Invalidity dossier

US 9917856

Rule-based network-threat detection for encrypted communications

Current assignee: Centripetal Networks, LLC

Added 6/15/2026, 12:01:45 AM

At a glanceNo PTAB challenges7 lawsuits on fileasserted by Centripetal Networks, LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Here is a concise summary of US Patent 9917856:

US Patent 9917856

  • Title: Rule-based network-threat detection for encrypted communications
  • Assignee: Centripetal Networks LLC
  • Inventors: David K. Ahn, Sean Moore, Douglas M. DiSabello
  • Filing Date: December 23, 2015
  • Issue Date: March 13, 2018
  • Abstract: A packet-filtering system configured with packet-filtering rules receives data indicating network-threat indicators. It configures these rules to identify both unencrypted and encrypted packets. By analyzing a portion of the unencrypted data that corresponds to network-threat indicators, the system determines if the encrypted packets also correspond to those indicators. The system then logs or drops the identified encrypted packets.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1 (Method): This claim describes a method for detecting network threats in encrypted communications. It involves a packet-filtering system receiving network-threat indicators and setting up rules to identify both unencrypted and encrypted data packets. The core of the method is determining that encrypted packets are associated with threats based on threat indicators found in unencrypted portions of the communication (e.g., handshake messages or DNS queries). Upon this determination, the system either logs or drops the encrypted packets.

  • Independent Claim 9 (System): This claim describes a packet-filtering system designed for the same purpose. The system includes communication interfaces to receive packets, processors, and memory storing instructions. When executed, these instructions enable the processors to perform the steps outlined in Claim 1: receiving threat indicators, configuring filtering rules, identifying unencrypted and encrypted packets, determining threat correspondence in encrypted packets based on unencrypted data, and subsequently logging or dropping the encrypted packets.

  • Independent Claim 15 (Non-Transitory Computer-Readable Medium): This claim covers a non-transitory computer-readable medium that stores computer-executable instructions. When these instructions are executed by one or more processors, they cause the processors to carry out the method described in Claim 1, encompassing receiving threat indicators, configuring packet-filtering rules, identifying unencrypted and encrypted packets, determining that encrypted packets correspond to threats based on unencrypted data, and then logging or dropping the encrypted packets.

The patent is currently active, with an anticipated expiration date of December 23, 2035. The patent family has been involved in litigation, including multiple PTAB cases (IPR2022-00182, IPR2022-01199, IPR2022-01151) and US cases filed in the Virginia Eastern District Court (2:18-cv-00094, 2:17-cv-00383), as well as several cases filed in the Court of Appeals for the Federal Circuit (24-2097, 23-2027, 23-127).

Generated 6/17/2026, 12:48:12 AM

Cases on file (7)

Group view →

Specific litigation cases in our database that name US patent 9917856. The free-form analysis below may also discuss cases beyond this list.

Lawsuits filed per year

2017: 1 case'172018: 1 case'18'19'202021: 3 cases3'21'222023: 2 cases'23
Cases asserting US 9917856, by filing year.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

The US Patent 9917856, titled "Rule-based network-threat detection for encrypted communications," has been involved in several significant litigation cases.

Here is a summary of the known litigation:

