DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is a non-final office action in response to applicant’s communication filed on 7/2/2025.
Claims 1-20 are pending and being considered.
Priority
This application is a Continuation of 18/663,340. Applicant’s claim for the benefit of a prior-filed application 18/663,340 (filed 5/14/2024, now US Patent No. 12,375,507B2), which is continuation of 17/191,350 (filed 3/3/2021, now US Patent No. 12,021,881B2), which is a continuation of 15/202,247 (filled on 7/5/2016, now US Patent No. 10,972,482B2) under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged.
Claim Objections
Claims 1, 14, 19 are objected to because of the following informalities:
Claim 1 lines 4-5 (similarly claim 19) recites “perform a method for automatic inline detection of malicious content”. However, there is no step(s) in the method can be understood as performing action that is related to detection of malicious content.
Similarly, claim 15 line 1 recites “for automatic inline detection of malicious content” in the preamble. However, there is no step(s) in the method can be understood as performing action that is related to detection of malicious content.
Applicant is suggested to include at least one action in the method for detection of malicious content from the download of the downloading executable file, to clarify the scope of the claimed invention.
Appropriate correction is suggested.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 5, 15 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 5 line 2 (similarly claim 15 line 2) recites “the state information”. There is insufficient antecedent basis for this limitation in the claim.
Double Patenting
A rejection based on double patenting of the “same invention” type finds its support in the language of 35 U.S.C. 101 which states that “whoever invents or discovers any new and useful process... may obtain a patent therefor...” (Emphasis added). Thus, the term “same invention,” in this context, means an invention drawn to identical subject matter. See Miller v. Eagle Mfg. Co., 151 U.S. 186 (1894); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Ockert, 245 F.2d 467, 114 USPQ 330 (CCPA 1957).
A statutory type (35 U.S.C. 101) double patenting rejection can be overcome by canceling or amending the claims that are directed to the same invention so they are no longer coextensive in scope. The filing of a terminal disclaimer cannot overcome a double patenting rejection based upon 35 U.S.C. 101.
Claim 19 is rejected under 35 U.S.C. 101 as claiming the same invention as that of claim 1 of instant application. This is a statutory double patenting rejection.
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1, 14, 19 are rejected on the ground of nonstatutory double patenting as being anticipated by the corresponding claims of US Patent No. 10,972,482 B2 (hereinafter “’482”).
Claim 12 (or claim 1) of ‘482 discloses all of the limitations recited in claim 14 (or claim 1, 19) of the instant application. See Claim Comparison table below for details.
Claim Comparison
Instant Application 19/258,273
US Patent No. 10,972,482 B2
Claim 14 (similarly claim 1, 19).
A method for automatic inline detection of malicious content, comprising:
for each executable file of a first plurality of executable files, extracting static data from the executable file, generating a feature vector using the static data, and assigning a score to the feature vector;
receiving input representing a downloading executable file downloading from a first network device to a second network device;
during, and prior to completion of the download of the downloading executable file:
generating an updatable feature vector using the static data extracted from the downloading executable file;
determining an updatable score of the updatable feature vector using a model executing between the first network device and the second network device, the model based on generated feature vectors for a plurality of executable files and assigned scores for the generated feature vectors, the assigned scores relating to a security status, the generated feature vectors based on extracted static data for the plurality of executable files;
and in response to determining that the updated updatable score meets a threshold value, terminating the download of the downloading executable file.
Claim 12 (or claim 1).
A method for automatic inline detection of malicious content, the method comprising:
receiving, by a computing device, a set of labeled data, wherein the set of labeled data is associated with one or more executable files comprising one or more security determinations;
extracting the first static data;
creating a first set of one or more feature vectors using the extracted first static data;
training one or more predictive models to determine the one or more security determinations using at least a portion of the set of labeled data;
intercepting, by the computing device, a first portion of an executable file during a download of the executable file to a client device and prior to completion of the download, the first intercepted portion comprising an incomplete portion of the executable file;
during the download of the executable file to the client device: determining a format for the executable file using the first intercepted portion of the executable file;
based on the determined format, identifying, within the first intercepted portion of the executable file, one or more data fields and corresponding data field values of first static data using a pattern matching technique;
using the one or more trained predictive models to generating an incremental security status score from the first set of one or more feature vectors;
intercepting a second portion of the executable file;
parsing the second intercepted portion of the executable file to identify second static data within the second intercepted portion of the executable file;
extracting the second static data; creating a second set of one or more feature vectors using the extracted second static data;
updating the incremental security status score based on the second set of one or more feature vectors;
based on the incremental security status score, generating a security determination for the downloading executable file;
and in response to the security determination indicating that the executable file is not benign, terminating the download of the executable file to the client device prior to completion of the download.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being anticipated by the corresponding claims of US Patent No. 12,021,881 B2 (hereinafter “’881”).
