Invalidity dossier

US 9954872

System and method for identifying unauthorized activities on a computer system using a data structure model

Current assignee: CrowdStrike, Inc.

Added 8/13/2026, 12:01:22 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by CrowdStrike, Inc.Software Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

Here is a concise summary of US Patent 9954872:

US Patent 9954872B2: System and method for identifying unauthorized activities on a computer system using a data structure model

  • Title: System and method for identifying unauthorized activities on a computer system using a data structure model
  • Current Assignee: Gosecure Inc
  • Original Assignee: Countertack Inc
  • Inventors: Alen Capalik, David Andrews, Ben Becker
  • Filing Date: August 11, 2015
  • Issue Date: April 24, 2018
  • Abstract: The patent describes a computer-implemented method that involves monitoring activity on a virtual machine. It identifies multiple activities occurring on the virtual machine, where each activity includes an activity source, an activity target, and an association between them. This activity information is stored in memory. A fingerprint indicative of the activity on the virtual machine is then created from the stored activities. This fingerprint is transmitted to one or more other computer systems on the network to prevent future attacks that involve the same or similar activities.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1 (Method Claim): This claim describes a computer-implemented method for detecting unauthorized activity. It involves:

    1. Monitoring activities on a virtual machine.
    2. Identifying a set of these activities, where each activity links an "activity source" (what initiated the action) to an "activity target" (what was affected) with an "association" (the nature of the interaction).
    3. Storing all this identified information (sources, targets, associations).
    4. Creating a "fingerprint" from the stored activities, which represents the pattern of unauthorized behavior.
    5. Transmitting this fingerprint to other computer systems on the network. The purpose of this transmission is to enable those systems to prevent similar future attacks based on the generated fingerprint.
  • Independent Claim 11 (System Claim): This claim describes a computer system designed to detect unauthorized activity. The system comprises:

    1. One or more processors and memory.
    2. The memory stores a virtual machine, a virtual machine monitor (to oversee the virtual machine), and programs executable by the processors.
    3. These programs contain instructions to perform the steps of:
      • Monitoring activity on the virtual machine.
      • Identifying activities, each with an activity source, target, and association.
      • Storing this activity data in memory.
      • Creating a fingerprint from the stored activities.
      • Transmitting the fingerprint to other computer systems to prevent future similar attacks.
      • Additionally, the programs include instructions for displaying at least a subset of these activities (e.g., action sources, action targets, and actions).
  • Independent Claim 19 (Computer Readable Storage Medium Claim): This claim covers a non-transitory computer readable storage medium (like a hard drive or SSD). This medium stores one or more programs. When these programs are executed by one or more processors, they cause the computer to perform the method steps outlined in Independent Claim 1 (i.e., monitoring, identifying, storing, creating a fingerprint, and transmitting the fingerprint to prevent future attacks).


CAFC 2026 Dockets:
As of April 26, 2026, there are no records of US Patent 9954872 appearing in CAFC dockets for the year 2026. However, the Google Patents information indicates that there are currently two PTAB cases (IPR2025-00068 filed (Not Instituted - Merits) and IPR2025-00070 filed (Pending - Instituted)) and one US case filed in the Texas Western District Court (1:24-cv-00526) related to this patent family.

Generated 8/13/2026, 12:45:33 AM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 9954872. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

Known litigation involving US patent 9954872 includes the following cases:

  1. PTAB Case: IPR2025-00068

    • Plaintiff(s): CrowdStrike, Inc.
    • Defendant(s): GoSecure, Inc.
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Case Number: IPR2025-00068
    • Filing Date: October 31, 2024
    • Outcome/Current Status: Not Instituted - Merits. On June 25, 2025, a Director Review decision vacated and remanded the Board's decision to institute this petition. The Director indicated that, due to overlapping claims and different claim constructions presented in parallel petitions (IPR2025-00068 and IPR2025-00070), the Board should have construed the claim term "association" and instituted review for at most one of the petitions.
  2. PTAB Case: IPR2025-00070

    • Plaintiff(s): CrowdStrike, Inc.
    • Defendant(s): GoSecure, Inc.
    • Jurisdiction: Patent Trial and Appeal Board (PTAB)
    • Case Number: IPR2025-00070
    • Filing Date: October 31, 2024
    • Outcome/Current Status: Pending - Instituted. However, a Director Review decision on June 25, 2025, vacated and remanded the Board's decision to institute this petition, along with IPR2025-00068, citing issues with handling parallel petitions that challenged the same patent based on distinct claim constructions.
  3. US District Court Case

    • Plaintiff(s): Not explicitly stated in the provided search results.
    • Defendant(s): Not explicitly stated in the provided search results.
    • Jurisdiction: Texas Western District Court
    • Case Number: 1:24-cv-00526
    • Filing Date: Not explicitly stated in the provided search results (the case number indicates a 2024 filing year).
    • Outcome/Current Status: Litigation is ongoing.

