DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 04/07/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Specification
Applicant is reminded of the proper language and format for an abstract of the disclosure.
The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details.
The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided.
The abstract of the disclosure is objected to because the abstracts included legal phraseology (“said”). A corrected abstract of the disclosure is required and must be presented on a separate sheet, apart from any other text. See MPEP § 608.01(b).
Claim Objections
Claim 9 is objected to because of the following informalities: The examiner the acronym “ASCII” without spelling out the acronym at its first occurrence. The Examiner suggest the acronym to be spelled out to recite “American Standard Code for Information Interchange”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 7, 9, 11, 17 and 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 11 and 19 recites the limitation "said script" in line 6. There is insufficient antecedent basis for this limitation in the claim.
Claim 9 recites the limitation "the text" in line 6. There is insufficient antecedent basis for this limitation in the claim.
Claims 7 and 17 use the term “and/or”. This term renders the scope of the claim language unclear because it is not clear whether all of the limitations are required or not, in order to fall within the scope of the claim. The use of "and" in the language would require all the limitations to be present in order to fall within the scope of the claim language. The use of "or" in the language would only require one of the limitations to be present in order to fall within the scope of the claim language. The use of "and/or" makes the applicants intended scope unclear because one of ordinary skill in the art would be unable to determine whether or not all of the listed limitations are required or not. Therefore, the claims are rejected for failing to specifically point out and distinctly claim the subject matter which the inventors regard as the invention.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claim 11 recites identify a file…, determine a plurality of parameter…, analyze the plurality of parameters…, process the identified file…, generate a plurality of hash codes and compare the plurality of generated hash codes.
The limitation identify a file, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “a processor” nothing in the claim element precludes the step from practically being performed in the mind. For example, but for the “the processor” language, “identify” in the context of this claim encompasses the user manually obtaining data. Similarly, the limitations of determine a plurality of parameter…, analyze the plurality of parameters…, process the identified file…, generate a plurality of hash codes and compare the plurality of generated hash codes, as drafted, are processes that, under its broadest reasonable interpretation, covers performance of the limitations in the mind but for the recitation of generic computer components. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim only recites additional element – using a processor to perform the steps. The processor is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function), such that they amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, these additional elements does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
Independent claims 1 and 19 includes limitations similar to the limitations of independent claim 1 and rejected under 3 USC 101 for being directed to abstract idea for similar reasons as discussed above with respect to independent claim 1.
Dependent claims 2-10, 12-18 and 20 do not cure the deficiency of the independent claims and are rejected under 35 USC 101 for being directed to abstract idea.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 6-8, 10-12 and 17-20 of U.S. Patent No. 12,292,985. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are anticipated by the claims of the patent.
Independent claims 1, 12 & 20 of the patent are mapped to claims 1, 5, 11, 15 & 19 of the instant application. Claims 6-7 of the patent are mapped to claims 34, 13-14 & 20 of the patent. Claims 10-11 of the patent are mapped to claims 2, 6-8, 12 & 16-18 of the instant application. Claims 7-8 & 18-19 of the patent are mapped to claims 9-10 of the instant application.
Instant Application No. 19/098,047
US Patent No. 12,292,985
1. A method for detecting harmful scripts, comprising:
1. A method for detecting harmful scripts based on a set of hash codes, the method comprising:
identifying a file that contains a script;
identifying a file containing a script, wherein the identification of the file is performed by analyzing each file of a plurality of files for a presence of a harmful script; generating a summary of the script based on the identified file;
determining a plurality of parameters of the script;
calculating static and dynamic parameters of the generated summary of the script;
analyzing the plurality of parameters of the script using a machine learning model trained to recognize a script programming language of said script;
recognizing a script programming language based on inputting the calculated static parameters and dynamic parameters of the generated summary of the script into a pre-trained machine learning model;
processing the identified file based on the recognized script programming language;
processing the identified file based on the data about the recognized script programming language;
generating a plurality of hash codes from the processed file;
generating a set of hash codes based on a processed file using rules for generating hash codes;
And comparing the plurality of generated hash codes with hash codes of known harmful files to determined if the file contains a harmful script.
and detecting the harmful script when the generated set of hash codes is similar to known harmful sets of hash codes.
Allowable Subject Matter
Claims 1-20 would be allowable if rewritten or amended to overcome the rejection(s) under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), 2nd paragraph, 35 U.S.C 101, Double Patenting and objections set forth in this Office action.
