Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detail Action
2. This office action is response to the application filed on . Claims 1-4,6-21are pending in this communication.
Claim Objections
3. Claims 1-4,6-21 are objected to because of the following informality: the submitted text version of claim limitations are hard to read due to poor resolution. Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4. Claims 1-4,8-10 are rejected under AIA 35 U.S.C. 103 as being unpatentable over AKITA et al (US 20180121653 A1) in view of Iwanir et al. (US 20180034835 A1)
Regarding Claim 1:
AKITA discloses:
a. A method implemented by a storage device, (Para.0036, Para.0045, Abstract; “system …. configured by …. processing apparatuses 10 (10a, 10b, 10c …”, “The MFP 10 is an apparatus …. having functions such as a scan function….the MFP 10 includes…..a storage”, “information processing apparatuses performs virus detection processing for detecting a computer virus” information processing apparatuses/MFP 10 including a storage performs virus detection processing for detecting a computer virus is construed as the claimed ‘A method implemented by a storage device’) the method comprising:
receiving; an infection detection request from a detection device; (FIG.5/Para.0077/Para.0078, Para.0059; “in step S21, the one request destination apparatus ….. MFP 10c…. determines whether a virus scan request has been received”, “the virus scan request received from the request source apparatus issuing a virus scan request …. MFP 10a”, “computer virus …. detected from ….. MFP 10a” MFP 10a is construed as the claimed ‘detection device’) and
b. performing …. on target data in response to the infection detection request …. of target data; (Para.0079, Para.0063; “in response to …. the virus scan request, the request destination apparatus (MFP 10c) …. starts a virus scan of the to-be-scanned data …. included in the virus scan request”, “a regular scan (virus scan ….) of data …. referred to as “to-be-scanned data”). This virus scan is performed by the antivirus software installed in the MFP 10a” to-be-scanned data is construed as target data) and
c. ….. the data ….. to the detection device, ……whether the target data is infected by a virus. (Para.0083, Para.0073, Para.0004; “In step S25…. the ….virus scan of the to-be-scanned data….has been completed”, “if the virus scan has been completed for all to-be-scanned data in the MFP 10a, the antivirus processing of the MFP 10a is completed”, “if one information processing apparatus is infected with a computer virus….”)
Examiner noted that, in FIG.5, in step S21, the virus scan request received from the request source apparatus MFP 10a/claim ‘detection device’, issuing a virus scan request. In step S23, any computer virus can be detected by virus scan. Thus. FIG.5 of AKITA discloses the same sequences mentioned in the claimed limitation.
However, AKITA does not explicitly disclose:
b. performing feature extraction on …. data …..to obtain a data feature of ….. data;
c. outputting, the data feature to the …… device, wherein the data feature is for detecting whether the ….. data is infected by a ….
In an analogous reference Iwanir discloses:
b. performing feature extraction on …. data …..to obtain a data feature of ….. data; (Para.0027, Para.0038; “extract ….features associated with each file ….”, “label the extracted features as malicious or not malicious …. detect whether the extracted features indicate that …. a change to a file appears to be malicious”)
c. outputting, the data feature to the …… device, wherein the data feature is for detecting whether the ….. data is infected by a …. (Para.0031, Para.0027; “In block 403, the component extracts features from the files. In block 404, the component sends the features to the …. ransomware detector component …...”, “The …. ransomware detector …. classify a file …. as being legitimate or possibly malicious”)
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify AKITA’s method for performing virus detection processing for detecting a computer virus by enhancing AKITA’s method to include Iwanir’s method for assessing whether a change to a file appears to be malicious.
The motivation: by extracting features associated with each file, assessment can be done whether a change to a file appears to be malicious in that the change may be caused by ransomware/virus.