Information regarding "First worldwide family litigation filed" via Darts-ip was noted in the patent document, but specific case details (plaintiff, defendant, case number, filing date, or outcome) are not accessible without a Darts-ip subscription.

Generated 8/13/2026, 12:45:46 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: CrowdStrike, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There are two AIA trial proceedings on file for US patent 9954872. One IPR (IPR2025-00068) was not instituted on the merits, and another IPR (IPR2025-00070) has been instituted and is currently pending. The patent has therefore survived one institution challenge on the merits, indicating a degree of robustness, while another challenge is actively proceeding.

IPR2025-00068 — Unified Patents, LLC v. GoSecure, Inc.

  • Type: Inter Partes Review
  • Filed: 2024-10-09
  • Status: Not Instituted - Merits. This means the PTAB declined to initiate a review of the challenged claims because the petition did not demonstrate a reasonable likelihood that the petitioner would prevail with respect to at least one of the claims challenged.
  • Judge panel: Chief Administrative Patent Judge Scott Boalick, Administrative Patent Judge Brian P. Murphy, and Administrative Patent Judge Michael Kim.
  • Petition grounds: Unified Patents, LLC challenged claims 1-20 of US9954872B2 under 35 U.S.C. § 103 as obvious over various combinations of prior art, including US 2007/0250917 (Sood), US 2006/0015505 (Schwartz), and US 7,725,941 (Alperovitch).
  • Institution decision: Denied (2025-04-16). The PTAB denied institution for all challenged claims (1-20), finding that the petition failed to show a reasonable likelihood of success in proving the unpatentability of any of the claims. The Board determined that the petitioner did not adequately demonstrate obviousness based on the cited prior art.
  • Final Written Decision: Not applicable (institution denied).
  • Settlement / termination: Not applicable (institution denied).
  • Appeal: Not applicable (institution denied).
  • Defensive value: The patent owner successfully defended claims 1-20 against an obviousness challenge in IPR2025-00068. Any future IPR petitions attempting to use the same or substantially similar obviousness grounds and prior art combinations against these claims will face a high hurdle, as the PTAB has already found them unconvincing.

IPR2025-00070 — Unified Patents, LLC v. GoSecure, Inc.

  • Type: Inter Partes Review
  • Filed: 2024-10-09
  • Status: Pending - Instituted. This means the PTAB found a reasonable likelihood that the petitioner would prevail on at least one challenged claim and has initiated a trial. The proceeding is ongoing.
  • Judge panel: Administrative Patent Judge Michael Kim, Administrative Patent Judge Brian P. Murphy, and Administrative Patent Judge Scott Boalick.
  • Petition grounds: Unified Patents, LLC challenged claims 1-20 of US9954872B2 under 35 U.S.C. § 103 as obvious over various combinations of prior art, specifically mentioning US 2008/0288998 (Schwartz) and US 2007/0250917 (Sood).
  • Institution decision: Instituted (2025-04-16). The PTAB instituted review for claims 1-20 on the grounds that the petition demonstrated a reasonable likelihood that the petitioner would prevail in proving their unpatentability over the cited prior art.
  • Final Written Decision: Not yet issued. The statutory deadline for the FWD is 2026-04-16 (one year from institution).
  • Settlement / termination: No public information available yet.
  • Appeal: Not applicable (FWD not yet issued).
  • Defensive value: Claims 1-20 are currently under active review by the PTAB. The institution of this IPR suggests that there is a viable challenge to these claims based on obviousness, potentially leading to their invalidation. A defendant facing assertion of these claims should closely monitor this proceeding, as a Final Written Decision invalidating these claims would significantly weaken the patent owner's position.

Strategic summary

Currently, claims 1-20 of US9954872 have been successfully defended against one IPR petition (IPR2025-00068), which was denied institution on the merits. This indicates that the initial obviousness arguments presented by Unified Patents, LLC against these claims in that specific petition were found insufficient by the PTAB. However, the same claims (1-20) are simultaneously under active review in a separate IPR (IPR2025-00070), which was instituted. This means that while the patent owner has shown some ability to defend against challenges, the claims' patentability is still very much in question. No claims have been definitively canceled or sustained through a Final Written Decision yet.

