Prosecution Insights
Last updated: October 02, 2026
Application No. 19/088,966

ENTROPY-BASED RANSOMWARE DETECTION

Non-Final OA §101§103
Filed
Mar 24, 2025
Priority
Nov 15, 2021 — continuation of 12/259,977
Examiner
LIN, AMIE CHINYU
Art Unit
Tech Center
Assignee
Commvault Systems Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
260 granted / 308 resolved
+24.4% vs TC avg
Strong +31% interview lift
Without
With
+30.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
12 currently pending
Career history
319
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
46.8%
+6.8% vs TC avg
§102
15.3%
-24.7% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 308 resolved cases

Office Action

§101 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to the communication filed on 05/30/2025. Claim 1 has been canceled. New claims 2-21 have been added. Claims 2-21 are pending. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 12-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claims do not fall within at least one of the four categories of patent eligible subject matter because the claims do not include at least one hardware element in the bodies. Claim 12 recites a client computing device including a volume driver and a data agent; a storage manager; secondary storage; and a secure cloud storage which can all be interpreted as software. Note that the specification does not limit these elements to be hardware only, also the specification paragraphs 34 and 170 state that the claimed client computing device can be a virtual client computing device which is software. Thus, under the broadest reasonable interpretation, these elements can all be software. The claimed invention is directed to non-statutory subject matter, software per se. Dependent claims 13-21 are rejected under same rationale as they do not cure the deficiency of claim 12. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2-10, 12-16, and 18-21 are rejected under 35 U.S.C. 103 as being unpatentable over Adams (US 10,121,003) in view of Graun et al. (US 2020/0089881). Claim 2, Adams teaches: A computer-implemented method for protecting data on a client computing device from ransomware, the computer-implemented method comprising: receiving, at a volume driver executing on the client computing device, an instruction indicating potential ransomware infection; determining, by the volume driver, one or more volumes of the client computing device potentially affected by the potential ransomware infection; (e.g., col. 3 ll. 31-34, “The mere presence of one or more encrypted files does not necessarily indicate that ransomware has been encrypting the files…some of the files 14 will have been encrypted for one or more valid reasons” col. 4 ll. 44-46, “The workstation 18N identifies 230 files having a high entropy value by determining whether the entropy value of each file is greater than a threshold entropy value” col. 5 ll. 9-16, “If an excessive entropy condition is present, such as the number or percentage of files with a high entropy value is larger than would be expected for normal operations (e.g., larger than a threshold value)…it is likely that ransomware is in operation. Therefore, the workstation 18N performs 240 one or more specified action(s) regarding the malware”) restricting, by the volume driver, one or more permissions associated with the one or more volumes of the client computing device potentially affected by the potential ransomware infection; (e.g., col. 5 ll. 26-40,“Performing 240 the specified action(s) regarding the malware may be, for example, one or more of: to lock one or more of the files 14; to make one or more of the files 14 to be read-only; to cause attempted modifications of one or more of the files 14 to be recorded as new or different files, or different versions, so that an original file 14 is not affected but the modified file can be written and stored to allow business operations which require updating and modification of files to continue until the ransomware is removed; to cause a copy of at least some files to be sent to a backup server (not shown); to send an alert to one or more human operators; and/or to postpone or stop any scheduled destruction, erasing, writeover, etc. of backup tapes or files or systems. As mentioned above, the operations of FIG. 2 may also be performed by the server 12”) identifying, by the volume driver, files unaffected by the potential ransomware infection; (e.g., col. 9 ll. 6-8, “If the change is not greater than the threshold value then the file has likely not been encrypted by a ransomware operation”) Adams teaches the client computing device, the determined one or more volumes, the identified unaffected files (see above) and does not appear to explicitly teach but Graun teaches: instructing a data agent executing on a client computing device to back up files from determined one or more volumes to secondary storage resulting in backed-up files comprising both unaffected and potentially affected files; and (e.g., [0056], “untrusted file processing module 202 can make a determination regarding whether the untrusted file is a clean file that is free of malicious content by first moving the untrusted file from the first repository to a third repository, such that the one or more security checks are applied to the untrusted file in the third repository”) instructing the data agent to separately back up identified unaffected files to a secure cloud storage environment. (e.g., [0056], “In one embodiment, the checked file can be moved back as a clean file into the first repository for onward copying to the second repository. In another embodiment, the checked file can be moved as a clean file directly from the third repository to the second repository”) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Graun into the invention of Adams, and the motivation for such an implementation would be for the purpose of ensuring only known good files are made available for access to users (Graun [0007]). Claim 3, Adams-Graun teaches: wherein restricting permissions comprises revoking write permissions for user accounts. (e.g., Adams col. 5 ll. 26-30) Claim 4, Adams-Graun teaches: storing metadata indicating ransomware infection status for each backed-up file. (e.g., Graun [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 2 would apply. Claim 5, Adams-Graun teaches: wherein the metadata is stored in an incident database accessible by a storage manager. (e.g., Graun [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 2 would apply. Claim 6, Adams-Graun teaches: wherein the secure cloud storage environment implements air-gap technology. (e.g., Graun [0071]) Same motivation as presented in claim 2 would apply. Claim 7, Adams-Graun teaches: restoring one or more unaffected files from the secure cloud storage environment to a primary storage location. (e.g., Graun [0073]) Same motivation as presented in