Prosecution Insights
Last updated: October 01, 2026
Application No. 19/024,667

Systems and methods for intelligent machine learning-based malware detection

Final Rejection §102§103
Filed
Jan 16, 2025
Priority
Apr 07, 2017 — provisional 62/483,102 +4 more
Examiner
WON, MICHAEL YOUNG
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
Zscaler Inc.
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
679 granted / 849 resolved
+22.0% vs TC avg
Strong +28% interview lift
Without
With
+28.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
34 currently pending
Career history
884
Total Applications
across all art units

Statute-Specific Performance

§101
8.3%
-31.7% vs TC avg
§103
48.2%
+8.2% vs TC avg
§102
31.2%
-8.8% vs TC avg
§112
8.6%
-31.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 849 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 2. This action is in response to the amendment filed August 11, 2026. 3. Claims 1 and 16 have been amended. 4. Claims 1-20 have been examined and are pending with this action. Response to Arguments 5. Applicant's arguments filed August 11, 2026, with respect to the rejection of claims 1-20, previously rejected under 35 U.S.C. 102(a)(1) and 102(a)(2) as being anticipated by Leddy et al. (US 2020/0067861 A1) have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Peinador et al. (US 2020/0076840 A1). Although Leddy clearly seems to suggest, “packet-based analysis performed before a file is completely received” (for example, see Leddy, [0242], “updating the filter set includes performing an incremental retrain.”, [0259], “This analysis can be performed in real time or within a specific window of time”; and [1151]: “Supervised learning based on curated examples: This takes place, for example, while a system such as system 160 of FIG. 1A, the scam evaluation system of FIG. 1C, and a platform such as platform 1600, is processing a live stream of message traffic. In some embodiments, the system learns by submitting some small subset of messages it encounters to humans for review”, emphasis added), in the interest of expediting prosecution, Peinador has been cited to better teach the amended claim limitation. Please see rejections set forth below. Clearly, it is well-known, routine, and conventional for processing to occur in real-time whereby data is processed by the processor as it is relayed via a network interface which concurrently receives the remaining packet streamed at a particular rate. Executing streaming video downloaded via the Internet is a clear example of such. The selected location of the video begins to be executed, as the remaining video stream is downloaded as it is well-known in the art that a 2 hour movie cannot be downloaded all at one instance. Nonetheless, Peinador explicitly teaches the language missing from Leddy. In response to the argument with respect to dependent claims 3 and 18, new or additional citations have been presented that which better teaches the claim element as pending. In response to the argument with respect to dependent claims 5 and 20, although calculating and applying entropy value is well-known, routine, and conventional with respect to machine-learning and especially ML that incorporates a decision tree such as taught by Leddy, for learning how much uncertainty exist in the data packet or for measuring impurity in a data set, has been cited to better teach the claim limitations of dependent claims 5 and 20. Please see rejection below. In response to the argument with respect to dependent claim 10, Leddy clearly and explicitly discloses, teaches, or in the very least suggests the pending limitations. New citations have been provided to better teach the claim limitations. Please see rejection below. In response to the argument with respect to dependent claim 13, Leddy clearly and explicitly discloses, teaches, or in the very least suggests the pending limitations. Leddy teaches in paragraph [1662], “The machine learning classifier, in one embodiment, implements the following machine learning classifiers: Logistic regression, random forest, SVM and naïve Bayes, respectively”, emphasis added. In response to the argument with respect to dependent claims 2 and 17, additional or new citations have been provided to better teach the claim limitations. Please see rejection below. For these reasons above and the rejections set forth below, claims 1-20 remain rejected and pending. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 6. Claims 1-4 and 6-19 are rejected under 35 U.S.C. 103 as being unpatentable over Leddy et al. (US 2020/0067861 A1) in view of Peinador et al. (US 2020/0076840 A1). INDEPENDENT: As per claim 1, Leddy teaches a method for training a machine learning model for malware detection, the method comprising: collecting a training dataset comprising a plurality of malicious files and a plurality of benign files from one or more sources (see Leddy, [0240]: “Further details regarding collection of (potentially) scam messages are described below. Ham messages (e.g., messages known to not be spam or scam) can also be similarly collected.”; and [0254]: “The collected information can be used for future processing (e.g., for dynamic filter updating/training, as described above).”); extracting features from each file in the training dataset, wherein the features include at least one of n-gram features, entropy features, or domain features (see Leddy, [0063]: “In some embodiments, the filter engine is configured to filter incoming messages using an array of filters. In some embodiments, filtering the messages includes parsing incoming messages and extracting components/features/elements (e.g., phrases, URLs, IP addresses, etc.) from the message for analysis and filtering. In some embodiments, this is done to detect generic fraud-related threats, such as traditional 419 scams or phishing attacks; in other embodiments, it is done to detect specialized attacks, such as business email compromise (BEC), which is also commonly referred to as “CEO scams”. In some embodiments, filter engine 164 is an example of analytics engine 200 of FIG. 2.”; and [0219]: “For example, the extracted URL can be analyzed to determine various characteristics. For example, it can be determined when the extracted URL was formed/registered, for example by performing a “whois” query against an Internet registry, whether the URL is associated with a known brand, whether the URL links to a good/bad page, etc. As one example, if the URL was recently formed/registered and is not associated with a known brand, then the training module can determine that a new rule should be generated for that URL.”); labeling each file in the training dataset as malicious or benign based on a predefined criterion (see Leddy, [0068]: “Supervised learning based on curated examples: This takes place, for example, while a system such as system 160 of FIG. 1A, the scam evaluation system of FIG. 1C, and a platform such as platform 1600, is processing a live stream of message traffic”; [1662]: “This example process implements machine learning classifiers, such as: Logistic regression, random forest, SVM and naïve Bayes, respectively. The processes receive as input TFIDF training and test sets along with their labels as inputs and outputs predicted labels upon the given test set. It first trains the classifier using the given test set and its label, and then predicts the labels of the test set. Once the classifiers have been tested, they are connected to classify the input messages pipelined to the applicable ML classifiers.”; and [1663]: “The machine learning classifier, in one embodiment, implements the following machine learning classifiers: Logistic regression, random forest, SVM and naïve Bayes, respectively. Each method corresponds to a single library included in sklearn library. The programs gets TFIDF train and test sets along with their labels as inputs and outputs predicted labels upon the given test set. It first trains the classifier using the given test set and its label, and then predicts the labels of the test set.”); and applying a supervised machine learning technique to learn patterns in the extracted features and generate a trained machine learning model configured to predict whether a file is malicious or benign based on an incremental packet-based analysis performed before a file is completely received (see Leddy, [0117]: “the training module is configured to generate/author new filter rules. In some embodiments, the training module is configured to determine what new rules should be authored/generated”; [0136]: “In some embodiments, the training module is configured to use machine learning techniques to perform training. For example, obtained messages/communications can be used as training/test data upon which authored rules are trained and refined. Various machine learning algorithms and techniques, such as support vector machines (SVMs), neural networks, etc. can be used to performing the training/updating”; [0242]: “updating the filter set includes a complete retraining of the entire filter set/dynamic updating system/platform. In some embodiments, updating the filter set includes performing an incremental retrain. In some embodiments, the incremental retrain is an optimization that allows for only new changes/updates to be made, thereby reducing system/platform downtime”; [0259]: “This analysis can be performed in real time or within a specific window of time”; [1151]: “Supervised learning based on curated examples: This takes place, for example, while a system such as system 160 of FIG. 1A, the scam evaluation system of FIG. 1C, and a platform such as platform 1600, is processing a live stream of message traffic. In some embodiments, the system learns by submitting some small subset of messages it encounters to humans for review. For example, human reviewers can identify whether messages are scam or not scam”; and [1162]: “The processes receive as input TFIDF training and test sets along with their labels as inputs and outputs predicted labels upon the given test set”). Leddy does not explicitly teach packet-based analysis performed before a file is completely received. Peinador teaches packet-based analysis performed before a file is completely received (see Peinador, [0141]: “In a streaming embodiment that incrementally (i.e. as each packet arrives) analyzes a network flow, threshold 590 may be crossed before the entire flow of packets is received or analyzed.”