Claim 15 (or claim 1) of ‘881 discloses all of the limitations recited in claim 14 (or claim 1, 19) of the instant application. Dependent claims of ‘881 each discloses all of the limitations recited in corresponding dependent claims of the instant application. See Claim Comparison table below for details.
Claim Comparison
Instant Application 19/258,273
US Patent No. 12,021,881 B2
Claim 14 (similarly claim 1, 19).
A method for automatic inline detection of malicious content, comprising:
for each executable file of a first plurality of executable files, extracting static data from the executable file, generating a feature vector using the static data, and assigning a score to the feature vector;
receiving input representing a downloading executable file downloading from a first network device to a second network device;
during, and prior to completion of the download of the downloading executable file:
generating an updatable feature vector using the static data extracted from the downloading executable file;
determining an updatable score of the updatable feature vector using a model executing between the first network device and the second network device, the model based on generated feature vectors for a plurality of executable files and assigned scores for the generated feature vectors, the assigned scores relating to a security status, the generated feature vectors based on extracted static data for the plurality of executable files;
and in response to determining that the updated updatable score meets a threshold value, terminating the download of the downloading executable file.
Claim 15 (or claim 1).
A method for automatic inline detection of malicious content, comprising:
for each executable file of a first plurality of executable files, extracting static data from the executable file, generating a feature vector using the extracted static data, and assigning a score to the feature vector;
training a model based on the generated feature vectors and corresponding scores for the first plurality of executable files; deploying the model on a malicious content detection system which is inline between a first network device and a second network device;
receiving input representing a downloading executable file downloading from the first network device to the second network device;
determining a file format of the downloading executable file;
during, and prior to completion of the download of the downloading executable file: parsing the input based on the determined file format, and extracting static data from the downloading executable file;
generating an updatable feature vector using the static data extracted from the downloading executable file,
determining an updatable score of the updatable feature vector using the model, and determining whether the downloading executable file comprises malicious content based on the updatable score meeting a threshold value; receiving additional input representing the executable file, updating the updatable feature vector and the corresponding updatable score based on the additional input as the executable file continues downloading, and determining whether the downloading executable file comprises malicious content based on the updated updatable score meeting the threshold value;
in response to determination that the updated updatable score meeting the threshold value, terminating the download of the downloading executable file.
Claim 2
Claim 2
Claim 3
Claim 3
Claim 4
Claim 4
Claim 5
Claim 6
Claim 6
Claim 7
Claim 7
Claim 8
Claim 8
Claim 9
Claim 9
Claim 10
Claim 10
Claim 11
Claim 11
Claim 12
Claim 12
Claim 13
Claim 13
Claim 14
Claim 15
Claim 17
Claim 16, 20
Claim 18
Claim 17
Claim 19
Claim 18
Claim 20
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being anticipated by the corresponding claims of US Patent No. 12,375,507 B2 (hereinafter “’507”).
Claim 14 (or claim 1) of ‘507 discloses all of the limitations recited in claim 14 (or claim 1, 19) of the instant application. Dependent claims of ‘507 each discloses all of the limitations recited in corresponding dependent claims of the instant application. See Claim Comparison table below for details.
Claim Comparison
Instant Application 19/258,273
US Patent No. 12,375,507 B2
Claim 14 (similarly claim 1, 19).
A method for automatic inline detection of malicious content, comprising:
for each executable file of a first plurality of executable files, extracting static data from the executable file, generating a feature vector using the static data, and assigning a score to the feature vector;
receiving input representing a downloading executable file downloading from a first network device to a second network device;
during, and prior to completion of the download of the downloading executable file:
generating an updatable feature vector using the static data extracted from the downloading executable file;
determining an updatable score of the updatable feature vector using a model executing between the first network device and the second network device, the model based on generated feature vectors for a plurality of executable files and assigned scores for the generated feature vectors, the assigned scores relating to a security status, the generated feature vectors based on extracted static data for the plurality of executable files;
and in response to determining that the updated updatable score meets a threshold value, terminating the download of the downloading executable file.
Claim 14 (or claim 1).
