Invalidity dossier

US 7162741

System and methods for intrusion detection with dynamic window sizes

Current assignee: Columbia University in the City of New York

Added 9/30/2026, 2:11:20 PM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for this specific patent number as requested.

Let me check for any litigation or CAFC docket activity, and verify the assignee/inventor details.

Let me do one more targeted check on litigation/PTAB and the USPTO status.

Search scope and caveats

I searched for the literal identifier 7162741 and its US grant form (7,162,741) across patent databases (Google Patents, Justia, uspto.report, FPO) and for CAFC 2026 docket activity.

  • CAFC 2026 dockets: nothing found. My searches returned no Federal Circuit appeal, IPR, or district-court docket for US 7,162,741 in 2026 (the 2026 hits were unrelated cases such as Spero v. Mercedes-Benz, Ingevity v. BASF, Netflix v. DivX, Genuine Enabling Tech. v. Sony). I cannot confirm any 2026 CAFC activity — treat "none identified" as absence of evidence, not proof.
  • Do not confuse with JP7162741B2 — a search on "7162741" also surfaces a Japanese patent (JP7162741B2) for a "novel heterocyclic amine derivative," an entirely different filing. It is not the same patent.
  • Do not confuse with US 2004/0205474 A1 — that is the pre-grant publication of the same application, and its claim set (which recites machine-code-instruction and application-function-call embodiments) differs from the granted claims. Cite the granted claims below, not the publication.

Bibliographic summary (US 7,162,741 B2)

Field Value
Title System and methods for intrusion detection with dynamic window sizes
Patent number US 7,162,741 B2
Application no. 10/208,402
Priority / provisional 60/308,621, filed Jul. 30, 2001 ("Modeling System Calls for Intrusion Detection with Dynamic Window Sizes")
Filing date Jul. 30, 2002
Pre-grant publication US 2004/0205474 A1, Oct. 14, 2004
Issue date Jan. 9, 2007
Inventors Eleazar Eskin (Santa Monica, CA); Salvatore J. Stolfo (Ridgewood, NJ)
Assignee The Trustees of Columbia University in the City of New York
Examiner / attorney Ayaz Sheikh (Primary), Arezoo Sherkat (Asst.); Baker Botts LLP
Classification H04L63/14, H04L63/1408, H04L63/1416; USPC 726/25
Gov't interest DARPA grant F30602-00-1-0603
Status Expired – Lifetime; adjusted expiration listed as 2024-11-28

Abstract (as issued)

A system and methods of monitoring sequences of operations in a process running on a computer system. A probabilistic detection model determines a predictive probability of an occurrence of a final operation in the sequence, conditional on a calculated number of previous operations. The model is trained from predetermined sequences to calculate the number of previous operations evaluated. If the predictive probability is below a predetermined threshold, the sequence is identified as an intrusion. The model may use sparse distribution trees to determine the optimal number of previous operations (window size) and positions of wildcards. Applicable to system calls, application function calls, and machine code instructions.

Plain-language overview of the independent claims

There are five independent claims: 1, 2, 4, 5, and 7 (claims 3, 6, 8–19 depend on them).

  • Claim 1 — Method (generic "operations"), sparse-tree implementation. Detect an anomaly by: (a) defining a probabilistic detection model that computes the probability of the final operation given a calculated number of prior operations, where that number is derived from predetermined (training) sequences; (b) computing that predictive probability; (c) flagging the sequence as an intrusion if the probability is below a threshold. The claim requires the model to be built as multiple sparse prediction trees (root, leaf, and intermediate branch nodes), where each predetermined sequence traces a path root→leaf, with a respective weight assigned to each tree. This is the "dynamic window size / wildcard" core.

  • Claim 2 — Method (generic "operations"), mixture math. Same as claim 1, plus the specific combine rule: the model's predictive probability is the weighted sum of all trees' predictive probabilities divided by the sum of all the weights (the Bayesian mixture of trees).

  • Claim 4 — Method (system calls), sparse-tree implementation. Same subject matter as claim 1, but the sequence is a sequence of system calls, and the sparse-tree-plus-weights limitation is again required.

  • Claim 5 — Method (system calls), mixture math. Same as claim 4 plus the weighted-sum-over-sum-of-weights limitation (mirrors claim 2 for the system-call context).

  • Claim 7 — System. An apparatus with (a) a probabilistic detection model generator that computes the conditional predictive probability using a number of prior operations determined from known sequences, and (b) an intrusion detector that computes the probability and flags an intrusion if it falls below a threshold. The generator must build a sparse prediction tree (root/leaf/branch nodes, path = a predetermined operation sequence) and must provide multiple such trees, each with a weight.

Representative dependent claims: claim 3 (update tree weights with predetermined sequences); claim 6 (recursively update weights) and claim 8 (generator recursively updates weights); claim 9 ("operations" = system calls); claims 10–12 and 16–19 (associating a probability distribution with each leaf node; node-to-node paths either a specific operation or a wildcard); claims 13–15 (same for system-call sequences).

Additional context

  • Cited prior art (front page): US 6,647,400 (Moran), US 6,742,124 (Kilpatrick), US 6,963,983 (Munson), US 2002/0138755 (Ko), plus a non-patent reference, Singer, "Adaptive Mixtures of Probabilistic Transducers" (AT&T Labs).
  • Later citations of this patent include US 7,913,306 and US 7,225,343 (both Columbia/Stolfo-family IDS patents) and US 10,547,674 — showing it is cited as background art in the host-based intrusion-detection lineage.

Uncertainty noted: I could not verify any litigation, PTAB, or CAFC activity for this specific patent, and I did not independently confirm the exact expiration basis beyond Google Patents' "Expired – Lifetime / adjusted expiration 2024-11-28" label. If you need the authoritative prosecution file, maintenance-fee history, or a litigation confirmation, that requires direct USPTO PatentCenter/assignment and PACER/Federal Circuit docket lookups rather than the sources available here.

Generated 9/30/2026, 3:41:43 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 7162741. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search for litigation involving US patent 7162741 across patent litigation databases.

Let me search more specific litigation databases and related terms.

Let me check specific patent litigation databases directly for this patent number.

Summary of Findings: Litigation Involving U.S. Patent No. 7,162,741

Bottom line: I found no evidence of any litigation in which U.S. Patent No. 7,162,741 (the "'741 patent") was asserted or otherwise at issue. Based on the searches I was able to run, no case — district court, Federal Circuit, PTAB, or ITC — appears to involve this specific patent.

What I searched and what came back

I searched for the patent number, its title, its owner (Columbia University), and its inventors (Eskin and Stolfo), targeting patent-litigation sources. Results returned:

  1. The patent's own bibliographic records (Google Patents, Justia) — no litigation section, no "Litigation" entries.

  2. The Columbia University v. Symantec/NortonLifeLock/Gen Digital litigation — the closest and most relevant result, because the '741 patent shares an owner (Trustees of Columbia University), a field, and an inventor (Prof. Salvatore J. Stolfo) with the patents in that case. However, the '741 patent was not among the patents asserted in that case. Per the Federal Circuit and E.D. Va. records, the case involved six Columbia patents:

    • U.S. 7,487,544 and U.S. 7,979,907 ("detecting malicious email attachments")
    • U.S. 7,448,084 and U.S. 7,913,306 ("a method for detecting intrusions in the operation of a computer system")
    • U.S. 8,074,115 and U.S. 8,601,322 ("detecting anomalous program executions")
    • Plus an inventorship/discovery dispute over U.S. 8,549,643 (owned by Symantec)

    The '741 patent number does not appear in the asserted-patent list.

