Prosecution Insights
Last updated: October 04, 2026
Application No. 18/984,089

EARLY FILTERING OF CLEAN FILE USING DYNAMIC ANALYSIS

Final Rejection §103
Filed
Dec 17, 2024
Priority
Dec 03, 2019 — provisional 62/943,134 +2 more
Examiner
GRACIA, GARY S
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Sonicwall Inc.
OA Round
2 (Final)
72%
Grant Probability
Favorable
3-4
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
408 granted / 571 resolved
+13.5% vs TC avg
Strong +48% interview lift
Without
With
+48.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
24 currently pending
Career history
590
Total Applications
across all art units

Statute-Specific Performance

§101
11.9%
-28.1% vs TC avg
§103
65.8%
+25.8% vs TC avg
§102
11.2%
-28.8% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 571 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments 2. Applicant’s arguments filed on 07/22/2026, with respect to the 35 U.S.C 103 rejections of claims 2-21 as being unpatentable over U.S. Publication No. 20140137255 hereinafter Wang in view of U.S. Publication No. 20080022281 hereinafter Dubhashi, and further in view of U.S. Publication No. 20190205537 hereinafter Das have been fully considered but are not persuasive. Applicant states on pg. 12, first paragraph discloses none of the references alone or in combination teach, suggest, or disclose each claim limitation of the independent claims. Independent claim 2 recites collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code. Examiner respectfully disagrees. Applicant stated Das and Wang fails to teach collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code. Wang discloses para 0045 discloses step 202 of Fig. 2 “Obtain execution characteristics of the program code according to execution of the instruction. Paragraph 0046 discloses the execution characteristics of the program code include the content of the instruction generated in escape mode from the read-write request generated during execution of the program code, a behavior characteristic of the instruction in the virtual machine supervisor, or a behavior characteristic of the instruction during access to the physical hardware device. Wang further states “Both a blacklist and a whitelist are stored in the local database of a host computer. The whitelist contains execution characteristics of known normal code.” Fig. 3 paragraph 0074, step 302 discloses If the first comparison result indicates that the execution characteristics are different, the host computer compares the obtained execution characteristics with execution characteristics of known normal code in the whitelist in the local database for a second time.” Wang discloses monitoring execution of an instruction in a virtual machine supervisor, obtaining behavior execution characteristics of the program code, and to further verify does the program code includes malicious code, comparing obtained execution characteristics with execution characteristics of known normal code in the whitelist. The whitelist contains execution characteristics of known normal code which mean the execution characteristics in the whitelist is not obtained from uncontrolled environment. They are obtained in a controlled environment where known normal code is run and analyzed, either statically or dynamically, to define what “normal” behavior looks like. Therefore, Wang teaches or suggest collecting behavioral information associated with known good program code during execution of the known good program code, executing the instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data (Wang fig. 2) and identifying whether the contextual information corresponds to the behavioral information associated with the known good program code (Wang Fig. 3). For the reasons above, the rejection is maintained. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 3. Claims 2, 4-11, and 13-21 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20140137255 hereinafter Wang in view of U.S. Publication No. 20080022281 hereinafter Dubhashi, and further in view of U.S. Publication No. 20190205537 hereinafter Das. As per claim 2, Wang discloses: A method for analyzing received computer data (para 0010 "A method for detecting malicious code includes: monitoring execution of an instruction in a virtual machine supervisor of a host computer, where the instruction is generated in escape mode when a read-write request generated during execution of program code in a virtual machine of the host computer is delivered to the virtual machine supervisor; obtaining execution characteristics of the program code according to execution of the instruction; and comparing the obtained execution characteristics with pre-stored execution characteristics of known malicious code, and determining that the program code is malicious code when the obtained execution characteristics and the pre-stored execution characteristics are the same."), the method comprising: receiving at a computer system a set of computer data that includes instructions executable before the set of computer data is received by an intended destination (para 0140 "Optionally, in step 602 illustrated in FIG. 6A or step 615 illustrated in FIG. 6B, the cluster antivirus device executes the program code by using the sandboxing technology. The specific mode for obtaining the execution result includes but is not limited to any one or combination of the following modes: para 0141 "Mode 1: The program code is executed in the pre- constructed first sandbox for simulating an environment of a virtual machine supervisor, and a security state report of the first sandbox is obtained after the program code is executed. According to mode 1, behaviors of transmitting malicious code by the virtual machine using the host computer may be detected.") collecting behavioral information associated with known good program code during execution of the known good program code (para 0045 “Step 202 of Fig. 2 “Obtain execution characteristics of the program code according to execution of the instruction.” Para 0046 “The execution characteristics of the program code include the content of the instruction generated in escape mode from the read-write request generated during execution of the program code, a behavior characteristic of the instruction in the virtual