A method for automatic inline detection of malicious content, comprising:
for each executable file of a first plurality of executable files, extracting static data from the executable file, generating a feature vector using the extracted static data, and assigning a score to the feature vector;
receiving input representing a downloading executable file downloading from a first network device to a second network device;
determining a file format of the downloading executable file;
during, and prior to completion of the download of the downloading executable file:
parsing the input based on the determined file format, and extracting static data from the downloading executable file;
tracking state information related to progress of the parsing of the downloading executable file;
using the state information to resume said parsing after said parsing is suspended or terminated;
generating an updatable feature vector using the static data extracted from the downloading executable file;
determining an updatable score of the updatable feature vector using a model executing between the first network device and the second network device, the model based on generated feature vectors for a plurality of executable files and assigned scores for the generated feature vectors, the assigned scores relating to a security status, the generated feature vectors based on extracted static data for the plurality of executable files;
in response to determining that the updated updatable score meets a threshold value, terminating the download of the downloading executable file.
Claim 2
Claim 2
Claim 3
Claim 3
Claim 4
Claim 4
Claim 5
Claim 5
Claim 6
Claim 6
Claim 7
Claim 7
Claim 8
Claim 8
Claim 9
Claim 9
Claim 10
Claim 10
Claim 11
Claim 11
Claim 12
Claim 12
Claim 13
Claim 13
Claim 15
Claim 15
Claim 16
Claim 16
Claim 17
Claim 17
Claim 18
Claim 18
Claim 20
Claim 20
Examiner Notes
Examiner cites particular paragraphs, columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 6-11, 14, 16-17, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Xue (US20150261954A1, hereinafter, "Xue"), in view of Raugas et al (US20150128263A1, hereinafter, "Raugas"), further in view of Schultz et al (US20030065926A1, hereinafter, "Schultz").
Regarding claim 1, similarly claim 14, claim 19, Xue teaches:
A system/A method/A system comprising: at least one processor; and memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, perform a method for automatic inline detection of malicious content (Xue, discloses systems and methods for pre-installation detection of malware in application downloaded on mobile computing device, see [Abstract]. And Fig. 5, processor and system memory, [0061-0062]), the method comprising:
receiving input representing a downloading executable file downloading from a first network device to a second network device (Refer to Fig. 3, and [0030] As illustrated in FIG. 3, at step 302 one or more of the systems described herein may intercept one or more communications of an application installation agent that installs applications (i.e., input … executable file, see [0032, 0039]) on a mobile computing device (i.e., receiving input). And [0039] the term "application" generally refers to any type or form of executable file and/or process);
during, and prior to completion of the download of the downloading executable file (e.g., [Abstract] The method may further include identifying, based on the one or more intercepted communications, an application that has been at least partially downloaded by the application installation agent):
While Xue does not specifically teach updatable feature vector, determining an updatable score of the updatable feature vector using a model, in the same field of endeavor Raugas teaches:
for each executable file of a first plurality of executable files, generating a feature vector using the extracted static data, and assigning a score to the feature vector (Raugas, discloses systems and methods for malware detection from network traffic, see [Abstract] Feature vectors may be extracted from the network traffic resulting in feature vectors. One or more machine learning models may be applied to the feature vectors producing a score. The score may indicate the presence of malware or the presence of a particular type of malware. And [0006] Features may be extracted from the network traffic samples. One or more machine learning models may be applied to the features generating a score representing some probability that malware exists on a particular networked device in the network. And [0021] These unknown threats may comprise new potentially malicious software components that potentially could infect the organization's computing resources. Potential new means of infection (e.g. installation or execution) of the software may include, but are not limited to, downloading via network interface);
generating an [updatable] feature vector using the static data extracted from the downloading executable file; determining an [updatable] score of the updatable feature vector using a model executing between the first network device and the second network device, the model based on generated feature vectors for a plurality of executable files and assigned scores for the generated feature vectors, the generated feature vectors based on extracted static data for the plurality of executable files ([0022] Using one or more methods of feature extraction, the network samples may be prepared for scoring. Subsequently, a specific machine learning algorithm may use models trained a priori against specific and/or known classes of malware to compute rankable scores (for a given time window). And [0065] The machine learning modules receive the extracted features as inputs, and produce scores as outputs for each input. The scores are produced using the provided feature vector as input to the specified model and model configuration (e.g., Support Vector Machine with a trained SVM model)); Examiner notes, the feature vector by Raugas is updatable in view of Schultz below as the model based on feature is updated.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Raugas in the pre-installation detection of malware of Xue by extracting feature vectors from network traffic and producing score. This would have been obvious because the person having ordinary skill in the art would have been motivated to detect malware based on score indicating presence of malware in monitored network traffic (Raugas, [Abstract]).
