Invalidity dossier
US 10567413
Rule-based network-threat detection
Current assignee: Palo Alto Networks, Inc.
Added 8/30/2026, 4:49:28 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
Based on searches of USPTO/Google Patents records, RPX, Unified Patents, CourtListener, and Federal Circuit/PACER-derived sources, here is my summary of US 10,567,413 B2. I confined the analysis to this exact patent number and did not substitute similar numbers (e.g., 9,413,722 or 10,530,903).
US Patent 10567413B2 — Core Data
| Field | Value |
|---|---|
| Title | Rule-based network-threat detection |
| Patent No. | US10567413B2 (U.S. 10,567,413 B2) |
| Application No. | US16/217,720 |
| Filing date | December 12, 2018 (continuation of Ser. No. 15/827,477, filed Nov. 30, 2017, a continuation of Ser. No. 14/690,302, now US 9,755,576, filed Apr. 17, 2015) |
| Priority date | April 17, 2015 |
| Issue date | February 18, 2020 |
| Assignee | Centripetal Networks LLC (listed as Centripetal Networks, Inc. at grant; name changed to Centripetal Networks, LLC per 2023 USPTO assignment records) |
| Inventors | David K. Ahn; Keith A. George; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry; Jonathan R. Rogers |
| Status on USPTO/Google Patents | "Active" (anticipated expiration 2035-04-17) — but see validity status below, which materially qualifies this |
Abstract (verbatim)
"A packet-filtering device may receive packet-filtering rules configured to cause the packet-filtering device to identify packets corresponding to network-threat indicators. The packet-filtering device may receive packets and, for each packet, may determine that the packet corresponds to criteria specified by a packet-filtering rule. The criteria may correspond to one or more of the network-threat indicators. The packet-filtering device may apply an operator specified by the packet-filtering rule. The operator may be configured to cause the packet-filtering device to either prevent the packet from continuing toward its destination or allow the packet to continue toward its destination. The packet-filtering device may generate a log entry comprising information from the packet-filtering rule that identifies the one or more network-threat indicators and indicating whether the packet-filtering device prevented the packet from continuing toward its destination or allowed the packet to continue toward its destination."
Independent Claims — Plain-Language Overview
The patent has 20 claims (all of which were challenged in IPR). Independent claim 1 is a method claim; the exact full text of the other independent claim(s) was not verified in my searches, so treat that part as uncertain. What I can confirm:
Claim 1 (method) — A packet-filtering device located at the boundary between a protected network and an unprotected network:
- Receives threat identifiers from multiple network-threat-intelligence providers.
- Receives packets, and when a first packet matches a packet-matching criterion specified by a packet-filtering rule, applies the rule's operator (e.g., ALLOW/BLOCK) to the packet.
- Generates a packet-log entry containing the corresponding threat identifier.
- Counts how many network-threat-intelligence providers supplied that threat identifier.
- Computes a score for the threat identifier based at least on that provider count.
- Generates an ordered listing of threat identifiers whose positions depend on the computed score.
- Reconfigures at least one packet-filtering rule based on the generated listing. (Source: RPX first-claim text for US10567413B2: https://insight.rpxcorp.com/patent/US10567413B2)
Dependent claims 6–8, 15, and 20 further detail the score-determination process (per the Fed. Cir. summary in Vitallaw/IP Law Daily). I could not verify the full text of any additional independent claims (e.g., a device- or media-type claim) with the sources available, so I flag that as a gap rather than guess.
Validity / Litigation Status (important caveat to the "Active" label)
- IPR2021-01149 (Palo Alto Networks, Inc. v. Centripetal Networks, Inc., filed July 23, 2021): The PTAB instituted review of all claims 1–20 and, in a Final Written Decision dated February 17, 2023, found all challenged claims unpatentable as obvious under 35 U.S.C. § 103 over the Sourcefire 3D System User Guide and Macaulay (U.S. 2015/0207809), with Maestas (U.S. 9,342,691) for certain dependent claims. (Sources: Unified Patents portal; ex-parte.com IPR docket summary; CourtListener.)
- CAFC Appeal No. 23-1785 (Centripetal Networks, LLC v. Palo Alto Networks, Inc.): On October 31, 2024, the Federal Circuit affirmed the PTAB's unpatentability findings; PACER docket shows the judgment "AFFIRMED." (Sources: CourtListener opinion PDF; Vitallaw IP Law Daily, Oct. 31, 2024; PatSnap litigation summary citing PACER.)
- The Google Patents page also lists related litigation: E.D. Va. cases 1:21-cv-00313 and 2:21-cv-00137 (Centripetal v. Palo Alto Networks), and a separate CAFC matter 23-1785. PatSnap characterizes the CAFC affirmance as ending enforcement of this patent.
Uncertainty Notes
- Conflicting status indicators: USPTO/Google Patents still label the patent "Active," while post-IPR sources describe the claims as cancelled/unpatentable following the affirmed Final Written Decision. I cannot independently confirm whether USPTO has formally recorded claim cancellation; the IPR/CAFC outcome is the current ground truth for validity.
- "CAFC 2026 dockets": My search surfaced a Bloomberg Law item dated June 10, 2026 (a date after today's stated date of April 26, 2026) reporting a Federal Circuit affirmance of PTAB unpatentability decisions in IPRs by Keysight and Palo Alto Networks involving a Centripetal secured-network patent — but that item appears to concern a different Centripetal patent, and its future date makes me unable to verify it. I also found a reference to CAFC appeal 25-1167 being reactivated (Dec. 2025) in the related E.D. Va. case 2:21-cv-00137, but I could not confirm whether that appeal involves US10567413. Treat these as unverified leads, not findings.
- Claim text: Only claim 1's text was verified from a secondary source (RPX); I did not access the USPTO full-text claims for the remaining independent/dependent claims in this session.
Key sources: https://patents.google.com/patent/US10567413/en ; https://insight.rpxcorp.com/patent/US10567413B2 ; https://portal.unifiedpatents.com/ptab/case/IPR2021-01149 ; https://www.courtlistener.com/opinion/[10171831](/patent/10171831)/ ; https://www.vitallaw.com/news/patent-fed-cir-invalidity-of-centripetal-s-network-threat-detection-patent-affirmed-on-appeal/
Generated 8/30/2026, 6:47:33 PM
Cases on file (3)
Group view →Specific litigation cases in our database that name US patent 10567413. The free-form analysis below may also discuss cases beyond this list.
- Palo Alto Networks, Inc. v. Centripetal Networks, Inc.filed Jul 23, 2021IPR2021-01149Patent Trial and Appeal Board (PTAB)terminated Feb 17, 2023Final Written Decision - all claims unpatentable; appealed
Defendants: Centripetal Networks, Inc.
- Centripetal Networks, Inc. v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137 (orig. 1:21-cv-00313)U.S. District Court for the Eastern District of Virginia, Norfolk Division (originally Alexandria Division)Judgment as a matter of law granted in part and denied in part; new trial denied; dismissed in part as of October 3, 2024
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10785266, 10567343, 10091246, 10567437, 10530903, 10659573, 10757126, 10542028, 10503899, 10735380, 10749906, 10931797
- Centripetal Networks, LLC v. Palo Alto Networks, Inc.filed Mar 12, 20212:21-cv-00137U.S. District Court for the Eastern District of Virginia, Norfolk Divisionpost-judgment proceedings/appeal ongoing
Defendants: Palo Alto Networks, Inc.
