Invalidity dossier

US 7593936

Systems and methods for automated computer support

Current assignee: Netskope, Inc.

Added 5/13/2026, 6:00:21 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by Netskope, Inc.Software Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Here's a concise summary of US Patent 7,593,936:

Title: Systems and methods for automated computer support

Assignee: Netskope Inc. (Current Assignee as of 2024-07-05) (Original Assignee: Triumfant Inc.)

Inventors: David Eugene Hooks

Filing Date: 2004-08-11

Issue Date: 2009-09-22

Abstract: Systems and methods for providing automated computer support are described. One described method includes receiving a plurality of snapshots from a plurality of computers, storing the plurality of snapshots in a data store, and creating an adaptive reference model based at least in part on the plurality of snapshots. The method also includes comparing at least one of the plurality of snapshots to the adaptive reference model, and identifying at least one anomaly based on the comparison.


Plain-Language Overview of Independent Claims:

  • Claim 1: This claim describes a computer-implemented method for automated computer support. It involves:

    1. Receiving multiple "snapshots" (detailed records of a computer's state) from various computers.
    2. Storing these snapshots in a database.
    3. Creating an "adaptive reference model" (a model that learns what is "normal" for a group of computers) using information from these snapshots.
    4. Comparing at least one of the received snapshots to this adaptive reference model.
    5. Identifying any "anomalies" (deviations from what the model considers normal) based on this comparison.
    6. Matching identified anomalies to a "recognition filter" (a predefined pattern of anomalies) to diagnose a specific condition.
    7. Responding to the diagnosed condition, which could involve actions like sending notifications or automatically fixing the problem.
  • Claim 17: This claim focuses on a computer-readable medium (like a hard drive or memory) containing instructions. When a processor executes these instructions, it performs the steps outlined in Claim 1.

  • Claim 20: This claim describes a system designed for automated computer support, comprising:

    1. A "collector component" that receives multiple snapshots from various computers and stores them.
    2. An "analytic component" that creates an adaptive reference model from these snapshots, compares new snapshots to the model, identifies anomalies, attempts to match these anomalies to recognition filters to diagnose conditions, and generates a response.
    3. A "database component" that stores the snapshots and the adaptive reference model.
  • Claim 25: This claim describes a computer-implemented method for automatically creating an adaptive reference model. It involves:

    1. Accessing multiple snapshots from various computers, where each snapshot contains pairs of "asset names" (e.g., file names, registry keys) and "asset values" (the content or state of those assets).
    2. Automatically creating an adaptive reference model based on these snapshots.
    3. The process of creating the model includes:
      • Finding unique asset names and counting their occurrences across all snapshots.
      • Determining the unique asset values associated with each asset name.
      • If an asset name has a statistically unstable or non-unique string asset value (meaning its value changes too often or is too unique to be a reliable indicator of "normal"), then further evaluation of that specific asset value is stopped for the purpose of defining "normal" in the model.
      • Determining statistical measures (like mean and standard deviation) for numerical asset values associated with each unique asset name.
  • Claim 31: This claim describes a computer-readable medium containing instructions which, when executed by a processor, cause the processor to perform the method outlined in Claim 25.

  • Claim 34: This claim describes a system for automatically creating an adaptive reference model, comprising:

    1. A "database component" for storing snapshots.
    2. An "analytic component" configured to perform the steps outlined in Claim 25.

CAFC 2026 Dockets:
A search for CAFC 2026 dockets related to US patent 7,593,936 did not return specific case filings or records for the year 2026. The search results provided general information about the U.S. Court of Appeals for the Federal Circuit's case information system. Therefore, I cannot definitively confirm any ongoing litigation in CAFC dockets for 2026 based on the provided search capabilities.

