Invalidity dossier
US 11775326
Techniques for securing a plurality of virtual machines in a cloud computing environment
Current assignee: Wiz, Inc.
Added 9/29/2026, 10:12:13 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll verify the patent details and litigation status with targeted searches.
US 11,775,326 B2 — Analyst Summary
Grounding note: The full text you supplied is the authoritative source and I have used it over the search results wherever they conflict. Where secondary databases disagree with the patent document on dates, I flag it rather than reconcile it.
1. Bibliographic data (per the patent document / Google Patents record)
| Field | Value |
|---|---|
| Patent number | US 11,775,326 B2 |
| Title | Techniques for securing a plurality of virtual machines in a cloud computing environment |
| Application no. | US 18/055,181 |
| Pre-grant pub. | US 2023/0087080 A1 (published 2023-03-23) |
| Filing date | 2022-11-14 |
| Issue/grant date | 2023-10-03 |
| Earliest priority | 2019-01-28 (prov. 62/797,718) |
| Inventor | Avi Shua (Tel Aviv–Jaffa, IL) |
| Assignee | Orca Security Ltd. (Tel Aviv, IL) — assignment recorded 2023-03-27 |
| Examiner | Joseph P. Hirl (primary); Hassan Saadoun (assistant) |
| Claims | 28 total; independent claims 1, 15, 18 |
| Status | Active; adjusted expiration listed as 2039-11-11 |
Continuity (from the specification): "This application is a continuation of U.S. Application No. 17/330,998 (now U.S. Patent No. 11,516,231), filed May 26, 2021, which is a continuation of U.S. Application No. 16/585,967 (now U.S. Patent No. 11,431,735), filed September 27, 2019, which claims the benefit of U.S. Provisional Applicantion No. 62/797,718 filed on January 28, 2019." The '326 patent is thus the fourth member of a chain in a 13-application family.
⚠ Date discrepancy to flag: The Unified Patents portal entry for US-11775326-B2 lists application date 2022-11-13, grant date 2023-10-02, priority 2019-01-27 and expiration 2039-11-10 — each one day earlier than the patent record. These are almost certainly time-zone normalization artifacts, not a different document, but I am not asserting that as fact.
Classification: G06F 9/45558, G06F 11/14, G06F 16/128, G06F 21/55, H04L 63/14 (per the record's CPC listing); Justia additionally lists current US class 713/176.
2. Abstract (verbatim)
"A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority."
3. Plain-language overview of the independent claims
All three independents cover the same subject matter in three statutory formats — claim 1 (method), claim 15 (non-transitory CRM), claim 18 (system with at least one processor). The substance is identical across all three; the differences are formal.
Claim 1 — Method
Plain language: Scan many cloud workloads at once, off their disk snapshots, and rank the results by risk.
- Receive a request to scan a plurality of protected virtual cloud assets in the cloud environment.
- For each asset, in a loop:
- (a) Use an API or service provided by the cloud environment to determine the location of a snapshot of at least one virtual disk belonging to that asset. (The "using an API or service" limitation is expressly in the claim language.)
- (b) Access that snapshot, again using an API/service of the cloud environment.
- (c) Analyze the snapshot to determine whether potential cyber vulnerabilities exist.
- (d) Determine a risk associated with each identified vulnerability.
- For each asset that has vulnerabilities, determine a risk level to the cloud computing environment (i.e., an asset-level, environment-relative score — not just per-vulnerability severity).
- Report the existence of the vulnerabilities for those assets "such that the plurality of protected virtual cloud assets … are prioritized based on associated risk levels." Population-level prioritization is the point of the claim.
Note: the independent claim recites "reporting the existence of the potential cyber vulnerabilities" — it does not recite "alerting," and it does not recite an agentless/no-agent limitation or a "VM is inactive/at rest" limitation. That is a meaningful drafting difference from the abstract and from sibling patents in the family.
Claim 15 — Non-transitory computer readable medium
Same four-step operation as claim 1 (receive request → per-asset API-based snapshot location + access → analyze → per-vulnerability risk → per-asset environment risk level → prioritized reporting). Written as instructions that, when executed by at least one processor, cause the operations. No additional technical limitations beyond claim 1.
Claim 18 — System
Same operations as claim 1, implemented in a system comprising at least one processor configured to receive the request, and for each asset determine the snapshot location via cloud API/service, access the snapshot via cloud API/service, analyze it for a plurality of potential vulnerabilities, determine a risk per vulnerability, determine a per-asset risk level to the cloud environment, and report so assets are prioritized by risk level. (Claim 18 mixes "configured to" framing with gerund-form limitations — "determining," "accessing," "analyzing" — which is a possible §112(b) vulnerability worth noting but which I make no legal conclusion about.)
Dependent-claim highlights (for context, not independent scope)
- Cl. 2 / 19: take (or request taking) the snapshot, then obtain its location.
- Cl. 3, 6–8, 20: risk scoring based on external exploit-likelihood intelligence; relevance checks for whether an installed application is actually in use; filtering based on risk.
- Cl. 4–5, 16–17: matching installed applications/app versions against a known-vulnerable list; binary comparison and cryptographic-hash matching.
- Cl. 9–10: parsing the snapshot and scanning it; checking config files, file access times, system logs.
- Cl. 11–12: mitigation — blocking untrusted traffic, halting the asset, quarantining it.
- Cl. 13–14: determining the specific virtual disk, e.g., by querying a cloud management console.
- Cl. 21–27: asset risk level based on the per-vulnerability risks; weighting "takeover risk" by network location, criticality from stored contents, and reachability of other assets.
- Cl. 28: prioritizing reported vulnerabilities by the asset's risk level.
4. Litigation and PTAB status (as found; verify before relying)
District court: Orca Security Ltd. v. Wiz, Inc., D. Del. C.A. No. 1:23-cv-00758 (JLH/SRF). The '326 patent was one of six asserted Orca patents (with 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926).
PTAB: IPR2024-01191, Wiz, Inc. v. Orca Security Ltd., petition filed 2024-08-07, challenging claims 1–28 of the '326 patent. Grounds per the petition record: (1) Veselov (US 11,216,563) in view of Basavapatna (US 2013/0191919) for claims 1–21 and 28; (2) additionally Czarny (US 9,749,349) for claims 4–5, 17; (3) additionally Giakouminakis for claims 22–27. Instituted; a consolidated oral argument covering IPR2024-01109/-01190/-01191 was held 2025-10-14 (Paper 79). Final Written Decision was due no later than 2026-01-22.
Settlement: The Google Patents family-litigation field labels IPR2024-01191 as "(Settlement)." Consistent with that, the companion '326-family IPR2024-01190 saw a joint motion to terminate filed 2026-01-07, and the district court case was dismissed with prejudice by stipulation (filed 2026-01-06; so-ordered 2026-01-13).
CAFC 2026: I was unable to confirm any Federal Circuit appeal docketed in 2026 specifically involving 11,775,326. The '326 IPR apparently resolved by settlement rather than a merits final written decision, which normally leaves no PTAB decision to appeal. I did see that the PTAB's 2025-12-08 decisions against the sibling patents 11,663,031 / 11,663,032 / 11,693,685 had a Federal Circuit notice-of-appeal deadline of 2026-02-09, but I did not verify whether Orca filed such an appeal. Treat the CAFC point as unverified.
Citation conflict to note: my first search returned a Google Patents snippet attributing the IPR2024-01191 link to Unified Patents' PTAB data portal, while the PTAB and court filings identify the petitioner as Wiz, Inc. The Unified Patents portal is a data aggregator; the underlying PTAB record names Wiz. I am not auto-correcting the Google Patents citation, merely reporting both.
5. Relevance of the '326 to the family
Relative to the parent '431/'231 documents, claim 1 of the '326 was rewritten around a plurality of assets plus an explicit environment-level risk-level determination feeding asset prioritization, and it expressly requires the cloud-provider API or service for both locating and accessing the snapshot. That is the family's differentiation for this member and is also where the Wiz IPR grounds concentrated (Basavapatna supplying the vulnerability-risk-metric and asset-level aggregation/prioritization teaching).
Generated 9/29/2026, 10:21:33 AM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 11775326. The free-form analysis below may also discuss cases beyond this list.
- Wiz, Inc. v. Orca Security Ltd.filed Aug 7, 2024IPR2024-01191USPTO, Patent Trial and Appeal Boardterminated by settlement; no final written decision on the merits
Defendants: Orca Security Ltd.
- Orca Security Ltd. v. Wiz, Inc.filed Jul 12, 20231:23-cv-00758U.S. District Court for the District of Delaware (Wilmington Division)terminated Jan 13, 2026dismissed with prejudice
Defendants: Wiz, Inc.
Other patents asserted: 11663031, 11663032, 11693685, 11726809, 11740926
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US patent 11775326, starting with the leads embedded in the patent record I've already retrieved.
I have solid leads. Let me verify the IPR outcomes, settlement, and check for any other defendants or jurisdictions.
Bottom line
I found one litigation matter and one related PTAB proceeding that specifically involve U.S. Patent No. 11,775,326 (= 11775326). Both arose from the same dispute — Orca Security Ltd. v. Wiz, Inc. — and both ended in early 2026 with a global settlement and dismissal with prejudice. I found no other district court suits, no ITC Section 337 investigation, and no Federal Circuit appeal involving the '326 patent.
Note on identity: the string "11775326" and the citation "11,775,326" refer to the same patent. US 11,775,326 B2, "Techniques for securing a plurality of virtual machines in a cloud computing environment," App. No. 18/055,181, filed 2022-11-14, granted 2023-10-03, assignee Orca Security Ltd., priority 2019-01-28 (provisional 62/797,718). Every source below uses "11,775,326" or "the '326 patent."