Regarding Claim 2:
AKITA in view of Iwanir discloses:
The method of claim 1, wherein performing ….. related to storage of the target data. (AKITA, Para.0063, Para.0045; “the MFP 10a starts … a regular scan (virus scan ….) of data …. referred to as “to-be-scanned data”). This virus scan is performed by the antivirus software installed in the MFP 10a”, “The MFP 10 is an apparatus …. having functions such as a scan function….the MFP 10 includes…..a storage”)
….. the feature extraction comprises performing the feature extraction in a process of running a task related to ….. data. (Iwanir, Claim.10, Para.0024, Para.0028, “extracting features relating to the file and …. detect whether the extracted features indicate that a change appears to be malicious”, “direct anti-virus software to identify malware that caused the change (e.g., by running a scan of files based on …. ransomware)”, “The antivirus software may scan …. activity of the client device to determine whether the client device may be infected with ransomware or other malware”)
Regarding Claim 3:
AKITA in view of Iwanir discloses:
The method of claim 2, wherein performing the feature extraction comprises:
performing, by a central processing unit (CPU) of the storage device …. in which the CPU stores the target data….. (AKITA, Para.0070, Para.0009, Para.0044; “the MFP 10a …. starts a ….virus scan …. of data ….referred to as “to-be-scanned data” …virus scan is performed by the antivirus software installed in the MFP 10a”, “… processing apparatus … includes ….hardware processor”, “processing apparatuses 10 …. A Multi-Functional Peripheral (MFP) …. as an example”)
performing, …. a second process …. (Iwanir, Claim.10, Para.0024, Para.0028, “extracting features relating to the file and …. detect whether the extracted features indicate that a change appears to be malicious”, “direct anti-virus software to identify malware that caused the change (e.g., by running a scan of files based on …. ransomware)”, “The antivirus software may scan …. activity of the client device to determine whether the client device may be infected with ransomware or other malware” running a scan of files is construed as a second process) first calculation on the … data to generate the data feature; (Para.0019; “use data analytics to ….distinguish between legitimate changes and malicious changes…. use …. an evolutionary algorithm, …. to detect malicious changes…. collect various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes ….” evolutionary algorithm to detect malicious changes and collect various features is construed as ‘first calculation on the … data to generate the data feature’) or
performing, by a processing unit of storage interface card connected to the CPU and in a third process in which the storage interface card receives the target data from a host, second calculation on the target data to generate the data feature.
Regarding Claim 4:
AKITA in view of Iwanir discloses:
The method of claim 1, wherein prior to performing the feature extraction,
the method further comprises: … storage device…..(AKITA, disclosed in claim 1)
receiving the data feature from a host; (Iwanir, Para.0031; “the component retrieves a file ….. generated by a … cloud …. system….the component extracts features from the files”) and
sending the data feature to a storage medium of the storage device for persistent storage. (Iwanir, Para.0031, Para.0028, Para.0036; “the component sends the features to the …. data storage”, “Each client device …include …. ARC agent …. The ARC agent may implement client-side components of the ARC system”, “computer-readable storage medium that implements the ARC system”)
Regarding Claim 8:
AKITA in view of Iwanir discloses:
The method of claim 1, wherein performing the feature extraction comprises performing, based on the infection detection request, the ….target data stored in a target storage space indicated by the infection detection request …… (AKITA, Para.0079, Para.0045; “in response to …. the virus scan request, the request destination apparatus (MFP 10c) …. starts a virus scan of the to-be-scanned data …. included in the virus scan request”, “The MFP 10 is an apparatus ….. includes…..a storage”)
… performing …..feature extraction on …. data …..to obtain a data feature of…. (Iwanir, disclosed in claim 1)
Regarding Claim 9:
AKITA in view of Iwanir discloses:
The method of claim 1, further comprising obtaining feature policy information for the storage device based on a feature policy configuration instruction, wherein the feature policy information indicates a manner of performing the feature extraction. (Iwanir, Para.0019; “use …. techniques, such as a support vector machine, a Bayesian network, learning regression…. to detect malicious changes…collect various features such as the number and frequency of file changes, the location of file changes….”)
