DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is a Non-Final Office Action in response to the communication filed on December 11, 2024.
Claims 1-20 have been examined.
Drawings
The drawings filed on December 11, 2024 are acceptable for examination proceedings.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on February 12, 2025 was filed after the mailing date of the application 18/977433 on December 11, 2024. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 101 (CRM Analysis)
Claims 18-20 are directed to “computer program product” and applicant's specification support for said “computer program product” is being limited to a statutory embodiment (See, Specification Para 0071).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-3, and 5-20 are rejected under 35 U.S.C. 103 as being unpatentable over Alexandru Razvan Caciulescu (U.S. Patent Application Publication No.: US 2017/0011214 A1 / or “Caciulescu” hereinafter) in view of Nelson et al. (U.S. Patent Application Publication No.: US 2019/0340103A1 / or “Nelson” hereinafter).
Regarding claim 1, Caciulescu discloses “A computer system comprising” (Para 0006-0007: method, apparatus for testing vulnerability ):
“a processor set; one or more computer-readable storage media” (Para 0008: processor executing computer program on computer readable medium);
“and program instructions stored on the one or more computer-readable storage media to cause the processor set to perform operations comprising” (Para 0008: processor executing computer program on computer readable medium):
“obtaining [system diagnostic data] corresponding to data events associated with an authorized system component of an operating system” (Fig. 6: Step 605; and Para 0074: test is done on an OS);
“determining, based on the [system diagnostic data], at least one parameter format associated with the authorized system component” (Fig. 6: Step 610; and Para 000074: “…service may be running on a different port number or may have a different binary depending on the OS. For this reason, the robot may also determine the environment in which the OS is operating and/or the user level access for the given OS or computing system”);
“configuring a security test based on the at least one parameter format” (Fig. 6: Step 615; and Para 000074: “…the one or more robots simulate the pen test on the OS to identify malicious activity or vulnerable configurations within the OS and/or environment”);
“and performing the security test in association with the authorized system component” (Fig. 6: Step 620; and Para 000074: “…a report is generated for the user. The report identifies the malicious activity or the vulnerable configurations within the operating system”).
But Caciulescu fails to specially disclose obtaining “system diagnostic data” associated an event of an OS.
However, Nelson discloses obtaining “system diagnostic data” associated an event of an OS (Nelson, Para 0030: dump file is read).
It would have been obvious to an ordinary person skilled in the art before the effective filing date of the claimed invention to employ the teachings of obtaining “system diagnostic data” associated an event of an OS of Nelson to the system of Caciulescu to create a system where appropriate data can be collected and the ordinary person skilled in the art would have been motivated to combine to “….present memory content in a format that shows variable values translated from binary into informative structures that include variable names and that display variable values based on the respective data types of the variables” (Nelson, Para 0030).
Regarding claim 2, in view of claim 1, Caciulescu in view of Nelson disclose “wherein the obtaining the system diagnostic data comprises obtaining at least one of system dump data and system log entry data” (Nelson, Para 0030: file dump).
Regarding claim 3, in view of claim 1, Caciulescu in view of Nelson disclose “wherein the obtaining the system diagnostic data comprises obtaining system call traces including parameter data” (Nelson, Para 0008: “…The runtime includes support code which provided dynamic compilation or memory garbage collection services as the traced program executed and the trace was captured. The trace may include a record of native code instructions which were executed by the program…”).
Regarding claim 5, in view of claim 1, Caciulescu in view of Nelson disclose “wherein the obtaining the system call traces comprises obtaining call traces from system log entry interface program (SLIP) traps” (Nelson, Para 0391).
Regarding claim 6, in view of claim 1, Caciulescu in view of Nelson disclose “wherein the obtaining the system diagnostic data comprises obtaining system traces including register status information” (Nelson, Para 0145).
Regarding claim 7, in view of claim 1, Caciulescu discloses “wherein the authorized system component comprises at least one of an authorized service or an authorized program” (Para 0081).
Regarding claim 8, in view of claim 1, Caciulescu in view of Nelson disclose “wherein the obtaining the system diagnostic data comprises: observing a call via a trace facility, the call comprising at least one of a system call or a supervisor call; and recording, at least one of register data passed in association with the call or parameter data passed in association with the call” (Nelson, Abstract).