Litigation specifically involving US 11,775,326
| Case 1 — District Court | Case 2 — PTAB | |
|---|---|---|
| Caption | Orca Security Ltd. v. Wiz, Inc. | Wiz, Inc. v. Orca Security Ltd. |
| Forum / Jurisdiction | U.S. District Court for the District of Delaware (Wilmington) | USPTO, Patent Trial and Appeal Board |
| Case number | C.A. No. 23-758 (JLH) (SRF) / 1:23-cv-00758-JLH-SRF | IPR2024-01191 |
| Plaintiff / Petitioner | Orca Security Ltd. | Wiz, Inc. |
| Defendant / Patent Owner | Wiz, Inc. (counterclaim-plaintiff) | Orca Security Ltd. |
| Filing date (as to this patent) | Complaint filed 2023-07-12; the '326 patent was added by the Second Amended Complaint filed 2023-10-10 (D.I. 15) | Petition filed 2024-08-07; PTAB notice of filing date 2024-08-19 |
| Status / outcome | Dismissed with prejudice; case terminated. Stipulation of dismissal filed 2026-01-06 (D.I. 237); so-ordered 2026-01-13 (D.I. 238). Each side bears its own costs and fees. Case had been stayed since 2025-01-16 pending the IPRs. | Terminated by settlement; no final written decision on the merits. FWD was due no later than 2026-01-22; the parties filed a joint motion to terminate under 35 U.S.C. § 317(a) in January 2026. |
Case 1 details — Orca Security Ltd. v. Wiz, Inc., D. Del. 1:23-cv-00758
- Asserted patents (Orca's affirmative case, six total): U.S. Patent Nos. 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926; and 11,775,326. All six are in the same family (priority to provisional 62/797,718). The original July 2023 complaint asserted only the '031 and '032 patents; the '326 patent entered the case with the Second Amended Complaint (D.I. 15, Oct. 10, 2023).
- Judges: District Judge Jennifer L. Hall (presiding); Magistrate Judge Sherry R. Fallon (referral). The case was initially assigned to Judge Gregory B. Williams.
- Counterclaims: Wiz answered and counterclaimed on 2024-06-04 (D.I. 70), asserting Orca infringed Wiz's U.S. Patent Nos. 11,722,554; 11,929,896; 11,936,693; 12,001,549; and 12,003,529.
- Key interim rulings: Wiz's motion to dismiss Orca's indirect/willful infringement claims was denied 2024-05-21 (D.I. 65). Orca moved to dismiss Wiz Counterclaim Count IV ('549 patent) under § 101/Alice (D.I. 112, 137/138); Wiz amended its counterclaims (D.I. 124) in response. Claim construction briefing proceeded in late 2024 (D.I. 201, 202).
- Stay: On 2025-01-16 the court so-ordered the parties' stipulation staying the entire case — all claims and counterclaims — "through final written decision in each of the Wiz IPRs," vacating the scheduling order and tolling discovery (D.I. 232, 233).
- Termination: Stipulation of dismissal with prejudice filed 2026-01-06; "SO ORDERED" and civil case terminated 2026-01-13 (D.I. 238). A January 2026 stipulation amended the protective order's post-dismissal retention/purge obligations.
- Why it ended: PTAB decisions issued 2025-12-08 holding all challenged claims of three of Orca's asserted patents unpatentable; with the remaining reviews (including the '326) pending, the parties settled globally rather than continue.
Case 2 details — IPR2024-01191, Wiz, Inc. v. Orca Security Ltd.
- Patent challenged: U.S. 11,775,326, claims 1–28 (all claims).
- Grounds (all § 103 obviousness):
- Ground 1: claims 1–21 and 28 over Veselov (U.S. 11,216,563) in view of Basavapatna (US 2013/0191919).
- Ground 2: claims 4–5 and 17 over Veselov, Basavapatna, and Czarny (U.S. 9,749,349).
- Ground 3: claims 22–27 over Veselov, Basavapatna, and Giakouminakis.
- Panel: Administrative Patent Judges Garth D. Baer, Michael R. Zecher, and Scott Raevsky.
- Procedural posture: Institution decision was expected around 2025-02-19; the Board granted Orca's motion for additional discovery (226 confidential Wiz documents going to objective indicia of non-obviousness / alleged copying of Orca's SideScanning™ technology) on 2025-03-28. Oral hearing for IPR2024-01109, -01190, and -01191 was held 2025-10-14. The '326 FWD deadline was 2026-01-22.
- Outcome: The parties settled; a joint motion to terminate under 35 U.S.C. § 317(a) was filed (Board authorization 2026-01-06) with the confidential settlement agreement filed as an exhibit. No final written decision on the merits issued on the '326 patent. Google Patents' litigation banner likewise flags IPR2024-01191 as "(Settlement)".
Related proceedings (do NOT involve the '326 patent — different Orca patents)
- Wiz's other IPRs against Orca: IPR2024-00863, -00864, -00865 (the '031, '032, '685 patents; instituted 2024-12-09; FWDs due 2025-12-09 and reported 2025-12-08 as unpatentable); IPR2024-01109 (the '809 patent) and IPR2024-01190 (the '926 patent) — different patents from the '326, though litigated in parallel and terminated together with the '326 IPR.
- Orca's IPRs against Wiz (e.g., IPR2025-01086, Orca Security Ltd. v. Wiz, Inc.) — challengen Wiz's patents, not the '326.
Caveats
- The district court docket data here is drawn from CourtListener/RECAP and Docket Alarm and may lag PACER; I did not access PACER directly. PACER would be the authoritative check for any post-dismissal filings.
- I could not retrieve the individual Board termination order for IPR2024-01191 itself (the accessible joint motion to terminate is the companion IPR2024-01190 motion), but the Board's January 6, 2026 authorization email and Google Patents' "Settlement" designation cover -01109/-01190/-01191 collectively. Treat the '326 IPR's termination-by-settlement as well supported but not independently confirmed by the -01191 termination paper.
- No CAFC appeal of the '326 patent right was identified. Because the district court case was dismissed with prejudice and the IPR was terminated before a final written decision, there was no appealable merits judgment specific to the '326 patent.
Sources:
- Orca Security Ltd. v. Wiz, Inc., 1:23-cv-00758 (D. Del.) docket — https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/
- Stipulation of dismissal with prejudice (D.I. 237) — https://www.courtlistener.com/docket/67600951/237/orca-security-ltd-v-wiz-inc/
- Stay stipulation (D.I. 232) — https://www.docketalarm.com/cases/Delaware_District_Court/1--23-cv-00758/Orca_Security_Ltd._v._Wiz_Inc/232/
- Notice of IPR events / IPR2024-01191 identification (D.I. 126) — https://www.courtlistener.com/docket/67600951/126/orca-security-ltd-v-wiz-inc/
- Joint Notice of IPR Final Written Decisions (FWD due 2026-01-22 for the '326) — https://archive.org/download/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf
- IPR2024-01191 petition/grounds summary — https://ai-lab.exparte.com/case/ptab/IPR2024-01191/doc/1044
- Board Order granting additional discovery (IPR2024-01191) — https://www.docketalarm.com/cases/PTAB/IPR2024-01191/Wiz_Inc._v._Orca_Security_Ltd/
- Joint motion to terminate on settlement (IPR2024-01190, Jan. 2026) — https://www.docketalarm.com/cases/PTAB/IPR2024-01190/Wiz_Inc._v._Orca_Security_Ltd/
- Unified Patents litigation entry — https://portal.unifiedpatents.com/litigation/Delaware%20District%20Court/case/1%3A23-cv-00758
- "Orca, Wiz End Dueling Lawsuits Over Cloud Security Patents," Information Security Media Group — https://www.inforisktoday.in/orca-wiz-end-dueling-lawsuits-over-cloud-security-patents-a-30463
- Calcalist/CTech, "Wiz and Orca agree to end bitter legal battle, dismissing all claims" — https://www.calcalistech.com/ctechnews/article/b1114vsiebl
Generated 9/29/2026, 10:21:42 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Wiz, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll research this. Let me start with web searches on the identified proceedings and the patent.
Key finding: the patent's own page and web sources reference a PTAB case. Let me pin down its status.
Let me confirm the institution details, panel, and the termination of IPR2024-01191 specifically.
PTAB Activity on US 11,775,326 ("Techniques for securing a plurality of virtual machines in a cloud computing environment")
⚠️ Data-source conflict — flagged up front. The structured "PTAB proceedings on file" block supplied in this prompt states the USPTO ODP API returns no AIA trial proceedings for this patent. That block is incomplete/out of date. The patent's own Google Patents page carries a litigation/PTAB entry reading "PTAB case IPR2024-01191 filed (Settlement)", and PTAB + district-court records confirm the proceeding. I have therefore reported IPR2024-01191 below as the canonical proceeding, sourced from the patent page, the PTAB docket, and the Orca v. Wiz Delaware filings — not from the ODP block. Treat the ODP "no proceedings" answer as a stale-ingest artifact.
Proceedings overview
One AIA trial proceeding is on file for US 11,775,326: IPR2024-01191 (Wiz, Inc. v. Orca Security Ltd.). Breakdown: 0 active, 0 claims invalidated, 0 claims sustained on the merits, 1 settled/terminated pre-Final Written Decision, 0 institution denied.
Bottom line for a defendant: this patent is neither "hardened" nor "dead" — it is untested on the merits. Wiz challenged all of claims 1–28, the Board instituted, the parties tried the case through an oral hearing, and then the proceeding was swept into a global January 2026 Orca–Wiz settlement and dismissed before any Final Written Decision issued. No claim of the '326 patent has ever been adjudicated unpatentable, and no IPR estoppel (§ 315(e)(2)) ever attached. If you are facing a demand letter citing this patent, every one of claims 1–28 is still live — but the same prior art that killed three sibling patents in the same family is on the public record and largely unadjudicated against the '326 claims.
IPR2024-01191 — Wiz, Inc. v. Orca Security Ltd.
- Type: Inter Partes Review (35 U.S.C. §§ 311–319)
- Filed: 2024-08-07 (notice of filing date accorded 2024-08-19)
- Patent challenged: U.S. Patent No. 11,775,326 B2 (challenged claims 1–28, i.e., all claims)
- Status: Settled / terminated pre-Final Written Decision. Verbatim framing from the patent page: "PTAB case IPR2024-01191 filed (Settlement)." The Board never issued an FWD on the merits. The parties' 2025-12-15 joint notice to the Delaware court had projected the Final Written Decision deadline as 2026-01-22; the case was terminated by settlement before that date. (The companion '926 IPR, IPR2024-01190, was terminated by a joint motion to terminate filed 2026-01-07 under 35 U.S.C. § 317(a); the Google Patents docket flags -01191 with the same "(Settlement)" designation. I have confirmed the termination motion in the -01190 record directly; the corresponding -01191 termination order is reported consistently but I have not separately pulled that paper — verify on PTAB E2E.)
- Judge panel: Not confirmed from the sources retrieved. (Docket Alarm lists APJs Easthom, Khan, and Murray for a different Orca/Wiz IPR, IPR2025-01087 — do not attribute that panel here.) Verify on PTAB E2E.
- Petition grounds (three grounds, all § 103 obviousness; derived from a secondary summary of the petition — confirm against Petition Paper 2 on E2E):
- Ground 1 — Claims 1–21 and 28 obvious over Veselov (U.S. Pat. No. 11,216,563, assigned to Amazon) in view of Basavapatna (U.S. Pub. 2013/0191919). Veselov supplied the agentless, snapshot-based cloud scanning core; Basavapatna supplied per-vulnerability risk metrics, asset-level risk aggregation, and risk-based alert prioritization.
- Ground 2 — Claims 4–5 and 17 further obvious over Veselov + Basavapatna in view of Czarny (U.S. Pat. No. 9,749,349) for binary-file and cryptographic-hash matching of application files.
- Ground 3 — Claims 22–27 further obvious over Veselov + Basavapatna in view of Giakouminakis.
- Note: Veselov was the common primary reference across all six Orca-patent IPRs Wiz filed (Wiz states this in its 2024-12-12 letter to the court, D.I. 218).
- Institution decision: Instituted as to all claims (January 2025). The parties' joint notice reports the institution/FWD-deadline pairing for the '926/'326 proceedings as 2025-01-22 with FWD due 2026-01-22; earlier docket notices had projected the '326 institution deadline at 2025-02-07/2025-02-19. The precise institution date should be read off the Board's Decision Granting Institution on PTAB E2E. Post-institution activity — Patent Owner's updated exhibit list (2025-02-13), Petitioner's reply and demonstratives, and a joint oral hearing held 2025-10-14 for IPR2024-01109/-01190/-01191 — confirms institution and a completed trial.
- Final Written Decision: None. No FWD on the merits was ever entered in IPR2024-01191. No claim of US 11,775,326 has been canceled, and no claim has been held patentable. The Dec. 8, 2025 all-claims-unpatentable FWDs reported in the trade press belong to the sibling proceedings IPR2024-00863/-00864/-00865 ('031, '032, '685 patents) — not to the '326 patent.
- Settlement / termination: The Orca–Wiz dispute settled globally in early January 2026. Terms are confidential — the settlement agreement was filed as a confidential exhibit (e.g., Ex. 2429 in IPR2024-01190) with a joint request to keep it separate under 35 U.S.C. § 317(b) / 37 C.F.R. § 42.74(c). The parallel Delaware action, Orca Security Ltd. v. Wiz, Inc., 1:23-cv-00758-JLH-SRF, was dismissed with prejudice and terminated 2026-01-13, each side bearing its own fees.
- Appeal: None and none possible — with no FWD, there is no Board decision to appeal to the Federal Circuit, and no CAFC docket exists for this proceeding.
- Defensive value: An IPR-based defense against this patent starts from scratch. There is no FWD, no cancellation, and no estoppel; Orca can (subject to § 315(b) timing) assert claims 1–28 against new targets. The upside for a defendant is that the entire Wiz petition record is public — Veselov/Basavapatna/Czarny/Giakouminakis, the institution decision, the patent owner response, and the briefing — giving you a fully briefed, expert-supported invalidity roadmap at zero research cost.
Strategic summary
Claim status. Every claim of US 11,775,326 — claims 1–28 — is UNTESTED. Not canceled (0), not sustained on the merits (0), not disclaimed. The single IPR that challenged all of them was instituted, tried through an October 2025 oral hearing, and terminated by settlement in January 2026 before the Board could rule. Anything you read suggesting "claims 1–28 were held unpatentable" is confusing the '326 patent with its siblings: on 2025-12-08 the Board issued FWDs in IPR2024-00863, -00864, and -00865 finding all claims of U.S. Pat. Nos. 11,663,031, 11,663,032, and 11,693,685 unpatentable. Those three patents share a common specification with the '326 patent (all continuations of Application No. 16/585,967), but the FWDs do not bind the '326 claims.
Estoppel landscape. No statutory estoppel exists. Under § 315(e)(2) estoppel attaches only after a final written decision; because IPR2024-01191 terminated pre-FWD, neither Wiz nor its privies are estopped from raising the Veselov/Basavapatna/Czarny/Giakouminakis grounds in any forum — and in any event the Delaware case was dismissed with prejudice, mooting it between those two. For a new defendant, § 315(e)(2) is irrelevant (estoppel runs only against the petitioner and its privies), so no ground is off the table. The practical constraint is § 315(b): if you were served with a complaint alleging infringement of this patent more than one year ago, an IPR petition is time-barred; a PGR is unavailable (the patent issued from an application filed well before the AIA's PGR window considerations and is not PGR-eligible for § 112 grounds), so you are limited to IPR-based §§ 102/103 art or district-court invalidity. The Veselov family — including the prior art and reasoning that prevailed in the sibling FWDs — remains the highest-value attack vector, and the fact that the Board instituted on all claims of the '326 patent shows the Veselov-based theory cleared the § 314(a) threshold once.
Pattern signals. This was not a troll/aggregator scenario: petitioner Wiz, Inc. is a direct commercial competitor of patent owner Orca Security Ltd., and the IPR was a defensive counter-move inside a larger six-patent, cross-asserted war. Wiz filed six IPRs, one per asserted Orca patent (IPR2024-00863/-00864/-00865/-01109/-01190/-01191). Three ended in all-claims-invalid FWDs (2025-12-08); three (including this one) settled. Orca counter-petitioned against Wiz's own patents (IPR2025-01083, -01086 institution denied 2025-12-15; IPR2025-01084 instituted 2025-12-15). The "Unified Patents" link on the Google Patents page is only the third-party data license (Unified Patents PTAB/Litigation Data) — no defensive aggregator was a party. There has been no patent-owner appeal from anything touching the '326 patent, because there was nothing to appeal. Note for completeness: the sibling FWDs of 2025-12-08 carried notice-of-appeal deadlines of 2026-02-09, but the global dismissal-with-prejudice makes appellate activity there unlikely and, in any event, it would not change the '326 patent's status.
Recommended next steps
- Stop treating this patent as PTAB-weakened. No claim has been canceled. Any "the PTAB killed Orca's patents so you're safe" defense built on the December 2025 headlines is wrong as to the '326 patent and would be embarrassing if Orca produces the -01191 institution decision showing all 28 claims were taken to trial.
- Mine the IPR2024-01191 public record. Pull Paper 2 (Petition, filed 2024-08-07) and the Decision Granting Institution from PTAB E2E (https://ptacts.uspto.gov/ptabweb) or the Unified Patents page linked from the patent (https://portal.unifiedpatents.com/ptab/case/IPR2024-01191). You inherit a Board-vetted § 103 mapping against claims 1–28 with expert declarations — the cheapest invalidity work product you will ever get.
- Lean on the sibling FWDs as persuasive authority. The 2025-12-08 FWDs in IPR2024-00863/-00864/-00865 found all claims of the '031, '032, and '685 patents unpatentable over the same primary reference (Veselov). Because those patents share a common specification with the '326 patent, those opinions are strong confirmatory evidence that the shared claims survive only by claim-drafting differences — but they are not estoppel or binding precedent, so you must still map Veselov to the '326 claim limitations, especially the risk-determination/prioritization features of claims 21–28 that drove Grounds 1 and 3.
- Check your § 315(b) clock immediately. IPR is your most efficient invalidity forum, but it is barred one year after service of a complaint alleging infringement. If you are inside that window, file before it closes; if you are outside it, plan on district-court §§ 102/103 invalidity using the Veselov family and the IPR record as your evidentiary core.
- No active PTAB milestones to track. There is no pending IPR, no FWD due date, and no oral hearing on the horizon for this patent. The only live dates in the family relate to the '809 ('926) proceedings, which also settled, and the Orca-initiated IPRs against Wiz patents — none of which affect US 11,775,326.
Primary authorities/links:
- Patent page (litigation entry: "PTAB case IPR2024-01191 filed (Settlement)"): https://patents.google.com/patent/US11775326/en
- Orca v. Wiz, D. Del. 1:23-cv-00758 — Joint Notice of IPR FWDs (status table for -01109/-01190/-01191): https://archive.org/download/gov.uscourts.ded.83027/gov.uscourts.ded.83027.235.0.pdf
- Joint Motion to Terminate IPR2024-01190 (confidential settlement, ex. 2429), filed 2026-01-07: https://www.docketalarm.com/cases/PTAB/IPR2024-01190/Wiz_Inc._v._Orca_Security_Ltd/
- D. Del. docket (dismissal with prejudice, 2026-01-13): https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/
Caveat: the proceeding number, petitioner, patent, filing date, challenged claims (1–28), institution, hearing, and settlement are corroborated by the patent page, PTAB docket data, and district-court filings. The ground-by-ground art mapping above is drawn from a secondary summary of Petition Paper 2; the exact institution date and APJ panel were not confirmed in the sources retrieved and should be read directly off PTAB E2E before being relied on in a filing.
Generated 9/29/2026, 10:22:11 AM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
2019-09-26 · recorded 2023-03-27 · Assignment
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record and related ownership data for this patent before assembling the analysis.
Ownership & Assignment Reconstruction — US 11,775,326 B2
Scope note / methodology. I reconstructed this from the authoritative patent text (Google Patents legal events for US11775326B2), USPTO/PTAB file-history documents (ADS, powers of attorney, terminal disclaimers), and litigation/PTAB dockets. I was not able to retrieve the specific reel/frame number for the recorded assignment through the sources available to me; where a reel/frame is unknown I say so rather than guess. All dates below trace to a cited record.
Inventors
| Inventor | Residence | Employer at filing | Notes |
|---|---|---|---|
| Avi Shua (sole inventor) | Tel Aviv, Israel | Orca Security Ltd. — co-founder & CEO | Inventor's mailing address of record is "c/o Orca Security LTD., 65 Yigal Alon St., Tel Aviv 6744316" (ADS / assignment instrument, executed 2019-09-26). He signed the ADS applicant block as CEO of Orca. |
- This is a single-inventor portfolio. There is no plurality of inventors to test for coordinated departure.
- No unusual-departure pattern. Avi Shua did not leave; he was still CEO and still giving fact/deposition testimony on the family in 2025 (Wiz v. Orca, IPR2024-01190, Notice of Deposition of Avi Shua, 2025-07-11). This is the profile of a founder-inventor whose company is asserting its own patents — the opposite of the "inventors gone, portfolio fire-sale" precursor.
Original assignee
- Entity named on the face of the patent: Orca Security Ltd., Tel Aviv, Israel (Assignee field + ADS applicant "Orca Security LTD."). Application 18/055,181 filed 2022-11-14; granted 2023-10-03.
- Business: Orca Security is an operating cloud-security vendor. It ships the Orca Cloud Security Platform, built on its branded, agentless "SideScanning™" technology. The claims here (take/locate a snapshot of a VM's virtual disk via cloud-provider API, analyze the snapshot for vulnerabilities, and alert by priority) are precisely the SideScanning mechanism, and Orca's own PTAB filings describe the
'031/'926family as "patent-practicing SideScanning." - Product embodying the claims: Yes — Orca marketed and sold the SideScanning platform commercially, and its own litigation filings argue Wiz copied it (Wiz counterclaim, D. Del. 1:23-cv-00758, Dkt. 70, at ¶¶22–29).
- Current status: Operating, private, independent. Founded 2019; ~$630M+ raised; Israeli HQ with US presence. Not acquired, not dissolved, not in bankruptcy. It is actively litigating and filing IPRs in its own name as of 2025–2026.
- Assignee string on the record is stable across the whole family (13 US family members) — always "Orca Security LTD." No holding company, no IP-holding subsidiary, no channel through which the portfolio was pushed to a third party.
Assignment timeline
The Assignment Center / Google Patents legal-events record for this patent shows one recorded assignment — the inventor's original conveyance to the operating company. The chain of title was not broken up, securitized, or transferred to any third party.
2019-09-26 (executed) / recorded 2023-03-27 — Reel/frame not retrievable from available sources (Assignment Center indexed event only)
- Conveyance: Assignment (Assignment of Assignors' Interest)
- Assignor: Avi Shua (inventor)
- Assignee: Orca Security Ltd., 65 Yigal Alon St., Tel Aviv 6744316, Israel
- Correspondent: Not confirmed at the reel/frame level. The prosecution/recordation firms appearing on the family are M&B IP Analysts, LLC (2019 power of attorney: "I hereby appoint all attorneys and agents of M&B IP Analysts, LLC…") and Finnegan, Henderson, Farabow, Garrett & Dunner, LLP (901 New York Ave NW, Washington DC; USPTO Customer No. 22852; listed as attorney/agent on the granted family members). Neither recurs across multiple distinct assignees here — the chain has only one assignee — so this is not a repeat-correspondent tell. Not flagged.
- Context: Original founder/inventor-to-company conveyance (in-house employment/obligation-to-assign assignment). Execution 2019-09-26 precedes the parent nonprovisional filing (16/585,967, 2019-09-27).
Note on dates: the instrument was executed 2019-09-26 but the legal-events record shows the recording event 2023-03-27, contemporaneous with the 2022-11-14 continuation filings (the 18/055,xxx wave). This is a late recordation of an obligation-to-assign instrument for the continuation, not a new transaction.
No post-issuance assignments exist beyond this one. There is no transfer to an IP-holding LLC, no security agreement, no merger, no change of name, no license recordation, and no transfer to any asserter or defensive aggregator. Orca Security Ltd. remains the sole owner.
Timeline diagram
timeline
title Ownership of US 11775326
2019 : Provisional filed by Avi Shua
: Nonprovisional filed by Orca Security
: Shua assigns rights to Orca
2022 : Continuation application filed Nov 14
2023 : Inventor assignment recorded Mar 27
: Patent granted to Orca Security
: Orca sues Wiz for infringement
- Underlying chain (one transaction): Avi Shua → Orca Security Ltd. (assignor-interest assignment; executed 2019, recorded 2023).
- No further links. Chain terminates at the operating company.
NPE / troll-pattern signals
1. Shell-entity transfer — NOT PRESENT. The only assignee is Orca Security Ltd., an operating vendor that ships the patented SideScanning platform. No "IP / Holdings / Ventures" successor, no single-member Delaware/Texas LLC, no registered-agent address appears anywhere in the chain. The recordation addresses are operational (65 Yigal Alon St., Tel Aviv; and, for the US filings, Finnegan's Washington DC office).
2. Known asserter in the chain — NOT PRESENT. No assignee or ancestor assignee matches Acacia, Marathon, IV, IPNav, Wi-LAN, Conversant/Mosaid, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, or any Unified Patents / RPX high-frequency-plaintiff list. The plaintiff asserting this patent (Orca) is a commercial competitor of the defendant (Wiz), not a monetization vehicle.
3. Repeat correspondent across the chain — NOT PRESENT (no chain to recur across). Only one assignment exists, so recurrence cannot be established. The firms of record (M&B IP Analysts, LLC; Finnegan Henderson) are general-practice IP firms serving operating companies; no correspondent on this patent appears on an NPE assertion list in the sources reviewed. One appearance is not a finding.
4. Cascading transfers — NOT PRESENT. One assignment, over a ~3.5-year gap, into the company that filed and prosecuted the application. No chained LLC hops, no shared correspondent addresses, no common-principal LLCs.
5. Pre-litigation transfer — NOT PRESENT. The conveyance predates the first infringement suit (Orca Security Ltd. v. Wiz, Inc., 1:23-cv-00758, D. Del., filed 2023-07-12) by years, and runs toward the operating company, not to a litigation shell. Orca asserted the patent family in its own name and on its own standing.
6. Bankruptcy fire-sale — NOT PRESENT. No bankruptcy of Orca Security in any record reviewed. The company is funded and operating.
7. Privateering — NOT PRESENT. Orca sued its own direct competitor to enforce its own patents. There is no operating company transferring to an NPE to assert on its behalf; the plaintiff is the operating company. (The reverse allegation — Wiz counterclaiming that Orca copied Wiz's technology — is a commercial/competitive dispute, not privateering.)
8. Defensive aggregator — NOT PRESENT. Chain does not terminate at RPX, AST, LOT, Unified Patents, or OIN. Orca remains the active owner/asserter.
Corroborating litigation context (not an NPE signal): Orca's suit against Wiz was dismissed with prejudice by stipulation, D. Del. 1:23-cv-00758, entered 2026-01-13, following adverse PTAB outcomes on several family members and a post-institution settlement wave (e.g., IPR2025-01084 / -01087 "Terminated-Settled," 2026-01-14). Orca also petitioned for IPR against Wiz's patents (e.g., IPR2025-01083). This is a two-way operating-company patent war — consistent with a genuine vendor portfolio, not a troll campaign.
Verdict
Operating-company assertion.
The chain of title is a single inventor-to-company assignment (Avi Shua → Orca Security Ltd.; executed 2019-09-26, recorded 2023-03-27, reel/frame not retrievable from the sources available to me) into the operating vendor that filed, prosecuted, and owns the patent. Orca Security ships a commercial product embodying the claims (SideScanning) and asserted US 11,775,326 in its own name against a direct competitor (Wiz) in Orca Security Ltd. v. Wiz, Inc., 1:23-cv-00758 (D. Del., filed 2023-07-12) — satisfying the "operating company suing actual competitors" test — with zero shell-entity, asserter-list, cascading-transfer, or defensive-aggregator signals present.
Verification links:
- USPTO Patent Assignment Search (search by patent number 11775326): https://assignmentcenter.uspto.gov/ and https://assignment.uspto.gov/patent/index.html
- Google Patents legal events / family: https://patents.google.com/patent/US11775326/en
- Litigation docket (D. Del. 1:23-cv-00758): https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/
Confidence caveat: The verdict rests on the recorded-assignment event set (one inventor→Orca assignment) plus the assignee-of-record on the granted patent and the litigation/PTAB record. I could not pull the exact reel/frame from the Assignment Center directly; if you need the reel/frame and the named recording correspondent verbatim, that requires a live Assignment Center query (patent number 11775326), which would also confirm whether any additional instrument exists outside the Google Patents legal-events feed.
Generated 9/29/2026, 10:21:54 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll search for the citation records for US 11,775,326 to identify the prior art references.
Let me pull the full citation list and details for the key references.
Let me retrieve the face-of-patent citation list and key reference details.
Prior-Art Analysis — US 11,775,326 B2
⚠️ Method & confidence note (read first)
I could not open a live USPTO Patent Center / Patent Public Search (PatFT) session with the tools available; my searches returned the same content through the Google Patents record, the Justia record, the Unified Patents record, and — most usefully — USPTO PTAB documents (which quote the allowed-application file histories verbatim). I therefore built the citation list from the face-of-patent "References Cited" data as mirrored by Google Patents/Justia/Unified Patents, and I have marked every field I could not independently verify.
Two structural facts govern everything below:
- The citations on the face of the '326 are almost entirely inherited from the parent chain ('967 → '735 → '231 → '326). They are the references the family cited/overcame. None of them individually defeated claim 1 as issued.
- The prior art that actually matters now is not the face-of-patent list. It is the set Wiz, Inc. assembled in IPR2024-01191 (Veselov, Basavapatna, Czarny, Giakouminakis) plus the near-identical sibling challenges (Price, Hufsmith). Those are the true §102/§103 candidates, and I treat them separately in §3.
A count discrepancy to flag: Unified Patents reports "Patent Art (45)" and "Non-Patent Literature (9)" for the '326, while the Google/Justia citation table I could retrieve exposes only ~30 patent entries. I could not reconcile the 45 vs. 30 gap with the tools available — treat the list below as complete-for-the-30-I-verified, not as the full 45.
1. Two references in the list are NOT prior art (correction)
| Ref | Why it is not §102/§103 art |
|---|---|
| US 11,431,735 B2 (Shua; Orca) | This is the grandparent of the '326 (filed 2019-09-27 from the same 62/797,718 provisional). Same inventor, same disclosure — it is the priority chain, not art. |
| US 11,516,231 B2 (Shua; Orca) | This is the parent of the '326 (app. 17/330,998, filed 2021-05-26). Same inventor/disclosure — not art against the '326. |
If any third party (or a later analyst) treats these two as §102 art against the '326, that is an error I am flagging explicitly rather than propagating.
2. Face-of-patent patent citations (the "References Cited")
Dates below: for pre-grant publications the publication date; for granted patents the issue date. Filing/priority dates are given only where I verified them (marked ✓) — elsewhere I have written (filing date not verified). "§102(a)(1)?" asks whether the reference was publicly available before the 2019-01-28 priority date; references that fail that test can still be §102(a)(2) art if they are US patents/applications effectively filed before 2019-01-28.
2a. References published BEFORE the 2019-01-28 priority date (eligible as §102(a)(1) art)
| # | Full citation | Pub. date (filing/prio.) | Brief description (source) | Claims it could bear on under §102 |
|---|---|---|---|---|
| 1 | US 2007/0266433 A1 — Moore, Hezi. "System and Method for Securing Information in a Virtual Computing Environment" | pub. 2007-11-15 (prio. 2006-03-03 ✓, from patent's own table) | Per the '326's own citation table. Securing information in a virtualized environment. | Background only; nothing in claim 1. Not an anticipation candidate. |
| 2 | US 2008/0189788 A1 — Bahl (assignee appears to be [Microsoft Corp.](/litigations/by-plaintiff/Microsoft%20Corp.); name truncated in the patent's table) | pub. 2008-08-07 (prio. 2007-02-06 ✓) | Per the '326's own citation table. (Subject matter not verified — title truncated in source.) | Unverified; flag as background. |
| 3 | US 2008/0263658 A1 — Michael et al. | pub. 2008-10-23 | Cited in family prosecution in a §103 combination (Sancheti + Derbeko + Michael) — see PTAB/court record. | Used as a secondary §103 reference; no standalone §102. |
| 4 | US 2009/0007100 A1 — Field et al. | pub. 2009-01-01 | Not verified. | Unverified. |
| 5 | US 2010/0017512 A1 — Ciano et al. | pub. 2010-01-21 | Not verified. | Unverified. |
| 6 | US 2011/0289584 A1 — Palagummi | pub. 2011-11-24 | Not verified. | Unverified. |
| 7 | US 2012/0323853 A1 — Fries et al. | pub. 2012-12-20 | Not verified. | Unverified. |
| 8 | US 2013/0191643 A1 — Song et al. | pub. 2013-07-25 | Not verified. (Distinct from Basavapatna 2013/0191919 — do not conflate.) | Unverified. |
| 9 | US 2014/0096135 A1 — Kundu et al. | pub. 2014-04-03 | Not verified. | Unverified. |
| 10 | US 2014/0137190 A1 — Carey et al. | pub. 2014-05-15 | Not verified. | Unverified. |
| 11 | US 2015/0052520 A1 — Crowell et al. | pub. 2015-02-19 | Not verified. | Unverified. |
| 12 | US 2016/0004449 A1 — Lakshman et al. | pub. 2016-01-07 | Not verified. | Unverified. |
| 13 | US 2016/0094568 A1 — Balasubramanian et al. | pub. 2016-03-31 | Not verified. | Unverified. |
| 14 | US 2016/0364255 A1 — Chefalas et al. | pub. 2016-12-15 | Not verified. | Unverified. |
| 15 | US 2017/0011138 A1 — Venkatesh et al. | pub. 2017-01-12 | Not verified. | Unverified. |
| 16 | US 2017/0031704 A1 — Sudhakaran et al. | pub. 2017-02-02 | Not verified. | Unverified. |
| 17 | US 2017/0103212 A1 — Deng et al. | pub. 2017-04-13 | Appears in the family prosecution as a secondary §103 reference (Golan + Derbeko + Deng) per PTAB filings. | §103 only. |
| 18 | US 2017/0111384 A1 — Loureiro et al. | pub. 2017-04-20 | Not verified. | Unverified. |
| 19 | US 2018/0137032 A1 — Tannous et al. | pub. 2018-05-17 | Not verified. | Unverified. |
| 20 | US 2018/0255080 A1 — Paine | pub. 2018-09-06 | Not verified. | Unverified. |
| 21 | US 2018/0293374 A1 — Chen | pub. 2018-10-11 | Not verified. | Unverified. |
2b. Granted patents / publications that post-date 2019-01-28 → §102(a)(2) only
| # | Full citation | Issue date (filing) | Brief description | Claims / status |
|---|---|---|---|---|
| 22 | US 10,536,471 B1 — Derbeko et al. (EMC IP Holding Co.) "Malware detection in virtual machines" | 2020-01-14 (filed 2016-03-31 ✓ per app. 15/086,979) | Verified from USPTO record: "periodically creating snapshots of the VM, analyzing each of the snapshots in comparison to one or more previous snapshots to determine whether anomalies exist, and based on a threshold amount of anomalies detected, scanning the VM." | The strongest single face-of-patent reference. §102(a)(2) art. Maps to claims 2, 9 (snapshot creation/analysis of a VM image). Does not disclose the cloud-API/service "location of snapshot" step or the asset-level risk-level prioritization → not a claim-1 anticipation. |
| 23 | US 10,782,952 B1 — Doring et al. | 2020-09-22 | Not verified. | §102(a)(2) only. |
| 24 | US 10,944,778 B1 — Golan et al. | 2021-03-09 | Risk-based cyber-security management (per PTAB quote: "a method and system for implementing risk-based cyber security"). | §102(a)(2). Bears on claims 3, 21–28 (risk scoring). |
| 25 | US 11,068,353 B1 — Ved | 2021-07-20 | Not verified. | §102(a)(2) only. |
| 26 | US 11,120,124 B1 — Fusenig et al. | 2021-09-14 | Not verified. | §102(a)(2) only. |
| 27 | US 11,216,563 B1 — Veselov et al. (Amazon Technologies, Inc.) "Security assessment of virtual computing environment using logical volume image" | 2022-01-04 (filed 2017-05-19 ✓) | The single most important reference. Security-assessment service that obtains a snapshot of a target VM's logical volume ("virtual disk"), then either instantiates a duplicate assessment VM or mounts the volume image read-only and scans it (CVE/CIS rule packages, config assessment); communicates with the target environment via APIs; can schedule periodic snapshots. | §102(a)(2) art (filed 2017 < 2019-01-28). Maps strongly to claim 2 (take/request snapshot), claims 4–5, 16–17 (match installed apps / CVE lists), claims 9–10 (parse+scan), claims 13–14 (logical volume / locate disk). See §3. |
| 28 | US 2020/0042707 A1 — Kucherov et al. | pub. 2020-02-06 | Not verified. | §102(a)(2) only (filed before priority; published after). |
| 29 | US 11,431,735 B2 — Shua (Orca) | 2022-08-30 | NOT prior art (grandparent). | Excluded — see §1. |
| 30 | US 11,516,231 B2 — Shua (Orca) | 2022-11-29 | NOT prior art (parent). | Excluded — see §1. |
Non-patent literature (9 items per Unified Patents): at least one is "IBM Point of View: Security and Cloud Computing," IBM SmartCloud Enterprise White Paper (2009) (verified via Justia); the remainder are the family's own prosecution papers (Advisory Actions, etc.) and are not prior art. I could not enumerate all nine.
3. The references that actually threaten the '326 (IPR2024-01191)
These are not on the face of the patent (except Veselov, which is). This is where genuine §102/§103 risk concentrates:
| Reference | Citation / date | Description | §102 / §103 role |
|---|---|---|---|
| Veselov | US 11,216,563 B1, Amazon, filed 2017-05-19, issued 2022-01-04 | Snapshot-based agentless security assessment of a VM's logical volume. | Primary reference. §102(a)(2) art on its own for the snapshot/API/scan limitations; combined with Basavapatna for claims 1–21, 28. |
| Basavapatna | US 2013/0191919 A1 (per IPR ground) | Supplies the vulnerability risk-metric and asset-level aggregation/prioritization teaching (per the petition record and my earlier summary). | §103 partner for claim 1 step (3) "risk level to the cloud computing environment" + claims 21–28. Full title/assignee not independently verified today. |
| Czarny | US 9,749,349 (per IPR ground) | CVE-database matching for vulnerability identification (per PTAB quote, Czarny 4:25–33, 6:25–38). | §103 for claims 4–5, 17. |
| Giakouminakis | Publication/patent (exact number not verified; PTAB cites 4:22–35, 13:59–14:07) | Vulnerability database storing "known vulnerabilities for various types of known software resources and hardware resources," VMs inspected for installed software/version/config and compared to the DB. | §103 for claims 22–27. |
| Price | US 2013/0247133 A1 (per sibling IPR2024-00863) | Security assessment of offline VM images. | Supplies the "at rest / inactive" element used against sibling patents, not against the '326's claims (the '326 does not recite "inactive"). |
| Hufsmith | US 2020/0097662 A1 (per sibling IPR) | Assigns weights/priorities to detected risks (malware/CVEs) and sends prioritized alerts. | §103 for the '326's claims 3, 28 (prioritized reporting). |
4. §102 anticipation analysis (my assessment, claim-by-claim)
Bottom line: no reference on the face of US 11,775,326, taken alone, appears to anticipate independent claims 1, 15, or 18. Independent claim 1 requires a specific combination — (i) a request to scan a plurality of assets, (ii) a cloud-provider API or service used both to locate and to access each snapshot, (iii) snapshot analysis for vulnerabilities, (iv) a per-vulnerability risk, (v) a per-asset risk level to the cloud environment, and (vi) population-level prioritization of those assets. Every face-of-patent reference I could characterize supplies at most two or three of these, and most were already overcome to obtain the '326.
Reference-by-reference, the realistic ceilings:
- Veselov (US 11,216,563) — closest to §102 for the snapshot-mechanics dependent claims: claims 2, 4, 5, 9, 10, 13, 14, 16, 17. It discloses API-mediated snapshot obtainment, logical-volume/virtual-disk locating, application/CVE matching, and parse-then-scan. It does not clearly disclose the per-asset "risk level to the cloud computing environment" of claim 1(3) or the plurality-prioritization of claim 1(4) — hence the petition pairs it with Basavapatna rather than asserting sole anticipation.
- Derbeko (US 10,536,471) — §102 candidate only for claims 2 and 9 (snapshot creation + comparative snapshot analysis); malware/anomaly focus, not risk-scored vulnerability prioritization. Not a claim-1 anticipation.
- Basavapatna (US 2013/0191919) — §103 (§102 is unlikely) against claims 1(3), 3, 6–8, 20, 21–28: it is the source of the risk-metric + aggregation/prioritization logic.
- Golan (US 10,944,778) — §103 material for claims 3, 21–28 (risk-based security).
- Czarny (US 9,749,349) and Giakouminakis — §103 only, narrowly for claims 4–5, 17 and 22–27 respectively.
- Hufsmith (US 2020/0097662) — §103 only, for claims 3, 28 (prioritized reporting).
- The remaining ~25 face-of-patent references are background/§103 secondary material at best; I could not verify subject matter sufficient to assert §102 anticipation for any of them, and I am not going to assert it.
Practical conclusion for a validity/risk read: the '326's independent claims survived prosecution against the inherited citation list (notably Derbeko and the Derbeko/Sancheti/Michael and Golan/Derbeko/Deng combinations). The live attack surface is Veselov + Basavapatna (+ Czarny / Giakouminakis), which is exactly the IPR2024-01191 ground set — consistent with the earlier summary, which I am building on rather than repeating. Note the Google Patents family-litigation field labels IPR2024-01191 "(Settlement)", and the companion '326-family challenge saw termination activity in early 2026, so the merits (FWD) outcome for these grounds may never have issued — which is consistent with the earlier "unverified CAFC appeal" flag.
5. What I could NOT verify (stated explicitly)
- The complete face-of-patent citation set (Unified Patents says 45 patent art + 9 NPL; I confirmed ~30 + 1 NPL).
- Filing/priority dates for the pre-grant publications numbered 3–21 above (Only the Moore and Bahl entries carried verified dates in the patent's own table).
- Subject matter of: Bahl 2008/0189788, Field 2009/0007100, Ciano 2010/0017512, Palagummi 2011/0289584, Fries 2012/0323853, Song 2013/0191643, Kundu 2014/0096135, Carey 2014/0137190, Crowell 2015/0052520, Lakshman 2016/0004449, Balasubramanian 2016/0094568, Chefalas 2016/0364255, Venkatesh 2017/0011138, Sudhakaran 2017/0031704, Loureiro 2017/0111384, Tannous 2018/0137032, Paine 2018/0255080, Chen 2018/0293374, Doring 10,782,952, Ved 11,068,353, Fusenig 11,120,124, Kucherov 2020/0042707.
- Exact identity of "Giakouminakis" (patent vs. publication, number, date) and the full bibliographic details of Basavapatna US 2013/0191919.
- Whether the '326's own examiner (Hirl) substantively relied on any of these citations or merely listed them via IDS — the record I retrieved shows the allow/overcome activity in the sibling applications, not a clean §102 rejection on the '326 itself.
If you want, I can drill into any single reference (e.g., pull Veselov's full claim 1 language, or Derbeko's column citations) to build an element-by-element §102 chart for a specific independent claim.
Nothing here is a legal conclusion on validity, infringement, or patentability. These are analyst observations grounded in the documents cited above.
Generated 9/29/2026, 10:22:25 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll work from the Prior Art section of this record, supplementing where it's truncated with targeted searches. Let me gather the citation data first.
Good — the petition grounds are confirmed. Let me pull the reference details and the face-of-patent citation list.
Obviousness Analysis — US 11,775,326 B2 under 35 U.S.C. § 103
0. Scope and source caveats (read first)
Two grounding limitations must be stated up front, because they bound how strong this analysis can be:
The "Citations (41)" block on this record is truncated. The text I was given cuts off after two entries —
US20070266433A1(Hezi Moore, "System and Method for Securing Information in a Virtual Computing Environment," pub. 2007-11-15) andUS20080189788A1(Microsoft, pub. 2008-08-07). I cannot see the remaining ~39 references the Examiner cited, so I cannot reconstruct the face-of-patent obviousness record. What follows is therefore not an "Examiner's combination" analysis.The operative prior-art combination for this patent comes from the IPR record, not the patent's own citation list. The Google Patents litigation field lists IPR2024-01191 (Wiz, Inc. v. Orca Security Ltd., filed 2024-08-07, challenging claims 1–28), and the petition record sets out three grounds against Veselov (US 11,216,563), Basavapatna (US 2013/0191919 A1), Czarny (US 9,749,349), and Giakouminakis (US 9,141,805). I have used these as the prior-art set. I retrieved the full text/abstract of Veselov, Basavapatna, and Czarny in this session; I did not independently retrieve the Giakouminakis disclosure (my last search returned no results before the tool limit), so the claim 22–27 mapping below is reported from the petition's characterization, not from my own reading of that reference.
⚠️ Contradiction flag (carried from the prior section): the Google Patents family-litigation field labels IPR2024-01191 as "(Settlement)." That matters legally — if the IPR terminated by settlement, there is no Final Written Decision on the merits for the '326, so none of the grounds below has been adjudicated. Treat the entire analysis as an asserted obviousness theory, not an established invalidity holding. I make no legal conclusion.
Priority date: 2019-01-28 (prov. 62/797,718). Fixed POSITA assumed for this analysis: a person with a bachelor's in CS/EE plus ~3–5 years in cloud security/vulnerability management, familiar with VMs, disk snapshots, cloud provider APIs, CVE/CVSS, and risk scoring.
Prior-art status of the references against the 2019-01-28 priority date:
| Reference | Date basis | AIA category |
|---|---|---|
| Veselov, US 11,216,563 (Amazon) | filed 2017-05-19 | §102(a)(2) (patent naming another inventor) |
| Basavapatna, US 2013/0191919 A1 (McAfee) | pub. 2013-07-25 | §102(a)(1) |
| Czarny, US 9,749,349 (OPSWAT) | filed 2016-09-22; granted 2017-08-29 | §102(a)(1)/(a)(2) |
| Giakouminakis, US 9,141,805 | granted 2015-09-22 (per petition record) | §102(a)(1) |
All four predate the critical date comfortably; none is in danger of being disqualified.
1. The legal frame
Claim 1 is a three-reference-agnostic "system-level" claim: scan a plurality of cloud assets off their disk snapshots, locate the snapshot via a cloud API/service, detect vulnerabilities, score each vulnerability, score each asset relative to the environment, and report so the assets are ranked by risk. Independent claims 15 (CRM) and 18 (system) are the same substance in different statutory dress.
Under KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007), the combination is assessed for (a) whether each element was known, (b) whether the references are analogous, (c) a reasoned motivation to combine, and (d) reasonable expectation of success. As the petition itself framed it: "Arriving at the claims involved using known elements according to their known functions to achieve predictable results."
The '326 claim 1 is materially friendlier to the obviousness theory than its parents, for a specific drafter's reason: the abstract and the '431/'231 parents are framed around "cyber threats," whereas claim 1 of the '326 recites "potential cyber vulnerabilities." That pulls the claim directly into Basavapatna's wheelhouse — Basavapatna is literally a quantitative vulnerability-risk-scoring patent. The narrowing is not cosmetic; it removes the gap a "detect non-vulnerability threats (PII, weak ciphers, ASLR)" argument would otherwise have to close.
2. Primary combination — Ground 1: Veselov + Basavapatna (claims 1–21, 28)
2.1 The references in one line each
- Veselov (US 11,216,563, Amazon): a scanning service that obtains a snapshot of a target VM/logical volume over the cloud provider's infrastructure, then performs a security assessment (CVE packages, CIS benchmarks, host-configuration assessments) on the snapshot or a duplicate instantiated from it, and returns assessment results.
- Basavapatna (US 2013/0191919 A1, McAfee): a quantitative asset-risk engine computing a per-vulnerability vulnerability-centric risk metric (from a standardized/CVSS vulnerability score + a vulnerability detection score + a countermeasure component score), aggregating per-vulnerability metrics into an asset-level aggregate risk metric, and presenting/alerting results sorted or thresholded by aggregate risk.
2.2 Element-by-element mapping of claim 1
| Claim 1 limitation | Veselov | Basavapatna |
|---|---|---|
| Preamble: method for securing virtual cloud assets in a cloud environment | Security assessment of "a target computing resource, such as a virtual machine or an instance of a virtual machine"; Figs. 1/3A–3B in a computing-resource-service-provider environment | Same field (enterprise/cloud vulnerability management) |
| "receiving a request to scan a plurality of protected virtual cloud assets" | Scanning service 110 is invoked on target resources; a user/administrator communicates instructions via API 338 | — |
| "determining, using an API or service provided by the cloud computing environment, a location of a snapshot of at least one virtual disk" | Snapshot data 146 / snapshot storage service 108; scanning service obtains/obtains access to snapshot state ("a state of the resource at a point in time (e.g. a 'snapshot')") | — |
| "accessing, based on the determined location and using an API or service … the snapshot" | "The scanning system obtains, or obtains access to a state of the resource … (snapshot)" over the provider environment | — |
| "analyzing the snapshot … to determine an existence of potential cyber vulnerabilities" | Rule packages "such as Common Vulnerabilities and Exposures (CVEs), CIS benchmarks, 'best practices' packages, static or runtime behavior analysis, host configuration assessments" | Vulnerability detection data → determines whether the asset possesses the vulnerability |
| "determining a risk associated with each of the determined potential cyber vulnerabilities" | — | Vulnerability-centric risk metric per asset-and-vulnerability: standardized (CVSS) score × vulnerability detection score, adjusted by countermeasure score (Abstract; Fig. 3B ¶¶100–113) |
| "for each … asset with vulnerabilities, determining a risk level to the cloud computing environment" | — | Aggregate risk metric for the asset from the per-vulnerability metrics — sum / mean / maximum / minimum / mode (¶¶130–135, Fig. 5), plus a criticality score representing impact of losing the asset |
| "reporting … such that the plurality … are prioritized based on associated risk levels" | Reports assessment results to owner/administrator | Assets/vulnerabilities/threats "sorted by the aggregate risk metric"; "list a top number, e.g., top ten"; alert if aggregate metric rises above a specified threshold (¶¶138–140) |
Assessment: Veselov supplies the entire snapshot-acquisition-and-analysis spine; Basavapatna supplies the entire per-vulnerability-risk → asset-level-aggregate → prioritized-reporting tail. Read together, the only unaddressed limitation is the express "using an API or service provided by the cloud computing environment" qualifier on steps 2(a) and 2(b) — discussed in §5 below as the pivotal dispute.
2.3 Motivation to combine (the §103 heart)
The petition's articulated rationales, which are legally cognizable:
- Same field, same problem, complementary functions (KSR; In re Keller). Both references address vulnerability/risk management of computing assets. Veselov outputs an unranked assessment result set; Basavapatna's entire purpose is to rank vulnerability data so administrators can act. Combining a known generator of vulnerability findings with a known prioritizer of vulnerability findings is "the familiar, predictable arrangement of old elements, each performing the function it was known to perform."
- Articulated improvement. Basavapatna supplies "contextualizing their severity, allowing administrators to predictably focus remediation efforts on the highest-priority threats." That is a concrete, non-hindsight engineering benefit: Veselov's scanner, applied to a plurality of assets, would otherwise return an undifferentiated list.
- Design incentive recognized in the art. Alert fatigue / prioritization was itself a recognized problem; Basavapatna expressly teaches filtering by threshold and a "top ten" list "by aggregate risk metric."
- No bodily incorporation / no change of operating principle. Basavapatna's risk engine consumes inputs Veselov already generates (vulnerability identifications + asset configuration data). Neither reference must be modified in a way that defeats its purpose for the combination to work. Veselov's snapshot analysis is untouched; only the output stage is extended. This is the classic "add-on that doesn't disturb the host" posture.
Reasonable expectation of success: both techniques were mature by 2017–2019 (CVSS-based scoring dates to 2005+; Basavapatna itself dates to 2012). The combination "would not have presented meaningful technical challenges or produced unexpected results."
2.4 Dependent claims covered by Veselov + Basavapatna
| Claim(s) | Mapping |
|---|---|
| 2, 19 (take/request snapshot) | Veselov's snapshots are captured ("a snapshot … is captured and used to implement the duplicate"); the service also obtains/accesses them |
| 3 (risk from external intelligence on likelihood of exploitation; filtering by risk) | Basavapatna's threat information service 210 / threat feed, applicability score, and threshold filtering |
| 6, 7, 20 (in use / not in use relevance; not-in-use lowers risk) | Basavapatna's applicability data vs. asset configuration data — whether the vulnerability actually applies; Veselov's configuration assessment |
| 8 (checking config files to find not-in-use apps; reduce priority) | Basavapatna asset configuration data (software configuration); Veselov host-configuration assessments |
| 9, 10 (parse snapshot; scan parsed snapshot; check config files / file access times / system logs) | Veselov expressly scans a parsed copy and searches for "files that identify the software application, version, installation attributes," then decides "which assessment tasks to run based on the installed software packages"; Basavapatna supplies configuration-file checking |
| 11, 12 (mitigation: block untrusted traffic / halt / quarantine) | Veselov's remediation ("performing remediation if vulnerabilities are identified in the assessment results") |
| 13, 14 (determine the specific virtual disk; query a cloud management console for snapshot and virtual-disk location) | ⚠️ Weakest mapping. Veselov's Fig. 1 snapshot-storage-service embodiment is the closest, but Orca's POPR argues Veselov's "API calls" only specify requestor/user identity and do not teach cloud APIs to locate a virtual disk. See §5. |
| 21 (asset risk level based in part on per-vulnerability risks) | Basavapatna ¶¶130–135 aggregate-from-components — near-verbatim |
| 28 (prioritize reported vulns by asset risk level) | Basavapatna's "sorted by the aggregate risk metric for the asset" |
3. Ground 2: + Czarny (claims 4–5, 17)
Claim 4 requires either (a) matching installed applications against a known list of vulnerable applications, or (b) matching application files directly against application files of a known vulnerable list. Claim 5 requires computing a cryptographic hash and matching against a database of files.
Czarny (US 9,749,349, OPSWAT): "computer security vulnerability assessment" using product binary data matched against product vulnerability data; expressly discloses that the binary data may be "hashes of strings of bits, bytes, words or characters extracted from the files of the software products," and that the comparison is done at the binary level "rather than matching a file name or other higher level meta data." Czarny even scans a powered-off target device mounted as external storage — i.e., it is agnostic to whether the target is running.
Motivation: Czarny itself explains the why — name/version matching "is less thorough, robust or flexible … because it could potentially miss some known vulnerabilities, since the actual binary level data in the files of the software product could be different from the official version" (corrupted or malware-modified files). That is a reference-internal, articulated reason for a POSITA to prefer binary/hash matching, which makes this combination materially stronger than most. Czarny is analogous art (same field: vulnerability assessment of software assets). Expectation of success: hash comparison is a deterministic, predictable operation.
Assessment: Ground 2 is the cleanest of the three grounds — it maps a narrow dependent claim to an express disclosure with an in-reference motivation, and it does not disturb either Veselov or Basavapatna.
4. Ground 3: + Giakouminakis (claims 22–27)
Claims 22–27 concern weighting "takeover risk" by (i) correlating a vulnerability with a network location (cl. 23), (ii) criticality from contents stored (cl. 24), and (iii) criticality from other assets reachable from the asset (cl. 25), and combinations (cl. 26–27).
Per the petition record, Giakouminakis (US 9,141,805) is cited as supplying vulnerability-database and asset-criticality/risk-weighting teachings (the petition excerpt in my search results quotes Giakouminakis at 4:22–35 for a "vulnerability database … store a record of known vulnerabilities for various types of known software resources and hardware resources … to identify vulnerabilities in the … VMs," and 13:59–14:7 for examining VMs to "identify the software resources … version of the software installed, configuration of the software installed" and comparing to the vulnerability database).
Critical caveat — this is where the theory is thinnest. As noted in §0, I did not independently retrieve Giakouminakis, and my search excerpt does not show me text on network-location correlation or reachable-asset criticality, which are the actual novelty-bearing aspects of claims 23–26. The petition's own framing — "Integrating these factors to refine the risk scoring of the Veselov/Basavapatna system would be a predictable enhancement" — is close to a bare "refine the score" assertion, which is the kind of rationale that invites an "impermissible hindsight / no articulated motivation" attack. Note also that cl. 24 and 25's criticality concepts are already substantially present in Basavapatna itself (the "criticality score for the particular asset, representing an impact of losing the asset"), so a POSITA arguably gets most of claims 22, 24, and 27 from Veselov + Basavapatna without Giakouminakis. The Giakouminakis addition is most needed for cl. 23 (network-location correlation) and cl. 25 (reachable-asset criticality), and I cannot verify its disclosure on those points.
5. Where the obviousness case is actually contested
An examiner-style counter-analysis must acknowledge that the strongest infringement-facing limitation is also the strongest validity-facing limitation: claim 1's requirement that the snapshot location be determined "using an API or service provided by the cloud computing environment."
Orca's POPR position (from the IPR2024-00863/2024-01191 record) is:
- Veselov's "APIs" appear only in the Fig. 1 and Figs. 3A/3B embodiments, and those calls specify "the requestor, the user associated with" a request — not cloud-platform APIs used to identify, query, or receive the location of a specific virtual disk. Orca asserts Veselov's disclosures "do not disclose using cloud computing platform APIs to identify, query, or receive virtual disk location."
- Orca separately argues that "analysis of a VM instantiated from a snapshot is not an analysis of a snapshot" — attacking the petition's broad reading of "analyzing the snapshot."
- Orca invokes objective indicia (Mr. Shua's public statements that using cloud APIs to locate specific virtual disks before snapshot analysis "was critical to SideScanning™ performance and Orca's commercial success").
My assessment of that dispute: the "API" element is a genuine §103 pressure point. Whether it is disclosed or obvious turns on (a) the claim construction of "using an API or service provided by the cloud computing environment," and (b) whether a POSITA would find it obvious given that Veselov's scanning service is itself a cloud-provider service (Amazon) operating inside the provider environment and accessing snapshot data over provider interfaces. If the construction requires only that the cloud provider's own interface be used — which Veselov's Amazon-context disclosure plausibly supports — the limitation is met; if it requires affirmatively querying a management console for a virtual-disk address, Veselov's express disclosure is thinner and the case leans harder on "obvious to try"/common-knowledge arguments, which are more vulnerable to a hindsight challenge.
The secondary considerations point cuts against obviousness if substantiated; but note that the objective-indicia record belongs to the family/litigation, and the Google Patents field indicates the '326 IPR resolved by settlement, so none of the above was ever adjudicated. The 2025-12-08 PTAB decisions against sibling patents 11,663,031 / 11,663,032 / 11,693,685 (with a 2026-02-09 CAFC notice-of-appeal deadline) are the family members where a merits ruling actually exists — I did not verify whether Orca appealed, and I cannot transfer any sibling outcome to the '326.
6. Bottom line
| Ground | Claims | Strength | Comment |
|---|---|---|---|
| Veselov + Basavapatna | 1–3, 6–16, 18–21, 28 | Moderate-to-strong | Two analogous, complementary references; near-element-level mapping of the risk/aggregation/prioritization tail; fails only on the express "cloud API/service" qualifier for the snapshot/virtual-disk location, which is the contested construction |
| + Czarny | 4–5, 17 | Strong | Czarny supplies express binary/hash-matching and an in-reference motivation (name/version matching is less robust) |
| + Giakouminakis | 22–27 | Weak-to-moderate, unverified | Petition relies on "predictable enhancement" framing for takeover-risk weighting; I could not confirm the network-location and reachable-asset teachings; much of cl. 22/24/27 is arguably already in Basavapatna's criticality score |
A POSITA would have been motivated to combine Veselov with Basavapatna to convert an unranked snapshot-based vulnerability report into a risk-ranked, filtered, remediation-focused output — the classic KSR "known elements, known functions, predictable results" case, and the classic "same field, same problem, complementary teachings" case. A POSITA would further have been motivated to add Czarny for hash/binary matching (strong, reference-internal reason) and Giakouminakis to enrich asset-risk inputs (weaker, and I cannot verify the key teachings).
Two honest reservations to carry forward: (1) if the "using an API or service provided by the cloud computing environment" limitation is construed to require querying a management console for a specific virtual disk address, Veselov's express disclosure may be insufficient and the ground degrades to a common-knowledge/"obvious to try" theory that is more exposed to a hindsight attack; and (2) no merits decision exists on the '326 — the record says the IPR settled — so this analysis is a prediction of how the grounds would be assessed, not a report of how they were.
Cross-reference note
This analysis is consistent with, and builds on, the previous section's framing that the '326's differentiation within the family is (a) the plurality of assets, (b) an explicit environment-level risk level feeding asset prioritization, and (c) the express cloud-provider API/service requirement for locating and accessing the snapshot — and that the Wiz grounds concentrated precisely on (b) via Basavapatna. The one nuance I would add to that prior framing: claim 1's shift from the family's "cyber threats" language to "cyber vulnerabilities" makes the Basavapatna mapping tighter than the parent claims would be, which is a drafting choice that works for the obviousness theory.
Generated 9/29/2026, 10:22:18 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Orca Security Ltd.
- US 12001549US patent 12001549, titled "Cybersecurity incident response techniques utilizing artificial intelligence," was assigned to Wiz Inc. The inventors are Alon SCHINDEL, Barak Sharoni, Amitai Cohen, Ami Luttwak, Roy Reznik, and Yinon COSTICA…
- US 11722554US Patent 11722554, titled "System and method for analyzing network objects in a cloud environment," was granted to Wiz Inc. The inventors are Shai Keren, Danny Shemesh, Roy Reznik, Ami Luttwak, and Avihai Berkovitz. The patent was filed…
- US 11663031I'll search for authoritative information on this specific patent number, including any 2026 litigation activity. Let me check for the PTAB final written decision and any Federal Circuit 2026 appeal activity. Let me check specifically for…
- US 11663032
- US 11693685I'll search for authoritative information on this specific patent number and any litigation involving it. Let me search for the specific IPR outcome and any Federal Circuit appeal involving this patent. US Patent 11,693,685 B2 — Patent…
- US 11726809I'll search for authoritative information on US patent 11726809. Let me check for Federal Circuit (CAFC) activity and the PTAB proceeding. Let me verify the post-settlement and any Federal Circuit activity. Summary: US Patent No…
- US 11740926I'll verify this patent against live sources before summarizing. Let me check litigation/PTAB/CAFC status specifically. Let me check for the January 2026 IPR final decision on this patent and any Federal Circuit appeal. US Patent…
- US 11431735I'll search for current information on this patent, including any litigation or CAFC 2026 docket activity. Let me search for the specific PTAB proceeding and any related 2026 litigation developments. US Patent 11,431,735 — Analyst Summary…
Other patents in Software Technology & Computing Systems (T)
- US 7107221I'll search for authoritative information on this specific patent number, including any 2026 litigation activity. Let me look specifically for the claims of US 7,107,221 and any litigation history. Let me verify the claim set directly from…
- US 6721803Search scope and what it returned I ran targeted lookups on the literal identifier 6721803 (US 6,721,803 B1) across patent databases and litigation dockets. Results: - USPTO/patent records: Found and confirmed — Google Patents, the…
- US 11431735I'll search for current information on this patent, including any litigation or CAFC 2026 docket activity. Let me search for the specific PTAB proceeding and any related 2026 litigation developments. US Patent 11,431,735 — Analyst Summary…
- US 11374982I'll search for authoritative information on this specific patent number. Let me search more specifically for litigation and docket activity involving this patent. Let me look for the actual claim set and any appellate activity. Summary of…
- US 6785727I'll verify this patent number against live sources and check for any litigation or CAFC activity. Let me check for any litigation or CAFC docket activity involving this patent. Let me attempt to retrieve the actual claim text, since the…
- US 11740926I'll verify this patent against live sources before summarizing. Let me check litigation/PTAB/CAFC status specifically. Let me check for the January 2026 IPR final decision on this patent and any Federal Circuit appeal. US Patent…
- US 11726809I'll search for authoritative information on US patent 11726809. Let me check for Federal Circuit (CAFC) activity and the PTAB proceeding. Let me verify the post-settlement and any Federal Circuit activity. Summary: US Patent No…
- US 11693685I'll search for authoritative information on this specific patent number and any litigation involving it. Let me search for the specific IPR outcome and any Federal Circuit appeal involving this patent. US Patent 11,693,685 B2 — Patent…
This patent in court (2)
2 tracked lawsuits name US 11775326.