Regarding Claim 10:
AKITA in view of Iwanir discloses:
The method of claim 1, wherein …. the target data … and wherein … a segment … from the target data and is for identifying the target data. (AKITA, Para.0234; “performs, …a virus scan (e.g., …. increasing the number of directories to be scanned)”)
…… the data feature is an information entropy of the target data or a digest of the target data, (Iwanir, Para.0019; “collect various features such as the number and frequency of file changes, …. entropy changes”) wherein the information entropy indicates uncertainty of the target data, (Para.0017, Abstract; “When a change to a file is detected… determines whether the file was maliciously changed (e.g., deleted, encrypted, or otherwise corrupted). To determine whether a file has been maliciously changed…. use …detection criteria such as (a) entropy changes”, “assesses whether a change to a file appears to be malicious in that the change … caused by ransomware”) and wherein the digest is ….. extracted from the ….data …. (Iwanir, Para.0026, Para.0019; “features extracted from files”, “collect ….features such as the number and frequency of file changes, the location of file changes, the patterns of the changes (file extensions, file headers”)
Claims 6,11-21 are rejected under AIA 35 U.S.C. 103 as being unpatentable over AKITA et al (US 20180121653 A1) in view of Iwanir et al. (US 20180034835 A1) and further in view of Izuta et al. (US 20150058658 A1)
Regarding Claim 6:
AKITA in view of Iwanir discloses:
The method of claim 1, further comprises:
…. Further performing, in response to the …. request and …. the target data …. into a target storage space of the storage device, ….on the target data …. wherein … request comprises the target data, and wherein the target storage space is a persistent storage space of the storage device; (AKITA, Para.0079, Para.0070, Para.0045; “in response to the … virus scan request, the …. apparatus …. starts a virus scan of the to-be-scanned data”, “The virus scan request includes ….data to be scanned …”, “The MFP 10 is an apparatus ….. includes…..a storage”) and
storing the …. the target data in the target storage space. (AKITA, Para.0139, Para.0070; “each MFP 10 is capable of …. storing data”, “data to be scanned …. performed by the ….. apparatuses…. data stored in the ….directory …. of the MFP 10a”)
… performing feature extraction on …. data …..to obtain a data feature of…. (Iwanir, disclosed in claim 1)
…. storing the data feature as metadata of the …. data in the …storage space. (Iwanir, Para.0017, Para.0019; “changes in … files …on the files stored on the …. storage of a client device”, “various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes….”)
However, AKITA in view of Iwanir does not explicitly disclose:
…. Receiving a write request from a host;
……in response to the write request and prior to the ….data being written into a ….. device, …..wherein the write request comprises the …. data….
In an analogous reference Izuta discloses:
…. Receiving a write request from a host; (Para.0034; “the host … transmits …a data write request”)
……in response to the write request and prior to the ….data being written into a ….. device, …..wherein the write request comprises the …. data…. (Para.0054, Para.0038; “write of the write data is completed in response to the drive write request”, “data written to the storage device”)
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify AKITA in view of Iwanir’s method for performing virus detection processing for detecting a computer virus by enhancing AKITA in view of Iwanir’s method to include Izuta’s method for controlling the storage apparatus.
The motivation: In order to make data transfer more efficient as well as the processing of data read or data write efficient and less time consuming, a buffer memory is provided in the cache memory of the data transfer controller, and the data write request or the data read request control information is stored in the buffer memory.
Regarding Claim 11:
AKITA in view of Iwanir discloses:
… receive an infection detection request from a detection device;
perform feature extraction on target data in response to the infection detection request to obtain a data feature of target data; and
output the data feature to the detection device, wherein the data feature for detecting whether the target data is infected by a virus. (disclosed in claim 1)
However, AKITA in view of Iwanir does not explicitly disclose:
An interface card, comprising:
an interface, configured to;
install the interface card in a storage …. and
communicate with a central processing unit {CPU l of the storage ….after
being installed in the storage ….and
at least one processor configured to execute a computer program to cause the interface card to:….