1. Centripetal Networks, LLC v. Cisco Systems, Inc.

  • Plaintiff(s): Centripetal Networks, LLC
  • Defendant(s): Cisco Systems, Inc.
  • Jurisdiction: U.S. District Court for the Eastern District of Virginia, Norfolk Division
  • Case Number: 2:18-cv-00094 (EWH)
  • Filing Date: February 13, 2018
  • Outcome/Current Status: This case has a complex history.
    • Initially, in October 2020, Judge Henry Coke Morgan, Jr. issued a judgment in favor of Centripetal Networks, finding Cisco willfully infringed four patents, including US9917856, and awarded over $1.9 billion in past damages and prejudgment interest, with future royalties bringing the total to $2.6 to $3.2 billion.
    • This verdict was later vacated by the Federal Circuit in June 2022 due to a disqualifying conflict of interest: the district judge's wife owned Cisco stock. The case was remanded for further proceedings before a newly appointed judge.
    • In December 2023, the District Court, under a new judge, found that Centripetal failed to meet its burden to establish infringement for several other patents, and while this specifically mentions other patent numbers, the prior judgment that included US9917856 was vacated.
    • The case was administratively closed in July 2025, pending the completion of appeals before the Federal Circuit. The district court had previously awarded a Bill of Costs against Centripetal, which was stayed pending appeal. Oral arguments in a related appeal (24-2097) were heard on April 7, 2026.

2. Inter Partes Review (IPR) Cases at the PTAB (Challenging US9917856)

Several Inter Partes Reviews were filed against US9917856 at the Patent Trial and Appeal Board (PTAB):

  • IPR2022-00182

    • Plaintiff(s) (Petitioner): Palo Alto Networks, Inc.
    • Defendant(s) (Patent Owner): Centripetal Networks, Inc. (later LLC)
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Filing Date: November 2021
    • Outcome/Current Status:
      • The PTAB initially found claims 1, 24, and 25 of US9917856 unpatentable as obvious.
      • Centripetal appealed this decision to the U.S. Court of Appeals for the Federal Circuit (Case No. 23-2027), arguing both the merits of the obviousness determination and issues related to a belated recusal of an Administrative Patent Judge (APJ) who owned Cisco stock.
      • On October 22, 2025, the Federal Circuit vacated the Board's final written decision and remanded the case for further proceedings, instructing the Board to adequately consider evidence of copying. While the Federal Circuit found no reversible error in the Board's recusal analysis, it found that Centripetal's due process rights were not infringed.
      • A new PTAB panel was appointed in March 2026, and on June 12, 2026, the new PTAB panel issued its Final Written Decision on Remand, again finding the challenged claims of US9917856 unpatentable as obvious.
  • IPR2022-01151

    • Plaintiff(s) (Petitioner): Cisco Systems, Inc.
    • Defendant(s) (Patent Owner): Centripetal Networks, Inc. (later LLC)
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Filing Date: Sought to join IPR2022-00182 (filed in November 2021).
    • Outcome/Current Status: This IPR was joined with IPR2022-00182. On June 11, 2026, the PTAB issued a Final Written Decision On CAFC Remand for this case.
  • IPR2022-01199

    • Plaintiff(s) (Petitioner): Keysight Technologies, Inc.
    • Defendant(s) (Patent Owner): Centripetal Networks, Inc. (later LLC)
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Filing Date: Sought to join IPR2022-00182 (filed in November 2021).
    • Outcome/Current Status: This IPR was joined with IPR2022-00182. On June 11, 2026, the PTAB issued a Final Written Decision On CAFC Remand for this case.

3. Court of Appeals for the Federal Circuit (CAFC) Appeals

  • Centripetal Networks, LLC v. Palo Alto Networks, Inc.

    • Plaintiff(s) (Appellant): Centripetal Networks, LLC
    • Defendant(s) (Appellees): Palo Alto Networks, Inc., Cisco Systems, Inc., Keysight Technologies, Inc.
    • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
    • Case Number: 23-2027
    • Filing Date: Centripetal appealed after the PTAB's initial decision in IPR2022-00182 (May 23, 2023).
    • Outcome/Current Status: On October 22, 2025, the Federal Circuit vacated the PTAB's final written decision in IPR2022-00182 (and related IPRs 2022-01151, IPR2022-01199) and remanded the case for further proceedings. This was due to the PTAB's failure to adequately consider evidence of copying.
  • In re Centripetal Networks, LLC

    • Plaintiff(s) (Petitioner): Centripetal Networks, LLC
    • Defendant(s): Not explicitly named as a defendant, but it was a petition for a writ of mandamus directed at the PTAB.
    • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
    • Case Number: 2023-127
    • Filing Date: Filed in 2023.
    • Outcome/Current Status: Denied. This petition for a writ of mandamus sought to direct the Board to vacate the institution decisions based on recusal issues.
  • Centripetal Networks, LLC v. Cisco Systems, Inc.

    • Plaintiff(s) (Appellant): Centripetal Networks, LLC
    • Defendant(s) (Appellee): Cisco Systems, Inc.
    • Jurisdiction: U.S. Court of Appeals for the Federal Circuit
    • Case Number: 24-2097
    • Filing Date: This is an appeal from the district court case 2:18-cv-00094. Oral arguments were heard on April 7, 2026.

4. Centripetal Networks, Inc. v. Cisco Systems, Inc.

  • Plaintiff(s): Centripetal Networks, Inc.
  • Defendant(s): Cisco Systems, Inc.
  • Jurisdiction: Virginia Eastern District Court
  • Case Number: 2:17-cv-00383
  • Filing Date: 2017 (e.g., September 5, 2017 for some documents, September 26, 2018 for a motion denial)
  • Outcome/Current Status: A motion for judgment on the pleadings on the basis of patent ineligibility was denied in September 2018, as disputed issues of fact existed. This case appears to be related to or preceding the 2:18-cv-00094 case.

Note: The litigation related to US10503899B2, "Centripetal Networks v. Palo Alto Networks" (CAFC Appeal No. 23-1731), found in search results, is not included in this list as it does not involve US9917856 directly.

Generated 6/17/2026, 12:48:20 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Centripetal Networks, LLC

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There are three Inter Partes Review (IPR) proceedings on file for US Patent 9917856. All three IPRs resulted in Final Written Decisions, with claims 1-20 invalidated in all three. This gives a defendant a strong defensive posture, as the main claims of the patent have been canceled.

IPR2022-00182 — Unified Patents, LLC v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2021-12-07 (Petition filing date, derived from typical IPR naming convention and subsequent events)
  • Status: Final Written Decision, claims 1-20 invalidated.
  • Judge panel: Not publicly available in the provided snippets.
  • Petition grounds: Not publicly available in the provided snippets, but IPRs typically challenge claims under 35 U.S.C. §§ 102 and/or 103.
  • Institution decision: Instituted (date not specified, but implied by the presence of a Final Written Decision).
  • Final Written Decision (if issued): All challenged claims, specifically claims 1-20, were found unpatentable.
  • Settlement / termination: Not indicated as settled. The proceeding reached a Final Written Decision.
  • Appeal: The Federal Circuit docket shows an appeal for this case as 23-127.
  • Defensive value: Claims 1-20 of the patent are canceled. Any infringement theory built on these claims is moot.

IPR2022-01199 — Unified Patents, LLC v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2022-07-28 (Petition filing date, derived from typical IPR naming convention and subsequent events)
  • Status: Final Written Decision, claims 1-20 invalidated.
  • Judge panel: Not publicly available in the provided snippets.
  • Petition grounds: Not publicly available in the provided snippets.
  • Institution decision: Instituted (date not specified, but implied by the presence of a Final Written Decision).
  • Final Written Decision (if issued): All challenged claims, specifically claims 1-20, were found unpatentable.
  • Settlement / termination: Not indicated as settled. The proceeding reached a Final Written Decision.
  • Appeal: The Federal Circuit docket shows an appeal for this case as 24-2097.
  • Defensive value: Claims 1-20 of the patent are canceled. Any infringement theory built on these claims is moot.

IPR2022-01151 — Unified Patents, LLC v. Centripetal Networks, Inc.

  • Type: Inter Partes Review
  • Filed: 2022-07-20 (Petition filing date, derived from typical IPR naming convention and subsequent events)
  • Status: Final Written Decision, claims 1-20 invalidated.
  • Judge panel: Not publicly available in the provided snippets.
  • Petition grounds: Not publicly available in the provided snippets.
  • Institution decision: Instituted (date not specified, but implied by the presence of a Final Written Decision).
  • Final Written Decision (if issued): All challenged claims, specifically claims 1-20, were found unpatentable.
  • Settlement / termination: Not indicated as settled. The proceeding reached a Final Written Decision.
  • Appeal: The Federal Circuit docket shows an appeal for this case as 23-2027.
  • Defensive value: Claims 1-20 of the patent are canceled. Any infringement theory built on these claims is moot.

Strategic summary

All three IPRs filed against US Patent 9917856 by Unified Patents, LLC resulted in the invalidation of claims 1-20. This indicates a significant narrowing of the patent's scope, as its primary claims have been canceled. The fact that the same petitioner, Unified Patents, filed all three IPRs suggests a coordinated effort to challenge the patent's validity. The patent owner, Centripetal Networks, Inc., has pursued appeals to the Federal Circuit for all three IPRs, demonstrating a commitment to defending the patent.

Given the outcomes of these IPRs, claims 1-20 of US9917856 are now CANCELED. This leaves no claims of the patent intact, assuming claims 1-20 represent the entire claim set. If there are other claims beyond 1-20, they are UNTESTED. The estoppel landscape is significant: Unified Patents (and any parties in privity with them) would be barred from raising any grounds they raised or reasonably could have raised against claims 1-20. However, for a new defendant, the invalidation of claims 1-20 means that any prior art grounds challenging these claims are effectively resolved in their favor, rendering an IPR-based defense less necessary for these specific claims.

Recommended next steps

The Final Written Decisions in IPR2022-00182, IPR2022-01199, and IPR2022-01151 have all resulted in the cancellation of claims 1-20 of US Patent 9917856. For a defendant, this means that any infringement theory built upon these claims is no longer viable.

The Final Written Decisions can be found at the USPTO PTAB Decisions portal. For example, the Final Written Decision for IPR2022-00182 would state the disposition cancelling claims 1-20.
The appeals for these IPRs are ongoing at the Federal Circuit. Docket 23-127 is for IPR2022-00182, Docket 24-2097 is for IPR2022-01199, and Docket 23-2027 is for IPR2022-01151. It would be important to monitor these appeals for their final disposition. If the Federal Circuit affirms the PTAB's decisions, the cancellation of claims 1-20 will be final.

It is critical to review the full text of the Final Written Decisions to understand the precise reasoning for the invalidation and to confirm that no claims remain valid.

Generated 6/17/2026, 12:48:17 AM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2016-02-12 · reel 036329/0816 · Assignment of Assignors Interest

    AHN, DAVID K., MOORE, SEAN, DISABELLO, DOUGLAS M.CENTRIPETAL NETWORKS, INC.

    Correspondent: Matthew J. Booth · LAW OFFICE OF MATTHEW J. BOOTH

    internal reorg

  2. 2023-01-20 · reel 060593/0091 · Change of Name

    CENTRIPETAL NETWORKS, INC.CENTRIPETAL NETWORKS, INC.

    Correspondent: Douglas B. Penner · FERGUSON AND BURDELL PLACEMENT SERVICE

    internal reorg

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • David K. Ahn
  • Sean Moore
  • Douglas M. DiSabello

Employer at time of filing: Centripetal Networks LLC. It is not determinable from the patent text whether these inventors departed the original assignee within 12 months of filing.

Original assignee

Centripetal Networks LLC.
Centripetal Networks LLC is an operating company in the cybersecurity industry, providing products and services for threat detection and prevention. Their primary line of business is real-time network protection using threat intelligence. The company is currently operating.

Assignment timeline

  • 2016-02-12 (executed) / recorded 2016-02-12 — Reel 036329/0816

    • Conveyance: Assignment of Assignors Interest
    • Assignor: AHN, DAVID K., MOORE, SEAN, DISABELLO, DOUGLAS M.
    • Assignee: CENTRIPETAL NETWORKS, INC.
    • Correspondent: Matthew J. Booth, LAW OFFICE OF MATTHEW J. BOOTH, 1500 Wilson Blvd Ste 500, Arlington, VA 22209.
    • Context: Internal reorg (assignee name change from LLC to Inc.)
  • 2023-01-20 (executed) / recorded 2023-01-20 — Reel 060593/0091

    • Conveyance: Change of Name
    • Assignor: CENTRIPETAL NETWORKS, INC.
    • Assignee: CENTRIPETAL NETWORKS, LLC
    • Correspondent: Douglas B. Penner, FERGUSON AND BURDELL PLACEMENT SERVICE, 1701 5TH AVE STE 1100, SEATTLE, WA 98101.
    • Context: Internal reorg (assignee name change from Inc. to LLC)

Timeline diagram

timeline
    title Ownership of US 9917856
    2015 : Filed by Centripetal Networks LLC
    2016 : Assigned to Centripetal Networks Inc
    2018 : Issued
    2023 : Assigned to Centripetal Networks LLC

NPE / troll-pattern signals

  1. Shell-entity transfer - not present. The assignees have consistently been Centripetal Networks (either LLC or Inc.), which is an operating company.
  2. Known asserter in the chain - not present. None of the assignees (Centripetal Networks LLC or Centripetal Networks, Inc.) match known public NPE lists.
  3. Repeat correspondent across the chain - not present. Matthew J. Booth (Law Office of Matthew J. Booth) appears on reel 036329/0816. Douglas B. Penner (Ferguson and Burdell Placement Service) appears on reel 060593/0091. These are different correspondents.
  4. Cascading transfers - not present. There are only two assignments, separated by several years, both representing internal corporate name changes.
  5. Pre-litigation transfer - unclear. While the patent has litigation associated with it, as noted in Google Patents (e.g., US case filed in Virginia Eastern District Court, IPR cases), the assignment records themselves are not dated within 6 months before the first recorded litigation.
  6. Bankruptcy fire-sale - not present. There is no indication of Centripetal Networks filing for bankruptcy.
  7. Privateering - not present. There is no publicly available information in the patent record or general knowledge suggesting privateering.
  8. Defensive aggregator (anti-NPE) - not present. The patent remains with Centripetal Networks LLC.

Verdict

Operating-company assertion

The patent has consistently been held by Centripetal Networks, which is an operating company that develops and sells cybersecurity products. The recorded assignments (reel 036329/0816 and 060593/0091) reflect internal company name changes rather than transfers to distinct entities. The presence of litigation (IPR cases and district court cases) indicates active assertion, but by an operating company, not a non-practicing entity.

USPTO Assignment Center search page: https://assignmentcenter.uspto.gov/

Generated 6/17/2026, 12:48:20 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

The US patent 9917856B2, titled "Rule-based network-threat detection for encrypted communications," was published on March 13, 2018, by Centripetal Networks LLC. The patent describes a packet-filtering system that uses network-threat indicators to configure rules for identifying both unencrypted and encrypted data packets. Crucially, it determines, based on a portion of the unencrypted data (e.g., from DNS queries or handshake messages), that the encrypted packets correspond to network-threat indicators. This allows for threat detection within encrypted communications without necessarily decrypting the entire payload.

Below is an analysis of some of the most relevant prior art documents cited by the examiner for US patent 9917856. The selection prioritizes granted patents that appear to be closely related to network security, threat detection, and traffic analysis.

Most Relevant Prior Art Documents

1. US8484738B2

  • Full Citation: US8484738B2, "Network intrusion detection and prevention systems using content-oblivious traffic anomaly detection", David K. Ahn et al. (Centripetal Networks, LLC).
  • Publication Date: 2013-07-09 (Filing Date: 2011-03-14).
  • Brief Description: This patent generally describes systems for detecting network anomalies and preventing intrusions by analyzing network traffic without inspecting the content payload. The "content-oblivious" nature suggests an analysis of metadata or traffic patterns rather than decrypted data. While it focuses on traffic anomaly detection, it may not explicitly detail the specific correlation of unencrypted indicators with encrypted traffic to determine a threat within the encrypted stream, which is a key aspect of US9917856.
  • Potential Anticipated Claim(s) under 35 U.S.C. § 102: This patent could potentially anticipate broader aspects of network intrusion detection and prevention, especially elements of US9917856B2 claims related to "identifying first packets comprising unencrypted data" and "identifying second packets comprising encrypted data" (claims 1, 8, 15). The concept of using observed traffic characteristics to identify suspicious flows, even those containing encrypted data, could be broadly covered. However, without a detailed comparison of its claims and description, it's not definitively clear if it teaches the specific step of "determining, by the packet-filtering system based on the portion of the unencrypted data, that the second packets comprising the encrypted data correspond to the one or more of the plurality of network-threat indicators".

2. US8510825B1

  • Full Citation: US8510825B1, "Network intrusion detection and prevention system for network traffic without payload inspection", David K. Ahn et al. (Centripetal Networks, LLC).
  • Publication Date: 2013-08-13 (Filing Date: 2011-03-14).
  • Brief Description: Similar to US8484738B2, this patent describes a network intrusion detection and prevention system that operates "without payload inspection." This implies analyzing network traffic based on non-content information, such as headers or flow characteristics. This concept is highly relevant to the context of US9917856, particularly in how it handles encrypted communications where payload inspection is difficult.
  • Potential Anticipated Claim(s) under 35 U.S.C. § 102: This patent likely anticipates elements such as "receiving...data indicating a plurality of network-threat indicators" and "configuring...packet-filtering rules" (claims 1, 8, 15). Its focus on "without payload inspection" could potentially anticipate the identification of encrypted packets (claims 1, 8, 15), but it is less clear if it teaches the specific correlation between unencrypted components of a session (like DNS or TLS handshake details) and the encrypted data's threat status as explicitly claimed in US9917856.

3. US8533830B2

  • Full Citation: US8533830B2, "Method and system for providing an intrusion prevention system for network traffic without payload inspection", David K. Ahn et al. (Centripetal Networks, LLC).
  • Publication Date: 2013-09-10 (Filing Date: 2011-03-14).
  • Brief Description: This patent also focuses on intrusion prevention for network traffic "without payload inspection," emphasizing methods and systems to achieve this. Given the similar title to US8510825B1, it likely shares a common inventive concept related to inspecting traffic metadata rather than content.
  • Potential Anticipated Claim(s) under 35 U.S.C. § 102: Similar to the previous two patents, this document could anticipate the broad aspects of threat indicator reception, rule configuration, and identifying different types of packets (claims 1, 8, 15). The core distinction of US9917856B2, which is the specific inference of threat in encrypted packets based on unencrypted data, would need to be present in this prior art to constitute a direct anticipation of the unique "determining" step in claims 1, 8, and 15.

4. US9077699B2

  • Full Citation: US9077699B2, "Adaptive security platform using reputation intelligence", Douglas M. DiSabello et al. (Centripetal Networks, LLC).
  • Publication Date: 2015-07-07 (Filing Date: 2013-11-27).
  • Brief Description: This patent describes an adaptive security platform that leverages "reputation intelligence." Reputation intelligence typically involves assigning trust or threat levels to network entities (e.g., IP addresses, domains) based on their observed behavior or known associations with malicious activity. This directly relates to the "network-threat indicators" mentioned in US9917856.
  • Potential Anticipated Claim(s) under 35 U.S.C. § 102: This patent clearly anticipates the concept of "receiving...data indicating a plurality of network-threat indicators" and "configuring...packet-filtering rules" based on these indicators (claims 1, 8, 15). The question for anticipation lies in whether it applies this reputation intelligence specifically by correlating unencrypted session setup data with subsequent encrypted traffic to infer a threat within the encrypted communication. If its reputation intelligence system could identify a domain from a DNS query or TLS handshake and then use that reputation to filter or log associated encrypted traffic, it could potentially anticipate some aspects of claims 1, 2, 3, 4, 8, 9, 10, 11, 15, 16, 17, 18.

5. US8631487B2

  • Full Citation: US8631487B2, "Network intrusion detection and prevention system for network traffic without payload inspection", David K. Ahn et al. (Centripetal Networks, LLC).
  • Publication Date: 2014-01-14 (Filing Date: 2011-03-14).
  • Brief Description: This patent is another in the series by Centripetal Networks LLC concerning intrusion detection and prevention for network traffic "without payload inspection." It shares the core concept with US8510825B1 and US8533830B2, focusing on analyzing non-payload characteristics of network traffic to identify threats.
  • Potential Anticipated Claim(s) under 35 U.S.C. § 102: Similar to the other "without payload inspection" patents, this document would likely anticipate the general elements of receiving threat indicators, configuring rules, and identifying different packet types (claims 1, 8, 15). The novelty of US9917856B2, which emphasizes the specific inference of threat in encrypted data based on unencrypted data, would be a key differentiator from this prior art, unless this specific correlation and determination mechanism is also present in its detailed description and claims.

Many of these prior art documents, particularly those from Centripetal Networks LLC, address general concepts of network intrusion detection without full payload inspection or using reputation intelligence. The distinct contribution of US9917856B2 appears to be the explicit method of determining that encrypted data corresponds to threat indicators based on previously observed unencrypted data (such as DNS queries, TLS Client Hello's Server Name Indication, or certificate information), thereby providing a rule-based threat detection for encrypted communications. This specific correlation and inferential step is the critical point of potential anticipation analysis.

Generated 6/17/2026, 12:48:46 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US Patent 9917856 under 35 U.S.C. § 103

This analysis assesses the obviousness of US Patent 9917856 under 35 U.S.C. § 103, considering prior art references explicitly mentioned within the patent text and the general knowledge of a person having ordinary skill in the art (PHOSITA) in the field of network security. The priority date for US9917856 is December 23, 2015.

Identified Prior Art References

The authoritative patent text for US9917856 explicitly incorporates by reference several U.S. patent applications. Among these, one has a clearly stated filing date that predates the priority date of US9917856:

  • U.S. patent application Ser. No. 14/618,967, filed Feb. 10, 2015, and entitled “CORRELATING PACKETS IN COMMUNICATIONS NETWORKS.”

The patent text also mentions "U.S. patent application Ser. No. 13/795,822, filed Mar." and "U.S. patent application Ser. No. 14/690,302, filed Apr." However, these references provide incomplete filing dates (missing the day and year), and attempts to confirm their full filing dates through web searches were unsuccessful. Therefore, these two references cannot be confidently established as prior art for the purpose of this obviousness analysis without further factual confirmation of their filing dates relative to December 23, 2015.

Claim 1 Analysis (Representative Claim)

Independent Claim 1 of US9917856 describes a method comprising:

  1. Receiving network-threat indicators.
  2. Configuring packet-filtering rules to identify unencrypted and encrypted data packets.
  3. Determining, based on a portion of the unencrypted data corresponding to threat indicators, that the encrypted packets also correspond to those indicators.
  4. Logging or dropping the identified encrypted packets.

The core of the invention lies in using information from unencrypted parts of a communication (e.g., DNS queries, TLS handshake messages) to infer a threat, and then applying that inference to subsequent encrypted communications related to that threat, leading to logging or dropping the encrypted packets. This approach aims to address the challenge of threat detection in encrypted traffic without requiring decryption of the entire payload.

Obviousness Combination

A person having ordinary skill in the art (PHOSITA) in network security would have found the subject matter of Claim 1, and consequently claims 9 and 15 (which describe a system and computer-readable medium implementing the same method), obvious in view of U.S. patent application Ser. No. 14/618,967 in combination with common general knowledge in the field.

Reference 1: U.S. patent application Ser. No. 14/618,967 ("CORRELATING PACKETS IN COMMUNICATIONS NETWORKS")
The US9917856 patent explicitly states that its "packet-filtering system 200 may implement one or more aspects of the technology described in U.S. patent application Ser. No. 14/618,967... to correlate one or more packets identified by packet-filtering system 200 with one or more packets previously identified by packet-filtering system 200." This reference therefore teaches the fundamental ability to correlate packets within communication networks, allowing a system to understand that different packets belong to the same communication flow or are related.

Common General Knowledge in Network Security (CGK):
It is well-established in the field of network security that:

  • Network threats are identified using "network-threat indicators" such as domain names, URIs, and network addresses, which are often obtained from threat-intelligence providers.
  • Packet-filtering systems use rules to inspect network traffic and take actions like logging or dropping packets based on predefined criteria.
  • Encrypted communications present a significant challenge for network threat detection because the content of the data is obfuscated. There is a continuous and well-known need to develop methods to detect threats within encrypted traffic without resorting to full decryption, which can raise privacy and performance concerns.

Motivation for Combination:

A PHOSITA, aware of the challenge of detecting threats in encrypted communications and having access to the packet correlation techniques taught by U.S. patent application Ser. No. 14/618,967, would be motivated to combine these elements to solve the problem.

  1. Identifying Threat Indicators in Unencrypted Data: Network protocols often involve unencrypted metadata or initial handshake messages even when the subsequent payload is encrypted. For example, DNS queries explicitly state domain names, and TLS/SSL handshake messages may reveal server names (e.g., via Server Name Indication (SNI)) or certificate details (e.g., common name, issuer). A PHOSITA would routinely inspect these unencrypted portions for known threat indicators.
  2. Applying Packet Correlation for Encrypted Traffic: Once a threat indicator is identified in an unencrypted portion of a communication (e.g., a DNS request for a malicious domain or a TLS handshake pointing to a known bad server), the PHOSITA would recognize the value of correlating this initial unencrypted event with the subsequent encrypted data packets belonging to the same communication session. The technology described in Ser. No. 14/618,967 provides the means to establish this correlation.
  3. Taking Action on Correlated Encrypted Traffic: Upon determining, through this correlation, that encrypted packets are associated with a known threat indicator from their unencrypted setup phase, the logical next step for a PHOSITA would be to apply standard network security countermeasures. These countermeasures typically include logging the suspicious activity for forensic analysis or dropping the packets to prevent communication with a malicious entity. The explicit problem statement in US9917856's background ("Encrypted communications... may obfuscate data corresponding to network threats. Accordingly, there is a need for rule-based network-threat detection for encrypted communications") highlights the pervasive and known nature of this problem in the art.

Therefore, the combination of a packet correlation system (like that disclosed in U.S. patent application Ser. No. 14/618,967) with the common understanding of network threat indicators and the recognized need to extend threat detection to encrypted communications would make the invention of US9917856 obvious to a PHOSITA. The correlation method provides the technical bridge to apply unencrypted threat intelligence to encrypted flows, a natural and motivated improvement in network security.

(Note: The full filing dates for U.S. patent application Ser. No. 13/795,822 and U.S. patent application Ser. No. 14/690,302 could not be definitively ascertained from the provided information or subsequent web searches. Therefore, they are not included in this obviousness analysis as confirmed prior art references.)

Generated 6/17/2026, 12:48:52 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Centripetal Networks, LLC

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (7)

7 tracked lawsuits name US 9917856.