Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
2. Applicant’s arguments filed on 07/22/2026, with respect to the 35 U.S.C 103 rejections of claims 2-21 as being unpatentable over U.S. Publication No. 20140137255 hereinafter Wang in view of U.S. Publication No.
20080022281 hereinafter Dubhashi, and further in view of U.S. Publication No.
20190205537 hereinafter Das have been fully considered but are not persuasive.
Applicant states on pg. 12, first paragraph discloses none of the references alone or in combination teach, suggest, or disclose each claim limitation of the independent claims. Independent claim 2 recites collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code. Examiner respectfully disagrees.
Applicant stated Das and Wang fails to teach collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code.
Wang discloses para 0045 discloses step 202 of Fig. 2 “Obtain execution characteristics of the program code according to execution of the instruction. Paragraph 0046 discloses the execution characteristics of the program code include the content of the instruction generated in escape mode from the read-write request generated during execution of the program code, a behavior characteristic of the instruction in the virtual machine supervisor, or a behavior characteristic of the instruction during access to the physical hardware device.
Wang further states “Both a blacklist and a whitelist are stored in the local database of a host computer. The whitelist contains execution characteristics of known normal code.” Fig. 3 paragraph 0074, step 302 discloses If the first comparison result indicates that the execution characteristics are different, the host computer compares the obtained execution characteristics with execution characteristics of known normal code in the whitelist in the local database for a second time.” Wang discloses monitoring execution of an instruction in a virtual machine supervisor, obtaining behavior execution characteristics of the program code, and to further verify does the program code includes malicious code, comparing obtained execution characteristics with execution characteristics of known normal code in the whitelist.
The whitelist contains execution characteristics of known normal code which mean the execution characteristics in the whitelist is not obtained from uncontrolled environment. They are obtained in a controlled environment where known normal code is run and analyzed, either statically or dynamically, to define what “normal” behavior looks like.
Therefore, Wang teaches or suggest collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data (Wang fig. 2) and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code (Wang Fig. 3). For the reasons above, the rejection is maintained.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
3. Claims 2, 4-11, and 13-21 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20140137255 hereinafter Wang in view of U.S. Publication No. 20080022281 hereinafter Dubhashi, and further in view of U.S. Publication No. 20190205537 hereinafter Das.
As per claim 2, Wang discloses:
A method for analyzing received computer data (para 0010 "A method for
detecting malicious code includes: monitoring execution of an instruction in a
virtual machine supervisor of a host computer, where the instruction is generated
in escape mode when a read-write request generated during execution of
program code in a virtual machine of the host computer is delivered to the virtual
machine supervisor; obtaining execution characteristics of the program code
according to execution of the instruction; and comparing the obtained execution
characteristics with pre-stored execution characteristics of known malicious code,
and determining that the program code is malicious code when the obtained
execution characteristics and the pre-stored execution characteristics are the
same."),
the method comprising:
receiving at a computer system a set of computer data that includes
instructions executable before the set of computer data is received by an
intended destination (para 0140 "Optionally, in step 602 illustrated in FIG. 6A or
step 615 illustrated in FIG. 6B, the cluster antivirus device executes the program
code by using the sandboxing technology. The specific mode for obtaining the
execution result includes but is not limited to any one or combination of the
following modes: para 0141 "Mode 1: The program code is executed in the pre-
constructed first sandbox for simulating an environment of a virtual machine
supervisor, and a security state report of the first sandbox is obtained after the
program code is executed. According to mode 1, behaviors of transmitting
malicious code by the virtual machine using the host
computer may be detected.")
collecting behavioral information associated with known good program code during execution of the known good program code (para 0045 “Step 202 of Fig. 2 “Obtain execution characteristics of the program code according to execution of the instruction.” Para 0046 “The execution characteristics of the program code include the content of the instruction generated in escape mode from the read-write request generated during execution of the program code, a behavior characteristic of the instruction in the virtual machine supervisor, or a behavior characteristic of the instruction during access to the physical hardware device.” Para 0071 “Both a blacklist and a whitelist are stored in the local database of a host computer. The whitelist contains execution characteristics of known normal code.” Fig. 3 para 0074 “Step 302, If the first comparison result indicates that the execution characteristics are different, the host computer compares the obtained execution characteristics with execution characteristics of known normal code in the whitelist in the local database for a second time.” Wang discloses monitoring execution of an instruction in a virtual machine supervisor, obtaining behavior execution characteristics of the program code, and to further verify does the program code includes malicious code, comparing obtained execution characteristics with execution characteristics of known normal code in the whitelist.)