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Leddy in view of Peinador by implementing packet-based analysis being performed before a file is completely received. One would be motivated to do so because such would enable further processing in real-time as suggested by Leddy in paragraph [0259]: “This analysis can be performed in real time or within a specific window of time”, and paragraph [1151]: “Supervised learning based on curated examples: This takes place, for example, while a system such as system 160 of FIG. 1A, the scam evaluation system of FIG. 1C, and a platform such as platform 1600, is processing a live stream of message traffic. In some embodiments, the system learns by submitting some small subset of messages it encounters to humans for review. For example, human reviewers can identify whether messages are scam or not scam”, thereby avoiding further harm due to a malicious packet. As per claim 16, Leddy and Peinador teach a non-transitory computer-readable medium storing instructions for training a machine learning model for malware detection (see Leddy, Page 92, Claim 20: “A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions…”), the instructions, when executed, cause one or more processors to perform steps of: collecting a training dataset comprising a plurality of malicious files and a plurality of benign files from one or more sources (see Claim 1 rejection above); extracting features from each file in the training dataset, wherein the features include at least one of n-gram features, entropy features, or domain features (see Claim 1 rejection above); labeling each file in the training dataset as malicious or benign based on a predefined criterion (see Claim 1 rejection above); and applying a supervised machine learning technique to learn patterns in the extracted features and generate a trained machine learning model configured to predict whether a file is malicious or benign based on an incremental packet-based analysis performed before a file is completely received (see Claim 1 rejection above). DEPENDENT: As per claim 2 and 17, which respectively depend on claims 1 and 16, Leddy further teaches wherein the collecting the training dataset further comprises: retrieving benign files from at least one reputable public or private data source (see Leddy, [0254]: “In some embodiments, information associated with the results of message evaluation (e.g., as a result of the evaluation using analysis engine 112) is collected and stored to storage 140. The collected information can be used for future processing (e.g., for dynamic filter updating/training, as described above).”; and [0424]: “history of user communications collected by the system while processing communications and detecting scams”; and [0425]: “history of communications from, or with, whitelisted or blacklisted senders”); and retrieving malicious files from at least one malware repository or third-party malware database (see Leddy, [0138]: “Platform 160 can also be implemented using a scalable, elastic architecture and may comprise several distributed components, including components provided by one or more third parties.”; [0219]: “Any other appropriate URL analysis techniques (which may include third party techniques) can be used to determine whether a new rule should be generated for a URL. Thus, based on the analysis of the URL, the message is placed in the yellow bin.”; [0252]: “In other embodiments, the offline analysis tools and admin 150 is implemented using third-party services (e.g., remote third-party services).”; [0800]: “Scam data can be collected from known scam sources through interaction that, in some embodiments, is referred to as “scambaiting.” For scambaiting, attractive looking targets referred to as “honeypots” are created and presented to scammers to contact. These honeypot accounts can be made visible to scammers in a variety of ways”; and [1038]: “In one embodiment, registered third parties can provide information to the scam evaluation system described herein and the information is validated and is dynamically incorporated into Filters and Rules”). As per claim 3 and 18, which respectively depend on claims 1 and 16, Leddy further teaches wherein the extracting features from each file further comprises: converting binary content of at least a portion of the file into a digital representation selected from one of decimal, hexadecimal, or binary (see Leddy, [0426]: “In some embodiments, vulnerabilities can be implemented as a flexible data structure with variable syntax. For example, representing a binary value”; and [1512]: “For these Short