Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
This application is a continuation of International Application No. PCT/CN2024/074845, filed on Jan. 31, 2024, which claims priority to Chinese Patent Application No.202310093402.X, filed on Jan. 31, 2023. The disclosures of the aforementioned applications are hereby incorporated by reference in their entireties.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 08/29/2025, and 09/19/2025 were filed after the mailing date of the Non-Provisional Patent Application on 07/30/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
DETAILED ACTION
This Office Action is in response to a Non-Provisional Patent Application received on 07/30/2025. In the application, claims 1-20 have been received for consideration and have been examined.
Specification
Applicant’s submitted specification has been reviewed and found to be in compliance.
Drawings
Applicant’s submitted drawings have been reviewed and found to be in compliance.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al., (US20220067159A1) in view of Boll et al., (US20230394144A1) and further in view of Jang., (KR102325629B1).
Regarding claim 1 Chen teaches a method for detecting ransomware infection using backup data stored and processed by a data-management/storage system. Chen mounts a snapshot constituting backup data, analyzes files within the backup, and determines whether the files are encrypted. See Chen ¶¶4, 13, 15–19, and 23–28.
Regarding:
obtaining, by a backup storage device, an encryption heatmap of each of a plurality of backup files, wherein the encryption heatmap indicates distribution of encrypted data in the backup file based on distribution of a target color.
Chen teaches obtaining and analyzing backup data and determining entropy values for files, where entropy measures randomness and is indicative of encryption. Chen ¶¶4, 15, 19, 23–24 and 28.
Chen does not expressly describe representing the entropy values as a color-based heatmap. Boll, however, teaches converting a computer file under test into image data and using the image to detect malware. Boll explains that:
• images may differ according to the distribution of a particular color or black pixels, ¶14;
• image pixels may represent brightness, color, and spatial position, ¶20;
• randomly selected portions of a file may be converted into images, ¶¶39–44;
• entropy values calculated for respective file-data blocks may be represented as normalized pixel values, ¶49;
• the resulting entropy images visualize local entropy distributions and entropy “hotspots,” ¶50; and
• file-derived data may be represented as a color image, ¶52.
It would have been obvious to represent Chen’s file-entropy features using Boll’s entropy/color image because Boll expressly teaches that visualization of local entropy distribution improves detection of encrypted, packed, or obfuscated portions of malicious files. The result would be an encryption heatmap in which a selected color represents data blocks having entropy indicative of encrypted data.
Regarding:
determining … an encryption score of the backup file based on the distribution of the target color in the encryption heatmap, wherein the encryption score indicates a proportion of the encrypted data in the backup file.
Chen teaches calculating an encryption score from entropy features, where the score reflects the degree or probability of encryption. Chen ¶¶4, 19 and 28; claim 28. Boll teaches that entropy-image pixel values may be expressed as normalized ratios from zero to one, that color distribution distinguishes images, and that image-classification outputs may be scalar scores. Boll ¶¶14, 18 and 49–52.
It would have been obvious to calculate Chen’s encryption score from the amount or distribution of pixels representing high-entropy data in Boll’s image. Counting or calculating the ratio of high-entropy-colored regions would have been a predictable way of expressing the proportion of a file identified as encrypted.
Regarding:
constructing … a sequence from the encryption score of each backup file, and performing sampling on the sequence by using a sliding window, to obtain a plurality of subsequences.
Chen teaches collecting file and filesystem measurements over successive time intervals and comparing behavior during patterns over time. Chen ¶¶16–17 and 23–28.
Jang teaches collecting sequential monitoring-variable values, applying a sliding window of a predetermined size to those values, repeatedly moving the window by a selected number of variables, and evaluating the variables contained within each window. Jang additionally teaches that the window may contain, for example, sixteen variables and move eight variables during each iteration.
Regarding claim 9, it is a device claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection.
Regarding claim 17, it is a device claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection.
Regarding claim 2, Chen teaches
analyzing the contents of files contained in backup data and determining an entropy value for each analyzed file. Chen ¶¶19 and 28.
Boll teaches dividing a file into data clusters or segments, randomly selecting data from the clusters, and repeatedly converting selected file-data subsets into images. Boll ¶¶39–46 and 55–56.
It would have been obvious to extract N data portions from Chen’s backup file using Boll’s sampling technique to obtain representative measurements without parsing or processing every byte of a potentially large file.
performing a randomness test on the N pieces of data to obtain N test values.
Chen teaches that entropy is a measure of file randomness and determines entropy values from file content. Chen ¶19.
Boll teaches calculating entropy values for respective data blocks of a file. Boll ¶¶49–50. Thus, the combination teaches applying an entropy/randomness test to the N extracted portions to obtain N entropy values.
constructing an N-dimensional randomness test vector from the N test values.
Boll teaches extracting N numerical data features from a file, optionally normalizing the N values, and converting them into a matrix image. Boll ¶67. Boll also teaches latent representations described as vectors in a high-dimensional vector space. Boll ¶52.
Organizing the N entropy values into an N-dimensional vector would have been an ordinary and predictable data structure for supplying the N numerical values to the subsequent image-encoding operation.
inputting the randomness test vector into a color coding function to obtain a color vector
Boll teaches converting numerical file data into pixels having brightness and/or color values; forming color images from file-derived values; and using distribution of particular colors to distinguish file images. Boll ¶¶14, 20, 49 and 52.
Thus, assigning colors to the numerical randomness values would have been an obvious visualization implementation of Boll’s entropy/color images.
mapping the color vector to a space filling curve to obtain the encryption heatmap.