The estoppel landscape is complex. For IPR2025-00068, since institution was denied, statutory estoppel under 35 U.S.C. § 315(e)(1) does not apply. However, for IPR2025-00070, if a Final Written Decision issues, Unified Patents, LLC (and its privies) would be estopped from asserting in district court or the ITC that claims 1-20 are invalid on any ground that was raised or reasonably could have been raised in that IPR. Given that Unified Patents, LLC filed both petitions, it indicates a strategic effort by a defensive aggregator to challenge the patent. The difference in institution outcomes between the two IPRs (denied vs. instituted, both filed on the same date) suggests that the PTAB found different levels of persuasiveness in the specific obviousness arguments and prior art combinations presented in each petition, even if the challenged claims were the same.

Recommended next steps

The most critical current event is the pending Final Written Decision for IPR2025-00070, which is due by 2026-04-16. This decision will determine the patentability of claims 1-20. A defendant facing assertion of US9954872 should:

  • Closely monitor IPR2025-00070 for the issuance of the Final Written Decision, which is expected by 2026-04-16. This decision will dictate the future viability of claims 1-20. You can track the progress and access filings via the PTAB End-to-End system by searching for IPR2025-00070.
  • If the FWD in IPR2025-00070 invalidates any claims, this will provide strong defensive leverage. The specific language of the Board's disposition and reasoning should be carefully reviewed.
  • Understand that while IPR2025-00068 was denied institution, the prior art grounds considered in that petition may still be available for a new defendant (not in privy with Unified Patents, LLC) to challenge in a separate IPR if they meet the institution thresholds. However, institution in IPR2025-00070 suggests there are indeed viable non-patentability arguments to be made against claims 1-20.

Generated 8/13/2026, 12:45:36 AM

Ownership chain (8)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2016-11-21 · reel 038914/0839 · Security Agreement

    COUNTERTACK, INC.PACIFIC WESTERN BANK

    Correspondent: John J. Penny, Jr. · Goodwin Procter

    securitization

  2. 2018-05-29 · reel 041793/0074 · Release

    PACIFIC WESTERN BANKCOUNTERTACK, INC.

    Correspondent: John J. Penny, Jr. · Goodwin Procter

  3. 2023-09-28 · reel 067425/0805 · Change of Name

    COUNTERTACK, INC.GOSECURE, INC.

    Correspondent: Patrick G. Reardon · Reardon

    change of name only

  4. 2023-12-13 · recorded 2024-01-26 · reel 068153/0732 · Assignment of Assignors Interest

    ANDREWS, DAVID, BECKER, BEN, CAPALIK, ALENNEURALIQ, INC.

    Correspondent: Michael J. Newman

    transfer-to-asserter

  5. 2023-12-13 · recorded 2024-01-26 · reel 068153/0733 · Change of Name

    COUNTERTACK, INC.GOSECURE, INC.

    Correspondent: Michael J. Newman

    change of name only

  6. 2023-12-13 · recorded 2024-01-26 · reel 068153/0734 · Change of Name

    NEURALIQ, INC.COUNTERTACK, INC.

    Correspondent: Michael J. Newman

    internal reorg

  7. 2025-02-06 · recorded 2025-02-14 · reel 070134/0413 · Security Agreement

    GOSECURE, INC.Comerica Bank

    Correspondent: Matthew S. Bloom

    securitization

  8. 2025-02-14 · reel 070134/0415 · Corrective Assignment

    GOSECURE, INC.Comerica Bank

    Correspondent: Matthew S. Bloom

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Alen Capalik
  • David Andrews
  • Ben Becker

The patent does not explicitly state the employer of the inventors at the time of filing. However, the original assignee is Countertack Inc. Google Patents lists Alen Capalik, David Andrews, and Ben Becker as inventors, and Countertack Inc as the original assignee.

Original assignee

The original assignee on the issued patent is Countertack Inc.

Countertack Inc. was a cybersecurity company focused on endpoint detection and response (EDR). They developed platforms to detect and respond to advanced threats. The company's primary line of business involved enterprise endpoint security. Countertack was acquired by GoSecure in 2019.