The combination of Xue and Raugas does not specifically teach updatable (feature vector, score), in the same field of endeavor Schultz teaches:
Updatable (feature vector, score) (Schultz, discloses methods for detection of malicious executables of email attachment, [Abstract]. And [0108] When the Multi-Naive Bayes analysis is used herein, the data is partitioned into several components and all the components may be processed in parallel to increase speed. This updated model may then be distributed to the malicious email detector 220. And [0109] The feature extractor 246 accesses attachments stored in the data repository 244, and then extracts features from the attachments. This function may be performed by invoking the hexdump routine, as described above. The learning algorithm executor 248 receives features from the feature extractor 246 and executes learning algorithms on the features extracted from the attachments to generate an updated classification rule set); Examiner notes, network traffic of Raugas is result of downloading executable files. Updating classification model set of Schultz is based on updated feature vector and corresponding score in view of Raugas’s teachings of feature and corresponding score).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Schultz in the pre-installation detection of malware of Xue-Raugas by parsing executable attachment and extracting/analyzing static properties of executable attachment. This would have been obvious because the person having ordinary skill in the art would have been motivated to classify the executable attachment as malicious or benign for detection of malicious executables (Schultz, [Abstract]).
The combination of Xue and Raugas further teaches: in response to determining that the updated updatable score meets the threshold value, terminating the download of the downloading executable file (Xue, [0043] At illustrated in FIG. 3, at step 306, one or more of the systems described herein may, in response to identifying the application, and before the application is installed on the mobile computing device, scan the application for malware. And [0050] As illustrated in FIG. 3, at step 310, one or more of the systems described herein may perform a security action in response to determining that the application contains malware. Examiner notes, Xue’s teachings of intercepting and identifying partially downloaded application suggests the security action may be performed before completing the downloading of application (i.e., terminating the download). And Raugas teaches a threshold value to accompany a score indicating the likelihood that the traffic sample indicates the presence of malware and the likely effectiveness of planned remediation effort (see [Abstract]).
Regarding claim 6, Xue-Raugas-Schultz combination teaches the system of claim 1,
Schultz further teaches: wherein the extracted static data includes at least one of: header information, section information, import and export information, certificate information, resource information, string and flag information, legal information, and comments and program information (Schultz, [0044] To extract resource information from Windows executables, GNU's Bin-Utils may be used (as described in "GNU Binutils Cygwin, online publication as viewed on http://sourceware.cygnus.com/cygw- in, 1999, which is incorporated by reference in its entirety herein). GNU's Bin-Utils suite of tools can analyze PE binaries within Windows. In PE, or Common Object File Format (COFF), program headers are composed of a COFF header, an Optional header, at MS-DOS stub, and a file signature. All of the information about the binary is obtained from the program header without executing the unknown program but by examining the static properties of the binary, using libBFD). Same motivation as presented in claim 1 would apply.
Regarding claim 7, Xue-Raugas-Schultz combination teaches the system of claim 1,
Schultz further teaches: wherein the extracted static data is organized into categories identifying a type for the static data, the categories including at least one of: numeric values, nominal values, string values, and Boolean values (Schultz, [0021] ... extracting the byte sequence feature from said executable attachment comprises extracting static properties of the executable attachment, … extracting the byte sequence features from the executable attachment may comprise creating a byte string representative of resources referenced by said executable attachment. Or [0049] A first approach to binary profiling used the DLLs loaded by the binary as features. Data can be modeled by extracting a feature or a set of features, and each set of features may be represented as a vector of feature values. The feature vector comprised of a number of boolean values, e.g., 30, representing whether or not a binary used a DLL). Same motivation as presented in claim 1 would apply.
Regarding claim 8, Xue-Schultz-Raugas combination teaches the system of claim 1,
Schultz further teaches: wherein the feature vector comprises multiple data points and the generating the feature vector using the extracted static data comprises populating the multiple data points based on at least one of: grouping static data fields and values, labeling identified anomalies, converting data into hex representations, building n-grams and word-grams, and encapsulating special characters (Schultz, [0021] According to a preferred embodiment, extracting the byte sequence feature from said executable attachment comprises extracting static properties of the executable attachment, which are properties that do not require the executable to be run in order to discern. Extracting the byte sequence feature from the executable attachment may comprise converting the executable attachment from binary format to hexadecimal format). Same motivation as presented in claim 1 would apply.