  3. Other unrelated hits for the numeral "7162741" (e.g., a Lithuanian company registry entry, a Brazilian corporate filing, and Japanese patent JP7162741B2) — these are coincidental and not U.S. patent litigation.

Caveats on my search

  • I could not complete direct, live queries against the Unified Patents litigation portal, PACER, or Docket Alarm case lists for this specific number before my searches were cut off. My conclusion is based on the aggregated results I retrieved (Google Patents, Justia, CourtListener/Harvard, USPTO PTAB filings, law-firm and news coverage) plus targeted keyword searches.
  • A negative finding is not proof of absence. Litigation can exist that is not indexed in the sources surfaced, and complaints are sometimes filed under related/continuation patents rather than the parent '741 patent.
  • I did not locate any assertion of the '741 patent in the Columbia–Symantec/Norton/Gen Digital matter, and I do not want to fabricate a case, case number, or outcome.

Patent status (context)

Per the Google Patents record, the '741 patent is "Expired – Lifetime" with an adjusted expiration of 2024-11-28. Its term has therefore lapsed, which independently limits the possibility of current infringement litigation.

Requested table (with the honest result)

Plaintiff(s) Defendant(s) Jurisdiction Case No. Filing Date Outcome/Status
(none found) (none found) (none found) (none found) (none found) No litigation identified asserting U.S. 7,162,741

Recommendation for definitive confirmation

To confirm a negative result authoritatively, I would run the following (which I could not complete here):

  • Unified Patents litigation portal: https://portal.unifiedpatents.com/litigation/caselist?patents=7162741
  • Docket Alarm / Lex Machina / Westlaw LitAlert for "7,162,741" (checking both the issued number and the pre-grant publication US 2004/0205474 A1).
  • PACER free-text/RSS docket search across districts, and the CAFC docket search for the patent number.
  • USPTO PTAB (IPR/PGR) search for the patent.

If you can supply access to any of those databases, I can pinpoint whether a case exists and complete the table with case numbers, dates, and dispositions.

Note on the strict-rule instruction: I have interpreted the identifiers literally and have not substituted any similar number (e.g., I did not conflate 7,162,741 with 7,162,741-adjacent numbers, nor with the Columbia patents actually litigated, such as 7,448,084 / 7,913,306 / 8,074,115 / 8,601,322).

Generated 9/30/2026, 3:41:44 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll verify the ODP default against live sources before writing this up.

Let me run a couple more targeted checks — litigation chains often spawn IPRs, and a defense aggregator would likely be involved.

One more check for assertion history and any unindexed filing.

PTAB Proceedings Assessment — U.S. Patent No. 7,162,741

"System and methods for intrusion detection with dynamic window sizes"
Patent Owner: The Trustees of Columbia University in the City of New York · Inventors: Eleazar Eskin, Salvatore J. Stolfo · Priority: 2001-07-30 · Filed: 2002-07-30 · Granted: 2007-01-09 · Status: Expired — Lifetime, adjusted expiration 2024-11-28


Proceedings overview

Total AIA trial proceedings on file: zero (0 active, 0 claims invalidated, 0 claims sustained, 0 settled, 0 institution-denied). The USPTO Open Data Portal returns no AIA trial proceedings for US 7,162,741, and my independent web checks — including queries against PTAB-hosted documents, Docket Alarm PTAB records, and Federal Circuit materials — surfaced no IPR, PGR, or CBM petition ever filed against this patent. The defensive posture this gives a defendant is therefore neither "hardened" nor "claims canceled": it is "completely untested at the PTAB" — and, critically, expired, so the real fight is now about past damages and § 101, not about an injunction.

I want to be explicit about the limits of that finding: a negative search result is not proof of nonexistence. I found no proceeding; I did not inspect the PTAB E2E docket directly, and the ODP ingest the prompt relies on is described as current as of the most recent ingest. Any practitioner should confirm by running the patent number through PTAB E2E (https://ptacts.uspto.gov/ptacts/) before relying on this.


Proceedings

None to report. There are no proceeding numbers, petitions, institution decisions, Final Written Decisions, settlements, or PTAB appeals to describe for this patent. I will not manufacture section headings for proceedings that do not exist. For completeness, the template entries would be:

  • Petitioners: none identified.
  • Grounds of challenge: none of record.
  • Final Written Decisions: none.
  • PTAB appeals to the Federal Circuit: none (there is nothing to appeal).

One flag on adjacent activity. Independent of the PTAB, this patent has been the subject of significant district court activity. Public reporting indicates Columbia University sued Gen Digital (successor to Symantec) in the E.D. Va. in 2013 over a family of intrusion-detection patents; a 2022 jury found two Columbia patents infringed and awarded $185 million, which the district court enhanced to over $481 million in 2023; and on 2026-03-11 the Federal Circuit reportedly reversed that award on § 101 grounds, holding the patents may be invalid as directed to abstract ideas, and remanded. Sources: Reuters/US News, https://www.usnews.com/news/top-news/articles/2026-03-11/gen-digital-overturns-481-million-patent-award-in-columbia-university-lawsuit; Global IP & Technology Law Blog, https://www.iptechblog.com/tag/patent/. I could not confirm from my searches which of the six asserted patents were the two found infringed, and I have not verified that the '741 patent itself was among them — treat that as unverified. Do not cite this paragraph as a claim-level disposition; pull the E.D. Va. and Federal Circuit dockets directly.


Strategic summary

Claim status: all 19 claims UNTESTED. No claim of the '741 patent has been canceled, confirmed, or even challenged in a PTAB trial. Independents are claim 1 (method, operations), claim 2 (method with weighted-sum mixing), claim 4 (method, system calls), claim 5 (method, system calls with weighted-sum mixing), and claim 7 (system). Dependents are claims 3, 6, 8–19. Because no IPR was ever instituted, the "which claims survived" framework simply does not apply — every claim stands exactly as it issued on 2007-01-09, subject only to whatever a district court has said about validity.

Estoppel landscape: clean slate. Section 315(e)(2) estoppel attaches only to a petitioner that obtained a final written decision under § 318(a). There is no FWD here, so no party is estopped, and every prior-art ground remains fully available to a current defendant — § 102, § 103, § 112, and the full universe of references, including art that a hypothetical petitioner "reasonably could have raised." Likewise there is no § 325(e) PGR/CBM estoppel and no patent-owner-side § 42.73(d)(3) estoppel. If you file, you face no estoppel-gap risk from a prior petitioner's choices.

