Prosecution Insights
Last updated: October 02, 2026
Application No. 19/244,458

COMBINED STRUCTURE AND IMPORT BEHAVIOR SIGNATURES BASED MALWARE LEARNING AND DETECTION

Non-Final OA §DP
Filed
Jun 20, 2025
Priority
Oct 28, 2022 — continuation of 12/367,280
Examiner
HARRIS, CHRISTOPHER C
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
77%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
290 granted / 378 resolved
+18.7% vs TC avg
Strong +25% interview lift
Without
With
+25.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
19 currently pending
Career history
399
Total Applications
across all art units

Statute-Specific Performance

§101
15.1%
-24.9% vs TC avg
§103
41.8%
+1.8% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
26.9%
-13.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 378 resolved cases

Office Action

§DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. DETAILED ACTION Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/20/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-24 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-22 of U.S. Patent No. 12367280B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims while broader encompasses the subject matter of the parent application as indicated in the table below. Instant Application 19/244,458 US Patent No. 12, 367,280 B2 1. A method comprising: based on program code generated from disassembly of a binary program code, creating a control flow based representation of each subroutine; generating a subroutine signature for each control flow based representation; generating an import behavior signature based, at least in part, on an import table of the program code; and indicating an association of the subroutine signatures and the import behavior signature as a representation of structure and import behavior of the binary program code. 2. The method of claim 1, wherein creating the control flow based representations of the subroutines comprise: for each subroutine, determining descriptors for each basic block including a normalized identifier of the basic block; aggregating the basic block descriptors; and hashing the aggregated basic block descriptors. 3. The method of claim 2, wherein determining descriptors including a normalized identifier of each basic block of each subroutine comprising determining an offset of each basic block relative to a beginning of the corresponding subroutine and use the relative offset as the normalized basic block identifier. 4. The method of claim 2, wherein the descriptors for a basic block also comprise a basic block size, a jump type of the basic block, and indication of one or more successor basic blocks. 5. The method of claim 1, further comprising deterministically ordering the subroutine signatures in a data structure and associating the data structure of deterministically ordered subroutine signatures with the import behavior signature. 6. The method of claim 1, wherein generating the import behavior signature comprises: determining caller-callee relationships between the subroutines and import code units indicated in the import table; and generating the import behavior signature based, at least in part, on indications of the caller-callee relationships, wherein the indications use corresponding ones of the subroutine signatures. 7. A non-transitory, machine-readable medium having program code stored thereon, the program code comprising instructions to: determine, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers; generate a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows; generate a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and combine the plurality of signatures with the second signature. 8. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to determine a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature. 9. The non-transitory, machine-readable medium of claim 7, wherein the instructions to generate the plurality of signatures for the subroutines comprise instructions to, for each subroutine: create a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and hash the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine. 10. The non-transitory, machine-readable medium of claim 9, wherein the instructions to create the representation that indicates control flow comprise instructions to create the representation to indicate at least one of types of jumps in the basic blocks and successor blocks of the basic blocks. 11. The non-transitory, machine-readable medium of claim 9, wherein the instructions to create the representations comprise instructions to normalize identifiers of the basic blocks. 12. The non-transitory, machine-readable medium of claim 11, wherein the instructions to normalize identifiers of the basic blocks comprise instructions to, for each basic block of a subroutine, determine an offset of the basic block relative to a beginning of the corresponding subroutine. 13. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to: form a signature vector with the plurality of signatures, wherein the instructions to combine the plurality of signatures with the second signature comprise instructions to associate the signature vector with the second signature. 14. The non-transitory, machine-readable medium of claim 13, wherein the instructions to form the signature vector comprise instructions to: deterministically order the plurality of signatures in the signature vector. 15. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to generate clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file. 16. The non-transitory, machine-readable medium of claim 15, wherein the instructions to generate the clusters comprise instructions to: generate fuzzy representations of each of the combined signatures; cluster the fuzzy representations; and for each cluster, indicate a malicious or benign verdict based, at least in part, on verdicts of cluster members. 17. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to: for each import code unit, determine which of the subroutines calls the import code unit; and associate the signature of each caller subroutine with the import code unit, wherein the instructions to generate the second signature comprise instructions to generate the second signature based, at least in part, on associations of the set of import code units with the signatures of caller subroutines. 18. The non-transitory, machine-readable medium of claim 17, wherein the instructions to generate the second signature further comprise instructions to: for each import code unit, determine a quantity of call sites in each caller subroutine, wherein the second signature is also generated based on the quantity of call sites. 19. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to: generate a first file signature of the first binary file; and determine that the first file signature does not have a match in a cache of binary file signatures, wherein the instructions to generate the plurality of signatures, generate the second signature, and combine the plurality of signatures with the second signature comprise the instructions to generate the plurality of signatures, generate the second signature, and combine the plurality of signatures with the second signature based, at least in part, on a determination that the first file signature does not have a match in the cache. 20. An apparatus comprising: a processor; and a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to, determine, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers; generate a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows; generate a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and combine the plurality of signatures with the second signature. 21. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to determine a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature. 22. The apparatus of claim 20, wherein the instructions to generate the plurality of signatures for the subroutines comprise instructions executable by the processor to cause the apparatus to, for each subroutine: create a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and hash the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine. 23. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to: form a signature vector with the plurality of signatures, wherein the instructions to combine the plurality of signatures with the second signature comprise instructions to associate the signature vector with the second signature. 24. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to generate clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file. 1. A method comprising: determining, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers; generating a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows; generating a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and combining the plurality of signatures with the second signature as a representation of structure and import behavior of the first binary file. 2. The method of claim 1 further comprising determining a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature. 3. The method of claim 1, wherein generating the plurality of signatures for the subroutines comprises, for each subroutine: creating a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and hashing the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine. 4. The method of claim 3, wherein creating the representation that indicates control flow comprises creating the representation to indicate at least one of types of jumps in the basic blocks and successor blocks of the basic blocks. 5. The method of claim 3, wherein creating the representations comprises normalizing identifiers of the basic blocks. 6. The method of claim 5, wherein normalizing identifiers of the basic blocks comprises, for each basic block of a subroutine, determining an offset of the basic block relative to a beginning of the corresponding subroutine. 7. The method of claim 1, further comprising: forming a signature vector with the plurality of signatures, wherein combining the plurality of signatures with the second signature comprises associating the signature vector with the second signature. 8. The method of claim 7, wherein forming the signature vector comprises: deterministically ordering the plurality of signatures in the signature vector. 9. The method of claim 1 further comprising generating clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file. 10. The method of claim 9, wherein generating the clusters comprises: generating fuzzy representations of each of the combined signatures; clustering the fuzzy representations; and for each cluster, indicating a malicious or benign verdict based, at least in part, on verdicts of cluster members. 11. The method of claim 1 further comprising: for each import code unit, determining which of the subroutines calls the import code unit; and associating the signature of each caller subroutine with the import code unit, wherein generating the second signature comprises generating the second signature based, at least in part, on associations of the set of import code units with the signatures of caller subroutines. 12. The method of claim 11, wherein generating the second signature further comprises, for each import code unit, determining a quantity of call sites in each caller subroutine, wherein the second signature is also generated based on the quantity of call sites. 13. The method of claim 1 further comprising: generating a first file signature of the first binary file; and determining that the first file signature does not have a match in a cache of binary file signatures, wherein generating the plurality of signatures, generating the second signature, and combining the plurality of signatures with the second signature is based, at least in part, on determining that the first file signature does not have a match in the cache. 14. A non-transitory, machine-readable medium having program code stored thereon, the program code comprising instructions to: based on program code generated from disassembly of a binary program code, create a control flow based representation of each subroutine; generate a subroutine signature for each control flow based representation; generate an import behavior signature based, at least in part, on an import table of the program code; and indicate an association of the subroutine signatures and the import behavior signature as a representation of structure and import behavior of the binary program code. 15. The machine-readable medium of claim 14, wherein the instructions to create the control flow based representations of the subroutines comprise instructions to: for each subroutine, determine descriptors for each basic block including a normalized identifier of the basic block; aggregate the basic block descriptors; and hash the aggregated basic block descriptors. 16. The machine-readable medium of claim 15, wherein the instructions to determine descriptors including a normalized identifier of each basic block of each subroutine comprise instructions to determine an offset of each basic block relative to a beginning of the corresponding subroutine and use the relative offset as the normalized basic block identifier. 17. The machine-readable medium of claim 15, wherein the descriptors for a basic block also comprise a basic block size, a jump type of the basic block, and indication of one or more successor basic blocks. 18. The machine-readable medium of claim 14, wherein the program code further comprises instructions to deterministically order the subroutine signatures in a data structure and to associate the data structure of deterministically ordered subroutine signatures with the import behavior signature. 19. The machine-readable medium of claim 14, wherein the instructions to generate the import behavior signature comprise instructions to: determine caller-callee relationships between the subroutines and import code units indicated in the import table; and generate the import behavior signature based, at least in part, on indications of the caller-callee relationships, wherein the indications use corresponding ones of the subroutine signatures. 20. An apparatus comprising: a processor; and a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to, based on program code generated from disassembly of a binary program code, create a control flow based representation of each subroutine; generate a subroutine signature for each control flow based representation; generate an import behavior signature based, at least in part, on an import table of the program code; and indicate an association of the subroutine signatures and the import behavior signature as a functional representation of the binary program code. 21. The apparatus of claim 20, wherein the instructions to create the control flow based representations of the subroutines comprise instructions executable by the processor to cause the apparatus to: for each subroutine, determine descriptors for each basic block including a normalized identifier of the basic block; aggregate the basic block descriptors; and hash the aggregated basic block descriptors. 22. The apparatus of claim 20, wherein the instructions to generate the import behavior signature comprise instructions executable by the processor to cause the apparatus to: determine caller-callee relationships between the subroutines and import code units indicated in the import table; and generate the import behavior signature based, at least in part, on indications of the caller-callee relationships that use corresponding ones of the subroutine signatures. Allowable Subject Matter Claim(s) 1-24 would be allowable if a terminal disclaimer is filed and approved to overcome the double patenting rejection, set forth in this Office action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER C HARRIS whose telephone number is (571)270-7841. The examiner can normally be reached Monday through Friday between 8:00 AM to 4:00 PM CST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER C HARRIS/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jun 20, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12745090
NETWORK-LEVEL ELEVATED SECURITY EXECUTION MODES FOR NETWORK-ACCESSIBLE DEVICES
2y 8m to grant Granted Sep 22, 2026
Patent 12745081
POINTER MECHANISMS FOR COMMUNICATING AUTHENTICATION AND KEY MANAGEMENT (AKM) AND CIPHERS
1y 12m to grant Granted Sep 22, 2026
Patent 12737457
Machine Learning Process Detection
2y 9m to grant Granted Sep 15, 2026
Patent 12732811
LOGIN AUTHENTICATION SYSTEM AND METHOD, AND ELECTRONIC DEVICE
1y 11m to grant Granted Sep 08, 2026
Patent 12724883
Machine Learning Model Adversarial Attack Monitoring
2y 3m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
77%
Grant Probability
99%
With Interview (+25.3%)
2y 10m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 378 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month