Other patents asserted: 10749906, 10091246, 10503899, 10530903, 10542028, 10567343, 10567437, 10659573, 10735380, 10757126, 10785266, 10931797
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
Litigation Involving U.S. Patent No. 10,567,413 ("Rule-Based Network-Threat Detection")
Based on searches of PTAB records, PACER-derived dockets, and Federal Circuit opinions, the known litigation involving U.S. Patent No. 10,567,413 (the "'413 patent") is a single dispute between Centripetal Networks and Palo Alto Networks, spanning a district court case, an IPR before the PTAB, and a Federal Circuit appeal. The patent's claims were ultimately held unpatentable and the Federal Circuit affirmed.
1. District Court: Centripetal Networks, Inc. v. Palo Alto Networks, Inc.
- Plaintiff: Centripetal Networks, Inc. (later Centripetal Networks, LLC)
- Defendant: Palo Alto Networks, Inc.
- Jurisdiction / Case No.: U.S. District Court for the Eastern District of Virginia. Filed in the Alexandria Division as 1:21-cv-00313 on March 12, 2021, then transferred intradistrict to the Norfolk Division and assigned 2:21-cv-00137 (Judge Elizabeth W. Hanes; Magistrate Judge Lawrence R. Leonard).
- Filing date: March 12, 2021
- Cause of action: Patent infringement, 35 U.S.C. § 271 (jury demanded). Centripetal alleged infringement of thirteen patents — including the '413 patent — with twenty-six counts of direct and indirect infringement, and sought damages, treble damages for willfulness, and injunctive relief.
- Status / key events:
- In 2022, the court (Judge Young) granted Palo Alto's motion to stay pending IPR, denied Centripetal's motion to disqualify Ropes & Gray, and denied the motion to dismiss without prejudice.
- After the PTAB's February 17, 2023 Final Written Decision invalidating all claims of the '413 patent, the '413 patent claims were effectively resolved (the patent was cancelled).
- The case continued as to the other asserted patents, and a jury trial proceeded in January–February 2024 before Judge Hanes (trial transcripts on file for January 29–31, 2024). The '413 patent itself was no longer enforceable following the IPR.
2. PTAB / IPR: Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Petitioner: Palo Alto Networks, Inc.
- Patent Owner: Centripetal Networks, Inc.
- Case No.: IPR2021-01149
- Petition filed: July 23, 2021
- Institution decision: February 22, 2022
- Final Written Decision: February 17, 2023 (Paper 46) — all claims 1–20 held unpatentable under 35 U.S.C. § 103 as obvious over the Sourcefire 3D System User Guide and U.S. Patent Application Publication No. 2015/0207809 (Macaulay), with a third reference (U.S. Patent No. 9,342,691 / Maestas) for certain dependent claims (claims 3, 13, 18).
- Panel: Administrative Patent Judges Brian J. McNamara (author), Kevin F. Turner, and Lynne E. Pettigrew.
- Status: Final Written Decision; appealed by Centripetal.
3. Federal Circuit Appeal: Centripetal Networks, LLC v. Palo Alto Networks, Inc.
- Appellant: Centripetal Networks, LLC
- Appellee: Palo Alto Networks, Inc.
- Case No.: 23-1785 (Court of Appeals for the Federal Circuit)
- Filing date: Appeal docketed in 2023 (appeal of IPR2021-01149).
- Decision: October 31, 2024 — the Federal Circuit AFFIRMED the PTAB's unpatentability determination. The court upheld the Board's constructions and findings on the "boundary" limitation (citing the patent's Figure 2A) and the reputation-based "score" limitation, and rejected Centripetal's arguments on dependent claims 6–8, 15, and 20.
- Status: Affirmed. Per PACER, the mandate ordered "AFFIRMED," meaning the cancellation of all claims of the '413 patent is final and the patent is no longer enforceable.
Summary of current status
U.S. Patent No. 10,567,413 was asserted by Centripetal only against Palo Alto Networks in the E.D. Va. action (1:21-cv-00313 / 2:21-cv-00137). All claims were invalidated in IPR2021-01149 (Feb. 17, 2023), and that invalidity was affirmed by the Federal Circuit on October 31, 2024. I found no other district court, ITC, or PTAB matters specifically naming the '413 patent against other defendants (related Centripetal litigation against Cisco and Keysight involves different patents, e.g., U.S. Patent No. 9,917,856, not the '413 patent).
Sources: Google Patents family/litigation metadata for US10567413; Unified Patents portal (IPR2021-01149); PACER-derived dockets via DocketAlarm and Justia (2:21-cv-00137; 1:21-cv-00313); Federal Circuit opinion in Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 23-1785 (Fed. Cir. Oct. 31, 2024) (CourtListener); Patexia case summary IPR2021-01149; Ex Parte/PTAB case pages; Vitallaw IP Law Daily summary (Oct. 31, 2024).
Note: I treated "10567413" and "10,567,413" as the same patent (U.S. Patent No. 10,567,413), which is the correct literal reading of the identifier. I did not find any litigation involving a distinct "10567343" or similar neighboring numbers in connection with this patent's litigation history.
Generated 8/30/2026, 6:47:31 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Palo Alto Networks, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I have strong initial results. IPR2021-01149 (Palo Alto Networks v. Centripetal) is confirmed as the key proceeding — the ODP block says "no proceedings," but the Google Patents page itself and multiple PTAB databases show IPR2021-01149. Let me verify the institution decision details, panel composition, and the CAFC appeal, plus check for any other IPRs on this exact patent.
The core picture is confirmed. Let me verify the CAFC appeal details (case 23-1785), check for any cert petition, and confirm whether any other IPR/PGR was filed against this specific patent.
Proceedings overview
One IPR proceeding is on file for US 10,567,413 — IPR2021-01149 (Palo Alto Networks v. Centripetal) — which went to a Final Written Decision canceling all 20 claims, was affirmed by the Federal Circuit on 2024-10-31, and is fully terminated. ⚠️ Discrepancy to flag: the structured "PTAB proceedings on file" block states the USPTO ODP API returned no AIA trial proceedings, but that ingest is stale/incomplete — the Google Patents record for this patent itself lists "PTAB case IPR2021-01149 (Final Written Decision)," and the proceeding is confirmed across USPTO-based PTAB databases (Unified Patents portal, Patexia, DocketAlarm). The correct count is one IPR, fully concluded, all claims invalidated, affirmance on appeal. The bottom-line defensive posture is the strongest possible: every claim of US10567413 has been canceled and the cancellation is final — a demand letter citing any claim of this patent has no case, and the patent is unenforceable against anyone, not just Palo Alto.
IPR2021-01149 — Palo Alto Networks, Inc. v. Centripetal Networks, Inc.
- Type: Inter Partes Review (35 U.S.C. § 311)
- Filed: 2021-07-23
- Status: Final Written Decision — terminated 2023-02-17; appeal to the Federal Circuit affirmed 2024-10-31 (nonprecedential); mandate issued. No proceeding remains active. (The ODP block says "no AIA trial proceedings" — that is incorrect/stale; see overview above.)