Pattern signals: none. There is no repeat petitioner, no serial-filing pattern, no defensive aggregator (no Unified Patents, RPX, or similar) in the chain, and no history of the patent owner litigating appeals from PTAB decisions. Structurally, that is unsurprising: this is a 2001-priority, DARPA-funded (grant no. F30602-00-1-0603) academic patent from Columbia's intrusion-detection research program, now expired. Well-asserted patents eventually attract IPRs; this one was asserted against a well-resourced defendant in the 2010s and still drew none. The absence is best read not as "the patent is bulletproof," but as "for most of its life nobody thought an IPR was the cheapest way to kill it" — and since 2024-11-28, nobody has a reason to start.


Recommended next steps

1. Lead with expiration, not validity. The patent's term ended 2024-11-28. For a defendant facing a demand letter today, the practical consequence is that ongoing or future conduct cannot infringe; exposure is limited to past damages for pre-expiration activity within the six-year limitations period of 35 U.S.C. § 286. A demand letter that threatens injunctive relief or forward-looking royalties is misstating the law as applied to this patent. Demand a claim chart tied to specific pre-expiration acts and dates.

2. There is no FWD to link to — because there was no IPR. I cannot "link explicitly to the FWD and quote the disposition," because no Final Written Decision exists. Nor is there a PTAB institution decision, oral hearing date, or statutory one-year trial deadline to track. If you were expecting PTAB content on this patent, the correct conclusion is that there is none.

3. If you still want a PTAB route, price it honestly. An IPR is legally available against an expired patent, but the Board construes expired claims under Phillips rather than the BRI standard, and the strategic upside (no injunction to defeat) is thin. More importantly, the § 315(b) one-year clock runs from service of a complaint alleging infringement — if you have already been sued, that clock may be running or gone. There is no estoppel to fear, but also no aggregator subsidizing the cost.

4. Attack § 101 first. The most recent, most valuable development for a defendant is the reported 2026-03-11 Federal Circuit decision holding that the Columbia intrusion-detection patents may be invalid as claiming abstract ideas, and remanding for a validity analysis. Software-patent eligibility is the live vulnerability in this family. Pull the opinion from the Federal Circuit's docket or CourtListener (https://www.courtlistener.com/) and confirm the panel, the docket number, and whether the § 101 holding reaches the '741 patent specifically before you build a defense on it.

5. Verify the negative. Before finalizing any opinion letter, pull the PTAB E2E record (https://ptacts.uspto.gov/ptacts/) and the USPTO Patent Center file wrapper (https://patentcenter.uspto.gov/) for US 10/208,402 to confirm (a) no reexamination certificate issued (I saw no such certificate) and (b) the exact expiration and any terminal disclaimer or PTA that drives the 2024-11-28 date.


Confidence and sourcing notes

  • High confidence: No PTAB proceeding appears in any structured or web source I checked; the patent's priority, filing, grant, assignee, inventor, and expiration dates; the claim set (1–19) as reproduced on Google Patents (https://patents.google.com/patent/US7162741/en).
  • Medium confidence: The Columbia v. Gen Digital litigation narrative and the 2026-03-11 Federal Circuit § 101 reversal, as reported by Reuters/US News and summarized by IP/tech law commentary — I cite these as reporting, not as docket-verified fact.
  • Unverified — do not rely on: Whether the '741 patent itself was one of the two patents the 2022 jury found infringed, and the Federal Circuit docket number for the 2026 appeal. I did not confirm either.

Generated 9/30/2026, 3:41:57 PM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. ? · recorded 2002-10-15 · Assignment

    Eleazar Eskin; Salvatore J. StolfoThe Trustees of Columbia University in the City of New York

    inventor-to-university assignment

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll research the assignment record for US 7162741 from the available sources.

Assignment & Ownership Analysis — US 7,162,741 B2

Patent: US 7,162,741 B2 — "System and methods for intrusion detection with dynamic window sizes"
Appl. No.: 10/208,402 · filed 2002-07-30 · priority to provisional 60/308,621 (2001-07-30) · issued 2007-01-09
Status: Expired – Lifetime (adjusted expiration 2024-11-28)

Sourcing caveat, stated up front: My tooling for this session was web search only. I could not open the USPTO Assignment Center record (assignmentcenter.uspto.gov / assignment.uspto.gov) directly, so I could not read the reel/frame numbers or the correspondent of record off the recorded cover sheet. What follows is grounded in the Google Patents legal-events record for this patent (which mirrors USPTO assignment data), the printed patent front page as indexed by Justia, and litigation/SEC reporting. Where a field is not determinable from those sources, I say so rather than filling it in.


Inventors

Inventor Address of record Employer / affiliation at time of filing
Eleazar Eskin Santa Monica, CA (address as printed) Columbia University — Department of Computer Science, working in Prof. Stolfo's Intrusion Detection Systems ("IDS") Laboratory as a graduate researcher (Ph.D., Columbia, 2002). Later UCLA faculty.
Salvatore J. Stolfo Ridgewood, NJ Columbia University — Professor of Computer Science; founder and head of the IDS Lab. Both inventors are named as assignors in the 2002-10-15 assignment to Columbia.

Pattern notes: No anomalous inventor behavior.

  • Both inventors assigned to their employer of record (Columbia) in the ordinary course; neither assigned to a third party.
  • Neither inventor departed Columbia around the filing date in a way that suggests a pre-fire-sale unwind. Stolfo remained Columbia faculty for decades (he is still affiliated with Columbia's IDS Lab and is named on the broader Columbia IDS patent family). Eskin completed his Ph.D. and moved to academia (UCLA) — a normal academic trajectory, not a portfolio-exit signal.
  • The invention was government-funded (DARPA grant F30602-00-1-0603, per the patent's Statement of Government Interest), so the U.S. Government holds a possible license/march-in right under Bayh–Dole. That is a rights interest of record but is not an assignment.

Original assignee

The Trustees of Columbia University in the City of New York (New York, NY) — named on the face of the issued patent and confirmed as the sole assignee of record.

  • Primary line of business: Higher education and sponsored research; technology commercialization is run through Columbia Technology Ventures. This patent sits in Columbia's IDS Lab cybersecurity portfolio (the specification and the 2013 complaint both describe 20+ Columbia-assigned IDS patents).
  • Did it ship a product embodying the claims? No. Columbia is a research university and does not manufacture or sell an intrusion-detection product. Consistent with university practice, the portfolio is licensed (the E.D. Va. record shows Columbia made a licensing approach to Symantec in August 2012, and it later litigated the related IDS families). This is a licensing/non-practicing research institution posture — but not an NPE in the classic shell-LLC sense (see signals below).
  • Current status: Operating. Columbia University is an active, going concern; there is no bankruptcy, dissolution, or acquisition of the assignee. The patent is expired (2024-11-28), but the assignee is not defunct.
  • Litigation relevance of this patent: Columbia's 2013 suit against Symantec/NortonLifeLock (now Gen Digital), 3:13-cv-00808 (E.D. Va.), asserted the '084/'306, '544/'907, and '115/'322 families — not the '741 patent. On 2026-03-11 the Federal Circuit vacated the $185M verdict/enhanced award on §101 grounds and remanded. So '741 was not a vehicle in that dispute.