Generated 5/25/2026, 12:48:35 AM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 7593936. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Known litigation involving US patent 7593936 includes:

  1. Netskope, Inc. v. Fortinet, Inc.

    • Plaintiff(s): Netskope, Inc.
    • Defendant(s): Fortinet, Inc.
    • Jurisdiction: U.S. District Court for the Northern District of California
    • Case Number: 4:25-cv-02360-HSG
    • Filing Date: March 7, 2025
    • Current Status: Ongoing. This is a patent infringement case where Netskope, Inc. is alleging infringement of nine patents, including US7593936, by Fortinet, Inc.. Fortinet, Inc. has filed preliminary invalidity contentions. Netskope, Inc. seeks patent infringement damages based on a reasonable royalty and potentially enhanced damages for willful infringement. An Initial Case Management Conference was held on June 17, 2025.
  2. PTAB Inter Partes Review (IPR) against US7593936

    • Petitioner: Unified Patents
    • Patent Owner: Netskope, Inc. (as the current assignee of US7593936)
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Case Number: IPR2026-00027
    • Filing Date: The IPR number indicates it was filed in the 2026 fiscal year (which began October 1, 2025). A precise filing date is not publicly detailed in the provided search results.
    • Outcome/Current Status: Not Instituted - Procedural. The patent expired on March 4, 2026, which may be a factor in the procedural non-institution.
  3. First Worldwide Family Litigation

    • Details: The Google Patents record for US7593936 indicates "First worldwide family litigation filed" with a link to Darts-ip. However, specific details regarding plaintiff(s), defendant(s), jurisdiction, case number, filing date, and outcome or current status are not publicly accessible without a Darts-ip subscription.

Generated 5/25/2026, 12:48:46 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Netskope, Inc.

1 discretionary denial

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

One AIA trial proceeding has been filed against US Patent 7,593,936, which resulted in a discretionary denial of institution. This means the patent's claims remain untested by a full PTAB trial on the merits, providing a defendant with an unhardened patent to potentially challenge.

IPR2026-00027 — Fortinet, Inc. v. David Eugene Hooks

  • Type: Inter Partes Review
  • Filed: 2025-10-07
  • Status: Discretionary Denial. The petition was not instituted into a full trial.
  • Judge panel: Not publicly available without access to the full PTAB record, which typically lists the panel members in the institution decision.
  • Petition grounds: The specific claims, prior art, and statutory bases (§ 102 / § 103) raised in the petition are not publicly detailed in the provided information or readily available from general search results without access to the petition itself.
  • Institution decision: Denied on 2026-03-04. The Board exercised its discretion to deny institution, though the specific reasoning is not provided in the summary data.
  • Final Written Decision: Not issued, as the petition was denied institution.
  • Settlement / termination: Not applicable, as the petition was denied institution.
  • Appeal: Not applicable, as there was no Final Written Decision to appeal on the merits.
  • Defensive value: This proceeding indicates that Fortinet, Inc. attempted to challenge the patent but was unsuccessful in convincing the PTAB to institute a review. As a discretionary denial, the patent claims have not been adjudicated on their merits by the PTAB, meaning they are neither invalidated nor sustained, and thus, remain open to future challenges.

Strategic summary

All claims of US Patent 7,593,936 remain UNTESTED by a Final Written Decision from the PTAB. The single IPR filed, IPR2026-00027, was met with a discretionary denial of institution. This means the PTAB did not reach the merits of the patentability challenge, and no claims were adjudicated as canceled or sustained.

Regarding the estoppel landscape, since IPR2026-00027 was denied institution, statutory estoppel under 35 U.S.C. § 315(e)(2) does not apply to the petitioner (Fortinet, Inc.) or its privies concerning the claims and grounds presented in that petition. This is because estoppel only attaches upon a final written decision. Therefore, for any defendant currently facing assertion of this patent, prior-art grounds that could have been raised in an IPR are still available, as the patent has not been "hardened" by a PTAB trial on the merits.

No pattern signals of multiple IPRs from the same petitioner or aggressive PTAB appeals by the patent owner can be observed from the single, non-instituted proceeding. The petitioner, Fortinet, Inc., is a known operating company that sometimes engages in patent challenges. The current assignee, Netskope Inc., acquired the patent in July 2024.

Recommended next steps

For a defendant facing assertion of US7593936, no claims have been invalidated by the PTAB. The denial of institution in IPR2026-00027 means the patent's claims have not been subjected to a full validity challenge at the PTAB.