machine supervisor, or a behavior characteristic of the instruction during access to the physical hardware device.” Para 0071 “Both a blacklist and a whitelist are stored in the local database of a host computer. The whitelist contains execution characteristics of known normal code.” Fig. 3 para 0074 “Step 302, If the first comparison result indicates that the execution characteristics are different, the host computer compares the obtained execution characteristics with execution characteristics of known normal code in the whitelist in the local database for a second time.” Wang discloses monitoring execution of an instruction in a virtual machine supervisor, obtaining behavior execution characteristics of the program code, and to further verify does the program code includes malicious code, comparing obtained execution characteristics with execution characteristics of known normal code in the whitelist.) identifying whether the contextual information corresponds to behavioral information associated with known good program code (para 0126 "Step 607: The cluster antivirus device compares the execution characteristics sent by the host computer with execution characteristics of known normal code in the whitelist in the extended database; if the execution characteristics are the same as the execution characteristics of the known normal code in the whitelist, step 608 is performed; if the execution characteristics are different, step 609 is performed."): and providing the set of computer data to the intended destination based on the comparison result (para 0015 "When the obtained execution characteristics and the pre-stored execution characteristics are different, send the program code to the cluster antivirus device and receive a determination result returned by the cluster antivirus device about whether the program code is malicious code; and the cluster antivirus device is configured to receive the program code sent by the host computer, execute the program code in a pre- constructed first sandbox for simulating an environment of a virtual machine supervisor, and obtain a security state report of the first sandbox after the program code is executed; and/or execute the program code in a pre-constructed second sandbox for simulating an environment of a virtual machine, and obtain a security state report of the second sandbox after the program code is executed; determine, according to values of preset parameters in the security state report and a set of preset determination rules, whether the program code is malicious code, where the determination rules include a parameter value range for at least one of the preset parameters; and send the determination result to the host computer.") Wang does not disclose: executing instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data identifying whether an execution time of the instructions corresponds to an execution time threshold Dubhashi discloses: executing instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data (para 0003 "If an operating system creates a sub-process while executing a given process, then this sub-process is called the 'child process' of the given process, which in turn is called the 'parent process'. In particular, when a child process is created, it can communicate with its parent process through an allotted communication channel, to send and receive information regarding the tasks that need to be performed." para 0008 "Further, the parent process waits for a child process termination notification from the API of the operating system, which indicates the termination of a child process. On receiving the child process termination notification, the parent process refuses communication with the child process and closes the RPC communications endpoint. While waiting for the child process termination notification, the parent process may receive a child- initiated request for communication. The requestor- initiated request includes a requesting process identifier. In order to verify the identity of the requestor, the parent process queries the operating system fora spawned child process identifier. On receiving the spawned child process identifier from the operating system, the parent process compares the requestor process identifier with the spawned child process identifier.") Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method for detecting malicious code of Wang to include executing instructions included in the set of computer data while concurrently collecting contextual information relating to behaviors of the set of computer data, as taught by Dubhashi. The motivation would have been to properly validate/filter parent and child processes. Wang in view of Dubhashi does not disclose: identifying whether an execution time of the instructions corresponds to an execution time threshold Das discloses: identifying whether an execution time of the instructions corresponds to an execution time threshold (para 0021 "The present disclosure is directed to monitoring internal process memory of a computer at a time with program code executes. Methods and apparatus consistent with the present disclosure monitor the operation of program code (executable code or application program code, for example) with the intent of detecting whether program inputs may exploit vulnerabilities that may exist in the program code at runtime. By detecting suspicious activity or malicious code that may affect internal process memory at run-time, methods and apparatus described herein identify suspected malware based on suspicious actions performed as program code executes." Para 0039 " When a TEB stores information relating to memory addresses that are known to be associated with a normal (or expected) memory address range, the information in the TEB may effectively be used to set boundaries when identifying whether certain commands correspond with normal or expected program activity or whether program functions/actions do not correspond to abnormal program activity that may be associated with suspicious or malicious code. When a stack pointer points to a memory address that are outside of a known stack memory address range accessed by a set of program code, the received computer information relating to that set of program code may be identified attempting to exploit a