identifying whether the contextual information corresponds to behavioral
information associated with known good program code (para 0126 "Step
607: The cluster antivirus device compares the execution characteristics sent by
the host computer with execution characteristics of known normal code in the
whitelist in the extended database; if the execution characteristics are the same
as the execution characteristics of the known normal code in the whitelist, step
608 is performed; if the execution characteristics are different, step 609 is
performed."):
and providing the set of computer data to the intended destination based
on the comparison result (para 0015 "When the obtained execution
characteristics and the pre-stored execution characteristics are different, send
the program code to the cluster antivirus device and receive a determination
result returned by the cluster antivirus device about whether the program code is
malicious code; and the cluster antivirus device is configured to receive the
program code sent by the host computer, execute the program code in a pre-
constructed first sandbox for simulating an environment of a virtual machine
supervisor, and obtain a security state report of the first sandbox after the
program code is executed; and/or execute the program code in a pre-constructed
second sandbox for simulating an environment of a virtual machine, and obtain a
security state report of the second sandbox after the program code is executed;
determine, according to values of preset parameters in the security state report
and a set of preset determination rules, whether the program code is malicious
code, where the determination rules include a parameter value range for at least
one of the preset parameters; and send the determination result to the host
computer.")
Wang does not disclose:
executing instructions included in the set of computer data while
concurrently collecting contextual information relating to behaviors of the set of
computer data
identifying whether an execution time of the instructions corresponds to an
execution time threshold
Dubhashi discloses:
executing instructions included in the set of computer data while
concurrently collecting contextual information relating to behaviors of the set of
computer data (para 0003 "If an operating system creates a sub-process while
executing a given process, then this sub-process is called the 'child process' of
the given process, which in turn is called the 'parent process'. In particular, when
a child process is created, it can communicate with its parent process through an
allotted communication channel, to send and receive information regarding the
tasks that need to be performed." para 0008 "Further, the parent process waits
for a child process termination notification from the API of the operating system,
which indicates the termination of a child process. On receiving the child process
termination notification, the parent process refuses communication with the child
process and closes the RPC communications endpoint. While waiting for the
child process termination notification, the parent process may receive a child-
initiated request for communication. The requestor- initiated request includes a
requesting process identifier. In order to verify the identity of the requestor, the
parent process queries the operating system fora spawned child process
identifier. On receiving the spawned child process identifier from the operating
system, the parent process compares the requestor process identifier with the
spawned child process identifier.")
Therefore, it would have been obvious to one of ordinary skill in the art
before the effective filing date of the claimed invention to modify the method for
detecting malicious code of Wang to include executing instructions included in
the set of computer data while concurrently collecting contextual information
relating to behaviors of the set of computer data, as taught by Dubhashi.
The motivation would have been to properly validate/filter parent and child
processes.
Wang in view of Dubhashi does not disclose:
identifying whether an execution time of the instructions corresponds to an
execution time threshold
Das discloses:
identifying whether an execution time of the instructions corresponds to an
execution time threshold (para 0021 "The present disclosure is directed to
monitoring internal process memory of a computer at a time with program code
executes. Methods and apparatus consistent with the present disclosure monitor
the operation of program code (executable code or application program code, for
example) with the intent of detecting whether program inputs may exploit
vulnerabilities that may exist in the program code at runtime. By detecting
suspicious activity or malicious code that may affect internal process memory at
run-time, methods and apparatus described herein identify suspected malware
based on suspicious actions performed as program code executes." Para 0039
" When a TEB stores information relating to memory addresses that are known to
be associated with a normal (or expected) memory address range, the
information in the TEB may effectively be used to set boundaries when
identifying whether certain commands correspond with normal or expected
program activity or whether program functions/actions do not correspond to
abnormal program activity that may be associated with suspicious or malicious
code. When a stack pointer points to a memory address that are outside of a
known stack memory address range accessed by a set of program code, the
received computer information relating to that set of program code may be
identified attempting to exploit a vulnerability/flaw/bug in that set of program
code." Para 0040 "Normal or expected program code operation may be
associated with a set of contextual data that identifies boundaries of program
code activity. For example, when a process of an application program has been
allocated a certain specific memory region for storing executable code, and
instrumentation code observes that that application program is attempting to
access executable code in a memory location outside of that certain specific
memory region, that application program could be identified as acting
abnormally." Para 0046 "In certain instances, instrumentation code
(i.e., probe) may be used to identify sets of normal or expected program code
activity by executing that program code after various known good inputs are
provided to that program code. In such an instance, the instrumentation code
could collect context information related to "exploit free" program code operation.
