Invalidity dossier

US 8402543

Machine learning based botnet detection with dynamic adaptation

Current assignee: Boeing Co

Added 9/20/2026, 6:23:07 AM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative information on this patent, including any litigation activity.

Let me dig deeper on litigation, the claim set, and any 2026 appellate docket.

A few more targeted checks on claims, litigation, and PTAB activity.

US 8,402,543 B1 — Verified Bibliographic Record

I ran targeted searches restricted to "8402543" / "US8402543" and filtered out near-miss identifiers. The record below is taken from the authoritative patent text supplied to me (Google Patents full text, fetched 2026‑09‑20) and cross‑checked against secondary sources (Justia Patents, USPTO.report, FreePatentsOnline, SumoBrain).

Title: Machine learning based botnet detection with dynamic adaptation

Patent number: US 8,402,543 B1 (grant publication; no pre‑grant publication for this number)

Application number: US 13/072,290

Inventors: Supranamaya Ranjan; Feilong Chen

Assignee / owner of record:

  • Original assignee: Narus, Inc. (Sunnyvale, CA)
  • Assignment recorded 2011‑03‑25 (NARUS, INC.; assignors Ranjan and Chen)
  • Reassignment recorded 2020‑06‑01 to The Boeing Company (merger; assignor Narus, Inc.)
  • Google Patents currently lists both "Boeing Co" and "Narus Inc" as current assignees. Note that Boeing's public announcement of its acquisition of Narus is dated 2010‑07‑29 (https://boeing.mediaroom.com/2010-07-29-Boeing-Completes-Acquisition-of-Narus), which is a different transaction from the 2020 merger assignment; I have not independently verified the document behind the 2020 record.

Filing date: 2011‑03‑25 (priority date also 2011‑03‑25; no earlier priority claim)

Issue/grant date: 2013‑03‑19

Term: Google Patents lists legal status "Active, expires 2031‑08‑04" (i.e., the 20‑year term from 2011‑03‑25 as adjusted under 35 U.S.C. §154(b)). I could not verify the underlying patent term adjustment document or maintenance‑fee payment history independently, so treat the 2031‑08‑04 date as the surface record rather than a confirmed legal conclusion.

Prosecution details: 27 claims, 6 drawing sheets. Attorney/agent of record: Fernandez & Associates, LLP. Examiners named in the printed patent: a Primary Examiner and Assistant Examiner John B King. Classifications: H04L63/1408, H04L63/1416, H04L2463/144 (plus H04L2463/00).

Abstract (verbatim): "Embodiments of the invention address the problem of detecting bots in network traffic based on a classification model learned during a training phase using machine learning algorithms based on features extracted from network data associated with either known malicious or known non-malicious client and applying the learned classification model to features extracted in real-time from current network data. The features represent communication activities between the known malicious or known non-malicious client and a number of servers in the network."


Plain-Language Overview of the Independent Claims

The patent presents three aspects in its Summary — a method, a system, and a non‑transitory computer readable medium (CRM). From the claim text visible in search results (e.g., "The system of claim 14…", "The system of claim 18…", "The system of claim 19…", "The system of claim 25…"), the 27‑claim set is consistent with: claims 1–13 (method chain), claims 14–26 (system chain), and claim 27 (CRM). I state the claim numbers for the system and CRM independent claims with moderate — not high — confidence, since I could not retrieve the complete claim listing; the claim substance below is directly supported by the patent's own Summary text.

Claim 1 — Method for botnet detection in a network (independent).
A processor does the following:

  1. From traffic between a known malicious client and many servers, extract a "malicious data instance": one feature per server, each feature measuring how much communication occurred between that client and that server (flows, packets or bytes over a fixed window).
  2. Do the same for a known non‑malicious client, producing a "non‑malicious data instance" in the same vector format.
  3. Put both instances into a training data set containing many malicious and non‑malicious instances, each tied to one of the classified clients.
  4. Using a pre‑determined machine‑learning algorithm (the spec's implementation is LS‑SVM), generate a classification model that outputs a malicious label for malicious instances and a non‑malicious label for non‑malicious instances.
  5. Extract the same style of feature vector for an unclassified client (its traffic against the same server set).
  6. Apply the model to that unclassified instance to produce a classification label.
  7. If the label is the malicious label, identify that unclassified client as associated with a botnet.

In short: learn the "who talks to which servers" signature of known bots vs. known good clients, then flag any new client whose server‑contact pattern matches the bot pattern.

Claim 14 — System for botnet detection in a network (independent).
The apparatus counterpart of claim 1, reciting a hardware processor plus cooperating modules:

  • a feature extractor that extracts the malicious, non‑malicious and unclassified data instances and assembles the training data set;
  • a model generator that generates the classification model from the training data set using the pre‑determined machine‑learning algorithm;
  • an online classifier that applies the model to an unclassified instance, and, when the resulting label is malicious, identifies the client as a botnet‑associated client; and
  • a repository storing the data instances and the model.

Claim 14's dependent claims add the SVM mechanics (constrained optimization criterion in variables w, b and margins eᵢ, conversion to an unconstrained formulation, solving for the maximum‑margin hyperplane, and applying f(x)=sign[wᵀx+b]) and the adaptation features (expanding the feature vectors with newly observed servers; retraining incrementally; bounding training‑set size by removing instances selected by age or by low contribution/least influence on the decision surface).

Claim 27 — Non‑transitory computer readable medium (independent).
The software counterpart of claim 1: stored instructions that, when executed, perform the identical sequence — extract malicious and non‑malicious instances, assemble the training set, learn the model, extract the unclassified instance, label it, and identify the client as botnet‑associated when the label is malicious.

Key claim‑level takeaway: the independent claims are drafted to be met by counts of communication activity per (client, server) pair — the patent stresses that this can be done from layer‑3 information only, making the approach robust to encryption and to payload‑obfuscation defenses (Spec., "the features may be derived by using only the layer-3 communication activity information… delivers higher performance in botnet detection even in the environment of encrypted traffic flows").


CAFC 2026 Dockets and USPTO Litigation/PTAB Post‑Grant Activity

I found no evidence of any Federal Circuit appeal in 2026 (or any year) involving U.S. 8,402,543, and no IPR/PGR/CBM proceeding against it. My searches for "8402543" combined with CAFC, appeal, IPR and PTAB returned only unrelated 2026 Federal Circuit matters — e.g., Apple v. SpaceTime3D (No. 25‑1022), In re Incept LLC (catheter claim construction, Sept. 2026), Netlist v. Micron (argument recap, Sept. 2026), Teva v. Lilly (Apr. 16, 2026), and Moskowitz Family LLC v. Globus Medical (No. 24‑1696) — none of which involve this patent or these parties.

Caveats I want to be explicit about:

  • I could not query PACER or the CAFC docket system directly; my checks relied on public web indexes. A live PACER/CAFC docket or Docket Navigator search is required for a definitive "no litigation/appeal" statement.
  • The Google Patents record for US 8,402,543 shows no litigation or PTAB events, which is consistent with (but not proof of) the absence of such proceedings.
  • The patent's assignee history (Narus → Boeing) means any litigation would likely be styled under Boeing/Narus; nothing surfaced under either name in connection with this number.

