Prosecution Insights
Last updated: October 02, 2026
Application No. 19/207,599

DETECTING RANSOMWARE IN MONITORED DATA

Non-Final OA §103
Filed
May 14, 2025
Priority
Mar 12, 2021 — provisional 63/160,459 +3 more
Examiner
CATTUNGAL, DEREENA T
Art Unit
Tech Center
Assignee
Commvault Systems Inc.
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
229 granted / 285 resolved
+20.4% vs TC avg
Strong +29% interview lift
Without
With
+29.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
21 currently pending
Career history
309
Total Applications
across all art units

Statute-Specific Performance

§101
8.0%
-32.0% vs TC avg
§103
59.9%
+19.9% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
13.8%
-26.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 285 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status 1.The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting 2. The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper time wise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). 3. Claims 1-20 of the instant application are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-4,9-13,15-17 of U.S. Patent No. 12,333,007; and claims 1-6 and 8-17 of U.S. Patent No. 12,026,252. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the current application encompass the same subject matter as the patent claims, but with obvious wording [such as an information management system includes one or more client computing devices in communication with a storage manager and a secondary storage computing device. The storage manager manages the primary data of the one or more client computing devices and the secondary storage computing device manages secondary copies of the primary data of the one or more client computing devices. Each client computing device may be configured with a ransomware protection monitoring application that monitors for changes in their primary data. The ransomware protection monitoring application may input the changes detected in the primary data into a machine-learning classifier, where the classifier generates an output indicative of whether a client computing device has been affected by malware and/or ransomware. Using a virtual machine host, a virtual machine copy of an affected client computing device may be instantiated using a secondary copy of primary data of the affected client computing device]. Claim Rejections - 35 USC § 103 4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claim(s) 1-4,6-14 and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Kripalani (US Pub.No.2013/0332685) in view of Gaurav (US Pub.No.2020/0226256). 6. Regarding claim 1 Kripalani teaches a system comprising: a secondary storage computing device comprising one of more hardware processors, wherein the secondary storage computing device is configured to generate secondary copies of primary data in a file system, and wherein the secondary storage computing device is further configured to: maintain records of the secondary copies in an index, wherein the records include file system information associated with each of the secondary copies, after a first backup job that generated a first secondary copy of the primary data, perform a second backup job, which includes: generate a second secondary copy of the primary data (Para:0017 teaches the client computing devices each having at least one software application executing thereon generating production data, and one or more storage devices configured to store copies of the production data. Para:0085 teaches a secondary copy 116 [secondary copy of first data] can comprise a separate stored copy of application data that is derived from one or more earlier created, stored copies (e.g., derived from primary data 112). Para:0081 teaches the information management system 100 includes one or more secondary storage computing devices 106 and one or more secondary storage devices 108 configured to create and store one or more secondary copies 116 of the primary data 112 and associated metadata. The secondary storage computing devices 106 and the secondary storage devices 108 may be referred to in some cases as a secondary storage subsystem 118. Para:0085 teaches a secondary copy can comprise a separate stored copy of application data that is derived from one or more earlier created, stored copies (e.g., derived from primary data 112), i.e., performing a second backup operation. Para:0087 teaches after creation of a secondary copy 116 representative of certain primary data 112, a pointer or other location indicia (e.g., a stub) may be placed in primary data 112, or be otherwise associated with primary data 112 to indicate the current location on the secondary storage device(s) 108. Fig.1C and Para:0149-0152 teaches for each secondary copy 116, the index 153 may include metadata such as a list of the data objects (e.g., files/subdirectories, database objects, mailbox objects, etc.), a path to the secondary copy 116 on the corresponding secondary storage device 108, location information indicating where the data objects are stored in the secondary storage device 108, when the data objects were created or modified, etc. Thus, the index 153 includes metadata associated with the secondary copies 116 that is readily available for use in storage operations. Para:0072-0073 teaches the metadata associated with the data objects can include, without limitation, one or more of the following: the data owner (e.g., the client or user that generates the data), the last modified time (e.g., the