Invalidity dossier
US 9560176
Correlating packets in communications networks
Current assignee: Centripetal Networks, LLC
Added 6/26/2026, 6:46:00 AM
Active provider: Google · gemini-2.5-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
Here is a concise summary of US patent 9560176:
US Patent 9560176B2
- Title: Correlating packets in communications networks
- Assignee: Centripetal Networks LLC
- Inventors: David K. Ahn, Peter P. Geremia, Pierre Mallett, III, Sean Moore, Robert T. Perry
- Filing Date: 2015-05-15
- Issue Date: 2017-01-31
- Abstract: A computing system identifies packets received by a network device from a host in a first network and generates corresponding log entries. It also identifies packets transmitted by the network device to a host in a second network and generates log entries for those. By using both sets of log entries, the system can correlate the transmitted packets with the received packets.
Plain-Language Overview of Independent Claims:
Claim 1 (Method): This claim describes a method for a computing system to track network packets. It involves:
- Recording information (log entries) about packets that a network device receives from an internal network host.
- Recording information (log entries) about packets that the same network device then transmits to an external network host.
- Using these recorded log entries to match the transmitted packets back to their original received counterparts. This is particularly useful when the network device (e.g., a NAT device, proxy, or gateway) has changed the packets in a way that normally hides their connection to the original communication flow. The goal is to determine that the transmitted packets are indeed part of the same original end-to-end communication flow.
Claim 13 (System): This claim describes a physical system (with memory, processors, and communication interfaces) designed to perform the method of correlating packets. It does this by:
- Receiving log data from a "tap" device monitoring packets entering the network device.
- Receiving log data from another "tap" device monitoring packets exiting the network device.
- Processing this log data to link the outgoing packets to their corresponding incoming packets, even if the network device performing functions like network address translation (NAT), proxying, or gateway operations has altered the packets, making their relationship less obvious. This helps confirm that the outgoing packets belong to the original communication session.
Claim 14 (Computer-Readable Medium): This claim covers a storage medium (like a hard drive or solid-state memory) that contains computer instructions. When a computer runs these instructions, it carries out the method described in Claim 1.
Claim 15 (System): This claim describes a system (including memory, processors, and communication interfaces) that is configured to:
- Detect incoming packets to a network device from a host in a first network and create logs for them.
- Detect outgoing packets from the network device to a host in a second network and create logs for them.
- Match the outgoing packets with the incoming packets using these logs. This matching process is crucial for understanding network traffic when an intermediate network device has modified the packets, potentially hiding their original communication flow. The system aims to re-establish this original flow association.
Claim 19 (Method): This claim details a method for a computing system to correlate packets by:
- Receiving a log entry for a packet coming into a network device from a first host.
- Receiving a log entry for a packet going out of the network device to a second host.
- Correlating these packets by comparing specific data within their log entries (e.g., network, transport, or application layer information) AND by comparing timestamps from the log entries. This is done to figure out that the outgoing packet is part of the same communication flow as the incoming packet, even when the network device acts as a flow-transforming device (like a NAT, proxy, or gateway) that changes packet information.
Claim 20 (Method): This claim presents a method for a computing system to correlate network packets, specifically involving:
- Collecting log entries from a first "tap" device that monitors packets received by a network device.
- Collecting log entries from a second "tap" device that monitors packets transmitted by the same network device.
- Correlating the transmitted packets with the received packets by comparing data fields in their respective log entries (to find matching portions) and by comparing the timestamps of the entries (to find the closest temporal match). This process helps to determine the original flow association, even when the network device acts as a flow-transforming device.
CAFC 2026 Dockets for US9560176:
Based on the provided information, US patent 9560176 is currently active and has been involved in litigation at the Court of Appeals for the Federal Circuit (CAFC). There are two specific cases mentioned:
- US case filed in Court of Appeals for the Federal Circuit (case number 21-1888, noted as "Critical")
- US case filed in Court of Appeals for the Federal Circuit (case number 24-2097)
While these cases were filed in 2021 and 2024 respectively, their ongoing status means they would appear in "CAFC 2026 dockets" as active or unresolved matters during that year. The litigation data was fetched as recently as June 26, 2026.
Generated 6/26/2026, 12:45:42 PM