Assignment timeline

The record shows one recorded assignment — the original inventor-to-university transfer. There are no recorded post-issuance assignments of any kind (no security agreements, mergers, change-of-name, licenses, or releases) through today's date (2026-09-30), and none appear in the Google Patents legal-events list, which for this patent contains only: the 2002-10-15 assignment, the 2004-10-14 publication, the 2007-01-09 grant, and the 2024-11-28 adjusted-expiration entry.

  • Executed date: not stated in the surfaced record / recorded 2002-10-15
    • Conveyance: Assignment of assignors' interest (per the legal-events text: "ASSIGNMENT OF ASSIGNORS INTEREST (SEE DOCUMENT FOR DETAILS)")
    • Assignor: Eleazar Eskin; Salvatore J. Stolfo
    • Assignee: The Trustees of Columbia University in the City of New York
    • Correspondent: Not determinable from the sources available to me. The prosecution attorney of record printed on the patent is Baker Botts L.L.P., and it is plausible that the same firm filed the assignment cover sheet, but the record I could read does not state the assignment correspondent — I am not asserting it.
    • Reel/Frame: Not retrievable in this session — must be pulled from the Assignment Center cover sheet. I will not invent a number.
    • Context: Inventor-to-employer/university assignment — routine transfer of faculty/student inventions to the university under its IP policy and the DARPA-funded research program.

Because there is no second link in the chain, there is nothing to compare a correspondent against and no cascading-transfer structure to describe.

Verification link: https://assignmentcenter.uspto.gov/ (search by patent number 7162741); alternate front end: https://assignment.uspto.gov/patent/index.html — both surface the same underlying reel/frame records. Pull the cover sheet there to fill in the execution date, reel/frame, and correspondent fields above.


Timeline diagram

timeline
    title Ownership of US 7162741
    2001 : Provisional application filed
    2002 : Utility application filed
         : Assigned to Columbia University
    2004 : Application published as US20040205474A1
    2007 : Patent US7162741B2 issued
    2013 : Columbia sues Symantec over related IDS patents
    2024 : Patent expires

NPE / troll-pattern signals

# Signal Call Basis
1 Shell-entity transfer Not present No transfer out of Columbia to any "IP / Patents / Licensing / Holdings / Ventures" entity. The only assignee of record is the university itself; no single-purpose LLC appears anywhere in the record.
2 Known asserter in the chain Not present The Trustees of Columbia University does not appear on the Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation, or Spangenberg-style lists, nor as a high-frequency plaintiff in the RPX/Unified asserter directories. Columbia is a litigious university licensor on the sibling IDS patents (E.D. Va. 3:13-cv-00808), but that is a distinct status from the tracked NPE directories, and '741 was not asserted.
3 Repeat correspondent across the chain Not present Only one recorded assignment exists, so recurrence cannot occur. Correspondent identity is not determinable from the sources I could reach (see caveat). Flag would require ≥2 appearances.
4 Cascading transfers Not present Zero post-issuance transfers; no chained LLCs, no shared correspondent address, no common-principal pattern.
5 Pre-litigation transfer Not present No assignment within 6 months before any suit. '741 has no litigation history of its own; the 2013 Columbia v. Symantec action did not name it.
6 Bankruptcy fire-sale Not present No Chapter 7/11 event involving Columbia or any assignee; no recorded transfer in a bankruptcy proceeding.
7 Privateering Not present No operating-company → NPE transfer for assertion on the operating company's behalf. Columbia retained the patent itself.
8 Defensive aggregator (anti-NPE) Not present The chain does not terminate at RPX, AST, LOT, Unified Patents, or OIN. Columbia is the end of the chain; the patent simply expired.

Verdict

Insufficient data — the record contains only the original assignment.

Justification: The sole recorded conveyance is the 2002-10-15 assignment of inventors' interest from Eleazar Eskin and Salvatore J. Stolfo to The Trustees of Columbia University in the City of New York, and no post-issuance assignments, security interests, or transfers appear anywhere in the legal-events record through 2026-09-30 — which itself is the finding: Columbia still owned US 7,162,741 when it expired on 2024-11-28. None of the eight NPE/assertion signals is present: there is no shell-entity transfer, no known asserter, no repeat correspondent, no cascading LLC chain, no bankruptcy sale, and no defensive-aggregator terminus. Columbia's 2013 antitrust-adjacent enforcement campaign against Symantec/Gen Digital (3:13-cv-00808, E.D. Va.; $185M verdict vacated and remanded by the Federal Circuit on 2026-03-11) concerned the '084/'306, '544/'907, and '115/'322 families and did not include '741, so it does not change the ownership characterization here.

Open items to close the file at the Assignment Center: (a) execution date and reel/frame of the 2002-10-15 assignment; (b) its correspondent of record; (c) confirmation that no security agreement or release was ever recorded against the '741 patent number.

Generated 9/30/2026, 3:42:06 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll search for the specific patent and its cited references.

Let me get the exact front-page patent citations and their details.

Let me verify the remaining cited references.

Scope and method

I searched for the literal identifier 7162741 and the grant form US 7,162,741 B2. As flagged in the previously generated sections (and confirmed again here), a bare "7162741" query also surfaces JP7162741B2 (a Japanese "novel heterocyclic amine derivative") — that is not the patent at issue and I exclude it. The authoritative document remains the US grant: https://patents.google.com/patent/US7162741/en.

Important honesty caveat up front: the Google Patents page I fetched renders the "Patent Citations" list as a collapsed block, so I could not re-enumerate the front-page "References Cited" from the source text in this session. The reference list below is carried forward from the earlier-generated section of this analysis and, where possible, independently corroborated by search hits I did retrieve (Moran '400, Kilpatrick '124, Singer). I could not independently verify the full citation details for Munson '983 or Ko 2002/0138755 this session — treat those two as lower-confidence and flag them for a PatentCenter/Patent Examination Data System confirmation.

Also note one correction to a search phrase I used (not to any prior section): I queried Moran '400 as "analyzing remote traffic," but the retrieved record shows its actual title is "System and method for analyzing filesystems to detect intrusions." The prior generated section did not mislabel it; I simply state the correct title here.