Assignment timeline

  • 2016-11-21 (executed) / recorded 2016-11-21 — Reel 038914/0839

    • Conveyance: Security Agreement
    • Assignor: COUNTERTACK INC.
    • Assignee: PACIFIC WESTERN BANK
    • Correspondent: John J. Penny, Jr., Goodwin Procter LLP, 53 State Street, Boston, MA 02109.
    • Context: Financing transaction, a security interest was granted to the bank.
  • 2018-05-29 (executed) / recorded 2018-05-29 — Reel 041793/0074

    • Conveyance: Release
    • Assignor: PACIFIC WESTERN BANK
    • Assignee: COUNTERTACK INC.
    • Correspondent: John J. Penny, Jr., Goodwin Procter LLP, 53 State Street, Boston, MA 02109. This correspondent recurs in this chain.
    • Context: Release of the security interest by the bank, returning full interest to Countertack Inc.
  • 2023-09-28 (executed) / recorded 2023-09-28 — Reel 067425/0805

    • Conveyance: Change of Name
    • Assignor: COUNTERTACK, INC.
    • Assignee: GOSECURE, INC.
    • Correspondent: Patrick G. Reardon, Reardon, 2300 M Street NW, Suite 800, Washington, DC 20037.
    • Context: Formal change of name from CounterTack, Inc. to GoSecure, Inc.
  • 2023-12-13 (executed) / recorded 2024-01-26 — Reel 068153/0732

    • Conveyance: Assignment of Assignors Interest
    • Assignor: ANDREWS, DAVID, BECKER, BEN, CAPALIK, ALEN
    • Assignee: NEURALIQ, INC.
    • Correspondent: Michael J. Newman, NEURALIQ, INC., 1735 N. Lynn Street, Suite 500, Arlington, VA 22209.
    • Context: Inventors assign their interest to NeuraLiq, Inc.
  • 2023-12-13 (executed) / recorded 2024-01-26 — Reel 068153/0733

    • Conveyance: Change of Name
    • Assignor: COUNTERTACK, INC.
    • Assignee: GOSECURE, INC.
    • Correspondent: Michael J. Newman, NEURALIQ, INC., 1735 N. Lynn Street, Suite 500, Arlington, VA 22209. This correspondent recurs in this chain.
    • Context: Another formal change of name from CounterTack, Inc. to GoSecure, Inc., recorded with NeuraLiq's correspondent.
  • 2023-12-13 (executed) / recorded 2024-01-26 — Reel 068153/0734

    • Conveyance: Change of Name
    • Assignor: NEURALIQ, INC.
    • Assignee: COUNTERTACK, INC.
    • Correspondent: Michael J. Newman, NEURALIQ, INC., 1735 N. Lynn Street, Suite 500, Arlington, VA 22209. This correspondent recurs in this chain.
    • Context: Change of name from NeuraLiq, Inc. to CounterTack, Inc. (potentially a reversion or renaming of an entity for a specific purpose).
  • 2025-02-06 (executed) / recorded 2025-02-14 — Reel 070134/0413

    • Conveyance: Security Agreement
    • Assignor: GOSECURE, INC.
    • Assignee: COMERICA BANK
    • Correspondent: Matthew S. Bloom, Comerica Bank, 1717 Main Street, 10th Floor, Dallas, TX 75201.
    • Context: Financing transaction, a security interest was granted to the bank.
  • 2025-02-14 (executed) / recorded 2025-02-14 — Reel 070134/0415

    • Conveyance: Corrective Assignment
    • Assignor: GOSECURE, INC.
    • Assignee: COMERICA BANK
    • Correspondent: Matthew S. Bloom, Comerica Bank, 1717 Main Street, 10th Floor, Dallas, TX 75201. This correspondent recurs in this chain.
    • Context: Corrective assignment to confirm security interest, referencing the prior recording.

Timeline diagram

timeline
    title Ownership of US 9954872
    2015 : Filed by Countertack Inc
    2016 : Security to Pacific Western Bank
    2018 : Granted; Security released to Countertack
    2023 : Countertack becomes GoSecure Inc
         : Inventors assign to NeuraLiq Inc
         : Countertack Inc becomes GoSecure Inc
         : NeuraLiq Inc becomes CounterTack Inc
    2025 : Security to Comerica Bank
         : Corrective Assignment to Comerica

NPE / troll-pattern signals

  1. Shell-entity transferUnclear. While entities like "NeuraLiq, Inc." and the subsequent renaming to "CounterTack, Inc." (after the original Countertack became GoSecure) could suggest shell entities, there is no direct evidence of them being licensing-only, having no products, or using a registered-agent address from the USPTO assignment records alone. The Google Patents page lists GoSecure Inc. as the current assignee.

  2. Known asserter in the chainNot present. None of the assignees (Countertack Inc., Pacific Western Bank, GoSecure Inc., NeuraLiq Inc., Comerica Bank) match known NPEs or asserters as per public lists.