Identifiers That Must Not Be Confused With This Patent

Per your strict‑interpretation instruction, these surfaced in the same searches and are different legal instruments:

  • NL 8402543 A — Dutch application, "Synchroonmotor" (synchronous motor), filed 1984‑08‑20, published 1986‑03‑17. Unrelated technology and jurisdiction.
  • MU 8402543‑3 (Brazil, INPI) — utility model filed 2004‑10‑21, "Disposição em semi‑reboque portuário" (port semi‑trailer). Unrelated.
  • Various third‑party patents/pages that merely cite US 8,402,543 (e.g., US 8,578,493, US 10,911,472, US 10,320,810, US 10,846,404, US 10,321,270). A search snippet that displayed Damballa/HelpSystems assignment and maintenance‑fee events alongside "US8402543B1" was actually the citation table of a different patent (US 2014/0068763 A1); those events do not belong to 8,402,543.

Stated Uncertainties and Internal Inconsistencies in the Source

  1. Independent claim numbering (claims 14 and 27): inferred from dependent‑claim cross‑references and the three aspects in the Summary; not verified against the full printed claim set. Treat claim numbers as provisional, though the three independent claim concepts are certain.
  2. Priority date discrepancy: the Unified Patents portal entry for US‑8402543‑B1 lists a priority date of 2011‑03‑24, whereas the authoritative Google Patents full text (and Justia, USPTO.report) state 2011‑03‑25 for both filing and priority. I follow the authoritative text: 2011‑03‑25.
  3. Expiration/mainenance status: the "expires 2031‑08‑04 / Active" indication is from Google Patents and reflects an assumed PTA; I have not confirmed fee payments or the §154(b) award.
  4. Assignee "current" status: two assignees are listed (Boeing Co and Narus Inc) following a 2020 merger assignment; the exact chain of title and whether Boeing alone is the present owner is not something I can confirm with high confidence from these sources.
  5. Figure‑numbering errors inside the patent: the specification text refers to "FIG. 2" as the method flowchart and "FIG. 2" again where FIG. 3 is intended, and to "training data set (130)" and "(134)" interchangeably (also "un classified data instaces"). These are drafting errors in the document itself, not transcription errors on my part; they do not change the claims, but they matter if you later rely on the specification for claim construction.

Bottom line: US 8,402,543 is a Narus (now Boeing) patent with two inventors, filed and issued on the dates above, claiming a three‑track family (method, system, CRM) around ML‑based bot detection from per‑server communication‑volume features with incremental LS‑SVM retraining; I found no 2026 CAFC docket or USPTO post‑grant challenge tied to it, and I flag the claim‑number and priority‑date details as partially inferred rather than definitively confirmed.

Generated 9/20/2026, 12:48:46 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 8402543. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search for litigation involving US patent 8402543 across the specified sources.

Let me search more specifically for litigation records tied to this patent.

Let me search more targeted litigation databases.

Summary: Litigation search for US Patent 8,402,543

Bottom line: I could not identify any litigation involving US Patent 8,402,543. Based on the sources searched, there is no evidence that this patent has ever been asserted in a district court case, an ITC Section 337 investigation, an IPR/PGR at the PTAB, or an appeal at the CAFC.

What I searched

I ran multiple queries against litigation-oriented sources, including the Unified Patents patent/litigation portal, Google Patents (which maintains a "Litigation" section for asserted patents), Justia Dockets, Docket Alarm, and general web search for the patent number rendered as both "8402543" and "8,402,543." None returned a case, docket, complaint, or PTAB proceeding naming this patent.

Patent identity (for literal-identification purposes)

  • Patent: US 8,402,543 B1
  • Title: "Machine learning based botnet detection with dynamic adaptation"
  • Application No.: 13/072,290 — filed March 25, 2011
  • Grant date: March 19, 2013
  • Inventors: Supranamaya Ranjan; Feilong Chen
  • Original assignee: Narus, Inc.
  • Current assignee: The Boeing Company (assignment recorded June 1, 2020, "MERGER"); Google Patents also lists Narus, Inc.
  • Legal status: Active; adjusted expiration cited as 2031-08-04

Important caveats

  1. Sources that returned no hits. The searches surfaced citations to this patent (e.g., it is cited as prior art in later patents such as US 8,555,388, and it cites earlier Narus work), but none indicated it was ever the asserted patent in litigation. Google Patents' page for US 8,402,543 did not display a litigation section.
  2. Search limitations. I was not able to query PACER or the CAFC docket system directly; my findings rest on secondary aggregators and indexed web results. A patent held by a large enterprise (Boeing) may also have been involved in settlements or licensing disputes that never produced a public docket entry.
  3. The "8402543" string is ambiguous. Several unrelated registrations share the digits — e.g., a Brazilian utility model "MU 8402543-3" and PCT publication "WO 1984002543 A1" — which appeared in results and are not US 8,402,543. I excluded these from the analysis above.

Conclusion

If any litigation exists, it is not reflected in the publicly indexed litigation sources I was able to search. I do not have high-confidence knowledge of any specific case (plaintiff, defendant, jurisdiction, case number, filing date, outcome) involving US 8,402,543, and I will not fabricate one. To close the gap with certainty, the definitive next steps would be a direct PACER docket search on the patent number and a Docket Navigator / Lex Machina patent-level query, which are paywalled and/or require authenticated access I do not have here.

Generated 9/20/2026, 12:48:41 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll verify the ODP's "no proceedings" result against public sources before finalizing.

Let me run a few more targeted checks (PTAB E2E, Unified Patents portal, litigation history).

One more pass specifically targeting PTAB dockets and litigation dockets.

Bottom line first

No AIA trial proceedings are on file. I could not confirm any IPR, PGR, or CBM petition against US 8,402,543 in the USPTO ODP structured data, in Google Patents' litigation/PTAB-linked legal events, in Unified Patents' patent portal, or in general web search. That is a negative finding based on public sources, not proof of nonexistence — but combined with the ODP result, "no PTAB activity" is the correct working assumption.


Proceedings overview

Total AIA trial proceedings: 0 — 0 active, 0 claims invalidated, 0 claims sustained, 0 settled, 0 institution denials; the patent (application filed 2011-03-25, granted 2013-03-19, currently held by The Boeing Company via the 2020-06-01 Narus merger) has never been the subject of a Board trial, which means every claim remains presumptively valid and untested, but also that all § 102/§ 103 grounds based on patents and printed publications remain available to a defendant who has not been served more than one year ago — an IPR-based defense is fully unencumbered, not foreclosed.


Proceedings detail

None identified

  • Type: N/A — no Inter Partes Review, Post-Grant Review, or Covered Business Method review located.
  • Filed: N/A
  • Status: No proceedings on file (USPTO ODP structured data); no contrary public record located by search on 2026-09-20.
  • Judge panel: N/A
  • Petition grounds: N/A
  • Institution decision: N/A
  • Final Written Decision: N/A
  • Settlement / termination: N/A
  • Appeal: No PTAB decision exists to appeal; I found no Federal Circuit appeal attributable to this patent.
  • Defensive value: Because no FWD has ever issued on any claim of the '543 patent, 35 U.S.C. § 315(e)(2) estoppel has never attached to anyone. A defendant is not locked out of any prior-art ground by another party's IPR, and no claim has been canceled that could undercut a demand letter.