vulnerability/flaw/bug in that set of program code." Para 0040 "Normal or expected program code operation may be associated with a set of contextual data that identifies boundaries of program code activity. For example, when a process of an application program has been allocated a certain specific memory region for storing executable code, and instrumentation code observes that that application program is attempting to access executable code in a memory location outside of that certain specific memory region, that application program could be identified as acting abnormally." Para 0046 "In certain instances, instrumentation code (i.e., probe) may be used to identify sets of normal or expected program code activity by executing that program code after various known good inputs are provided to that program code. In such an instance, the instrumentation code could collect context information related to "exploit free" program code operation. As such, normal/expected program code operation may be associated with a set of exploit free context information that is stored in a database. In such instances, this exploit free context information may be used to identify one or more sets of expected program code activity. The gathering of this exploit free information or the analysis of that information may be used to train instrumentation and analysis code to detect abnormal program behavior. Because of this the scope of "expected" actions of a set of program code may be learned. Whenever unexpected behavior is observed, subsequent analysis of that program activity may be used to identify whether an application program is vulnerable or may be used to train instrumentation code to identify normal program code activity more comprehensively. In instances where vulnerabilities are identified, information gathered by the instrumentation code may be used to immunize (patch or fix) that program code from that exploit before a computer or computer data are exploited by a previously unknown vulnerability (paragraph 0046) " Para 0042 "When step 230 does not identify that a pointer has been changed inappropriately, program flow may move to step 240 that identifies whether parameters associated with the received computer information command a write to a memory location that crosses a boundary condition.") Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method for detecting malicious code of Wang in view of Garman to include identifying whether an execution time of the instructions corresponds to an execution time threshold, as taught by Das. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes. As per claim 4, Wang in view of Dubhashi and Das discloses: The method of claim 2, wherein the behavioral information associated with the known good program code includes system state data and action data (Das para 0025 "The instrumentation code can remain entirely transparent to an application that it's been injected into, the instrumentation code may be used to pass context information relating to the behavior of that software application as it executes in real-time. As such, processes performed by an application program may be monitored by a processor executing code that analyzes what the application program does by reviewing the context information passed from the instrumentation code. This context information includes, yet is not limited to the content of certain computer registers, parameters associated with a process performed by a processor executing code of the application, the content of certain memory locations, information that relates to the state of a memory, or information relating to the allocation of memory or other potentially malicious actions. Analysis of an application at runtime using binary instrumentation makes it possible to gain insight into the behavior of a particular application including internal central processing unit (CPU) registers and memory state of the application throughout its execution." Though Wang in view of Dubhashi discloses behavioral information, Das discloses behavioral information associated with the known good program code includes system state data and action data. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.) As per claim 5, Wang in view of Dubhashi and Das discloses: The method of claim 4, wherein the action data associated with the known good program code pertains to generation of graphical user interface (GUI) that includes information associated with receiving a user response (Das para 00654 "Yet another potential exploit is related to the operation of a JAVA virtual machine (JVM). Java language provides legitimate methods to create child processes, but access to that interface is guided by the policies defined on the domain where the java code is executing. This domain policy is enforced by a component of the JVM called an access manager. In certain instances, a JVM exploit may disable this access manager via a vulnerability after which malicious code may use a legitimate child process creation interface to create a child process that includes malware. In such an instance, there is no shellcode to detect. Hence, a probe may be designed to independently detect whether a domain policy originally relating to an originally disabled creation process is accessed and may identify whether an access manager has been disabled. As such, the accessing of an access manager function relating to a previously disabled creation process may be indicative of the presence of malware." Though Wang in view of Dubhashi discloses behavioral information, Das discloses wherein the action data associated with the known good program code pertains to generation of graphical user interface (GUI) that includes information associated with receiving a user response. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.) As per claim 6, Wang in view of Dubhashi and Das discloses: The method of claim 4, wherein the system state data includes at least one of memory access patterns, a state of memory, a state of a process, a content of one or more memory locations, a content of one or more CPU registers, or a change in an operating system file data (Das para 0025 "The instrumentation code can remain entirely transparent to an application that it's been injected into, the instrumentation code may be used to pass context information relating to the behavior of that software application as it executes in real-time. As such, processes performed by an application program may be monitored by a processor executing code that analyzes what the application program does by reviewing the context information passed from the instrumentation code. This context information includes, yet is not limited to the content of certain computer registers, parameters associated with a process performed by a processor executing code of the application, the content of certain memory locations, information that relates to the state of a memory, or information relating to the allocation of memory or other potentially malicious actions. Analysis of an application at runtime using binary instrumentation makes it possible to gain insight into the behavior of a particular application including internal central processing unit (CPU) registers and memory state of the application throughout its execution." Though Wang in view of Dubhashi discloses behavioral information, Das discloses wherein the system state data includes at least one of memory access patterns, a state of memory, a state of a process, a content of one or more memory locations, a content of one or more CPU registers, or a change in an operating system file data. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.) As per claim 7, Wang in view of Dubhashi and Das discloses: The method of claim 2, wherein the set of computer data is executed by a first process, and wherein the contextual information is collected by a second process that uses one or more probes to monitor behaviors of the instructions in the set of computer data being executed by the first process (Dubhashi para 0003 "If an operating system creates a sub-process while executing a given process, then this sub-process is called the 'child process' of the given process, which in turn is called the 'parent process'. In particular, when a child process is created, it can communicate with its parent process through an allotted communication channel, to send and receive information regarding the tasks that need to be performed." para 0008 "Further, the parent process waits for a child process termination notification from the API of the operating system, which indicates the termination of a child process. On receiving the child process termination notification, the parent process refuses communication with the child process and closes the RPC communications endpoint. While waiting for the child process termination notification, the parent process may receive a child- initiated request for communication. The requestor- initiated request includes a requesting process identifier. In order to verify the identity of the requestor, the parent process queries the operating system fora spawned child process identifier. On receiving the spawned child process identifier from the operating system, the parent process compares the requestor process identifier with the spawned child process identifier." Though Wang discloses behavioral information, Dubhashi discloses wherein the set of computer data is executed by a first process, and wherein the contextual information is collected by a second process. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.) and (Das para 0052 "Another form of malicious attack that can be detected using probes and instrumentation code is by identifying that program code is about to be executed out of a temporary directory. When malicious code is identified as being executed out of a temporary directory, potential malicious activity may be identified based on that executable code being present in the temporary directory. Here again, potentially malicious code may be identified before or during execution of that potentially malicious code." Para 0043 "In yet other instances, ROP attacks may pivot a stack pointer to point to a memory location that is still included within an expected range of memory addresses. In such instances, the malicious code identification technique that identifies a "stack pivot" attack by identifying inappropriate memory accesses could fail to detect malware. In such instances, a probe that reviews contents of the stack pointer and the content of a frame pointer may be used to detect malware. Since, in assembly level programming the stack pointer and the frame pointer often work in unison to create space for local function variables, the stack pointer, the frame pointer, and function variables can be used to identify possible malicious activity. As such, the stack pointer and the frame pointer may be used when performing a sanity check on stack operations and locations where stack variables are stored. Such a "stack sanity" probe can be used when back tracing these stack frames." Though Wang in view of Dubhashi discloses behavioral information, Das discloses process that uses one or more probes to monitor behaviors of the instructions in the set of computer data being executed by the first process. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes). As per claim 8, Wang in view of Dubhashi and Das discloses: The method of claim 7, further comprising generating the second process based on the first process, wherein the second process is associated only with the first process. (Dubhashi para 0003 and 0022 "The RPC communications endpoint is a network-specific address that can be used by a process to communicate with other processes on the same or different computer systems in a network. Further, the process responses can be communicated between parent process 104 and child processes for a certain task." Though Wang discloses behavioral information, Dubhashi generating the second process based on the first process, wherein the second process is associated only with the first process. The motivation would have been to properly validate/filter parent and child processes). As per claim 9, Wang in view of Dubhashi and Das discloses: The method of claim 2, further comprising: identifying that contextual information relating to behaviors of a second set of computer data does not correspond to the behavioral information of the known good program code (Das para 0026 "As such, a set of program code may be associated with a first set of contextual information and analysis code may be associated with a second