As such, normal/expected program code operation may be associated with a set
of exploit free context information that is stored in a database. In such instances,
this exploit free context information may be used to identify one or more sets of
expected program code activity. The gathering of this exploit free information or
the analysis of that information may be used to train instrumentation and analysis
code to detect abnormal program behavior. Because of this the scope of
"expected" actions of a set of program code may be learned. Whenever
unexpected behavior is observed, subsequent analysis of that program activity
may be used to identify whether an application program is vulnerable or may be
used to train instrumentation code to identify normal program code activity more
comprehensively. In instances where vulnerabilities are identified, information
gathered by the instrumentation code may be used to immunize (patch or fix) that
program code from that exploit before a computer or computer data are exploited
by a previously unknown vulnerability (paragraph 0046) " Para 0042 "When
step 230 does not identify that a pointer has been changed inappropriately,
program flow may move to step 240 that identifies whether parameters
associated with the received computer information command a write to a memory
location that crosses a boundary condition.")
Therefore, it would have been obvious to one of ordinary skill in the art
before the effective filing date of the claimed invention to modify the method for
detecting malicious code of Wang in view of Garman to include identifying
whether an execution time of the instructions corresponds to an execution time
threshold, as taught by Das.
The motivation would have been to detect exploits at runtime in order to
properly validate/filter parent and child processes.
As per claim 4, Wang in view of Dubhashi and Das discloses:
The method of claim 2, wherein the behavioral information associated with
the known good program code includes system state data and action data (Das
para 0025 "The instrumentation code can remain entirely transparent to an
application that it's been injected into, the instrumentation code may be used to
pass context information relating to the behavior of that software application as it
executes in real-time. As such, processes performed by an application program
may be monitored by a processor executing code that analyzes what the
application program does by reviewing the context information passed from the
instrumentation code. This context information includes, yet is not limited to the
content of certain computer registers, parameters associated with a process
performed by a processor executing code of the application, the content of
certain memory locations, information that relates to the state of a memory, or
information relating to the allocation of memory or other potentially malicious
actions. Analysis of an application at runtime using binary instrumentation makes
it possible to gain insight into the behavior of a particular application including
internal central processing unit (CPU) registers and memory state of the
application throughout its execution." Though Wang in view of Dubhashi
discloses behavioral information, Das discloses behavioral information
associated with the known good program code includes system state data
and action data. The motivation would have been to detect exploits at
runtime in order to properly validate/filter parent and child processes.)
As per claim 5, Wang in view of Dubhashi and Das discloses:
The method of claim 4, wherein the action data associated with the known
good program code pertains to generation of graphical user interface (GUI) that
includes information associated with receiving a user response (Das para 00654
"Yet another potential exploit is related to the operation of a JAVA virtual
machine (JVM). Java language provides legitimate methods to create child
processes, but access to that interface is guided by the policies defined on the
domain where the java code is executing. This domain policy is enforced by a
component of the JVM called an access manager. In certain instances, a JVM
exploit may disable this access manager via a vulnerability after which malicious
code may use a legitimate child process creation interface to create a child
process that includes malware. In such an instance, there is no shellcode to
detect. Hence, a probe may be designed to independently detect whether a
domain policy originally relating to an originally disabled creation process is
accessed and may identify whether an access manager has been disabled. As
such, the accessing of an access manager function relating to a previously
disabled creation process may be indicative of the presence of malware."
Though Wang in view of Dubhashi discloses behavioral information, Das
discloses wherein the action data associated with the known good program
code pertains to generation of graphical user interface (GUI) that includes
information associated with receiving a user response. The motivation
would have been to detect exploits at runtime in order to properly
validate/filter parent and child processes.)