Vector messages it may not be possible to definitively match a message with a previously known scam, so instead of returning a binary decision on whether a test message is scam, in some embodiments, a scam score is returned. This score indicates the likelihood of scam and is used with other information about the message such as the sender's reputation or attachment information to make a decision.”); and generating n-gram features by calculating probabilities associated with individual bytes or contiguous groups of bytes of the converted file content (see Leddy, [01659]: “It first divides the given data into train and test datasets, and then builds n-gram feature list of train and test sets using n-gram feature extractor described above. Then it builds TFIDF feature vectors from n-gram feature vectors of train set. For TF weighting, it uses “double normalization K” scheme with the K value of 0.4.”). As per claim 4 and 19, which respectively depend on claims 1 and 16, Leddy further teaches wherein the extracting features from each file further comprises: determining a domain feature by parsing at least one URL or host name within the file (see Leddy, [0063]: “In some embodiments, filtering the messages includes parsing incoming messages and extracting components/features/elements (e.g., phrases, URLs, IP addresses, etc.) from the message for analysis and filtering.”); and calculating a probability that the URL or host name is associated with either malicious or benign content based on previous training data or a domain model (see Leddy, [1413]: “In another embodiment, if the scam training messages have a confidence factor associated with them (e.g, if the first message is classified scam with 90% probability, and the second with 50% probability), then this score can be considered when determining the outcome; for example, the system can return 0.90*55+0.50*55=522.5 as the score.”; and [1865]: “thus producing a probability assessment that the message is designed to deceptively appear to come from a sender that it does not come from.”). As per claim 6, which depends on claim 1, Leddy further teaches wherein the applying the supervised machine learning technique further comprises: splitting the training dataset into a training subset and a validation subset (see Leddy, [0262]: “After emails are obtained, each email can be scored. AE (112) can retain email messages in storage (140) depending, for example, on how messages are triaged. The system can retain all or a subset of emails for subsequent analysis and testing of new Filters and Rule variations.”); and training a classification algorithm selected from the group consisting of decision trees, random forests, gradient boosting, logistic regression, support vector machines, or neural networks, using the training subset (see Leddy, [1446]: “If more scam messages are added to the tree after pruning, the pruning steps must be run again using all ham pruning messages”; and [1501]: “In one embodiment, the Vector Filter uses an Aho-Corasick(AC) tree trained with the scammiest phrases… ”). As per claim 7, which depends on claim 1, Leddy teaches further comprising: validating the trained machine learning model against a validation dataset to determine whether the trained machine learning model satisfies a predefined false positive rate or detection rate threshold (see Leddy, [0120]: “In some embodiments, the false positive testing of the rule against ham is based on a measure of confidence that messages including the parameter for which the rule will filter for will be spam or scam.”; and [1039]: “The system can validate that the account is cured, as described herein, and remove any negative scoring associated with the account in the future”). As per claim 8, which depends on claim 7, Leddy further teaches wherein the validating the trained machine learning model comprises: determining a false positive rate (FPR) of the trained model based on classification outcomes over a validation dataset of benign files (see Leddy, [0120]: “In some embodiments, when authoring new rules, the training module is also configured to determine whether the rule will result in false positives. In some embodiments, false positives are determined based on a check against a ham repository, such as ham repository 178… ”; and [0734]: “In some embodiments, the False Positive thresholds are determined experimentally through iteration and varying across datasets. In one embodiment, all Rules are run against a large set of good messages to detect the rate at which each Rule hits good messages and the Rules are then ordered by the most False Positives... ”); determining a detection rate (DR) of the trained model based on classification outcomes over a validation dataset of malicious files (see Leddy, [0626]: “The rate of scams can be mapped into a score using a simple linear formula.”; [0629]: “The rate of scams can be mapped into a score using a non-linear formula”; and [1022]: “In one embodiment the rate of scam is calculated based on the number of bad