Regarding 9, similarly claim 16, claim 20, Xue-Schultz-Raugas combination teaches the system of claim 1, the method of claim 14, the system of claim 19,
Raugas further teaches: wherein said determining the updatable score of the feature vector is based on security status of the downloading executable file and generating of a similarity between the feature vector and a predefined feature vector (Raugas, [0067] At least one machine learning model 125 is applied to the features 145, thereby generating score 130, wherein the score indicates the likelihood of malware being present in a host or network device in network 105. The machine learning model 125 may be trained prior to applying the machine learning model to the extracted features. The training may include at least one of the following: scoring network traffic based on similarity to malicious behavior by software executing on a network-connected host system; scoring network based on similarity to benign or non-malicious behavior by software executing on a network-connected host system). Same motivation as presented in claim 1, 14, 19 would apply.
Regarding claim 10, Xue-Schultz-Raugas combination teaches the system of claim 10,
Raugas further teaches: wherein said determining the updatable score further comprises at least one of: determining whether the updatable score exceeds a threshold, determining a degree of similarity between the feature vector and malicious content, determining a probability that the feature vector includes unwanted content, and determining an identified threat as a percentage of the downloading executable file (Raugas, [Abstract] A threshold value may be calculated to accompany a score indicating the likelihood that the traffic sample indicates the presence of malware and the likely effectiveness of planned remediation effort. An alert may be generated from the score and the threshold when the threshold is acceded. And [0067] At least one machine learning model 125 is applied to the features 145, thereby generating score 130, wherein the score indicates the likelihood of malware being present in a host or network device in network 105. The machine learning model 125 may be trained prior to applying the machine learning model to the extracted features. The training may include at least one of the following: scoring network traffic based on similarity to malicious behavior by software executing on a network-connected host system; scoring network based on similarity to benign or non-malicious behavior by software executing on a network-connected host system). Same motivation as presented in claim 1 would apply.
Regarding claim 11, similarly claim 17, Xue-Schultz-Raugas combination teaches the system of claim 1, the method of claim 14,
Raugas further teaches: wherein the model is based on one or more machine learning mechanisms including at least one of: a support vector machine, a restricted Boltzmann machine and a decision tree (Raugas, [0065] Machine learning models may include a set of supervised learning algorithms, such as Boosted Decision Trees, Support Vector Machines, and Gaussian Mixture Models. The machine learning models may be specified in a predefined configuration or by a user. The machine learning modules receive the extracted features as inputs, and produce scores as outputs for each input. The scores are produced using the provided feature vector as input to the specified model and model configuration (e.g., Support Vector Machine with a trained SVM model)). Same motivation as presented in claim 1, 14 would apply.
Claims 2-4 are rejected under 35 U.S.C. 103 as being unpatentable over Xue-Raugas-Schultz as applied above to claim 1, further in view of Schipka (US20090013405A1, hereinafter, "Schipka").
Regarding claim 2, Xue-Raugas-Schultz combination teaches the system of claim 1,
The combination of Xue-Raugas-Schultz teaches the main concept of claimed invention and file format but does not specifically teach the following, in the same field of endeavor Schipka teaches:
further comprising determining a schema of the downloading executable (Schipka, discloses classification technique to classify an input file as malicious or not, see [Abstract]. And [0041] In the case of messages 2 which are emails, the object extractor 11 extracts files 100 attached to the emails. In the case of HTTP traffic, the files 100 will typically be web pages, web page components and downloaded files).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Schipka in the pre-installation detection of malware of Xue-Raugas-Schultz by classifying input file. This would have been obvious because the person having ordinary skill in the art would have been motivated to classify the file on basis of structure of data fields to identify data fields and meaning for heuristic detection of malicious code (Schipka, [Abstract]).
Regarding claim 3, Xue-Raugas-Schultz-Schipka combination teaches the system of claim 2,
Schipka further teaches: further comprising identifying applicable sections of the downloading executable file ([Abstract] The representation of a file is derived by determining the file format, parsing the file on the basis of the structure of data fields in the determined file format to identify the data fields (i.e., applicable sections). And 0054] The file format identifier 21 determines the file format using any reliable technique available. Some examples of such techniques are given below One simple technique is to determine the file format based on the filename extension of the file 100, that is the section of the name of the file 100 following the final period). Same motivation as presented in claim 2 would apply.