Boll expressly teaches arranging file-derived pixels in an image using a space-filling curve, preferably a Hilbert curve, to preserve locality. Boll ¶¶41–42 and 47–48.
Regarding claim 10, it is a device claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection.
Regarding claim 18, it is a device claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection.
Regarding claim 3, Chen teaches
a distributed backup/storage architecture having data-management and storage nodes and further teaches that computationally intensive analysis may be performed by a cloud or remote server, with the resulting models or information distributed to the ransomware-detection component. Chen ¶¶22–24 and 31–36.
Boll teaches that file data may be obtained through network traffic or remote connections and processed by computer-based image-generation and classification modules. Boll ¶¶13 and 15–18.
It would have been obvious to perform Boll’s heatmap-generation operations at Chen’s backup server and transmit the resulting heatmap to a backup storage device. Allocation of the disclosed image-processing function between Chen’s networked server and storage nodes would have been a predictable distributed-processing arrangement, particularly where it reduces processing load on the storage device.
Regarding claim 11, it is a device claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection.
Regarding claim 19, it is a device claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection.
Regarding claim 4, Boll teaches
• distinguishing images according to the distribution of a particular color or black pixels, ¶14;
• assigning normalized numerical pixel values from zero to one, ¶49;
• identifying local entropy hotspots, ¶50;
• dividing an image into multiple image segments corresponding to respective file-data segments, ¶¶55–56; and
• producing scalar classification scores, including scores between zero and 100, ¶18.
Given Boll’s segmented image and Chen’s requirement that the encryption score indicate a degree of encryption, it would have been obvious to classify each image segment as encrypted or unencrypted based on its color and calculate the encrypted proportion as:
When all M segments are classified as encrypted, the same calculation necessarily produces . Expressly checking whether the entire image contains the target color before performing the segment calculation is an obvious shortcut that avoids unnecessary subdivision and counting when the result is already known.
Regarding claim 12, it is a device claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection.
Regarding claim 20, it is a device claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection.
Regarding claim 5, Jang teaches
applying a sliding window having a predetermined number of monitored values, moving the sliding window by a selected number of values during each iteration, and sequentially performing anomaly detection as the window moves through the collected values. Jang further teaches that the window can contain sixteen variables and move eight variables during each iteration, and that the movement distance may be no more than half the window size. Jang, claim 13 and the discussion corresponding to Fig. 5.
Thus, Jang teaches or suggests:
a window containing K encryption scores;
moving the window by L scores during each iteration; and
treating the values at the starting position and each subsequent position as respective windowed groups or subsequences.
Applying Jang’s sliding window to the sequence of encryption scores produced by Chen and Boll would have predictably generated the claimed plurality of subsequences.
Regarding claim 13, it is a device claim and recites similar subject matter as claim 5 and therefore rejected under similar ground of rejection.
Regarding claim 6, Jang teaches
an isolation-forest anomaly-detection algorithm that receives monitored variables contained in sliding windows and classifies the variables as anomalous or normal. Jang explains that the isolation forest isolates anomalous data using tree-based processing and may be applied to variables within windows identified as potentially abnormal. See Jang, claim 7 and the discussions corresponding to Figs. 6 and 7.
It would have been obvious to input the successive windowed subsequences of encryption scores into Jang’s isolation-forest model. The motivation would have been to obtain the known benefits identified by Jang: improved anomaly-detection accuracy and reduced computational-resource usage.
Regarding claim 14, it is a device claim and recites similar subject matter as claim 6 and therefore rejected under similar ground of rejection.
Regarding claim 7, Chen teaches
an entropy value as a measure of file randomness. Chen ¶19. Boll likewise teaches calculating Shannon entropy for respective file-data blocks. Boll ¶¶49–50.
Because claim 7 is written in the alternative—“an entropy value, a P value of a chi-square test, or a P value of a bit frequency test”—disclosure of the entropy-value alternative is sufficient.
Regarding claim 15, it is a device claim and recites similar subject matter as claim 7 and therefore rejected under similar ground of rejection.
Regarding claim 8, Boll teaches
teaches mapping file-derived pixels using a space-filling curve and specifically identifies a Hilbert curve. Boll ¶¶41–42 and 47–48.
Because claim 8 recites “Hilbert, Z-order, or Grey-code” in the alternative, Boll’s Hilbert curve satisfies the limitation.
Regarding claim 16, it is a device claim and recites similar subject matter as claim 8 and therefore rejected under similar ground of rejection.
Overall motivation to combine:
A person of ordinary skill would have been motivated to combine Chen, Boll, and Jang because the references address complementary aspects of the same technical problem:
Chen detects ransomware in backup data using file randomness, entropy features, encryption scores, and anomaly detection.
Boll provides an established method for converting local entropy or other numerical file features into segmented color images arranged using a space-filling curve, thereby preserving locality and revealing high-entropy hotspots.
Jang provides an established method for detecting anomalies in sequential measurements using moving windows and isolation-forest analysis.
The combination would have predictably improved Chen’s ransomware detection by:
preserving the location and distribution of high-entropy regions within backup files;
quantitatively expressing the proportion of each file that appears encrypted;
evaluating groups of temporally adjacent backup-file scores instead of isolated values; and
using an isolation forest to detect unusual groups of encryption scores without requiring labeled ransomware examples.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED M AHSAN whose telephone number is (571)272-5018. The examiner can normally be reached 8:30 AM - 6:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SYED M AHSAN/Primary Examiner, Art Unit 2491