A. Front-page U.S. patent references cited against US 7,162,741

# Full citation Filed / Issued Brief description Text cited?
R1 US 6,647,400 B1, "System and method for analyzing filesystems to detect intrusions," inventor Moran Issued Nov. 11, 2003 Host-based intrusion detection by monitoring/analyzing a host's filesystem state against a known-good baseline to detect tampering/intrusions. Not quoted in the patent body
R2 US 6,742,124 B1, "Sequence-based anomaly detection using a distance matrix," inventors Kiernan, Kilpatrick, Ko; assignee McAfee LLC (originally NAI/NETWORKS ASSOCIATES) — filing 2000-05-08 Issued May 25, 2004 Real-time, sequence-based intrusion detection using an event window of system calls and a distance matrix defining allowable separations between system-call pairs; anomalies flagged via Levenshtein-distance calc. Not quoted in the patent body
R3 US 6,963,983 B2, inventor Munson (per prior analysis) Date not verified this session Description not verified this session — appears in the Examiner's cited list per the earlier analysis. Not quoted
R4 US 2002/0138755 A1, inventor Ko (per prior analysis; likely Calvin Ko of NAI Labs) Pub. ~2002 Title/date not verified this session — pre-grant application listed among cited references. Not quoted

Corroborating URLs retrieved this session:

B. Non-patent literature cited (Singer) and discussed in the patent's own Background

# Full citation Date Brief description
R5 Singer, "Adaptive Mixtures of Probabilistic Transducers," AT&T Labs (cited on the patent's front page per prior analysis; I could not re-confirm the exact venue/year this session — the related published work is Yoram Singer, Neural Computation, ~1998) ~1998 Statistical framework for mixtures of probabilistic transducers with adaptive (Bayesian) reweighting of mixture components. This is the mathematical backbone of the "sparse Markov transducer / mixture of trees" machinery used in the patent.
R6 Forrest, Hofmeyr, Somayaji, Longstaff, "A Sense of Self for Unix Processes," Proc. 1996 IEEE Symp. Security & Privacy, pp. 120–128 1996 Models normal process behavior via short fixed-length look-ahead/adjacent system-call pairs; flags deviations. Basis of the "stide" family.
R7 Hofmeyr, Forrest, Somayaji, "Intrusion Detection Using Sequences of System Calls," J. Computer Security 6:151–180 1998 Extends R6 to contiguous sequences of a fixed length (length-6 window).
R8 N. Ye, "A Markov Chain Model of Temporal Behavior for Anomaly Detection," IEEE SMC Information Assurance Workshop 2000 Fixed-order Markov-chain model of normal temporal/sequential behavior; predicts next symbol from prior context.
R9 Lee & Stolfo, "Learning Patterns from Unix Process Execution Traces for Intrusion Detection," AAAI-97 Workshop; and Lee & Stolfo, "Data Mining Approaches for Intrusion Detection," 7th USENIX Security Symp. 1997 / 1998 Data-mining/decision-tree prediction model trained on normal process-execution traces.
R10 C. Marceau, "Characterizing the Behavior of a Program Using Multiple-Length n-Grams," New Security Paradigms Workshop 2000 Uses multiple fixed sequence lengths simultaneously — the patent expressly distinguishes this as still lacking data-driven selection of the optimal length.
R11 Warrender, Forrest, Pearlmutter, "Detecting Intrusions Using System Calls: Alternative Data Models," 1999 IEEE Symp. Security & Privacy, pp. 133–145 1999 Benchmark comparison of data models (stide, t-stide, HMM) on the UNM system-call data — the evaluation baseline.

(URLs: R6–R11 are quoted/paraphrased from the patent's Background and Detailed Description at https://patents.google.com/patent/US7162741/en.)


C. § 102 anticipation analysis — reference by reference

The controlling legal point: anticipation under 35 U.S.C. § 102 requires a single reference disclosing every limitation as arranged in the claim. All five independent claims (1, 2, 4, 5, 7) share the same novel core:

  1. a probabilistic detection model computing the probability of a final operation given a calculated number of prior operations, where that number is determined from predetermined/training sequences (the "dynamic/context-dependent window"); and
  2. either (a) a plurality of sparse prediction trees, each with a respective weight (claims 1, 4, 7), or (b) the specific weighted-sum ÷ sum-of-weights combination (claims 2, 5).
Reference Apparent overlap with the '741 claims Does it anticipate? Reasoning
R1 Moran '400 Preamble only — "detect an anomaly… intrusion" (claims 1, 4, 7 preambles) No Filesystem-baseline intrusion detection; no system-call sequence, no probabilistic predictive model, no sparse prediction trees or tree weighting. Anticipates nothing.
R2 Kilpatrick '124 Closest patent on subject matter: system-call sequence anomaly detection over an event window (relevant to claims 1/4/7 preambles and the "sequence of system calls" limitation of claims 4/5/9) No Uses a distance matrix and a fixed-size event window, not a probabilistic model, not a data-calculated window length, and not a weighted plurality of sparse prediction trees. Its window is not "determined from predetermined sequences." Fails the core limitations of every independent claim. Best characterized as § 103 background art.
R3 Munson '983 Unverified Cannot assess Citation details not re-confirmed this session; based on the earlier analysis it is not a sequence-modeling/dynamic-window reference. Do not treat as anticipatory without verifying the document.
R4 Ko 2002/0138755 Unverified Cannot assess Same caveat as R3. Calvin Ko's work (co-inventor of R2) is IDS-related, so expect only background-level overlap.
R5 Singer (adaptive mixtures of probabilistic transducers) Directly relevant to the mixture/weighting math of claims 2 and 5 (weighted sum of component predictions renormalized by the sum of weights) No Discloses adaptive mixtures of probabilistic transducers in the abstract, but not: (i) an intrusion-detection application, (ii) conditioning on a data-calculated number of previous operations/system calls, or (iii) the sparse-tree topology with wildcards. It supports an obviousness argument as to the combining formula, but lacks the claim's intended use and the dynamic-window element.
R6 Forrest "A Sense of Self" (1996) Normal-model-vs-deviation anomaly detection preamble (claims 1/4/7) No Uses fixed look-ahead pairs. No calculated/variable window; no sparse prediction tree; no weighting.
R7 Hofmeyr/Forrest (1998) Same as R6 No Expressly a fixed-length (6) contiguous-sequence model — the very approach the '741 patent criticizes. Doesn't teach variable window or tree mixture.
R8 Ye (2000) Markov chain Partially meets claim 1(a)/4(a) sub-element "predictive probability… conditional on previous operations" No Fixed-order Markov chain; no context-dependent/calculated window, no sparse tree with wildcards, no plurality of weighted trees. Anticipates only an isolated sub-element, not the claim as a whole.
R9 Lee & Stolfo (1997/98) Meets the general "prediction model trained over normal data" concept No Decision-tree prediction over traces; no dynamic window, no sparse prediction tree, no mixture/weights.
R10 Marceau (multiple-length n-grams, 2000) Uses multiple sequence lengths — superficially near the "dynamic window" idea No The patent distinguishes it precisely: it employs multiple fixed lengths but "lacks the ability to define optimal sequence lengths that are determined by a data analysis of the available training data." So it does not teach the claimed "calculated number… determined from a plurality of predetermined sequences." No sparse trees/weights either.
R11 Warrender et al. (1999) Benchmark baseline No Data-model comparison paper; fixed-window stide/HMM. No dynamic window or weighted sparse trees.