As per claim 6, Wang in view of Dubhashi and Das discloses:
The method of claim 4, wherein the system state data includes at least
one of memory access patterns, a state of memory, a state of a process, a
content of one or more memory locations, a content of one or more CPU
registers, or a change in an operating system file data (Das para 0025 "The
instrumentation code can remain entirely transparent to an application that it's
been injected into, the instrumentation code may be used to pass context
information relating to the behavior of that software application as it executes in
real-time. As such, processes performed by an application program may be
monitored by a processor executing code that analyzes what the application
program does by reviewing the context information passed from the
instrumentation code. This context information includes, yet is not limited to the
content of certain computer registers, parameters associated with a process
performed by a processor executing code of the application, the content of
certain memory locations, information that relates to the state of a memory, or
information relating to the allocation of memory or other potentially malicious
actions. Analysis of an application at runtime using binary instrumentation makes
it possible to gain insight into the behavior of a particular application including
internal central processing unit (CPU) registers and memory state of the
application throughout its execution." Though Wang in view of Dubhashi
discloses behavioral information, Das discloses wherein the system state
data includes at least one of memory access patterns, a state of memory, a
state of a process, a content of one or more memory locations, a content of
one or more CPU registers, or a change in an operating system file data.
The motivation would have been to detect exploits at runtime in order to
properly validate/filter parent and child processes.)
As per claim 7, Wang in view of Dubhashi and Das discloses:
The method of claim 2, wherein the set of computer data is executed by a
first process, and wherein the contextual information is collected by a second
process that uses one or more probes to monitor behaviors of the instructions in
the set of computer data being executed by the first process (Dubhashi para
0003 "If an operating system creates a sub-process while executing a given
process, then this sub-process is called the 'child process' of the given process,
which in turn is called the 'parent process'. In particular, when a child process is
created, it can communicate with its parent process through an allotted
communication channel, to send and receive information regarding the tasks that
need to be performed." para 0008 "Further, the parent process waits for a child
process termination notification from the API of the operating system, which
indicates the termination of a child process. On receiving the child process
termination notification, the parent process refuses communication with the child
process and closes the RPC communications endpoint. While waiting for the
child process termination notification, the parent process may receive a child-
initiated request for communication. The requestor- initiated request includes a
requesting process identifier. In order to verify the identity of the requestor, the
parent process queries the operating system fora spawned child process
identifier. On receiving the spawned child process identifier from the operating
system, the parent process compares the requestor process identifier with the
spawned child process identifier." Though Wang discloses behavioral
information, Dubhashi discloses wherein the set of computer data is
executed by a first process, and wherein the contextual information is
collected by a second process. The motivation would have been to detect
exploits at runtime in order to properly validate/filter parent and child
processes.) and (Das para 0052 "Another form of malicious attack that can be
detected using probes and instrumentation code is by identifying that program
code is about to be executed out of a temporary directory. When malicious code
is identified as being executed out of a temporary directory, potential malicious
activity may be identified based on that executable code being present in the
temporary directory. Here again, potentially malicious code may be identified
before or during execution of that potentially malicious code." Para 0043 "In yet
other instances, ROP attacks may pivot a stack pointer to point to a memory
location that is still included within an expected range of memory addresses. In
such instances, the malicious code identification technique that identifies a "stack
pivot" attack by identifying inappropriate memory accesses could fail to detect
malware. In such instances, a probe that reviews contents of the stack pointer
and the content of a frame pointer may be used to detect malware. Since, in
assembly level programming the stack pointer and the frame pointer often work
in unison to create space for local function variables, the stack pointer, the frame
pointer, and function variables can be used to identify possible malicious activity.
As such, the stack pointer and the frame pointer may be used when performing a
sanity check on stack operations and locations where stack variables are stored.
Such a "stack sanity" probe can be used when back tracing these stack frames."
Though Wang in view of Dubhashi discloses behavioral information, Das
discloses process that uses one or more probes to monitor behaviors of
the instructions in the set of computer data being executed by the first
process. The motivation would have been to detect exploits at runtime in
order to properly validate/filter parent and child processes).
As per claim 8, Wang in view of Dubhashi and Das discloses:
The method of claim 7, further comprising generating the second process
based on the first process, wherein the second process is associated only with
the first process. (Dubhashi para 0003 and 0022 "The RPC communications
endpoint is a network-specific address that can be used by a process to
communicate with other processes on the same or different computer systems in
a network. Further, the process responses can be communicated between parent
process 104 and child processes for a certain task." Though Wang discloses
behavioral information, Dubhashi generating the second process based on
the first process, wherein the second process is associated only with the
first process. The motivation would have been to properly validate/filter
parent and child processes).