versus good messages that were sent from the identified email address, domain, device or hosting service and compared to a threshold before determining that it is a source of scam.”); and comparing the determined FPR and DR to corresponding threshold values specified for the model's operational requirements (see Leddy, [0325]: “In another example, an individual may attempt to forward all his incoming emails to the described system to discover scams, but in some embodiments this is an abuse of the service and the user stops receiving responses after the user has sent messages exceeding a threshold rate (e.g., 12 messages in one hour).”; and [1235]: “Pruning reduces false positive rates (identifying ham as scam) for the system”). As per claim 9, which depends on claim 1, Leddy further teaches wherein the machine learning model is configured to output, for each incremental packet, a probability of maliciousness, and wherein training the model further comprises incorporating packet-level features derived from partial file data into the training dataset (see Leddy, [1413]: “In another embodiment, if the scam training messages have a confidence factor associated with them (e.g, if the first message is classified scam with 90% probability, and the second with 50% probability), then this score can be considered when determining the outcome; for example, the system can return 0.90*55+0.50*55=522.5 as the score.”; Claim 1 and Claim 6 rejections above). As per claim 10, which depends on claim 1, Leddy further teaches wherein the labeling each file in the training dataset as malicious or benign includes: retrieving metadata associated with each file, including at least one of file hash information, scan results from antivirus engines, or known file reputation scores (see Leddy, [0981]: “Reading any metadata available for the images. This can include but is not limited to timestamp, geolocation information, or who took the picture”; [1002]: “If a match is found, the ScamScore for the matching document is applied to the message by the DF”; and [1003]: “against the SDR based on the document metadata contained in the original document—For example, metadata typically contains author information and creation date information, and can also contain revision history and other information depending on the document type”); and assigning a malicious or benign label to each file based on whether the file meets or exceeds a predetermined maliciousness criterion (see Leddy, [0433]: “This can be used to indicate that the system will categorize any communication for this user from the financial Rule Family triggering a Rule hit with Message ScamScore between 1 and 19 as yellow, and delete (categorize as red) any such communication with a Message ScamScore 20 or greater.”; [0986]: “In one embodiment, each scam image is stored in a Scam Image Repository, SIR, and a ScamScore is assigned to the image. The initial ScamScore is assigned from the Message Score when the image was initially found.”; and [1663]: “The machine learning classifier, in one embodiment, implements the following machine learning classifiers: Logistic regression, random forest, SVM and naïve Bayes, respectively. Each method corresponds to a single library included in sklearn library. The programs gets TFIDF train and test sets along with their labels as inputs and outputs predicted labels upon the given test set.”). As per claim 11, which depends on claim 1, Leddy teaches further comprising: augmenting the training dataset with packet-level feature distributions, including segmenting at least some of the files into incremental packets (see Leddy, [0838]: “A repository (308) of {S,V}, which, in some embodiments, are paired scammer messages and responses from the scammer's intended victim, can be assembled from these interactions and can be augmented over time”; and Claim 6 rejection above); extracting features from each packet segment (see Claim 1 rejection above); associating a packet-level label to each packet segment based on the overall file label (see Leddy, [0693]: “Filters can be tested against message sets that have been previously classified into categories. Filters that trigger against the messages in the category can be grouped into a Family associated with that category.”; and [1224]: “Signatures participate in search, and corresponding vectors are looked up in order to associate the signatures with training messages.”); and updating the training of the machine learning model so that it predicts maliciousness at an incremental, per-packet granularity (see Leddy, Abstract: “updating the filter set in response to training triggered by the first message having been determined to have training potential”; and [0064]: “The filter engine can be run in a production mode (e.g., for analyzing messages in a commercial context) or in a test mode (e.g., for performing training). Messages that are processed through the production mode can also be used to perform training/updating.”). As per claim 12, which depends on claim 