In an analogous reference Izuta discloses:
An interface card, comprising:
an interface, configured to;
install the interface card in a storage …. (Para.0032, Para.0037; “storage apparatus 100”, “111 is configured by using an NIC (Network Interface Card)”100 contains 110, containing 111, 111 is configured by using an NIC (Network Interface Card)) and
communicate with a central processing unit {CPU) of the storage ….after
being installed in the storage …. (Para.0017, Para.0037; “hardware configuration of a front-end I/F unit 110”, “The external communication I/F 111 is configured by using an NIC (Network Interface Card) ….. the coupled communication network….The processor 112 is configured by using a CPU (Central Processing Unit)” 110 contains 111 and 112) and
at least one processor (Para.0037; “… The processor 112 is configured by using a CPU (Central Processing Unit)”) configured to execute a computer program to cause the interface card to:….
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify AKITA in view of Iwanir’s method for performing virus detection processing for detecting a computer virus by enhancing AKITA in view of Iwanir’s method to include Izuta’s method for controlling the storage apparatus.
The motivation: A Network Interface Card (NIC) enables a device to connect to a network.
With respect to dependent claim 12, corresponding reasoning was given earlier in this section with respect to claim 2; therefore, claim 12 rejected, for similar reasons, under the grounds as set forth for claim 2.
Regarding Claim 13:
AKITA in view of Iwanir and further in view of Izuta discloses:
The interface card of claim 12, wherein the interface is further configured to communicate with a …. through a network, (disclosed in claim 11) to receive the target data from the …. performing … on the target data…..(AKITA, Para.0069, Para.0070; “receiving a virus scan request”, “The virus scan request includes …. data to be scanned”)
…. communicate with a host …. to receive the …. data from the host, (Iwanir, Para.0031; “the component retrieves a file ….. generated by a … cloud …. system….”) and wherein performing the feature extraction comprises performing a calculation on the …..data to generate the data feature. (Iwanir, Para.0019; “use data analytics to ….distinguish between legitimate changes and malicious changes…. use …..techniques, such as …. an evolutionary algorithm, …. to detect malicious changes…. collect various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes ….”)
Regarding Claim 15:
AKITA in view of Iwanir and further in view of Izuta discloses:
The interface card of claim 11, wherein the at least processor is further configured to execute the computer program to cause the interface card to:
Receive a write request from a host;
perform the feature extraction in response to the write request and prior to the target data being written into a target storage space of the storage device, wherein the write request carries the target data, and wherein the target storage space is a persistent storage space provided by the storage device; and
store the data feature as metadata of the target data in the target storage space, (disclosed in claim 6) wherein …. the infection detection request……(disclosed in claim 1)
….. obtaining the data feature based on the …. comprises: obtaining the data feature from the metadata based on the ….. (Iwanir, Para.0019, Claim.19,Para.0032; “collect various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes …”, “the extracted features indicate that a change is determined to be malicious”, “determine whether a file event may be a result of a malicious change”)
Regarding Claim 16:
AKITA in view of Iwanir and further in view of Izuta discloses:
A storage device, comprising:
an interface card configured to communicate with a host, wherein the
storage device is configured to provide a storage service for the host; and
at least one processor, configured to execute a computer program to cause the storage device to:
receive an infection detection request from a detection device;
perform feature extraction on target data in response to the infection
detection request to obtain a data feature of target data; and
output the data feature to the detection device, wherein the data feature is for detecting whether the target data is infected by a virus. (disclosed in claim 1 and 11)
With respect to dependent claim 17, corresponding reasoning was given earlier in this section with respect to claim 2; therefore, claim 17 rejected, for similar reasons, under the grounds as set forth for claim 2.
Regarding Claim 18:
AKITA in view of Iwanir and further in view of Izuta discloses:
The storage device of claim 17, wherein the at least one processor is at least one CPU of the storage device, and wherein the at least one processor is further configured to: perform; during the first process, …. on the target data …. (AKITA, Para.0039; “If any computer virus has been detected by the virus scan, the antivirus software ….. executes … harmless processing… harmless processing includes processing such as … (removing) computer viruses from …infected files…. isolating the infected files within a specific area” executing harmless processing is construed as the first process)
perform; during the …. process, (Iwanir, Claim.10, Para.0024, Para.0028, “extracting features relating to the file and …. detect whether the extracted features indicate that a change appears to be malicious”, “direct anti-virus software to identify malware that caused the change (e.g., by running a scan of files based on …. ransomware)”, “The antivirus software may scan …. activity of the client device to determine whether the client device may be infected with ransomware or other malware”) a calculation on the …. data to generate the data feature. (Para.0019; “use data analytics to ….distinguish between legitimate changes and malicious changes…. use ….. an …. algorithm, …. to detect malicious changes…. collect various features ….”)