As per claim 9, Wang in view of Dubhashi and Das discloses:
The method of claim 2, further comprising: identifying that contextual
information relating to behaviors of a second set of computer data does not
correspond to the behavioral information of the known good program code (Das
para 0026 "As such, a set of program code may be associated with a first set of
contextual information and analysis code may be associated with a second set of
contextual information. These different sets of contextual information may be
related to different distinct process of the program code and of a set analysis
code. This may be true even when the analysis code analyzes the real-time
execution of the program code. Analysis code consistent with the present
disclosure may execute as a background task that is an independent process
from a process associated with the execution of program code. In certain
instances, this analysis code may poll memory associated with program code
using techniques associated with a DBI framework. Alternatively or additionally
analysis code may analyze data stored in memory by scanning the contents of
memory with techniques associated with deep packet inspection (DPI). As such,
analysis software may identify malicious or suspicious code via instrumentation
code that matches program code contexts to criteria that is associated with
suspicious code. Furthermore, analysis software may identify malicious code by
matching signatures associated with known malware with data stored in
memory." Though Wang in view of Dubhashi discloses behavioral
information, Das discloses process above. The motivation would have
been to detect exploits at runtime in order to properly validate/filter parent
and child processes);
determining that the second set of computer data includes malware based
on performance of additional testing that allows the second set of computer data
to be run completely (Das Fig. 2, para 0045 "When the stack pointer and frame
pointer contents do not appear to be related to creating or storing variables in an
unusual manner, program flow may move from step 250 to step 260 where
additional tests may be performed when checking to see if a set of received
computer information includes exploitative code." Though Wang in view of
Dubhashi discloses behavioral information, Das discloses process above.
The motivation would have been to detect exploits at runtime in order to
properly validate/filter parent and child processes);
generating one or more signatures of the second set of computer data,
wherein the signatures are associated with the determined malware; and
providing the signatures to one or more deep packet inspection (DPI) processes
at a firewall (para 0061 "Once malware has been identified, signatures may be
generated from the packet data for future use by processors that perform a DPI
function. Sandboxing and DPI may be performed in parallel, thus detecting
malware that has not been previously identified may be identified by a
"Sandboxing" technique or detecting malware that has been previously identified
may be identified via matching DPI techniques." Para 0064 " Further analysis
may also identify what malicious acts are performed by program code. In certain
instances, signatures may be generated from the reorganized data or from
received computer information associated with a set of program code. These
signatures may then be used by a deep packet inspection (DPI) engine when
identifying potentially malicious code." Also see paragraph 0066. Though
Wang in view of Dubhashi discloses behavioral information, Das discloses
process above. The motivation would have been to detect exploits at
runtime in order to properly validate/filter parent and child processes).
As per claim 10, Wang in view of Dubhashi and Das discloses:
The method of claim 2, further comprising classifying a second set of
computer data as suspicious based on an associated execution time relative to
the execution time threshold (Das para 0021 "The present disclosure is directed
to monitoring internal process memory of a computer at a time with program
code executes. Methods and apparatus consistent with the present disclosure
monitor the operation of program code (executable code or application program
code, for example) with the intent of detecting whether program inputs may
exploit vulnerabilities that may exist in the program code at runtime. By detecting
suspicious activity or malicious code that may affect internal process memory at
run-time, methods and apparatus described herein identify suspected malware
based on suspicious actions performed as program code executes." Para 0026
" As such, a set of program code may be associated with a first set of contextual
information and analysis code may be associated with a second set of contextual
information. These different sets of contextual information may be related to
different distinct process of the program code and of a set analysis code. This
may be true even when the analysis code analyzes the real-time execution of the
program code. Analysis code consistent with the present disclosure may execute
as a background task that is an independent process from a process associated
with the execution of program code. In certain instances, this analysis code may
poll memory associated with program code using techniques associated with a
DBI framework. Alternatively or additionally analysis code may analyze data
stored in memory by scanning the contents of memory with techniques
associated with deep packet inspection (DPI). As such, analysis software may
identify malicious or suspicious code via instrumentation code that matches
program code contexts to criteria that is associated with suspicious code.