Two structural limits worth knowing before you plan a challenge

  1. Post-Grant Review is unavailable. The application was filed 2011-03-25, before the AIA first-inventor-to-file effective date, so the patent is not PGR-eligible under § 321. IPR is the only AIA trial vehicle available.
  2. CBM review is doubly unavailable. The patent is directed to network-traffic/botnet security analytics — not a "financial product or service" — and the CBM program's statutory sunset (2020-09-16) has passed in any event. Do not let anyone budget for a CBM.

Strategic summary

Claim status. Because there is no FWD, no claim of US 8,402,543 is canceled, and no claim has been judicially construed by the Board. The patent as issued stands intact. Per the specification, the claims are arranged as a method independent claim (claim 1, a botnet-detection method with extract-train-classify-identify steps), plus system and non-transitory-computer-readable-medium independent claims recited in the SUMMARY. I did not find a claim-by-claim listing or a reexamination certificate in any source I reviewed, so I am not stating a total claim count or asserting anything about dependent-claim scope beyond what the specification supports. If your theory of the case turns on claim numbering, pull the printed claim set from the USPTO PatentCenter record for application 13/072,290 rather than relying on secondary sources.

Estoppel landscape. Clean slate. There is no petitioner, no FWD, and therefore no § 315(e)(2) bar on any party. Every § 102/§ 103 ground built on patents and printed publications is on the table for a first petitioner. The real constraints are timing and discretion, not estoppel: § 315(b) bars a petition filed more than one year after service of a complaint alleging infringement of this patent, and the Fintiv-line discretionary factors (parallel litigation posture, investment in the district court case, stay prospects) will drive institution more than the merits will. Note also that district court and ITC invalidity defenses are wholly unconstrained — including § 112 and § 101 theories, which an IPR cannot reach, and system-art / public-use art, which an IPR cannot reach either.

Pattern signals. There is no pattern to report, and that itself is the signal. No petitioner has filed once against this patent, let alone twice or in parallel waves. There is no defensive-aggregator footprint: Unified Patents' portal surfaces the '543 patent only incidentally in citation/related-patent contexts, not as a challenged patent. The patent owner chain is Narus, Inc. → The Boeing Company (merger recorded 2020-06-01), which means the current holder is a large defense prime with the resources to litigate and no apparent history of monetizing this family through an assertion campaign against end users. I found no infringement suit asserting the '543 patent. Practically, that explains the absence of IPRs: the patent has not been asserted hard enough to attract them, so "no IPRs" is weak evidence of strength and stronger evidence of non-assertion.

Revenue life. The Google Patents legal-status record lists an adjusted expiration of 2031-08-04, i.e., roughly five years of term remain from today, and the record reflects the patent as active. That is long enough that a defendant should price a real validity challenge rather than wait the patent out.


Recommended next steps

  1. Confirm the negative independently before you rely on it. Run the patent number directly in PTAB E2E (https://ptab.uspto.gov, "Patent Trial Proceedings" search) and in the USPTO PTAB API/Decisions portal (https://www.uspto.gov/patents/ptab/decisions). Cross-check the district court and ITC side on CourtListener (https://www.courtlistener.com) to confirm the patent has not been asserted — because if there is a live campaign, my "no litigation" finding is the thing most likely to be stale, and it changes the § 315(b) analysis completely.
  2. Because no claims are invalidated, there is no FWD to link or quote. There is no disposition to leverage and no canceled claim that neutralizes a demand letter. Do not tell a client that claims of this patent are dead — they are not, and representing otherwise would be a serious error.
  3. If you are a defendant served with a complaint asserting the '543 patent, calendar the § 315(b) one-year bar immediately. IPR is the only AIA route (no PGR, no CBM), and it is fully available. On institution, § 316(a)(11) gives the Board a statutory deadline of one year from the institution decision to reach an FWD, and institution itself is targeted at roughly six months from filing — so model a realistic total timeline of about 18 months from petition to FWD.
  4. Build the invalidity case around what an IPR cannot reach. Since the Board's estoppel would be claim-specific and limited to patents/printed publications, reserve § 112 written-description/enablement attacks on the feature-vector-plus-incremental-LS-SVM claim language, § 101 eligibility attacks on the "applying a classification model" steps, and any system-art or public-use evidence for district court or the ITC. Those theories cannot be raised at the PTAB and are therefore the arguments an IPR would not exhaust.
  5. Consider ex parte reexamination as a fallback. It carries no § 315(b) time bar and no estoppel, and given that the patent is now ~13 years old, newer printed art may be available. It is slower and gives the patent owner an unimpeded amendment opportunity, so treat it as a secondary track.

Confidence and caveats. High confidence that no AIA trial proceeding is on file: the ODP structured data says so and three independent public searches returned nothing. Lower confidence on the litigation silence — I found no assertion suit, but I did not have access to a complete district court docket database, and a recently filed complaint could exist outside my search coverage. All statements above about claim structure derive from the patent's own SUMMARY and DETAILED DESCRIPTION; I did not verify the issued claim set against a claim-by-claim source, so do not quote claim numbers from this memo into a filing.

Generated 9/20/2026, 12:49:00 PM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2011-03-25 · Assignment

    Ranjan, Supranamaya; Chen, FeilongNARUS, INC.

  2. 2020-06-01 · Merger

    NARUS, INC.THE BOEING COMPANY

    internal reorg

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll start by trying to pull the actual USPTO assignment records and cross-reference the litigation/ownership history.

Let me dig into the assignment records themselves and any litigation history.

Ownership & Assignment Reconstruction — US 8,402,543 B1

Patent: Machine learning based botnet detection with dynamic adaptation
App. No. 13/072,290 · Filed 2011-03-25 · Granted 2013-03-19 · Priority 2011-03-25
Claims 27 · Status Active, projected expiry 2031-08-04 (term adjusted)

Sourcing caveat, stated up front: I could not render the USPTO Assignment Center result set directly — it is a JavaScript single-page application and the reel/frame and correspondent fields are not exposed in the indexed mirrors I was able to retrieve (Google Patents legal-events table, Justia, FreePatentsOnline, Espacenet, SumoBrain). The two conveyance events below are sourced from Google Patents' legal-events table, which mirrors USPTO assignment data, and I have not invented reel/frame numbers or correspondent names to fill the gap. Where a field could not be verified, it is marked not verified rather than estimated.


Inventors

Inventor Employer at filing Notes
Supranamaya Ranjan Narus, Inc. (Sunnyvale, CA) Listed residence Albany, CA on the sibling Narus patent US 8,260,914. Prolific Narus inventor — 19 Narus patents all-time (Patent Leaderboard), incl. US 8,260,914, US 8,577,493, US 8,762,298, US 8,682,812.
Feilong Chen Narus, Inc. (Sunnyvale, CA) Two Narus patents all-time (this one and US 8,762,298, with Ranjan and Joshua Robinson).

Departure pattern: not present as an anomaly. Ranjan is a named inventor on Narus-family filings through at least mid-2011 (e.g., US 8,577,493, filed 2011-05-10) and appears on later-granted Narus patents, so he did not exit at filing. His public Google Scholar profile now lists Yelp Inc. as his affiliation, confirming a departure from the Narus/Boeing orbit at some point — but I could not date that move, and it does not resemble the "all inventors gone within 12 months" pre-fire-sale signature. Both inventors assigned their rights to Narus by the recorded assignment below; no inventor-retained or individually-held interest appears in the record.