With respect to dependent claims 14 and 19, corresponding reasoning was given earlier in this section with respect to claim 4; therefore, claims 14 and 19 rejected, for similar reasons, under the grounds as set forth for claim 4.
With respect to dependent claim 20, corresponding reasoning was given earlier in this section with respect to claim 8; therefore, claim 20 rejected, for similar reasons, under the grounds as set forth for claim 8.
Regarding Claim 21:
AKITA in view of Iwanir and further in view of Izuta discloses:
The method of claim 6, wherein …. the target data based on the infection detection request…. (disclosed in claim 8)
….performing feature extraction on ….data to obtain the data feature of the …. data based on the …. comprises obtaining the data feature from the metadata based on the ….. (Iwanir, Para.0019, Claim.19,Para.0032; “collect various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes …”, “the extracted features indicate that a change is determined to be malicious”, “determine whether a file event may be a result of a malicious change”)
Claim 7 is rejected under AIA 35 U.S.C. 103 as being unpatentable over AKITA et al (US 20180121653 A1) in view of Iwanir et al. (US 20180034835 A1) also in view of Izuta et al. (US 20150058658 A1) and further in view of ZHANG et al. (CN 114896086 A)
Regarding Claim 7:
AKITA in view of Iwanir in view of Izuta discloses:
The method of claim 6, further comprising …. storage space of the storage device ….. and …. storing …. the …. data in the target storage space. (AKITA, Para.0139, Para.0070; “each MFP 10 is capable of …. storing data”, “data to be scanned …. performed by the ….. apparatuses…. data stored in the ….directory …. of the MFP 10a”)
…. storing the data feature as metadata of the …. data in the …storage space. (Iwanir, Para.0017, Para.0019; “changes in … files …on the files stored on the …. storage of a client device”, “various features such as the number and frequency of file changes, the location of file changes, the patterns of the changes….”)
However, AKITA in view of Iwanir in view of Izuta does not explicitly disclose:
…. dividing a storage space …. into a metadata storage space dedicated for metadata storage and a non-metadata storage space not dedicated for metadata storage….
….…..storing the data ….as the metadata of the data ….storage space comprises: storing the …. metadata in the metadata storage space….
In an analogous reference ZHANG discloses:
…. dividing a storage space …..into a metadata storage space dedicated for metadata storage (Claim 1, Page. 12; “the target storage space is a storage space for persistent storage data”, “The format of …. the persistent file ….include total message length and message content, and the total length of the message occupies 4 bytes” the target storage space is a storage space for persistent storage data is construed as ‘a metadata storage space dedicated for metadata storage’) and a non-metadata storage space not dedicated for metadata storage…. (Abstract; “adding …. to the first storage space; the first storage space is the storage space of non-persistent storage data”)
….…..storing the data ….as the metadata of the data ….storage space comprises: storing the …. metadata in the metadata storage space…. (Contents of the Invention; “…. corresponding to the target storage space stored by persistent storage….”)
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify AKITA in view of Iwanir in view of Izuta’s method for performing virus detection processing for detecting a computer virus by enhancing AKITA in view of Iwanir in view of Izuta’s method to include ZHANG’s method of data writing speed of the target storage space.
The motivation: Dedicating a separate storage space for metadata improves system maintainability, search efficiency, governance, and long-term data accessibility.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAYEDA SALMA NAHAR whose telephone number is (703)756-4609. The examiner can normally be reached M-F 12:00 PM to 6:00 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached on (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAYEDA SALMA NAHAR/Examiner, Art Unit 2435
/BEEMNET W DADA/Primary Examiner, Art Unit 2435