Furthermore, analysis software may identify malicious code by matching
signatures associated with known malware with data stored in memory." Para
0039 " When a TEB stores information relating to memory addresses that are
known to be associated with a normal (or expected) memory address range, the
information in the TEB may effectively be used to set boundaries when
identifying whether certain commands correspond with normal or expected
program activity or whether program functions/actions do not correspond to
code. When a stack pointer points to a memory address that are outside of a
known stack memory address range accessed by a set of program code, the
received computer information relating to that set of program code may be
identified attempting to exploit a vulnerability/flaw/bug in that set of program
code. "Though Wang in view of Dubhashi discloses behavioral information,
Das discloses process above. The motivation would have been to detect
exploits at runtime in order to properly validate/filter parent and child
processes);
As per claim 11, the implementation of the method of claim 2 will execute
the non-transitory (Wang paragraph 0205) of claim 11. The claim is
analyzed with respect to claim 2.
As per claim 13, the claim is analyzed with respect to claim 4.
As per claim 14, the claim is analyzed with respect to claim 5.
As per claim 15, the claim is analyzed with respect to claim 6.
As per claim 16, the claim is analyzed with respect to claim 7.
As per claim 17, the claim is analyzed with respect to claim 8.
As per claim 18, the claim is analyzed with respect to claim 9.
As per claim 19, the claim is analyzed with respect to claim 10.
As per claim 20, the implementation of the method of claim 2 will execute
the system of claim 20. The claim is analyzed with respect to claim 2.
As per claim 21, the claim is analyzed with respect to claim 4.
As per claim 23, Wang in view of Dubhashi and Das discloses:
The method of claim 2, further comprising identifying that memory locations accessed by a processor during execution of the instructions included in the set of computer data correspond to memory locations accessed during execution of the known good program code (Das Para 0039 " When a TEB stores information relating to memory addresses that are known to be associated with a normal (or expected) memory address range, the information in the TEB may effectively be used to set boundaries when identifying whether certain commands correspond with normal or expected program activity or whether program functions/actions do not correspond to abnormal program activity that may be associated with suspicious or malicious code. When a stack pointer points to a memory address that are outside of a known stack memory address range accessed by a set of program code, the received computer information relating to that set of program code may be identified attempting to exploit a vulnerability/flaw/bug in that set of program code." Para 0040 "Normal or expected program code operation may be
associated with a set of contextual data that identifies boundaries of program
code activity. For example, when a process of an application program has been
allocated a certain specific memory region for storing executable code, and
instrumentation code observes that that application program is attempting to
access executable code in a memory location outside of that certain specific
memory region, that application program could be identified as acting abnormally." While Wang in view of Dubhashi discloses, Das discloses identifying that memory locations accessed by a processor during execution of the instructions included in the set of computer data correspond to memory locations accessed during execution of the known good program code. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.”).
4. Claims 22 is rejected under 35 U.S.C. 103 as being unpatentable over Wang in view of Dubhashi, and further in view of Das, and further in view of U.S. Publication No. 20190354680 hereinafter De Lima.
As per claim 22, Wang in view of Dubhashi and Das discloses:
The method of claim 2, further comprising identifying that the contextual information (Wang para 0045, 0046, 0071, and 0074)
Wang in view of Dubhashi and Das does not discloses:
contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code, wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system
De Lima discloses:
contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code (para 0019 “As described herein, embodiments can monitor I/O (input/output) and other performance data from multiple operations, programs, and devices to assess whether the behavior exhibited by executing code of the enclave indicates anomalous, and potentially malicious, behavior.” Para 0046 “ Aspects described herein can observe such signatures over time. A signature at one point in time might match that of normal, benign executing code, whereas a later signature at a particular point indicates malicious behavior.”),
wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system (para 0021 “Aspects to detect an enclave workload based on performance counter events. Para 0025 “In this regard, the antivirus software monitors, via the system events, the data input to and output from multiple devices, programs, and systems.” Para 0034 “Pattern group size, for example clock cycles consumed by a processing unit (e.g. a CPU) of the processing system: For instance, an observed spike in CPU utilization but little or no apparent I/O on a thread might be indicative of malicious activity.”)
Therefore, it would have been obvious to one of ordinary skill in the art
before the effective filing date of the claimed invention to modify the method for
detecting malicious code of Wang in view of Garman and Das to include contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code, wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system, as taught by De Lima.
The motivation would have been to identifying malicious code execution of executing subject code of a software enclave of a processing system (De Lima paragraph 0002).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GARY S GRACIA whose telephone number is (571)270-5192. The examiner can normally be reached Monday-Friday 9am-6pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GARY S GRACIA/Primary Examiner, Art Unit 2499