Original assignee

Narus, Inc., Sunnyvale, CA (570 Maude Court), a real-time network traffic analytics vendor founded 1997 by an Israeli team (Ori Cohen, Stanislav "Stas" Khirman). Approximately $100M raised from Mayfield, NeoCarta Ventures, Walden International, American Capital and others.

  • Product embodying the claims: Yes — the NarusInsight / Narus nSystem platform, marketed to carriers, governments and enterprises for real-time traffic intelligence, botnet/anomaly detection and cyber-threat analytics. Customers cited publicly include AT&T and Pakistan Telecom Authority. The claimed subject matter (layer-3 flow-feature extraction, incremental LS-SVM classification of client IPs as bot vs. legitimate) is squarely within that product line, and the specification's own experimental section uses the "botnet detection data set collected by monitoring the HTTP network traffic at a large ISP."
  • Primary line of business: network traffic analytics / lawful-intercept and mass-surveillance technology (Narus STA 6400 at AT&T's Room 641A; widely reported as a PRISM supplier).
  • Current status: Dissolved as a separate legal entity. Boeing completed its acquisition of Narus on 2010-07-29 (announced 2010-07-07), operating it as a wholly owned subsidiary inside Boeing Network & Space Systems. In 2015 Boeing transferred 65 Narus engineers/technical staff to Symantec while expressly retaining Narus's intellectual property and licensing — Symantec received marketing rights only, not title. Finally, on 2020-06-01, a merger conveyed Narus, Inc.'s rights to The Boeing Company (per the recorded reassignment). No bankruptcy proceeding is associated with Narus.

Assignment timeline

Field-level caveat: the two records below are drawn from Google Patents' legal-events mirror. Dates shown are the dates Google records against the event; where the executed-vs-recorded distinction is not resolvable from that source, it is flagged. Reel/frame: not verified. Correspondent: not verified (see NPE signal 3 for the partial, lower-confidence substitute evidence).

  • 2011-03-25 (filing date) / recorded 2011-03-25 — Reel not verified / not verified

    • Conveyance: Assignment (ASSIGNMENT OF ASSIGNORS INTEREST)
    • Assignor: Ranjan, Supranamaya; Chen, Feilong (individually)
    • Assignee: NARUS, INC.
    • Correspondent: Not verified from available sources.
    • Context: Ordinary inventor-to-employer assignment at filing — this is the standard employment-relationship conveyance that gives the operating company title, not a transfer to an asserter.
  • 2020-06-01 (executed) / recorded 2020-06-01 — Reel not verified / not verified

    • Conveyance: Merger (not an assignment for value)
    • Assignor: NARUS, INC.
    • Assignee: THE BOEING COMPANY
    • Correspondent: Not verified from available sources.
    • Context: Internal corporate reorganization — the subsidiary was merged up into its parent. No consideration, no third-party purchaser, no change in ultimate control (Boeing had owned Narus outright since 2010).

Record count: exactly two recorded post-filing ownership events across 15 years. That thinness is itself the finding: no broker, no intermediary LLC, no reassignment chain.

Notably absent from the record: Symantec does not appear as an assignee despite the 2015 Narus business/employee transfer — consistent with contemporaneous reporting that Boeing kept the IP and licensed marketing rights. The patent therefore never left the Boeing controlled group.


Timeline diagram

timeline
    title Ownership of US 8402543
    2011 : Filed by Narus Inc
         : Inventors assign rights to Narus
    2013 : Patent issued
    2015 : Narus staff move to Symantec
         : Boeing retains the Narus IP
    2020 : Narus Inc merged into Boeing
    2031 : Projected expiry under adjusted term

NPE / troll-pattern signals

  1. Shell-entity transfer — not present.
    The only post-issuance conveyance is a merger (2020-06-01) from Narus, Inc. to The Boeing Company, a NYSE-listed operating manufacturer. There is no "IP / Holdings / Licensing / Ventures" entity anywhere in the chain, no registered-agent-service address, and no single-purpose LLC. The one non-operating-looking name in the record (Narus, Inc.) is a 1997-founded operating software vendor with a shipping product, a customer list, and ~150 employees at acquisition.

  2. Known asserter in the chain — not present.
    Neither assignee matches any entity on the referenced NPE lists (Acacia, Marathon, IV, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation, Spangenberg entities). Boeing and Narus are not high-frequency plaintiffs in the Unified Patents or RPX directories on the evidence retrieved. I found no infringement litigation naming US 8,402,543 in the sources searched; I cannot rule out a qui tam, ITC, or government-contract dispute, but no district-court assertion surfaced.

  3. Repeat correspondent across the chain — unclear (not verifiable).
    The Assignment Center correspondent field is the whole point of this signal and it is exactly what I could not extract. Two partial, lower-confidence substitutes, presented as such and not as findings:

    • US 8,260,914 (sibling Narus patent) shows its "Attorney, Agent, or Firm" front-page field as "Narus, Inc. (Sunnyvale, CA, US)" — i.e., Narus prosecuted in-house, without a named outside firm.
    • A third-party aggregator (scholareye) lists the patent agency for US 8,577,493 as Fernandez & Associates, LLP, Palo Alto CA.
      Neither is the assignment correspondent, and neither is confirmed on US 8,402,543 itself. Even if both proved correct, two different firms/appearances would not constitute the recurrence this signal requires. I am flagging this as unresolved rather than scoring it.
  4. Cascading transfers — not present.
    Two events, nine years apart (2011-03-25 → 2020-06-01). No <24-month chained-LLC sequence, no shared correspondent address, no common-principal pattern. The chain is the opposite of cascade-shaped.

  5. Pre-litigation transfer — not present.
    No first infringement suit was identified for this patent, so there is no suit date to measure a 6-month window against. The 2020 merger post-dates issuance by seven years and is unrelated to any assertion I could find.

  6. Bankruptcy fire-sale — not present.
    No Chapter 7/11 proceeding for Narus, Inc. or The Boeing Company touching these assets. The 2015 Symantec transaction was a going-concern talent/asset deal in which Boeing retained the IP — the inverse of a distressed liquidation, and the assignment record confirms the patents were never conveyed out.

  7. Privateering — not present.
    No operating company → NPE transfer appears in the chain. Boeing did not hand this patent to an assertion vehicle to attack competitors; it kept title itself and merged it up. No SEC-filing or Patent Progress/EFF coverage of a privateering arrangement was located.

  8. Defensive aggregator — not present.
    The chain terminates at The Boeing Company, an operating aerospace/defense manufacturer — not RPX, AST, LOT Network, Unified Patents, or OIN. This patent has therefore not been neutralized by aggregation; it remains a live asset inside a large operating company. If anything, this is the residual risk in the file: Boeing is a sophisticated, well-resourced patent holder that has never needed to sell or aggregate this portfolio.


Verdict

Insufficient data — with the specific clarification that the insufficiency runs to assertion history, not to ownership records.

The ownership chain is complete and fully benign: inventor assignment to Narus, Inc. at filing (2011-03-25), then a merger of Narus up into The Boeing Company (executed/recorded 2020-06-01). Zero of the eight NPE signals are affirmatively present — no shell-entity transfer, no known asserter, no cascade, no bankruptcy sale, no privateering, no defensive aggregator, and no litigation against which to test a pre-litigation transfer. I cannot certify "Operating-company assertion" (Boeing is not suing anyone on this patent on the evidence found) nor "Defensive / non-asserting," because that category is defined by termination at a defensive aggregator and this chain ends at an operating parent by merger. The signal that would most strengthen the file — the recording correspondent on reel/frame entries for both conveyances, plus any third entry I may have missed — is precisely the field I could not retrieve; verified reel/frame and correspondent should be pulled before this patent is treated as conclusively non-NPE.

Verify directly (search patent number 8402543):

What would change the verdict: a third recorded conveyance (e.g., a 2015-era recording to Symantec or a licensing security interest), or a correspondent appearing on both the 2011 and 2020 records, would each be a separately reportable finding. Neither is currently evidenced.

Generated 9/20/2026, 12:49:17 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll search for the specific patent and its cited references. Let me run several targeted searches.

Let me try to locate the specific "References Cited" section for this patent.

I have the patent's technical content but need its actual cited-reference list. Let me search more specifically.

Executive summary / important caveat up front

I could not retrieve the authoritative "(56) References Cited" (backward‑citation) list printed on the front page of US 8,402,543 from the sources available to me. The searches returned (a) the full specification of the patent you already supplied, and (b) the forward citations (later patents that cite '543). They did not return the USPTO/EPO‑indexed list of patents and publications that the examiner/applicant cited against '543.

Per your operating rules — "If you do not know something with high confidence, say so explicitly rather than fabricating" — I will not invent a citation list, dates, or a claim‑by‑claim §102 mapping. Below I give you: (1) what I confirmed about the patent itself, (2) exactly what I could and could not obtain, (3) the citations I did find (clearly labeled as forward citations, which are not prior art to '543), and (4) an accurate framework for the anticipation analysis you asked for, plus where to pull the definitive reference list.


1. Patent identity (verified, interpreted literally as US 8,402,543)

Field Value (as reported by the sources)
Patent number US 8,402,543 B1 (I did not auto‑correct or substitute any similar number)
Title Machine learning based botnet detection with dynamic adaptation
Application number US 13/072,290
Filing date 2011‑03‑25
Priority date 2011‑03‑25
Grant/publication date 2013‑03‑19
Inventors Supranamaya Ranjan; Feilong Chen
Original assignee Narus, Inc.
Current assignee (per Google Patents) The Boeing Company (via 2020‑06‑01 merger assignment from Narus)
Adjusted expiration (as listed) 2031‑08‑04
Classifications H04L63/14, H04L63/1408, H04L63/1416, H04L2463/144

Subject matter (from the authoritative text you provided): binary classification of clients as malicious/non‑malicious using features that are per‑server counts of layer‑3 communication activity (flows/packets/bytes) between a client and each server, learned via an incremental least‑squares support vector machine (LS‑SVM) with dynamic feature adaptation and dynamic data adaptation. The claims are directed to (i) a method, (ii) a system (hardware processor + feature extractor + model generator + online classifier + repository), and (iii) a non‑transitory computer‑readable medium.

Note on internal consistency: the OCR text you provided and the Google Patents verbatim text contain internal mismatches (e.g., "FIG. 2 depicts a method flowchart" in the Detailed Description versus "FIG. 3 shows a method flow chart" in the Brief Description of Drawings; the training set is referenced both as (130) and (134)). These are apparent transcription/OCR artifacts, not part of the claimed subject matter, but I flag them because you instructed literal interpretation.


2. What I could NOT obtain (and why it matters)

  • No authoritative (56) "References Cited" list. Google Patents' Patent Citations table, the USPTO PatentCenter/Global Dossier citation data, and the Espacenet "Cited documents" list were not returned in the search results. A tool limit was reached before I could pull them.
  • Because the backward‑citation list is the only proper set of "patent citations for 8402543," I cannot truthfully give you each reference's "full citation, publication/filing date, brief description, and the claim(s) it potentially anticipates." Any such list I produced now would be fabricated.

3. Citations I DID find — these are FORWARD citations (later documents citing '543), i.e., NOT prior art

The following documents cite or reference US 8,402,543. A forward citation cannot anticipate '543, because it post‑dates '543's 2011‑03‑25 priority date. I list them only as a factual record of what the searches surfaced:

Document Date Relationship to '543
US 10,567,409 B2 — Automatic and scalable log pattern learning in security log analysis 2020 (grant) Cites US 8,402,543
US 8,838,992 B1 — Identification of normal scripts in computer systems 2014 Cites US 8,402,543
US 10,614,107 B2 — System and method for keyword searching using both static and dynamic dictionaries 2020 Cites US 8,402,543
WO 2007/050244 A3 — Method and system for detecting and responding to attacking networks 2007 Listed as citing US 8,402,543 (per Google Patents "Cited By" table)
US 2014/0068763 A1 — Data mining to identify malicious activity (Damballa) 2014 Cites US 8,402,543

Related co‑pending/co‑assigned Narus patents (likely same technical family, later filings — verify dates before relying on them): US 8,682,812 B1 (Machine learning based botnet detection using real‑time extracted traffic features) and US 8,762,298 B1 (Machine learning based botnet detection using real‑time connectivity graph‑based traffic features). These surfaced alongside '543 but I could not confirm they are listed in '543's own reference section.


4. How to read this for a real §102 / §103 analysis (correct legal framing)

  1. Patent‑front‑page "(56) References Cited" are examiner/applicant‑cited prior art, considered during prosecution. They are typically applied under 35 U.S.C. §103 (obviousness), singly or in combination — not usually §102 (anticipation). If a single reference had anticipated any claim outright, that claim would not have issued. So the expectation that a citation list will map "reference → claim(s) it anticipates under §102" is, in most cases, legally mis‑framed; the realistic inquiry is §103.
  2. Forward citations (Section 3 above) are not prior art to '543 and cannot support either §102 or §103 against it.
  3. To do the analysis you asked for properly, one must compare each cited reference's enabling disclosure against each independent claim element ("extracting a malicious data instance comprising features per server representing a measure of communication activity"; "including … in a training data set"; "generating, using a pre‑determined machine learning algorithm, a classification model"; "extracting a unclassified data instance"; "applying the classification model"; "identifying the unclassified client as associated with a botnet") and its dependent claims.

5. Where to retrieve the definitive citation list (so this can be completed accurately)

  • USPTO PatentCenter / PatFT for US 8,402,543 B1 → "References Cited" (front‑page 56 list) — authoritative U.S. source.
  • USPTO Global Dossier / Assignment for application 13/072,290.
  • Google Patents > US8402543B1 > "Patent Citations" table (backward citations) and "Cited By" (forward).
  • Espacenet (worldwide.espacenet.com) → "Cited documents" and "Citing documents" for US8402543.
  • The issued patent PDF (front page) — the "(56) References Cited" block is printed there.

If you can paste the front‑page reference list (or authorize me to pull the Google Patents Patent Citations table), I will then produce, for each cited reference: full citation, publication and filing dates, a brief description, and a rigorous, element‑by‑element §102/§103 assessment against the specific claims — with each conclusion tied to the reference's disclosure.


Bottom line

I confirmed US 8,402,543 is Narus's (now Boeing's) incremental‑LS‑SVM botnet‑detection patent (filed/priority 2011‑03‑25, granted 2013‑03‑19). I could not obtain its actual cited prior‑art references from the available searches, and I will not fabricate them or invent §102 claim mappings. The only citations I found are forward citations, which are not prior art. Provide the (56) list and I can complete the requested reference‑by‑reference anticipation analysis immediately.

Generated 9/20/2026, 12:49:02 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll start by locating the actual prior-art references associated with US 8,402,543, since the page text supplied to me contains the "Prior art keywords" and "Prior art date" metadata but not the cited-references tables.

I now have the actual "References Cited" list from the patent's front page. Let me verify the identity, dates, and disclosures of each cited U.S. reference so the § 103 analysis is grounded in real documents.

Obviousness Analysis — U.S. Patent No. 8,402,543 B1

"Machine learning based botnet detection with dynamic adaptation"
Narus, Inc. (now The Boeing Company) · Inventors Ranjan & Chen · Appl. No. 13/072,290 · Filed 2011‑03‑25 · Granted 2013‑03‑19


0. Two preliminary notes on sources

On the "Prior Art section." The page text I was given (the Google Patents rendering at https://patents.google.com/patent/US8402543/en) contains only the "Prior art keywords" field (malicious, data, client, instance, data instance) and "Prior art date 2011‑03‑25." It does not contain the front‑page "References Cited" / "Cited By" tables. To avoid fabricating a prior‑art list, I pulled the actual front‑page citations from the printed patent's "References Cited" as reproduced at https://uspto.report/patent/grant/8402543 and the patent PDF front page at https://patentimages.storage.googleapis.com/55/f3/47/d71bc0b0e9ea4d/US8402543.pdf. Where I state a reference's title or disclosure, I mark whether I verified it in this session.

On "previously-generated sections." Your message references sections already generated for this patent. None were included in my context, so this analysis is self-contained and flags its own verification gaps rather than assuming prior findings.


1. The prior art of record (the references the examiner/applicant actually cited)

U.S. patent documents

Reference Date on face Title / disclosure Verified? Role in a § 103 combination
US 8,056,132 B1 (Chang et al.) Nov 2011 Client‑side technique for detecting software robots — client‑side bot detector using bot event profiles keyed to IP addresses of zombie computers; monitored bot events tied to IPs; bot events identified by same/similar activity from different computers ✅ Title & content verified (sumobrain) Bot detection via per‑client, per‑IP communication records
US 8,161,548 B1 (Wan) Apr 2012 Malware detection using pattern classificationfeature definition file + feature extraction module + trained model + pattern‑classification algorithm → classification label; training samples are "examples of benign software and malware" ✅ Title & content verified (Google Patents) The supervised‑classification framework of claim 1
US 8,195,750 B1 (Bakhmutov) Jun 2012 Not verified in this session Unknown
US 8,244,752 B2 (Buehrer et al.) Aug 2012 Not verified in this session Unknown
US 2008/0307526 A1 (Chung et al.) Dec 2008 Not verified in this session Unknown
US 2011/0153811 A1 (Jeong et al.) Jun 2011 Not verified in this session (Jeong's family includes botnet‑detection filings) Likely botnet‑detection context
US 2011/0320816 A1 (Yao et al.) Dec 2011 Not verified in this session Unknown
US 2012/0096549 A1 (Amini et al.) Apr 2012 Not verified in this session Unknown
US 2012/0159620 A1 (Seifert et al.) Jun 2012 Not verified in this session; marked with "*" (appears examiner‑cited) on the printed front page Unknown

Non‑patent literature of record (cited by applicant; Gestel also marked examiner‑cited)

Reference What it supplies
Suykens et al., Least Squares Support Vector Machines, World Scientific, 2002 The LS‑SVM formulation itself: equality constraints, Lagrangian conversion, closed‑form solution
Gestel et al., "Benchmarking least square support vector machine classifiers," Machine Learning 54(1):5‑32, 2004 LS‑SVM performance vs. standard SVM
Ye et al., "SVM versus least square SVM," AISTATS 2007, 640‑647 Direct comparison of the two SVM variants
Tax & Duin, "Online SVM learning: from classification to data description and back," IEEE NNSP '03, 499‑508 Incremental/online SVM learning
Sculley & Wachman, "Relaxed online SVMs for spam filtering," SIGIR '07, 415‑422 Online SVM with bounded memory / discarding old examples
Wang et al., "SVM‑based spam filter with active and online learning," TREC '06 Active + online learning: adding newly labeled/misclassified examples
Ma et al., "Identifying suspicious URLs: an application of large‑scale online learning," ICML '09, 681‑688 Large‑scale online learning where freshness matters
Ma et al., "Beyond blacklists: Learning to detect malicious websites from suspicious URLs," KDD '09, 1245‑1254 Blacklists as labels/seeds for supervised learning
Binkley & Singh, "An algorithm for anomaly‑based botnet detection," SRUTI '06 Botnet detection from flow/connection statistics, not payload
Gu et al., "BotSniffer," NDSS '08 C&C channel detection via spatial‑temporal correlation of client→server flows, no payload inspection
Gu et al., "BotHunter," USENIX Security '07 IDS‑driven dialog correlation; whitelisting of benign services to suppress false positives
Cooke et al., "The zombie roundup," SRUTI 2005; Goebel et al., "Rishi," HotBots '07 Bot identification in operational traffic
Perdisci et al., "Detecting malicious flux service networks…," ACSAC 2009; Porras et al., "An analysis of Conficker's logic and rendezvous points," SRI 2009; Yadav et al., "Detecting algorithmically generated malicious domain names," IMC 2010; Kreibich et al., "On the spam campaign trail," LEET 2008 Infrastructure churn: flux, rendezvous points, DGA — i.e., the dynamic feature problem
Nagaraja et al., "BotGrep," USENIX Security '10 Graph/connection‑set analysis of source–target IP pairs
Zhang et al., "An evaluation of statistical spam filtering techniques," ACM TALIP 2004; Rumelhart et al., 1986 ML classifiers for spam/pattern tasks

Key effective‑date caveat (pre‑AIA). The application was filed 2011‑03‑25, before the AIA's 2013‑03‑16 change, so pre‑AIA § 103(a) governs. Five of the nine U.S. documents published after that date (Nov 2011 – Aug 2012). Each is available only under pre‑AIA § 102(e) if its U.S. filing/priority date predates 2011‑03‑25. That date is not on the face of the '543 patent, so any ground built on Chang, Wan, Bakhmutov, Buehrer, Yao, Amini, or Seifert must first be date‑qualified against the file wrapper. (Note also that the front page, as rendered, does not clearly separate "cited by examiner" from "cited by applicant"; applicant‑cited references carry no admission that they qualify as prior art.)

Minor literal‑interpretation flags: Google Patents lists priority/filing as 2011‑03‑25 while a third‑party aggregator (unifiedpatents.com) lists priority as 2011‑03‑24 — an apparent timezone artifact; and the printed claim 1 reads "each malicious data instance" in one rendering while another rendering of the same claim reads "one or more malicious data instance." Both should be reconciled against the USPTO certified copy before any rejection is drafted. The claims also literally recite "maximum margin hyerplane" (sic) — a typographical error with no claim‑construction weight.