1, Leddy further teaches wherein the trained machine learning model is optimized to reduce overall time to detect malware by assigning higher weight to features derived from initial packets of a file, thereby enabling an early detection decision for malicious files (see Leddy, [0950]: “Each message is processed separately and a different scam weighting are applied to each section. For example, the older messages in the Message Thread are considered as weaker factors in evaluating the potential for scam”; and [1790]: “The importance of a given factor, including friendly location, can be determined by weights associated with the rules; also, for some users, only a subset of the rules need be active or configured.”). As per claim 13, which depends on claim 1, Leddy further teaches wherein the applying the supervised machine learning technique further comprises employing a random forest model, each tree within the random forest having a set of nodes representing feature decision boundaries and termini representing probability scores, and wherein the random forest's output is a probability of maliciousness averaged across the probability scores of the plurality of decision trees (see Leddy, [0120]: “the rule is tested against a subset (e.g., random subset) of ham”; and [1662]: “This example process implements machine learning classifiers, such as: Logistic regression, random forest, SVM and naïve Bayes, respectively. The processes receive as input TFIDF training and test sets along with their labels as inputs and outputs predicted labels upon the given test set.”). As per claim 14, which depends on claim 1, Leddy teaches further comprising: segmenting at least a portion of each file in the training dataset into multiple incremental packets (see Claim 6 rejection above); associating each incremental packet with a malicious or benign label based on the overall classification of its corresponding file (see Claim 11 rejection above); extracting incremental packet-level features, including n-gram, entropy, or domain features, from each of said incremental packets (see Claim 11 rejection above); and including the incremental packet-level features and associated labels in the training process such that the machine learning model learns to identify maliciousness before all packets of the file are received (see Leddy, [0669]: “These URLs can be personalized on a per-recipient basis, allowing granular collection of statistics of who clicks on high-risk URLs. Similarly, reply-to addresses can be introduced in scam messages before they are delivered, causing any responses from the recipient to go to a service that in turn responds with an explanation or alert, and which allows the collection of statistics”; and [1022]: “In one embodiment the rate of scam is calculated based on the number of bad versus good messages that were sent from the identified email address, domain, device or hosting service and compared to a threshold before determining that it is a source of scam.”). As per claim 15, which depends on claim 1, Leddy further teaches wherein the applying the supervised machine learning technique further comprises: incorporating partial-file scenarios in the training dataset such that the trained model is exposed to malicious and benign packet sequences of varying lengths (see Claim 6 rejection above); assigning higher weighting to features derived from early-arriving packets to improve the model's capacity for early detection of malicious files (see Claim 12 rejection above); and evaluating the trained model on a validation dataset of partial-file packets to measure performance in detecting malicious content incrementally (see Leddy, [1231]: “In training and testing, the automated, adaptive scam evaluation system described herein is asked to process and learn from pre-classified messages. Its performance can be evaluated through standard machine learning techniques. In some embodiments, the system can capture sufficient information for it to be able to describe how the message was processed (for example, what filters processed it, and what they decided), and ultimately, what processing decision was reached (if any)”; and [1257]: “ABCCNLP is a (vectorization for a) test scam message to be used in evaluating system performance”). 7. Claims 5 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Leddy et al. (US 2020/0067861 A1) and Peinador et al. (US 2020/0076840 A1), and still further in view of McLane et al. (US 2019/0007433 A1) As per claim 5 and 20, which respectively depend on claims 1 and 16, Leddy and Peinador do not explicitly teach wherein the extracting features from each file further comprises: calculating an entropy value associated with at least a portion of the file ; and incorporating the entropy value into the machine learning feature vector to characterize the randomness or uniformity of byte distribution in the file content. McLane teaches calculating an entropy value associated with at least a portion of the file (see Peinador, [0101]: “The entropy calculation