time of the most recent modification of creation date... last accessed time... frequency of change (e.g., a period in which the data object is modified)... a data object size (e.g., a number of bytes of data) and aging information (e.g., a schedule, such as a time period, in which the data object is migrated to secondary or long term storage, file location within a file folder directory structure); Kripalani teaches all the above claimed limitations, but fails to teach determine differences between the first secondary copy and the second secondary copy, wherein the differences are based on comparing first file system information about the first secondary copy stored in the index with second file system information about the second secondary copy also stored in the index, and provide the differences to a classifier at the secondary storage computing device, determine, by the classifier, that the differences indicate anomalous activity in the primary data after the first backup job, and cause a notification of the anomalous activity to be issued by the system. Gaurav teaches determine differences between the first secondary copy and the second secondary copy, wherein the differences are based on comparing first file system information about the first secondary copy stored in the index with second file system information about the second secondary copy also stored in the index, and provide the differences to a classifier at the secondary storage computing device, determine, by the classifier, that the differences indicate anomalous activity in the primary data after the first backup job, and cause a notification of the anomalous activity to be issued by the system (Para:0030 -0031 teaches the secondary copy having file metadata includes one or more pointers and index. Para:0033-0034 teaches a version of a file (e.g., version of a file backed up from a primary system) is determined to have been potentially infected with malicious software by comparing the file metadata trees associated with a file. A file may be determined to have been infected with malicious software by comparing the file metadata trees associated with the file and determining the amount of data associated with the file that has changed between backup snapshots (i.e., the amount of data that has changed with versions of the file). In some embodiments, a rate at which the file has changed over a plurality of backup snapshots may be determined and compared to determine whether a file has been potentially infected with malicious software. For example, a particular file may normally exhibit a less than 5% change per backup snapshot over the ten backup snapshots before the last backup snapshot. However, for the last backup snapshot, the particular file may have exhibited a 50% change. Such an increase of the rate at which the file has changed may indicate that the file has been infected by malicious software. Para:0053 teaches a notification that data associated with the backup snapshot is potentially infected by malicious software is received from the server. The version of the content file is indicated as being potentially infected by malicious software. It would have been obvious to one of the ordinary skills in the art before the invention was filed to modify Kripalani to include determine differences between the first secondary copy and the second secondary copy, wherein the differences are based on comparing first file system information about the first secondary copy stored in the index with second file system information about the second secondary copy also stored in the index, and provide the differences to a classifier at the secondary storage computing device, determine, by the classifier, that the differences indicate anomalous activity in the primary data after the first backup job, and cause a notification of the anomalous activity to be issued by the system as taught by Gaurav, such a setup would detect Ransomware, a type of malicious software and would take mitigation action to prevent cyber-attacks (para:0002 and para:0039). 7. Regarding claim 2 Gaurav teaches the system, wherein the notification indicates an anomaly associated with one or more of: the second secondary copy, and the primary data (Para:0053 teaches notification indicates an anomaly associated with the second secondary copy and primary data) 8. Regarding claim 3 Kripalani in view of Gaurav teaches the system, wherein a user interface displays one or more secondary copies of the primary data that may be selected for restoration, wherein the one or more secondary copies that are displayed were generated before the second secondary copy (Kripalani: Para:0073 and Para:0151 teaches an identifier representing the file system directory. Para:0076 teaches the secondary storage devices 108 are provided in a cloud. Fig.1C and Para:00124 teaches storage policy may be stored as metadata in a media agent database 152 or in a secondary storage device 108 for use in restore operations. Gaurav: Para:0028-0031 teaches the file system data corresponds to a full backup snapshot or an incremental backup snapshot, the view of the file system data corresponding to the backup snapshot provides a fully hydrated backup snapshot that provides a complete view of the primary system at a moment in time corresponding to when the backup snapshot was performed. The view of file system data may allow any file that was stored on the primary system at the time the corresponding backup snapshot was performed, to be retrieved, restored, or