set of contextual information. These different sets of contextual information may be related to different distinct process of the program code and of a set analysis code. This may be true even when the analysis code analyzes the real-time execution of the program code. Analysis code consistent with the present disclosure may execute as a background task that is an independent process from a process associated with the execution of program code. In certain instances, this analysis code may poll memory associated with program code using techniques associated with a DBI framework. Alternatively or additionally analysis code may analyze data stored in memory by scanning the contents of memory with techniques associated with deep packet inspection (DPI). As such, analysis software may identify malicious or suspicious code via instrumentation code that matches program code contexts to criteria that is associated with suspicious code. Furthermore, analysis software may identify malicious code by matching signatures associated with known malware with data stored in memory." Though Wang in view of Dubhashi discloses behavioral information, Das discloses process above. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes); determining that the second set of computer data includes malware based on performance of additional testing that allows the second set of computer data to be run completely (Das Fig. 2, para 0045 "When the stack pointer and frame pointer contents do not appear to be related to creating or storing variables in an unusual manner, program flow may move from step 250 to step 260 where additional tests may be performed when checking to see if a set of received computer information includes exploitative code." Though Wang in view of Dubhashi discloses behavioral information, Das discloses process above. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes); generating one or more signatures of the second set of computer data, wherein the signatures are associated with the determined malware; and providing the signatures to one or more deep packet inspection (DPI) processes at a firewall (para 0061 "Once malware has been identified, signatures may be generated from the packet data for future use by processors that perform a DPI function. Sandboxing and DPI may be performed in parallel, thus detecting malware that has not been previously identified may be identified by a "Sandboxing" technique or detecting malware that has been previously identified may be identified via matching DPI techniques." Para 0064 " Further analysis may also identify what malicious acts are performed by program code. In certain instances, signatures may be generated from the reorganized data or from received computer information associated with a set of program code. These signatures may then be used by a deep packet inspection (DPI) engine when identifying potentially malicious code." Also see paragraph 0066. Though Wang in view of Dubhashi discloses behavioral information, Das discloses process above. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes). As per claim 10, Wang in view of Dubhashi and Das discloses: The method of claim 2, further comprising classifying a second set of computer data as suspicious based on an associated execution time relative to the execution time threshold (Das para 0021 "The present disclosure is directed to monitoring internal process memory of a computer at a time with program code executes. Methods and apparatus consistent with the present disclosure monitor the operation of program code (executable code or application program code, for example) with the intent of detecting whether program inputs may exploit vulnerabilities that may exist in the program code at runtime. By detecting suspicious activity or malicious code that may affect internal process memory at run-time, methods and apparatus described herein identify suspected malware based on suspicious actions performed as program code executes." Para 0026 " As such, a set of program code may be associated with a first set of contextual information and analysis code may be associated with a second set of contextual information. These different sets of contextual information may be related to different distinct process of the program code and of a set analysis code. This may be true even when the analysis code analyzes the real-time execution of the program code. Analysis code consistent with the present disclosure may execute as a background task that is an independent process from a process associated with the execution of program code. In certain instances, this analysis code may poll memory associated with program code using techniques associated with a DBI framework. Alternatively or additionally analysis code may analyze data stored in memory by scanning the contents of memory with techniques associated with deep packet inspection (DPI). As such, analysis software may identify malicious or suspicious code via instrumentation code that matches program code contexts to criteria that is associated with suspicious code. Furthermore, analysis software may identify malicious code by matching signatures associated with known malware with data stored in memory." Para 0039 " When a TEB stores information relating to memory addresses that are known to be associated with a normal (or expected) memory address range, the information in the TEB may effectively be used to set boundaries when identifying whether certain commands correspond with normal or expected program activity or whether program functions/actions do not correspond to code. When a stack pointer points to a memory address that are outside of a known stack memory address range accessed by a set of program code, the received computer information relating to that set of program code may be identified attempting to exploit a vulnerability/flaw/bug in that set of program code. "Though Wang in view of Dubhashi discloses behavioral information, Das discloses process above. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes); As per claim 11, the implementation of the method of claim 2 will execute the non-transitory (Wang paragraph 0205) of claim 11. The claim is analyzed with respect to claim 2. As per claim 13, the claim is analyzed with respect to claim 4. As per claim 14, the claim is analyzed with respect to claim 5. As per claim 15, the claim is analyzed with respect to claim 6. As per claim 16, the claim is analyzed with respect to claim 7. As per claim 17, the claim is analyzed with respect to claim 8. As per claim 18, the claim is analyzed with respect to claim 9. As per claim 19, the claim is analyzed with respect to claim 10. As per claim 20, the implementation of the method of claim 2 will execute the system of claim 20. The claim is analyzed with respect to claim 2. As per claim 21, the claim is analyzed with respect to claim 4. As per claim 23, Wang in view of Dubhashi and Das discloses: The method of claim 2, further comprising identifying that memory locations accessed by a processor during execution of the instructions included in the set of computer data correspond to memory locations accessed during execution of the known good program code (Das Para 0039 " When a TEB stores information relating to memory addresses that are known to be associated with a normal (or expected) memory address range, the information in the TEB may effectively be used to set boundaries when identifying whether certain commands correspond with normal or expected program activity or whether program functions/actions do not correspond to abnormal program activity that may be associated with suspicious or malicious code. When a stack pointer points to a memory address that are outside of a known stack memory address range accessed by a set of program code, the received computer information relating to that set of program code may be identified attempting to exploit a vulnerability/flaw/bug in that set of program code." Para 0040 "Normal or expected program code operation may be associated with a set of contextual data that identifies boundaries of program code activity. For example, when a process of an application program has been allocated a certain specific memory region for storing executable code, and instrumentation code observes that that application program is attempting to access executable code in a memory location outside of that certain specific memory region, that application program could be identified as acting abnormally." While Wang in view of Dubhashi discloses, Das discloses identifying that memory locations accessed by a processor during execution of the instructions included in the set of computer data correspond to memory locations accessed during execution of the known good program code. The motivation would have been to detect exploits at runtime in order to properly validate/filter parent and child processes.”). 4. Claims 22 is rejected under 35 U.S.C. 103 as being unpatentable over Wang in view of Dubhashi, and further in view of Das, and further in view of U.S. Publication No. 20190354680 hereinafter De Lima. As per claim 22, Wang in view of Dubhashi and Das discloses: The method of claim 2, further comprising identifying that the contextual information (Wang para 0045, 0046, 0071, and 0074) Wang in view of Dubhashi and Das does not discloses: contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code, wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system De Lima discloses: contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code (para 0019 “As described herein, embodiments can monitor I/O (input/output) and other performance data from multiple operations, programs, and devices to assess whether the behavior exhibited by executing code of the enclave indicates anomalous, and potentially malicious, behavior.” Para 0046 “ Aspects described herein can observe such signatures over time. A signature at one point in time might match that of normal, benign executing code, whereas a later signature at a particular point indicates malicious behavior.”), wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system (para 0021 “Aspects to detect an enclave workload based on performance counter events. Para 0025 “In this regard, the antivirus software monitors, via the system events, the data input to and output from multiple devices, programs, and systems.” Para 0034 “Pattern group size, for example clock cycles consumed by a processing unit (e.g. a CPU) of the processing system: For instance, an observed spike in CPU utilization but little or no apparent I/O on a thread might be indicative of malicious activity.”) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method for detecting malicious code of Wang in view of Garman and Das to include contextual information indicates one or more delay operations that are inconsistent with the behavioral information associated with the known good program code, wherein the one or more delay operations include at least one of a sleep instruction, a series of no-operation instructions, setting and decrementing a counter, or processing input device entries when no input device is connected to the computer system, as taught by De Lima. The motivation would have been to identifying malicious code execution of executing subject code of a software enclave of a processing system (De Lima paragraph 0002). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GARY S GRACIA whose telephone number is (571)270-5192. The examiner can normally be reached Monday-Friday 9am-6pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GARY S GRACIA/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Dec 17, 2024
Application Filed
Apr 22, 2026
Non-Final Rejection mailed — §103
Jul 22, 2026
Response Filed
Aug 20, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750243
SYSTEMS AND METHODS FOR PRESERVING PRIVACY OF A REGISTRANT IN A DOMAIN NAME SYSTEM ("DNS")
3y 3m to grant Granted Sep 29, 2026
Patent 12748873
SYSTEMS AND METHODS FOR DATA CLASSIFICATION AND GOVERNANCE
3y 5m to grant Granted Sep 29, 2026
Patent 12743501
DEVICE, METHOD, AND SYSTEM TO DETERMINE AN ACCESS TO A TRUSTED EXECUTION ENVIRONMENT
3y 9m to grant Granted Sep 22, 2026
Patent 12737487
METHOD FOR MANAGING ACCESS TO A FILE FOR NON-VOLATILE MEMORY
1y 6m to grant Granted Sep 15, 2026
Patent 12730915
SYSTEM AND METHOD FOR AUTHENTICATION USING TOKENIZATION OF A RESOURCE PRIOR TO RESOURCE ALLOCATION
3y 3m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+48.0%)
3y 4m (~1y 7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 571 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month