instructions 403 may be configured to calculate an entropy (e.g., a Shannon entropy) for each of the chunks 402. For example, in FIG. 5, the binary file 310 is used to generate five chunks 402 and the entropy calculation instructions 403 generate data including five of entropy values 404. Entropy values may be calculated using Equation 1… In other implementations, other ranges of entropy values may be used depending on the chunking, how data within each chunk is grouped (e.g., into two hexadecimal values in the example above), and the base of the logarithm that is used to calculate the entropy.”); and incorporating the entropy value into the machine learning feature vector to characterize the randomness or uniformity of byte distribution in the file content (see Peinador, [0004]: “the classifier may be trained using features derived from binary files. Binary files may be executable files or files that contain executable portions in a binary form. Binary files may be processed to generate features by converting the binary files into feature data. The feature data may include a set of characters (e.g., printable characters or entropy indicators) based on the binary files, as described further below. The feature data may be used to generate one or more vectors that are provided as input (e.g., supervised training data) to train a file classifier to determine whether or not particular files contain malware”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Leddy and Peinador in view of McLane so that the extracting features from each file further comprises: calculating an entropy value associated with at least a portion of the file; and incorporating the entropy value into the machine learning feature vector to characterize the randomness or uniformity of byte distribution in the file content. One would be motivated to do so because entropy is well-known, routine, and conventional with respect to machine-learning and especially ML that incorporates a decision tree such as taught by Leddy (see McLane, [1448]: “Scam messages can be tested for false negatives (scams not detected) and ham messages for false positives (“not scam” misclassified as scam). To diagnose false positives and false negatives, the tree is traversed by iterating through the signatures for each email message, looking to see whether it is IN the tree (for a ham message, a false positive) or out of the tree (for a scam message, a false negative).”, emphasis added) and McLane (see McLane, [0089]: “The classifier generation instructions 115 use the supervised training data 224 to generate the file classifier 116. For example, the classifier generation instructions 115 may utilize an automated neural network building process, a support vector machine building process, a gradient descent boosting decision tree building process, or another process to build the file classifier 116 using a machine learning technique.” , emphasis added), for learning how much uncertainty exist in the data packet or for measuring impurity in a data set as taught by McLane (see McLane, [0101]: “Thus, in this implementation, the entropy values (H) range between zero and eight where the maximum entropy (eight) is reached when Pi takes a constant value of 1/256 (i.e., every byte is completely random). In other implementations, other ranges of entropy values may be used depending on the chunking, how data within each chunk is grouped (e.g., into two hexadecimal values in the example above), and the base of the logarithm that is used to calculate the entropy.”, emphasis added). Conclusion 8. For the reasons above, claims 1-20 have been rejected and remain pending. 9. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. 10. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL Y WON whose telephone number is (571)272-3993. The examiner can normally be reached on Wk.1: M-F: 8-5 PST & Wk.2: M-Th: 8-7 PST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas R Taylor can be reached on 571-272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Michael Won/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Jan 16, 2025
Application Filed
May 12, 2026
Non-Final Rejection mailed — §102, §103
Aug 11, 2026
Response Filed
Sep 01, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719878
MAINFRAME AUTHENTICATION AND MONITORING SYSTEM WITH ENHANCED SECURITY
2y 11m to grant Granted Aug 25, 2026
Patent 12719791
Efficient Handling of Fragmented Packets in Multi-Node All-Active Clusters
1y 9m to grant Granted Aug 25, 2026
Patent 12712830
Conversational Artificial Intelligence Regression Ensemble
1y 8m to grant Granted Aug 18, 2026
Patent 12689969
TRANSPORT MECHANISM SELECTION FOR MULTI-ACCESS POINT COORDINATION GROUP (CG)
1y 8m to grant Granted Jul 21, 2026
Patent 12689678
DETERMINING PROCESSING WEIGHTS OF RULE VARIABLES FOR RULE PROCESSING OPTIMIZATION
1y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+28.5%)
2y 11m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 849 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month