Regarding claim 4, Xue-Raugas-Schultz-Schipka combination teaches the system of claim 3,
Schipka further teaches: wherein the applicable sections include at least one of: DOS headers, data directories and section tables (Schipka, [0125] If the entry point points to, say, "MS-DOS MZ Header", then a new feature is extracted). Same motivation as presented in claim 2 would apply.
Claims 5, 15 are rejected under 35 U.S.C. 103 as being unpatentable over Xue-Raugas-Schultz combination as applied above to claim 1, 14 respectively, further in view of Garcia (US20110314107A1, hereinafter, "Garcia").
Regarding claim 5, similarly claim 15, Xue-Raugas-Schultz combination teaches the system of claim 1, The method of claim 14,
The combination of Xue-Raugas-Schultz does not specifically teach, in the same field of endeavor Garcia teaches:
further comprising: using the state information to generate completion percentage statistics for the downloading executable file (Garcia, discloses apparatus and method for downloading code image to remote devices, see [Abstract]. And [0036] … devices 105, 107, and 109 provide a download status that is indicative of a percentage of the code image that was successfully downloaded to the device).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Garcia in the pre-installation detection of malware of Xue-Raugas-Schultz by providing download status. This would have been obvious because the person having ordinary skill in the art would have been motivated for downloading center 104 to subsequently download the remaining part of the code image to the device (Garcia, [Abstract], [0036]).
Claims 12, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Xue-Raugas-Schultz combination as applied above to claim 11, 17 respectively, further in view of Muddu et al (US20170063894A1, hereinafter, "Muddu").
Regarding claim 12, similarly claim 18, Xue-Raugas-Schultz combination teaches the system of claim 11, the method of claim 17,
The combination of Xue-Raugas-Schultz does not specifically teach, in the same field of endeavor Muddu teaches:
wherein the model is a predictive model configured to detect malicious content based on the updatable scores and security determinations associated with the feature vectors, further comprising receiving feedback regarding the updatable scores and updating the predictive model based on the feedback (Muddu, discloses network security threat detection based on behavioral analysis, [Abstract]. And [0347] updating a machine learning model based on the user feedback … regarding a determination of a detected security-related issue. For example, such an update can be performed by one of the engines to the model state, and through the shared model state, the effect of that feedback can be propagated into the other engine's anomaly and threat detection processes. And [0633] ensemble learning techniques can be applied to process the plurality of feature scores according to a plurality of models (including machine-learning models) to achieve better predictive performance in the anomaly scoring and reduce false positives).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Muddu in the pre-installation detection of malware of Xue-Raugas-Schultz by providing feedback to model training process to update model. This would have been obvious because the person having ordinary skill in the art would have been motivated to achieve better predictive performance in anomaly scoring and reduce false positives (Muddu, [Abstract], [0633]).
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Xue-Raugas-Schultz -Muddu combination as applied above to claim 12, further in view of Sculley et al (US20100205123A1, hereinafter, "Sculley").
Regarding claim 13, Xue-Raugas-Schultz-Muddu combination teaches the system of claim 12,
The combination of Xue-Raugas-Schultz-Muddu does not specifically teach, in the same field of endeavor Sculley teaches:
wherein the feedback comprises a disagreement with one or more of the updatable scores received from a human operator (Sculley, discloses method for identifying unwanted or harmful electronic text, see [Abstract]. And [0045] the method begins with a model generated either by an online or offline training phase. Each new piece of electronic text is converted to features using the inexact string matching methods, and then classified by the machine learning method using the current model. However, after classification, the method may receive feedback from some trusted source (e.g., such as user feedback or human labeling). If the feedback disagrees with the classification, then the machine learning algorithm updates the model accordingly).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Sculley in the pre-installation detection of malware of Xue-Raugas-Schultz-Muddu by providing user feedback as trusted source to update machine learning algorithm. This would have been obvious because the person having ordinary skill in the art would have been motivated to update machine learning model accordingly if there is disagreement from trusted user for identifying unwanted or harmful electronic spam (Sculley, [Abstract], [0045]).
Citation of References
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action:
Jiang (US20160212160A1) discloses system and method for alerting against unknown malicious codes.
Glick et al (US9350755B1) discloses method and apparatus for detecting malware transmission through a web portal.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL M LEE/Primary Examiner, Art Unit 2436