Examiner’s Statement for Indicating Allowable Subject Matter
The following is a statement of reasons for the indication of allowable subject matter: After a fully conducted search and consideration, the prior art either taken alone or in combination neither anticipates nor render obvious to the claimed subject matter of the instant application. The prior art STRANNE (US Pub No. 2011/0154495) discloses automatically generating a genetic signature for a set of malware, comprising parsing (step S11) the malware to identify a set of binary comparable features present in said malware, storing (step S5; step S11) all binary comparable features occurring in said set of malware, determining (step S13, S14) a subset comprising binary comparable features occurring in at least a predetermined portion of all malware in the set, and including (step S15) representations of the binary comparable features in the subset in the genetic signature. (STRANNE, Abstract), Ducau et al. (US Pub No. 2020/0364338) discloses machine learning recognition of portable executable files as malware includes providing training data comprising features of portable executable files and a descriptive information for the portable executable files, the descriptive information comprising a family or type of malware. The method may include training a model using the training data to detect malware. The method may include using the trained model to recognize malware by providing features of a portable executable file as input and providing a threat score and descriptive information as output. (Ducau, Abstract), Ivanov et al. (US Pub No. 2017/0004310) discloses detecting harmful files executed by a virtual stack machine. An example method includes: analyzing a file executable on the virtual stack machine to identify both parameters of a file section of the file and parameters of a function of the virtual stack machine when executing the file; identifying, in a database, at least one cluster of safe files based on the identified parameters of the file section of the file and the identified parameters of the virtual stack machine; creating, using at least one clustering rule, a data cluster based on the identified at least one cluster of safe files; calculating at least one checksum of the created data cluster; and determining that the file executable on the virtual stack machine is harmful if the computed at least one checksum matches a checksum in a database of checksums of harmful files.. (Ivanov, Abstract), Najafirad et al. (US Pub No. 2024/0354424) discloses vulnerability code detection systems and related methods. One such method comprises executing, by a client computing device, a joint RoBERTa and graph convolutional neural network model that is configured to detect a code vulnerability attack on a computing device. The model can analyze the code structure and its connections and identify any irregularities or patterns that could be used to exploit vulnerabilities. Once the GCNN model has analyzed the code, it can provide insights to the user or system administrator about potential vulnerabilities and provide suggested actions to remediate them. Poacher Flow edges are defined to bridge the gap between dynamic and static analysis of source code. As opposed to programming language structure (data flow, control flow, and sequential flow), PF edges are meant to identify program boundaries, potential corner cases, and external checkpoints. This is accomplished by considering the external environment context in which the program operates, including insecure input handling, the use of unsafe functions, SQL injection, or unauthorized code execution that have just recently been discovered by the CWE community in programs of a similar nature. A goal is to bridge the gap between dynamic and static analysis of a program by using PF edges. Specifically, PF edges serve as a connection between the knowledge and patterns learned stochastically from known existing vulnerability patterns using labeled data by incorporating PF edges into the machine learning training procedure. We have identified three categories of PF edges: data processing edges, access control edges, and resource management edges. These edge categories is discussed in detail in the subsections below. Additionally, algorithm in FIG. 3 presents the algorithm to generate all the elements of Poacher Flow Edges. Red (denoted with “4”) edges in block 401 of FIG. 4, shows the poacher flow edges. (Najafirad, Abstract and paragraph 0024), ABDELAZIZ et al. (US Pub No. 2023/0029250) discloses to improve the technological process of programming a computer using a dynamic programming language, generate a first portion of training data which maps types in the dynamic programming language to corresponding functions and methods by performing information retrieval on documentation libraries in the dynamic programming language and/or generate a second portion of training data which maps program variables to the corresponding functions and methods by performing data flow analysis on a plurality of pre-existing programs written in the dynamic programming language. Train a neural network on the first and/or second portions of training data to infer unknown types in the dynamic programming language. Carry out inference with the trained neural network to infer the unknown types. Facilitate programming in the dynamic programming language based on the inferred unknown types. Optionally, execute a resulting program. (ABDELAZIZ, Abstract), KOTA et al. (US Pub No. 2022/0067095) discloses searching, ranking, and recommending script samples using an integrated script-search system that includes programmatically defined script-search operations that are associated with action query-data for intelligent structured and immersive searching of a script repository. The action query-data specifically includes recorded actions of an automation function, where the recorded actions are captured and transformed into action query-data. The action query-data is communicated to an integrated script-search service to cause identification of script search results data including script samples from the script repository. The sample scripts in the repository are stored with metadata and action data associated with a programming language of the application, which support matching the script samples based on the action query-data. Based on the script search results data, integrated script search system functionality can be performed via an interface of the application including providing a relevant sample script as a search result. (KOTA, Abstract) and Seletkiy et al. (US Patent No. 12,273,385) discloses automated malicious code replacement. In one exemplary aspect, a method may comprise scanning for malicious content in a file comprising a script written in an interpretable programming language, wherein the malicious content triggers malicious activity on a computing device that stores the file. The method may comprise detecting a malware injection in the file based on the scanning, wherein the malware injection comprises at least one operator that enables the malicious activity. The method may comprise identifying a benign operator that can replace the at least one operator to prevent execution of the malicious activity without causing a syntax error. The method may comprise updating the file by replacing the at least one operator with the benign operator. (Seletskiy, Abstract), however, the prior art taken alone or in combination fails to teach or suggest “analyzing the plurality of parameters of the script using a machine learning model trained to recognize a script programming language of said script; processing the identified file based on the recognized script programming language ;generating a plurality of hash codes from the processed file; and comparing the plurality of generated hash codes with hash codes of known harmful files to determined if the file contains a harmful script” (as recited in claim 1, 11 & 19). Claims are allowed in light of the above claim limitations when in combination with the remaining claim limitations.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAQUEAL D WADE whose telephone number is (571)270-0357. The examiner can normally be reached M-F 8:00-5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHAQUEAL D WADE-WRIGHT/Primary Examiner, Art Unit 2407