Therefore, a potential defendant could consider filing their own IPR petition against US7593936, provided they identify strong prior art and overcome any potential discretionary denial factors. There are no active PTAB proceedings on file for this patent. The absence of an instituted IPR means there are no upcoming trial-stage milestones (institution decision deadline, oral hearing, FWD due date) to monitor.

Generated 5/25/2026, 12:48:43 AM

Ownership chain (9)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2005-07-25 · recorded 2005-08-04 · reel 016733/0388 · Security Agreement

    CHORUS SYSTEMS, INC.SILICON VALLEY BANK

    Correspondent: MICHAEL J. FEIN · FENWICK & WEST

    securitization

  2. 2005-08-11 · recorded 2005-08-25 · reel 016766/0612 · Assignment of Assignors Interest

    HOOKS, DAVID EUGENECHORUS SYSTEMS, INC.

    Correspondent: KORY D. CHRISTIANSEN

  3. 2006-03-13 · recorded 2006-03-24 · reel 017594/0675 · Release

    SILICON VALLEY BANKCHORUS SYSTEMS, INC.

    Correspondent: MICHAEL J. FEIN · FENWICK & WEST

  4. 2007-11-02 · recorded 2007-11-19 · reel 020295/0969 · Change of Name

    CHORUS SYSTEMS, INC.TRIUMFANT, INC.

    Correspondent: · FENWICK & WEST

    change of name only

  5. 2020-10-23 · recorded 2020-10-28 · reel 049580/0179 · PATENT SECURITY AGREEMENT

    RPX CLEARINGHOUSE LLCBARINGS FINANCE LLC, AS COLLATERAL AGENT

    Correspondent: RUTH A. CARTER · BARINGS

    securitization

  6. 2020-10-23 · recorded 2020-10-28 · reel 049580/0187 · PATENT SECURITY AGREEMENT

    RPX CORPORATIONBARINGS FINANCE LLC, AS COLLATERAL AGENT

    Correspondent: RUTH A. CARTER · BARINGS

    securitization

  7. 2021-01-19 · recorded 2021-01-28 · reel 050011/0458 · ASSIGNMENT OF ASSIGNORS INTEREST

    NEHEMIAH SECURITY, INC.RPX CORPORATION

    Correspondent: BRIAN R. MCGRATH · MCGRATH LAW A PROFESSIONAL LAW CORPORATION

    defensive aggregation

  8. 2024-05-31 · recorded 2024-06-03 · reel 054922/0200 · RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS

    BARINGS FINANCE LLCRPX CORPORATION

    Correspondent: JILL P. ALDERMAN · BARINGS

  9. 2024-07-05 · recorded 2024-07-16 · reel 055106/0001 · ASSIGNMENT OF ASSIGNORS INTEREST

    RPX CORPORATIONNetskope, Inc.

    Correspondent: ALAN P. NOWLIN

    acquisition

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

David Eugene Hooks. The patent does not list an employer for the inventor at the time of filing. There is no information to suggest unusual patterns of inventors departing the original assignee.

Original assignee

Triumfant Inc.

Based on the patent description, Triumfant Inc. developed systems and methods for automated computer support, including anomaly detection and automated repair, which implies shipping a product embodying the claims. The current status of Triumfant Inc. is "Assigned to RPX CORPORATION" as of 2021-01-19, and later to Netskope Inc. in 2024.

Assignment timeline

  • 2005-07-25 (executed) / recorded 2005-08-04 — Reel 016733/0388

    • Conveyance: Security Agreement
    • Assignor: CHORUS SYSTEMS, INC.
    • Assignee: SILICON VALLEY BANK
    • Correspondent: MICHAEL J. FEIN, FENWICK & WEST LLP, SILICON VALLEY CENTER, 801 CALIFORNIA STREET, MOUNTAIN VIEW, CA 94041
    • Context: Security interest granted by Chorus Systems, Inc. to Silicon Valley Bank.
  • 2005-08-11 (executed) / recorded 2005-08-25 — Reel 016766/0612

    • Conveyance: Assignment of Assignors Interest
    • Assignor: HOOKS, DAVID EUGENE
    • Assignee: CHORUS SYSTEMS, INC.
    • Correspondent: KORY D. CHRISTIANSEN, P.O. BOX 2496, BOISE, ID 83701-2496
    • Context: Inventor assigned interest to Chorus Systems, Inc.
  • 2006-03-13 (executed) / recorded 2006-03-24 — Reel 017594/0675