claim 2 would apply. Claim 8, Adams-Graun teaches: invoking the volume driver based on a determination by an entropy driver that ransomware infection has occurred. (e.g., Adams col. 4 ll. 44-col. 5 ll. 40) Claim 9, Adams-Graun teaches: wherein the entropy driver identifies ransomware infection based on a comparison between file entropy values and expected entropy thresholds. (e.g., Adams col. 4 ll. 44-col. 5 ll. 25) Claim 10, Adams-Graun teaches: maintaining an entropy database associating file types with expected entropy values and deviation thresholds. (e.g., Adams col. 3 ll. 31-col. 5 ll. 8) Claim 12, Adams teaches: A computer-implemented system for securing data against ransomware infection, comprising: a client computing device including a volume driver and a data agent; (e.g., figs. 7, col. 21 ll. 1-4, 11-30) a storage manager configured to manage backup operations; (e.g., col. 4 ll. 22-24) secondary storage configured to store backup copies of files from the client computing device; and (e.g., col. 5 ll. 34-39) wherein the volume driver is configured to restrict permissions on identified ransomware-affected volumes, instruct the data agent to back up files to the secondary storage. (e.g., col. 5 ll. 26-40) Adams teaches the data agent (see above) and does not appear to explicitly teach but Graun teaches: a secure cloud storage configured to securely store unaffected backup files; instruct the data agent to back up unaffected files to the secure cloud storage. (e.g., [0056], “untrusted file processing module 202 can make a determination regarding whether the untrusted file is a clean file that is free of malicious content by first moving the untrusted file from the first repository to a third repository, such that the one or more security checks are applied to the untrusted file in the third repository. In one embodiment, the checked file can be moved back as a clean file into the first repository for onward copying to the second repository. In another embodiment, the checked file can be moved as a clean file directly from the third repository to the second repository such that the clean file can be accessed by the users of the enterprise network”) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Graun into the invention of Adams, and the motivation for such an implementation would be for the purpose of ensuring only known good files are made available for access to users (Graun [0007]). Claim 13, Adams-Graun teaches: an entropy driver configured to monitor file entropy changes on the client computing device. (e.g., Adams col. 4 ll. 44-col. 5 ll. 40) Claim 14, Adams-Graun teaches: wherein the entropy driver triggers the volume driver upon detecting entropy changes exceeding predetermined thresholds. (e.g., Adams col. 4 ll. 44-col. 5 ll. 25) Claim 15, Adams-Graun teaches: wherein the volume driver stores ransomware infection metadata associated with backed-up files. (e.g., Graun [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 12 would apply. Claim 16, Adams-Graun teaches: wherein the storage manager accesses the ransomware infection metadata to present file infection statuses via a user interface. (e.g., Graun fig. 3, [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 12 would apply. Claim 18, Adams-Graun teaches: wherein the volume driver selectively restricts write permissions on data volumes while preserving permissions on operating system volumes. (e.g., Adams col. 5 ll. 26-40) Claim 19, Adams-Graun teaches: wherein the storage manager provides a user interface enabling restoration of unaffected files from the secure cloud storage. (e.g., Graun fig. 3, [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 12 would apply. Claim 20, Adams-Graun teaches: wherein the data agent creates backup copies in a secure format. (e.g., Graun fig. 3, [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 12 would apply. Claim 21, Adams-Graun teaches: wherein the secondary storage and secure cloud storage environment are provided by separate storage infrastructures. (e.g., Graun [0062]-[0063], [0068], [0070]) Same motivation as presented in claim 12 would apply. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Adams (US 10,121,003) in view of Graun et al. (US 2020/0089881) further in view of Jeon et al. (US 2004/0107357). Claim 11, Adams-Graun teaches wherein the one or more permissions restricted by the volume driver vary (e.g., Adams col. 5 ll. 26-40) and does not appear to explicitly teach but Jeon teaches: vary based on whether a volume of one or more volumes contains operating system data or user data. (e.g., [0041]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Jeon into the invention of Adams-Graun, and the motivation for such an implementation would be for the purpose of protecting and recovering data without using extra hardware so that the computer system can stably operate in an optimal state (Jeon [0008]-[0010]). Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Adams (US 10,121,003) in view of Graun et al. (US 2020/0089881) further in view of Silvert (US 2019/0196981). Claim 17, Adams-Graun teaches the secure cloud storage (see above) and does not appear to explicitly teach but Silvert teaches: employs encryption to secure backed-up files against unauthorized access. (e.g., [0047], [0049], [0060]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Silvert into the invention of Adams-Graun, and the motivation for such an implementation would be for the purpose of providing data backup mechanism which is secure even from evolved malware which have the ability to detect and infiltrate backup devices, while remaining practically useful (Silvert [0004]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 2019/0347415 discloses computer implemented method for protecting data stored in at least one file from being overwritten by malicious code. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIE C LIN whose telephone number is (571)272-7752. The examiner can normally be reached M-F 9:00AM -5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GELAGAY SHEWAYE can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMIE C. LIN/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Mar 24, 2025
Application Filed
Sep 22, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737504
Access Control System and a Data Storage Device
3y 1m to grant Granted Sep 15, 2026
Patent 12739135
METHOD FOR AUTHENTICATING DATA
1y 6m to grant Granted Sep 15, 2026
Patent 12725106
ENDPOINT WITH REMOTELY PROGRAMMABLE DATA RECORDER
2y 0m to grant Granted Sep 01, 2026
Patent 12699764
CERTIFICATE RESILIENCY VALIDATION USING CHAOS ENGINEERING
3y 4m to grant Granted Aug 04, 2026
Patent 12665894
SYSTEMS AND METHODS FOR AUTHENTICATION BROKERING
2y 9m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+30.9%)
2y 8m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 308 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month