- Judge panel: APJ Brian J. McNamara (author of the Final Written Decision), APJ Kevin F. Turner, APJ Lynne E. Pettigrew. PTAB docket records also list APJs Jon Jurgovan and Steven Amundson in connection with the proceeding (motion/other panels). (Patexia summary; Unified Patents portal)
- Petition grounds: All claims 1–20, all under § 103:
- Ground 1 — obviousness over the Sourcefire 3D System User Guide v4.10 ("Sourcefire") + U.S. Patent App. Pub. 2015/0207809 ("Macaulay"), asserted against claims 1–20. Sourcefire was mapped to the packet-filtering device, filtering rules, log entries, and ALLOW/BLOCK operators; Macaulay was mapped to the reputation/risk "score" based on the number of network-threat-intelligence providers.
- Ground 2 — obviousness over Sourcefire + Macaulay + U.S. Patent 9,342,691 ("Maestas"), asserted against dependent claims 3, 13, and 18 (the score further based on geographic information).
- Petitioner's expert was Dr. Wenke Lee (Ex. 1003); petitioner's proposed construction of "threat identifier" was not adopted — the Board applied plain and ordinary meaning.
- Institution decision: Instituted on all challenged claims — Decision to Institute dated 2022-02-22 (institution phase finding a reasonable likelihood for claims 1–20 on Ground 1 and claims 3, 13, 18 on Ground 2). Notably, the Board rejected Centripetal's § 325(d) discretionary-denial argument, finding material error in the Office's treatment of Macaulay: the Examiner appears to have located Macaulay the same day as the Notice of Allowance was mailed, with no substantive analysis on the record. (Institution-decision text quoted at DocketAlarm Ex. 2020; see also Unified Patents portal)
- Final Written Decision: Issued 2023-02-17, Paper 46, 58 pages — "Final Written Decision Determining All Challenged Claims Unpatentable 35 U.S.C. § 318(a)." Every challenged claim — claims 1–20, including independent claims 1, 11, and 16 and all dependents — was held unpatentable under § 103. The Board found claims 1–20 obvious over Sourcefire + Macaulay, and claims 3, 13, 18 additionally obvious over that combination with Maestas (the CAFC described these as "three dependent claims ... based on a combination of those two references and a third reference"). The Board applied plain and ordinary meaning (no express constructions disputed) and found Sourcefire (User Guide plus the Installation Guide introduced by Centripetal) taught the "packet-filtering device located at a boundary" and the filtering/operator/logging framework, with Macaulay supplying the multi-provider reputation-scoring limitation. (Paper 46 cited in Unified Patents portal; FWD facts recited in the CAFC opinion.)
- Settlement / termination: No settlement. The proceeding terminated on the merits with the FWD on 2023-02-17 (no request for rehearing appears in the record, and Centripetal appealed directly).
- Appeal: Yes — Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2023-1785 (Fed. Cir.), decided 2024-10-31, nonprecedential, judgment: AFFIRMED; costs taxed against Centripetal. (CAFC opinion, Justia; CourtListener; CAFC docket entry). Centripetal raised: (1) the "boundary" limitation should require the device to be the first point of contact with the unprotected network — the court rejected this as overly restrictive under Phillips, citing the '413 patent's own Figure 2A showing tap/network devices at the edge; (2) the score-determination limitation and motivation-to-combine findings — rejected as supported by substantial evidence; (3) teaching away — the court conceded the Board misstated the Syntex standard (converting a sufficient condition into a necessary one) but held the error harmless because the Board applied the correct rule in finding no teaching away; and (4) petition sufficiency (a cross-reference label allegedly limiting the ground to Macaulay alone) — rejected. An errata was filed 2024-11-04; no certiorari petition is reflected in the record as of this research.
- Defensive value: Maximum. All 20 claims were canceled by the FWD, and the CAFC affirmed. Under § 318(b) the claims were canceled from the patent; there is no claim left to infringe. Any demand or complaint on US10567413 is dead on arrival — the proper response is to cite Paper 46 and the affirmance and put Centripetal to its Rule 11 obligations. For Palo Alto Networks, § 315(e)(2) estoppel is now largely academic because the claims are gone; for any other defendant, cancellation is inter partes as to the patent itself — the claims cannot be asserted against anyone.
Strategic summary
Claim status: ALL claims CANCELED. US10567413 has exactly 20 claims (1–20), all challenged in IPR2021-01149, all held unpatentable under § 103 in the 2023-02-17 FWD, and all confirmed on appeal (CAFC 2023-1785, 2024-10-31). There are no sustained claims and no untested claims — the patent is a hollow shell. This is the rare end-state where the claims have been canceled (not merely held invalid as to one defendant), so the cancellation has effect against the world: the USPTO's certificate will reflect cancellation, and no future infringement suit on this patent can survive. The only remaining "risk" is Centripetal's broader family (e.g., US 10,542,028, 10,757,126, 10,706,388, 9,413,722, and later continuations such as US 11,722,073 / 12,015,626), which share the same specification — but note the coordinated IPRs on the '028/'126 patents (IPR2021-01147 and IPR2021-01148) also ended in unpatentability FWDs affirmed the same day in CAFC 2023-1654, and other family members have faced parallel challenges (e.g., the '856 patent IPR where Cisco and Keysight joined PAN).
Estoppel landscape. Because all claims are canceled, § 315(e)(2) estoppel questions are moot for this patent — there is nothing left to re-litigate. For a new defendant facing a different family member, PAN's estoppel does not bind you (you are not PAN's privy), so the Sourcefire / Macaulay / Maestas combination — now judicially blessed as invalidating — remains fully available, as do any additional § 102/103/§ 112 grounds. The CAFC's affirmance is persuasive (though nonprecedential) authority that rule-based network-threat-detection claims of this type face a high validity bar; the Board's material-error finding on Macaulay's non-consideration is a useful model for overcoming § 325(d) discretionary denial in follow-on petitions.
Pattern signals. One petitioner drove this outcome: Palo Alto Networks filed a coordinated three-petition campaign (IPR2021-01147/01148/01149) against the same-specification family, and won all three — a textbook example of parallel-family IPR strategy. Centripetal is a litigation-aggressive assertion entity (March 2021 E.D. Va. suits asserting twelve patents against PAN; separate litigation against Cisco and Keysight; CAFC appeals in both 2023-1654 and 2023-1785), and it lost both appeals. Note: the "Unified Patents" attribution on the Google Patents page is only a Creative Commons data-license credit for the PTAB/litigation data feed — Unified Patents was not the petitioner here; Palo Alto Networks was. No other IPR, PGR, or CBM has been filed on US10567413.
Recommended next steps
- If Centripetal (or any assignee) contacts you about US10567413: treat the demand as baseless and respond with the dispositive record — IPR2021-01149 Final Written Decision, Paper 46 (2023-02-17), Palo Alto Networks, Inc. v. Centripetal Networks, Inc., holding "All Challenged Claims Unpatentable" (claims 1–20 under § 103), and the Federal Circuit's affirmance in Centripetal Networks, LLC v. Palo Alto Networks, Inc., No. 2023-1785 (Fed. Cir. 2024-10-31) ("JUDGMENT. AFFIRMED"). The PTAB's FWD and the CAFC opinion are public: USPTO PTAB E2E (ptab.uspto.gov, search IPR2021-01149), the Unified Patents PTAB portal, and Justia for the CAFC opinion. Under § 318(b) the claims have been canceled — there is no enforceable claim; if a complaint is filed anyway, move to dismiss (failure to state a claim) and consider Rule 11 sanctions.
