Invalidity dossier
US 12244630
Security threat alert analysis and prioritization
Current assignee: Sophos Ltd
Added 9/30/2026, 5:35:37 PM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll search for the patent and any related litigation.
Let me verify the granted patent's claims and check for any litigation or PTAB proceedings.
US Patent 12,244,630 — Analyst Summary
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 12,244,630 B2 (interpreted literally as given) |
| Title | Security threat alert analysis and prioritization |
| Assignee | Sophos Ltd (Abingdon, United Kingdom) — original and current assignee |
| Inventors | Ben Uri Gelman (Burlington, MA); Salma Taoufiq (Budapest); Konstantin Berlin (Potomac, MD); Tamás Vörös (Budapest) |
| Application number | US 17/958,147 |
| Filing date | September 30, 2022 |
| Priority date | May 9, 2022 (provisional 63/339,908; a second provisional, 63/390,913, filed Jul. 20, 2022) |
| Issue / grant date | March 4, 2025 |
| Pre-grant publication | US 2023/0362184 A1 (Nov. 9, 2023) |
| PCT | PCT/GB2023/051192 → WO 2023/218167 A1 |
| Primary CPC | H04L 63/1433 (network security — vulnerability analysis), within H04L 63/14 |
| Legal status (per Google Patents) | Active; adjusted expiration listed as 2043-03-26 |
Source: https://patents.google.com/patent/US12244630/en
Caveat on identifiers: I interpreted "12244630" as US 12,244,630 exactly as written. Google Patents returns this patent for that number, so I have high confidence this is the correct record. I did not find any other patent or application under a similar number that I confused it with.
Abstract (as published)
A method for prioritizing security events comprises receiving a security event that includes security event data generated by an endpoint agent based on a detected activity, wherein the security event data includes one or more features; applying a first computing model to the security event data to automatically determine which of the one or more features are input features to a machine learning system; applying a second computing model to historical data related to the security event data to determine time pattern information of the security event data as an input to the machine learning system; combining the input features from the first computing model and the input from the second computing model to generate a computed feature result; and generating an updated security level value of the security event from the computed feature result.
Plain-language overview of the independent claims
The specification's Summary describes the claimed system as a method, a computer system, and a computer program product. The independent claims I could confirm are:
Claim 1 — Method. A computer-implemented method steps through the following: (1) receive a set of alerts produced by an endpoint agent in response to detected computer security activity; (2) extract feature vectors from those alerts; (3) compute temporal features from the alerts; (4) train a first classification model on the feature vectors; (5) train a second classification model on the temporal features; (6) combine the two trained classification models into an ensemble model; (7) output, from the ensemble model, an alert-level risk score that corresponds to a severity-level value for each alert; and (8) arrange the alerts for output to an analyst's computer according to those risk scores.
In plain terms: take the raw security alerts, build one model that looks at what is inside each alert (content) and a second model that looks at when/where/how often alerts occur (behavior over time), fuse them into one scoring engine, and use the resulting per-alert score to reorder the analyst's queue.
Claim 10 — Computer system. Mirrors the operations of claim 1, but recited as a system: one or more processors plus memory storing program code that, when executed, cause the system to receive the alerts, extract feature vectors, compute temporal features, train the first and second classification models, combine them into an ensemble model, output an alert-level risk score per alert, and arrange the alerts for output to an analyst computer.
Computer program product. The Summary recites an accompanying computer program product, but the claim listing I retrieved (from the pre-grant publication US 2023/0362184 A1) was truncated before the end of the claim set. I could not verify the exact claim number or complete scope of a third independent claim in the granted patent. Treat this as an open item rather than a confirmed claim.
Notable dependent-claim themes (for context)
From the claim set retrieved for the pre-grant publication: aggregating alert-level risk scores into an incident-level score and performing a prioritization operation on it (claim 2); feeding analyst feedback back to storage, modifying the alerts, and retraining the models (claim 3); suppressing an incident whose incident-level score is below a threshold (claim 4); ranking alerts within an incident (claim 5); retraining to replace a current security level value with the alert-level risk score (claim 6); threat-case re-prioritization (claims 7–8); and handling semi-structured alert formats (claim 9).
Supporting disclosure highlights
- Architecture (FIG. 3): a feature extraction module (with an automatic featurization processor and a temporal computation processor), a machine learning module (content model, context model, ensemble model), and a triage module, plus a feedback loop from the analyst response system back to the alerts database.
- Featurization: JSON-style semi-structured alerts are flattened, missing keys filled (NaN/−1/"missing val"), identifier/timestamp columns excluded, low-cardinality strings excluded, rare values collapsed, and remaining strings one-hot or token/character encoded — allowing adaptation to new detectors and schema changes without human intervention.
- Temporal features: counts and summary statistics over multiple time windows (customer estate size, alerts per endpoint, sensors fired, endpoints triggering alerts, per-detector firing counts, global customer activity), capturing anomalous alert-volume peaks.
- Ensemble aggregation: averaging, max, weighted sum, or training a unified model on both feature sets; logistic regression, Random Forest, or XGBoost are named algorithms (e.g., Random Forest for the content model, XGBoost for the context model).
- Triage output: false-positive suppression, incident prioritization, and within-incident alert prioritization.
- Figures 6–7 compare case-level ROC and precision-recall curves against baselines.
Litigation / CAFC 2026 docket check
I searched Google Patents, Justia, USPTO PTAB/PTACTS materials, and general web sources for this patent number combined with litigation, IPR, and CAFC 2026 docket terms.
Finding: I found no Federal Circuit 2026 appeal docket, no PTAB inter partes review, and no district court action naming US 12,244,630 as an asserted patent. The Google Patents page likewise lists no litigation or post-grant events.
Important caveats:
- My searches surfaced unrelated Sophos patent disputes (e.g., the Open Text/Webroot v. Sophos W.D. Tex. case involving the '250, '389, '224, '045, '591, '844, and '721 patents, and several Sophos IPR petitions). None of these involve US 12,244,630. Those results are background noise, not evidence about this patent.
- I do not have direct access to the CAFC 2026 docket database or PACER/Docket Alarm as primary sources. The absence of results is not proof that no 2026 appeal exists; it means I could not find one. A 2026 CAFC appeal would require an underlying district court or PTAB decision that I also could not locate.
- I could not retrieve the full granted claim set of US 12,244,630; the independent-claim descriptions above for claims 1 and 10 are drawn from the corresponding pre-grant publication and should be verified against the official granted claims in USPTO Patent Center before relying on them.
Bottom line
US 12,244,630 is a Sophos patent (filed Sep. 30, 2022; priority May 9, 2022; issued Mar. 4, 2025) covering a two-model machine-learning ensemble — a content model over extracted alert features and a temporal/context model over historical alert behavior — whose fused alert-level risk scores are used to re-rank and triage security alerts, and from which incident-level scores drive suppression and prioritization. I found no CAFC 2026 docket or other litigation specifically on this patent, but that finding is limited by my search access and should be confirmed against authoritative docket sources.
Generated 9/30/2026, 5:36:00 PM
Cases on file (0)
Specific litigation cases in our database that name US patent 12244630. The free-form analysis below may also discuss cases beyond this list.
