Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 06/20/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-24 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-22 of U.S. Patent No. 12367280B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims while broader encompasses the subject matter of the parent application as indicated in the table below.
Instant Application 19/244,458
US Patent No. 12, 367,280 B2
1. A method comprising:
based on program code generated from disassembly of a binary program code,
creating a control flow based representation of each subroutine;
generating a subroutine signature for each control flow based representation;
generating an import behavior signature based, at least in part, on an import table of the program code; and
indicating an association of the subroutine signatures and the import behavior signature as a representation of structure and import behavior of the binary program code.
2. The method of claim 1, wherein creating the control flow based representations of the subroutines comprise:
for each subroutine,
determining descriptors for each basic block including a normalized identifier of the basic block;
aggregating the basic block descriptors; and
hashing the aggregated basic block descriptors.
3. The method of claim 2, wherein determining descriptors including a normalized identifier of each basic block of each subroutine comprising determining an offset of each basic block relative to a beginning of the corresponding subroutine and use the relative offset as the normalized basic block identifier.
4. The method of claim 2, wherein the descriptors for a basic block also comprise a basic block size, a jump type of the basic block, and indication of one or more successor basic blocks.
5. The method of claim 1, further comprising deterministically ordering the subroutine signatures in a data structure and associating the data structure of deterministically ordered subroutine signatures with the import behavior signature.
6. The method of claim 1, wherein generating the import behavior signature comprises:
determining caller-callee relationships between the subroutines and import code units indicated in the import table; and
generating the import behavior signature based, at least in part, on indications of the caller-callee relationships, wherein the indications use corresponding ones of the subroutine signatures.
7. A non-transitory, machine-readable medium having program code stored thereon, the program code comprising instructions to:
determine, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers;
generate a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows;
generate a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and
combine the plurality of signatures with the second signature.
8. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to determine a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature.
9. The non-transitory, machine-readable medium of claim 7, wherein the instructions to generate the plurality of signatures for the subroutines comprise instructions to, for each subroutine:
create a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and
hash the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine.
10. The non-transitory, machine-readable medium of claim 9, wherein the instructions to create the representation that indicates control flow comprise instructions to create the representation to indicate at least one of types of jumps in the basic blocks and successor blocks of the basic blocks.
11. The non-transitory, machine-readable medium of claim 9, wherein the instructions to create the representations comprise instructions to normalize identifiers of the basic blocks.
12. The non-transitory, machine-readable medium of claim 11, wherein the instructions to normalize identifiers of the basic blocks comprise instructions to, for each basic block of a subroutine, determine an offset of the basic block relative to a beginning of the corresponding subroutine.
13. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to:
form a signature vector with the plurality of signatures, wherein the instructions to combine the plurality of signatures with the second signature comprise instructions to associate the signature vector with the second signature.
14. The non-transitory, machine-readable medium of claim 13, wherein the instructions to form the signature vector comprise instructions to:
deterministically order the plurality of signatures in the signature vector.
15. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to generate clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file.
16. The non-transitory, machine-readable medium of claim 15, wherein the instructions to generate the clusters comprise instructions to:
generate fuzzy representations of each of the combined signatures;
cluster the fuzzy representations; and
for each cluster, indicate a malicious or benign verdict based, at least in part, on verdicts of cluster members.
17. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to:
for each import code unit,
determine which of the subroutines calls the import code unit; and
associate the signature of each caller subroutine with the import code unit,
wherein the instructions to generate the second signature comprise instructions to generate the second signature based, at least in part, on associations of the set of import code units with the signatures of caller subroutines.
18. The non-transitory, machine-readable medium of claim 17, wherein the instructions to generate the second signature further comprise instructions to:
for each import code unit, determine a quantity of call sites in each caller subroutine, wherein the second signature is also generated based on the quantity of call sites.
19. The non-transitory, machine-readable medium of claim 7, wherein the program code further comprises instructions to:
generate a first file signature of the first binary file; and
determine that the first file signature does not have a match in a cache of binary file signatures,
wherein the instructions to generate the plurality of signatures, generate the second signature, and combine the plurality of signatures with the second signature comprise the instructions to generate the plurality of signatures, generate the second signature, and combine the plurality of signatures with the second signature based, at least in part, on a determination that the first file signature does not have a match in the cache.
20. An apparatus comprising:
a processor; and
a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,
determine, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers;
generate a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows;
generate a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and
combine the plurality of signatures with the second signature.
21. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to determine a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature.
22. The apparatus of claim 20, wherein the instructions to generate the plurality of signatures for the subroutines comprise instructions executable by the processor to cause the apparatus to, for each subroutine:
create a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and
hash the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine.
23. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to:
form a signature vector with the plurality of signatures, wherein the instructions to combine the plurality of signatures with the second signature comprise instructions to associate the signature vector with the second signature.
24. The apparatus of claim 20, wherein the machine-readable medium further has stored thereon instructions that are executable by the processor to cause the apparatus to generate clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file.
1. A method comprising:
determining, based on program code from a disassembled first binary file, a plurality of intra-subroutine control flows, a set of one or more import code unit identifiers, and call relationships between subroutines of the program code and the set of import code unit identifiers;
generating a plurality of signatures for the subroutines based, at least in part, on the plurality of intra-subroutine control flows;
generating a second signature based, at least in part, on the set of import code unit identifiers and the call relationships; and
combining the plurality of signatures with the second signature as a representation of structure and import behavior of the first binary file.
