Invalidity dossier

US 11431735

Techniques for securing virtual machines

Current assignee: Wiz, Inc.

Added 9/29/2026, 10:23:08 AM

At a glanceNo PTAB challenges1 lawsuit on fileasserted by Wiz, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for current information on this patent, including any litigation or CAFC 2026 docket activity.

Let me search for the specific PTAB proceeding and any related 2026 litigation developments.

US Patent 11,431,735 — Analyst Summary

Bibliographic data (from the patent text and Google Patents)

Field Value
Patent number US 11,431,735 B2
Title "Techniques for securing virtual machines"
Inventor Avi Shua (sole named inventor)
Assignee Orca Security Ltd. (original and current)
Application no. 16/585,967 (Utility, non-provisional)
Priority date 2019-01-28 (provisional 62/797,718)
Filing date 2019-09-27
Issue/publication date 2022-08-30 (pre-grant pub. US 2020/0244678 A1, 2020-07-30)
Claims 19 total (independent: 1 method, 10 CRM, 11 system)
Legal status (per Google Patents) Active; adjusted expiration 2040-10-12
CPC classes H04L63/1433, G06F9/45558, G06F21/55x, G06F11/14xx, G06F16/128, and others

Source: https://patents.google.com/patent/US11431735/en

Abstract (verbatim)

"A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority."

Independent claims — plain-language overview

Claim 1 (method). A computer-implemented method with four steps: (1) find where a snapshot of a virtual disk of the protected cloud asset is stored; (2) access that snapshot based on the found location; (3) analyze the snapshot to detect possible cyber threats to the asset; and (4) alert on detected threats according to a priority that has been determined.

Claim 10 (non-transitory computer-readable medium). The same four-step process as claim 1, but claimed as instructions stored on a non-transitory CRM.

Claim 11 (system). The same four-step process as claim 1, but claimed as a system comprising a processing circuit and memory whose instructions configure the system to perform those steps.

Notably, the core concept of all three independent claims is agentless, out-of-band inspection of a disk snapshot (i.e., the VM's virtual disk copy) rather than inspecting live traffic or installing an in-guest agent. The dependent claims add: prioritization/mitigation (2, 12); identifying the virtual disk (3, 13); querying a cloud management console (4, 14); parsing and scanning for known/unknown vulnerabilities (5, 15); config-file checks, file-access-time checks, log analysis, page-file/memory analysis (6, 16); instantiating/monitoring a copy of the asset (7, 17); PID-file analysis (8, 18); and asset types (VM, container, micro-service) (9, 19).

Litigation and post-grant status (this is the important part)

District court: The ’735 patent was asserted by Orca Security in Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del.), filed July 12, 2023. The complaint (and the docket's patent list) shows 11,431,735 among the asserted Orca patents. CourtListener docket: https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/

PTAB — IPR2024-00220: Wiz, Inc. petitioned for inter partes review of the ’735 patent on Jan. 8, 2024, challenging claims 1–7, 9–17, and 19 over Veselov in combination with Basavapatna (asserting alert prioritization was conventional). https://www.docketalarm.com/cases/PTAB/IPR2024-00220/WIZ_Inc/docs/01-08-2024-Petitioner/Petition_as_filed-2-Petition__as_filed.pdf

Statutory disclaimer: On April 17, 2024, Orca filed a statutory disclaimer under 37 C.F.R. § 1.321(a) disclaiming claims 1–7, 9–17, and 19 — i.e., every claim Wiz challenged. Orca argued the petition was therefore moot ("IPR cannot be instituted, and the Petition is moot"). POPR: https://www.docketalarm.com/cases/PTAB/IPR2024-00220/WIZ_Inc._v._Orca_Security_Ltd/docs/04-18-2024-Patent_Owner/POPR_filed-6-Patent_Owners_Preliminary_Response.pdf

Institution denied (May 9, 2024): The Board denied institution because all challenged claims had been disclaimed. Wiz, Inc. v. Orca Security Ltd., IPR2024-00220, Paper 7 (PTAB May 9, 2024). Google Patents labels this "IPR2024-00220 filed (Not Instituted – Procedural)." Note: the surviving, non-disclaimed claims in the ’735 patent are dependent claims 8 and 18 (the PID-file claims), which Wiz did not challenge.

Parallel IPRs on related Orca patents: Wiz filed IPR2024-00863, -00864, -00865 (on U.S. Pat. Nos. 11,663,031, 11,663,032, 11,693,685) and IPR2024-01109/-01190/-01191 (on 11,726,809, 11,740,926, 11,775,326). On December 8, 2025, the PTAB issued Final Written Decisions holding all claims unpatentable in the first three IPRs. The parties' joint notice to the court is available here: https://archive.org/download/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf

Litigation outcome: The Delaware case was stayed Jan. 16, 2025 pending IPR, and on/about January 13, 2026 the parties stipulated to dismissal with prejudice (D.I. 238), each bearing its own costs. The parties also filed a confidential settlement agreement (Feb. 2026). Coverage: https://www.bankinfosecurity.asia/orca-wiz-end-dueling-lawsuits-over-cloud-security-patents-a-30463

CAFC 2026 docket — what I could and could not confirm

  • I performed targeted searches but did not find a Court of Appeals for the Federal Circuit 2026 docket or opinion specifically captioned to U.S. Patent No. 11,431,735. The Federal Circuit decisions I surfaced in 2026 relate to unrelated patents (e.g., FedEx/Qualcomm, Spero/Mercedes, Greenthread, Roambee) and are not about the ’735 patent.
  • Because IPR2024-00220 was never instituted, there is no PTAB Final Written Decision on the ’735 patent to appeal from; the statutory disclaimer mooted it. So a CAFC appeal keyed directly to the ’735 patent would be unusual.
  • The appeal window referenced in the joint notice (Notice of Appeal deadline Feb. 9, 2026) pertained to the related patents 11,663,031 / 11,663,032 / 11,693,685, not to 11,431,735.

Uncertainty / caveats

  • Patent number interpreted literally: all statements above refer to 11,431,735 only. I did not substitute or auto-correct to any similar number (e.g., 11,431,735 vs. family members 11,516,231 / 11,668,798-family).
  • My CAFC search is not a complete docket scrape; it is possible a related appeal is not indexed in the sources reached. I cannot certify the absence of a 2026 CAFC proceeding with 100% confidence — treat the "no CAFC docket found" statement as a search result, not a legal conclusion.
  • Disclaimer scope nuance: the disclaimer covers claims 1–7, 9–17, and 19, leaving claims 8 and 18 formally not disclaimed (though they depend on disclaimed claims 5 and 15, respectively). I am reporting this as the documents state it; the legal effect on the surviving dependent claims is a question I cannot resolve definitively here.
  • Some "expiration" and "active" labels on aggregator sites (e.g., 2040-10-12) are automated estimates and were flagged by the source as assumptions, not legal conclusions.
  • Note a date discrepancy between sources: the patent page was fetched with a 2026-09-29 timestamp, whereas the instruction header states today is April 26, 2026. Verify the current date against your own records before relying on relative timing.

Generated 9/29/2026, 10:33:00 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 11431735. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US Patent 11431735. Let me run several searches.

Let me verify the outcome details and check for any appeal.

Litigation Involving U.S. Patent No. 11,431,735

Based on my searches of patent litigation sources (Docket Alarm, CourtListener/RECAP, Unified Patents PTAB data, and the USPTO PTAB docket), here is what I found.

Summary

Yes — there is known litigation involving U.S. Pat. No. 11,431,735, but only one district court action (plus one related PTAB proceeding). No CAFC appeal or other separate litigation involving this patent surfaced in my searches.


1. District Court Litigation

Field Detail
Plaintiff Orca Security Ltd. (patent owner)
Defendant / Counterclaim-Plaintiff Wiz, Inc.
Court / Jurisdiction U.S. District Court for the District of Delaware (Wilmington)
Case Number C.A. No. 1:23‑cv‑00758 (captioned variously as 23‑758 (GBW), then (JLH)(SRF))
Judges Judge Jennifer L. Hall (presiding); Magistrate Judge Sherry R. Fallon
Filing Date July 12, 2023
Cause of Action 35 U.S.C. § 271 patent infringement
Status / Outcome Dismissed with prejudice, all claims and counterclaims, on Jan. 13, 2026 (D.I. 238, granting the parties' stipulation of dismissal, D.I. 237 filed Jan. 6, 2026). Civil case terminated; each side to bear its own costs and fees.

Notes:

  • The '735 patent was one of several Orca patents asserted in this action. The docket lists the asserted patents as: 11,374,982; 11,431,735; 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926; 11,775,326; and 6,721,803. The complaint was amended twice (Second Amended Complaint, D.I. 15, filed Oct. 10, 2023).
  • Wiz filed counterclaims asserting its own patents against Orca (e.g., U.S. Pat. 12,001,549).
  • The case was stayed on Jan. 16, 2025 pending inter partes review (D.I. 232–233).
  • The dismissal followed a Dec. 8, 2025 PTAB decision holding all challenged claims of three of Orca's asserted patents unpatentable, which substantially weakened Orca's case (reported by ISMG/Inforisktoday).

2. Related PTAB Proceeding (not district court litigation, but directly on this patent)

Field Detail
Petitioner Wiz, Inc.
Patent Owner Orca Security Ltd.
Forum USPTO Patent Trial and Appeal Board
Case Number IPR2024-00220
Patent Challenged U.S. Pat. No. 11,431,735 B2
Petition Filing Date Jan. 8, 2024
Claims Challenged Claims 1–7, 9–17, and 19
Outcome / Status Not instituted (procedural). Orca filed a statutory disclaimer on April 17, 2024 disclaiming all challenged claims (Ex. 2001), and filed its Patent Owner Preliminary Response on April 18, 2024 arguing the petition was moot. The PTAB did not institute. The Google Patents family record lists this as "Not Instituted - Procedural."

Important caveat: Because of the April 17, 2024 statutory disclaimer, claims 1–7, 9–17, and 19 of the '735 patent were disclaimed and no longer exist. Notably, claims 8 and 18 were neither challenged in IPR2024-00220 nor disclaimed.

Wiz also filed related IPRs against other Orca patents in this family (IPR2024-00863, -00864, -00865, -01109, -01190, -01191), three of which were instituted on Dec. 9, 2024. Orca, in turn, filed IPRs against Wiz patents (IPR2025-01086, IPR2025-01087, etc.). These related proceedings were terminated by settlement in January 2026 (e.g., IPR2024-01190 joint motion to terminate, filed Jan. 7, 2026; IPR2025-01087 terminated Jan. 14, 2026).


3. Appellate Litigation

None found. I did not identify any Court of Appeals for the Federal Circuit appeal involving U.S. Pat. No. 11,431,735. The district court case ended by stipulated dismissal with prejudice (not by judgment likely to be appealed), and the IPR was never instituted.


Bottom Line

  • Only one district court case asserted U.S. Pat. No. 11,431,735: Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del.), which was dismissed with prejudice on Jan. 13, 2026 as part of a global settlement.
  • One PTAB IPR challenged the patent (IPR2024-00220, Wiz v. Orca), but it was not instituted after Orca statutorily disclaimed the challenged claims.
  • No other litigation or appellate proceedings involving this specific patent were found.

Caveats on reliability: Docket aggregator coverage (Docket Alarm, CourtListener/RECAP) may lag PACER, and I could not independently confirm every docket entry via PACER directly. The litigation history is recent and rapidly evolving (the dismissal occurred only three months before the stated current date). If you need certified docket verification, I'd recommend pulling the PACER docket for 1:23-cv-00758 and the PTAB docket for IPR2024-00220 directly. I deliberately did not auto-correct any patent or case identifiers, and I only report the '735 patent (11,431,735) — not similar-sounding numbers that appeared incidentally in search results.

Generated 9/29/2026, 10:32:54 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Wiz, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll start by reconciling the two sources: the structured block says no AIA trials on file, but the patent page itself flags IPR2024-00220 (Not Instituted – Procedural). Let me research that and any other proceedings.

Key correction found: the petitioner is Wiz, Inc., not Unified Patents (the "Unified Patents PTAB Data" label on the Google Patents page is just the dataset attribution). Let me research the institution outcome and any sibling IPRs.

Now let me verify the denial details, the fate of the two unchallenged claims, and any appeal/settlement developments.

PTAB / AIA Trial Analysis — U.S. Patent No. 11,431,735 ("Techniques for securing virtual machines," Orca Security Ltd.)

Data-reconciliation flag (read first). The structured "PTAB proceedings on file" block says ODP returns zero AIA trials for this patent. That is incomplete. The patent's own authority-mirrored record (Google Patents, fetched 2026-09-29) carries a litigation/PTAB field stating: "PTAB case IPR2024-00220 filed (Not Instituted - Procedural)." Third-party PTAB dockets and the patent owner's own filings confirm it. The true count is one proceeding. Separately, the Google Patents page labels the petitioner as "Unified Patents PTAB Data" — that string is the dataset attribution for the PTAB feed, not the petitioner. The real petitioner is Wiz, Inc. Do not repeat the Unified Patents error in any brief.


Proceedings overview

One AIA trial proceeding has ever been filed on the '735 patent — IPR2024-00220 — and it was never instituted: the Patent Owner statutorily disclaimed all 18 challenged claims (claims 1–7, 9–17, 19) six days after the petition was served, mooting the petition; the Board denied institution on 2024-05-09. Breakdown: 0 active · 0 claims canceled by Final Written Decision · 0 claims sustained by Final Written Decision · 1 closed on disclaimer / institution denied (procedural) · 0 settlements in the IPR itself.

Bottom line for a defendant: this is not "the patent survived and is hardened," and it is also not a merits invalidation. It is a voluntary surrender. Every independent claim (1, 10, 11) and all but two dependent claims of the '735 patent — including claim 1 — have been statutorily disclaimed under 37 C.F.R. § 1.321(a) and are treated as though they never existed (35 U.S.C. § 253(a)). If a demand letter or complaint asserts the '735 patent, it is asserting surrendered claims. The only two claims not disclaimed (8 and 18) depend respectively from disclaimed claims 5 and 15 and have no independently enforceable scope. The patent is, for practical purposes, unusable.


IPR2024-00220 — Wiz, Inc. v. Orca Security Ltd.

  • Type: Inter Partes Review (35 U.S.C. §§ 311–319)
  • Filed: 2024-01-08 (Petition, Paper 2). Case page: Unified Patents PTAB portal; petition copy: Docket Alarm PDF
  • Status: "Not Instituted - Procedural" (verbatim from the structured record). Plain English: the Board denied institution on 2024-05-09 (Paper 7) — not on the merits of the prior art, but because the Patent Owner had disclaimed every challenged claim, leaving nothing to review. No trial was ever conducted.
  • Judge panel: Not confirmed in the public materials I could retrieve. Denials of institution on disclaimer/mootness grounds are typically issued by a three-APJ panel, but the Paper 7 panel is not quoted in the sources I located, and I will not guess names. (For contrast, the sibling '685 institution panel was Galligan, Baer, Zecher & Raevsky.)
  • Petition grounds:
    • Claims challenged: 1–7, 9–17, and 19 (all claims of the patent except claims 8 and 18).
    • Statutory basis: § 103(a) obviousness, "under 35 U.S.C. § 311 and AIA § 6."
    • Primary art: Veselov — U.S. Patent No. 11,216,563, "Security Assessment of Virtual Computing Environment Using Logical Volume Image," filed 2017-05-19 (pre-AIA-critical-date art) — teaching API-based snapshot acquisition, disk/virtual-disk location, snapshot scanning, and alert reporting; combined with Basavapatna for the "based on a determined priority" alerting limitation, which Wiz conceded Veselov "does not expressly state." A further reference, Price, was used in the sibling-family combinations.
    • Supporting evidence: Declaration of Dr. Angelos Stavrou (EX1002).
    • Petitioner counsel: Matthew A. Argenti (Reg. 61,836), Michael T. Rosato (Reg. 52,182), Wesley E. Derryberry (Reg. 71,594) — Wilson Sonsini Goodrich & Rosati.
  • Institution decision: Denied, 2024-05-09 (Paper 7) — "the Board denied institution because Orca disclaimed all the challenged claims of the '735 patent" (recited verbatim inside the PTAB's own later institution decision in IPR2024-00865). The path there:
    1. 2024-04-17 — Orca filed a statutory disclaimer under 37 C.F.R. § 1.321(a) with the USPTO, disclaiming claims 1–7, 9–17, and 19 (Patent Owner Ex. 2001, with Acknowledgement of Receipt and fee receipt).
    2. 2024-04-18 — Orca's Preliminary Response — a 62-word filing — argued the petition was moot: "Because the Petition challenges only disclaimed claims, IPR cannot be instituted, and the Petition is moot" (invoking 37 C.F.R. § 42.107(e)). POPR link
    3. 2024-05-09 — Board denied institution.
    • Patent Owner counsel: Inge A. Osman (Reg. 74,480), Latham & Watkins LLP.
    • Strategic read on the panel's reasoning: § 42.107(e) is a hard rule — no IPR will be instituted on disclaimed claims. The Board had no discretion to reach Veselov/Basavapatna. This was a race by Orca to shield the '735 patent from a merits decision, and it succeeded procedurally while destroying the claims substantively.
  • Final Written Decision: None issued. Because institution was denied, no claim was ever adjudicated unpatentable, and no claim was ever held patentable. Any statement that "the PTAB invalidated the '735 claims" is wrong; the claims died by disclaimer, not by decision.
  • Settlement / termination: No settlement of the IPR (the IPR terminated at the institution stage). No Rule 42.74 confidentiality terms to report.
  • Appeal: None, and none possible on this proceeding. A denial of institution is non-reviewable (35 U.S.C. § 314(d)), and there is no FWD to appeal to the Federal Circuit. I found no CAFC docket arising from IPR2024-00220.
  • Defensive value: Maximum for the disclaimed claims — and this is the whole point. Claims 1, 10, and 11 (all independents) plus 2–7, 9, 12–17, and 19 are statutorily disclaimed; they are treated as never having existed and cannot be asserted against anyone. Any infringement allegation, demand letter, or damages theory premised on those claims is asserting surrendered rights. The residual claims 8 and 18 were not disclaimed — but claim 8 depends from disclaimed claim 5 and claim 18 depends from disclaimed claim 15, so neither retains live scope. Net: no commercially meaningful claim of the '735 patent remains available to assert.

Strategic summary

Claim-level status of the '735 patent.

Claim(s) Status Basis
1–7, 9–17, 19 Statutorily disclaimed / surrendered (not "invalidated by PTAB") Orca's § 1.321(a) disclaimer filed 2024-04-17; acknowledged in IPR2024-00220 POPR and in the Board's 2024-05-09 denial
8, 18 Never disclaimed, never adjudicated — but no independent scope Each depends from a disclaimed parent (claim 8 ← claim 5; claim 18 ← claim 15). Untested by the PTAB.

Note the granularity: the disclaimer and the petition challenge track each other exactly (1–7, 9–17, 19) — Orca disclaimed precisely the claims Wiz attacked, no more. Why Wiz did not also challenge claims 8 and 18 is not explained in the record I retrieved; I flag that as an open item rather than speculate. What is verifiable is that every independent claim of the '735 patent is gone.

Estoppel landscape. There is no § 315(e)(2) estoppel against anyone. Estoppel attaches only after a final written decision, and IPR2024-00220 produced none (denial of institution on disclaimer). No petitioner — Wiz or otherwise — is estopped from raising Veselov, Basavapatna, Price, or any other ground. In practice this is academic: there are no claims left to defend. For a new defendant the useful move is not an IPR but a covenant-and-dismiss demand or a Rule 12 motion: the disclaimer is a matter of public record and is dispositive on the face of the patent's prosecution/assignment file.

Pattern signals.

  • This is a two-front commercial war, not troll activity. Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758-JLH-SRF (D. Del., filed 2023-07-12) is Orca (patent owner) as plaintiff against a same-market competitor, Wiz, with Wiz counterclaiming on its own patents.
  • Wiz, not a defensive aggregator, is the petitioner. Unified Patents appears in the Google Patents record only as a data source, and a PTAB aggregator (Unified) has not filed against this patent. There is no defensive-aggregator chain here.
  • Serial petitioning by Wiz across the family. Wiz filed seven IPRs against Orca's family: the '735 petition (IPR2024-00220) plus IPR2024-00863 ('031), -00864 ('032), -00865 ('685), -01109 ('809), -01190 ('926), and -01191 ('326). All six of the later petitions hit institution (2024-12-09 for the first three; 2025-01-16 and 2025-01-22 for the rest).
  • The rest of the family collapsed on the merits. On 2025-12-08 the Board issued FWDs in IPR2024-00863, -00864, and -00865 finding all claims of U.S. Patents 11,663,031, 11,663,032, and 11,693,685 unpatentable — the three Orca patents that had been asserted in the Delaware case. FWDs on the '809 ('926 / '326) IPRs were due by 2026-01-16 / 2026-01-22. (Joint Notice to the D. Del. court)
  • The litigation went quiet after that. The Delaware action was stayed pending the Wiz IPRs by order of 2025-01-16, and the docket reflects a stipulation of dismissal with prejudice, So Ordered 2026-01-13 (D.I. 237–238) — consistent with a global resolution after the December 2025 FWDs gutted three of Orca's asserted patents. I could not confirm the terms of that resolution, and the IPR itself was never settled. Treat the settlement characterization as a docket-level inference, not a verified fact.
  • Orca counter-punched against Wiz's patents. Orca filed IPR2025-01083 through -01087 against Wiz's U.S. Patents 11,722,554 / 11,929,896 / 11,936,693 / 12,001,549 / 12,003,529. Deputy Director Coke Morgan Stewart declined to exercise discretionary denial and referred the petitions to the Board; on 2025-12-15 three were instituted as to all claims ('896, '693, '529), with FWDs due no later than 2026-12-15, and two were denied institution ('554, '549).

What this means for the '735 patent specifically. It is the least dangerous patent in the Orca family. It never reached a merits adjudication because Orca chose to surrender it rather than litigate, and the members of the same family that were litigated were held entirely unpatentable on 2025-12-08.


Recommended next steps

If you are a defendant facing assertion of the '735 patent:

  1. Do not file an IPR on it. It is a waste of money — § 42.107(e) forecloses review of the disclaimed claims, and no claim worth defending remains.
  2. Demand the disclaimer record and move to dismiss. Cite Orca's statutory disclaimer under 37 C.F.R. § 1.321(a), filed 2024-04-17, disclaiming claims 1–7, 9–17, and 19, and the PTAB's Decision Denying Institution, IPR2024-00220, Paper 7 (2024-05-09) ("denied institution because Orca disclaimed all the challenged claims"). Pull both from PTAB E2E / PTACTS and the IPR2024-00220 case page. A § 253(a) disclaimer means the claims are "treated as though [they] never existed."
  3. If claims 8 or 18 are ever asserted, note the dependency defect (claim 8 ← disclaimed claim 5; claim 18 ← disclaimed claim 15) and the absence of any PTAB adjudication. There is no FWD to quote because none exists — say so, and do not let opposing counsel imply a merits survival.
  4. Watch the CAFC window on the family, not this patent. The deadline for notices of appeal from the 2025-12-08 FWDs in IPR2024-00863/-00864/-00865 was 2026-02-09; check the Federal Circuit docket and CourtListener for any Orca appeal, since a reversal there could theoretically revive the commercial posture of the broader Orca family (though it would not revive the disclaimed '735 claims).
  5. Do not over-claim the win in briefing. The correct statement is: claims 1–7, 9–17, and 19 were statutorily discontinued by the patent owner; the PTAB never instituted and never invalidated anything. Overstating it as a PTAB invalidity ruling invites a correction you don't need.

If you are advising on the Orca family generally: the '735 patent is not the threat — the '809, '926, and '326 patents still have live IPRs with FWDs due in early 2026, and the three patents that Orca did litigate ('031, '032, '685) were held entirely unpatentable on 2025-12-08.


Source / verification notes

  • Conflict resolved against the structured block. The ODP-derived "no AIA trial proceedings" statement is contradicted by (i) the patent page's own PTAB field, (ii) the POPR and disclaimer record, and (iii) the PTAB's own recitation in IPR2024-00865 of the Paper 7 denial in IPR2024-00220. I have treated the ODP result as an ingest gap.
  • Not independently verified: the identity of the three APJs on the IPR2024-00220 denial panel; the exact terms of the January 2026 dismissal with prejudice in D. Del. No. 1:23-cv-00758; and whether any CAFC appeal was filed from the 2025-12-08 FWDs. I did not find these in the sources retrieved and have not guessed.
  • No proceeding numbers were invented. IPR2024-00220 is the only number tied to the '735 patent; the other IPR numbers listed are for different patents in the same family and are labeled as such.

Generated 9/29/2026, 10:33:42 AM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2019-09-26 · recorded 2019-09-27 · Assignment

    Avi ShuaOrca Security Ltd.

    Correspondent: Christopher C. Johns · M&B IP Analysts

    acquisition

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record, litigation history, and corporate status before assembling the report.

Let me dig deeper into the assignment record, correspondent, litigation, and Orca's corporate status.

Let me try to pin down the specific assignment reel/frame and any post-issuance transfers.

Ownership & Assignment Analysis — US 11,431,735 B2

Patent: "Techniques for securing virtual machines" · App. 16/585,967 · filed 2019‑09‑27 · granted 2022‑08‑30 · provisional 62/797,718 (2019‑01‑28)
Assignee of record on the face of the patent: ORCA SECURITY LTD., Tel Aviv (IL)

Sourcing caveat (stated up front): I was able to retrieve the substantive chain from primary documents (the recorded assignment/PoA text reproduced in PTAB exhibits, the issued patent front page, and Google Patents legal events), but I could not retrieve the reel/frame numbers from the USPTO Assignment Center index during this session. Every reel/frame slot below is therefore marked [not retrieved] rather than guessed. Treat the dates and parties as reliable and the reel/frame identifiers as needing direct verification at the Assignment Center.


Inventors

Inventor Residence Employer at filing Notes
Avi Shua (sole inventor) Tel Aviv, Israel Orca Security Ltd. — co‑founder (and then‑CEO) Correspondence address recorded on the assignment: "c/o Orca Security LTD., 65 Yigal Alon St., Tel Aviv 6744316 ISRAEL." Executed the assignment 2019‑09‑26.

Background from the Orca v. Wiz complaint (D. Del. 1:23‑cv‑00758, D.I. 15, p. 3): Shua spent ~10 years in IDF Unit 8200, then ~a decade at Check Point Software, serving as Chief Technologist for four years, before co‑founding Orca in 2019. The complaint describes him as the sole named inventor across Orca's asserted family.

Unusual patterns — none of the fire‑sale precursors.

  • Single inventor who is also the founder/CEO. This is the opposite of the typical pre‑fire‑sale signature (a large inventor team that all departs within 12 months). No departures are documented in any source I retrieved.
  • The only leadership change surfaced is Avi Shua → Gil Geron as CEO (Geron is quoted as CEO in the 2025 Opus acquisition coverage). That is a normal executive transition in a venture‑backed company, not an inventor departing an ailing assignee. No evidence ties it to a portfolio sale.

Original assignee

Orca Security Ltd. (a/k/a "Orca Security LTD."; address at filing: 65 Yigal Alon St., Tel Aviv 6744316, Israel; later patent covers list Tel Aviv‑Jaffa / Tel‑Aviv‑Yafo).

  • Primary line of business: agentless cloud security ("CNAPP") — cloud workload protection and cloud security posture management across AWS, Azure and GCP.
  • Did it ship a product embodying the claims? Yes — demonstrably. Its flagship SideScanning™ technology reads cloud‑provider APIs and workload block storage out‑of‑band to analyze snapshots, which is precisely the subject matter of claim 1. In IPR2024‑00863 (Paper 38) Orca's patent owner response argued that its own funding and revenue history is tied to "the cloud computing provider API‑based techniques to facilitate analyzing snapshots for vulnerabilities claimed in the '031 Patent" (the '031 patent is a direct sibling of the '735 patent from the same 2019‑01‑28 priority family).
  • Current status: operating, privately held, well capitalised. ~$630–640M raised; ~$1.8B valuation after the extended Series C; ~400–500 employees; customers include SAP, Autodesk, Unity, Lemonade. It is an acquirer, not a target: RapidSec (API security) and, in 2025, Opus Security. No bankruptcy, no dissolution, no acquisition of Orca itself.
  • Ownership disclosure: in the Delaware action Orca filed a Rule 7.1 Disclosure Statement of "No Parents or Affiliates Listed" (D.I. 4, 2023‑07‑12) — i.e., Orca is the ultimate parent, not a subsidiary of a holding/licensing entity.

Assignment timeline

One recorded assignment chain; no post‑issuance transfers of any kind found.

1. 2019‑09‑26 (executed) / recorded on or about the filing date of 2019‑09‑27 — Reel [not retrieved] / Frame [not retrieved]

  • Conveyance: Assignment (captioned "Declaration and Assignment for Patent Applications"; Google Patents legal events render this as "ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
  • Assignor: Avi Shua (individual inventor; signature date 09/26/2019)
  • Assignee: Orca Security LTD., 65 Yigal Alon St., Tel Aviv 6744316, Israel
  • Correspondent / attorney of record: The accompanying Power of Attorney appoints "all attorneys and agents of M&B IP ANALYSTS, LLC" acting under USPTO Customer Number 22852. Prosecution personnel named on the filing receipt are Christopher C. Johns (Reg. No. 68,664), "AUTHORIZED BY Christopher Johns," and Dena Bohannon; the filing was made under Customer No. 22852 and Confirmation No. 2249 / Patent Center 60895402. For later continuations in the same family (e.g., App. 17/821,345, filed 2022‑08‑22) the Application Data Sheet lists Finnegan, Henderson, Farabow, Garrett & Dunner LLP, 901 New York Avenue NW, Washington DC 20001‑4413 — also under Customer No. 22852 — indicating the same customer‑number file was transitioned from the M&B IP Analysts roster to Finnegan. Recurrence flag: this same correspondent pair (M&B IP Analysts / Customer No. 22852, then Finnegan / Customer No. 22852) appears across the entire Orca family (the '031, '032, '685, '809, '926 and '326 patents all trace to the same 2019‑01‑28 priority date and the same prosecution customer number). Recurrence here is vertical to a single operating‑company portfolio, not horizontal across unrelated LLCs.
  • Context: Standard founder‑to‑company assignment, executed one day before the non‑provisional was filed and eight months after the provisional. It is an inbound acquisition of title by the operating company from its own founder, not a transfer to an asserter.

Subsequent records

No Security Agreement, Merger, Change of Name, License, Release, Correction, or subsequent Assignment affecting US 11,431,735 surfaced in Google Patents legal events, in the PTAB exhibits for IPR2024‑00220 (Wiz v. Orca) or IPR2024‑01190 (Wiz v. Orca, Ex. 2199 is a copy of this very patent), or in Orca's Delaware Rule 7.1 disclosure. All continuation/divisional children (US 11,516,231; 11,668,685; 11,868,798; 11,663,031; 11,663,032; 11,775,326; 11,740,926; 11,726,809; 12,204,930) remain with Orca Security Ltd. — title never left the operating company.

I cannot affirmatively rule out a non‑event‑indexed record (e.g., an unpublicised internal or security‑interest filing) because I could not query the Assignment Center index directly. Verify at the link at the end of this report.


Timeline diagram

timeline
    title Ownership of US 11431735
    2019 : Provisional filed by Avi Shua
         : Inventor assigns rights to Orca Security Ltd
         : Non-provisional application filed
    2022 : Patent issues to Orca Security Ltd
    2023 : Orca sues Wiz in Delaware
    2024 : Orca disclaims all challenged claims
         : Wiz IPR denied as moot
    2026 : Delaware case dismissed with prejudice

NPE / troll-pattern signals

# Signal Call Evidence
1 Shell‑entity transfer Not present The only assignee ever recorded is Orca Security Ltd., an operating company at 65 Yigal Alon St., Tel Aviv — a real corporate R&D address, not a registered‑agent drop. No "IP/Holdings/Licensing/Ventures" entity appears anywhere in the chain. Orca's D. Del. Rule 7.1 filing states "No Parents or Affiliates Listed" (D.I. 4, 2023‑07‑12).
2 Known asserter in the chain Not present Orca Security Ltd. matches no entry on the Acacia / Marathon / IV / IPNav / Wi‑LAN / Conversant / Pendrell / Round Rock / Spangenberg NPE lists. It appears in the Unified Patents portal only as a "Parent Company: Orca Security Ltd" for its own patents — and as a petitioner in IPRs it filed against Wiz's patents (IPR2025‑01086, IPR2025‑01087). Operating companies that petition for IPR are the inverse of NPEs.
3 Repeat correspondent across the chain Not present as an NPE tell The chain has only one link, so intra‑chain recurrence cannot be computed. The recording/prosecution firm — M&B IP Analysts, LLC then Finnegan (both under Customer No. 22852), with Christopher C. Johns (Reg. 68,664) named on the assignment paperwork — recurs across Orca's own family, which is ordinary outside‑counsel continuity for a single operating company. No correspondent on this file appears on any NPE‑assertion correspondent list I could reach.
4 Cascading transfers Not present Zero transfers beyond the initial inventor→company assignment. No chained LLCs, no shared correspondent addresses across unrelated assignees, no common principals.
5 Pre‑litigation transfer Not present The sole assignment (2019‑09‑26) predates the first infringement suit (2023‑07‑12, D. Del. 1:23‑cv‑00758) by roughly 45 months — the opposite of a venue‑shopping transfer arranged inside 6 months of filing. Standing in the litigation derives from the original 2019 founder assignment, not from a late conveyance.
6 Bankruptcy fire‑sale Not present Orca has raised ~$630–640M and is valued at ~$1.8B; it is a net acquirer (RapidSec; Opus Security, 2025). No Chapter 7/11, no insolvency, no IP sale in proceedings.
7 Privateering Not present Orca asserted the '735 patent itself, as plaintiff, against a direct product competitor (Wiz, Inc.) — not through a proxy NPE. This is direct operating‑company enforcement, evidenced by the complaint (Orca Security Ltd. v. Wiz, Inc., C.A. 23‑0758‑JLH‑SRF, filed 2023‑07‑12) and the joint claim‑construction appendix listing US 11,431,735 as Exhibit F.
8 Defensive aggregator (chain terminates at RPX/AST/LOT/Unified/OIN) Not present Title never moved off Orca. Note one owner‑initiated neutralizing act that is not a defensive‑aggregator transfer: Orca filed a statutory disclaimer of claims 1–7, 9–17 and 19 of the '735 patent under 35 U.S.C. § 253(a) on 2024‑04‑17, which the Board accepted as recorded in Wiz, Inc. v. Orca Security Ltd., IPR2024‑00220, Decision Denying Institution (Paper 7, 2024‑05‑09): "[N]o inter partes review will be instituted based on disclaimed claims." Since all challenged claims were disclaimed, the IPR was denied as moot. That disclaimed the asserted claims of this patent while Orca continued litigating siblings.

Additional litigation context (not a troll signal, but material to the asset's value): the broader Orca↔Wiz war ran in both directions — Orca asserted six patents ('031, '032, '685, '809, '926, '326 plus the '982 patent in later amendments) and Wiz counterclaimed on its own '554, '896, '693, '549 and '529 patents. The Delaware case was stayed pending IPR (D.I. 233, 2025‑01‑16) and then resolved by stipulated dismissal with prejudice, entered 2026‑01‑13 (D.I. 238) per the Docket Alarm docket. The '735 patent's disclaimed claims no longer carry assertion value, though the specification/family survives through the continuations.


Verdict

Operating-company assertion

Orca Security Ltd. has been the sole owner of US 11,431,735 since a one‑day‑before‑filing founder assignment executed 2019‑09‑26 (correspondent M&B IP Analysts, LLC under Customer No. 22852, later Finnegan), with no shell‑entity transfer, no cascading LLC chain, no bankruptcy sale, and no late pre‑litigation conveyance. Orca is a ~$1.8B venture‑backed cloud‑security vendor that ships the SideScanning product practising the claims and sued a direct competitor itself (Orca Security Ltd. v. Wiz, Inc., D. Del. 1:23‑cv‑00758, filed 2023‑07‑12, listing the '735 patent as an asserted patent and as Exhibit F to the joint claim‑construction appendix). The one "asset‑neutralizing" event — Orca's statutory disclaimer of all challenged claims on 2024‑04‑17, which mooted Wiz's IPR2024‑00220 — was an owner's litigation tactic, not a defensive‑aggregator acquisition.

Verify the reel/frame identifiers directly (I could not retrieve them in this session):

Generated 9/29/2026, 10:33:37 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research US patent 11431735 and its cited prior art. Let me start with several searches.

I have the core record. Now let me verify the specific cited references' bibliographic details.

Prior-Art Analysis — US 11,431,735 B2

Note on method: I searched for the identifier 11431735 literally and did not substitute similar numbers. All bibliographic data below is taken from (a) the authoritative full text you supplied, (b) Google Patents/FreePatentsOnline/Justia records for US11431735B2, and (c) primary records for the individual cited references. Where I could not verify something, I say so explicitly rather than guessing.


1. The patent under analysis (literal identifiers as retrieved)

Field Value
Patent number US 11,431,735 B2
Title Techniques for securing virtual machines
Application no. US 16/585,967
Filed 2019-09-27
Priority 2019-01-28 (provisional US 62/797,718)
Granted / published 2022-08-30
Inventor Avi Shua
Assignee Orca Security Ltd. (Tel Aviv, IL)
Pre-grant pub. US 2020/0244678 A1 (2020-07-30)
Adjusted expiry 2040-10-12 (active)
Related IPR IPR2024-00220, petitioner Wiz, Inc. — not instituted (procedural)
Related litigation Wiz, Inc. v. Orca Security Ltd., D. Del. 1:23-cv-00758-GBW

The patent has 19 claims: independent claim 1 (method), claim 10 (non-transitory CRM), claim 11 (system). Claims 2–9 and 12–19 are dependent. The three independent claims share the same four-step core:

  1. determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset that is instantiated in the cloud environment;
  2. accessing the snapshot based on the determined location;
  3. analyzing the snapshot to detect potential cyber threats; and
  4. alerting detected threats based on a determined priority.

Critical date for §102 purposes: The effective filing date is 2019-01-28. A reference is §102(a)(1) art only if it was publicly available before that date; a reference is §102(a)(2) art if its effective filing date predates 2019-01-28 even if it published/granted later (e.g., US 10,536,471 B1 granted 2020-01-14, US 11,068,353 B1 granted 2021-07-20).


2. The cited references on the face of US 11,431,735

The authoritative text lists "Citations (17)" plus "Family Cites Families (45)". The 17 citations are reproduced below with their dates as given, plus my description and claim mapping. (An asterisk in the source table denotes "cited by examiner"; unstarred entries are third-party citations, which in this family typically reflects the Wiz IPR/invalidity contentions.)

2.1 Table of citations

# Citation Pub. date Priority/filing Assignee / inventor Title Starred (examiner)
1 US 2007/0266433 A1 2007-11-15 2006-03-03 Hezi Moore System and Method for Securing Information in a Virtual Computing Environment —
2 US 2013/0191643 A1 2013-07-25 2012-01-25 Fujitsu Ltd. Establishing a chain of trust within a virtual machine ★
3 US 2014/0137190 A1 2014-05-15 2012-11-09 Rapid7, Inc. Methods and systems for passively detecting security levels in client devices —
4 US 2015/0052520 A1 2015-02-19 2013-08-19 IBM Method and apparatus for virtual machine trust isolation in a cloud environment —
5 US 9,177,145 B2 2015-11-03 2009-03-24 Sophos Ltd. Modified file tracking on virtual machines —
6 US 2016/0004449 A1 2016-01-07 2014-07-02 Hedvig, Inc. Storage system with virtual disks ★
7 US 2016/0094568 A1 2016-03-31 2014-09-25 IBM Automated response to detection of threat to cloud virtual machine ★
8 US 9,519,781 B2 2016-12-13 2011-11-03 Cyphort Inc. Systems and methods for virtualization and emulation assisted malware detection —
9 US 2017/0011138 A1 2017-01-12 2015-07-07 Synopsys, Inc. System and method for hierarchical power verification —
10 US 9,563,777 B2 2017-02-07 2015-04-29 IBM Security policy generation based on snapshots of similar virtual machines —
11 US 2018/0137032 A1 2018-05-17 2016-11-11 Atlassian Pty Ltd Systems and methods for testing source code ★
12 US 2018/0255080 A1 2018-09-06 2017-03-02 ResponSight Pty Ltd System and Method for Cyber Security Threat Detection —
13 US 2018/0293374 A1 2018-10-11 2017-04-11 Red Hat, Inc. Runtime non-intrusive container security introspection and remediation —
14 US 10,412,109 B2 2019-09-10 2015-10-15 (P) / 2016-10-11 (filed) Outpost 24 France (SecludIT; inv. Loureiro, Donnat) Method for detecting vulnerabilities in a virtual production server of a virtual or cloud computer system —
15 US 10,536,471 B1 2020-01-14 2016-03-31 EMC IP Holding Co. LLC Malware detection in virtual machines ★
16 US 10,944,778 B1 2021-03-09 2017-10-27 EMC IP Holding Co. LLC Method and system for implementing risk based cyber security ★
17 US 11,068,353 B1 2021-07-20 2017-09-27 Veritas Technologies LLC Systems and methods for selectively restoring files from virtual machine backup images ★

Caveat on the list itself. Taken literally, a few of the 17 (e.g., #6 Hedvig "Storage system with virtual disks," #9 Synopsys "hierarchical power verification," #11 Atlassian "testing source code") are not obviously on-point for VM snapshot vulnerability scanning. I am reporting them exactly as the record gives them and do not auto-correct or recharacterize the titles. I also could not retrieve the actual examiner's Office Action / rejection text for 16/585,967, so the §102 mapping below is my own analyst assessment of what each reference could anticipate — not a quotation of an examiner's stated ground.


3. Reference-by-reference analysis and §102 mapping

3.1 The single most significant §102 candidate

US 10,412,109 B2 — Outpost 24 France (SecludIT) — pub. 2019-09-10; priority 2015-10-15; filed 2016-10-11.

  • Disclosure: An agentless vulnerability-analysis system located outside the cloud system connects to the cloud system and requests cloning of a virtual production server to obtain "a clone or a disk copy" of its virtual disk; connects to the clone/disk copy; analyzes vulnerabilities of the clone/disk copy (including viruses, malware, hacking, intrusions, security-policy violations, code flaws); erases the clone; and generates a vulnerability report/alerts, deducing the production server's vulnerabilities from the analysis.
  • §102 relevance: This is the closest single-reference anticipation of claim 1 / claim 11 (and correspondingly claim 10): all of (a) locating/obtaining a disk-level copy of the asset, (b) analyzing it for cyber vulnerabilities, and (c) reporting are taught, and the spec expressly notes no agent need be installed on the server.
  • Gaps that argue against clean §102 anticipation: the reference's "clone or disk copy" is not literally a "snapshot"; it does not expressly recite "determining a location of a snapshot" or "alerting … based on a determined priority" (it describes alerts on critical vulnerabilities); and it teaches cloning via cloud APIs/hypervisor rather than querying a "cloud management console" (claim 4). These gaps make it a stronger §103 combination reference than a stand-alone anticipator.
  • Best claim matches: claims 1, 3, 10, 11, 13 (and arguably 5/15, since it analyzes the disk copy for vulnerabilities).

3.2 References directly implicating "snapshot / disk-image analysis"

US 9,563,777 B2 — IBM ("Security policy generation based on snapshots of similar virtual machines"), pub. 2017-02-07.

  • Teaches taking snapshots of virtual machines and deriving security content (policies) from them. Relevant to claims 1, 3, 5, 10, 11, 13, 15 — the snapshot-of-a-VM-disk concept and its use for security. Potentially anticipatory of the snapshot acquisition limitations when combined with a vulnerability-scanning reference.

US 10,536,471 B1 — EMC IP Holding (Dell) ("Malware detection in virtual machines"), pub. 2020-01-14 (filed 2016-03-31; §102(a)(2) art).

  • Scanning VM images/disk data for malware without running in-guest agents. Directly relevant to the "analyzing the snapshot … to detect potential cyber threats" limitation of claims 1/11 and to claims 5/15 (parsing a copy and scanning).

US 11,068,353 B1 — Veritas Technologies ("Systems and methods for selectively restoring files from virtual machine backup images"), pub. 2021-07-20 (filed 2017-09-27; §102(a)(2) art).

  • Accessing and parsing virtual-machine backup images (disk images). Relevant to claims 1(a)–(b), 3, 5, 13, 15 — i.e., locating and accessing a disk-level image of a VM and reading files from it.

3.3 References implicating "prioritization / risk / alerting" and "mitigation"

US 10,944,778 B1 — EMC IP Holding (Dell) ("Method and system for implementing risk based cyber security"), pub. 2021-03-09 (filed 2017-10-27).

  • Risk-based security prioritization. Directly relevant to the "alerting … based on a determined priority" element of claim 1/11 and to claims 2/12 (prioritize by risk, mitigate).

US 2016/0094568 A1 — IBM ("Automated response to detection of threat to cloud virtual machine"), pub. 2016-03-31.

  • Detecting a threat to a cloud VM and taking an automated response/mitigation. Relevant to claims 2/12 (mitigation) and to the "cloud virtual asset" environment of claim 1.

US 2013/0191643 A1 — Fujitsu ("Establishing a chain of trust within a virtual machine"), pub. 2013-07-25 (examiner-cited).

  • Trust measurement of a VM. Relevant as background to claims 1/11 (assessing integrity/security of a VM) and to claim 6/16's configuration-file verification aspect.

US 2014/0137190 A1 — Rapid7 ("Methods and systems for passively detecting security levels in client devices"), pub. 2014-05-15.

  • Passively determining the security level/posture of devices and reporting. Relevant to claim 1's "alerting … based on a determined priority" and the general security-assessment framing.

3.4 References implicating "instantiating a copy / sandbox monitoring" (claims 7/17)

US 9,519,781 B2 — Cyphort Inc. ("Systems and methods for virtualization and emulation assisted malware detection"), pub. 2016-12-13.

  • Uses virtualization/emulation of a target to detect malware. Relevant to claims 7/17 (instantiate an instance copy from the snapshot and monitor its activity — the patent's "sandbox" embodiment).

3.5 References implicating "containers / non-intrusive introspection" (claims 9/19)

US 2018/0293374 A1 — Red Hat, Inc. ("Runtime non-intrusive container security introspection and remediation"), pub. 2018-10-11.

  • Non-intrusive (agentless) security introspection of containers. Relevant to claims 9/19 ("a virtual machine, a software container, a micro-service") and to the agentless theme of claim 1.

3.6 References implicating file/process-level analysis (claims 6/16 and 8/18)

US 9,177,145 B2 — Sophos Limited ("Modified file tracking on virtual machines"), pub. 2015-11-03.

  • Tracks file modifications on VMs. Relevant to claims 6/16 (checking configuration files, verifying file access times, detecting changed files) and to the spec's "monitoring changes in sensitive machine areas" embodiment.

US 2018/0255080 A1 — ResponSight Pty Ltd ("System and Method for Cyber Security Threat Detection"), pub. 2018-09-06.

  • Behavioral threat detection. Relevant to claim 1's "detect potential cyber threats" and to claim 2's risk prioritization.

US 2015/0052520 A1 — IBM ("Method and apparatus for virtual machine trust isolation in a cloud environment"), pub. 2015-02-19.

  • Isolation/trust in a cloud environment. Relevant background to claims 1/11 (cloud computing environment) and claims 7/17 (isolated sandbox).

3.7 References that appear peripheral or non-substantive on their face

Reported literally, without correction, per your instructions:

  • US 2007/0266433 A1 — Hezi Moore ("System and Method for Securing Information in a Virtual Computing Environment"), pub. 2007-11-15. Discloses virtual security appliances (VSAs) that inspect data communications within a virtual network on a host. It is traffic/communication-centric, not snapshot-analysis-centric, so it maps only to the general "protecting virtual machines against cyber threats" framing of claims 1/11 (and is the kind of reference the patent itself distinguishes in its Background).
  • US 2016/0004449 A1 — Hedvig, Inc. ("Storage system with virtual disks"), pub. 2016-01-07. About virtual-disk storage abstractions; relevant at most to the "virtual disk" terminology of claims 1/3/13.
  • US 2017/0011138 A1 — Synopsys, Inc. ("System and method for hierarchical power verification"), pub. 2017-01-12; and US 2018/0137032 A1 — Atlassian Pty Ltd ("Systems and methods for testing source code"), pub. 2018-05-17. These do not appear to be on-point VM-security prior art for the snapshot-scanning claims; on the face of the record they read as verification/code-testing citations (possibly §103/background art). I flag this as an observation, not a reclassification.

4. Additional prior art cited elsewhere in the same family (worth including)

The record also lists "Family Cites Families (45)" — references cited against Orca's related applications. Several of these are more on-point to claim 1 than some of the 17 above, and would be primary §102/§103 material in any validity challenge:

  • US 8,010,010 B2 — Microsoft ("Using antimalware technologies to perform offline scanning of virtual machine images") — offline scanning of VM images: directly parallels claim 1 (analyzing a VM disk image without executing the guest).
  • US 9,286,182 B2 — Microsoft Technology Licensing ("Virtual machine snapshotting and analysis") — taking/analyzing VM snapshots: squarely reads on claims 1, 3, 5, 10, 11, 13, 15.
  • US 2009/0007100 A1 — Microsoft ("Suspending a Running Operating System to Enable Security Scanning") — security scanning of a VM's disk without guest cooperation: reads on claim 1's agentless/guest-independent analysis.
  • US 8,613,080 B2 — Veracode ("Assessment and analysis of software security flaws in virtual machines") — vulnerability assessment of VM software: reads on claims 5/15.
  • US 9,069,983 B1 — Symantec ("Method and apparatus for protecting sensitive information from disclosure through virtual machines files") — sensitive-data detection in VM files.
  • US 8,407,795 B2 — CA, Inc. ("Systems and methods to secure backup images from viruses") — scanning backup images for malware (relevant to claims 1, 5, 15).
  • EP 2 304 560 B1 — IBM ("A method and system for improvements in or relating to off-line virtual environments").

The near-identical, earlier-filed sibling applications in the same family (US 16/750,556 / US 2020/0244692 A1, "Techniques for securing virtual cloud assets at rest against cyber threats," and its continuations US 11,663,031 / US 11,663,032 / US 11,726,809 / US 11,740,926 / US 11,775,326 / US 11,868,798) are not prior art to US 11,431,735 (common priority date / same family), but they are the closest "prior disclosure" and were the subject of terminal disclaimers tying their terms to US 11,516,231.

I also note the file-history facts visible in the record: multiple terminal disclaimers (filed July 2023) over prior patent US 11,516,231, and an IPR (IPR2024-00220 by Wiz) that was not instituted on procedural grounds — so no PTAB claim-construction validity ruling is available yet.


5. Bottom line

  • Closest single-reference §102 candidate for independent claims 1, 10, and 11: US 10,412,109 B2 (Outpost 24 / SecludIT) — agentless, cloud-based cloning of a virtual production server's disk copy and vulnerability analysis of that copy. Its weaknesses for anticipation are the literal "snapshot" wording, "determining a location of the snapshot," and "alerting … based on a determined priority"; expect it to be used in a §103 combination rather than as a standalone anticipator.
  • References that most strongly read on the claimed snapshot-analysis steps: US 9,563,777 B2 (IBM snapshots), US 10,536,471 B1 (EMC VM malware detection), US 11,068,353 B1 (Veritas VM backup-image access), plus the family-cited US 8,010,010 B2 and US 9,286,182 B2 (Microsoft) — the latter two are the most direct on "offline/snapshot analysis of a VM image."
  • References that read on the prioritization/alerting and mitigation limitations (claims 1, 2, 11, 12): US 10,944,778 B1 (EMC risk-based cyber security) and US 2016/0094568 A1 (IBM automated threat response).
  • References that read on dependent claims: US 9,519,781 B2 (Cyphort → claims 7/17 sandbox monitoring); US 9,177,145 B2 (Sophos → claims 6/16 file tracking); US 2018/0293374 A1 (Red Hat → claims 9/19 containers); US 2014/0137190 A1 (Rapid7) and US 2018/0255080 A1 (ResponSight) → security-posture/threat detection.
  • Apparent non-substantive citations (reported literally, not corrected): US 2017/0011138 A1 (Synopsys, hierarchical power verification), US 2018/0137032 A1 (Atlassian, testing source code), and arguably US 2016/0004449 A1 (Hedvig, storage system with virtual disks).

Confidence and limits: Full bibliographic strings and titles are high-confidence (they come from the patent record you supplied and from primary patent pages). My §102 claim mapping is an analyst opinion, not a record of the examiner's actual rejections — I could not retrieve the Office Actions or the examiner's stated grounds for US 16/585,967, and I have therefore hedged each mapping accordingly. I also note that several post-2019-01-28 grants (US 10,536,471 B1; US 10,944,778 B1; US 11,068,353 B1) qualify only as §102(a)(2) art via their earlier effective filing dates.

Primary sources: https://patents.google.com/patent/[US11431735B2](/patent/US11431735B2)/en ; https://www.freepatentsonline.com/11431735.html ; https://patents.justia.com/patent/11431735 ; https://patents.justia.com/patent/[10412109](/patent/10412109) ; https://portal.unifiedpatents.com/patents/patent/US-10412109-B2 ; https://portal.unifiedpatents.com/ptab/case/IPR2024-00220 ; https://patents.google.com/patent/US20070266433 ; https://storage.courtlistener.com/recap/gov.uscourts.ded.83027/gov.uscourts.ded.83027.15.1_1.pdf

Generated 9/29/2026, 10:33:49 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll research the prior-art references cited on this patent page to ground the § 103 analysis.

Let me confirm the primary reference (Veselov) and research prior art for the surviving PID-file claims.

Obviousness Analysis — U.S. Pat. No. 11,431,735 ("Techniques for securing virtual machines") under 35 U.S.C. § 103

Built on the previously generated Patent Summary and Litigation Summary. I do not repeat their content except where a § 103 point turns on it.


0. Claim posture (threshold point that changes the analysis)

Before reaching the merits, note the posture already established: claims 1–7, 9–17, and 19 were statutorily disclaimed on April 17, 2024 (37 C.F.R. § 1.321(a)) — every claim challenged in IPR2024-00220. A statutory disclaimer is treated as though the disclaimed claim never existed (cf. Vectra Fitness v. TNWK Corp., 162 F.3d 1379 (Fed. Cir. 1998)). Practically, therefore, the § 103 analysis has two very different parts:

  1. Claims 1–7, 9–17, 19 — disclaimed; no longer enforceable, but I analyze them because the task is a technical invalidity assessment of the patent as published.
  2. Claims 8 and 18 — the only claims not in the disclaimer list, reciting "reading process identification number (PID) files" and "checking if the access times of the PID files match against process descriptors."

Flag (contradiction/structural defect to resolve): claims 8 and 18 depend respectively from disclaimed claims 5 and 15 ("The method of claim 5, wherein…"). If claim 5 is deemed never to have existed, claim 8 has no valid parent under 35 U.S.C. § 112(d). That is an independent invalidity/enforceability problem distinct from § 103, but it means the "surviving claims" are, at best, a fragile fallback.


1. Legal framework applied

Under Graham v. John Deere Co., 383 U.S. 1 (1966), and KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007):

  • The field here is predictable: using an already-known capture mechanism (VM snapshot / disk copy / checkpoint), already-known inspection tools (antivirus engines, CVE matching, config/log analysis), and already-known risk-scoring to present results.
  • § 103 does not require bodily incorporation of one reference into another; it is enough that the claimed subject matter as a whole would have been obvious. In re Mouttet, 686 F.3d 1322 (Fed. Cir. 2012).
  • Motivation may come from the references themselves, the nature of the problem, or ordinary design incentives / market pressure. KSR, 550 U.S. at 418–421.

POSITA: a person with a bachelor's degree in computer science/electrical engineering (or equivalent) and ~3–5 years of experience in virtualization and/or cloud/network security, or a master's plus ~2 years — i.e., a person familiar with hypervisors, VM snapshots, cloud APIs/management consoles, and vulnerability scanners. (Orca and Wiz may have litigated a different formulation; the outcome of the Grounds below is not sensitive to reasonable variations.)

Critical prior-date test: all art relied on below published or had effective filing before the '735 patent's Jan. 28, 2019 priority date, so all qualify under § 102(a)(1)/(a)(2).


2. Reference inventory (and what each supplies)

Reference Date / status Teaches
Loureiro / Outpost 24 France, U.S. Pat. No. 10,412,109 B2 (pub. US 2017/0111384 A1, Apr. 20, 2017) — examiner-cited on the patent page Filed Oct. 2016; priority Oct. 16, 2015 Agentless detection of vulnerabilities in a virtual production server: an external analysis system connects to the cloud/virtualization system via its APIs/hypervisor, requests cloning or a disk copy of the virtual disk(s) of the production server, obtains the location of those disks, connects to and analyzes the clone/disk copy (Nessus/OpenVAS scanning, config-file good-practice verification, log analysis, cryptographic checksums, malware/virus presence, APT "weak signals… abnormal when compared to the history"), generates reports and "alerts… generated when the analysis system identifies a critical vulnerability," and erases the copy. Explicitly: "an agent does not need to be installed on the server." Classifies servers/tests "according to how critical they are." (portal.unifiedpatents.com; patents.justia.com/patent/10412109)
Basavapatna, U.S. Pat. No. 8,595,845 (pub. US 2013/0191919) — Wiz's EX1008 2013 Vulnerability-centric and asset-centric risk metrics (standard vulnerability score, e.g. CVSS; composite vulnerability score; countermeasure score); aggregate risk metric summing/mean/max across assets; UI that "lists all assets, vulnerabilities, or threats, sorted by aggregate risk metric," "top ten," and threshold-triggered alerts. (Per the IPR record: ai-lab.exparte.com/case/ptab/IPR2024-01191/doc/1044)
Veselov, U.S. Pat. No. 11,216,563 — Wiz's EX1007, IPR2024-00220 Used as prior art for the '735 claims A scanning service that determines/obtains a snapshot of a target VM's logical volume ("virtual disk"), obtains the snapshot at its storage location or by copy, and performs agentless security assessment either by instantiating an assessment VM from the snapshot or by analyzing the snapshot as a data file; uses CVE matching, directory/filename pattern matching against installed applications, and configuration assessment. (Petition excerpts: ptacts.uspto.gov … /1557245)
Microsoft, U.S. Pat. No. 8,011,010 B2 — family-cited on the patent page 2011 Offline scanning of VM images: image stored as VHD(s) by taking the VM offline or by taking a checkpoint/snapshot while the VM is on-line; renders the image to file-system data (mounting VHDs); anti-malware engine scans exposed file-system data; can iterate across a chain of checkpoints. (patents.google.com/patent/US8011010)
Microsoft, US 2009/0007100 A1 — family-cited Pub. Jan. 1, 2009 Suspending a running OS to enable security scanning of the disk — the germ of "snapshot then scan."
Veracode, U.S. Pat. No. 8,613,080 B2 — family-cited 2013 Security assessment of a VM represented by an image file: load/execute the VM, extract files, identify installed applications, use a vulnerability database, scan executing applications with test/fuzz input, produce a report; periodic, event-triggered assessments. (patents.justia.com/patent/8613080)
EMC, U.S. Pat. No. 10,944,778 B1 — examiner-cited on the patent page Priority Oct. 26, 2017 Risk-based cyber security using app-granularity images of system images in cloud environments; "evaluat[es] risk as a decision threshold for conducting cyber security assessments of system images within cloud computing environments"; returns "cyber protection reports." (freepatentsonline.com/10944778.html)
IBM, U.S. Pat. No. 9,563,777 B2 — examiner-cited 2017 Security policy generation based on snapshots of similar virtual machines — snapshot-as-data-source for security.
EMC, U.S. Pat. No. 10,536,471 B1 — examiner-cited 2016/2020 Malware detection in virtual machines (disk-image–oriented).
Cyphort, U.S. Pat. No. 9,519,781 B2 — examiner-cited 2016 Virtualization/emulation-assisted malware detection — instantiate/emulate and monitor execution.
Red Hat, US 2018/0293374 A1 — examiner-cited Oct. 2018 Runtime non-intrusive container security introspection and remediation.
IBM, US 2016/0094568 A1 — examiner-cited Mar. 2016 Automated response to detection of a threat to a cloud VM (mitigation).
VMware, U.S. Pat. No. 9,189,265 B2; Hedvig, US 2016/0004449 A1 — family-cited 2015/2016 Storage architectures with virtual disks — locating/associating virtual disks with VMs.
Sophos, U.S. Pat. No. 9,177,145 B2 — examiner-cited 2015 Modified-file tracking on virtual machines (file-level metadata/hash forensics inside VM images).

3. Ground 1 (strongest) — Loureiro + Basavapatna renders claims 1, 10, 11 obvious

Loureiro is nearly a bit-for-bit map of the independent claims:

Claim 1 / 10 / 11 limitation Loureiro
"determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset… instantiated in the cloud computing environment" External analysis system connects to the cloud system via "infrastructure of programming interfaces (APIs)" and the hypervisor, and requests cloning or a disk copy "of the virtual disk or disks" of the production server; each virtual server "is associated with one or more virtual memory disks" — i.e., locating the disk/copy in the cloud.
"accessing the snapshot of the virtual disk based on the determined location" "the system for analyzing vulnerabilities connects to the clone or to the disk copy."
"analyzing the snapshot … to detect potential cyber threats" "analyzes the vulnerabilities of the clone or of the disk copy": scanner (Nessus/OpenVAS), config-file checking, log-file analysis, checksum/modification detection, malware/virus presence, APT weak-signal analysis.
"alerting detected potential cyber threats based on a determined priority" "It allows alerts to be generated when the analysis system identifies a critical vulnerability"; security policies "classify the servers and the tests… according to how critical they are, the network and connection zone, and the threats."

To the extent Orca argued priority is not "determined" in Loureiro, Basavapatna supplies an explicit, quantified prioritization scheme (risk metrics + sorted/top-N/threshold alerting). Motivation: both references address the same problem — surfacing the most consequential cloud/VM flaws to overwhelmed operators — and Loureiro's own "criticality-based" policy classification provides the natural hook to Basavapatna's risk scoring. No teaching away; combination is of known techniques with a predictable result (fewer, better-ordered alerts). Under KSR this is "a combination of familiar elements according to known methods [yielding] predictable results."

Note the "without agents" and "no copy" nuances: Loureiro states it needs no agent on the production server, and Veselov states the snapshot may be analyzed at its storage location without making a copy — squarely covering claim 1's bare "accessing." Claim 1 does not require copying, a schedule, or guest-OS cooperation, which materially narrows any distinction Orca could draw.


4. Ground 2 — Veselov + Basavapatna (the ground Wiz actually presented)

This is the combination from IPR2024-00220: Veselov teaches every element of the independent claims except explicit alert prioritization, which Basavapatna supplies (Wiz's words: "commonplace at the time"). Motivation is the same as Ground 1. Because Orca disclaimed all challenged claims rather than contest this ground, there is no contrary PTAB or court finding — and Orca's disclaimer is, practically, a concession that the claim set could not survive. (Petition: docketalarm.com …/IPR2024-00220/…Petition_as_filed.pdf)


5. Ground 3 — a coherent alternative from the patent page's own cited art

Even setting Veselov/Basavapatna aside, the references the Examiner and family already considered combine to the same result:

  • Microsoft '010 (snapshot-taking on a live VM → mount → antimalware scan of file-system data) supplies "determining location / accessing / analyzing a snapshot of the virtual disk."
  • Veracode '080 supplies VM-image application identification + vulnerability-database matching + dynamic/fuzz testing (→ claim 5/15 "known and unknown vulnerabilities").
  • EMC '778 supplies the risk-based decision threshold and prioritized reporting for cloud system images (→ claim 2/12 and "determined priority").

Motivation: Microsoft '010 itself explains the reason to scan images out-of-band — "some malware is adept at hiding itself from antimalware programs that are running while the operating system is running," and per-VM agents "tax processing and memory resources" and add licensing cost. That is the exact motivation for the '735 patent's snapshot approach, stated in art eight-plus years earlier. Applying Veracode's vulnerability-specific analyses and EMC's risk-based prioritization to Microsoft's snapshot-scanning pipeline is a textbook obvious improvement.


6. Dependent-claim mapping (claims 2–7, 9, 12–17, 19 — all disclaimed)

Claim Limitation Reference(s) supplying it
2, 12 prioritize by risk; mitigate Basavapatna; EMC '778; IBM US 2016/0094568 (automated response); Loureiro (corrections applied to clone, clone can replace production server)
3, 13 determine the virtual disk allocated to the asset Loureiro; VMware '265; Hedvig '449
4, 14 query a cloud management console for snapshot/disk location Loureiro (connects to cloud system via APIs/hypervisor to list servers and obtain disk-copy location); Veselov (I/F and command to the virtualization layer)
5, 15 parse a copy; scan for known and unknown vulnerabilities by type Veracode '080; Loureiro; Veselov (CVE)
6, 16 config files; file access times; system logs; machine memory (page file) Loureiro (config files, log files, checksums); Veracode (OS/registry config); Veselov (config files of installed applications); memory/page-file inspection = routine memory-forensics (see § 7 caveat)
7, 17 instantiate a copy and monitor all activity Veracode '080 (load/execute image, connect to and fuzz executing apps); Cyphort '781 (emulation-assisted malware detection); Veselov (assessment VM from snapshot); Red Hat '374 (non-intrusive container introspection)
9, 19 asset = VM / container / micro-service Loureiro, Red Hat '374, Veracode '080

7. Claims 8 and 18 — the only non-disclaimed claims (and the weakest § 103 ground)

Claim 8 (from claim 5): scanning also comprises any one of "reading process identification number (PID) files" and "checking if the at least access times of the PID files match against process descriptors." Claim 18 is the system mirror.

These are narrow, but they are the only formally surviving claims, so I treat them separately and honestly:

  • What the record supports. Loureiro teaches a disk-copy analysis that "involves carrying out tests and verifying files on the clone" including cryptographic-checksum/modification checks and log-file analysis. Sophos '177,145 (modified-file tracking on VMs) and EMC '10,536,471 (offline malware detection in VM disk images) teach reading file-level metadata inside a VM image. The Unix/Linux run-time PID file convention (e.g., /var/run/*.pid) and process-descriptor correlation are themselves well-known operating-system facts a POSITA brings as "prior art" under § 103(a) without a documentary reference (cf. In re Venner, 262 F.2d 91; In re Kahn).
  • The honest gap. I did not locate a reference that expressly discloses "reading PID files and matching their access times against process descriptors" to deduce running processes. This is precisely the limitation Wiz did not challenge in IPR2024-00220, which is consistent with the art mapping being thin here.
  • The likely ground would be: [PID-file/process-file convention + file-timestamp forensics, as in Sophos '145 / EMC '471 / Loureiro's file-verification] in view of [Microsoft '010 / Veselov snapshot pipeline], with the motivation being the patent's own stated need — inferring which processes actually ran so that vulnerabilities in running (not merely installed) software can be prioritized (Loureiro likewise stresses reducing false positives and deducing relevance). Combining an offline disk-image reader with standard OS run-state artifacts is a predictable, conventional step.
  • Caveat (do not overstate): absent a documentary reference expressly tying PID files to process descriptors, this is the one claim family where a § 103 challenge is vulnerable, and it is also the family already compromised by the § 112(d) parent-dependency problem flagged in § 0.

8. Motivation-to-combine, articulated (common across Grounds 1–3)

  1. Same field of endeavor: cloud/virtualization security by inspecting VM disks/images rather than live traffic or in-guest agents (Loureiro, Microsoft '010, Veracode '080, Veselov, EMC '778, IBM '777).
  2. Same problem, same solution space: agentless, production-safe, periodic assessment — Loureiro and Microsoft '010 explicitly motivate agentless/offline scanning (avoids performance impact, agent licensing/management, and malware that hides from in-OS scanners).
  3. Predictable results / no new mechanism: each claim element is a known technique (snapshot/disk copy; CVE + dynamic scanning; risk scoring; alert sorting), combined to yield the ordinary aggregate of their separate functions — the KSR "familiar elements according to known methods" case.
  4. Reason to add prioritization specifically: Basavapatna and EMC '778 both motivate prioritization to combat alert fatigue and to set a risk decision threshold; the '735 patent's own specification claims the same benefit ("reduces the number of alerts reported to the user"), confirming the goal was known and the combination predictable.
  5. No teaching away; simultaneous invention context: the density of independent references (Loureiro, Veselov, Microsoft, Veracode, EMC, IBM, All) all landing on snapshot/disk-image cloud security in 2015–2018 corroborates that this was the expected, obvious direction — evidence of obviousness, not invention. Hoffmann-La Roche v. Promega (secondary-consideration nexus caution).

9. Objective indicia / secondary considerations

  • No proven nexus (on the record here) between any commercial success of Orca's product and the specific claimed subject matter; and the family's history undercuts a "long-felt, unexpected" narrative — Loureiro (2015 priority) and Microsoft '010 (2007) pre-date it by years.
  • Conduct-based signals cut against the patent: Orca disclaimed every challenged claim rather than defend them; and on Dec. 8, 2025 the PTAB held all claims unpatentable in the related-patent IPRs IPR2024-00863/‑00864/‑00865 on Veselov + Basavapatna — the same primary art and the same 2019-01-28 priority family. (Joint notice: archive.org/gov.uscourts.ded.83027…235.0.pdf). That is powerful, near-dispositive corroboration that the shared specification's snapshot-security concepts were obvious.

10. Bottom line

  • Claims 1–7, 9–17, 19: very likely obvious under § 103 — Loureiro alone (plus Basavapatna for priority) or Veselov + Basavapatna, with Ground 3 (Microsoft '010 + Veracode '080 + EMC '778) as a fully independent fallback. These are additionally statutorily disclaimed and should be treated as never having existed.
  • Claims 8, 18: not disclaimed, but (a) structurally compromised under § 112(d) because they depend on disclaimed claims 5/15; and (b) the subject of the weakest obviousness record, since no located reference expressly discloses PID-file/access-time-to-process-descriptor correlation. A § 103 attack here would rest on routine OS knowledge plus file-metadata forensics (Sophos '145, EMC '471) applied to a snapshot-scanning pipeline.

11. Caveats and contradictions to flag

  • Unverified bibliographic details: the exact publication/priority date and assignee of Veselov, U.S. Pat. No. 11,216,563, and the assignee of Basavapatna, U.S. Pat. No. 8,595,845 / US 2013/0191919, were taken from the IPR record (ai-lab.exparte.com/case/ptab/IPR2024-01191/doc/1044). I did not independently verify their PDFs; the § 103 conclusions assume both predate Jan. 28, 2019, as Wiz asserted. Veselov/Basavapatna are not among the 17 examiner citations on the Google Patents page; they come from the IPR record carried over from the earlier sections, and I distinguish them accordingly from the "page's Prior Art section" references.
  • Contradiction already noted in the earlier sections stands: the Google Patents fetch timestamp (2026-09-29) conflicts with the task header date (April 26, 2026). I treat April 26, 2026 as "today" and note that the Dec. 8, 2025 FWDs and the Jan. 13, 2026 dismissal are therefore in the past.
  • Claims 8/18 prior-art mapping is the soft spot — I am explicitly not asserting that a specific reference discloses "PID files matched against process descriptors" as claimed; that limitation lacks a clean documentary hit in the material I reviewed.
  • This is a technical invalidity assessment, not a legal opinion. A statutory disclaimer's effect on dependent claims 8/18, and the precise obviousness outcome on those claims, are questions on which I flag residual uncertainty rather than certify a conclusion.

Generated 9/29/2026, 10:34:15 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Wiz, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 11431735.