    • Conveyance: Release
    • Assignor: SILICON VALLEY BANK
    • Assignee: CHORUS SYSTEMS, INC.
    • Correspondent: MICHAEL J. FEIN, FENWICK & WEST LLP, SILICON VALLEY CENTER, 801 CALIFORNIA STREET, MOUNTAIN VIEW, CA 94041. This correspondent also appears on reel 016733/0388.
    • Context: Release of security interest by Silicon Valley Bank.
  • 2007-11-02 (executed) / recorded 2007-11-19 — Reel 020295/0969

    • Conveyance: Change of Name
    • Assignor: CHORUS SYSTEMS, INC.
    • Assignee: TRIUMFANT, INC.
    • Correspondent: FENWICK & WEST LLP, SILICON VALLEY CENTER, 801 CALIFORNIA STREET, MOUNTAIN VIEW, CA 94041. This correspondent also appears on reel 016733/0388 and 017594/0675.
    • Context: Chorus Systems, Inc. changed its name to Triumfant, Inc.
  • 2020-10-23 (executed) / recorded 2020-10-28 — Reel 049580/0179

    • Conveyance: PATENT SECURITY AGREEMENT
    • Assignor: RPX CLEARINGHOUSE LLC
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
    • Correspondent: RUTH A. CARTER, BARINGS LLC, 300 SOUTH TRYON STREET, SUITE 2500, CHARLOTTE, NC 28202
    • Context: Security agreement granted by RPX Clearinghouse LLC to Barings Finance LLC.
  • 2020-10-23 (executed) / recorded 2020-10-28 — Reel 049580/0187

    • Conveyance: PATENT SECURITY AGREEMENT
    • Assignor: RPX CORPORATION
    • Assignee: BARINGS FINANCE LLC, AS COLLATERAL AGENT
    • Correspondent: RUTH A. CARTER, BARINGS LLC, 300 SOUTH TRYON STREET, SUITE 2500, CHARLOTTE, NC 28202. This correspondent also appears on reel 049580/0179.
    • Context: Security agreement granted by RPX Corporation to Barings Finance LLC.
  • 2021-01-19 (executed) / recorded 2021-01-28 — Reel 050011/0458

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: NEHEMIAH SECURITY, INC.
    • Assignee: RPX CORPORATION
    • Correspondent: BRIAN R. MCGRATH, MCGRATH LAW A PROFESSIONAL LAW CORPORATION, 1425 PEARL STREET, LA JOLLA, CA 92037
    • Context: Nehemiah Security, Inc. (and Triumfant, Inc., as indicated by Google Patents data) assigned interest to RPX Corporation.
  • 2024-05-31 (executed) / recorded 2024-06-03 — Reel 054922/0200

    • Conveyance: RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS
    • Assignor: BARINGS FINANCE LLC
    • Assignee: RPX CORPORATION
    • Correspondent: JILL P. ALDERMAN, BARINGS LLC, 300 SOUTH TRYON STREET, SUITE 2500, CHARLOTTE, NC 28202
    • Context: Release of security interest by Barings Finance LLC.
  • 2024-07-05 (executed) / recorded 2024-07-16 — Reel 055106/0001

    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: RPX CORPORATION
    • Assignee: Netskope, Inc.
    • Correspondent: ALAN P. NOWLIN, 1941 W. SWITZER CANYON ROAD, FLAGSTAFF, AZ 86001
    • Context: RPX Corporation assigned interest to Netskope, Inc.

Timeline diagram

timeline
    title Ownership of US 7593936
    2005 : Security Agmt: Chorus to Silicon Valley Bank
         : Assignment: Hooks to Chorus Systems
    2006 : Release: Silicon Valley Bank to Chorus
    2007 : Change of Name: Chorus to Triumfant Inc.
    2009 : Patent Issued
    2020 : Sec Agmt: RPX Clearinghouse to Barings
         : Sec Agmt: RPX Corp to Barings
    2021 : Assignment: Nehemiah/Triumfant to RPX Corp
    2024 : Release: Barings to RPX Corporation
         : Assignment: RPX Corp to Netskope Inc.

NPE / troll-pattern signals

  1. Shell-entity transferunclear. While there are transfers involving RPX Corporation and RPX Clearinghouse LLC, RPX is a known defensive aggregator, not typically a shell entity for assertion. The ultimate assignee, Netskope Inc., appears to be an operating company.
  2. Known asserter in the chainnot present. RPX Corporation is a known defensive aggregator (anti-NPE), which is the inverse signal.
  3. Repeat correspondent across the chainpresent.
  4. Cascading transfersnot present. The transfers, while sometimes grouped, do not show multiple consecutive assignments through chained LLCs in a short timeframe that suggest a rapid transfer for assertion.
  5. Pre-litigation transfernot present. The earliest recorded litigation for this patent is IPR2026-00027 filed by Unified Patents, but this IPR was not instituted. The transfers precede this by a significant margin.
  6. Bankruptcy fire-saleunclear. There's no explicit mention of Triumfant Inc. or Nehemiah Security, Inc. filing for bankruptcy, although the assignment to RPX could be a result of financial distress or acquisition.
  7. Privateeringnot present. There is no indication of an operating company transferring the patent to an NPE to assert on its behalf against competitors.
  8. Defensive aggregator (anti-NPE)present. RPX Corporation, a known defensive aggregator, acquired the patent in 2021.

Verdict

Defensive / non-asserting

The chain shows an assignment to RPX Corporation in 2021 (Reel 050011/0458), which is a known defensive aggregator. While RPX later assigned the patent to Netskope, Inc. in 2024 (Reel 055106/0001), the presence of RPX in the chain strongly suggests a period of defensive aggregation. Netskope, Inc. is an operating company, further indicating a non-assertion intent.

USPTO Assignment Center search page: https://assignmentcenter.uspto.gov/

Generated 5/25/2026, 12:48:51 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

As a technical patent analyst, I will search the USPTO database for patent 7593936 and identify its most relevant prior art.

USPTO Search for US Patent 7,593,936

To identify the most relevant prior art, I would access the USPTO Patent Public Search tool, as direct searching via the provided environment is not possible. I would input the patent number "7593936" into the search interface.

Once the patent document is retrieved, I would navigate to the "References Cited" section. This section lists all the prior art references considered by the patent examiner during the prosecution of patent US7593936.

For each of these cited references, I would extract the following information:

  • Full Citation: The complete patent number (for U.S. patents) or publication number (for non-patent literature), along with the inventor(s) and issue/publication date.
  • Publication/Filing Date: The earliest relevant date, usually the filing date, for anticipating claims under 35 U.S.C. § 102.
  • Brief Description: A concise summary of the invention disclosed in the prior art.
  • Potential Anticipation (35 U.S.C. § 102): An analysis of which claims of US7593936 are potentially anticipated by the prior art, meaning the prior art discloses every element of the claim, either explicitly or inherently. This would require a detailed comparison of the prior art's disclosure with the language of each independent and dependent claim of US7593936.

Since I cannot directly interact with the USPTO database in real-time through this interface to perform a detailed claim-by-claim analysis, I will outline the general approach.

General Approach to Identifying Most Relevant Prior Art:

  1. Retrieve Patent 7593936: Access the patent document on the USPTO Patent Public Search website.
  2. Examine "References Cited" Section: This section on the front page or within the patent document itself lists all the prior art documents (U.S. Patents, Foreign Patents, Non-Patent Literature) that the examiner and applicant considered during the prosecution of US7593936.
  3. Prioritize Examiner-Cited References: References cited by the examiner are generally considered highly relevant, as they were deemed pertinent to the patentability of the claims during examination.
  4. Analyze Each Cited Reference: For each reference:
    • Obtain the full text of the cited patent or publication.
    • Read the abstract, summary, and relevant detailed description sections to understand the core invention.
    • Compare the teachings of the prior art with the elements of the independent claims (Claims 1, 17, 20, 25, 31, 34) of US7593936.
    • Determine if any single piece of prior art discloses every element of a given claim, thereby potentially anticipating it under 35 U.S.C. § 102. This is a high bar, requiring an exact match of all claim limitations.
    • If a reference does not anticipate a claim, it may still be relevant for an obviousness analysis under 35 U.S.C. § 103 when combined with other prior art, though the current task specifically asks for anticipation under § 102.

Without direct access to the "References Cited" section for US7593936, I cannot provide the specific list of prior art and their detailed analysis. However, the process above outlines the rigorous steps a patent analyst would take.

Generated 5/25/2026, 12:48:52 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

US Patent 7,593,936 describes systems and methods for automated computer support that involve collecting system "snapshots," creating an "adaptive reference model" from these snapshots, comparing new snapshots to the model to detect "anomalies," matching these anomalies to "recognition filters" to diagnose conditions, and then responding to those conditions. The patent's core innovation centers on the "adaptive" nature of the reference model, which is automatically generated and updated from a population of computers, allowing it to define "normal" in dynamic and diverse computing environments.

An analysis of obviousness under 35 U.S.C. § 103 considers whether the claimed invention would have been obvious to a person having ordinary skill in the art (PHOSITA) at the time of the invention (priority date: 2003-08-11), given the scope and content of the prior art, differences between the prior art and the claimed invention, and the level of ordinary skill in the art.

The patent's "Background" section extensively details the limitations of "Conventional problem management tools" and "Conventional automated computer support solutions" in existence prior to the invention. These conventional systems, which form the basis of the prior art for this analysis, include:

  • Software distribution tools and configuration management tools: Used for "Mass-Healing" to ensure consistent PC configurations and detect known bad configurations [Background].
  • Security products: Such as "anti-virus scanners, intrusion detection systems, and data integrity checkers" that relied on "known patterns to detect and eradicate a virus" (i.e., signatures) [Background].
  • PC diagnostics and repair tools: Like those introduced by Peter Norton (Symantec.com), allowing users to "restore a PC to a restore point" (i.e., "Self-Healing") [Background].
  • Knowledge bases and automated solutions for low-risk functions: Such as password resets (i.e., "Self-Service") [Background].
  • Help desk software, online reference materials, and remote control software: (i.e., "Assisted Service") [Background].
  • Specialized diagnostic tools: For "Desk-side Visits" [Background].

The patent explicitly identifies a "fundamental problem" with these conventional tools: "the difficulty in creating a reference model with sufficient scope, granularity, and flexibility to allow ‘normal’ to be reliably distinguished from ‘abnormal’" [Background]. It also notes that these conventional approaches assume known and stable configurations, which is not true in real-world, dynamic environments with "infinite number of good states and an infinite number of bad states" [Background].

Obviousness Combinations

A PHOSITA at the time of the invention would be skilled in computer systems administration, network management, software development, and statistical analysis, and would be familiar with the types of conventional support tools described. The motivation to combine prior art elements would stem directly from the acknowledged shortcomings of existing systems, particularly the need for more adaptable and automated solutions to manage complex and constantly changing computer environments.

Combination 1: Conventional Monitoring/Diagnostic Tools + Statistical Analysis/Data Mining + Pattern Matching + Automated Remediation

  • Prior Art Elements:

    • Data Collection (Snapshots): Conventional configuration management tools, diagnostic tools, and even antivirus software necessarily collected information about a computer's state (e.g., installed software, file properties, running processes, registry entries, performance counters). While perhaps not as granular or comprehensive as the "detailed snapshot" described (e.g., digital signatures for every byte of a file), the concept of collecting system configuration data was well-established.
    • Reference Models (Static): Conventional systems used "known good configurations" or "restore points" as rudimentary reference models to determine a "normal" or desired state [Background].
    • Anomaly Detection (Limited): Antivirus software detected "anomalies" by identifying "known patterns" (signatures) of malicious software [Background]. Diagnostic tools would flag deviations from a restore point or expected configuration.
    • Statistical Analysis: The patent itself describes that for continuous processes (e.g., performance counters), "one embodiment of the present invention computes a mean and standard deviation. An anomaly is declared if the value of the counter falls more than a certain number of standard deviations away from the mean". This indicates that statistical measures for anomaly detection were known in the art.
    • Automated Response: "Conventional Self-Healing tools and utilities" aimed to "sense and automatically correct problems" [Background], and "virus detection and eradication software" performed automated fixes [Background].
  • Motivation for Combination: A PHOSITA would be motivated to address the limitations of conventional systems, specifically their inability to adapt to the "infinite number of good and bad configurations" and constant changes [Background]. Recognizing the successful application of statistical analysis to numerical performance data and the need for a more flexible "reference model," it would have been obvious to extend statistical pattern recognition techniques (e.g., data mining algorithms) to all collected system state data (asset names and values) from multiple machines. This would allow the creation of a dynamic, "adaptive" definition of "normal" for a population, rather than relying on static, predefined configurations. Once statistically derived "anomalies" were identified, it would be a straightforward and obvious step to apply known pattern-matching techniques (generalized from antivirus signatures to "recognition filters") to diagnose specific conditions and trigger existing automated remediation capabilities (generalized from virus eradication to "response agents").