2. The method of claim 1 further comprising determining a malicious or benign verdict for the first binary file based, at least in part, on the combination of the plurality of signatures with the second signature.
3. The method of claim 1, wherein generating the plurality of signatures for the subroutines comprises, for each subroutine:
creating a representation of the subroutine that identifies basic blocks of the subroutine, that indicates size of each basic block, and that indicates control flow among the basic blocks based on the one of the plurality of intra-subroutine control flows corresponding to the subroutine; and
hashing the subroutine representation to generate the one of the plurality of signatures corresponding to the subroutine.
4. The method of claim 3, wherein creating the representation that indicates control flow comprises creating the representation to indicate at least one of types of jumps in the basic blocks and successor blocks of the basic blocks.
5. The method of claim 3, wherein creating the representations comprises normalizing identifiers of the basic blocks.
6. The method of claim 5, wherein normalizing identifiers of the basic blocks comprises, for each basic block of a subroutine, determining an offset of the basic block relative to a beginning of the corresponding subroutine.
7. The method of claim 1, further comprising:
forming a signature vector with the plurality of signatures, wherein combining the plurality of signatures with the second signature comprises associating the signature vector with the second signature.
8. The method of claim 7, wherein forming the signature vector comprises:
deterministically ordering the plurality of signatures in the signature vector.
9. The method of claim 1 further comprising generating clusters based on combined signatures of sample binary files and corresponding verdicts, wherein the combined signatures include the combined plurality of signatures and the second signature and the sample binary files include the first binary file.
10. The method of claim 9, wherein generating the clusters comprises:
generating fuzzy representations of each of the combined signatures;
clustering the fuzzy representations; and
for each cluster, indicating a malicious or benign verdict based, at least in part, on verdicts of cluster members.
11. The method of claim 1 further comprising:
for each import code unit,
determining which of the subroutines calls the import code unit; and
associating the signature of each caller subroutine with the import code unit,
wherein generating the second signature comprises generating the second signature based, at least in part, on associations of the set of import code units with the signatures of caller subroutines.
12. The method of claim 11, wherein generating the second signature further comprises,
for each import code unit, determining a quantity of call sites in each caller subroutine, wherein the second signature is also generated based on the quantity of call sites.
13. The method of claim 1 further comprising:
generating a first file signature of the first binary file; and
determining that the first file signature does not have a match in a cache of binary file signatures,
wherein generating the plurality of signatures, generating the second signature, and combining the plurality of signatures with the second signature is based, at least in part, on determining that the first file signature does not have a match in the cache.
14. A non-transitory, machine-readable medium having program code stored thereon, the program code comprising instructions to:
based on program code generated from disassembly of a binary program code, create a control flow based representation of each subroutine;
generate a subroutine signature for each control flow based representation;
generate an import behavior signature based, at least in part, on an import table of the program code; and
indicate an association of the subroutine signatures and the import behavior signature as a representation of structure and import behavior of the binary program code.
15. The machine-readable medium of claim 14, wherein the instructions to create the control flow based representations of the subroutines comprise instructions to:
for each subroutine,
determine descriptors for each basic block including a normalized identifier of the basic block;
aggregate the basic block descriptors; and
hash the aggregated basic block descriptors.
16. The machine-readable medium of claim 15, wherein the instructions to determine descriptors including a normalized identifier of each basic block of each subroutine comprise instructions to determine an offset of each basic block relative to a beginning of the corresponding subroutine and use the relative offset as the normalized basic block identifier.
17. The machine-readable medium of claim 15, wherein the descriptors for a basic block also comprise a basic block size, a jump type of the basic block, and indication of one or more successor basic blocks.
18. The machine-readable medium of claim 14, wherein the program code further comprises instructions to deterministically order the subroutine signatures in a data structure and to associate the data structure of deterministically ordered subroutine signatures with the import behavior signature.
19. The machine-readable medium of claim 14, wherein the instructions to generate the import behavior signature comprise instructions to:
determine caller-callee relationships between the subroutines and import code units indicated in the import table; and
generate the import behavior signature based, at least in part, on indications of the caller-callee relationships, wherein the indications use corresponding ones of the subroutine signatures.
20. An apparatus comprising:
a processor; and
a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,
based on program code generated from disassembly of a binary program code, create a control flow based representation of each subroutine;
generate a subroutine signature for each control flow based representation;
generate an import behavior signature based, at least in part, on an import table of the program code; and
indicate an association of the subroutine signatures and the import behavior signature as a functional representation of the binary program code.
21. The apparatus of claim 20, wherein the instructions to create the control flow based representations of the subroutines comprise instructions executable by the processor to cause the apparatus to:
for each subroutine, determine descriptors for each basic block including a normalized identifier of the basic block;
aggregate the basic block descriptors; and
hash the aggregated basic block descriptors.
22. The apparatus of claim 20, wherein the instructions to generate the import behavior signature comprise instructions executable by the processor to cause the apparatus to:
determine caller-callee relationships between the subroutines and import code units indicated in the import table; and
generate the import behavior signature based, at least in part, on indications of the caller-callee relationships that use corresponding ones of the subroutine signatures.
Allowable Subject Matter
Claim(s) 1-24 would be allowable if a terminal disclaimer is filed and approved to overcome the double patenting rejection, set forth in this Office action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER C HARRIS whose telephone number is (571)270-7841. The examiner can normally be reached Monday through Friday between 8:00 AM to 4:00 PM CST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER C HARRIS/Primary Examiner, Art Unit 2432