The system of claim 1, wherein the parsing of the code of the sample comprises to: parse a table of the sample to extract the packages and the function names [para. 69]. As regarding claims 6 and 14, Powers further discloses The system of claim 1, wherein the determining whether the sample is malware using the signature and the similarity score threshold comprises to: compare the signature with a signature associated with a known malware to obtain a similarity score [col. 4 lines 26-41]. As regarding claims 7 and 15, Powers further discloses The system of claim 6, wherein the determining whether the sample is malware using the signature and the similarity score threshold further comprises to: determine whether the similarity score is equal to or exceeds the similarity score threshold; and in the event that the similarity score is equal to or exceeds the similarity score threshold, determine that the sample is malware [col. 4 lines 26-41]. As regarding claims 8 and 16, Powers further discloses The system of claim 7, wherein the determining whether the sample is malware using the signature and the similarity score threshold further comprises to: determine whether the similarity score is equal to or exceeds the similarity score threshold; and in the event that the similarity score fails to equal or exceed the similarity score threshold, determine that the sample is benign [col. 4 lines 26-41]. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to THONG P TRUONG whose telephone number is (571)270-7905. The examiner can normally be reached on M-F 8:30AM - 5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 57127267986798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /THONG TRUONG/ Examiner, Art Unit 2433 /JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Nov 14, 2024
Application Filed
Aug 04, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701128
Network Authentication Evaluation
2y 5m to grant Granted Aug 04, 2026
Patent 12701135
SYSTEM AND METHOD FOR OMNICHANNEL SOCIAL ENGINEERING ATTACK AVOIDANCE
2y 10m to grant Granted Aug 04, 2026
Patent 12694121
LIMITING A NUMBER OF ILLEGITIMATE INTERRUPTS FROM SWITCHING A CENTRAL PROCESSING UNIT TO A SYSTEM MANAGEMENT MODE
3y 3m to grant Granted Jul 28, 2026
Patent 12695785
PASSIVE DETECTION OF DIGITAL SKIMMING ATTACKS
2y 0m to grant Granted Jul 28, 2026
Patent 12682076
SYSTEMS, APPARATUS AND METHODS FOR AUTOMATICALLY TESTING SECURITY DEVICES
2y 0m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
98%
With Interview (+15.1%)
3y 7m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 495 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month