No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll search the litigation databases for this specific patent number.
Let me run more targeted searches, including Sophos-specific queries.
Let me check the Unified Patents portal and RPX Insight directly, plus a Docket Alarm search.
Litigation search: US Patent 12,244,630
Bottom line
I found no litigation — district court, PTAB, ITC, or Federal Circuit — naming US Patent 12,244,630 as an asserted or challenged patent.
To be explicit about scope: no plaintiff has sued anyone on this patent, no defendant has filed a declaratory-judgment action against it, no inter partes review or post-grant review petition targets it, and no appeal involving it appears in any source I could reach. The patent issued only recently (March 4, 2025), which is consistent with the absence of an enforcement record.
Sources searched and what they returned
| Source | Query | Result |
|---|---|---|
| Unified Patents portal (portal.unifiedpatents.com litigation caselist) | 12244630 |
No case; the site's litigation caselist did not surface any docket tied to this number. (Note: the portal's caselist is principally NPE-focused and PTAB-facing; its silence is weak negative evidence.) |
| RPX Insight (insight.rpxcorp.com) | "12,244,630" and Sophos |
No case linked to this patent. RPX Insight returned a Sophos docket only for a different patent — Sulaco Enterprises LLC v. Sophos Limited, E.D. Tex. No. 2:25-cv-01222. |
| PACER Monitor / Docket Alarm | "12244630" patent litigation |
No docket naming the patent. |
| CAFC opinions/orders | Federal Circuit 2024–2026 | No appeal involving this patent. |
| General web | "12244630" patent litigation; "12,244,630" Sophos |
No litigation hits on the number. |
Important caveats (do not over-read the null)
- This is a negative finding, not proof of non-existence. Unified, RPX, Docket Alarm, and PACER are behind interactive/authenticated interfaces; my access is via indexed search results, which can lag or omit dockets. A 2026 filing naming US 12,244,630 would be recent and might not yet be indexed.
- A grant date of March 4, 2025 means any enforcement suit would have to post-date that issuance. The patent's ~3.5-year statutory pre-issuance window for a preliminary injunction is irrelevant here; there is no pre-grant assertion vehicle in the U.S. for this situation.
- Rebalanced caution for Sophos specifically: Sophos is an active patent defendant in multiple 2022–2026 cases (see below), so precedent suggests this patent could plausibly be asserted or challenged later. It just has not been, so far as I can determine.
Sophos litigation I did find — none of it on US 12,244,630
These are related-party context only and confirm the patent is not among them. I list them so the null finding is not confused with a failed search.
| Case | Parties | Jurisdiction | Case No. | Filed | Status |
|---|---|---|---|---|---|
| Arc Link LLC v. Sophos Limited | Arc Link (plaintiff) v. Sophos | E.D. Tex. | 2:26-cv-00490 | ~2026 | Patent infringement; pending (per PACER Monitor) |
| Sulaco Enterprises LLC v. Sophos Limited | Sulaco (NPE) v. Sophos | E.D. Tex. | 2:25-cv-01222 | 12/16/2025 | Pending; asserts US 8,990,942 (per Unified Patents) |
| Datamonitor Systems, LLC v. Sophos Group PLC | Datamonitor v. Sophos | W.D. Tex. (Judge Xavier Rodriguez) | 6:24-cv-00185 | 2024 | Dismissed with prejudice on joint motion; each party bears own costs; asserts US 7,594,009 |
| Webroot, Inc. & Open Text, Inc. v. Sophos, Ltd. | Webroot/Open Text v. Sophos | W.D. Tex. | (Sophos's final invalidity contentions on file) | 2022 | Ongoing; asserts the '244, '250, '389, '224, '045, '591, '844, '721, '243 patents — none is US 12,244,630 |
| Finjan, Inc. v. Sophos, Inc. | Finjan v. Sophos | N.D. Cal. | 3:14-cv-01197 | 2014 | Substantially resolved (summary-judgment rulings on the '289, '844, '918 patents) |
| Vir2us, Inc. v. Invincea/Sophos | Vir2us v. Sophos | E.D. Va. → 4th Cir. | 4th Cir. No. 25-01158 | — | Contract/royalty dispute and appeal; not a patent-infringement case |
| Malikie (Sophos Mobile) and related actions | various v. Sophos | E.D. Tex. (2:24-cv-00905) | — | 2024 | Asserts the '145, '829, '999 patents |
Contradiction / reconciliation with prior analysis
This is consistent with the previously generated litigation section, which likewise found no CAFC 2026 docket, no PTAB proceeding, and no district court action naming this patent. One cross-reference worth flagging: the earlier section referred to a Webroot/Open Text v. Sophos case involving "the '250, '389, '224, '045, '591, '844, and '721 patents." The Sophos final-invalidity-contentions document I retrieved adds the '244 and '243 patents to that list. Neither the earlier list nor the expanded list includes US 12,244,630 — so the two sections agree on the dispositive point.
Recommendation before relying on the null
Before treating this as a clean right-to-use conclusion, confirm against primary sources:
- USPTO PTAB (PTAB E2E / PTACTS) — search by patent number directly for any IPR/PGR.
- PACER / Docket Alarm — party-name search for "Sophos" and patent-number search for "12,244,630" across all districts; the number-search field will catch any docket where it is asserted.
- CAFC docket — search by patent number and by the '630's appeal potential.
- ITC EDIS — Section 337 investigations naming Sophos.
If you want, I can draft the specific citation-format litigation summary you'd need for a validity/enforcement memo once the primary-source checks are run.
Generated 9/30/2026, 5:40:58 PM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured block's "no proceedings" result against live sources before finalizing.
Let me run targeted checks on the patent number, the family, and any Sophos PGR/IPR activity.
Let me check the Unified Patents portal and whether Sophos has asserted this patent anywhere.
Proceedings overview
Total: 0 AIA trial proceedings. The canonical structured source for this prompt states: "The USPTO ODP API returns no AIA trial proceedings for this patent as of the most recent ingest" — i.e., zero IPRs, zero PGRs, and zero CBMs on US 12,244,630, meaning no claim of this patent has ever been canceled, narrowed, or even tested at the Board, and no estoppel has attached to anyone. The bottom-line defensive posture for a defendant is therefore the opposite of hardened: the patent is pristine and untested, which cuts both ways — you get a clean, un-estopped shot at invalidating it, but you also get zero free wins, because there is no FWD to point at and no canceled claim to fall back on.
Verification note. I searched Google Patents, general web sources, and PTAB materials for the patent number alone and in combination with IPR, PGR, CBM, PTAB, petition, Sophos, and litigation terms. Every hit was either this patent's own Google Patents page or unrelated Sophos activity in which Sophos is a petitioner (not patent owner) — see "Pattern signals" below. Consistent with the structured block, I found no proceeding naming US 12,244,630. Absence of results is not proof of absence; to confirm, run a patent-number query in PTAB E2E / the PTAB "Patent Trial and Appeal Board" search at https://ptacts.uspto.gov/ptacts/ and the USPTO Open Data Portal before relying on this in a filing or an opinion letter.