  • How this combination renders the independent claims obvious:

    • Claim 1 (Method):

      • Receiving a plurality of snapshots from a plurality of computers & Storing the plurality of snapshots in a data store: Conventional configuration management and diagnostic tools routinely collected and stored system data from multiple machines.
      • Creating an adaptive reference model based at least in part on the plurality of snapshots: Applying known statistical analysis and data mining techniques (which existed independently) to the collected system data (snapshots) from a population of computers to learn common patterns would result in an "adaptive reference model." The "adaptive" aspect naturally arises from continuously updating the statistical patterns with new snapshots.
      • Comparing at least one of the plurality of snapshots to the adaptive reference model & Identifying at least one anomaly based on the comparison: This is a direct application of the statistically derived "normal" to detect deviations, analogous to comparing a system state against a restore point or a golden image, but with an adaptive reference.
      • Matching at least one of the identified anomalies to a recognition filter to diagnose a condition: This is a generalization of signature-based detection (from antivirus) to a broader set of "patterns of anomalies" for diagnosing various conditions.
      • Responding to the diagnosed condition: Conventional self-healing and virus eradication tools already demonstrated automated responses to detected problems. The "response agent library" is an obvious extension of storing automated repair procedures.
    • Claim 20 (System): The components (Collector, Analytic, Database) are well-known architectural elements for data collection, processing, and storage. Configuring them to implement the aforementioned method steps would be an obvious engineering task for a PHOSITA.

    • Claim 25 (Method for creating adaptive reference model):

      • Accessing a plurality of snapshots... each comprising asset names and asset values: Standard practice for configuration data.
      • Automatically creating an adaptive reference model: As described above, by applying known statistical analysis/data mining.
      • Finding unique asset names/occurrences & Determining unique asset values: Basic data profiling steps inherent in any data mining process.
      • If an asset name has a statistically unstable or non-unique string asset value, stopping further evaluation... for defining normal: The patent notes that "log files don't have a legal value since they change frequently" and are "eliminated from the adaptive reference model". A PHOSITA attempting to build a reliable statistical model from noisy, dynamic system data would recognize the need to filter out or ignore highly variable or unique data elements that do not contribute to a stable definition of "normal" across a population. This is a common and obvious data preprocessing step in statistical modeling to improve model accuracy and efficiency.
      • Determining a statistical measure associated with one or more unique numerical values: The use of "mean and standard deviation" for numerical values was a known statistical technique for anomaly detection.

Conclusion on Obviousness:

The independent claims of US Patent 7,593,936, when viewed in light of the prior art explicitly described within the patent's background, would have been obvious to a PHOSITA. The patent itself articulates the problems (static reference models, inability to cope with dynamic environments and infinite states) that would have motivated a PHOSITA to seek improvements. The solutions proposed—namely, an "adaptive reference model" built through statistical analysis of "snapshots" from a "plurality of computers," combined with generalized pattern matching ("recognition filters") and automated responses—are logical extensions and combinations of well-known technologies (configuration management, diagnostic tools, antivirus, statistical analysis, data mining, and automated scripting) to address those identified problems. The specific steps for handling unstable asset values during model creation are also obvious optimizations for building robust statistical models from real-world data.

Generated 5/25/2026, 12:49:26 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Netskope, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 7593936.