- No active PTAB proceedings exist, so there are no institution deadlines, oral-hearing dates, or FWD due dates to calendar.
- Watch the family, not this patent. Centripetal's remaining value is in continuations/related patents (US 10,542,028, 10,757,126, 10,706,388, US 11,722,073, US 12,015,626, and the '856 patent family). If you are sued on one of those, file your own IPR promptly (the one-year § 315(b) bar runs from service) and reuse the Sourcefire/Macaulay/Maestas combination plus any additional art — the Board and CAFC have already validated that combination against this specification, and you are not estopped by PAN's petitions.
- Correct the record internally: the ODP-derived "no PTAB activity" note in your intake system is wrong for this patent — update it to reflect IPR2021-01149 and the final cancellation, so no one in your organization relies on the stale "no proceedings" flag when evaluating exposure on US10567413.
Generated 8/30/2026, 6:48:15 PM
Ownership chain (2)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2023-01-20 · Assignment
David K. Ahn; Keith A. George; Peter P. Geremia; Pierre Mallett III; Sean Moore; Robert T. Perry; Jonathan R. RogersCentripetal Networks, Inc.
acquisition
? · recorded 2023-01-20 · Change of Name
Centripetal Networks, Inc.Centripetal Networks, Inc.
change of name only
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
Rule-Based Network-Threat Detection — US 10567413
Assignment-chain reconstruction and NPE analysis
Source basis. The two recorded assignment events below are the ones surfaced in the USPTO-derived legal-events feed on Google Patents for this patent. I attempted to pull reel/frame numbers and correspondent names from the USPTO Assignment Center and secondary indexes, but the captured search results did not include the reel/frame or correspondent fields for this specific patent. I have not fabricated them; verify at the USPTO Assignment Center (search "10567413"; mirror: https://assignment.uspto.gov/patent/index.html#/patent/search).
Inventors
All seven named inventors (per the patent cover and the recorded Assignment of Assignors Interest):
| Inventor | City (per cover) |
|---|---|
| David K. Ahn | Winston-Salem, NC |
| Keith A. George | Fort Royal, VA |
| Peter P. Geremia | Portsmouth, NH |
| Pierre Mallett, III | Herndon, VA |
| Sean Moore | Hollis, NH |
| Robert T. Perry | Ashburn, VA |
| Jonathan R. Rogers | Hampton Falls, NH |
Employer at filing: All seven assigned to Centripetal Networks, Inc., Portsmouth, NH — the applicant/assignee on the face of the patent and throughout the family (e.g., US 10,542,028, US 10,757,126, US 11,516,241 all show the same inventor roster assigned to Centripetal Networks, Inc., Portsmouth, NH). They were Centripetal employees/affiliates at the time of the underlying 2015–2018 filings.
Unusual patterns: None. The same inventors continue to appear on Centripetal applications filed as late as April 2022 (US 11,516,241 B2), i.e., no mass-departure-then-fire-sale pattern. Note: founder/CEO Steven Rogers is not an inventor on this patent (he is an inventor on other Centripetal patents, e.g., US 9,565,213).
Original assignee
Centripetal Networks, Inc. (Portsmouth, NH), renamed Centripetal Networks, LLC (recorded 2023-01-20).
- Product: Yes — Centripetal ships the CleanINTERNET network-threat-detection/security platform; the '413 claims (packet filtering at a network boundary driven by threat-intelligence rules) map directly onto that product line.
- Line of business: Cybersecurity — rule-based network threat detection and filtering.
- Current status: Operating and privately held (not acquired, not dissolved, not in bankruptcy). The company has been an aggressive patent enforcer against firewall competitors: it sued Cisco (E.D. Va. 1:21-cv-00313) and Palo Alto Networks (E.D. Va. 2:21-cv-00137, filed 2021-03-12, which asserted the '413 patent among 13+ family patents), plus LookingGlass Cyber Solutions (E.D. Va. 1:21-cv-01051). Context: all claims of the '413 patent were held unpatentable in IPR2021-01149 (Final Written Decision Feb. 17, 2023), affirmed by the Federal Circuit Oct. 31, 2024 (Case 23-1785) — validity outcome, not an ownership signal.
Assignment timeline
Per the Google Patents legal-events feed (mirroring USPTO assignment records), two recorded assignment events exist for US 10567413. Reel/frame and correspondent-of-record were not captured in the available sources — flagged below rather than guessed.
Executed: not shown in available data (likely 2018 or earlier, contemporaneous with filing) / recorded 2023-01-20 — Reel not captured / NNNNNN/NNNN (verify at Assignment Center)
- Conveyance: Assignment of Assignors Interest
- Assignor: David K. Ahn; Keith A. George; Peter P. Geremia; Pierre Mallett, III; Sean Moore; Robert T. Perry; Jonathan R. Rogers
- Assignee: Centripetal Networks, Inc.
- Correspondent: not captured
- Context: Original inventors→company assignment recorded ~3 years after grant and ~22 months after the March 2021 infringement suits — a late chain-of-title perfecting recording made during active litigation, not a transfer of control.
Executed / recorded 2023-01-20 — Reel not captured / NNNNNN/NNNN (verify at Assignment Center)
- Conveyance: Change of Name ("SEE DOCUMENT FOR DETAILS")
- Assignor: Centripetal Networks, Inc.
- Assignee: Centripetal Networks, LLC
- Correspondent: not captured
- Context: Corporate entity-type conversion / name change only — same operating company, no change in economic ownership. Recorded the same day as the inventors' assignment, consistent with a single standing-cleanup filing.
No post-issuance transfer to any third party (no NPE, no shell LLC, no defensive aggregator, no security agreement) appears in the surfaced records. Caveat: the USPTO Assignment Center may contain additional conveyances (e.g., licenses or security interests) not surfaced in the legal-events feed; reel/frame confirmation is recommended via the search link above.
Timeline diagram
timeline
title Ownership of US 10567413
2015 : Filed by Centripetal Networks Inc
2018 : Continuation filed
2020 : Patent issued
2021 : Suits vs Cisco and Palo Alto
: IPR filed by Palo Alto
2023 : Inventor assignment recorded
: Name change to Centripetal Networks LLC
2024 : Fed Circuit affirms invalidity
NPE / troll-pattern signals
Shell-entity transfer — not present. The only assignee change is a same-day Change of Name from Centripetal Networks, Inc. to Centripetal Networks, LLC (recorded 2023-01-20). The "LLC" is the operating company itself (Portsmouth, NH, shipper of CleanINTERNET), not a licensing shell, registered-agent address, or single-purpose IP LLC. No "IP Holdings / Ventures / Licensing" vehicle appears anywhere in the chain.
Known asserter in the chain — not present on the classic NPE lists (Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Conversant/Mosaid, Vringo, Pendrell, Innovatio, MPHJ, Round Rock, Spangenberg entities). Centripetal Networks, LLC is a high-frequency plaintiff in cybersecurity patent litigation (Cisco, Palo Alto Networks, LookingGlass), but it is an operating company asserting its own products' patents, and no public NPE directory lists it as an NPE. Unified Patents appears in the Google Patents litigation metadata only as the PTAB-data provider for IPR2021-01149 — the actual petitioner there was Palo Alto Networks, Inc., not Unified.
Repeat correspondent across the chain — unclear. Correspondent names for the two 2023-01-20 recordings were not captured in the available sources. Both filings share a recording date, which often means a single counsel filed them together, but I cannot cite a correspondent name or firm, so this signal is unverified rather than present.
Cascading transfers — not present. Only two assignments, both recorded 2023-01-20: (a) inventors→Inc., (b) Inc.→LLC name change. No chained LLCs, no <24-month hopscotch, no common-principal shell series.
Pre-litigation transfer — not present. The recorded assignments post-date the first infringement suits naming this patent (E.D. Va. 2:21-cv-00137, filed 2021-03-12) by ~22 months. The Jan. 2023 recording is a during-litigation chain-of-title perfecting move (standing cleanup), the inverse of a pre-suit transfer engineered to enable venue or standing.
Bankruptcy fire-sale — not present. Centripetal is not in Chapter 7/11; no bankruptcy sale of this patent.
Privateering — not present. Centripetal asserts its own patents against direct competitors (Cisco, Palo Alto Networks, LookingGlass); there is no SEC or EFF/Patent Progress evidence of an operating company using Centripetal as a front to attack rivals.
Defensive aggregator (anti-NPE) — not present. The chain terminates at Centripetal Networks, LLC — an assertive operating company — not at RPX, AST, LOT Network, Unified Patents, or OIN. The patent was not neutralized by acquisition; it was invalidated by IPR, which is a different outcome.
Verdict
Operating-company assertion.
The chain of title is clean and benign: inventors → Centripetal Networks, Inc. → Centripetal Networks, LLC (name change), both recorded 2023-01-20, with no transfer to any shell, NPE, aggregator, or third party. The current assignee is the same operating company that ships CleanINTERNET and that filed infringement suits against Cisco and Palo Alto Networks (E.D. Va., March 2021) naming this patent — textbook operating-company assertion against actual competitors. The only wrinkle (a late, litigation-era recording of the inventors' assignment) is a standing-perfecting formality, not a troll signal; the absence of reel/frame and correspondent data in the sources I could reach means those fields should be confirmed at the USPTO Assignment Center (search "10567413"), but nothing in the available record supports an NPE characterization.
Generated 8/30/2026, 6:48:50 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
The search results surfaced a Justia page listing references for this patent. Let me dig into the specific reference lists for US10567413 on Justia and Google Patents.
Let me try to retrieve the references cited section directly from Google Patents and Justia for this exact patent.
I've reached the search-step limit for this session, so I'll now compile the best-supported answer from what was actually retrieved, flagging every gap rather than filling it with guesses.
Important methodology caveat (read first)
I was not able to retrieve the complete USPTO "References Cited" (backward citations) list for US 10,567,413 in this session. The Google Patents full-text dump you provided is truncated before its Citations section, and my searches did not surface a complete citation list for this exact patent number. What I did verify:
- A partial, on-point reference list rendered on the Justia page for this exact patent number (
https://patents.justia.com/patent/10567413#5— the "References" tab, which mirrors USPTO citation data). The search snippet captured only the tail end of that list (31 entries, starting mid-list at publication 2012/0113987). The earlier portion of the list (older U.S. patents and publications) was not captured. - The prior art that actually decided this patent's validity — the references relied on in IPR2021-01149 (Sourcefire 3D System User Guide, Macaulay US 2015/0207809 A1, Maestas US 9,342,691) — which I already documented in the litigation summary you provided.
I will not invent titles, dates, or claim mappings for references I could not verify.
Part 1 — Face-of-patent citations verified for US 10,567,413 (partial list)
The following 31 U.S. patent publications are the tail portion of the References Cited list displayed on the Justia page for the exact patent number 10567413. Publication numbers and dates are as displayed by Justia; I did not capture titles in the snippet, so descriptions below are limited to what I can state with confidence:
| Publication No. | Publication Date | First-named Inventor (as shown) | Notes |
|---|---|---|---|
| US 2012/0113987 A1 | May 10, 2012 | Riddoch et al. | Title not captured in snippet |
| US 2012/0240135 A1 | Sep. 20, 2012 | Risbood et al. | Title not captured |
| US 2012/0240185 A1 | Sep. 20, 2012 | Kapoor et al. | Title not captured |
| US 2012/0264443 A1 | Oct. 18, 2012 | Ng et al. | Title not captured |
| US 2012/0314617 A1 | Dec. 13, 2012 | Erichsen et al. | Title not captured |
| US 2012/0331543 A1 | Dec. 27, 2012 | Bostrom et al. | Title not captured |
| US 2013/0007257 A1 | Jan. 3, 2013 | Ramaraj et al. | Title not captured |
| US 2013/0047020 A1 | Feb. 21, 2013 | Hershko et al. | Title not captured |
| US 2013/0059527 A1 | Mar. 7, 2013 | Hasesaka et al. | Title not captured |
| US 2013/0061294 A1 | Mar. 7, 2013 | Kenworthy | Title not captured (Kenworthy has multiple network-security publications) |
| US 2013/0104236 A1 | Apr. 25, 2013 | Ray et al. | Title not captured |
| US 2013/0117852 A1 | May 9, 2013 | Stute | Title not captured |
| US 2013/0139236 A1 | May 30, 2013 | Rubinstein et al. | Title not captured |
| US 2013/0254766 A1 | Sep. 26, 2013 | Zuo et al. | Title not captured |
| US 2013/0291100 A1 | Oct. 31, 2013 | Ganapathy et al. | Title not captured |
| US 2013/0305311 A1 | Nov. 14, 2013 | Puttaswamy Naga et al. | Title not captured |
| US 2014/0075510 A1 | Mar. 13, 2014 | Sonoda et al. | Title not captured |
| US 2014/0082204 A1 | Mar. 20, 2014 | Shankar et al. | Title not captured |
| US 2014/0082730 A1 | Mar. 20, 2014 | Vashist et al. | Title not captured |
| US 2014/0115654 A1 | Apr. 24, 2014 | Rogers et al. | Centripetal-family self-citation (same inventor as '413 patent) |
| US 2014/0150051 A1 | May 29, 2014 | Bharali et al. | Title not captured |
| US 2014/0201123 A1 | Jul. 17, 2014 | Ahn et al. | Centripetal-family self-citation (Ahn is a named inventor of the '413 patent; this family includes sibling "rule-based network-threat detection" applications) |
| US 2014/0215561 A1 | Jul. 31, 2014 | Roberson et al. | Title not captured |
| US 2014/0215574 A1 | Jul. 31, 2014 | Erb et al. | Title not captured |
| US 2014/0259170 A1 | Sep. 11, 2014 | Amsler | Title not captured |
| US 2014/0281030 A1 | Sep. 18, 2014 | Cui et al. | Title not captured |
| US 2014/0283004 A1 | Sep. 18, 2014 | Moore | Centripetal-family self-citation (Moore is a named inventor of the '413 patent) |
| US 2014/0283030 A1 | Sep. 18, 2014 | Moore et al. | Centripetal-family self-citation |
| US 2014/0317397 A1 | Oct. 23, 2014 | Martini | Title not captured |
| US 2014/0337613 A1 | Nov. 13, 2014 | Martini | Title not captured |
| US 2014/0366132 A1 | Dec. 11, 2014 | Stiansen et al. | Title not captured |
Confirmed gaps: (a) the beginning of the list — older U.S. patents and earlier publications — was not captured; (b) no non-patent literature citations were captured (the Sourcefire 3D System User Guide appears in the IPR record, not necessarily on the face of the '413 patent); (c) I could not confirm whether Macaulay (US 2015/0207809 A1) or Maestas (US 9,342,691 B1) appear on the face of the '413 patent — they are the IPR references, which is a different question.
Part 2 — The prior art that actually invalidated this patent (IPR2021-01149)
These are the most relevant prior art in the operative sense, per the Final Written Decision (Feb. 17, 2023) affirmed by the Federal Circuit (Oct. 31, 2024, No. 23-1785):
| Reference | Type / Date | Role in IPR | Claims affected |
|---|---|---|---|
| Sourcefire 3D System User Guide (Version 4.9-era documentation) | Non-patent literature; publicly available well before Apr. 17, 2015 | Primary obviousness reference (firewall/packet-filtering device with rule-based inspection at a network boundary, logging of hits) | Combined with Macaulay: all claims 1–20 held unpatentable under §103 |
| Macaulay — US 2015/0207809 A1 | U.S. published application; published Jul. 23, 2015 (application effectively filed before Apr. 17, 2015, qualifying under AIA §102(a)(2)) | Primary obviousness reference (network-threat-intelligence feed integration and rule-based response) | Combined with Sourcefire: all claims 1–20 |
| Maestas — US 9,342,691 B1 | U.S. patent | Secondary reference used for certain dependent claims | Claims 3, 13, 18 (with Sourcefire + Macaulay) |
Critical §102/§103 distinction: The PTAB's holding was obviousness under 35 U.S.C. § 103, not anticipation under § 102. That means the Board did not find that any single reference (Sourcefire, Macaulay, or Maestas alone) disclosed every element of the challenged claims — it found the combinations would have been obvious. If you need a strict § 102 anticipation analysis, Macaulay is the only one of the three that plausibly approaches single-reference coverage of independent claim 1's elements (multiple threat-intelligence providers → rule criteria → packet match → operator applied → log entry with threat identifier → provider count → score → ordered listing → rule reconfiguration), but the Board's decision did not rest on §102, and I cannot certify from this session's materials that Macaulay alone discloses all of those elements.
Part 3 — § 102 anticipation potential, claim-by-claim (with explicit confidence limits)
I only have verified full text for independent claim 1 (via the RPX claim summary in your prior sections), not for the remaining claims. Under AIA § 102 (the '413 family is post-AIA), the effective filing date/critical date is April 17, 2015; prior art includes (a) anything publicly available before that date (§102(a)(1)) and (b) U.S. applications effectively filed before that date even if published later (§102(a)(2)).
- Claim 1 (independent, method): The three Centripetal-family self-citations (Rogers 2014/0115654; Ahn 2014/0201123; Moore 2014/0283004 and 2014/0283030) are the strongest single-reference anticipation candidates on the face of the patent, because they are earlier-filed (pre-April-2015) sibling applications from the same inventors disclosing overlapping rule-based threat-detection systems. If any one of them alone discloses every element of claim 1 — including the provider-count scoring and ordered listing/reconfiguration steps that were the focus of the CAFC appeal — it would be a §102(a)(2) anticipation reference. I cannot confirm from this session's data that any single one of them does, and notably the IPR petitioners did not prevail on a single-reference §102 theory either. Confidence: low-to-moderate that these anticipate; high that they are the most relevant face-of-patent references for claim 1.
- Claims 2–20 (dependent): I do not have verified text for these. The IPR record shows the Board used Maestas for claims 3, 13, and 18 (combined, §103). For a §102-only analysis of the remaining dependent claims (score-determination details in claims 6–8, 15, 20; BLOCK/ALLOW operator and UI reconfiguration details elsewhere), the applicable single references would most plausibly be Macaulay (provider/threat-feed aspects) or the Sourcefire guide (operator/logging aspects) — but again, the operative finding was §103, so a single-reference §102 case on any dependent claim is not established by anything I verified.
- References I could not describe: For the 27 non-self-citation publications in Part 1 (Riddoch through Stiansen), I only verified publication number, date, and first-named inventor. I declined to guess titles or content, so I cannot responsibly map any of them to specific claim elements for §102 purposes. Several (Kenworthy; Stiansen et al.; Amsler; Martini) are in the network-security space based on general knowledge, but that is not a verified basis for an anticipation claim.
Part 4 — Bottom line and recommended next step
- Most relevant prior art (validity outcome): Sourcefire 3D System User Guide + Macaulay (US 2015/0207809 A1) for all claims 1–20, plus Maestas (US 9,342,691 B1) for claims 3, 13, 18 — but as §103 obviousness, per IPR2021-01149 FWD, affirmed in CAFC No. 23-1785.
- Most relevant face-of-patent citations for a §102 analysis: the Centripetal self-citations (Ahn 2014/0201123; Moore 2014/0283004; Moore et al. 2014/0283030; Rogers 2014/0115654), which are earlier sibling applications by the same inventors.
- Gap to close: The complete USPTO References Cited list for US 10,567,413 (including the earlier U.S. patents and any non-patent citations) was not retrievable in this session. To complete the "each citation" analysis, pull the Citations tab on
https://patents.google.com/patent/US10567413/enor the "References Cited" page in USPTO Patent Center/PAIR for application 16/217,720, and the IPR2021-01149 Final Written Decision (Paper 46) for the full prior-art record and its element-by-element mapping of claims 1–20.
Generated 8/30/2026, 6:48:57 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
Obviousness Analysis — U.S. Patent 10,567,413 B2 ("Rule-Based Network-Threat Detection")
Scope note. The user message did not actually include a "Prior Art" section, so I used the prior-art references identified in the PTAB/IPR record for this exact patent (IPR2021-01149), which the searches confirmed as the operative prior art: the Sourcefire 3D System User Guide (Version 4.10) ("Sourcefire"), U.S. Patent Application Publication 2015/0207809 ("Macaulay"), and U.S. Patent 9,342,691 ("Maestas"). These are the same references the PTAB and Federal Circuit relied on in finding all claims 1–20 unpatentable (FWD dated Feb. 17, 2023; CAFC No. 23-1785 affirmed Oct. 31, 2024).
1. The legal framework
Under 35 U.S.C. § 103, a claim is unpatentable if the differences between the claimed subject matter and the prior art are such that the subject matter as a whole would have been obvious at the time of the invention to a person having ordinary skill in the art (POSITA). The Graham factors govern: (1) scope and content of the prior art; (2) differences between the prior art and the claims; (3) level of ordinary skill; and (4) secondary considerations. KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), additionally confirms that a combination of familiar elements according to known methods that yields a predictable result, a "simple substitution of one known element for another," and the "obvious to try" of a finite number of identified, predictable solutions are each grounds for obviousness.
The Board's decision in IPR2021-01149 applied precisely this framework and found all claims 1–20 obvious. I have not been able to verify the full text of the FWD in this session, so the element-by-element mapping below is reconstructed from the petition summaries, the Board's institution decision discussion, and the CAFC affirmance as reported in the search results (cited inline). Where a detail could not be verified, I flag it.
2. Claimed subject matter (what the prior art must meet)
Claim 1 (method; reconstructed from the RPX first-claim text and the Board's limitation labels 1.pre–1.j) requires a packet-filtering device at a boundary between a protected network and an unprotected network that:
- (1.pre / 1.a) receives a plurality of threat identifiers (from a plurality of network-threat-intelligence providers) and receives a packet matching a packet-matching criterion specified by a packet-filtering rule;
- (1.b–1.e) applies the rule's operator (ALLOW/BLOCK) and generates a packet-log entry containing the corresponding threat identifier and the allow/block disposition;
- (1.f–1.h) counts the number of network-threat-intelligence providers that supplied the threat identifier, computes a score based at least on that provider count, and generates an ordered listing of threat identifiers whose positions depend on the score; and
- (1.i–1.j) reconfigures at least one packet-filtering rule based on the listing, each rule specifying at least one packet-matching criterion and at least one operator.
Dependent claims 3, 13, and 18 additionally require the score to be based on further factors, including geographic information (per the Board's Ground 2 discussion).
3. The primary references
Sourcefire 3D System User Guide, Version 4.10 (2011) — a user manual for an intrusion prevention system (IPS). Per the IPR record, Sourcefire discloses: a 3D Sensor deployed at a network boundary that receives intrusion rules from the Sourcefire Vulnerability Research Team (VRT) and from "external systems that can provide data [on] known exploits and attacks"; rules containing identifiers such as CVE ID, Bugtraq ID, and Snort ID; rules that "inspect packets against conditions specified in the rule and take a specific action if the packet triggers operation of the rule" (e.g., alert, drop, pass); generation of intrusion-event log entries for matching packets, including per-packet data and the triggering rule's identifiers; priority values associated with rules (manually assigned by the rule creator) and displayed in a workflow/event table; the ability to sort and constrain events, create custom table views keyed on threat IDs (CVE/Bugtraq) and priority; and a Rule Actions menu by which a user sets or edits a rule action (e.g., drop packets or generate events) from a generated listing. Sourcefire's status as prior art was established in the related IPR2018-01760 / Centripetal v. Cisco proceedings, where the Board and Federal Circuit held the manual was a publicly accessible printed publication (distributed on CD-ROM with at least 586 commercial sales, no confidentiality restrictions).
Macaulay (US 2015/0207809) — discloses a network gateway/security-policy system that receives a customized threat report generated by a security policy management server (the "IHQ") from raw cyber threat intelligence sources (e.g., a malicious-host tracker service). The threat report is a dynamic security policy comprising packet-filtering rules, each entry having at least one traffic attribute (a packet-matching criterion) and an associated reputation indicator / reputation score. The gateway stores the report, matches incoming packets against the traffic attributes, retrieves the reputation score for the matching attribute, and disposes of the packet based on the score (e.g., block). Macaulay computes the reputation score from multiple factors, explicitly including the number of cyber threat intelligence sources that identified the threat, and the rules are dynamically and automatically updated as new threat reports arrive.
Maestas (US 9,342,691) — teaches computing an aggregate risk score for network entities/threats from multiple risk factors, including geographic origin/location of IP addresses, and using that score for network security decisions.
4. Ground 1: Claims 1–20 obvious over Sourcefire + Macaulay
Element-by-element (as found by the Board). The Board agreed with Palo Alto that Sourcefire alone discloses nearly every limitation of the independent claims — the boundary-deployed packet-filtering device receiving threat identifiers from multiple sources (1.pre, 1.a.i, 1.a.ii), rule-based matching and operator application (1.j), packet-log entries with threat identifiers (1.e), and user-driven rule reconfiguration via a Rule Actions menu (1.i). The Board specifically credited Sourcefire's disclosure of:
- receiving "new intrusion rules" containing identifiers such as CVE ID, Bugtraq ID, and Snort ID from external systems (mapping to receiving threat identifiers from a plurality of providers);
- tables of intrusion events containing threat identifiers and priority, with user-sortable columns (supporting the ordered-listing limitation 1.h's table aspect); and
- a menu of Rule Actions triggered from the generated listing, letting a user set a rule to drop packets or generate events (limitation 1.i), with each rule specifying matching conditions and an action (limitation 1.j).
The one gap the Board identified in Sourcefire was limitation 1.h's score based on the number of threat-intelligence providers. Macaulay fills that gap: it discloses a reputation score computed from multiple factors including the number of cyber threat intelligence sources that identified the threat, with the score used to dispose of matching packets. The Board found that "Sourcefire teaches generating tables based on threat IDs and priority" and that "Macaulay discloses one way of ordering such tables is based on the number of threat intelligence entities that report the threat, as recited in claim limitation 1.h." It likewise found the combined teachings satisfied 1.i and 1.j.
Motivation to combine (as articulated by the petitioner and accepted by the Board). A POSITA would combine these references to improve Sourcefire's threat-prioritization function:
- Sourcefire's priority is static and manually assigned by the rule creator — a crude, one-dimensional way to rank threats.
- Macaulay teaches a dynamic, multi-factor reputation score that reflects a real-time consensus across multiple intelligence sources.
- Combining them yields "a more effective system that allows network administrators to more accurately identify and prioritize the most significant threats" — the very problem the '413 patent addresses.
The modification is straightforward and predictable: replace or augment Sourcefire's "priority" value with Macaulay's calculated reputation score inside Sourcefire's existing event-table/user-interface framework. This is the classic KSR situation of substituting one known element (a computed consensus score) for another known element (a manual priority) in a known system to achieve a predictable improvement in ranking accuracy. The Board found the motivation and reasonable expectation of success satisfied.
Reasoning reinforcing obviousness. Both references are in the same field (network-threat detection and blocking at a perimeter device), the combination uses each reference for its known purpose, and the two systems are architecturally compatible (a rule-based packet-filtering engine with a scoring/prioritization layer). The Board also noted the related '722 patent's claims had already been found unpatentable over Sourcefire in IPR2018-01760, underscoring that the Sourcefire-based framework was well known.
5. Ground 2: Claims 3, 13, and 18 obvious over Sourcefire + Macaulay + Maestas
Dependent claims 3, 13, and 18 add that the score is determined based on additional factors including geographic information. Macaulay's score is already multi-factor, but the petitioner pointed to Maestas as the explicit teaching that geographic origin of IP addresses is a key risk factor in computing an aggregate risk score.
Motivation to combine. This is a straightforward extension of Ground 1's logic: after replacing Sourcefire's manual priority with Macaulay's dynamic scoring, a POSITA seeking to further refine the accuracy of the threat score would incorporate other known, publicly available risk factors. Maestas expressly identifies geographic origin as such a factor. Adding a geographic component to a multi-factor scoring algorithm is a predictable design choice, with a high expectation of success — the dependent claims merely collect one more known scoring input, not an inventive step. The Board agreed and found claims 3, 13, and 18 unpatentable on this ground as well.
6. Secondary considerations
Based on the search results, no secondary considerations were found to outweigh the strong prima facie case. The Board rejected Centripetal's arguments (e.g., that Sourcefire's priority merely categorizes already-identified events rather than actively configuring the device, and that Macaulay's scoring applies before intelligence is sent to sensors rather than after detection). The Federal Circuit, affirming on Oct. 31, 2024, upheld the Board's constructions of the "boundary" limitation (citing Figure 2A) and the reputation-based "score" limitation and rejected Centripetal's challenges to claims 6–8, 15, and 20. Notably, both Sourcefire and Macaulay were cited to the Office during prosecution (Sourcefire via IDS; Macaulay on Form PTO-892) — which does not defeat obviousness but explains why the Examiner did not reject over them; the Board found they were never substantively applied in a rejection, so the Advanced Bionics factors did not bar institution.
7. Conclusion
The combination of Sourcefire + Macaulay renders claims 1–20 obvious under § 103, and Sourcefire + Macaulay + Maestas renders dependent claims 3, 13, and 18 obvious:
| Reference(s) | Claims | Key gap filled | Motivation |
|---|---|---|---|
| Sourcefire (alone) | nearly all elements of 1–20 | rule-based packet filtering, threat-ID logging, operators, event tables, rule reconfiguration | — |
| + Macaulay | 1–20 | provider-count-based reputation score and ordering | replace static manual priority with dynamic consensus score; accurate threat prioritization |
| + Maestas | 3, 13, 18 | geographic factor in score | refine scoring accuracy with known risk factor; predictable design choice |
This analysis is consistent with, and largely mirrors, the grounds on which the PTAB actually cancelled all claims in IPR2021-01149 (FWD, Feb. 17, 2023) and the Federal Circuit affirmed (No. 23-1785, Oct. 31, 2024).
Caveats. (1) I could not access the full FWD text or the complete independent-claim texts in this session; the mapping is reconstructed from petition/Board summaries and may omit nuances of specific dependent-claim limitations beyond claims 3, 13, and 18. (2) If your working copy of the '413 patent has a formal "Prior Art" section listing additional references (e.g., prosecution-cited art beyond Macaulay/Sourcefire), I did not see it, and those additional references are not analyzed here. (3) The patent's USPTO record still labels it "Active," but post-IPR/CAFC the claims have been cancelled for unpatentability; that procedural status does not affect the technical obviousness analysis above.
Key sources: https://ai-lab.exparte.com/case/ptab/IPR2021-01149/doc/1061 ; https://portal.unifiedpatents.com/patents/patent/US-[12015626](/patent/12015626)-B2#9 ; https://www.docketalarm.com/cases/PTAB/IPR2021-01148/.../Exhibit-2020 ; https://www.mealeys.com/mealeys/mealeys-intellectual-property/articles/[1777357](/patent/1777357) ; https://keyhanillc.com/2020/03/02/a-users-guide-to-prior-art-ptab-holds-that-a-user-manual-may-qualify-as-a-printed-publication/ ; https://www.courtlistener.com/opinion/[10847071](/patent/10847071)/centripetal-networks-llc-v-keysight-technologies-inc/ ; https://ptacts.uspto.gov/... (Macaulay gateway/threat-report disclosure).
Generated 8/30/2026, 6:48:29 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Centripetal Networks, Inc.
- US 10193917Patent Analysis: US 10193917 B2 Date of Analysis: April 26, 2026 Here is a concise summary of United States Patent 10,193,917, including details from the patent document and recent legal proceedings. --- Patent Details Title: Rule-based…
- US 9917856Here is a concise summary of US Patent 9917856: US Patent 9917856 Title: Rule-based network-threat detection for encrypted communications Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello Filing…
- US 10511572US Patent 10511572 (US10511572) is titled "Rule swapping in a packet network." The patent is currently assigned to Centripetal Networks LLC. The inventors are David K. Ahn, Steven Rogers, and Sean Moore. The application was filed on July…
- US 9686193Here is a concise summary of US patent 9686193: US Patent 9686193: Filtering Network Data Transfers Title: Filtering network data transfers Current Assignee: Centripetal Networks LLC Inventor: Sean Moore Filing Date: February 18, 2015 (for…
- US 9203806US Patent 9203806: Rule Swapping in a Packet Network Title: Rule swapping in a packet network Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Steven Rogers, Sean Moore Filing Date: January 11, 2013 Issue Date: December 1, 2015…
- US 9560176Here is a concise summary of US patent 9560176: US Patent 9560176B2 Title: Correlating packets in communications networks Assignee: Centripetal Networks LLC Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert…
- US 10284526Verification Note I searched the USPTO/Google Patents records and the Federal Circuit's 2026 dockets for patent number 10284526 (interpreted literally; no similar numbers substituted). I located the authoritative Federal Circuit…
- US 9264370I have the bibliographic data confirmed. The provided patent text doesn't include the claims section, so let me retrieve the actual claim language. Let me retrieve the exact claims text of US9264370 from additional sources. Summary of U.S…
Other patents in Software Technology & Computing Systems (T)
- US 6665293I'll search for authoritative information on US Patent 6,665,293 and any CAFC 2026 docket references. Both searches returned no results. Let me try broader queries to locate authoritative sources. I have confirmation from Google Patents…
- US 6424624I searched the USPTO/patent databases and CAFC docket sources for the specific patent number 6424624 (i.e., US 6,424,624 B1 / US6424624B1). Here is the summary, with notes on confidence. Verification note - Searches for "6424624" confirmed…
- US 10491646Summary of U.S. Patent No. 10,491,646 (US10491646B2) I searched for the specific patent number 10491646 (front-page form: US 10,491,646 B2) and did not rely on similar numbers (e.g., 8,166,892, IPR2025-01046/01047, etc., which appeared in…
- US 9338140US Patent 9,338,140 B2 — Summary Bibliographic data (verified against USPTO-adjacent sources and the issued patent PDF) | Field | Data | |---|---| | Patent number | US 9,338,140 B2 (application no. 13/468,383) | | Title | Secure data…
- US 9129376US Patent 9,129,376 B2 — Summary Searches performed I searched for the exact identifier 9129376 (and US9129376B2 / 9,129,376) in patent databases and litigation/CAFC sources, and searched the CAFC 2026 docket for this patent number. My…
- US 8825454US Patent 8,825,454 — Summary Note on sources: Bibliographic data below is corroborated by Google Patents (patents.google.com/patent/US8825454) and FreePatentsOnline. The full specification was supplied in your prompt; however, the claims…
- US 8818770I have confirmation of the key bibliographic data and relevant dockets. Let me retrieve the independent claims' full text to describe them accurately. US Patent 8,818,770 B2 — Summary Bibliographic data (verified against USPTO/Google…
- US 8170840The CAFC 2026 hits so far involve different EagleView patents (8,670,961 and 8,078,436) — not 8,170,840. Let me verify whether 8,170,840 itself appears in any 2026 CAFC activity and pull the actual claim set. I need the actual claim text…
This patent in court (3)
3 tracked lawsuits name US 10567413.