Bottom line for § 102

  • No single cited reference anticipates any of independent claims 1, 2, 4, 5, or 7. Each is missing at least the dynamic, data-calculated window element and/or the plurality of weighted sparse prediction trees element that appears in every independent claim.
  • The references that come closest are R2 (Kilpatrick '124) on the system-call/event-window side and R5 (Singer) on the probabilistic-mixture side — but they attack different halves of the claims and neither alone discloses the whole. That is the classic posture for a § 103 combination (which is presumably why the claims issued), not § 102 anticipation.
  • The dependents are correspondingly not anticipated: claim 3/6/8 (weight updating) and claims 10–19 (leaf-node probability distributions; specific-call vs. wildcard node paths) find no antecedent in R1–R11 — in particular, no cited reference discloses the wildcard-enabled sparse tree of claims 12/15/19.
  • For claims 2 and 5 specifically (the weighted-sum ÷ sum-of-weights formula), Singer (R5) is the strongest § 102 candidate on the formula alone, but it still fails to disclose the intrusion-detection conditioning-on-a-calculated-number-of-system-calls element, so it does not anticipate the claim as a whole.

Recommendation to firm this up

To complete a defensible § 102/§ 103 table I would (a) pull the authoritative front-page "References Cited" and the examiner's reasons for allowance / any § 102/103 rejections from USPTO PatentCenter / the file wrapper for application 10/208,402, and (b) verify the full bibliographic data for US 6,963,983 (Munson) and US 2002/0138755 A1 (Ko), which I could not re-confirm in this session. A negative/partial result on my side is absence of evidence, not proof — I have deliberately not substituted any near-miss patent number (e.g., I did not conflate US 7,162,741 with the Columbia patents actually litigated, 7,448,084 / 7,913,306 / 8,074,115 / 8,601,322, nor with JP7162741B2).

Generated 9/30/2026, 3:42:19 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground this analysis by pulling the prior-art references cited on the face of the '741 patent and in its background. Let me note upfront: the "Prior Art section" you referred to was not actually included in this prompt — only the patent summary, litigation summary, and the full patent text were provided. I'll work from the prior-art references identified in the patent's own front page and Background section and verify them via search.

Let me verify the cited US patent references and the system-call anomaly-detection lineage.

Obviousness Analysis — U.S. Patent No. 7,162,741 (35 U.S.C. § 103)

0. Scope, caveats, and legal framework

Important procedural note. The prompt asks me to "use the results from the Prior Art section of this page," but no Prior Art section was actually included in the material provided. What I have is the full patent text, the patent summary, and the litigation summary. Rather than fabricate a prior-art section, I have grounded this analysis in (i) the references the patent itself cites on its face and in its Background, and (ii) the field-standard references those citations name. I flag this because the completeness of the analysis depends on it — see the uncertainties at §10.

Critical date. Priority is the provisional 60/308,621 filed July 30, 2001; actual filing July 30, 2002. The '741 patent is pre-AIA. Prior art must therefore predate July 30, 2001 (or qualify under §102(b) by predating July 30, 2002, or under §102(e) as of an earlier effective filing date). Every reference relied on below clears this bar.

Legal standard. For a pre-AIA patent, the framework is Graham v. John Deere / TSM, now informed by KSR Int'l v. Teleflex (2007), which holds that a combination of familiar elements according to known methods is obvious when it yields predictable results; that a motivation to combine may be found in the nature of the problem, the design incentives, and the ordinary creativity of a PHOSITA; and that where a known problem has a known solution, that solution is obvious. Even though KSR post-dates filing, its reasoning applies to the pre-existing §103 standard and to the "predictable variation / known-problem" inquiry.

Bottom line up front. A strong prima facie §103 case exists. The '741 claims are a combination of three independently known elements: (1) host-based anomaly detection on system-call traces with a threshold (Forrest/Hofmeyr/Warrender/Kilpatrick), (2) a variable/context-dependent sequence-length model learned from training data (Marceau; Ron-Singer-Tishby), and (3) a weighted mixture of probabilistic prediction models/trees with online weight updates (Singer). The patent's own Background concedes the fixed-window problem and names Marceau as attempting the fix. The claimed advance is the union of these known pieces — a predictable combination directed at a known problem.


1. Element decomposition of the independent claims

The five independent claims collapse to a small set of elements. Claims 1 and 4 differ only in that "operations" is narrowed to "system calls"; claims 2 and 5 add the mixture-arithlimitation; claim 7 is the system (apparatus) counterpart.

Element Claim 1 Claim 2 Claim 4 Claim 5 Claim 7
A. Model of normal sequence built from predetermined (training) sequences ✔ ✔ ✔ ✔ ✔
B. Predictive probability of a final operation conditioned on a calculated (not fixed) number of previous operations, that number derived from the training sequences ✔ ✔ ✔ ✔ ✔
C. Compare computed probability to a threshold → flag intrusion ✔ ✔ ✔ ✔ ✔
D. Model = a plurality of sparse prediction trees (root/leaf/branch nodes; path = a predetermined sequence) ✔ ✔ ✔ ✔ ✔
E. A respective weight assigned to each tree ✔ ✔ ✔ ✔ ✔
F. Predictive probability = Σ(weights·tree predictions) / Σ(weights) — ✔ — ✔ —
G. Recursive/iterative weight update from training data (dep. 3, 6, 8) dep. dep. dep. dep. dep.
H. Leaf node holds probability distribution over symbols (dep. 10, 13, 16–17) dep. dep. dep. dep. dep.
I. Path edge = specific operation OR wildcard (dep. 11–12, 14–15, 18–19) dep. dep. dep. dep. dep.

The heart of the asserted novelty is B ("dynamic/calculated window size") and D+E+F ("sparse prediction trees" combined as a weighted Bayesian mixture). Both are squarely in the prior art, in different references.


2. Prior-art reference inventory

Non-patent literature (all pre-critical-date):

Ref Citation Teaches
Forrest 1996 S. Forrest, S. Hofmeyr, A. Somayaji, T. Longstaff, "A Sense of Self for Unix Processes," 1996 IEEE Symp. Security & Privacy, 120–128 (PDF) Host-based anomaly detection from system-call traces; build a "normal database" of short sequences; detect mismatches; a threshold below/above which behavior is normal/anomalous. Explicitly notes "sequences of lengths 5, 6, and 11."
Hofmeyr 1998 S. Hofmeyr, S. Forrest, A. Somayaji, "Intrusion Detection Using Sequences of System Calls," J. Computer Security 6:151–180 Fixed-window contiguous sequence modeling ("stide"); the canonical fixed-window baseline.
Warrender 1999 C. Warrender, S. Forrest, B. Pearlmutter, "Detecting Intrusions Using System Calls: Alternative Data Models," 1999 IEEE S&P, 133–145 stide/t-stide; the threshold and false-positive/detection tradeoff; comparing alternative probabilistic data models.
Lee & Stolfo 1997/1998 W. Lee, S. Stolfo, P. Chan, "Learning Patterns from Unix Process Execution Traces for Intrusion Detection," AAAI-97 Workshop, 50–56 Prediction models built by machine-learning (decision tree/RIPPER) over normal traces; predicts the nth call from the previous.
Ye 2000 N. Ye, "A Markov Chain Model of Temporal Behavior for Anomaly Detection," 2000 IEEE SMC Info. Assurance & Security Workshop Markov-chain probabilistic model of temporal behavior for anomaly detection — i.e., a probabilistic predictive threshold applied to sequences.
Singer 1997 Y. Singer, "Adaptive Mixtures of Probabilistic Transducers," Neural Computation 9(8):1711–1733 (AT&T Labs) (DOI; NIPS version) A mixture model for probabilistic transducers with an online learning algorithm that infers the structure and estimates the parameters of each transducer, tracking the best model "from an arbitrarily large (possibly infinite) pool of models." This is the mixture-weight / adaptive-weight mechanism.
Marceau 2000 C. Marceau, "Characterizing the Behavior of a Program Using Multiple-Length N-grams," NSPW 2000, 101–110 (DOI) Program behavior modeled as an FSM whose states represent predictive sequences of different lengths, constructed from training data — solving the fixed-N problem by learning the appropriate length.
Ron, Singer, Tishby D. Ron, Y. Singer, N. Tishby, "The Power of Amnesia" / "Learning Probabilistic Automata with Variable Memory Length" (NIPS 1994/COLT) (abstract) Variable memory-length Markov models (probabilistic finite suffix automata) — the exact "sparse Markov"/context-dependent-window foundation.

Patent references (front page):

Ref Subject Relevance
US 6,647,400 (Moran) Filesystem-based host IDS (Justia) Host-based intrusion detection context.
US 6,742,124 (Kilpatrick, et al.) "Sequence-based anomaly detection using a distance matrix" — filed May 8, 2000 (PDF) Real-time sequence-based anomaly detection; an "event window" of recent system calls; compares sequences against a model built from known-good training data; declares anomaly. Directly supplies Elements A + C in the system-call setting.
US 6,963,983 (Munson) Cited on face (Filing date not verified here — see §10.)
US 2002/0138755 (Ko) Cited on face (Filing date not verified here.)

Note the significance of Singer: it was cited by the examiner, yet the patent issued — which suggests the examiner did not find a single reference (or obvious combination) teaching the variable-window element in the system-call context, rather than that the mixture mechanism itself was novel.


3. Ground 1 (primary): Marceau + Singer + Forrest/Hofmeyr/Warrender

This is the cleanest and most damaging combination. It maps element-for-element onto every claim.

What each reference supplies

  • Marceau 2000 → Elements A, B, and (largely) D and I. Marceau explicitly frames and solves the fixed-window problem: "The N-gram characterization… requires the user to choose a suitable value for N. This paper presents an alternative characterization, as a finite state machine whose states represent predictive sequences of different lengths," constructed from training data, and applied to system-call traces of programs. That is precisely "a calculated number of previous operations … determined from a plurality of predetermined sequences" (claim 1(a)) — a context-dependent/learned window size. Marceau's FSM states are predictive sequence contexts, i.e. the same object as the claimed leaf nodes; and the FSM's variable-length state transitions embody context-dependent length and effectively collapse variations at a single call (the wildcard/skip concept of element I).
  • Singer 1997 (and Ron-Singer-Tishby) → Elements D, E, F, G, H. Singer's mixture of probabilistic transducers is a weighted pool of sequence-prediction models whose weights are learned online and which "tracks the best transducer from an arbitrarily large pool." Every claimed feature of the sparse-tree mixture — multiple trees (D), per-tree weights (E), weighted combination (F), online/recursive weight updates (G), and per-context probability distributions (H) — is a standard property of this family. The patent itself characterizes its "sparse prediction tree" as "a type of prediction suffix tree" and "representationally equivalent to a SMT," i.e., the same mathematical object as Singer's probabilistic transducers/suffix trees.
  • Forrest 1996 / Hofmeyr 1998 / Warrender 1999 → Elements A, C and the "system calls" narrowing of claims 4–5. These establish the entire application context: monitoring sequences of system calls, building a normal model from training traces, and thresholding a deviation measure to declare an intrusion. Warrender additionally supplies the probabilistic data-model framing and the ROC/threshold tradeoff that the '741 patent reproduces in its own FIGS. 6–12 (the same DARPA/UNM datasets).

Motivation to combine (the key TSM/KSR inquiry)

  1. The problem is expressly identified in the art, and the patent admits it. Both the '741 Background and Marceau state the same problem — the fixed-window tradeoff (short windows occur more often but are ambiguous; long windows are accurate but sparse). KSR: "where a known problem has a known solution," the solution is obvious. Marceau is the known solution (learn the length from data).
  2. Both are in the same field and same problem space. Marceau is explicitly an intrusion-detection/system-call paper (it appears at a security workshop and is cited in the '741 Background as the multiple-length approach); Forrest/Warrender are the system-call IDS baseline that Marceau measures against. Singer is the general statistical-learning toolbox the field already uses for sequence prediction (Lee & Stolfo use ML; Ye uses Markov; Ghosh uses neural nets). Applying Singer's adaptive mixture to Marceau's variable-length predictive state machine is the ordinary way a PHOSITA would make the length selection automatic — Marceau builds the FSM by hand-tuned construction; Singer gives the principled, data-driven way to pick and weight among many such models.
  3. Predictable result / reasonable expectation of success. The combination yields exactly the claimed benefit — a detector whose effective window size is chosen by the data — with no asserted unexpected property. The '741 patent's own experimental results (FIGS. 6–12) show only incremental improvement over stide/t-stide and fixed-window predictors, which undercuts any argument of unexpected results.
  4. Combining known techniques with known methods. Weighted-mixture-of-experts and Bayesian model-averaging were routine in the statistical-learning art by 2001; applying them to a family of sequence models is a "predictable variation."

Result: Elements A–I all appear; prima facie obviousness of claims 1–19 over Marceau + Singer + Forrest/Hofmeyr/Warrender.


4. Ground 2: Marceau + Singer + Kilpatrick '124 (+ Ye)

Substitute (or add) US 6,742,124 (Kilpatrick) for the Forrest-line references. Kilpatrick is a granted U.S. patent (effective as prior art under §102(e) from its May 8, 2000 filing date) and it teaches, in the exact system-call setting:

  • a real-time sequence-based anomaly detection system;
  • an "event window" holding recent system calls (sliding window over the process's calls);
  • comparison of the observed sequence against a model built from known-good training data; and
  • declaring an anomaly when the sequence is not recognized.

That supplies Elements A and C and the "sequence of system calls" limitations of claims 4–5. Add:

  • Marceau for the learned, variable/context-dependent sequence length (Element B, D, I); and
  • Singer for the weighted-mixture/online-weight machinery (Elements D–H); or, alternatively,
  • Ye 2000 for the explicitly probabilistic Markov predictive model with a threshold (Elements B/C in probabilistic form).

Motivation: identical to Ground 1 — same field (host-based sequence anomaly detection), same recognized problem (fixed window), and complementarity (Kilpatrick supplies the detection scaffold and event window; Marceau+Singer supply the adaptive/variable probabilistic model that the fixed-window scaffold lacks). A PHOSITA seeking to improve Kilpatrick's fixed event window would naturally look to Marceau's learned-length FSM and to Singer's model-averaging.