No proceeding to profile
Because the structured list is empty, there is no {PROCEEDING_NUMBER} to head a per-proceeding block, and I will not invent one. There is no institution decision to summarize, no judge panel to name, no FWD disposition to quote, no settlement, and no appeal. Any citation to an "IPR2025-xxxxx" or "PGR2025-xxxxx" against the '630 patent in a demand-letter response or an invalidity contention that you cannot personally pull from PTAB E2E should be treated as fabricated until proven otherwise.
Two timing facts are worth stating precisely, because they define what is still available rather than what happened:
- PGR is time-barred. The '630 patent issued 2025-03-04. Under 35 U.S.C. § 321(c), a post-grant review petition must be filed within 9 months of grant — that window closed 2025-12-04. As of today (2026-09-30) a PGR on this patent is unavailable. So if a competitor was going to file a § 112 or § 101-style PGR, the record indicates they declined to, and can no longer.
- CBM is doubly unavailable. The AIA transitional covered-business-method program sunset for petitions filed after 2020-09-16, and this patent's 2022 priority postdates the sunset. CBM is off the table as a matter of law, not just as a matter of nobody having filed.
- IPR remains fully available. There is no statutory deadline for an IPR petition; the only clock is the § 315(b) one-year bar running from service of a complaint alleging infringement. With no IPR on file, no one has triggered § 315(e) estoppel and no one has forfeited their best art.
Strategic summary
Claim status: everything is UNTESTED. Not "sustained," which would imply a Board looked and approved — but untested, which means claims 1 through the last dependent claim all stand exactly as they issued on 2025-03-04, unreviewed. For claim-numbering precision in your own papers, note the flag carried forward from the earlier section of this analysis: the independent-claim descriptions (claim 1 method, claim 10 system) were reconstructed from the pre-grant publication US 2023/0362184 A1, and one open item is whether a third independent claim (the computer program product recited in the Summary) exists and at what number. That open item is more consequential here than in a litigation context, because a petition must identify challenged claims by granted number. Pull the granted claim set from USPTO Patent Center for application 17/958,147 and confirm the claim count and each independent claim's scope before drafting anything. Do not rely on the pre-grant publication's numbering — claims frequently change between publication and grant.
Estoppel landscape: empty, and that is your single biggest asset. Because no IPR or PGR was ever instituted, § 315(e)(2) estops nobody. There is no petitioner, no privy, no defensive aggregator with a prior bite at the apple, and no ground that a prior challenger "raised or reasonably could have raised." Practically, a defendant today can assert any § 102/§ 103 combination, any § 112(a)/(b) theory, and — if drafted as a PGR-style theory in an IPR-eligible way — any printed-publication prior art that predates the May 9, 2022 priority date. The only residual Office-side friction is discretionary: § 325(d) invites the Board to weigh art and arguments already before the Examiner, so art cited or overcome during prosecution of the '630 application is the weakest ammunition. Nothing in the record suggests the prosecution history has been stress-tested by an adversarial challenge.
Pattern signals: none on this patent, but informative in the neighborhood. The '630 patent's owner, Sophos, is an unusually active and sophisticated PTAB petitioner — the search results repeatedly surfaced Sophos Ltd./Sophos Inc. petitions against Webroot/Open Text patents (IPR2023-00491, IPR2023-00528, IPR2023-00556, IPR2023-00633, IPR2023-00655, IPR2023-00662, IPR2023-00677, IPR2023-00699, IPR2024-00253, among others) arising from the W.D. Tex. Waco consolidated litigation (Webroot, Inc. v. AO Kaspersky Lab, No. 6:22-cv-00243-ADA-DTG, lead case; the Sophos-specific case is No. 6:22-cv-00240-ADA-DTG). Sophos also litigated Sophos Ltd. v. Iancu, No. 2017-1567 (Fed. Cir. Mar. 28, 2018), on appeal from an IPR in which Sophos was patent owner and lost on construction of "are ranked." These matters involve entirely different patents and are background noise with respect to US 12,244,630 — but they tell you two useful things about your adversary: Sophos understands IPR procedure at a sophisticated level, and Sophos is willing to litigate all the way to the Federal Circuit. Do not expect a weak or pro-forma defense if you file. No defensive aggregator (Unified Patents, RPX, etc.) appears anywhere in the chain for this patent — the absence of a Unified proceeding is notable, since Unified's business model is precisely to file on well-asserted, NPE-adjacent patents, and its absence suggests the '630 patent has simply not yet been asserted in a way that attracted a crowd-funded challenge.
Recommended next steps
If you are a defendant and want an IPR-based defense. You have the full menu. Two strategic notes specific to this patent:
- The claims are procedural, not structural, which is a § 101 and § 112 opportunity. The claim 1 sequence — receive alerts, extract feature vectors, compute temporal features, train two classification models, combine into an ensemble, output a per-alert risk score, and reorder an analyst's queue — reads as a machine-learning pipeline implemented on generic hardware. That invites an Alice/Mayo eligibility challenge in district court, and, for the Board, § 112(b) indefiniteness attacks on purely functional terms ("content computing model," "context computing model," "computed feature result," "alert-level risk score corresponding to a severity-level value"). Note the procedural constraint: § 112 grounds are not available in an IPR (35 U.S.C. § 311(b) limits IPR to § 102/§ 103 on patents and printed publications); a § 112 attack had to go through a PGR, and that window closed 2025-12-04. So § 112 is now a district-court / ITC / ITC-style theory, not a PTAB one.
- Art selection. The specification is candid about the prior art it builds on — logistic regression, Random Forest, XGBoost, and ensemble aggregation (mean/max/weighted sum) over time-windowed count features are all described as conventional choices. That candor is useful: look for 2020–2022-era publications on alert triage, SOC alert fatigue, and two-tower / fused content-plus-context ML for intrusion detection, and for the earlier Sophos family members (e.g., US 11,562,088 "Threat response using event vectors," and US 2023/0111304 A1 "Composite threat score," both naming Andrew J. Thomas and colleagues) as § 102(a)(2) candidate art where they qualify.
If you are the patent owner. Treat the absence of any IPR as a genuine but fragile advantage. The patent issued 2025-03-04, is still within its first few years, and has attracted no challenge — but well-asserted patents eventually attract IPRs, and the moment Sophos (or a successor) sues, the § 315(b) one-year clock starts running against each defendant and the Board's § 314(a) discretion will be weighed against whatever trial schedule develops. If there is a live litigation campaign or a licensing program built on this patent, assume a petition is coming and prepare a POPR that forecloses it.
Milestones if a proceeding does appear. Once a petition is filed, the timeline is statutory and short: the Board's institution decision is due within 6 months of the petition's filing (35 U.S.C. § 314(b)); if instituted, oral hearing is typically scheduled roughly 8 months in, and the Final Written Decision is due within 12 months of institution (35 U.S.C. § 316(a)(11)), extendable to 15 months for good cause. A defendant weighing a stay motion should therefore track: petition filing date → +6 months (institution) → +12 months from institution (FWD). None of these milestones currently exists for this patent.
Plain statement of the negative result, per your instruction: there is no PTAB activity on this patent. I am not aware of any and the structured ODP data affirmatively reports none. That absence is itself a signal — a patent that has never been attacked has never been tested, so its claims are broad and unbracketed by any adverse construction or adverse validity finding, and any invalidity theory you build will be the first one the owner has had to answer.
Sources for confirmation. PTAB E2E / PTAB search: https://ptacts.uspto.gov/ptacts/. Patent record: https://patents.google.com/patent/US12244630/en and USPTO Patent Center. Federal Circuit dockets and opinions: CourtListener. For the unrelated Sophos-as-petitioner matters cited above, see the petitions at ptacts.uspto.gov (e.g., IPR2023-00699 against US 8,418,250; IPR2024-00253 against US 8,719,932) and Sophos Ltd. v. Iancu, No. 2017-1567, available at https://www.courtlistener.com/opinion/4481603/sophos-limited-v-iancu/.
Generated 9/30/2026, 5:41:12 PM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2023-05-04 · Assignment
Konstantin Berlin; Salma Taoufiq; Ben Uri Gelman; Tamás VörösSophos Limited
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll research the assignment record for this patent, starting with the recorded assignment noted in the Google Patents legal events.
Let me dig for the specific reel/frame and correspondent on this patent's assignment.
I hit the tool-step limit before I could pull the Assignment Center reel/frame directly from the USPTO interface or PlainSite. I'll give you everything the authoritative sources I did retrieve support, and flag exactly what remains unverified rather than filling the gap.
Assignment Record — US 12,244,630 (US 17/958,147)
Sourcing note (read first): The only assignment record I was able to confirm is the Google Patents legal-events entry on the authoritative patent page (https://patents.google.com/patent/[US12244630B2](/patent/US12244630B2)/en), which lists one reassignment event dated 2023-05-04 to SOPHOS LIMITED with assignors Berlin, Taoufiq, Gelman, and Vörös. I was not able to retrieve the reel/frame number or the correspondent of record before exhausting my search budget. Everything below that depends on reel/frame is marked as unverified. I did not fabricate reel numbers to fill the gap.
Inventors
Four named inventors, all appearing as co-assignors on a single inventor-to-employer assignment to Sophos Limited (Google Patents legal events, 2023-05-04):
| Inventor | Recorded location | Employer at filing |
|---|---|---|
| Ben Uri Gelman | Burlington, MA | Not stated on the patent record — see note |
| Salma Taoufiq | Budapest, HU | Not stated on the patent record — see note |
| Konstantin Berlin | Potomac, MD | Not stated on the patent record — see note |
| Tamás Vörös | Budapest, HU | Not stated on the patent record — see note |
On employer: The patent's face does not name an employer for any inventor. The strongest record-based inference is that all four were Sophos personnel, because (a) all four executed the same assignment conveying their entire interest to Sophos Limited, which is the signature pattern of an employment invention-assignment obligation, and (b) the Burlington, MA address corresponds to Sophos Inc.'s US headquarters location, and the Budapest addresses correspond to Sophos's Budapest R&D/AI site. I could not independently verify individual employment from an SEC filing or press release within my search budget, so treat "Sophos employee at filing" as high-confidence inference, not a documented fact.
Unusual-departure check: I found no evidence of the inventors departing Sophos within 12 months of the May 9, 2022 priority date, and no evidence of a portfolio fire-sale. Berlin is publicly associated with Sophos as its AI/science lead in the same period; I did not find a departure announcement for any of the four. Absence of a departure signal ≠ proof none occurred, but there is no affirmative signal here. This is the inverse of the fire-sale precursor pattern.
Original assignee
Sophos Ltd (named on the issued patent; also listed as current assignee — no change of owner since grant). Corporate address per the contemporaneous Sophos assignment documents: The Pentagon, Abingdon Science Park, Abingdon, OX14 3YP, United Kingdom.
- Product embodying the claims? Yes. Sophos ships commercial products directly practicing the claimed subject matter: Sophos Intercept X / Intercept X Advanced with EDR, Sophos Managed Threat Response (MTR), and Sophos's XDR/managed-detection services. The specification's own framing — managed threat response teams, analyst case loads, threat cases requiring analyst triage — maps onto Sophos MTR, whose published welcome guide uses "cases," "detections," and "threat hunts" in exactly the sense the patent claims score and prioritize. This is an operating-company patent, not a licensing vehicle.
- Primary line of business: Enterprise cybersecurity — endpoint, network, email/web security, managed detection and response. Sophos Limited is the UK holding/operating entity for the Sophos group.
- Current status: Operating. Sophos Group plc was taken private by Thoma Bravo in a 2020 acquisition (high confidence). I am not certain of the current ultimate ownership structure as of 2026 and did not verify it within budget. No bankruptcy, no dissolution, no receivership.
Assignment timeline
There is exactly one recorded assignment in the chain, and it is the original inventor-to-employer assignment. No post-issuance transfers, no security interests, no mergers, no changes of name appear on the record I retrieved.
- Execution date: not retrieved / recorded 2023-05-04 — Reel not retrieved (indexed as a "reassignment" event on Google Patents)
- Conveyance: Assignment (assignment of assignors' interest)
- Assignors: Konstantin Berlin; Salma Taoufiq; Ben Uri Gelman; Tamás Vörös (all four jointly)
- Assignee: Sophos Limited
- Correspondent: Not retrieved. See below for a related-but-different Sophos data point; I am not asserting it applies to this patent.
- Context: Original employment/obligation-to-assign conveyance, consolidating 100% of inventor interest in the original assignee. Not a fire-sale, reorg, securitization, or transfer-to-asserter.
Timing observation worth noting: recording occurred 2023-05-04, roughly 8 months after the 2022-09-30 filing and about 12 months after the May 9, 2022 priority date. Late-but-routine recordation of an inventor assignment is common (it is often recorded at, or after, PCT/family filing to support a Power of Attorney or a foreign-filing priority claim); the record also shows PCT/GB2023/051192 being accorded priority on 2023-05-05, the very next day. That juxtaposition suggests the recording was timed to support the PCT filing rather than to enable assertion. No support in the record for a litigation-driven transfer.
On the correspondent — a caution, not a finding. In a related but separate Sophos assignment I retrieved — app 16/129,183, "Threat Detection With Business Impact Scoring," filed 2018-09-12, recorded 2019-02-06, document at legacy-assignments.uspto.gov/assignments/assignment-pat-048254-0777.pdf (reel/frame as encoded in that filename: 048254/0777, itself unverified) — the recording names Sophos's counsel as Strategic Patents, P.C., USPTO Customer Number 138064, Abingdon-aligned Sophos counsel. That establishes that Sophos uses a regular outside recording firm. It does not establish that Strategic Patents, P.C. is the correspondent on US 12,244,630. I am flagging it strictly as a lead for your verification, per the instruction not to infer from pattern alone. A single appearance on a different patent is not a recurrence finding.
Timeline diagram
timeline
title Ownership of US 12244630
2022 : Filed by Sophos Ltd
: Inventors execute assignment
2023 : Assignment recorded to Sophos Limited
: PCT priority filing recorded
2025 : Patent issued to Sophos Ltd
NPE / troll-pattern signals
| # | Signal | Call | Basis |
|---|---|---|---|
| 1 | Shell-entity transfer | Not present | The only assignment runs from four natural persons to an operating UK company (Sophos Limited, Abingdon Science Park — a real corporate address, not a registered-agent service). No "IP / Patents / Licensing / Holdings / Ventures" entity appears anywhere in the chain. |
| 2 | Known asserter in the chain | Not present | Neither the assignor nor the assignee matches any entity on the referenced NPE lists (Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, Spangenberg entities). Current assignee is Sophos Ltd. |
| 3 | Repeat correspondent across the chain | Unclear / not assessable | A "repeat correspondent" signal requires at least two links (or cross-chain recurrence on the tracked site). This chain has one link, and I could not retrieve its correspondent of record. There is therefore nothing to test for recurrence. The Strategic Patents, P.C. (Customer No. 138064) reference above is on a different Sophos patent and cannot be counted here. |
| 4 | Cascading transfers | Not present | Zero consecutive transfers; one assignment total, dated 2023-05-04. No chained LLCs, no shared correspondent addresses, no common principals. |
| 5 | Pre-litigation transfer | Not present | No infringement suit naming US 12,244,630 was located (consistent with the earlier docket check in the prior section). With no suit, there is no 6-month pre-suit transfer window to assess. |
| 6 | Bankruptcy fire-sale | Not present | No Chapter 7/11 involving Sophos Ltd appears in the record; Sophos was taken private by Thoma Bravo in 2020 as a going concern, not liquidated. No patent sale-in-bankruptcy events. |
| 7 | Privateering | Not present | The patent has never left the operating company. There is no NPE downstream asserting on Sophos's behalf. |
| 8 | Defensive aggregator | Not present | The chain does not terminate at RPX, AST, LOT Network, Unified Patents, or OIN. It terminates at Sophos Ltd. |
Verdict
Insufficient data (chain consists of only the original assignment).
Justification: the sole recorded event is the original inventor-to-employer conveyance to Sophos Limited, recorded 2023-05-04, with all four named inventors as assignors and Sophos as assignee — and Sophos remains the current assignee per the patent record. No second link, no reel/frame-verified correspondent, and no assertion activity exist to support an NPE classification, and the rubric treats "only the original assignment" as insufficient data. Substantively, every one of the eight NPE signals resolves to not present or (for the correspondent signal) not assessable, so this patent is best read as a genuine operating-company asset — the affirmative inverse of an NPE pattern — rather than as an unresolved transfer chain.
Two open items you should close against primary sources before relying on this:
- The reel/frame and correspondent of the 2023-05-04 assignment — retrieve directly at the USPTO Assignment Center (https://assignmentcenter.uspto.gov/ or https://assignment.uspto.gov/patent/index.html) searching patent number 12244630 or application 17/958,147. Capture the correspondent name and firm; if it recurs across other Sophos recordings, that is a prosecution-firm consistency observation, not an NPE signal.
- Confirmation that no post-issuance assignment exists (e.g., a Thoma Bravo-related entity holding, or an intra-group transfer to a Sophos financing vehicle). The Google Patents legal-events list I relied on shows none, but Google Patents can lag or omit security-interest recordings, which would not appear as ownership changes.
Generated 9/30/2026, 5:41:14 PM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll search for the patent and its cited prior art references.
Let me search for the specific citation lists and related prior art.
Let me try to retrieve the specific citation tables from the patent record.
Direct answer first: I could not retrieve the authoritative citation list
I ran multiple searches against the Google Patents record, Justia, FreePatentsOnline, and general web sources for US 12,244,630. I was able to confirm the patent's existence and content, but I was not able to retrieve the actual "Patent Citations" / "References Cited" table from the front page of US 12,244,630.
Per my operating rules, I will not fabricate that list. Inventing reference numbers, dates, and § 102 mappings for an examiner's citation table would be exactly the kind of fabrication I am required to avoid. So this response does three things instead:
- Confirms the patent identification and flags a real numeric collision.
- States plainly what the citation list contains as far as I could verify, and what remains unverified.
- Provides the prior-art references my searches did surface in this technical space, each clearly labeled as not confirmed to be on the patent's face, with my best § 102 assessment and the caveats.
1. Patent identification — confirmed, with an important identifier caveat
| Field | Value |
|---|---|
| Patent number | US 12,244,630 B2 (interpreted literally, as written) |
| Title | Security threat alert analysis and prioritization |
| Assignee | Sophos Ltd |
| Inventors | Ben Uri Gelman; Salma Taoufiq; Konstantin Berlin; Tamás Vörös |
| Application number | US 17/958,147 |
| Filing date | 2022-09-30 |
| Priority date | 2022-05-09 (provisional 63/339,908; provisional 63/390,913 filed 2022-07-20) |
| Grant date | 2025-03-04 |
| CPC | H04L 63/1433 |
Source: https://patents.google.com/patent/US12244630/en
Numeric-collision warning (do not auto-correct either number). The string 12244630 also appears as an application serial number in a Chinese agricultural patent database: application US 12/244,630, which issued as US 8,137,918 B2, "Sperm-specific cation channel, CatSper4, and uses therefor" (Moran et al., filed 2008-10-02). That is a completely different patent that merely shares the digits 12/244,630. It is not patent number 12,244,630 and must not be conflated with the Sophos patent. Google Patents returns the Sophos patent for the query "12244630," which is why I treat US 12,244,630 as the correct record.
2. What the citation table is, and my verification status
A granted US patent's front page carries two distinct lists that the task is asking about:
- (56) References Cited — the references the applicant and/or examiner cited against this patent during prosecution.
- "Cited By" / "Patent Citations" — later patents that cite this one (forward citations). These are not prior art to US 12,244,630 at all.
My searches kept returning the patent's Definitions and Description text (featurization, content model 312, context model 314, ensemble model 315, triage module 320) rather than the bibliographic citation tables. I could not confirm a single examiner-cited reference by name.
Status: unverified. To obtain the real (56) list you need one of:
- USPTO Patent Center / Patent Application Locating and Monitoring (PAIR) for application 17/958,147;
- the USPTO full-text "References Cited" field;
- the granted PDF front page (patentimages.storage.googleapis.com);
- the prosecution file wrapper (which also shows what actually drove allowance).
I flag this as an open item, consistent with the earlier section's note that the full granted claim set was also not retrievable.
3. References surfaced by my searches — same technical space, NOT confirmed as the patent's face citations
The following appeared in my searches and are genuinely relevant to the subject matter of claims 1 and 10 (extract feature vectors from alerts → train a first classification model; compute temporal features → train a second classification model; ensemble → per-alert risk score → reorder analyst queue). None of these is confirmed to appear on US 12,244,630's face. Treat them as candidate prior art to check against the real (56) list.
(a) US 2021/0326744 A1 — "Security alert-incident grouping based on investigation history"
- Citation: U.S. Patent Application Publication US 2021/0326744 A1.
- Date: 2021 (publication year; exact date not verified in my searches).
- Description (verbatim themes): Machine learning model trained on analyst alert-to-incident grouping actions; each training representation includes an entity identifier, alert identifier, incident identifier, incident classification, action indicator, and action time; model prioritizes new alerts by grouping them with existing incidents, into new incidents, or leaving ungrouped; output may be fed to a SIEM.
- Potential § 102 relevance: Claim 1/10 — partially. It discloses a trained ML model operating over security alerts and producing a prioritization/grouping output, plus incident-level handling. It does not clearly disclose the two-model (content + temporal) architecture fused into an ensemble that outputs an alert-level risk score corresponding to a severity-level value and rearranges the analyst queue. On its face this looks more like a § 103 combination reference than a standalone § 102 anticipator of claims 1/10.
- Source surfacing this: patentimages.storage.googleapis.com (US20210326744A1 PDF).
(b) US 10,409,669 B2 — "discovering critical alerts through learning over heterogeneous temporal graphs"
- Citation: U.S. Patent No. 10,409,669 B2.
- Dates: Grant Sep. 10, 2019; priority to provisional 62/422,909 filed Nov. 16, 2016.
- Description (verbatim themes): Transforms training data into a neural-network learning model using temporal graphs; performs model learning by minimizing difference between a ground-truth ranking and the model's ranking; performs inference to extract context features for alerts and calculate a ranking list; top-ranked alerts identified as critical. Cited NPL listed on its face includes Cheng et al. (2016) and Zong et al., "Towards Scalable Critical Alert Mining" (2014).
- Potential § 102 relevance: Claim 1/10 — partial at best. This is the closest thing I saw to "rank alerts using temporal/context signals for human investigation." But it uses temporal graphs and a single ranking model; it does not show (i) extraction of feature vectors from alert content into a first classification model and separate temporal features into a second classification model, (ii) an ensemble of those two, or (iii) an alert-level score corresponding to a severity-level value that rearranges the analyst's output arrangement. Again, § 103 material rather than a clean § 102 reference for claims 1/10.
- Source surfacing this: patentimages.storage.googleapis.com (US10409669.pdf).
(c) US 11,956,253 B2 — "Ranking cybersecurity alerts from multiple sources using machine learning"
- Citation: U.S. Patent No. 11,956,253 B2.
- Dates: Not verified in my searches (examiner listed as Daniel B. Potratz on Justia).
- Description (from its claims, as surfaced): In response to receiving a security alert, evaluates the alert against a plurality of feature indicators, creates a feature vector for the alert, calculates a probability that the alert relates to a cybersecurity risk based on the feature vector and historical alert data, and ranks alerts from multiple sources; ranking updated in real time as new alerts arrive.
- Potential § 102 relevance: Claim 1/10 — the most on-point of the group so far, but still likely § 103. It shows feature-vector construction from alerts and use of historical data to score/rank alerts. The gap for § 102 against claim 1/10 is the two-distinct-thrall/ensemble architecture: a first classification model trained on alert-content feature vectors combined with a second classification model trained on computed temporal features, producing an ensemble alert-level risk score. That specific separation-and-fusion does not appear in the abstract/claims I saw.
- Source surfacing this: https://companyprofiles.justatic.com/patent/11956253
(d) US 2024/0195827 A1 — threat detection platform with alert-history "probabilities of relevance"
- Citation: U.S. Patent Application Publication US 2024/0195827 A1.
- Date: 2024 (publication). Note: published after the 2022-05-09 priority date, so it is not prior art to US 12,244,630 — I include it only because it surfaced and illustrates the crowded field.
- Description: Threat detection platform processes feature data in alerts plus an alert history to determine probabilities of relevance of alerts based on historical information; alerts labelled "common" vs "rare."
- Potential § 102 relevance: None — post-priority publication. Listed for completeness only.
- Source surfacing this: patentimages.storage.googleapis.com (US20240195827A1.pdf).
(e) Assignee-family / background references (likely not the (56) art, but relevant context)
- US 10,841,339 B2, Sophos Limited, "Normalized Indications of Compromise" — grant Nov. 17, 2020; filed May 2, 2018; continuation of 14/485,762 (2014).
- US 2023/0111304 A1, Sophos Limited, "Composite Threat Score" — filed May 26, 2022; a sibling Sophos filing.
- WO 2019/200317 A1, Sophos — entity models / risk scores in a vector space.
- US 2023/0362184 A1 — this patent's own pre-grant publication (same family; not prior art).
- US 2014/0115703 A1, Sophos — "Threat detection through the accumulated detection of threat characteristics."
These are same-assignee / same-field materials. They would be § 102(a)(2) / § 103 candidates only if they qualify as prior art, and they are most useful for showing the state of the assignee's own art rather than as the examiner's rejections.
4. The strongest "reference" is the inventors' own paper — but it is not § 102 prior art
My searches repeatedly surfaced the inventors' companion paper:
- Gelman, B., Taoufiq, S., Vörös, T., and Berlin, K., "That Escalated Quickly: An ML Framework for Alert Prioritization," arXiv:2302.06648 (2023), https://arxiv.org/abs/2302.06648 (also cited as reference [25] in a later arXiv survey on alert triage).
This paper describes the TEQ system — automatic featurization of semi-structured alerts, a random-forest content model, temporal-firing-pattern signals, and an ensemble — i.e., essentially the disclosure of US 12,244,630, by the same four inventors.
§ 102 assessment: not prior art. arXiv:2302.06648 was published in February 2023, which is after the 2022-05-09 priority date. Even setting the date aside, it is the inventors' own disclosure and would fall within the 35 U.S.C. § 102(b)(1)(A) exception (disclosure made by the inventor or joint inventor) if it fell within the grace period. So it cannot anticipate any claim. I mention it because it is the best available technical description of what the patent covers and because a diligent search of this patent's art should account for it explicitly.
5. Bottom line
- US 12,244,630 is confirmed as the Sophos patent (App. 17/958,147; priority 2022-05-09; granted 2025-03-04) on a two-model ML ensemble (content model + temporal/context model) generating alert-level risk scores that drive triage and incident-level suppression/prioritization.
- I could not retrieve the patent's actual (56) "References Cited" list, so I cannot give you the examiner-cited references "for each patent citation." I will not invent them.
- The references I did surface — US 2021/0326744 A1, US 10,409,669 B2, and US 11,956,253 B2 — are the most relevant prior art I identified, but on their faces they appear to be § 103 combination material, not single-reference § 102 anticipators of independent claims 1 and 10, because none disclosed the specific content-model + temporal-model → ensemble → alert-level severity score → analyst-queue rearrangement combination. That assessment is provisional pending the real claim text and citation list.
- Open items to close this properly: (1) the granted claim set for US 12,244,630; (2) the (56) references-cited list from the granted PDF front page or USPTO Patent Center for App. 17/958,147; (3) the prosecution history to see which references actually drove allowance and whether any rejection was under § 102 or § 103.
Generated 9/30/2026, 5:41:16 PM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll first try to retrieve the prior-art/citation data for this patent, since the "Prior Art section" content wasn't included in what was passed to me.
The fetch of the Google Patents page I was given does not include a Citations/"Prior Art" section (it's truncated mid-description). Let me try to recover the actual cited/citing references before analyzing.
Preliminary: what I actually have for "prior art" — an explicit gap
Before analyzing, I have to flag a limitation in the assignment, per the standing rule to say so rather than fabricate.
The fetched Google Patents text supplied to me does not contain a Citations / "Cited By" / "Prior Art" section. The fetch is truncated mid‑sentence in the FIG. 1 description ("...network connectivity not directly associa"), so everything after that — including the reference lists Google normally renders — was never captured. My follow‑up searches also failed to return a citation list for US 12,244,630 (results were dominated by unrelated Sophos/Webroot litigation on other patents). The only prior‑art‑related items I can actually confirm from the page are:
- Prior art keywords:
alerts,security,alert,classification model,computer - Prior art date: 2022‑05‑09 (Google's field, which here matches the priority date)
So I cannot map the claims onto a specific, verified citation list. What follows is therefore an independent §103 analysis built from the claim elements and from prior art I can identify with stated confidence levels — not a critique of an examiner's cited art. Every reference below is tagged with my confidence, and I have not read the full text of most of them in this session. Treat this as a framework to be completed once the actual cited art is in hand.
Also carried forward: I still have not verified the granted claim set. The dependent-claim analysis rests on the pre-grant publication US 2023/0362184 A1, as flagged in the earlier section. If claims were narrowed during prosecution, parts of this analysis change.
1. Legal framework and the person of ordinary skill
AIA applies (effective filing 2022‑05‑09, via provisionals 63/339,908 and 63/390,913). The governing test is Graham v. John Deere, 383 U.S. 1 (1966), applied through KSR Int'l v. Teleflex, 550 U.S. 398 (2007) and MPEP § 2143. No explicit teaching‑suggestion‑motivation is required; an articulated rationale with a rational underpinning suffices.
Proposed PHOSITA: a master's degree in computer science, data science, or equivalent, plus ~2–3 years of experience building security analytics / detection pipelines, or a bachelor's degree plus ~5 years of such experience. This person is comfortable with supervised classification, ensembling, feature engineering from semi‑structured logs, and SIEM/SOC workflows. Critically, this PHOSITA is presumed to know Logistic Regression, Random Forest (Breiman 2001) and XGBoost (Chen & Guestrin 2016) — all three are named in the patent itself — and to know ensembling/stacked generalization (Wolpert 1992).
That framing matters: a large part of claim 1 is the routine application of known ML tooling to a known data type.
2. Claim 1 element-by-element
| Claim 1 element (per pre-grant pub.) | Prior-art status | Confidence |
|---|---|---|
| Receive alerts from an endpoint agent in response to detected security activity | Ubiquitous. The patent's own FIG. 1 threat management facility describes this as conventional, as does Sophos's WO 2019/200317 A1 (sensors on compute instances → event collection → threat management facility) | High |
| Extract feature vectors from the alerts | Routine. Feature-vector generation from security data was standard; e.g., the Webroot patent asserted against Sophos in Webroot/Open Text v. Sophos, W.D. Tex. No. 6:22‑cv‑00243, recited "generating a feature vector from the plurality of static data points using a classifier" (reported in Sophos's IPR petition materials as the '844 patent, US 10,599,844) | Med‑High on the number; High on the practice being routine |
| Compute temporal features from the alerts | Strongly disclosed by WO 2019/200317 A1 (Sophos, pub. 2019‑10‑17): event vectors evaluated against entity models, "activity baseline … determined based on a historical window of event vectors," "periodically recalculated for a new historical window," risk scores from event streams across multiple compute instances | High |
| Train a first classification model on the feature vectors | Routine ML; RF/XGBoost/LogReg named in the patent | High |
| Train a second classification model on the temporal features | Routine ML applied to a second feature view | High |
| Combine the two into an ensemble model | Ensembling is textbook (Wolpert 1992; Breiman 2001); hybrid/ensemble IDS was an established literature | High |
| Output an alert-level risk score corresponding to a severity-level value | Risk scoring of entities/events is core to WO 2019/200317 A1 ("calculating a first risk score … based on a first distance between the event vector and the first entity model") and to US 2019/0319961 A1 (Levy et al., Sophos, pub. 2019‑10‑17: risk assessments of entities "either individually or in groups") | High |
| Arrange the alerts for output to an analyst computer according to risk scores | Conventional SOC case-management / queue ranking. The patent's own Background concedes that severity values, rulesets, and case-load ordering already existed | High |
Assessment: claim 1 is a strong § 103 candidate. Every element reads on known art, and the "invention" is essentially the composition of two known modeling views plus a known output-ordering step. There is no recited technical detail — no specific featurization algorithm, no specific aggregation mechanism, no specific data structure — that rescues it on the face of the pre-grant text.
3. Combinations that render the claims obvious
Ground 1 — WO 2019/200317 A1 alone, or in view of a generic ensembling teaching
WO 2019/200317 A1 (Sophos) as the primary reference. It discloses the sensor→event→vector→risk-score→remediation pipeline, historical-window baselines, and event-stream-level scoring — i.e., both a content representation (event vectors) and a temporal/behavioral baseline. To the extent it does not explicitly "train two models and ensemble them," that gap is filled by a single ensembling reference (Wolpert or any hybrid‑IDS paper). Motivation: a POSITA combining a content/point-in-time signal with a longitudinal baseline would do so because the two capture complementary information (whether this event looks malicious vs. whether this behavior is anomalous for that estate). Reasonable expectation of success: ensembling is a known accuracy-improving technique, and the patent's own FIGS. 6–7 show only incremental gains over baseline — consistent with predictable, not surprising, results.
Ground 2 — WO 2019/200317 A1 + US 2019/0319961 A1 (+ Breiman/Chen)
Use '9961 for the aggregated/group risk assessment and policy-driven handling (claim 2's incident-level scoring and claim 4's threshold suppression). Both references are Sophos, both in the same field of endeavor, both predate 2022 — a textbook KSR combination. Motivation: aggregating per‑entity risk into a group/incident score and acting on it when it crosses a threshold was an express design goal in '9961.
Ground 3 — US 2019/0319961 A1 + US 10,841,339 B2 + a security-featurization reference
US 10,841,339 B2 (Ray et al., Sophos, issued 2020‑11‑17, "Normalized indications of compromise") supplies context-sensitive labeling and normalized security telemetry. Combine with a reference teaching machine-learning feature extraction from security objects (a Webroot-family patent of the type asserted in 6:22‑cv‑00243, or a published featurization paper). Motivation: normalized, context-labeled telemetry is the natural input to a supervised classifier; using normalized labels as training targets is the obvious use of normalized labels.
Ground 4 — any of the above + conventional SOC queue ordering
For the final limitation, add a SIEM/case-management reference or simply rely on the applicant's own Background, which admits that events "can be prioritized according to their security risk" and that severity values come from a "user-defined ruleset." Admission against interest (§ 2144.03 / applicant's own specification as prior art). This is the weakest limitation in the claim.
Aggregation variants (claims 2, 5, 6)
The specification expressly lists mean, minimum, maximum, weighted sum, and "any other ensemble/voting algorithm," and expressly states the aggregation technique is "selected during training or tuning." Under In re Harza and the design-choice line, and under MPEP § 2144.04(IV) (claimed ranges/alternatives disclosed in the art), the selection among disclosed aggregation functions is not a patentable distinction. The patentee's own disclosure supplies the motivation and the closed set of alternatives.
4. Motivation to combine — the articulated rationale
For each ground, the record supports an express KSR/MPEP rationale:
- Same field / analogous art. All references are directed to enterprise network security, alert handling, and threat management. Under KSR, this weighs heavily toward combinability.
- Complementary, orthogonal signals. Content features answer "does this alert look malicious?"; temporal features answer "is this behavior anomalous for this customer/endpoint right now?" The patent itself says the context model's input layer is "orthogonal" to the content model's — that is the motivation, and it is the applicant's own characterization of why a POSITA would do it.
- Known technique applied to a known data type. Feature extraction, supervised classification, and ensembling are all routine data-science techniques; applying them to security alerts is not inventive under § 2143(A) ("combining prior art elements according to known methods to yield predictable results").
- Design incentive / known problem. Alert fatigue and false-positive overload were a documented, industry-wide problem (hence the commercial SIEM/UEBA tooling). Under KSR, a known problem supplies the motivation.
- Obvious to try. With a small, finite set of recognized modeling approaches (single content model, single temporal model, or an ensemble of both) and predictable results, this is an "obvious to try" scenario.
5. Dependent claims — likely obvious
- Claim 2 (incident-level score + prioritization): aggregating alert scores into an incident score is conventional case management; '9961's group risk assessment supports it. Obvious.
- Claim 3 (analyst feedback → storage → modify alerts → retrain): analyst-in-the-loop retraining is standard supervised-ML practice and was known in security triage. Analyst dispositions are the natural (and only cheap) source of ground-truth labels. Obvious.
- Claim 4 (suppress below threshold): threshold-based suppression is routine; the specification concedes pre-existing rulesets/thresholds. Obvious.
- Claim 5 (within-incident alert ranking): same reasoning as claim 1's ordering step. Obvious.
- Claim 6 (retrain to replace current severity value): routine model refresh. Obvious.
- Claims 7–8 (threat-case re-prioritization): routine queue reshuffling. Obvious.
- Claim 9 (semi-structured formats, e.g. JSON): the specification's own featurization recipe — flatten keys, NaN/−1/"missing val" fill, exclude id/timestamp columns, drop low-cardinality strings, collapse rare values, one-hot or token-encode — is straight out of standard tabular ML practice. Unless the granted claim recites a specific, non-obvious schema-agnostic pipeline, obvious.
6. Where the patent has its best (though limited) defenses
- Claim construction. If the granted independent claim recites the automatic featurization framework operating on arbitrary sensor schemas without human intervention — rather than generic "extract feature vectors" — the analysis moves. The obviousness case would then need art on schema-inferring / auto-ML feature pipelines (feature hashing, column-type inference, schema-agnostic encoders). I could not verify whether that language is in the granted independent claims, and flag this as the single highest-value item to check against the official claim set in USPTO Patent Center.
- The "orthogonal input layer" architecture is a permissive but arguably narrow limitation if it were claimed, though as a functional description of ensembling it likely still reads on the art.
- Objective indicia (§ 2145). I found no evidence of commercial success with a nexus, industry praise, licensing, or copying specific to this patent. FIGS. 6–7 are weak secondary evidence — an ROC/precision‑recall improvement from ensembling is the expected result of the disclosed technique, which if anything supports predictable results rather than unexpected ones. There is no long-felt-need argument available: the need was long felt and widely addressed by others (SIEM/UEBA vendors) before 2022.
7. Conclusions and verification checklist
- Claim 1 and claim 10 are, on the pre-grant claim text, vulnerable to § 103 over a security-telemetry/risk-scoring primary reference (WO 2019/200317 A1 being the closest I identified) combined with an ensembling teaching, with the queue-ordering limitation supplied by applicant-admitted background art.
- The most probative single-reference family is Sophos's own pre‑2022 subject matter — WO 2019/200317 A1 and US 2019/0319961 A1 — which is § 102(a)(1) art against this patent and squarely in the same field.
- Do not rely on my reference identifications as final. In this session I verified only that these documents exist with the general subject matter described; I did not parse them limitation-by-limitation. The '844 patent number in the Webroot litigation is my best reading of a petition appendix and is medium confidence.
To complete this properly, obtain and then chart:
- The official granted claim set of US 12,244,630 from USPTO Patent Center (unverified here).
- The actual "Citations" and "Cited By"/family listings from the Google Patents page — the section I was asked to use but did not receive.
- The prosecution history (any § 103 rejections and the applicant's arguments, which reveal the examiner's closest art).
- Full texts of WO 2019/200317 A1, US 2019/0319961 A1, and US 10,841,339 B2 to convert the confidence tags above into element-by-element citations.
I want to be direct rather than paper over it: a rigorous obviousness opinion for this patent cannot be delivered from the material I was given, because the prior-art section referenced in the task was not included in the fetched page. Everything above is a defensible framework built from the claims and from the field, not a substitute for charting the real cited art.
Generated 9/30/2026, 5:41:35 PM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
Other patents in Software Technology & Computing Systems (T)
- US 9934379I'll search for this specific patent number across USPTO and litigation sources. Let me run more targeted searches for litigation and USPTO records. Let me do one final targeted check for any litigation or Federal Circuit activity…
- US 8606819I'll search for authoritative information on this patent number before summarizing. Let me check the CAFC docket and the specific claims. US Patent 8,606,819 — Analyst Summary Scope note: I searched for the exact identifier 8606819 only…
- US 8280819I'll verify the patent's details against current sources and check for any litigation or CAFC 2026 activity. Let me search more specifically for litigation and CAFC 2026 activity involving this exact patent number. Verification status…
- US 7155451I'll verify the patent details and check for any 2026 CAFC activity. Let me check the specific CAFC docket and 2026 activity. Let me check the Federal Circuit docket 25-1651 and the current litigation status. US Patent 7,155,451 —…
- US 10353811I'll search for authoritative information on this patent, including any 2026 CAFC docket activity. Let me check for any Federal Circuit appeal activity and confirm the litigation posture. US Patent 10,353,811 — Analyst Summary Search scope…
- US 7212534I'll search for the authoritative record on this patent number and check for any 2026 CAFC activity. Now let me check for any CAFC 2026 docket activity and confirm the full claim set. Let me confirm the remaining independent claims and…
- US 6141749I'll search for authoritative information on this specific patent number, including any litigation. Let me probe specifically for litigation/docket activity and reassignment records. US Patent 6,141,749 — Summary Caveat up front: I…
- US 12554825I'll search for this specific patent number across USPTO and litigation sources. Let me dig deeper for the specific patent's claims and any 2026 CAFC activity. Let me try to locate the published application and any 2026 Federal Circuit…