2. The claims to be attacked

Claim Core limitation Closest cited art
1 (independent method) Extract malicious instance (per‑server features = measure of communication activity) and non‑malicious instance from labeled clients' traffic → put in training set → generate classification model with a pre‑determined ML algorithm → extract unclassified instance → apply model → malicious label ⇒ client is botnet‑associated Binkley, BotSniffer, Chang, Wan
2 Labels come from a pre‑determined list (blacklist/whitelist) Ma (KDD '09), BotHunter, Chang
3 Measure = flows / packets / bytes over a pre‑determined time window Binkley, BotSniffer, BotGrep
4 ML algorithm = SVM; model = decision surface Wan, Suykens, Gestel, Ye, Wang
5 Max‑margin hyperplane, constrained criterion → unconstrained (Lagrangian) formulation, solve w, b, classify by f(x)=sign[wᵀx+b] Suykens, Gestel, Ye
6 Unconstrained formulation terms wᵀw and αᵢyᵢ[wᵀxᵢ+b] Suykens (dual), Gestel
7 Dynamic feature adaptation: add features for new servers; revise objective to λ²wᵀw+vᵀv and αᵢyᵢ[λ(wᵀxᵢ+b)+vᵀx̂ᵢ+b̂]; solve v, b̂ from prior w, b; expand and re‑classify Tax & Duin; + new art may be needed for the exact λ‑formulation
8‑11 Instance removal: prune training set by timestamp (OLD), by smallest multiplier α (MIN), or by minimal decision‑surface impact (GREEDY) Sculley, Tax & Duin, Suykens, Zhang
12‑13 Add a misclassified labeled instance to the training set and re‑learn; client found via an updated list Wang (TREC '06), Ma (ICML '09)
14‑26, 27 System and CRM counterparts Wan, Chang (software‑implemented classifier)

3. Governing standard

Pre‑AIA 35 U.S.C. § 103(a); Graham v. John Deere Co., 383 U.S. 1 (1966) (scope/content of art; differences; PHOSITA level; secondary considerations); KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007) (a motivation may be found in "the background knowledge, creativity, and common sense of the person of ordinary skill"; a predictable use of prior‑art elements according to their established functions is obvious); In re Kahn / KSR (articulated reasoning with rational underpinning required). For dependent claims adding mathematical detail, a known published formulation carries no patentable weight: In re Grams; Parker v. Flook (a formula plus conventional post‑solution activity). When a limitation is a mere design choice among a finite number of identified, predictable solutions, obviousness follows (KSR; In re Aller).

Level of ordinary skill: a B.S. in CS/EE plus 2–4 years, or an M.S. plus ~1–2 years, in network security and applied machine learning — consistent with the sophistication of the cited NPL (Suykens, Tax & Duin, Gu, Binkley).


4. Proposed grounds of rejection

Ground A — Claims 1–3 (and 14–16, 27): Binkley (or Gu BotSniffer) in view of Wan (optionally + Chang)

  • **Binkley '06 and BotSniffer each detect bots by monitoring traffic flows between internal clients and external servers and correlating that client→server communication behavior — precisely the "measure of communication activity between the [client] and a [corresponding] server" of claim 1, and each expressly avoids payload inspection (satisfying the patent's layer‑3‑only premise). BotGrep reinforces the source‑IP/destination‑IP bipartite view that the '543 specification itself uses.
  • Wan supplies the missing machinery of claim 1: a feature definition file, a feature extraction module, a trained model produced from labeled training samples (benign vs. malware), and a pattern‑classification algorithm that outputs a classification label.
  • Motivation: Both references sit in the same field (automated detection of malicious hosts from network/host observations) and address the same problem — Binkley's anomaly heuristics and BotSniffer's correlation produce false positives and require hand‑tuned thresholds; a POSITA would have been motivated to replace/augment the heuristic decision with the supervised classifier Wan already teaches, using the two classes (malicious/non‑malicious) the art already treats as given. This is the classic KSR "familiar elements according to known methods" combination, with a predictable result (a labeled verdict per client).
  • Claim 2 (labels from a pre‑determined list): satisfied by Ma (KDD '09) — "Beyond blacklists" expressly treats blacklists as the labeling seed for supervised learning — and by BotHunter, which uses a whitelist of benign services to reduce false positives. Blacklists (Spamhaus, SORBS) are named in the '543 specification itself as an admitted, pre‑existing source of ground truth.
  • Claim 3 (flows/packets/bytes in a time window): reading a flow counter over a fixed interval is the ordinary output of the netflow‑style collectors the art assumes (Binkley; BotSniffer; BotGrep); this is a plain outcome of how the data are already aggregated.

Ground B — Claims 4–6 (and 17–19): Ground A + Suykens, Gestel, Ye, Wang

  • Choosing SVM as the "pre‑determined machine learning algorithm" (claim 4) is at most an obvious selection: the cited NPL treats SVM and LS‑SVM as the default binary classifiers for exactly this kind of high‑dimensional, sparse, adversarial classification problem (Wang's SVM spam filter; Ma's large‑scale URL learning; Zhang's statistical spam filtering comparison).
  • Claims 5–6 are, in substance, the LS‑SVM primal and its Lagrangian dual as published: identify the max‑margin hyperplane, formulate a constrained criterion, convert it to an unconstrained/Lagrangian form using w and b, and classify by sign[wᵀx+b] — with wᵀw and αᵢyᵢ[wᵀxᵢ+b] terms. Suykens' 2002 book and Gestel's and Ye's papers (all of record) describe this formulation and its closed‑form solution verbatim. The motivation is explicit in the cited art: LS‑SVM's closed‑form solution avoids the quadratic programming of standard SVM — a recognized, specific design benefit for a real‑time, high‑rate network classifier, which is the stated deployment context. Under In re Grams/KSR, reciting a known mathematical solution to a recognized engineering problem adds no inventive weight.

Ground C — Claim 7 (and 20): Ground B + Tax & Duin + Sculley + the flux/DGA art (+ applicant admissions) — the weakest ground

This is where the '543 patent's real contribution lies, and no reference of record appears to disclose the exact formulation. The case would rest on:

  1. Applicant's own § 103 admissions. The specification concedes: "a supervised learning model trained on initial features may not be as effective when applied to the next day's network data because it would not be able to utilize the new features present in the next day's network data. To improve its detection rate without incurring significant computational overhead, the classification model must be updated incrementally…" and identifies the causes — newly infected machines becoming C&C servers, C&C takedowns, "domain fast‑flux," "IP fast‑flux." These are admissions that the problem was known and articulated.
  2. The flux/DGA art of record (Perdisci ACSAC '09; Porras SRI 2009; Yadav IMC 2010; Kreibich LEET 2008) independently establishes the dynamic feature‑space problem — the very reason claim 7 adds features for newly observed servers.
  3. Online/incremental SVM learning is of record (Tax & Duin NNSP '03; Sculley SIGIR '07), supplying the mechanism. A POSITA seeking to extend an SVM to newly appearing features would predictably reach for the incremental/online SVM literature and, given LS‑SVM's closed‑form solution, would expect to be able to add terms to the existing Lagrangian rather than re‑solve from scratch (block/primal‑augmentation being a routine algebraic step).
  4. Motivation, articulated: retraining from scratch is expensive — the '543 specification itself notes SVM cost scales as N² — while feature churn is daily; so bounded‑cost incremental retraining is the recognized, finite set of available design options. Reasonable expectation of success is supported by the applicant's own data.