replicated. The root node of a file system metadata snapshot tree may include one or more pointers to one or more intermediate nodes. The root node may correspond to a particular backup snapshot of file system data. Each intermediate node may include one or more pointers to other nodes (e.g., a lower intermediate node or a leaf node). A leaf node of the file system metadata snapshot tree may store data associated with a file for a file with data that is smaller than a limit size (e.g., 256 kB). A leaf node may be an index node (Mode). A leaf node of the snapshot tree may store a pointer to a file metadata tree for a file with data that is greater than or equal to the limit size. The file metadata tree is a snapshot structure and is configured to store the metadata associated with a file. The file may correspond to a virtual machine container file. Thus, a file metadata tree may be used to represent an entire virtual machine.). 9. Regarding claim 4 Kripalani in view of Gaurav teaches the system, wherein a media agent that executes at the secondary storage computing device is configured to: generate the secondary copies and maintain the index (Kripalani: Para:0081, 0085, 0887 and Para:0149-0152 teaches generate the secondary copies and maintain the index. Gaurav :Para:0028-0032). 10. Regarding claim 6 Gaurav teaches the system, wherein the first file system information comprises information about changes in the primary data over a first defined time interval, and wherein the second file system information comprises information about changes in the primary data over a second defined time interval (para:0036-0039 teaches information about changes in the primary data over a defined time interval) , and wherein changes in the primary data comprise added files, deleted files, and modified files (Para:0045 teaches changes in the primary data comprise added files, deleted files, and modified files. 11. Regarding claim 7 Gaurav teaches the system, wherein the system further comprises: a storage manager comprising one or more hardware processors, and wherein the storage manager is configured to, based on output received from the classifier, which indicates anomalous activity in the primary data after the first backup job: initiate a virtualization of a client computing device that generated the primary data, the virtualization comprising causing a virtual machine copy of the client computing device to be created at a virtual machine host, wherein the first secondary copy of the primary data is restored for use by the virtual machine copy (Para:0028-0029 teaches the view of the file system data corresponding to the backup snapshot may be comprised of a file system metadata snapshot tree and one or more file metadata trees. A file metadata tree may correspond to one of the files included in the backup snapshot. The file metadata tree is a snapshot structure that stores the metadata associated with the file. For example, a file metadata tree may correspond to a virtual machine container file (e.g., virtual machine image file, virtual machine disk file, etc.). Thus, the file metadata tree may store the metadata associated with a virtual machine container file. Regardless if the view of the file system data corresponds to a full backup snapshot or an incremental backup snapshot, the view of the file system data corresponding to the backup snapshot provides a fully hydrated backup snapshot that provides a complete view of the primary system at a moment in time corresponding to when the backup snapshot was performed. The view of file system data may allow any file that was stored on the primary system at the time the corresponding backup snapshot was performed, to be retrieved, restored, or replicated). 12. Regarding claim 8 Gaurav teaches the system, wherein the storage manager is further configured to: place the client computing device in an offline state (Para:0033-0035 teaches preventing or prohibiting the affected client computing device from accessing some or all of the file system data [which is the offline state herein]). 13. Regarding claim 9 Kripalani teaches a computer-implemented method comprising: by a secondary storage computing device comprising one of more hardware processors, wherein the secondary storage computing device is configured to generate secondary copies of primary data in a file system: maintaining an index that includes file system information associated with each of the secondary copies; performing a first backup job that generates a first secondary copy of the primary data; after the first backup job: performing a second backup job that generates a second secondary copy of the primary data, determining differences between the first secondary copy and the second secondary copy, wherein the differences are based on comparing first file system information about the first secondary copy stored in the index with second file system information about the second secondary copy also stored in the index, providing the differences to a classifier at the secondary storage computing device, determining, by the classifier, that the differences indicate anomalous activity in the primary data after the first backup job, and causing a user interface to provide a notification of the anomalous activity wherein the notification indicates an anomaly associated with one or more of: the second secondary copy, and the primary data (Claim 9 is similar to claim 1 and is therefore rejected under same rationale). 14. Regarding claim 10 Kripalani in view of Gaurav teaches the computer-implemented method further comprising: by a media agent that executes at the secondary storage computing device, generating the secondary copies and maintaining the index (Claim 10 is similar to claim 4 and is therefore rejected under same rationale). 15. Regarding claim 11 Kripalani in view of Gaurav teaches the computer-implemented method wherein the first file system information comprises information about changes in the primary data over a first defined time interval that include added files, deleted files, and modified files; and wherein the second file system information comprises information about changes in the primary data over a second defined time interval that include added files, deleted files, and modified files (Claim 11 is similar to claim 6 and is therefore rejected under same rationale). 16. Regarding claim 12 Kripalani in view of Gaurav teaches the computer-implemented method further comprising: by a storage manager comprising one or more hardware processors: based on output received from the classifier, which indicates anomalous activity in the primary data after the first backup job, initiating a virtualization of a client computing device that generated the primary data, the virtualization comprising causing a virtual machine copy of the client computing device to be created at a virtual machine host, wherein the first secondary copy of the primary data is restored for use by the virtual machine copy (Claim 12 is similar to claim 7 and is therefore rejected under same rationale). 17. Regarding claim 12 Kripalani in view of Gaurav teaches the computer-implemented method further comprising: by the storage manager, placing the client computing device in an offline state (Claim 13 is similar to claim 7 and is therefore rejected under same rationale). 18. Regarding claim 14 Kripalani teaches a system comprising: a client computing device comprising one or more hardware processors, wherein the client computing device is configured to: monitor a file system at the client computing device, to track changes in primary data of the file system over a defined time interval, apply a classifier at the client computing device to determine whether the changes tracked over the defined time interval are associated with a malware behavior, and based on determining that the changes are associated with the malware behavior, transmit an output of the classifier to a storage manager; and the storage manager in communication with the client computing device, wherein the storage manager comprises one or more hardware processors and is configured to: receive the output from the classifier, log the output in an anomaly detection database at the storage manager, and cause a user interface of the system to display anomaly information from the anomaly detection database (Claim 14 is similar to claim 1 and is therefore rejected under same rationale. 19. Regarding claim 16 Gaurav teaches the system, wherein the changes comprise added files, deleted files, modified files, and encrypted files (Para:0043-0045 teaches changes comprise added files, deleted files, modified files and encrypted files). 20. Regarding claim 17 Kripalani in view of Gaurav teaches the system, wherein the storage manager is further configured to, based on the output received from the classifier, which indicates that the changes are associated with the malware behavior: initiate a virtualization of the client computing device, comprising causing a virtual machine copy of the client computing device to be created at a virtual machine host, and place the client computing device in an offline state (Claim 17 is similar to claims 7,8 and is therefore rejected under same rationale). 21. Regarding claim 18 Gaurav teaches the system, wherein a secondary copy of the primary data is restored for use by the virtual machine copy (Para:0028-0029 teaches the view of the file system data corresponding to the backup snapshot may be comprised of a file system metadata snapshot tree and one or more file metadata trees. A file metadata tree may correspond to one of the files included in the backup snapshot. The file metadata tree is a snapshot structure that stores the metadata associated with the file. For example, a file metadata tree may correspond to a virtual machine container file (e.g., virtual machine image file, virtual machine disk file, etc.). Thus, the file metadata tree may store the metadata associated with a virtual machine container file. Regardless if the view of the file system data corresponds to a full backup snapshot or an incremental backup snapshot, the view of the file system data corresponding to the backup snapshot provides a fully hydrated backup snapshot that provides a complete view of the primary system at a moment in time corresponding to when the backup snapshot was performed. The view of file system data may allow any file that was stored on the primary system at the time the corresponding backup snapshot was performed, to be retrieved, restored, or replicated). 22. Regarding claim 19 Gaurav teaches the system, wherein to place the client computing device in the offline state comprises blacklisting a media access control address of the client computing device (Para:0033-0035 teaches preventing or prohibiting the affected client computing device from accessing some or all of the file system data). 23. Regarding claim 20 Kripalani in view of Gaurav teaches the system, wherein the user interface displays one or more secondary copies of the primary data, which may be selected for restoration to the client computing device (Kripalani: Para:0082, Para:0141 teaches restoring data and/or metadata if an original version e.g., of primary data 112 is lost. Gaurav: para:0028-0029 teaches restoration). 24. Claims 5 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Kripalani (US Pub.No.2013/0332685) in view of Gaurav (US Pub.No.2020/0226256) as applied to claims 1, 14 above and further in view of Dontov (US Pub.No.2019/0138727). 25. Regarding claims 5 and 15 Kripalani in view of Gaurav teaches all the above claimed limitations but fails to teach the system, wherein the classifier uses an anomaly detection model that has been trained with a labeled training data set, which indicates which types of changes in a file system are innocuous and which types of changes are associated with malware operations, wherein the anomaly detection model was trained before the first backup job. Dontov teaches the system, wherein the classifier uses an anomaly detection model that has been trained with a labeled training data set, which indicates which types of changes in a file system are innocuous and which types of changes are associated with malware operations, wherein the anomaly detection model was trained before the first backup job (Para:0024-0027 teaches monitor cloud storage (secondary copy) systems in order to automatically detect and/or categorize various security events. The security application will be in communication with a cloud storage system, such that the application may transmit/receive information to/from the cloud storage system. The security application may receive file information relating to files stored in the cloud storage system in order to create and store backups of the files. Additionally, the security application may allow a user to manually generate backups of one or more of the files. The security application will apply machine learning and/or other algorithms to received file information in order to detect, score and/or classify security events. Fig.4, Para:0088-0099 teaches detecting a ransomware attack event and recovering infected files. All backed-up data may be stored on a secure and independent cloud storage system. The system receives event information, such as activities relating one or more files stored in the cloud storage system, file information relating to such files, source information relating to users and/or or cloud applications, location information relating to sources, and/or times when events occur. As the system receives the event information, the system may quantify the risk (i.e., by calculating a risk score) associated with such information. The system detects the start of a ransomware attack event. Specifically, the system determines that a certain number of file modification events have occurred within a given time period. And at step 420, the system determines whether the frequency (or intensity) of such modification events matches a predetermined pattern and/or exceeds a predetermined threshold (e.g., as specified by a given risk rule). If so, the system continues to step 425. If not, the system may return to step 410, where it continues monitoring the cloud storage system. The ransomware applications will modify file content, cause changes to file metadata, rename files, modify file extensions, move files to different locations, and/or cause other changes. Such file modifications will cause a syncing application installed on the local computer to automatically (and quickly) sync the modified, infected files to a cloud storage system. At step 440, the system may scan all files stored in the cloud storage system to determine whether any additional infected files exist. At step 445, the system recovers all files determined to be infected). It would have been obvious to one of the ordinary skills in the art before the invention was filed to modify Kripalani in view of Gaurav to include the classifier uses an anomaly detection model that has been trained with a labeled training data set, which indicates which types of changes in a file system are innocuous and which types of changes are associated with malware operations as taught by Dontov, such a setup would result in securing and protecting cloud-based data and data backups and implementing disaster recovery from cyberattack using machine learning and AI technology. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEREENA T CATTUNGAL whose telephone number is (571)270-0506. The examiner can normally be reached Mon-Fri : 7:30 AM-5 PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DEREENA T CATTUNGAL/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

May 14, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743558
SECURE MODULE, ELECTRONIC PAYMENT TERMINAL, CORRESPONDING DETECTION METHOD
3y 4m to grant Granted Sep 22, 2026
Patent 12737489
DETERMINING LOCAL ADMINISTRATOR RIGHTS-RELATED DEPENDENCY RELATIONSHIPS USING ARTIFICIAL INTELLIGENCE TECHNIQUES
2y 7m to grant Granted Sep 15, 2026
Patent 12726348
EVENT ROUTING AND ENCRYPTION IN A MULTI-TENANT PROVIDER NETWORK
2y 8m to grant Granted Sep 01, 2026
Patent 12719929
Security for Groupcast Message in D2D Communication
4y 4m to grant Granted Aug 25, 2026
Patent 12719697
Method for digital signing and corresponding system
1y 10m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+29.4%)
2y 9m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 285 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month