  3. Repeat correspondent across the chainPresent.

    • John J. Penny, Jr. of Goodwin Procter LLP appears on the 2016-11-21 security agreement (Reel 038914/0839) and the 2018-05-29 release (Reel 041793/0074) for Countertack/Pacific Western Bank.
    • Michael J. Newman of NEURALIQ, INC. appears on three consecutive recordings dated 2023-12-13 (Reel 068153/0732, 068153/0733, 068153/0734) associated with the assignment from inventors to NeuraLiq, and subsequent name changes involving NeuraLiq and CounterTack, Inc.
    • Matthew S. Bloom of Comerica Bank appears on the 2025-02-06 security agreement (Reel 070134/0413) and the 2025-02-14 corrective assignment (Reel 070134/0415) for GoSecure/Comerica Bank.
      The recurrence of Michael J. Newman as correspondent for multiple interrelated transactions involving NeuraLiq Inc. is a notable pattern.
  4. Cascading transfersPresent. The three transfers dated 2023-12-13 (recorded 2024-01-26) involving the inventors assigning to NeuraLiq Inc., NeuraLiq changing its name to CounterTack Inc., and a "Change of Name" for Countertack Inc. to GoSecure, Inc. all executed on the same date and recorded on the same day, handled by the same correspondent (Michael J. Newman). This sequence of three assignments/name changes in a short period suggests a structured transfer or re-organization.

  5. Pre-litigation transferUnclear. The Google Patents legal events section indicates litigation was filed in the Texas Western District Court in 2024, and PTAB cases IPR2025-00068 and IPR2025-00070 were filed in 2025. The inventor assignment to NeuraLiq (2023-12-13) and the subsequent name changes predate the 2024 district court case, falling within a plausible pre-litigation window for the first suit. However, without knowing the exact filing date of the Texas Western District Court case, it's difficult to confirm if the 6-month window is met.

  6. Bankruptcy fire-saleNot present. There is no indication in the assignment records or Google Patents of Countertack Inc. or GoSecure Inc. undergoing bankruptcy proceedings leading to a patent sale. The security agreements with Pacific Western Bank and Comerica Bank are standard financing arrangements, not bankruptcy sales.

  7. PrivateeringUnclear. While GoSecure Inc. is an operating company, the assignment from inventors to NeuraLiq Inc., followed by NeuraLiq's name change to CounterTack Inc., and the subsequent recording of a CounterTack Inc. name change to GoSecure Inc. (all dated 2023-12-13) is a complex sequence. It's unclear what role NeuraLiq/CounterTack (the new entity) plays. Without more information on NeuraLiq/new CounterTack's business, it's hard to determine if this is a privateering arrangement.

  8. Defensive aggregator (anti-NPE)Not present. The current assignee is GoSecure Inc. or Comerica Bank (as a security interest holder). None of the entities are known defensive aggregators like RPX, AST, LOT Network, Unified Patents, or Open Invention Network.

Verdict

NPE — moderate confidence

The combination of the cascading transfers involving NeuraLiq, Inc. (Reel 068153/0732, 0733, 0734, all executed 2023-12-13) and the recurrence of the same correspondent (Michael J. Newman) for these complex transactions, raises a moderate confidence signal for NPE activity or a structured assertion play. The timing of these transfers just prior to the publicly listed litigation further supports this.

For verification, see the USPTO Assignment Center: https://assignmentcenter.uspto.gov/patent/9954872

Generated 8/13/2026, 12:45:39 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

As a technical patent analyst, I have identified the following as the most relevant prior art for US patent 9954872, "System and method for identifying unauthorized activities on a computer system using a data structure model," based on examiner and applicant citations and their relevance to the claims of US9954872. The priority date for US9954872 is June 24, 2010.

For each reference, I provide the full citation, publication/filing date, a brief description, and the claim(s) of US9954872 it potentially anticipates under 35 U.S.C. § 102. The assessment of potential anticipation is based on the abstracts and general disclosures of the cited references, without a detailed claim-by-claim comparison of their full specifications.

1. US8104085B2 - Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems

  • Full Citation: US8104085B2, "Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems".
  • Publication/Filing Date:
    • Filing Date: October 26, 2007.
    • Issue Date: January 24, 2012.
    • Claims priority to U.S. Provisional Patent Application Ser. No. 60/802,543 filed May 22, 2006.
  • Brief Description: This patent describes a system and method for analyzing unauthorized intrusion into a computer network. It includes a decoy network device that uses a virtualized operating system to present an authentic fingerprint to attackers. An introspection module on the decoy device monitors and captures information from connections initiated by attackers. This captured information is then used to generate an attack signature, which is transmitted to a network security application on a protected network to prevent future attacks.
  • Potential Anticipation of Claims in US9954872: US8104085B2 is highly relevant as it explicitly discloses key elements found in US9954872's independent claims (Claim 1 and Claim 11). Specifically:
    • The "virtualized operating system" and "introspection module" directly correspond to "monitoring activity on a virtual machine by a virtual machine monitor" (Claim 1 and 11).
    • The "captures information from a connection, including port numbers, data streams, file uploads, keystrokes, ASCII or binary files, malicious payloads, memory manipulation attempts, and any other data transfers or malicious attempts" can be interpreted as identifying "a plurality of activities being performed at the virtual machine" which could infer an "activity source, an activity target, and an association." A detailed analysis of the full text would determine if the structured storage of such activities is explicitly taught.
    • The use of "captured information is used to generate a signature of attack" directly anticipates "creating a fingerprint indicative of the activity on the virtual machine from the stored activities" (Claim 1 and 11).
    • The "transmitted to a network security application on the protected network" anticipates "transmitting the fingerprint to one or more other computer systems on a network to prevent future attacks" (Claim 1 and 11).
    • Given these close parallels, US8104085B2 potentially anticipates claims 1, 11, and dependent claims of US9954872 that cover the fundamental concepts of monitoring virtual decoys, generating signatures from observed malicious activity, and using those signatures for broader network protection.

2. US20070266436A1 - Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems

  • Full Citation: US20070266436A1, "Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems".
  • Publication/Filing Date:
    • Filing Date: July 17, 2006.
    • Publication Date: November 15, 2007.
  • Brief Description: The abstract of US20070266436A1 is identical to that of US8104085B2. This application is the earlier published version of the same underlying invention that later granted as US8104085B2, and therefore provides an earlier prior art date as a printed publication.
  • Potential Anticipation of Claims in US9954872: Due to the identical abstract and shared subject matter with US8104085B2, US20070266436A1 carries the same strong potential to anticipate claims 1, 11, and related dependent claims of US9954872. Its earlier publication date strengthens its position as prior art.

3. US8225390B2 - System and method for analyzing unauthorized intrusion into a computer network

  • Full Citation: US8225390B2, "System and method for analyzing unauthorized intrusion into a computer network".
  • Publication/Filing Date:
    • Filing Date: September 16, 2008.
    • Issue Date: July 17, 2012.
  • Brief Description: This patent discloses a computer-implemented method for analyzing unauthorized intrusions. It involves monitoring activity on a decoy computer system to collect unauthorized activity data (forensic data). This data is analyzed to generate a signature of the unauthorized activities, which is then transmitted to other computer systems on the network to prevent future unauthorized activities.
  • Potential Anticipation of Claims in US9954872: US8225390B2 broadly anticipates the general methodology of US9954872.
    • "Monitoring activity on a decoy computer system" broadly covers "monitoring activity on a virtual machine by a virtual machine monitor" (Claim 1 and 11), assuming a virtual machine can be considered a type of decoy computer system.
    • "Collecting unauthorized activity data" and "analyzing the collected forensic data to generate a signature" are analogous to "identifying a plurality of activities," "storing the activity sources, activity targets, and associations," and "creating a fingerprint" (Claim 1 and 11). The specificity of US9954872's data structure ("activity source, activity target, and association") would be a key point of distinction.
    • "Transmitted to a plurality of computer systems on the computer network to prevent future unauthorized activities" directly anticipates the transmission aspect of US9954872's claims.
    • Therefore, US8225390B2 potentially anticipates claims 1, 11, and related dependent claims of US9954872, particularly for the high-level process of using decoy systems to generate and distribute attack signatures.

4. US8127370B2 - System and method for analyzing unauthorized intrusion into a computer network

  • Full Citation: US8127370B2, "System and method for analyzing unauthorized intrusion into a computer network".
  • Publication/Filing Date:
    • Filing Date: April 20, 2007.
    • Issue Date: February 28, 2012.
  • Brief Description: The abstract of US8127370B2 is identical to that of US8225390B2. This indicates they are likely related applications (e.g., continuations or divisionals) covering similar subject matter.
  • Potential Anticipation of Claims in US9954872: Given the identical abstract and shared subject matter with US8225390B2, US8127370B2 presents the same potential to anticipate claims 1, 11, and related dependent claims of US9954872, particularly concerning the general method of using decoy systems for intrusion analysis and signature generation.

5. US20080098495A1 - System and method for analyzing unauthorized intrusion into a computer network

  • Full Citation: US20080098495A1, "System and method for analyzing unauthorized intrusion into a computer network".
  • Publication/Filing Date:
    • Filing Date: April 20, 2007.
    • Publication Date: April 24, 2008.
  • Brief Description: The abstract of US20080098495A1 is identical to that of US8225390B2 and US8127370B2. This published application is an earlier public disclosure of the same underlying invention that later granted as US8127370B2. Its publication date makes it prior art as a printed publication.
  • Potential Anticipation of Claims in US9954872: As with US8225390B2 and US8127370B2, this published application broadly anticipates claims 1, 11, and related dependent claims of US9954872 regarding the use of decoy systems, forensic data collection, signature generation, and transmission for attack prevention. Its earlier publication date makes it significant prior art.

Generated 8/13/2026, 12:46:14 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Under 35 U.S.C. § 103, an invention is considered obvious if the differences between the claimed invention and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art (PHOSITA).

The independent claims of US9954872 (Claims 1, 8, and 15) essentially describe a system and method for identifying unauthorized activities by:

  1. Monitoring activity on a virtual machine.
  2. Identifying a plurality of activities, each including an activity source, an activity target, and an association between them.
  3. Storing these detailed activity sources, targets, and associations in memory.
  4. Creating a fingerprint indicative of the activity on the virtual machine from the stored activities.
  5. Transmitting the fingerprint to one or more other computer systems on the network to prevent future attacks that comprise the same or similar activities.

Based on the "RELATED APPLICATIONS" section within US9954872, the following prior art references are relevant:

  • U.S. patent application Ser. No. 11/488,743, entitled “Decoy Network Technology With Automatic Signature Generation for Intrusion Detection and Intrusion Prevention Systems,” filed on Jul. 17, 2006 (hereinafter '743 application).
  • U.S. patent application Ser. No. 13/163,590, entitled “System and Method for Identifying Unauthorized Activities on a Computer System Using a Data Structure Model,” filed Jun. 17, 2011 (hereinafter '590 application). US9954872 is a continuation application of this '590 application.

Combination of Prior Art References for Obviousness

A strong combination of prior art references that would render the claims of US9954872 obvious is the '743 application in view of the '590 application.

1. The '743 application (US11/488,743)
The '743 application discloses a foundational concept for US9954872, namely "Decoy Network Technology With Automatic Signature Generation for Intrusion Detection and Intrusion Prevention Systems." [cite: "This application relates to U.S. patent application Ser. No. 11/788,795, entitled “System and Method for Analyzing Unauthorized Intrusion into a Computer Network,” filed on Apr. 20, 2007, which is a continuation-in-part of U.S. patent application Ser. No. 11/488,743, entitled “Decoy Network Technology With Automatic Signature Generation for Intrusion Detection and Intrusion Prevention Systems,” filed on Jul. 17, 2006, which claims priority to U.S. Provisional Patent Application Ser. No. 60/802,543, filed May 22, 2006, all of which are incorporated herein by reference in their entireties."]
This reference would teach:

  • A computer system with processors and memory configured for network security.
  • The use of a "decoy network" (honeypot) to attract and capture intrusion attempts.
  • Monitoring activities on the decoy system.
  • Automatically generating "intrusion signatures" from the captured intrusion attempts.
  • Transmitting these signatures to an intrusion detection and prevention system (IDS/IPS) to prevent future attacks. The '872 patent itself notes that "The IDS/IPS system 142 uses the attack signature to identify and prevent subsequent attacks." [cite: "The IDS/IPS system 142 uses the attack signature to identify and prevent subsequent attacks."] and "The IDS/IPS system 142 identifies unauthorized activities based on the fingerprints stored in the fingerprint library, and provides notification to a user or a system administrator, and/or prevents unauthorized activities matching the stored fingerprints by modifying the protected network devices 136 and/or the firewall/router 198." [cite: "The IDS/IPS system 142 identifies unauthorized activities based on the fingerprints stored in the fingerprint library, and provides notification to a user or a system administrator, and/or prevents unauthorized activities matching the stored fingerprints by modifying the protected network devices 136 and/or the firewall/router 198."]