5. Ground 3: Ron-Singer-Tishby "Power of Amnesia" + Forrest-line (minimal two-reference case)

Even without Marceau, the variable-memory Markov work (Ron, Singer, Tishby) is the "sparse Markov" engine the '741 patent claims. The Power of Amnesia paper states the motivation verbatim: fixed-memory Markov models cannot capture multi-scale structure, while "using long memory models uniformly is not practical," so memory length should vary by context — which is precisely the claimed "calculated number of previous operations," and whose skipped symbols are the claimed wildcards. Combine with the Forrest/Warrender system-call anomaly-detection + threshold framework, and claims 1, 4 and (with the mixture-weights feature from Singer 1997) claims 2, 5, 7 follow.

This ground is notable because it shows the "dynamic window size" concept was already reduced to a general learning algorithm; the only asserted contribution is its application to call-trace IDS — an application of a known technique to an analogous, long-recognized problem.


6. Claim-by-claim mapping (Ground 1)

Claim Element(s) Primary reference(s)
1 A,B,C,D,E Marceau (A,B,D), Singer (D,E), Forrest/Warrender (A,C)
2 +F Singer 1997 (mixture prediction = Σw·P / Σw)
3 +G Singer 1997 (online weight updates from examples)
4 A,B,C,D,E (system calls) as 1, with Forrest/Hofmeyr/Warrender/Kilpatrick supplying "system calls"
5 +F (system calls) as 2
6 +G recursive Singer 1997; and the '741's own Appendix-A recursion is a design choice
7 system/apparatus A,B,C,D,E Forrest + Marceau + Singer
8 +G Singer 1997
9 "operations"=system calls Kilpatrick/Forrest
10, 13, 16, 17 +H (leaf distributions) Ron-Singer-Tishby PSTs; Singer 1997; Marceau FSM states
11, 14, 18 +path = specific operation PST/Markov context definition
12, 15, 19 +path = wildcard "Power of Amnesia" variable-memory skips; Marceau's collapsing of single-call branches; the patent's own call-graph "wildcard" discussion

Every dependent claim adds a feature already conventional in the PST/Markov-mixture art or in variable-memory modeling; none introduces a non-obvious structural or functional advance.


7. Why a PHOSITA would combine — consolidated

  • Same field / same problem. Marceau, Forrest, Hofmeyr, Warrender, Kilpatrick, Ye, Lee-Stolfo all address anomaly detection over program/system-call sequences. Singer and Ron-Singer-Tishby are the standard sequence-modeling toolbox the field already draws on (Lee-Stolfo use ML; Ye uses Markov; the '741 Background cites both).
  • The problem is expressly recognized and the solution known. The fixed-window deficiency is stated in the '741 Background and in Marceau and the Power-of-Amnesia paper. KSR makes the known-problem/known-solution path obvious.
  • Complementarity, not duplication. One reference supplies what to monitor (system calls; host IDS scaffold and threshold), another supplies how to make the window adaptive (Marceau / variable-memory Markov), another supplies how to select and combine competing models automatically (Singer mixture). There is no teaching away; each completes the other.
  • Reasonable expectation of success. All components are individually demonstrated and their union is a routine application with predictable, incremental benefit (as the '741's own results confirm).

8. Anticipated non-obviousness arguments and rebuttals

  1. "The efficient node-weight update (Appendix A) is non-obvious." The claims do not recite the logarithmic/efficient algorithm; they recite functional results ("weighted sum divided by sum of weights," "recursively updating weights"). Singer's online algorithm already produces those results. An unclaimed efficiency improvement cannot rescue the claims.
  2. "The specific combination of variable window + wildcards + tree mixture is novel." Novelty of the combination is not the test; §103 asks whether the combination was obvious to try. Each piece is known, the problem is common to all, and the combination is a predictable aggregation. KSR forecloses the "novel combination" defense where the references are combinable by design.
  3. "Different fields (NLP/speech vs. security)." Singer/Ron-Tishby are general sequence-modeling methods, and the patent itself reuses that vocabulary ("sparse Markov transducer," "prediction suffix tree"). A PHOSITA in anomaly detection would readily analogize; moreover Marceau already bridged statistical sequence modeling and system-call IDS.
  4. "Unexpected results." The '741 FIGS. 6–12 show incremental ROC improvements over stide/t-stide and fixed-window predictors — not the "unexpected" magnitude that would rebut obviousness. No secondary-consideration evidence (long-felt need tied to this specific refinement, licensing, copying) is apparent.

9. Additional observations

  • The claims are drafted at a high level of functional generality ("probabilistic detection model," "sparse prediction tree," "respective weight"). This breadth increases vulnerability to §103, because it reads onto any learned-mixture-of-context-models approach — precisely what Singer + Marceau enables.
  • The applicant's own Background concedes the state of the art and admits Marceau "lacks the ability to define optimal sequence lengths that are determined by a data analysis of the available training data." That admission frames the case: the asserted contribution is data-driven length selection, which is exactly what Marceau's own "construct the finite state machine from training data" describes and what Singer's online learning automates.
  • The pre-grant publication (US 2004/0205474 A1) recited machine-code/application-call embodiments that were dropped or narrowed in the granted claims — worth noting if any post-grant challenge were contemplated, though it doesn't change the §103 analysis of the granted claims.

10. Uncertainties and things I could not verify

  • The "Prior Art section" referenced in the task was not provided. This analysis uses the patent's own cited/background references. If a dedicated Prior Art section (e.g., from an IDS or examiner search report) exists, please supply it — it may add references and strengthen or alter the grounds above.
  • I did not verify the filing/priority dates of US 6,963,983 (Munson) or US 2002/0138755 (Ko) or their substantive disclosures; I relied only on their status as front-page citations. Confirm their §102(e) dates and content before relying on them in any formal challenge. (Search steps were exhausted mid-verification.)
  • I did not obtain full-text page/line or column/line cites for Marceau 2000, Singer 1997, or Kilpatrick '124 beyond the abstracts and quoted passages shown above. A formal invalidity contention would need pin cites to the specification/claims of '124 and to the relevant pages of Marceau and Singer.
  • Munson / Ko disclosure content is unverified. I have not asserted what they teach.
  • This is a technical obviousness analysis, not a legal opinion or a validity determination. Claim construction (especially of "sparse prediction tree," "calculated number of previous operations," and "wildcard") would materially affect the mapping, and the ultimate question is one of law.

Candidate primary grounds (summary):

  1. Marceau + Singer + Forrest/Hofmeyr (or Warrender) — covers all claims 1–19.
  2. Marceau + Singer + Kilpatrick '124 — covers all claims 1–19 in the system-call setting.
  3. Ron-Singer-Tishby ("Power of Amnesia") + Forrest-line (+ Singer 1997 for the mixture claims) — covers claims 1, 4, and with Singer 1997 claims 2, 5, 7 and dependents.
  4. Kilpatrick '124 + Marceau + Ye — alternative system-call-focused ground.

Generated 9/30/2026, 3:42:48 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →