Invalidity dossier

US 6715084

Firewall system and method via feedback from broad-scope monitoring for intrusion detection

Current assignee: Intellectual Ventures I LLC, Intellectual Ventures II LLC

Added 9/11/2026, 12:46:22 PM

At a glanceNo PTAB challenges10 lawsuits on fileasserted by Intellectual Ventures I LLC +1Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I have the authoritative patent text in front of me. Let me verify current status, especially for any 2026 Federal Circuit activity, via search.

Both searches returned no results. Let me try a few alternate queries to confirm.

Let me check the known Federal Circuit appeals and any 2026 activity.

US Patent 6,715,084 — Analyst Summary

Note on scope: All searches were run against the literal identifier 6715084 / 6,715,084 (and its family/docket identifiers). No 2026 CAFC docket activity was returned for this patent — see "Litigation status" below for the caveat.

Bibliographic data

Field Value
Patent number US 6,715,084 B2
Title "Firewall system and method via feedback from broad-scope monitoring for intrusion detection"
Application no. US 10/108,078
Filing date 2002-03-26
Priority date 2002-03-26
Issue date 2004-03-30
Pre-grant publication US 2003/0188191 A1 (2003-10-02)
Inventors Jeffrey A. Aaron; Thomas Anschutz
Original assignee BellSouth Intellectual Property Corp. (assignment recorded 2002-05-04)
Current assignee (as listed) Intellectual Ventures II LLC
Claim count 33 (independent claims: 1, 9, 19, 26)
Classification H04L 63/02 (firewalls / filtering policies); H04L 63/14; H04L 63/1441
Legal status Expired – Lifetime; adjusted expiration 2022-04-23

Assignment chain (per the patent record): BellSouth Intellectual Property Corp → AT&T Intellectual Property, Inc. (2011-09-22, name changes through AT&T BLS / AT&T Delaware) → AT&T Intellectual Property I, L.P. (2011-09-22) → Worcester Technologies LLC (2011-11-16) → Intellectual Ventures II LLC (2013-05-28, merger).

Family: continuation US 10/811,585 (US 2004/0221178 A1, filed 2004-03-29, abandoned); PCT/US2003/008509 (WO 2003/083659 A1); AU 2003/214237 A1.

Abstract (verbatim)

"A broad-scope intrusion detection system analyzes traffic coming into multiple hosts or other customers' computers or sites. This provides additional data for analysis as compared to systems that just analyze the traffic coming into one customer's site. Additional detection schemes can be used to recognize patterns that would otherwise be difficult or impossible to recognize with just a single customer detector. Standard signature detection methods can be used. Additionally, new signatures can be used based on broad-scope analysis goals. An anomaly is detected in the computer system, and then it is determined which devices or devices are anticipated to be affected by the anomaly in the future. These anticipated devices are then alerted to the potential for the future anomaly. The anomaly can be an intrusion or an intrusion attempt or reconnaissance activity."

Independent claims — plain language

Claim 1 (method of alerting devices). A method for alerting devices in a networked system where at least one device has a firewall. Three steps: (1) detect an anomaly using network-based intrusion detection techniques that involve analyzing data entering a plurality of hosts, servers, and computer sites; (2) determine which devices are anticipated to be affected, using pattern correlations across those hosts/servers/sites; (3) alert those anticipated devices. The core idea is broad-scope correlation for predictive alerting, not just detection at one site.

Claim 9 (method, first-device variant). A method for alerting a device to an anomaly: (1) detect an anomaly at a first device, again using network-based intrusion detection that analyzes data entering a plurality of hosts, servers, and computer sites; (2) determine a device anticipated to be affected using pattern correlations across them; (3) alert that anticipated device. (The claim text as published contains a typo, "technicques," which I have not corrected.) Dependent claim 10 adds that devices are polled in a predetermined sequential order, and the anticipated device is one not yet polled — i.e., the forecast/lead-time aspect.

Claim 19 (system). An intrusion detection and alerting system comprising: a plurality of network-coupled devices, each able to (1) sense data and send it to a data collection and processing center, and/or (2) be adjusted; plus the data collection and processing center — a computer with a firewall coupled to the network — that monitors data communicated to at least some devices, detects an anomaly using network-based intrusion detection analyzing data entering a plurality of hosts, servers, and computer sites, determines which devices are anticipated to be affected via pattern correlations, and alerts them.

Claim 26 (data collection and processing center). A data collection and processing center as such: a computer with a firewall coupled to a computer network, monitoring data communicated to the network, and detecting an anomaly using network-based intrusion detection techniques comprising analyzing data entering a plurality of hosts, servers, and computer sites. This is the broadest independent claim — it does not itself recite the alerting or prediction steps; those appear in dependents 27–29 (anticipated devices, affected devices, adjusting firewalls).

Selected dependents worth noting: claim 3 (adjust the firewall of anticipated devices responsive to detection); claim 8 and 25/33 (adjust anomaly detection sensitivity and alarm thresholds based on the detected anomaly); claims 6/14/24/32 (analyze packets received at at least two devices — the aggregation requirement); claims 11 (anomaly warning with a unique device identifier to a central analysis engine).

Litigation and post-grant status (as recorded)

District court litigation (per the patent record's litigation links):

  • S.D.N.Y. 1:13-cv-03777 — Intellectual Ventures II LLC v. JP Morgan Chase & Co. (claims 1 and 9 asserted as representative; independent claims identified as 1, 9, 19, 26)
  • D. Md. 8:14-cv-00111 — Intellectual Ventures I/II v. Capital One
  • Also: W.D. Mo. 2:13-cv-04160; D. Neb. 8:13-cv-00167; S.D. Ohio 2:13-cv-00785; N.D. Ala. 2:13-cv-01106; D. Minn. 0:13-cv-02071; N.D. Ga. 1:13-cv-02454

PTAB: IPR2014-00682 and IPR2014-00801 reached Final Written Decisions; IPR2014-00681 and IPR2014-00793 were not instituted on the merits.

Federal Circuit: appeals 14-1724, 16-1077, 17-2429, and 18-1367. In 2016-1077 (Intellectual Ventures I & II v. Capital One, decided 2017-03-07), the court affirmed the Maryland district court, which had found the '081 and '002 patents ineligible under 35 U.S.C. § 101 and had barred IV from pursuing the '084 patent's claims under collateral estoppel. So the '084 patent was not itself adjudicated § 101-ineligible in that decision; it was cut off procedurally by issue preclusion against that defendant.

CAFC 2026 dockets — result of this search

No 2026 Federal Circuit docket activity for 6,715,084 was found. Querying the patent number and combining it with "Federal Circuit 2026" / "CAFC 2026 appeal" returned no matching records. I cannot affirmatively certify that no such docket exists — search indexing for current-year dockets is imperfect. Two contextual points bear on this:

  1. The patent's recorded status is Expired – Lifetime with an adjusted expiration of 2022-04-23, which makes fresh 2026 infringement appeals improbable (though appeals in long-running matters can outlast expiry).
  2. The most recent listed Federal Circuit involvement I could verify is 2018 (18-1367) and 2017 (17-2429, 16-1077).

Uncertainty disclosures

  • The current assignee is given as Intellectual Ventures II LLC, and the original assignee as BellSouth Intellectual Property Corp; the Intermediate AT&T/Worcester assignments are from the record, not independently verified against USPTO assignment records in this session.
  • I did not retrieve the actual PTAB Final Written Decisions' outcomes (which claims, if any, were cancelled or upheld) — I can only confirm the proceedings exist and their institution status. If claim-level survival matters to your analysis, that should be pulled from the IPR documents directly.
  • The abstract, claims, dates, and bibliographic fields above are taken from the authoritative patent text supplied to me, which I treat as controlling over search results.

Generated 9/11/2026, 6:47:17 PM

Cases on file (10)

Group view →

Specific litigation cases in our database that name US patent 6715084. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2013: 4 cases4'132014: 1 case'14
Cases asserting US 6715084, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US patent 6715084. Let me search authoritative sources.

Let me search for the specific district court cases listed for this patent.

Let me search for the remaining district court cases and the Federal Circuit appeals.

Litigation Involving U.S. Patent No. 6,715,084

Important caveats up front. I was able to pull the litigation history embedded in the Google Patents record for US 6,715,084 B2 and to verify defendant identities for only a subset of the listed cases before hitting my research limit. Below I clearly separate (A) what is verified from (B) what is listed by the patent record but whose defendant/outcome I could not independently confirm. I have not auto-corrected any case number or patent number.

The patent is titled "Firewall system and method via feedback from broad-scope monitoring for intrusion detection," inventors Jeffrey A. Aaron and Thomas Anschutz, filed March 26, 2002, issued March 30, 2004, original assignee BellSouth Intellectual Property Corp., current assignee Intellectual Ventures II LLC. Legal status: Expired – Lifetime, adjusted expiration April 23, 2022. (Source: https://patents.google.com/patent/US6715084/en)

Because the patent expired in 2022 and the asserted campaign dates to 2013–2014, all known enforcement activity is historical.


A. Verified litigation

1. District court cases (patent-infringement suits by the patent owner)

Intellectual Ventures II LLC v. Commerce Bancshares, Inc. and Commerce Bank

  • Court / Jurisdiction: U.S. District Court, Western District of Missouri (W.D. Mo.)
  • Case No.: 2:13-cv-04160
  • Plaintiff: Intellectual Ventures II LLC
  • Defendants: Commerce Bancshares, Inc.; Commerce Bank, A State Chartered Trust Company
  • Filing date: 2013 (docket activity continues through 2014, with a 2017 fee/costs order)
  • Status/outcome: Defendants moved to stay pending inter partes review (Dkt. 63). On June 4, 2014, Judge Nanette K. Laughrey granted the stay and dismissed the case without prejudice, subject to reopening within 45 days of resolution (denial, final written decision under 35 U.S.C. § 318, or final appeal decision) of the pending IPRs on the patents-in-suit. Commerce had filed IPR petitions including IPR2014-00786, IPR2014-00793, and IPR2014-00801. In a September 29, 2017 order, the court denied defendants' motion for attorney fees; defendants recovered costs of $1,804.49.
  • Source: CourtListener docket, https://www.courtlistener.com/docket/[4515310](/patent/4515310)/intellectual-ventures-ii-llc-v-commerce-bancshares-inc/ ; Google Patents litigation link (W.D. Mo., 2:13-cv-04160)

Intellectual Ventures II LLC v. First National Bank of Omaha

Note: the W.D. Mo. docket references a related case, Intellectual Ventures II LLC v. BBVA Compass Bancshares, Inc., et al., which was also stayed pending IPR.

2. AIA post-grant proceedings (PTAB) — listed on the patent record

The Google Patents "Family has litigation" section lists four PTAB matters on this patent (note: IPRs are administrative validity challenges, not district-court infringement suits):

  • IPR2014-00682 — Final Written Decision issued
  • IPR2014-00801 — Final Written Decision issued
  • IPR2014-00793 — Not Instituted (Merits)
  • IPR2014-00681 — Not Instituted (Merits)

IPR2014-00793 and IPR2014-00801 are corroborated as having been filed by Commerce Bancshares/Commerce Bank (per the W.D. Mo. docket reference to "Commerce's IPR Petition in IPR2014-00793" and "-00801"). The petitioner(s) for IPR2014-00681/-00682 I could not confirm from the sources retrieved (an Exhibit cover page in IPR2014-00682 shows an assignment record bearing an "IBM EX." exhibit stamp, but I cannot state the petitioner with confidence).

3. Federal Circuit appeals — listed on the patent record

The Google Patents record lists four appeals to the U.S. Court of Appeals for the Federal Circuit:

  • 14-1724
  • 16-1077
  • 17-2429
  • 18-1367

These are consistent with appellate review arising from the W.D. Mo./D. Neb. litigation and/or the IPR final written decisions. I was not able to confirm, from retrieved sources, the specific lower-proceeding origin, appellant, or disposition of each appellate number.


B. Cases listed on the patent record whose defendant/outcome I could NOT verify

The Google Patents "Family has litigation" section also lists these district-court matters on US 6,715,084, but I was unable to retrieve the docket detail before reaching my research limit. I list them as reported by the patent record only, without asserting defendant names or outcomes:

Jurisdiction (as listed) Case No. (as listed)
Ohio Southern District Court 2:13-cv-00785
New York Southern District Court 1:13-cv-03777
Alabama Northern District Court 2:13-cv-01106
Minnesota District Court 0:13-cv-02071
Maryland District Court 8:14-cv-00111
Georgia Northern District Court 1:13-cv-02454

These 2013–2014 filings, together with the verified W.D. Mo. and D. Neb. cases, are consistent with a single coordinated enforcement campaign by Intellectual Ventures II LLC against a group of financial institutions. One retrieved docket reference ("Revised Joint Claim Construction Chart Filed in JPMC" / "Claim Construction Order in JPMC") suggests JPMorgan Chase was among the defendants, but I did not confirm which case number corresponds to it. I decline to assign specific defendants to the case numbers above without confirmation, per the instruction not to guess at identifiers.


Summary

  • Known enforcement is real and attributable to Intellectual Ventures II LLC (successor to Worcester Technologies LLC, which took the patent from AT&T; the patent originally issued to BellSouth).
  • Two district-court suits are verified: IV II v. Commerce Bancshares (W.D. Mo. 2:13-cv-04160) and IV II v. First National Bank of Omaha (D. Neb. 8:13-cv-00167). Both were resolved by stay/dismissal pending IPR (Mo.) and termination (Neb.).
  • Six additional district-court case numbers are listed on the patent record but unverified as to parties/outcomes.
  • Four PTAB IPRs touched this patent (two Final Written Decisions, two not instituted).
  • Four Federal Circuit appeal numbers are listed but unverified as to origin/disposition.
  • The patent expired April 23, 2022, so no live infringement exposure remains.

If you want, I can resume searching (PACER/CourtListener, RPX, Docket Alarm) to confirm the defendants and outcomes for the six unverified district-court cases and the four Federal Circuit appeals.

Generated 9/11/2026, 6:47:32 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Intellectual Ventures I LLC, Intellectual Ventures II LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll start by researching the PTAB proceedings that Google Patents lists for this patent, since the embedded structured data flags four IPR filings despite the ODP block saying "no proceedings."

Let me try broader queries.

The Docket Alarm result is valuable. Let me gather the remaining proceeding details and any Federal Circuit outcomes.

Generated 9/11/2026, 6:47:21 PM

Ownership chain (7)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2002-03-22 · recorded 2002-05-04 · reel 012892/0364 · Assignment

    Aaron, Jeffrey A. and Anschutz, ThomasBELLSOUTH INTELLECTUAL PROPERTY CORPORATION

    Correspondent: Jonathan M. Waldman · Woodcock Washburn

  2. 2007-04-27 · recorded 2011-09-22 · reel 026973/0346 · Change of Name

    BELLSOUTH INTELLECTUAL PROPERTY CORPORATIONAT&T INTELLECTUAL PROPERTY, INC.

    Correspondent: Marthenn Salazar · MBSS

    change of name only

  3. 2007-07-27 · recorded 2011-09-22 · reel 026973/0368 · Change of Name

    AT&T INTELLECTUAL PROPERTY, INC.AT&T BLS INTELLECTUAL PROPERTY, INC.

    Correspondent: Marthenn Salazar · MBSS

    change of name only

  4. 2007-11-01 · recorded 2011-09-22 · reel 026973/0386 · Change of Name

    AT&T BLS INTELLECTUAL PROPERTY, INC.AT&T DELAWARE INTELLECTUAL PROPERTY, INC.

    Correspondent: Marthenn Salazar · MBSS

    change of name only

  5. 2011-08-15 · recorded 2011-09-22 · reel 026946/0004 · Assignment

    AT&T DELAWARE INTELLECTUAL PROPERTY, INC.AT&T INTELLECTUAL PROPERTY I, L.P.

    internal reorg

  6. 2011-09-23 · recorded 2011-11-16 · reel 027241/0681 · Assignment

    AT&T INTELLECTUAL PROPERTY I, L.P.Worcester Technologies LLC

    Correspondent: · Turocy & Watson

    transfer-to-asserter

  7. 2013-05-23 · recorded 2013-05-28 · reel 030493/0972 · Merger

    Worcester Technologies LLCINTELLECTUAL VENTURES II LLC

    Correspondent: · Turocy & Watson

    transfer-to-asserter

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll search for the recorded assignment records, including reel/frame numbers and correspondents.

The search surfaced the actual assignment abstract of title (filed as an IPR exhibit). Let me get more precision on each link.

Assignment Reconstruction — US 6,715,084 B2

Source note. The USPTO Assignment Center was not directly queryable in this session, but the complete "Patent Assignment Abstract of Title" for Patent # 6,715,084 ("Total Assignments: 7") was located as a filed record — Petitioner's Exhibit 1014 in IPR2014-00682, filed 2014‑04‑16 (exhibit page). That exhibit prints the Assignment Center abstract verbatim and is the basis for the reel/frame data below. I flag below where the retrieved text was truncated and I am reading fields by position rather than by direct quotation.


Inventors

Inventor Employer at filing (per assignment record)
Jeffrey A. Aaron BellSouth — assignor of record to BellSouth Intellectual Property Corporation (reel 012892/0364, exec. 2002‑03‑22)
Thomas Anschutz BellSouth — co‑assignor on the same instrument

Departure pattern: No evidence of the "all inventors leave within 12 months" fire‑sale tell. To the contrary, the loop back into the file shows Jeffrey Aaron still filing as an AT&T inventor years later — e.g., US 2008/0115205 A1, "Methods, network services, and computer programs for recommending security policies to firewalls," priority 2006‑11‑13, listed in this patent's own "Cited By" set. Continued employment by the acquirer's successor undercuts (rather than supports) the departing-inventor precursor to a portfolio dump. Signal: not present.


Original assignee

BellSouth Intellectual Property Corporation, Suite 901, 824 Market Street, Wilmington, Delaware 19801 — the Delaware IP‑holding arm of BellSouth Corporation, one of the original Regional Bell Operating Companies (RBOC; wireline and wireless telecom, later also DSL/Internet services).

  • Product embodying the claims? BellSouth was a facilities‑based carrier, and this patent's claims are directed at service‑provider‑network aggregation — monitoring traffic across "a plurality of hosts, servers, and computer sites" and feeding predictive alerts back to customer firewalls (claims 1, 9, 19, 26). That is carrier/manged‑security architecture, not a shrink‑wrapped product. I cannot confirm that BellSouth commercially deployed an embodiment of the asserted claims; I found no product evidence either way. Treat "shipped a product" as unproven.
  • Current status: Acquired. BellSouth Corporation was absorbed by AT&T Inc. (SBC–BellSouth merger effective 2006‑12‑29). This is corroborated inside the patent record itself: the three BellSouth→AT&T change of name filings were executed in 2007, i.e., immediately after the merger closed (reels 026973/0346, /0368, /0386).

Assignment timeline

All seven recorded links, chronological by execution date:

  • 2002‑03‑22 (executed) / recorded 2002‑05‑04 — Reel 012892/0364

    • Conveyance: Assignment of Assignors' Interest (4 pages)
    • Assignor: Aaron, Jeffrey A. and Anschutz, Thomas
    • Assignee: BellSouth Intellectual Property Corporation, Suite 901, 824 Market Street, Wilmington, DE 19801
    • Correspondent: Jonathan M. Waldman, Woodcock Washburn LLP, One Liberty Place, 46th Floor, Philadelphia, PA 19103‑7301. Single appearance for this correspondent on this chain — not flagged as a repeat player.
    • Context: Original employment/invention assignment to the operating company's IP subsidiary.
  • 2007‑04‑27 (executed) / recorded 2011‑09‑22 — Reel 026973/0346

    • Conveyance: Change of Name
    • Assignor: BellSouth Intellectual Property Corporation
    • Assignee: AT&T Intellectual Property, Inc.
    • Correspondent: Marthenn Salazar (MBSS), 4140 Parklake Ave, Suite 600, Raleigh, NC 27612. This corporate‑secretary‑style correspondent recurs across the three 026973 change‑of‑name reels — see signal 3.
    • Context: Change of name only — consequence of AT&T Inc.'s acquisition of BellSouth (closed 2006‑12‑29).
  • 2007‑07‑27 (executed) / recorded 2011‑09‑22 — Reel 026973/0368

    • Conveyance: Change of Name
    • Assignor: AT&T Intellectual Property, Inc.
    • Assignee: AT&T BLS Intellectual Property, Inc.
    • Correspondent: same MBSS/Salazar series as 026973/0346 (fields truncated in the retrieved exhibit text — stated as likely, not directly read).
    • Context: Change of name only — intra‑AT&T rebranding step.
  • 2007‑11‑01 (executed) / recorded 2011‑09‑22 — Reel 026973/0386

    • Conveyance: Change of Name
    • Assignor: AT&T BLS Intellectual Property, Inc.
    • Assignee: AT&T Delaware Intellectual Property, Inc.
    • Correspondent: same MBSS/Salazar series (same truncation caveat).
    • Context: Change of name only — the last step before the operating company's IP was parked in an L.P.
  • 2011‑08‑15 (executed) / recorded 2011‑09‑22 — Reel 026946/0004

    • Conveyance: Assignment of Assignors' Interest
    • Assignor: AT&T Delaware Intellectual Property, Inc.
    • Assignee: AT&T Intellectual Property I, L.P., 645 E. Plumb Lane, Reno, Nevada 89502
    • Correspondent: not captured in the retrieved excerpt.
    • Context: Internal reorganization — a true assignment, consolidating AT&T's patent holdings into the AT&T IP I, L.P. monetization vehicle.
  • 2011‑09‑23 (executed) / recorded 2011‑11‑16 — Reel 027241/0681

    • Conveyance: Assignment of Assignors' Interest
    • Assignor: AT&T Intellectual Property I, L.P.
    • Assignee: Worcester Technologies LLC, 800 Delaware Avenue, c/o Delaware Corporations LLC, Wilmington, DE
    • Correspondent: Turocy & Watson, LLP, 127 Public Square, 57th Floor, Key Tower, Cleveland, OH 44114. Recurs — the same firm is correspondent on the next (merger) reel. See signal 3.
    • Context: Transfer to asserter. The patent leaves the operating company for a single‑purpose licensing LLC one month after the AT&T internal consolidation.
  • 2013‑05‑23 (executed) / recorded 2013‑05‑28 — Reel 030493/0972

    • Conveyance: Merger
    • Assignor: Worcester Technologies LLC
    • Assignee: Intellectual Ventures II LLC, 2711 Centerville Rd, Suite 400, Wilmington, Delaware 19808
    • Correspondent: Turocy & Watson LLP (repeat — same firm as 027241/0681).
    • Context: Defensive‑aggregation? No — transfer‑to‑asserter. The Worcester shell is merged into the parent IV entity, which then asserts.

Timeline diagram

timeline
    title Ownership of US 6715084
    2002 : Filed by BellSouth
         : Inventors assign to BellSouth IP Corp
    2007 : BellSouth renamed AT&T IP Inc
         : Renamed AT&T BLS IP Inc
         : Renamed AT&T Delaware IP Inc
    2011 : Assigned to AT&T IP I LP
         : Sold to Worcester Technologies LLC
    2013 : Merged into Intellectual Ventures II LLC
         : First infringement suits filed
    2022 : Patent expires

NPE / troll-pattern signals

1. Shell-entity transfer — PRESENT.
Reel 027241/0681 (exec. 2011‑09‑23) moves the patent from AT&T Intellectual Property I, L.P. to Worcester Technologies LLC, at 800 Delaware Avenue, c/o Delaware Corporations LLC — a registered‑agent service address. A single‑purpose licensing LLC taking title from a carrier, with no product line, is the archetype. Reinforced by reel 030493/0972 where that LLC is extinguished by merger into Intellectual Ventures II LLC.

2. Known asserter in the chain — PRESENT.
Current assignee Intellectual Ventures II LLC is a recognized high‑frequency patent plaintiff and appears on NPE/asserter directories (Unified Patents litigation portal, RPX). It is the entity that asserted this patent in the 2013 wave (S.D.N.Y. 1:13‑cv‑03777 IV II v. JP Morgan Chase, D. Md. 8:14‑cv‑00111 IV v. Capital One, plus the 2013 filings in Missouri, Nebraska, Ohio, Alabama, Minnesota, Georgia). Prior assignee Worcester Technologies LLC is part of the IV acquisition‑shell naming family (cf. the parallel "Worcester" entities used for the AT&T and other portfolios).

3. Repeat correspondent across the chain — PRESENT.
Turocy & Watson, LLP (127 Public Square, 57th Floor, Key Tower, Cleveland, OH 44114) is correspondent of record on two consecutive links of the same chain: reel 027241/0681 (AT&T IP I → Worcester) and reel 030493/0972 (Worcester → IV II, merger). This is exactly the pattern the brief flags — the named LLC changes, the recording firm does not. Separately, Marthenn Salazar / MBSS appears as correspondent on the cluster of reels 026973/0346, 026973/0368, and 026973/0386, but that is the operating company's corporate‑secretary function, not an NPE recording agent, so it is a recurrence of a different (benign) character.

4. Cascading transfers — PRESENT.
Two consecutive transfers inside ~20 months: AT&T IP I, L.P. → Worcester (exec. 2011‑09‑23) → IV II by merger (exec. 2013‑05‑23). Both links share the same correspondent (Turocy & Watson) and the assignees are both Delaware/Wilmington entities with a common address cluster (800 Delaware Ave / 2711 Centerville Rd).

5. Pre-litigation transfer — PRESENT.
The merger conveying title to Intellectual Ventures II LLC was executed 2013‑05‑23 and recorded 2013‑05‑28. The first infringement suits naming this patent are the 2013 filings in the patent record (e.g., S.D.N.Y. 1:13‑cv‑03777; N.D. Ga. 1:13‑cv‑02454; D. Minn. 0:13‑cv‑02071). Title therefore landed in the asserting entity within roughly one to three months before the assertion campaign — well inside the six‑month window. This is a clean standing‑record arrangement.

6. Bankruptcy fire‑sale — NOT PRESENT.
AT&T was not a bankrupt seller; the 2011 divestiture to Worcester occurred while AT&T was a solvent, publicly traded operating company. This was monetization, not distress liquidation.

7. Privateering — UNCLEAR.
The shape fits (operating carrier → NPE shell → suits against banks/enterprises), and the record shows the transfer (reel 027241/0681) followed by IV II's 2013 campaign. What is missing is the evidentiary hinge for privateering proper: I have no SEC 10‑K/8‑K disclosure, license‑back grant, or revenue‑sharing term showing AT&T stood behind the assertions or benefited from them. Without that, the transfer is better characterized as an outright sale than as proven privateering. Marked unclear, not absent — the timing is suggestive but the corporate‑interest evidence is not in the record I retrieved.

8. Defensive aggregator (anti‑NPE) — NOT PRESENT.
The chain terminates at Intellectual Ventures II LLC, an asserting entity — not RPX, AST, LOT Network, Unified Patents, or OIN. The patent was not neutralized; it was weaponized. (Its status today is merely Expired – Lifetime, adjusted expiration 2022‑04‑23, which neutralizes it by the passage of time, not by defensive acquisition.)


Verdict

NPE — high confidence.

Four independent strong signals converge on the record: (i) a shell‑entity transfer out of the operating company at reel 027241/0681 (exec. 2011‑09‑23, assignee Worcester Technologies LLC, c/o registered‑agent address); (ii) a known asserter as current owner per reel 030493/0972 (Intellectual Ventures II LLC, exec. 2013‑05‑23); (iii) a repeat correspondent, Turocy & Watson LLP, on both NPE‑side reels; and (iv) a pre‑litigation transfer, with title to the asserting entity recorded 2013‑05‑28 immediately ahead of the 2013 suit wave. The only countervailing fact — inventors Aaron and Anschutz remaining with AT&T — speaks to portfolio quality, not to ownership character, and does not defeat the NPE classification.

Verify at: USPTO Assignment Center (search patent number 6715084) — or the legacy interface at assignment.uspto.gov/patent. The IPR exhibit reproducing the abstract is at docketalarm.com, IPR2014‑00682 Ex. 1014.


Uncertainty disclosures

  • Reel/frame formats. The exhibit text rendered some pairs with a separator and some without (e.g., "026973 0346", "026946 0004", "027241 0681", "030493 0972"). I have normalized all to NNNNNN/NNNN form; the six‑digit reels are almost certainly correct, and I did not invent digits.
  • Gaps in the retrieved text. The exhibit snippet was truncated in places (marked "…"). The correspondents for reels 026973/0368, 026973/0386, and 026946/0004, and the exact recorded date for 026946/0004, are inferred by position rather than read directly. Those three correspondents should be confirmed before being relied on as evidence of anything.
  • Execution dates vs. recordation dates. Note the 20‑month lag on the three 026973 change‑of‑name filings (executed 2007, recorded 2011‑09‑22) and on 027241/0681 (executed 2011‑09‑23, recorded 2011‑11‑16). Where these differ, execution date governs the corporate‑history narrative and recording date governs the standing/notice narrative; I have used them accordingly above.
  • No conflict found between this reconstruction and the previously generated summary section; the two agree on the chain order, the intermediate AT&T/Worcester links, and the IV II terminus. The new information this section adds is the reel/frame numbers, the correspondents, and the "Total Assignments: 7" count.

Generated 9/11/2026, 6:48:01 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research the back-cited prior art for US 6,715,084 via the USPTO and related databases.

Let me pull the Justia and USPTO records for the back-cited references.

Important finding first: the requested citation list is not in the record I can verify

I was asked to look at "each patent citation for 6715084" and map them to claims under 35 U.S.C. § 102. I have to be straight with you about a gap before giving you anything else, because the operating rules for this analysis forbid fabricating references:

The authoritative patent text supplied for US 6,715,084 does not contain a "References Cited" / "Cited Patent" (examiner-cited prior art) section. The fetched Google Patents record includes the front of the document (bibliographic data, family, assignments, litigation), the forward citation table ("Cited By (66)"), and "Families Citing this family (63)" — but it contains no backward-citation table. Searches against USPTO PatentCenter, Google Patents, Justia, FreePatentsOnline, uspto.report, and Docket Alarm did not return a verifiable list of the examiner-cited U.S. patent documents, foreign patent documents, or non-patent literature for this patent within this session.

Consequently, I cannot enumerate specific examiner-cited references and assign them to claims without risking fabrication. What follows is (a) what I can verify, (b) a firm correction on a likely misreading of "the citations for 6715084," and (c) the analytical framework and best-available leads so the § 102 work can be completed properly.


1. Verification of the patent identifier (literal)

Field Verified value
Patent number US 6,715,084 B2
Application no. 10/108,078
Grant date 2004-03-30
Pre-grant pub. US 2003/0188191 A1 (2003-10-02)
Inventors Jeffrey A. Aaron; Thomas Anschutz
Original assignee BellSouth Intellectual Property Corporation
Title "Firewall system and method via feedback from broad-scope monitoring for intrusion detection"

Sources that returned the literal number 6715084 (and not a similar number): Google Patents (authoritative fetch, https://patents.google.com/patent/US6715084/en); FreePatentsOnline, https://www.freepatentsonline.com/6715084.html (returned full 33-claim text matching the supplied text verbatim); Docket Alarm PTAB record for IPR2014-00682, Inter Partes Review of U.S. Pat. 6715084, https://www.docketalarm.com/cases/PTAB/IPR2014-00682/Inter_Partes_Review_of_U.S._Pat._6715084/ — whose Exhibit 1014 reproduces the USPTO Assignment Abstract of Title confirming Patent # 6715084, Publication # 20030188191, Issue Dt 03/30/2004, Application # 10108078, Filing Dt 03/26/2002.

I found no evidence that the number resolves to anything other than this patent.


2. Correction: the 66 "Cited By" references are not § 102 prior art

The supplied record's citation tables are forward citations — later documents that cite the '084 patent. Every entry in "Cited By (66)" has a priority or filing date after 2002-03-26 (the '084 filing date). Examples from the authoritative text:

  • US 2004/0221178 A1 — actually a continuation of '084 itself (Aaron et al.), not prior art
  • US 2005/0066193 A1 (Overby, priority 2003-09-22)
  • US 2006/015715 A1 (Anderson, priority 2004-07-16)
  • US 7,461,418 B1 / US 7,506,360 B1 (Mirage Networks, priority 2002-10-01)
  • US 8,819,285 B1 (Trustwave, priority 2002-10-01)

None of these can anticipate or render obvious the '084 claims under § 102 or § 103, because they all post-date the '084 priority date of 2002-03-26. Treating that table as "prior art for 6715084" would be an error. (The "Families Citing this family (63)" table is likewise forward-only.)

Note the one date worth flagging: US 7,461,418 B1 and US 7,506,360 B1 carry a 2002-10-01 priority date — six months after '084, so still not § 102 art against it, but they are the closest forward citations date-wise.


3. Closest verifiable "related citation" material

The only citation-like entries I could verify that touch '084 are its own family members, which are not prior art to it (same disclosure, same or later dates):

Document Date Relationship § 102 status vs. '084
US 2003/0188191 A1 pub. 2003-10-02 '084's own pre-grant publication Not art
US 2004/0221178 A1 filed 2004-03-29 Continuation of '084 (abandoned) Not art
US 2003/0188190 A1 (Aaron et al.) pub. 2003-10-02 Co-filed sibling BellSouth application, same inventors, surfaced in a Justia "Referenced Cited" table of US 7,555,774 Not art if inventive entity is identical — § 102(e)/§ 102(a)(2) require the reference be by "another"

That last row is worth a manual check: search results show US 2003/0188190 A1 as "Aaron et al." with the same 2003-10-02 publication date. If its inventive entity is not identical to '084's, its § 102(e) date could matter; if it is identical (same two inventors, common assignee), it is disqualified as prior art. I could not retrieve the '190 application's full inventor list to confirm, so I am flagging this rather than asserting it.


4. Best lead for the actual prior-art list: the IPR record

The single most reliable source for prior art actually asserted against this patent is the PTAB filings already visible in the record:

  • IPR2014-00682 — Final Written Decision
  • IPR2014-00801 — Final Written Decision
  • IPR2014-00681 — Not Instituted (merits)
  • IPR2014-00793 — Not Instituted (merits)

Petitioner exhibits in these proceedings (e.g., Exhibit 1014 in IPR2014-00682) are the mechanism by which the challenger introduced prior art. Exhibits numbered 1001–1014+ in each petition will be the asserted references, and the petitions themselves will contain the § 102/§ 103 claim charts. I could not retrieve the exhibit lists or the Final Written Decisions' text in this session, so I cannot tell you which claims (if any) were cancelled or which references were credited.


5. § 102 framework for the '084 claims (grounded in the authoritative claim text)

Since I can't name verified references, here is the test any § 102 reference would need to pass. This also tells you how narrow the prior-art window really is.

Independent claim 1 requires all three of:

  1. detecting an anomaly using network-based IDS comprising analyzing data entering into a plurality of hosts, servers, and computer sites;
  2. determining which devices are anticipated to be affected using pattern correlations across that plurality; and
  3. alerting those anticipated devices.

A single-reference § 102 anticipation would need to disclose the predictive, cross-site element (step 2) — the patent's stated point of novelty. This is why the Background section expressly distinguishes the prior art it is overcoming:

  • Address/protocol packet-filtering firewalls (allow-lists of source addresses, FTP/HTTP/POP protocol lists) — see Background, "One fundamental technique used by firewalls…"
  • Source-routing bypass defenses in routers — Background discussion of router filtering rules.
  • Statistical anomaly detection — Background, "Anomaly detection systems look for statistically anomalous behavior…" (the archetype here being Denning-style statistical IDES work; I am not asserting a specific examiner citation).
  • Expert / rule-based systems layered on anomaly detection.
  • Signature/pattern-detection misuse systems using network sensors — Background, "A signature mechanism uses network sensors…"
  • Single-customer IDS products — Background, "Intrusion detection products and services presently available are directed to the analysis of a single customer's data… but lack the capability to perform broad-scope intrusion analysis/detection."

Independent claim 9 is narrower in one respect and broader in another: the anomaly is detected at a first device, and the anticipation test turns on cross-site pattern correlation to identify a not-yet-affected device. Dependent claim 10 adds the polling-order limitation (anticipated device = one not yet polled).

Independent claim 19 is a system claim requiring (i) devices that sense data and/or are adjustable, plus (ii) a data collection and processing center comprising a computer with a firewall.

Independent claim 26 is the broadest: a data collection and processing center = a computer with a firewall coupled to a network, monitoring data and detecting an anomaly by analyzing data entering a plurality of hosts, servers, and computer sites. It recites no alerting, no prediction, and no correlation — so it is the claim most exposed to a § 102 reference describing a central, firewall-equipped network monitoring node. Claims 27–29, 31–33 add the differentiators (anticipated devices, affected devices, firewall adjustment, packet-pattern analysis across ≥2 devices, sensitivity/threshold adjustment).

Practical consequence: to anticipate claim 26, a reference need only show a firewall-bearing central collection point performing multi-site network-based intrusion detection. To anticipate claims 1 and 9, the reference must additionally show predictive cross-site pattern correlation and alerting. The gap between those two burdens is where the real § 102 analysis of this patent lives.


6. What I recommend doing next to get the real references

  1. USPTO PatentCenter → US 10/108,078 → "References Cited" tab. This is the authoritative examiner-cited list and is where the § 102 mapping must start. I could not render this page in-session.
  2. FreePatentsOnline (https://www.freepatentsonline.com/6715084.html) — its bibliographic block normally carries the "References Cited" table; the returned page text I received was truncated to the claims/description and did not include it.
  3. PTAB petitions IPR2014-00682 / -00801 / -00681 / -00793 — pull Exhibits 1001 onward; these are the references the challenger believed could invalidate specific claims.
  4. Cross-check the WO 2003/083659 A1 international search report, which will list the ISR-cited prior art for the same family.

Uncertainty disclosures (explicit)

  • I did not retrieve and therefore cannot report the examiner-cited prior-art references for US 6,715,084. Any specific list of references-with-claims I produced without that source would be fabricated, so I have not produced one.
  • The § 102 test framework in § 5 above is derived directly from the authoritative claim text and Background; the field-context references (statistical anomaly detection, signature IDS, rule-based systems) are the categories the patent itself names — I have not verified which specific documents the examiner cited in those categories.
  • The § 102(e)/§ 102(a)(2) status of US 2003/0188190 A1 depends on whether its inventive entity is identical to '084's; I could not confirm the inventor list, so this remains open.
  • The forward-citation dates (including the 2002-10-01 priority of US 7,461,418 and US 7,506,360) are taken from the authoritative supplied text and are given literally.

Generated 9/11/2026, 6:47:52 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll research the prior art record for this patent, since the fetched page did not include the examiner's "References Cited" table (it only included the forward-citation lists).

Let me pull the actual IPR grounds and the key prior-art patents used against this patent.

Obviousness Analysis — US 6,715,084 B2 under 35 U.S.C. § 103

0. Threshold: what "the Prior Art section of this page" actually contains

Before the analysis, a scope correction that materially affects how this must be done.

The Google Patents page for US 6,715,084, as fetched, does not contain a "References Cited" / "Patent Citations" (examiner-cited) table. What it contains under the prior-art heading is:

  1. Prior-art keywords (examiner/search-engine tags): anomaly, devices, network, data collection, data — this is the classification keyword field, not a reference list.
  2. "Cited By (66)" — a forward citation list (documents that cite the '084 patent). Most of these post-date the '084 priority date and are therefore not § 102/§ 103 prior art against it; only a handful have pre-2002‑03‑26 priority (notably US 2002/0032774 A1, Kohler; and US 2002/0049899 A1, Kenworthy).
  3. "Families Citing this family (63)" — the patent's own family members and siblings, not prior art.

Because the operative evidence — the examiner's cited art and the asserted art in the IPR petitions — is absent from the fetched page, I supplemented it with targeted searches. The result is a mixed-confidence record, and I label each reference VERIFIED (I retrieved and read substantive text) or IDENTIFIED, NOT VERIFIED (existence/identifier confirmed, disclosure not read). This matters: an obviousness conclusion built on an unverified reference is not a conclusion, it is a hypothesis.

Contradiction flagged between previously generated sections: the prior summary states no 2026 Federal Circuit activity was found and gives the patent's status as expired 2022‑04‑23 (consistent with the page). The task prompt's "current date" is April 26, 2026, while the page fetch timestamp and the session date are 2026‑09‑11. This does not change the § 103 analysis (validity is assessed as of the 2002‑03‑26 filing), but the dates should not be silently reconciled.


1. Governing framework and the level of ordinary skill

Statute: The application was filed 2002‑03‑26 with a 2002‑03‑26 priority date. Pre‑AIA § 103(a) governs. Prior art must predate 2002‑03‑26 under §§ 102(a), (b), (e), or (g).

Standards applied:

  • Graham v. John Deere Co., 383 U.S. 1 (1966) — scope/content of the prior art; differences; level of ordinary skill; secondary considerations.
  • KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007) — the combination need not be taught expressly; an "articulated reasoning with a rational underpinning" suffices, including known-technique-to-improve-similar-device, predictable variation, design incentives/market forces, and "obvious to try" where the set of options is small and predictable.
  • MPEP § 2143 rationales, applied below.

Level of ordinary skill (POSITA): A person with a bachelor's degree in computer science/electrical engineering plus approximately 2–4 years of experience in network security, or a master's degree with 1–2 years of experience, familiar with TCP/IP packet structures, firewall packet-filtering rules, signature-based and statistical/anomaly-based intrusion detection, and SNMP/agent-based network management. This is not a narrow, esoteric skill set — the '084 specification itself describes the components as "commercial-off-the-shelf products."

Notable admission of record: the '084 Background expressly concedes the state of the art. It states that "a router may have a set of rules for inbound messages, a set of rules for outbound messages and a set of rules for source routing messages"; that anomaly detection, expert systems, and signature mechanisms are all known; and that "intrusion detection products and services presently available are directed to the analysis of a single customer's data." That last sentence is an admission that the only thing missing from the art was the aggregation scope — which frames nearly the entire § 103 question. It also states the motivation outright: "A need exists for an intrusion detection system which can provide early warning of potential misuses and intrusions with greater knowledge than can be obtained from detection at a single customer's premises."


2. The prior art references

Ref Identifier Date / § 102 status What it discloses Confidence
R1 US 6,321,338 B1 — Porras & Valdes, "Network Surveillance" (SRI International) App. 09/188,739 filed 1998‑11‑09; issued 2001‑11‑20. § 102(e) art as of 1998‑11‑09 (and § 102(a) as of issuance). Hierarchical, distributed network intrusion detection with cross-domain correlation and predictive sensitization of not-yet-affected domains; automated reconfiguration of network components including firewalls; adaptive analysis scope VERIFIED (full text retrieved — abstract, all 27 claims, and description)
R2 US 2002/0049899 A1 — Kenworthy, "Network attached device with dedicated firewall security" Priority 1998‑09‑01; published 2002‑04‑25 (12 days after the '084 filing) A network-attached appliance with dedicated firewall security IDENTIFIED, NOT VERIFIED (listed on the fetched page's "Cited By" list; § 102(e) date depends on whether the relied-upon disclosure was in the 1998 parent or was new matter in a later continuation — a genuine date risk)
R3 US 2002/0032774 A1 — Kohler, "Thwarting source address spoofing-based denial of service attacks" Priority 2000‑09‑07; published 2002‑03‑14 (before the '084 filing) Filtering/response at network elements to defeat spoofed-source attacks IDENTIFIED, NOT VERIFIED
R4 US 6,405,318 B1 — Rowland Issued 6/2002 (after the '084 filing date); § 102(e) date = its US filing date Intrusion-detection/monitoring system IDENTIFIED, NOT VERIFIED — I confirmed the numeral/date appear in a reference list of a related patent and in an IPR exhibit index, but did not retrieve its disclosure. I decline to characterize its teachings.
R5 US 7,237,264 B1 — Graham Appears as Petitioner's Exhibit 1006 in IPR2014‑00682 (Docket Alarm index of the Inter Partes Review of U.S. Pat. 6,715,084) Network security / intrusion detection prior art relied on by the petitioner IDENTIFIED, NOT VERIFIED — its presence in the petition record strongly implies the petitioner used it as prior art, but I could not retrieve the petition's Grounds or the Final Written Decision in this session.
R6 Porras et al., "EMERALD: Event Monitoring Enabling Responses to Anomalous Live Disturbances," 20th NISSC, Oct. 9, 1997 Printed publication, 1997 → § 102(b) art Distributed, hierarchically correlated intrusion detection across an infrastructure, with automated response IDENTIFIED as of record (expressly cited in R1's "Other References"); content at title level only
R7 Debar et al., "Towards a Taxonomy of Intrusion-Detection Systems," Computer Networks 31 (1999) 805–822; Snapp et al., "DIDS" (1991); Lindqvist & Porras, "P-BEST" (Oct. 25 1998) Pre‑2002 → § 102(b) Taxonomy, distributed IDS (DIDS), and production-based misuse detection IDENTIFIED as of record (listed in R1's "Other References"); content at title level only

Why R1 dominates this analysis. R1 is not a peripheral reference. It is a 1998‑priority SRI/DARPA patent whose entire architecture is the multi-site, hierarchically-correlated intrusion detection system the '084 patent claims, and whose text contains near-verbatim support for the allegedly novel predictive/feedback limitations. Key verified passages:

  • Scope across many sites: "Domain monitors 16d–16e perform surveillance over all or part of a domain … Domain monitors 16d–16e correlate intrusion reports disseminated by individual service monitors 16a–16c, providing a domain-wide perspective of activity (or patterns of activity)."
  • Wide-scope correlation: "Enterprise monitors 16f correlate activity reports produced across the set of monitored domains." The enterprise monitor "focuses on network-wide threats such as Internet worm-like attacks, attacks repeated against common network services across domains, or coordinated attacks from multiple domains against a single domain."
  • Predictive alerting of devices not yet affected — the core of claims 1 and 9: "As an enterprise monitor 16f recognizes commonalities in intrusion reports across domains … the monitor 16f can help domains 12a–12c counter the attack and can sensitize other domains 12a–12c to such attacks before they are affected." And: "Domain monitors … may use such reports to dynamically sensitize their local service monitors to malicious activity found to be occurring outside a domain."
  • Automated firewall/network-component reconfiguration — the core of claims 3, 21, 29: "Countermeasures range from very passive responses, such as report dissemination to other monitors 16a–16f or administrators, to highly aggressive actions, such as severing a communication channel or the reconfiguration of logging facilities within network components (e.g., routers, firewalls, network services, audit daemons)."
  • Adjusting detection sensitivity/thresholds based on detected events — claims 8, 18, 25, 33: "The resolver 20 can also submit runtime configuration requests to the analysis engines 22, 24, for example, to increase or decrease the scope of analyses (e.g., enable or disable additional signature rules) based on various operating metrics. These configuration requests could be made as a result of encountering other intrusion reports from other subscribers."
  • Analyzing packet data — claim 5/13/23/31: "an event record can be formed from data included in the header and data segment of a network packet"; event streams derived from "pass-through traffic," "packets having a common protocol," and "packets targeting ports to which an administrator has not assigned any network service."
  • Aggregation of packets/reports from multiple devices — claims 6, 14, 24, 32: R1 claim 12–15: "transmitting the event record to a network monitor … [that] receives event records from multiple network monitors," wherein such a monitor "correlates activity in the multiple network monitors based on the received event records."
  • Firewalls as monitored network entities — claim 1's "at least one … device having a firewall": "Network entities include gateways, routers, firewalls, or proxy servers."
  • Hosts and servers: "each domain 12a–12c includes one or more computers offering local and network services"; network services include "mail, HTTP, FTP, remote login, network file systems, finger, Kerberos, and SNMP."

3. Claim chart — independent claims

Claim 1 (method; broad-scope detection → prediction → alert)

Limitation Disclosure Status
"detecting an anomaly in the networked computer system using network-based intrusion detection techniques comprising analyzing data entering into a plurality of hosts, servers, and computer sites" R1: service/domain/enterprise monitors analyze packet-derived event streams across "one or more computers offering local and network services" in domains 12a–12c, correlating at the enterprise layer Disclosed
"determining which of the plurality of devices are anticipated to be affected … by using pattern correlations across the plurality of hosts, servers, and computer sites" R1: enterprise monitor recognizes "commonalities in intrusion reports across domains (e.g., the spreading of a worm or a mail system attack repeated throughout the enterprise)" and identifies domains that will be hit next Disclosed
"alerting the devices that are anticipated to be affected" R1: "can sensitize other domains 12a–12c to such attacks before they are affected"; domain monitors "dynamically sensitize their local service monitors" Disclosed
Firewall present on at least one device R1: network entities "include gateways, routers, firewalls, or proxy servers" Disclosed
"anomaly" R1 claim 1: "determining whether the difference … indicates suspicious network activity"; anomaly scoring engine Disclosed

Assessment: Claim 1 is, on this record, obvious over R1 alone — and arguably anticipated by R1 alone. Because § 103 was the question asked, the safer framing is single-reference obviousness (§ 103(a) over R1), with anticipation noted as an additional, stronger risk that should be evaluated claim-by-claim against R1's full text.

Claim 9 (method; "detected at a first device" variant)

Identical substance to claim 1 with the locus of detection moved to "a first device." R1 discloses exactly this: detection occurs at a service monitor (the first device, local to a network entity), the result is propagated as an event/intrusion report, and the domain/enterprise monitor determines which other domains are imminently at risk and sensitizes them. The "central analysis engine" of dependent claim 11 maps to R1's domain/enterprise monitor; R1's subscription-list "includes network address information and public keys used by the monitor to authenticate potential clients and servers," and its intrusion reports identify the reporting monitor — supplying the "unique device identifier" element.

Claim 19 (system) and Claim 26 (data collection and processing center)

Claim 19 adds: a plurality of network-coupled devices, each able to "(1) sense data and provide the data to a data collection and processing center, and (2) be adjustable"; plus the center itself being "a computer with a firewall."

Claim 26 is broader still — it recites the center monitoring data, detecting an anomaly via network-based IDS analyzing data entering a plurality of hosts, servers, and computer sites, and nothing else. It omits alerting, prediction, correlation, and firewall adjustment entirely (those appear only in dependents 27–29). Claim 26's scope sits very close to R1's disclosed monitor architecture.

  • "Devices adapted to sense data and provide the data to a data collection and processing center": R1's service monitors 16a–16c and third-party modules 28 supplying event records to analysis engines.
  • "Devices … adjustable": R1's network components are reconfigurable ("severing a communication channel or the reconfiguration of … routers, firewalls, network services, audit daemons").
  • "A computer with a firewall": R1 does not recite a firewall at the monitoring computer specifically. This is the one element requiring either a secondary reference or a "design choice / obvious to try" rationale — see § 5.

4. Claim chart — dependent claims

Claim Limitation Primary support Notes
2 Determine and alert devices already affected R1: reports are disseminated both to affected domains and to neighbors; the resolver's countermeasures are invoked on reports of activity already observed Straightforward
3 (also 21, 29) Adjust the firewall of anticipated devices responsive to detection R1: "reconfiguration of logging facilities within network components (e.g., routers, firewalls …)" — but note R1's express example is logging facilities, not filtering rules. Combine with R2/R3, or with the '084's own Background admission that firewalls use configurable inbound/outbound/source-routing rule sets Weakest link in the chain — see § 5
4, 12, 22, 30 Anomaly = intrusion / attempt / reconnaissance R1: signature engine detects "address spoofing, tunneling, source routing, SATAN attacks," port scanning (SYN-RST intensity measures), "doorknob rattling," intelligence gathering Disclosed
5, 13, 23, 31 Analyze data packets against predetermined patterns R1: signature engine "maps an event stream against abstract representations of event sequences that are known to indicate undesirable activity"; threshold analysis Disclosed
6, 14, 24, 32 Packets received at at least two devices R1 claims 12–15 (event records from multiple network monitors; correlation across multiple monitors) Disclosed — this limitation is squarely met
7 Recognition of intrusion + automated response R1 resolver invokes response methods automatically ("countermeasure handlers," response methods 48) Disclosed
8, 18, 25, 33 Adjust anomaly detection sensitivity and alarm thresholds based on the detected anomaly R1: resolver "increase or decrease the scope of analyses (e.g., enable or disable additional signature rules) based on various operating metrics," triggered by "intrusion reports from other subscribers"; "monitors 16 can be configured to accept configuration requests from only higher-level monitors" Disclosed — nearly verbatim
10 Devices polled in predetermined sequential order; anticipated device = one not yet polled Not disclosed by R1 — R1 teaches the opposite. R1 expressly prefers subscription-based dissemination "without requiring the overhead of synchronous polling" The single strongest non-obviousness argument in the patent
11 Anomaly warning from first device to central analysis engine, with unique device identifier R1: service→domain→enterprise report propagation; subscription list contains "network address information"; reports identify the reporting entity Disclosed / obvious
15 Alerting a firewall associated with the device R1: firewalls are network entities in the monitored hierarchy Disclosed
16 Electronic notification to device or its administrator R1: "administrator interface is simply a subscribing service to which the resolver may submit reports"; reports to administrators expressly contemplated Disclosed
17 Controlling the device R1: reconfiguration of network components; severing communication channels Disclosed

5. The combinations, with articulated motivations

Combination A (primary): R1 alone — single-reference obviousness

Rationale (KSR, known-technique-to-improve-similar-device + predictable variation): R1 already discloses multi-site, hierarchically-correlated, predictive intrusion detection with automated reconfiguration of firewalls and analysis engines. The only "difference" left in claims 1, 9, 19, and 26 is a change of scale and labeling: from an enterprise's domains to a service provider's multiple customer sites, and from "network monitors" to "a data collection and processing center." Widening the monitored population is a predictable, mechanical variation whose benefits (better pattern recognition, fewer false positives, earlier warning) are exactly the benefits R1 already claims for its enterprise layer. Rationale stated in the reference itself: R1 says "Interdomain event analysis is vital to addressing more global, information attacks against the entire enterprise." A POSITA reading R1 in 2002 and asked to improve multi-customer IDS would do precisely this.

Combination B: R1 + R6 (EMERALD) — reinforcing the correlation/response element

EMERALD (1997) is a § 102(b) printed publication addressing "Event Monitoring Enabling Responses to Anomalous Live Disturbances" — i.e., large-scale distributed correlation with automated response. Motivation: both are Porras-lineage work addressing the same problem (detecting attacks that are only visible across many monitored points); a POSITA would combine them because EMERALD generalizes the correlation-and-response architecture to a large, live infrastructure, which is what the '084 claims. Motivation is the overlapping problem, not hindsight.

Combination C: R1 + R2 (or R3) — supplying express dynamic firewall rule adjustment

If the PTAB or a court credits the argument that R1's "reconfiguration of logging facilities within … firewalls" does not expressly reach filtering rules, then claims 3, 21, and 29 need a secondary reference disclosing firewall rule adjustment in response to detected attack conditions. R2 (network-attached device with dedicated firewall security) or R3 (filtering responses to spoofed-source DoS attacks) would serve. Motivation: the '084 Background itself supplies it — "if this somewhat lax configuration is maintained even in the face of attacks … then overall security is lost. So it is desirable … to have the ability to rapidly respond … by closing the firewalls (i.e., adding the required firewall filtering) when the situation deteriorates." That is an express statement of the problem and the design incentive, made by the applicant. Caveat: R2's publication date (2002‑04‑25) post-dates the '084 filing; its availability depends entirely on pre‑AIA § 102(e) and whether the relied-upon firewall disclosure existed in the 1998 priority document. This must be verified; I could not.

Combination D: R1 + a firewall-protected monitoring server — for the "computer with a firewall" element of claims 19 and 26

Rationale (design choice / obvious to try): Placing a firewall in front of a server that is deliberately exposed to the network to collect traffic from many sites is a routine and well-understood security precaution with a predictable result (protecting the monitoring host). The '084's own FIG. 2 shows firewall 210 protecting the data collection and processing center 205 — the applicant evidently regarded this as unremarkable. Under KSR, a design choice whose alternatives are finite and whose result is predictable is obvious.

Combination E: R1 + R5 (Graham, IPR2014‑00682 Exhibit 1006) — the petitioner's apparent route

The Docket Alarm record for IPR2014‑00682 (Inter Partes Review of U.S. Pat. 6,715,084) shows US 7,237,264 (Graham) filed as Exhibit 1006 — i.e., part of a petitioner's prior-art record against this patent. I could not retrieve the Grounds, so I cannot state what Graham was combined with or which claims were targeted. This is flagged as the most likely place where the real, litigated § 103 theory lives, and it should be pulled directly from the IPR papers before any final validity opinion is issued.

Combination F: for claim 10 specifically — R1 + routine network scanning/polling

Claim 10 requires (a) devices polled in a predetermined sequential order, and (b) the predicted device being one not yet polled. R1 actively prefers against synchronous polling, so single-reference obviousness fails here. But: (i) sequential and pseudorandom scanning were notorious network-management/scanning techniques in 2002 — the '084 specification itself concedes "Standard scanning patterns can be used for the data as well, such as sequential or pseudorandom techniques"; (ii) the specification's own rationale (hackers scan a sequence of customers) supplies the motivation to order polling to match the intruder's reconnaissance pattern; and (iii) "obvious to try" applies where, as here, the universe of ordering schemes is small and predictable. A POSITA who wished to obtain "lead time" and had to choose a polling order would arrive at sequential order as an obvious, predictable variation. This is a defensible § 103 position but a materially weaker one than for the other claims.


6. Secondary considerations and the counter-case

Arguments the patent owner would raise:

  1. Claim 10's polling-order limitation. R1's express preference for asynchronous, subscription-based dissemination "without requiring the overhead of synchronous polling" is the best non-obviousness evidence in the file. It supports the argument that the sequential-polling/prediction architecture was a deliberate departure, not a design choice. Counter: KSR and In re Fulton require the reference to criticize, discredit, or discourage the alternative to constitute teaching away; R1's stated reason for avoiding polling is efficiency for report dissemination, not a statement that polling cannot predict future targets. A preference is not a teaching away. This argument likely narrows claim 10 but does not save the family.

  2. Teaching away from centralization — a real argument for claims 19 and 26. R1 states: "The enterprise monitor 16f (or monitors, as it would be important to avoid centralizing any analysis)". Claims 19 and 26 recite a single "data collection and processing center." This is the most substantive non-obviousness argument available, and it is a genuine tension in Combination A. Counter: (i) R1 nonetheless discloses a single enterprise monitor that performs cross-domain correlation; the parenthetical is a scalability preference; and (ii) the '084 specification itself notes the invention "can implement monolithic techniques in which a broad scope of customers' events are correlated at a central analysis engine" — the applicant treated central-vs-distributed as an implementation choice. Reasonable minds could differ; this should be briefed.

  3. No evidence of nexus. I found no record of unexpected results, industry praise, licensing-nexus evidence, long-felt-but-unsolved need with the requisite nexus, or copying. Commercial activity (the IV licensing campaign) is a monetization fact, not a secondary-considerations fact.

Arguments that favor the patent owner on the record: R2's § 102(e) date is uncertain (publication postdates the filing by 12 days); R3's applicability to firewall rule adjustment in a multi-customer IDS context is unverified; Rowland '318 issued after the '084 filing and its § 102(e) date is unverified; and Graham '264's disclosure is unverified. An obviousness case that leans on R2–R5 as currently documented would be built on unresolved evidentiary foundations.


7. Bottom line

  • On verified evidence, claims 1–9 and 11–20 and 22–28 and 30–33 are highly vulnerable to § 103(a) over US 6,321,338 (Porras) alone, or over Porras in view of EMERALD. Porras discloses broad-scope collection across multiple domains and network entities (including firewalls), cross-domain pattern correlation, recognition of attacks spreading across domains, sensitizing other domains "before they are affected," runtime adjustment of analysis scope and signature rules based on other monitors' reports, and automated reconfiguration of network components including firewalls. Those are, element for element, the predictive-alerting and feedback limitations the '084 claims.
  • Claims 3, 21, and 29 (adjusting a firewall's filtering in anticipation) are the weakest of the independent-claim set and are best attacked with a secondary firewall-reconfiguration reference — but the '084's own Background supplies an unusually clean motivation statement, which cuts strongly against the patent owner.
  • Claims 19 and 26 are the broadest claims (26 recites no alerting, no prediction, and no correlation at all) and are the most exposed; their only distinctive element is "a computer with a firewall," which is a predictable design choice.
  • Claim 10 is the least exposed claim in the patent, because R1 (the dominant reference) prefers the opposite architecture. It is still attackable on a predictable-variation/"obvious to try" theory, and the '084 specification's concession that "standard scanning patterns … such as sequential or pseudorandom techniques" are known helps that attack.
  • The strongest documented-but-unread thread is the actual IPR record: US 7,237,264 (Graham) appears as Petitioner's Exhibit 1006 in IPR2014‑00682, and IPR2014‑00682 and IPR2014‑00801 both reached Final Written Decisions. Retrieving those Grounds and Decisions is the single highest-value next step — it would replace most of the reconstruction above with the actual litigated theory and would reveal which claims, if any, survived.

8. Uncertainty disclosures and verification status

Verified in this session:

  • The full text of US 6,321,338 (Porras), including its 27 claims and the description passages quoted above (via patentimages.storage.googleapis.com/.../US6321338.pdf and uspto.report/patent/grant/6321338).
  • The existence of the '084 patent's forward-citation lists and prior-art keyword field on the fetched Google Patents page.
  • US 6,405,318 (Rowland, 6/2002) appearing in a related patent's reference list.

Identified but NOT verified — do not rely on these without pulling the documents:

  • The disclosure of US 6,405,318 (Rowland) and US 7,237,264 (Graham). I have confirmed their identifiers/dates appear in reference and exhibit lists but have not read their specifications. I therefore make no assertion about what they teach. My search attempts on these two returned no substantive text before I exhausted my tool budget.
  • The disclosure of US 2002/0049899 A1 (Kenworthy) and US 2002/0032774 A1 (Kohler).
  • The content of the EMERALD, DIDS, P-BEST, and Debar et al. references beyond their titles and citation of record in Porras.
  • The Grounds and Final Written Decisions of IPR2014‑00682 and IPR2014‑00801 — I could not retrieve the outcomes, including whether any claims were cancelled. This is a material gap: if claims were cancelled by FWD, the claim scope available for analysis changes accordingly. Google Patents shows no certification of cancellation, but Google Patents does not reliably reflect PTAB claim cancellations, so this is not evidence either way.
  • Whether R2's firewall disclosure existed in its 1998 priority document (determines its pre-AIA § 102(e) date and therefore its availability).
  • No 2026 Federal Circuit docket activity for 6,715,084 was located; consistent with the previously generated section, I cannot certify a negative.

Not legal advice: This is a technical validity assessment. A formal § 103 opinion should be built from the actual USPTO file history (including any examiner's amendments that produced the "analyzing data entering into a plurality of hosts, servers, and computer sites" language in all four independent claims), the IPR petitions and Final Written Decisions, and the district court record — none of which was available in full here.

Generated 9/11/2026, 6:48:50 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Intellectual Ventures II LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (10)

10 tracked lawsuits name US 6715084.