2. The '590 application (US13/163,590)
The '590 application is the direct parent application of US9954872. As such, it is expected to disclose, in detail, the core methodology claimed in US9954872. The title, "System and Method for Identifying Unauthorized Activities on a Computer System Using a Data Structure Model," is highly indicative of the specific technical elements. US9954872's own summary and detailed description clarify these elements:

  • Monitoring activity on a virtual machine. The '872 patent states, "The method includes monitoring activity on the virtual machine." [cite: "some embodiments involve a computer-implemented method ... The method includes monitoring activity on the virtual machine."] It also describes a "decoy network device 106" that includes "virtual machines 216" and "virtualized decoy operating systems 112." [cite: "The memory 206 stores a virtual machine, a virtual machine monitor supervising the virtual machine, and one or more programs.", "The memory 206 or the computer readable storage medium of the memory 206 stores one or more of the following programs: ... a virtual machine monitor 214 (also called a hypervisor); virtual machines 216 , including virtual machine 1 ( 113 - 1 ) and (optional) virtual machine 2 ( 113 - 2 ); and normal hypervisor OS user processes (e.g., 114 - 1 and 114 - 2 )".]
  • Identifying activities, each with an activity source, an activity target, and an association. The '872 patent states, "A plurality of activities performed at a virtual machine is identified. Each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target." [cite: "A plurality of activities performed at a virtual machine is identified. Each of the activities includes an activity source, an activity target, and an association between the activity source and the activity target."] FIG. 5A further illustrates "unauthorized activity data 502" containing "unauthorized activity entries 505" with fields for "activity source 512," "activity target 514," and "action 515," representing the association.
  • Storing the activity sources, activity targets, and associations in memory. The '872 patent states, "The activity sources, activity targets, and associations are stored in the memory." [cite: "The activity sources, activity targets, and associations are stored in the memory."]
  • Creating a fingerprint indicative of the activity on the virtual machine from the stored activities. The '872 patent states, "A fingerprint indicative of the activity on the virtual machine is created from the stored activities." [cite: "A fingerprint indicative of the activity on the virtual machine is created from the stored activities."] FIGS. 5B and 5C show "exemplary data structure of fingerprint 580" derived from such activities.

Motivation to Combine

A person having ordinary skill in the art (PHOSITA) in the field of computer network security, seeking to enhance the effectiveness of automated intrusion signature generation systems, would have been motivated to combine the teachings of the '743 application and the '590 application.

  1. Improving Signature Quality for Zero-Day Attacks: The '743 application provides the framework for using decoy networks to generate signatures for IDS/IPS. However, traditional signature generation methods often struggle with "zero-day attacks" where patterns are unknown. The '872 patent explicitly identifies this problem: "A critical threat to computer networks is the so-called zero-day attack... Because the security vulnerabilities are unknown... often the fingerprints of such zero-day attacks are unavailable for comparison." [cite: "A critical threat to computer networks is the so-called zero-day attack that exploits security vulnerabilities previously unknown to software developers or system operators. Because the security vulnerabilities are unknown to the software developers or system operators, often the fingerprints of such zero-day attacks are unavailable for comparison."] The '590 application's detailed data structure model, which captures fine-grained "activity sources, activity targets, and associations," directly addresses this by enabling the creation of more comprehensive and precise "fingerprints" from observed malicious activity, rather than relying on pre-determined ones. The '872 patent confirms, "These embodiments identify unauthorized activities by monitoring and identifying associations between activity sources and activity targets without using pre-determined fingerprints. The data collected by these embodiments can be used to generate fingerprint data in response to the zero-day attacks." [cite: "These embodiments identify unauthorized activities by monitoring and identifying associations between activity sources and activity targets without using pre-determined fingerprints. The data collected by these embodiments can be used to generate fingerprint data in response to the zero-day attacks."]. A PHOSITA would be motivated to adopt such a detailed monitoring and fingerprinting approach to improve detection and prevention against novel threats.

  2. Leveraging Virtualization Benefits for Decoy Systems: The '743 application describes decoy systems generally. The '590 application (and by extension, US9954872) specifically applies the detailed monitoring to a "virtual machine." The use of virtual machines for honeypots was a known practice in the art at the time, offering advantages like isolation from production systems, ease of deployment and resetting, and the ability to mimic various operating system environments realistically to lure attackers. The '872 patent itself notes the realism virtualized decoys provide: "When the attacker connects to a virtualized decoy operating system 112 through an open port, the attacker sees a fully-functional standard operating system fingerprint." [cite: "When the attacker connects to a virtualized decoy operating system 112 through an open port, the attacker sees a fully-functional standard operating system fingerprint."]. Thus, a PHOSITA would find it obvious to apply the detailed activity monitoring of the '590 application within a virtualized decoy environment as taught by the '743 application, to maximize the benefits of both technologies for more effective security.

Therefore, combining the general framework of automated signature generation using a decoy network from the '743 application with the specific, granular activity monitoring and data structure modeling on a virtual machine for fingerprint creation described in the '590 application would have been an obvious step for a PHOSITA striving to produce more robust and adaptable intrusion prevention signatures, especially for previously unknown attacks.

Generated 8/13/2026, 12:46:07 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by CrowdStrike, Inc.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 9954872.