Regarding claim 9, in view of claim 1, Caciulescu discloses “wherein the determining the at least one parameter format associated with the authorized system component comprises: obtaining a set of values of a parameter associated with the authorized system component; and classifying the parameter into one of a plurality of different parameter types based on the set of values” (Para 0052; and 0055).
Regarding claim 10, in view of claim 9, Caciulescu discloses “wherein the classifying the parameter into one of the plurality of different parameter types comprises: classifying the parameter as a constant value based on the set of values being constant” (Para 0052; and 0055).
Regarding claim 11, in view of claim 9, Caciulescu discloses “wherein the classifying the parameter into one of the plurality of different parameter types comprises: classifying the parameter as a function code based on a variance in the set of values associated with a value range” (Para 0052; and 0055).
Regarding claim 12, in view of claim 9, Caciulescu discloses “wherein the classifying the parameter into one of the plurality of different parameter types comprises: classifying the parameter as a bit flag based on the set of values comprising a set of bit flag values” (Para 0052; and 0055).
Regarding claim 13, in view of claim 9, Caciulescu discloses “wherein the classifying the parameter into one of the plurality of different parameter types comprises: classifying the parameter as a pointer based on a variance in the set of values and the set of values including pointer information” (Nelson, Para 0273: pointer; and 0354).
Regarding claim 14, claim 14 is directed to a method corresponding to the system recited in claim 1. Claim 14 is similar in scope to claim 1, and is therefore, rejected under similar rationale.
Regarding claim 15, claim 15 is directed to a method corresponding to the system recited in claim 9. Claim 15 is similar in scope to claim 9, and is therefore, rejected under similar rationale.
Regarding claim 16, claim 16 is directed to a method corresponding to the system recited in claim 11. Claim 16 is similar in scope to claim 11, and is therefore, rejected under similar rationale.
Regarding claim 17, claim 17 is directed to a method corresponding to the system recited in claim 12. Claim 17 is similar in scope to claim 12, and is therefore, rejected under similar rationale.
Regarding claim 18, claim 18 is directed to a computer program product corresponding to the system recited in claim 1. Claim 18 is similar in scope to claim 1, and is therefore, rejected under similar rationale.
Regarding claim 19, claim 19 is directed to a computer program product corresponding to the system recited in claim 9. Claim 19 is similar in scope to claim 9, and is therefore, rejected under similar rationale.
Regarding claim 20, claim 20 is directed to a computer program product corresponding to the system recited in claim 2. Claim 20 is similar in scope to claim 2, and is therefore, rejected under similar rationale.
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Alexandru Razvan Caciulescu in view of Nelson and in further view of LeCrone et al. (U.S. Patent Publication No.: US 9,170,904 Bl / or “LeCrone” hereinafter).
Regarding claim 4, in view of claim 3, Caciulescu discloses penetration testing to identity malicious or vulnerable configurations of an operating system (Caciulescu, Abstract).
Nelson discloses “…live debugging environment to support trace-based reverse execution” (Nelson, Para 0007).
But Caciulescu and Nelson fail to specially disclose “…obtaining the system call traces comprises obtaining call traces from a general trace facility”.
However, LeCrone discloses “wherein the obtaining the system call traces comprises obtaining call traces from a general trace facility (GTF)” (LeCrone, Col 5: lines 19-37: GTF type trace records).
It would have been obvious to an ordinary person skilled in the art before the effective filing date of the claimed invention to employ the teachings of GTF type traces records of LeCrone to the system of Caciulescu and Nelson to create a system where GTF trace records can be presented where GTF type formatting can be utilized by GTF type formatting utilities (LeCrone, Col 5: lines 19-37) and the ordinary person skilled in the art would have been motivated to combine to share files with multiple systems (LeCrone, Col 7: lines 30-39).
Relevant Prior Arts
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Feng et al. (US 20230325301 A1) discloses “…interpretation engine generates a list of potential bugs that is provided to a machine learning engine (e.g., a reinforcement learning engine) that, iteratively for each potential bug, generates a learned input value range that is narrower than the input value range. The learned input value range is provided to the abstract interpretation engine, which updates the input value range, and to a fuzzer, which limits a search space for generating a set of seeds that is used to identify bugs in the source code” (Abstract).
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULLAH ALMAMUN whose telephone number is (571) 270-3392. The examiner can normally be reached on 8 AM - 5 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ABDULLAH ALMAMUN/Examiner, Art Unit 2431
/LYNN D FEILD/Supervisory Patent Examiner, Art Unit 2431