Where this ground would fail: the claim‑specific substitutions λ²wᵀw+vᵀv and λ derived automatically from the agreement between the previous model's predictions and the new labels (spec eq. (6)) are not shown to be taught by any reference of record. Absent additional art (e.g., incremental SVM/KTT‑update literature, multi‑view or block‑incremental learning references not cited on this face), a well‑supported rejection of claim 7 would be difficult, and the applicant's experimental parity result ("the classification model built incrementally performs as well as the counterpart exact solution") cuts against unexpected results while also cutting against obviousness of the specific derivation. Claim 7 is the most defensible claim in the patent.

Ground D — Claims 8–11 (and 21–24): Ground B + Sculley + Tax & Duin + Zhang

  • Sculley (relaxed online SVMs, bounded memory) supplies the motivation and the technique for capping the training‑set size; Tax & Duin supplies the incremental update mechanics; Zhang supplies model maintenance over streaming data.
  • Claim 9 (removal by timestamp / OLD): first‑in‑first‑out pruning of a sliding window is the canonical bounded‑memory technique in the online‑learning art of record — a simple, predictable choice (In re Aller).
  • Claim 10‑11 (removal by multiplier α / contribution measure): the SVM literature of record makes it elementary that examples with small α are not support vectors and therefore do not lie on/near the decision surface; discarding them is the evident pruning heuristic. That the patent's own MIN strategy is explained with exactly this rationale ("such examples have the least influence on the decision surface") demonstrates the rationale was already conventional.
  • The GREEDY variant (eq. 7‑9) is optimization of a removal objective — routine mathematical refinement that, absent demonstrated unexpected results, is obvious-to-try.

Ground E — Claims 12–13 (and 25–26): Ground D + Wang (TREC '06) + Ma (ICML '09)

  • Wang, "SVM‑based spam filter with active and online learning," is squarely on point: SVM classification with active selection of informative (e.g., misclassified) examples for labeling and online incorporation into the model. That is claim 12's "another malicious data instance [that the model labels non‑malicious] … included in the training data set … revising the classification model."
  • Ma (ICML '09) shows the same pattern at scale in the malicious‑URL domain, where feature distributions shift constantly — supplying motivation to re‑feed corrected examples continuously.
  • Claim 13 (identify the new malicious client via an updated version of the list) is a predictable data‑refresh step; the '543 specification itself contemplates that "a newly labeled client IP address may be added to the blacklist or whitelist" — and blacklist refresh cycles were a matter of ordinary practice.

Ground F — The system and CRM claims (14‑26, 27)

Claims 14‑26 recite a hardware processor, a feature extractor, a model generator, an online classifier, and a repository performing the method steps. Implementing an ML classifier pipeline on a general‑purpose computer is not a patentable distinction: Wan (feature extraction module + trained model + classifier) and Chang (client‑side detector and profiles) each describe software modules on conventional platforms, and the '543 specification admits the tool "may include one or more system computers, which may be implemented as a server or any conventional computing system." Under In re Venner / In re Hostetler, programmed‑computer claims reciting no more than a known algorithm applied on general hardware are obvious where the algorithm itself is old or obvious. (Note also the informality at claim 17, which depends from "the system of claim 1" — a method claim — and at claim 20, where the second term is missing its closing bracket; neither defect enlarges the claim's scope.)


5. Secondary considerations

Nothing in the record I can reconstruct supports non‑obviousness:

  • No unexpected results. The applicant's own FIGS. 4A‑4D are framed as showing that the incremental ("DynF") model performs as well as the batch ("Batch") model — i.e., parity, not superiority — and that training time is reduced. Parity in accuracy with lower cost is the expected consequence of incremental updating, not an unpredictable one, and a benefit that flows directly from the stated motivation.
  • Long‑felt need / failure of others: not established; the cited literature (Tax & Duin 2003; Wang 2006; Sculley 2007) shows the online‑SVM problem was already being solved in neighboring domains years before filing.
  • Commercial success / licensing / praise: none identified; no evidence of nexus is available from the documents reviewed.
  • I found no PTAB proceeding against the '543 patent itself (it appears only as a citing/related document in unrelated IPR records with the Boeing/Narus assignee history), so there is no IPR institution decision to borrow reasoning from.

6. Where the validity case is strongest for the patentee

  1. Claim 7 / claim 20 — the λ‑parameterized incremental reformulation with λ inferred from old‑model/new‑label agreement. Genuinely specific; not taught on the face of any cited reference.
  2. The specific removal‑objective of claims 11 and the GREEDY formulation — if the patentee can show the removal criterion yields a materially different, non‑predictable model behavior, the "routine optimization" characterization is contestable.
  3. Any claim whose scope the applicant narrowed during prosecution for a reason the AIA/§ 103 analysis above does not reach — the prosecution histories of the primary examiner (Vu; Kim) and the file wrapper should be checked; the front page itself gives no rejections, so I cannot state what the examiner actually relied on.

7. Verification gaps you should close before relying on this

Item Why it matters
Filing/priority dates of US 8,056,132; 8,161,548; 8,195,750; 8,244,752; 2011/0320816; 2012/0096549; 2012/0159620 Each published after 2011‑03‑25 and is prior art only if filed earlier (pre‑AIA § 102(e)). Unqualified reliance would be reversible error.
Full text of US 8,195,750 (Bakhmutov), US 8,244,752 (Buehrer), 2008/0307526 (Chung), 2011/0153811 (Jeong), 2011/0320816 (Yao), 2012/0096549 (Amini), 2012/0159620 (Seifert) I did not verify their disclosures; they could strengthen or defeat the grounds above. Several are plausibly on point (Jeong/Narus‑family botnet work; Seifert on classifier evasion), which is why the examiner starred at least one.
Exact text of claims 1, 14, 27 Two renderings of claim 1 differ ("each" vs. "one or more"). Confirm against the USPTO certified copy / any certificate of correction.
The actual front‑page citation table I rebuilt it from the printed PDF and a third‑party rendering because the page text supplied did not include it. Re‑pull from USPTO PatentCenter (the page's own link) before quoting.
Additional art for claim 7 The λ‑formulation likely requires art not of record (incremental/online SVM with feature‑space expansion, block‑incremental or multi‑view learning circa 2009‑2011).
Note on dates supplied The task header gives April 26, 2026 while the page fetch is stamped 2026‑09‑20; this does not affect the 2011‑03‑25 critical date, but I flag it rather than silently reconciling it.

Bottom line

On the references of record, claims 1–6, 8–13, and 14–27 present a strong § 103 case built on a small number of combinations: Binkley/BotSniffer/BotGrep (bot detection from client‑server flow statistics) + Wan (feature‑extraction‑to‑trained‑classifier pipeline) + Suykens/Gestel/Ye (the LS‑SVM formulation the claims recite) + Tax & Duin/Sculley/Wang/Ma (online, bounded‑memory, actively‑updated SVM learning), with the flux/DGA literature supplying the motivation for continuous adaptation. Claim 7 (and its system counterpart, claim 20) is the hard target: the λ‑parameterized incremental reformulation is not shown to be disclosed by anything cited on the face of the patent, and the applicant's parity (not superiority) results provide the patentee with a plausible non‑obviousness narrative rather than a secondary‑considerations win.

Generated 9/20/2026, 12:50:03 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →