Invalidity dossier

US 11726809

Techniques for securing virtual machines by application existence analysis

Current assignee: Wiz, Inc.

Added 9/29/2026, 10:12:12 AM

At a glanceNo PTAB challenges2 lawsuits on fileasserted by Wiz, Inc.Software Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative information on US patent 11726809.

Let me check for Federal Circuit (CAFC) activity and the PTAB proceeding.

Let me verify the post-settlement and any Federal Circuit activity.

Summary: US Patent No. 11,726,809 B2

Important caveat on method: I could not query the USPTO PatentCenter or the CAFC docket system directly — I ran live web searches. Everything below is grounded in the sources cited, and I flag anywhere I do not have authoritative confirmation.

Bibliographic data

Field Value
Patent number US 11,726,809 B2
Title "Techniques for securing virtual machines by application existence analysis"
Application no. 18/055,201
Filing date 2022-11-14
Issue (grant) date 2023-08-15
Pre-grant pub. US 2023/0093527 A1 (2023-03-23)
Inventor Avi Shua (sole inventor)
Assignee Orca Security Ltd. (Tel Aviv, IL)
Priority date 2019-01-28 (provisional 62/797,718)
Anticipated expiration 2039-09-27 (per Google Patents legal-status field)
Claims 23 total; independent claims 1 (method), 16 (non-transitory CRM), 19 (system)

Continuity chain: The '809 patent is a continuation of Ser. No. 17/330,998 (now US 11,516,231), filed 2021-05-26, which is a continuation of Ser. No. 16/585,967 (now US 11,431,735), filed 2019-09-27, which claims benefit of provisional 62/797,718 filed 2019-01-28. It is part of a 13-member Orca family (family ID 71731840) that also includes the '031, '032, '685, '926, and '326 patents.

Note: Google Patents' "prior art date" field lists 2019-01-28, consistent with the provisional. The examiner of record per the NDLI record appears as "Joseph P Hirl / Hassan Saadoun."

Abstract (as granted)

A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.

Note that the grant abstract is inherited from the parent specification and does not recite the "application existence analysis" / matching language that the '809 claims add.

Plain-language overview of the independent claims

Claim 1 (method). Steps:

  1. Determine, using an API or service provided by the cloud computing environment, the location of a snapshot of at least one virtual disk of a protected virtual cloud asset (e.g., a VM, container, micro-service, or serverless function) that is instantiated in the cloud.
  2. Access that snapshot based on the determined location, again using a cloud-provider API or service.
  3. Analyze the snapshot by matching installed applications against applications on a known list of vulnerable applications (this "application existence" matching is the distinguishing feature versus the parent patents).
  4. From that matching, determine the existence of a plurality of potential cyber vulnerabilities.
  5. Correlate those vulnerabilities with the asset's network location.
  6. Use the vulnerabilities plus the network location to determine a risk of the asset to the cloud environment.
  7. Prioritize the vulnerabilities by that determined risk.
  8. Report them as alerts prioritized by the determined risk.

Claim 16 (non-transitory computer readable medium). Parallel claim covering the same eight operations, with claim 16's matching step phrased as analyzing the snapshot "by matching installed applications with applications on a known list of vulnerable applications."

Claim 19 (system). Parallel claim directed to at least one processor configured to perform the same operations. I note from the Google Patents text that claim 19's sixth limitation reads "use the determined plurality of potential cyber vulnerabilities network location of the protected virtual cloud asset to determine a risk..." — i.e., there appears to be a typographical omission of "and the" in that limitation as published; I'm reporting this literally rather than correcting it.

Representative dependent claims of note: claim 6 (direct binary comparison of application files); claim 7 (cryptographic-hash matching against a database of files in vulnerable applications); claims 8–9 (parsing/scanning the snapshot; checking configuration files, file access times, and system logs); claim 3 (filtering so fewer alerts are reported than vulnerabilities found); claim 4 (external intelligence on exploit likelihood); claim 13–14 (using a cloud API to take or request a snapshot, then obtaining its location); claim 15 (querying a cloud management console); claim 23 (copying the snapshot and analyzing the copy).

The disclosed technique is agentless: the specification states the detection is performed "without using any agent installed in the server 115 or the VM 119, and without relying on cooperation from VM 119 guest OS." Orca markets this as SideScanning™.

Litigation and PTAB status

  • District court: Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del.) (JLH/SRF). Filed 2023-07-12. The '809 patent was one of six asserted Orca patents (the '031, '032, '685, '809, '926, and '326). The court stayed the case on 2025-01-16 pending the IPRs.
  • PTAB: Wiz petitioned for IPR on the '809 patent on 2024-07-01 — IPR2024-01109. Wiz filed a Sotera-style stipulation (D.I. 194) promising not to pursue in district court the same grounds it advanced in the IPR. The PTAB instituted. Oral hearing for IPR2024-01109 (with IPR2024-01190 and IPR2024-01191) was held 2025-10-14 before APJs Zecher, Galligan, and Baer. The statutory FWD deadline was 2026-01-16. The Google Patents record for US 11,726,809 flags IPR2024-01109 as "filed (Settlement)," and the parties filed a joint motion to terminate IPR2024-01190 (the '926 patent) on settlement grounds on 2026-01-07 (Ex. 2429 confidential settlement agreement). I did not find a public PTAB document specifically terminating IPR2024-01109, so I cannot state with certainty that the '809 IPR itself was terminated rather than decided — the settlement flag is my best available evidence, and it is consistent with the district court dismissal.
  • Related ORCA patents invalidated: In IPR2024-00863/00864/00865, the PTAB issued Final Written Decisions on 2025-12-08 holding all claims of the '031, '032, and '685 patents unpatentable. Orca's deadline to seek rehearing/Director review was 2026-01-07; the deadline to file a Notice of Appeal to the Federal Circuit was 2026-02-09 (per the parties' Joint Notice, D.I. 235). Those FWDs are the reason the '809's sibling patents may (or may not) surface at the CAFC.
  • Case ended: The parties filed a Stipulation of Dismissal (D.I. 237/238) dismissing all claims and counterclaims with prejudice, with each side bearing its own costs and fees. It was SO ORDERED on 2026-01-13.

CAFC 2026 dockets — explicit uncertainty

I found no Federal Circuit docket or appeal involving US 11,726,809. This is consistent with the record: the '809 patent's district court claims were dismissed with prejudice on 2026-01-13, and the IPR appears to have settled. The only live CAFC-appeal window I identified concerns the different patents ('031/'032/'685), whose Notice-of-Appeal deadline was 2026-02-09. I could not confirm whether Orca actually filed that appeal — my searches did not surface a CAFC docket number, and I will not guess at one. If you need certainty on CAFC activity, it should be verified directly in the Federal Circuit's PACER/CM-ECF docket or the USPTO PatentCenter for the specific appeal.

I have not auto-corrected any identifiers; all numbers above are reproduced exactly as they appear in the sources.

Generated 9/29/2026, 10:22:37 AM

Cases on file (2)

Group view →

Specific litigation cases in our database that name US patent 11726809. The free-form analysis below may also discuss cases beyond this list.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll research litigation involving US 11,726,809. Let me search multiple sources.

Found the lead case. Let me dig deeper into the PTAB proceeding, the case status, and any other suits.

Let me confirm the IPR2024-01109 outcome and check for any other suits involving this patent.

Litigation involving U.S. Patent No. 11,726,809 ("the '809 patent")

Summary: I found one district-court action and one PTAB post-grant proceeding in which the '809 patent was at issue. Both were between the same two parties (Orca Security Ltd. and Wiz, Inc.) and both were resolved by settlement/dismissal in January 2026. I found no CAFC appeal, no ITC investigation, and no other lawsuits asserting the '809 patent.

Interpretation note: I am treating the identifiers literally as given (U.S. Patent No. 11,726,809; case 1:23-cv-00758; IPR2024-01109). I did not find any record tying the '809 patent to a similarly numbered case or patent.


1. Orca Security Ltd. v. Wiz, Inc. — D. Del.

Field Detail
Plaintiff / Counterclaim-defendant Orca Security Ltd.
Defendant / Counterclaim-plaintiff Wiz, Inc.
Jurisdiction / Court [U.S. District Court for the District of Delaware (Wilmington Division)](/courts/district-of-delaware-wilmington); Judges Jennifer L. Hall (presiding) and Sherry R. Fallon (magistrate)
Case number 1:23-cv-00758-JLH-SRF (C.A. No. 23-758 (JLH)(SRF))
Cause of action 35 U.S.C. § 271 — patent infringement
Filing date July 12, 2023
Outcome / status Dismissed with prejudice — stipulation filed Jan. 6, 2026; "SO ORDERED" and case terminated Jan. 13, 2026. Each side bore its own costs and fees.
Asserted patents 11,374,982; 11,431,735; 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926; 11,775,326; 6,721,803

Sources:

Procedural history relevant to the '809 patent:

I note that Wiz's affirmative patent claims against Orca appear, per the docket, to have been asserted as counterclaims within the same case (1:23-cv-00758) — the docket lists "Counter Claimant: Wiz, Inc." I did not verify a separate Wiz-initiated district court complaint, so I will not represent that a separate "Wiz v. Orca" district court action exists.


2. Wiz, Inc. v. Orca Security Ltd. — PTAB (IPR2024-01109) — '809 patent

Field Detail
Petitioner Wiz, Inc.
Patent Owner Orca Security Ltd.
Forum U.S. Patent and Trademark Office, Patent Trial and Appeal Board
Case number IPR2024-01109
Patent challenged U.S. Patent No. 11,726,809
Petition filing date July 1, 2024
Status Terminated/associated with settlement (see caveat below)

Sources:

Caveat / open question — I want to flag this rather than overstate it: The sources I found do not let me state with high confidence the exact final disposition of IPR2024-01109 as to the '809 patent. What is clear: the petition was filed July 1, 2024; the PTAB instituted review (the district court's Jan. 14, 2025 stay order referenced three of six IPR petitions already instituted, with three institution decisions pending); and the proceeding was briefed through an October 14, 2025 consolidated oral argument with IPR2024-01190 and IPR2024-01191. Google Patents labels the case "(Settlement)." Separately, a joint motion to terminate IPR2024-01190 (a different patent, 11,740,926) was filed Jan. 7, 2026 on the basis that the parties had settled and no final written decision had issued in that proceeding (source: https://www.docketalarm.com/cases/PTAB/IPR2024-01190/.../Motion__Motion_to_terminate_due_to_settlement_post_DI-85...). News reporting states the PTAB on Dec. 8, 2025 held all challenged claims in certain of Orca's asserted patents unpatentable, while other reviews remained pending (source: https://www.bankinfosecurity.asia/orca-wiz-end-dueling-lawsuits-over-cloud-security-patents-a-30463). I could not conclusively match those Dec. 8, 2025 decisions to the '809 patent, and I could not retrieve a final written decision or termination order specifically in IPR2024-01109. Treat the '809 IPR's precise terminal outcome as unconfirmed.


3. Related activity that does NOT involve the '809 patent

  • Orca Security Ltd. v. Wiz, Inc., IPR2025-01087 (PTAB) — an IPR filed by Orca on June 4, 2025 against Wiz, terminated Jan. 14, 2026 following settlement. This concerns Wiz's patents, not the '809 patent. Source: https://www.docketalarm.com/cases/PTAB/IPR2025-01087/Orca_Security_Ltd._v._Wiz_Inc/
  • The several other Orca-Wiz IPRs (e.g., IPR2024-00863 on U.S. 11,663,031; IPR2024-01190 on U.S. 11,740,926; IPR2024-01191) are part of the same dispute but are directed to different patents in the family.
  • Google Patents also flags a "US case filed in Delaware District Court" and a Darts-IP link for "First worldwide family litigation filed" for family ID 71731840 — both corresponding to the Delaware action above.

Bottom line on the '809 patent

  • One known district court case: Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del., filed July 12, 2023), in which U.S. 11,726,809 was one of the asserted patents; dismissed with prejudice on Jan. 13, 2026 after the case had been stayed pending IPR.
  • One known PTAB proceeding: IPR2024-01109, Wiz, Inc. v. Orca Security Ltd. (filed July 1, 2024), challenging the '809 patent; per the Google Patents record the case is associated with settlement, though I could not independently confirm a final written decision or a termination order specific to this docket.
  • No other litigation (no other defendants, other jurisdictions, ITC, or CAFC appeal) involving the '809 patent was found. This is a negative finding based on the sources searched (Google Patents, Docket Alarm, CourtListener/RECAP, PTAB dockets, and trade press); I cannot rule out a very recent filing or a sealed proceeding that does not appear in those sources.

Generated 9/29/2026, 10:22:51 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Wiz, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

I'll start by searching for the PTAB proceeding flagged on the patent's Google Patents page (IPR2024-01109) and any others involving Orca Security's US 11,726,809.

Let me dig into the outcome of IPR2024-01109 and the related Wiz IPRs.

Let me search for the institution decision, final written decision, and any settlement in IPR2024-01109.

Important threshold note on the source data

The structured "PTAB proceedings on file" block (USPTO Open Data Portal) returns zero AIA trial proceedings for US 11,726,809. Taken literally, the canonical answer is "no PTAB activity on file."

However, that conflicts with two independent sources surfaced by search, and I am flagging the conflict rather than suppressing it:

  1. The Google Patents page for this patent itself carries a litigation entry: "PTAB case IPR2024-01109 filed (Settlement)", with a Unified Patents PTAB Data link and an empty "Petitioner:" field.
  2. D. Del. filings and PTAB documents confirm a real, docketed proceeding: IPR2024-01109, Wiz, Inc. v. Orca Security Ltd., on this exact patent, petition filed 2024-07-01, tried through an oral hearing on 2025-10-14.

So the ODP ingest is incomplete/stale here. I report the proceeding below, marked as web-sourced, and I do not invent anything the record doesn't support.


Proceedings overview

Count: 0 proceedings in the canonical ODP structured list; 1 proceeding confirmed via web search and cross-corroborated by the patent's own Google Patents litigation block and by docketed PTAB/district-court papers. Status breakdown for the one identified proceeding: instituted, argued at oral hearing, disposition not confirmed — the only status tag I can point to is the structured-data gloss "(Settlement)," which I could not independently verify and which is in tension with the fact that a merits hearing was held.

Bottom-line defensive posture: this is not a "patent survived two IPRs and is hardened" fact pattern, and it is not a "claim 1 is dead" fact pattern. It is a single, fully-litigated-through-hearing IPR by a single commercial rival (Wiz), whose final disposition I cannot confirm. No claims of US 11,726,809 are confirmed canceled by any decision I can cite. A defendant today should assume all claims 1–23 are live and unadjudicated at the Board, and should independently verify the case status on PTAB E2E before relying on anything.


IPR2024-01109 — Wiz, Inc. v. Orca Security Ltd.

  • Type: Inter Partes Review (35 U.S.C. §§ 311–319)
  • Filed: 2024-07-01 (accorded filing date per PTAB notice dated 2024-07-18; district-court notice states "On July 1, 2024, Wiz filed an IPR petition challenging all claims of a fourth Asserted Patent: the '809 patent. See IPR2024-01109 at Paper 2.")
  • Patent: U.S. Patent No. 11,726,809 B2 ("the '809 patent"); priority 2019-01-28
  • Status: Structured data (Google Patents / Unified Patents PTAB Data) states verbatim "PTAB case IPR2024-01109 filed (Settlement)". Gloss and caveat: the "(Settlement)" tag suggests termination by party settlement rather than by Final Written Decision, but an oral hearing on the merits was actually held on 2025-10-14, and I could not locate a termination order, a settlement date, or terms. Treat the disposition as unconfirmed.
  • Judge panel: For the 2025-10-14 oral hearing (jointly for IPR2024-01109, -01190, -01191): Administrative Patent Judges Michael R. Zecher, Daniel J. Galligan, and Garth D. Baer (Judge Baer presiding). For the earlier 2025-03-28 additional-discovery order covering the six Wiz/Orca IPRs: APJs Zecher, Baer, and Scott Raevsky, opinion by Baer with a dissent by Zecher.
  • Petition grounds: Obviousness only (§ 103), against all claims 1–23, per the Patent Owner's expert declaration summarizing the petition:
    • Ground 1: claims 1–10 and 12–23 obvious over Veselov + Mohanty
    • Ground 2: claims 1–10 and 12–23 obvious over Veselov + Mohanty + Czarny
    • Ground 3: claim 11 obvious over Veselov + Mohanty + Hutchins
    • Ground 4: claim 11 obvious over Veselov + Mohanty + Czarny + Hutchins
    • Primary reference "Veselov" is U.S. Patent No. 11,216,563 (Amazon-assigned, filed 2017-05-19). Petitioner's expert: Dr. Angelos Stavrou. Patent Owner's expert: Dr. David R. Kaeli (Ex. 2001).
    • Note: the petition's theory is that Veselov discloses the same "agentless" snapshot-analysis approach Orca claims. Orca's POPR distinguished "analyzing a snapshot" from "analyzing a VM instantiated from a snapshot," and Wiz has since argued those POPR constructions contradicted Orca's positions in the Delaware case.
  • Institution decision: Instituted. The exact decision date and reasoning are not in the sources I retrieved. Timeline anchors: district-court notice states "An institution decision is expected by January 1, 2025"; a D. Del. letter dated 2025-01-13 refers to "half of Wiz's IPRs [having] been instituted" (those were the '031/'032/'685 IPRs, IPR2024-00863/-00864/-00865, instituted December 2024), with institution decisions on the '809, '926, and '326 petitions expected "by mid-February" 2025. Petitioner's expert deposition (covering the '809, '926, and '326 institution decisions) confirms those decisions issued and were reviewed. I could not retrieve the '809 institution paper itself — do not treat the January-vs-February date as verified.
  • Final Written Decision: None located. I can state with confidence only that no FWD appears in the searchable record available to me. I therefore cannot report which claims (if any) were canceled, which survived, or any panel reasoning at the claim level. Any claim-level outcome statement would be fabricated, so I make none.
  • Settlement / termination: The structured data's "(Settlement)" tag is the only signal. If a settlement occurred, it came after the 2025-10-14 merits hearing, and terms would ordinarily be confidential. Not verified; no date, no terms.
  • Key procedural event worth knowing: On 2025-03-28 the Board granted Orca's motion for additional discovery (37 C.F.R. § 42.51(b)(2)), compelling Wiz to produce 226 internal documents already produced as "CONFIDENTIAL – ATTORNEYS' EYES ONLY" in the Delaware case, for Orca to argue objective indicia (copying, industry praise, commercial success of its SideScanning™ technology). Judge Zecher dissented. This is a notable pro-patent-owner discovery ruling that the panel applied across all six Wiz/Orca IPRs, and it shows Orca was building a serious secondary-considerations record heading into the hearing.
  • Parallel litigation / estoppel triggers: Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758-JLH-SRF (D. Del.), asserting six patents including the '809 patent. Wiz filed a stipulation concerning invalidity grounds on 2024-11-06 (D.I. 194): if the '809 IPR were instituted, Wiz would not pursue in Delaware "the specific grounds advanced in the instituted IPR or any ground that reasonably could have been raised in an IPR (i.e., any ground that could be raised under §§ 102 or 103 … only on the basis of prior art patents or printed publications)." The case was thereafter stayed pending the IPRs (Pet. Ex. 1112, "Delaware Litigation Stay Order").
  • Appeal: None identified. No Federal Circuit appeal docket found. Note the logical constraint: a § 315(e) statutory estoppel (and thus the typical trigger for an appeal) requires a Final Written Decision — so if this case ended in settlement rather than FWD, there would be nothing to appeal.

Defensive value (with the honesty caveat front and center): Because the disposition is unconfirmed, a defendant should not plan an invalidity theory around this proceeding. If it settled pre-FWD, no claim was canceled and no § 315(e)(2) estoppel attached to Wiz, meaning the entire Veselov/Mohanty/Czarny/Hutchins art set — plus everything else in Wiz's Delaware invalidity contentions — remains available against the '809 patent in district court and in a fresh IPR. Conversely, if an FWD did issue, its result is the single most important document on this patent and must be pulled immediately. Either way, the only reliable defensive asset here is the public record of Wiz's prior art, not any Board holding.


Strategic summary

Claim status: all claims 1–23 are UNTESTED at the Board as far as the public record I can verify shows. No claim of US 11,726,809 is confirmed canceled; none is confirmed sustained. The petition drew a comprehensive challenge (all 23 claims) and was instituted, so there is no carve-out of unchallenged claims to fall back on — the asserted independent claims (1, 16, 19) and every dependent claim were all in play. Correlate this with the fact that the sibling patents in the same family were challenged in parallel IPRs (IPR2024-00863/-00864/-00865 on the '031/'032/'685 patents, instituted December 2024; IPR2024-01190/-01191 on the '926/'326 patents), all six argued at the same October 2025 hearing slot, and all with the same 2019-01-28 priority. The family-wide attack matters because the six asserted patents share a specification (per the Delaware joint claim construction brief, the '031 patent has extra specification content; the rest share a common spec), so claim-construction positions Orca took in one IPR — e.g., distinguishing "analyzing a snapshot" from "analyzing a VM instantiated from a snapshot," and distinguishing "reporting results" from "reporting … as alerts" — are usable against it across the family.

Estoppel landscape. Statutory estoppel under § 315(e)(2) attaches only upon a Final Written Decision and runs against the petitioner, its real parties in interest, and privies. On the record I can verify, no FWD is confirmed on the '809 patent, so no § 315(e)(2) estoppel is confirmed either. What does bind Wiz is a contractual stipulation (D.I. 194, filed 2024-11-06) — a narrower, self-imposed bar scoped to the instituted grounds and to § 102/§ 103 art made of "prior art patents or printed publications," expressly not reaching "any other ground regardless of whether the IPR is instituted" (which preserves, e.g., § 112 and public-use/system-art theories). For a defendant that is not Wiz and not a Wiz privy, neither the statutory nor the contractual bar applies: the full prior-art universe — Veselov (U.S. 11,216,563), Mohanty, Czarny, Hutchins, and the entire Appendix D/D-1 invalidity chart from Wiz's 2024-06-07 contentions — remains fair game, subject only to your own § 315(b) one-year clock and the Board's § 325(d) discretion. That is the key asymmetry to exploit.

Pattern signals. The same petitioner, Wiz, Inc., filed six IPRs against six different Orca patents in a single coordinated campaign (three on 2024-05-24, three on 2024-07-01), all stemming from Orca's 2023-07-12 Delaware complaint — this is a defendant using the PTAB as the primary invalidity vehicle while the district case is stayed, not a defensive aggregator. Unified Patents is not the petitioner; the Google Patents page links Unified Patents only as the data source for the "(Settlement)" tag (the blank "Petitioner:" field on that page is a data artifact, not the absence of a petitioner). The patent owner, Orca, litigated aggressively rather than folding: it filed POPRs on all six, won a contested motion for additional discovery of 226 of Wiz's confidential documents to build an objective-indicia defense, submitted founder Avi Shua's declaration tying SideScanning™ to claims 1, 16, and 19, and argued at the hearing. This is a well-funded patent owner (Orca raised ~$630M across 2019–2021) that has demonstrated willingness to defend the family to decision.


Recommended next steps

  1. Resolve the disposition first — everything else depends on it. Pull the IPR2024-01109 docket on PTAB E2E / PTACTS (petition landing page: https://ptacts.uspto.gov/ptacts/public-informations/petitions/[1556286](/patent/1556286)) and on the Docket Alarm PTAB page (https://www.docketalarm.com/cases/PTAB/IPR2024-01109/WIZ_Inc._v._Orca_Security_Ltd/). Specifically look for: the Institution Decision (Paper ~8–12, expected ~2025-01/02), any Final Written Decision (statutory deadline one year from institution), and any Termination / Joint Request to Terminate / adverse judgment. Check the PTAB's public decisions portal and search the '809 patent number.
  2. If an FWD exists, it controls: read the claim-by-claim disposition, quote it, and link it. If any independent claim was canceled, any demand letter or infringement theory resting on that claim is dead on arrival — and you should also check whether it bars performance of the settlement-adjacent estoppel. Verify whether the FWD was appealed by checking the Federal Circuit docket and CourtListener for Wiz v. Orca (or Orca v. Wiz) appeals around 2026; a notice of appeal would typically be filed within 63 days of the FWD.
  3. If it settled pre-FWD (consistent with the "(Settlement)" tag), then treat the patent as fully intact and unadjudicated. Your live options are: (a) a fresh IPR on Veselov/Mohanty/Czarny/Hutchins — you are not bound by Wiz's stipulation, though the Board could exercise § 325(d) discretion since that art was already before it, so you'd want a materially different primary reference or a stronger obviousness rationale; (b) a district-court § 102/§ 103 case using the Wiz Appendix D/D-1 charts and the Delaware record (both parties' experts' depositions — Stavrou for Wiz, Kaeli for Orca — are in the public PTAB file); and (c) § 112 and § 101 attacks, which were expressly not part of the IPR and thus carry no estoppel/exhaustion risk.
  4. Mine the collateral record regardless of outcome. The Delaware docket (CourtListener: https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/) and the joint claim construction brief contain Orca's own prosecution-adjacent admissions, including its POPR statements that "an instantiated VM is not a 'snapshot'" and that "analysis of a VM instantiated from a snapshot is not an analysis of a snapshot" — while Orca argued the opposite construction to the district court. Wiz has already framed these as prosecution-history/claim-construction inconsistencies; a new defendant can reuse them for indefiniteness-adjacent or disclaimer arguments.
  5. Watch the sibling proceedings for outcome signals. IPR2024-01190 ('926) and IPR2024-01191 ('326) were heard on the same 2025-10-14 panel as the '809 case; the '031/'032/'685 IPRs (IPR2024-00863/-00864/-00865) were instituted in December 2024. Whatever those panels decided is the best available predictor of how the family fares at the Board, even though it is not binding on the '809 patent.
  6. Preserve your own § 315(b) clock. If you have been served with a complaint asserting the '809 patent, the one-year bar under § 315(b) runs from service; and note the parallel § 315(a)(1) bar if you filed a declaratory-judgment action of invalidity first.

Verification links I relied on:

Explicit limitations of this report: I could not confirm (i) the institution decision date or its reasoning for IPR2024-01109, (ii) whether any Final Written Decision issued, (iii) any claim-level disposition, or (iv) the existence, date, or terms of any settlement. Where the record is silent, I have said so rather than fill the gap. Treat the "(Settlement)" tag as a lead to verify, not a finding.

Generated 9/29/2026, 10:23:06 AM

Ownership chain (2)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2019-09-26 · recorded 2019-09-30 · reel 050520/0770 · Assignment

    SHUA, AviOrca Security Ltd.

    founder-to-company assignment

  2. ? · recorded 2023-05-03 · Assignment

    SHUA, AviOrca Security Ltd.

    confirmatory assignment

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll reconstruct the ownership chain for US 11726809. Let me gather records from multiple sources.

Good — I found a concrete assignment record. Let me verify the reel/frame and check for any post-issuance transfers.

Ownership & Assignment Analysis — US 11,726,809 B2

Patent: Techniques for securing virtual machines by application existence analysis
Application: 18/055,201 (filed 2022-11-14) · Granted: 2023-08-15 · Priority: 2019-01-28
Continuation of: 16/585,967 (US 11,431,735) → 17/330,998 (US 11,162,31)

Evidence-quality caveat up front: I was able to retrieve the family's Google Patents legal-events records and the litigation/PTAB record, but I could not complete a direct query of the USPTO Assignment Center (assignmentcenter.uspto.gov) within this session. The reel/frame for US 11,726,809's own record is therefore reported as documented in the family legal events and flagged where unconfirmed. I have not invented any reel/frame numbers.


Inventors

Inventor Address of record Employer at filing
Avi Shua (sole named inventor) Tel Aviv–Yafo, Israel Orca Security Ltd. — co-founder and CEO (2019–2023)
  • US 11,726,809 names one inventor only. Compare the sibling Orca filings (e.g., US 11,489,863, US 11,663,031) — all list Avi Shua sole, consistent with Orca's practice of naming only the founder-inventor.
  • Orca was founded in 2019 by Avi Shua (CEO), Gil Geron (CPO), Liran Antebi and Matan Ben Gur (chief architects) (Globes, 12 Jun 2019). Geron, Antebi and Ben Gur are not named as inventors on this patent — a narrowing pattern, not an inventorship anomaly per se.
  • Prior to Orca, Shua was Chief Technologist at Check Point Software Technologies (NASDAQ: CHKP) and served in IDF Unit 8200.
  • No "mass-departure" signal: Shua did not leave Orca after filing. He served as CEO 2019–2023 and remains Chief Innovation Officer & co-founder. There is no 12-month founder-exit pattern that would precede a portfolio fire-sale.

Original assignee

Orca Security LTD., Tel Aviv / Tel Aviv–Yafo, Israel (some records list a US HQ in Portland, OR). Assignee is unchanged from the face of the patent — Google Patents lists current assignee: Orca Security Ltd.

  • Product embodying the claims: Yes, unequivocally. Orca's SideScanning™ technology and Orca Cloud Security Platform (a CNAPP) practice the claimed snapshot-analysis approach; Orca publicly marketed SideScanning from mid-2019 as "patent-pending." Orca's own Patent Owner briefing in the Wiz IPRs affirmatively maps SideScanning onto the asserted claims (e.g., "takes snapshots of VMs at rest… analyzes such snapshots to detect vulnerabilities while target VMs are inactive").
  • Primary line of business: Agentless cloud-native application protection (CNAPP) — vulnerability assessment, CSPM, CIEM, DSPM, workload protection across AWS, Azure, GCP and Kubernetes. Led by CEO Gil Geron (Shua's co-founder) as of 2024–2025.
  • Current status: Operating, private, and well capitalized. Raised roughly $640M–$840M across seed through an extended Series C; valued ~$1.8B at the 2021 Series C (later marks cite ~$3.2B). No bankruptcy, no dissolution, no acquisition. The company remains an active acquirer itself (RapidSec, Opus) and holds FedRAMP Ready status.

This is the key fact driving the verdict: the original assignee is a live, revenue-generating operating company that sells a product accused… rather, that reads on the asserted claims.


Assignment timeline

Two records exist in the chain, both running inventor → Orca Security Ltd. No third-party transfer was found.

  • 2019-09-26 (executed) / recorded ~2019-09-30 — Reel 050520/0770

    • Conveyance: Assignment (Assignment of Assignors Interest)
    • Assignor: SHUA, Avi
    • Assignee: ORCA SECURITY LTD., Israel
    • Correspondent: Not exposed in the retrieved legal-events text. Flagged as unconfirmed. (For context, the Orca family's prosecution firm of record is Finnegan, Henderson, Farabow, Garrett & Dunner, L.L.P., attn. Christopher Johns, Customer No. 22852 — but that is prosecution counsel, not necessarily the assignment-recording correspondent, and I will not assert it as the recording agent.)
    • Context: Routine founder→company assignment perfecting the employer's title in the original application (16/585,967); not a sale or transfer-to-asserter.
  • 2023-05-03 (recorded) — Reel/frame not exposed in the retrieved sources

    • Conveyance: Assignment (Assignment of Assignors Interest)
    • Assignor: SHUA, Avi
    • Assignee: ORCA SECURITY LTD.
    • Correspondent: Not determinable from available records.
    • Context: Confirmatory/recordation assignment of the same interest to the same operating-company assignee covering the continuation (18/055,201). Not a shell-entity transfer — assignor and assignee are identical to the 2019 link.

No post-issuance assignment to any third party, LLC, licensing entity, or defensive aggregator was found. The assignee on the face of the patent (Orca Security Ltd.) is the current owner.


Timeline diagram

timeline
    title Ownership of US 11726809
    2019 : Provisional filed by Avi Shua
         : Inventor assigns rights to Orca Security
         : Parent application filed
    2022 : Continuation application filed
    2023 : Patent granted
         : Orca sues Wiz in Delaware
    2024 : Wiz files IPR2024-01109
    2025 : District case stayed pending IPR

NPE / troll-pattern signals

1. Shell-entity transfer — NOT PRESENT.
There is no transfer to any "IP / Holdings / Licensing / Ventures" entity. Both recorded assignments run to Orca Security Ltd., the operating company that makes and sells the accused-reading product. No single-member Delaware/Texas LLC appears anywhere in the chain.

2. Known asserter in the chain — NOT PRESENT.
Current assignee Orca Security Ltd. does not match Acacia, Marathon, Intellectual Ventures, IPNav, Wi-LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Round Rock, or any Spangenberg entity. Orca is a venture-backed cloud-security vendor (Temasek, CapitalG, ICONIQ, Redpoint, YL Ventures), not a licensing vehicle. ⚠️ Caution on a misread: Google Patents attributes the IPR2024-01109 entry to "Unified Patents PTAB Data" — that is the data provider, not the petitioner. The actual petitioner is Wiz, Inc., Orca's competitor (confirmed in the D. Del. stipulation, D.I. 194). This is not a defensive-aggregator event.

3. Repeat correspondent across the chain — UNCLEAR / NOT A FINDING.
Only one substantive assignment link exists, and the recording correspondent is not exposed in the retrieved records. A single appearance would not establish the signal in any event. Not enough data to call.

4. Cascading transfers — NOT PRESENT.
A single inventor→company assignment (2019), restated once for the continuation (2023). No chained LLCs, no shared correspondent addresses, no common-principal shell stack.

5. Pre-litigation transfer — NOT PRESENT (with a timing nuance).
The 2023-05-03 recordation sits ~2 months before the 2023-07-12 filing of Orca Security Ltd. v. Wiz, Inc. (D. Del. 1:23-cv-00758). Read mechanically that falls inside the 6-month window. Substantively it is not the signal: the "transfer" is inventor→same operating assignee, recorded to confirm title in the continuation — not a transfer to an asserter to set venue or manufacture standing. The substantive assignment (2019-09-26, reel 050520/0770) predates the suit by ~4 years.

6. Bankruptcy fire-sale — NOT PRESENT.
No Chapter 7/11, no 363 sale, no Kodak/Nortel/Polaroid-style event. Orca is solvent and raising capital.

7. Privateering — NOT PRESENT.
Orca asserts on its own behalf and on its own product, not on behalf of a third-party operating company. Wiz is Orca's direct commercial competitor in CNAPP/agentless cloud security (and is now being acquired by Google/Alphabet), which is the opposite of the privateering posture.

8. Defensive aggregator — NOT PRESENT.
No RPX, AST, LOT Network, Unified Patents, or OIN conveyance. The chain does not terminate at a defensive aggregator; the patent remains live and asserted.


Verdict

Operating-company assertion.

Orca Security Ltd. is both the original assignee on the face of the patent and the current assignee — the sole recorded conveyance is a founder-to-company assignment executed 2019-09-26, reel 050520/0770 (Shua → Orca Security Ltd.), restated for the continuation on 2023-05-03. There is no shell LLC, no known NPE, no cascading transfer, and no defensive-aggregator termination anywhere in the chain. The patent is asserted by Orca — a live, revenue-generating vendor whose own SideScanning™ product the claims are said to cover — against a direct competitor, Wiz, Inc., in Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del., filed 2023-07-12), now stayed pending IPR (D.I. 233). Wiz's own IPRs (IPR2024-01109, -01190, -01191, -00863/864/865) further confirm this is a competitor-vs-competitor fight, not monetization by a non-practicing entity.

Verification links:

Note on completeness: the two-step reel/frame for the 2023-05-03 recordation, and the assignment-recording correspondent for both links, could not be confirmed from the sources reachable in this session. I have flagged these as unconfirmed rather than infer them.

Generated 9/29/2026, 10:23:03 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research this patent and its cited prior art using live searches. Let me start by confirming the patent record and its citations.

Let me dig into the actual IPR/invalidity grounds and the remaining cited references.

Method & confidence caveat (read first)

I could not query USPTO Patent Public Search / PatentCenter directly in this session — my tool is live web search. I therefore cross-checked two authoritative sources:

  1. The full text of US 11,726,809 B2 supplied in this task (which includes the patent's own "Citations (47)" reference list, reproduced from the Google Patents record).
  2. Live web searches returning the Google Patents, FreePatentsOnline, and PTAB/district-court records for the '809 patent and its family.

Important limitation on the citation list: the supplied patent text's "Citations (47)" table is truncated at entry 20 (US 9,519,781 B2). I can therefore list and analyze 20 of the 47 cited references with full bibliographic certainty. Entries 21–47 are not visible in the available record, and I will not invent them. If you need all 47, they should be pulled directly from the "References Cited" page of the '809 patent on USPTO PatentCenter or the Google Patents "Citations" tab.

One contradiction to flag: Orca's own PTAB filing states the asserted patents "claim priority to the same provisional application filed January 16, 2019," while the '809 patent and the Google Patents record state the provisional (62/797,718) was filed January 28, 2019. I reproduce both literally; the January 16 date appears to be an error in the motion, but I am not auto-correcting it.


1. The patent being analyzed

Field Value
Patent US 11,726,809 B2
Title Techniques for securing virtual machines by application existence analysis
Appl. no. 18/055,201 (filed 2022-11-14)
Granted 2023-08-15
Inventor / Assignee Avi Shua / Orca Security Ltd.
Effective priority 2019-01-28 (prov. 62/797,718) → all cited art below is §102(a)(1)/(a)(2) prior art
Independent claims 1 (method), 16 (CRM), 19 (system)

2. The closest cited prior art — potential §102 relevance to the independent claims

Legal caveat up front: None of the references cited on the face of the '809 patent appears to disclose every limitation of independent claim 1 (or claims 16/19). Anticipation under §102 requires all elements in a single reference. These references were used in §103 obviousness rejections, and my analysis identifies the specific limitations each one supplies — which is what a §102/§103 challenge would actually turn on. I mark clearly where a reference is missing an element.

(A) US 2012/0323853 A1 — Microsoft, "Virtual machine snapshotting and analysis" (closest of all cited art)

  • Filing: 2011-06-17 · Publication: 2012-12-20 · Granted as US 9,286,182 B2 (2016-03-15) · Inventors Fries, Hunt, Balakrishnan · URL: https://patents.google.com/patent/US20120323853A1/en
  • Description: Automatically obtains snapshots of executing VMs to build a "pool of virtual machine snapshots"; reads the snapshots to extract a feature set including "information about a running guest operating system, software installed on the virtual machine," metadata; the feature extractor may use a "template or definition file … a set of software packages to be checked for"; a rule/ML analysis tool ranks snapshots "according to likelihood of a virtual machine having a defined condition."
  • §102 analysis: Strongest cited reference. It discloses (i) obtaining a snapshot of a live VM; (ii) reading/extracting installed-software features from the snapshot; and (iii) ranking/prioritizing output by condition. It is a serious §102(a)(1) exposure against claim 8 (parsing + scanning the snapshot); and it supplies the "matching installed applications" concept of claim 1.3. Missing for full anticipation of claim 1: determining the snapshot location via a cloud-provider API, the "known list of vulnerable applications" specifically, correlating with network location, and using that to compute a risk. So: near-miss on claim 1; strong on claim 8.

(B) US 2013/0247133 A1 — McAfee, "Security assessment of virtual machine environments"

  • Filing: 2011-10-13 · Publication: 2013-09-19 · Granted as US 8,850,512 B2 (2014-09-30) · Inventors Price, Bettini · URL: https://patents.google.com/patent/US20130247133A1/en
  • Description: A security server identifies VMs via the virtual machine manager (an API of the cloud/hypervisor); for offline VMs it collects a “machine image” via the VM manager, assesses security from the collected images, and can remedy a detected vulnerability/policy violation before the VM returns online; a security-assessment tool is authenticated at the VM manager; queries/identification data are communicated "over an API of the virtual machine manager."
  • §102 analysis: The best cited reference for the "using an API or service provided by the cloud computing environment" limitations (1.1–1.2) and for claim 15 (querying the cloud management console), claim 12 (determining the virtual disk), and claims 10–11 (mitigation — remedying vulnerability, blocking/halting). Missing for claim 1: it uses "machine images," not "snapshots" (its own record and the IPR briefing stress images ≠ snapshots), matching against a known vulnerable-application list, and network-location correlation/prioritization. Near-miss only.

(C) US 2008/0263658 A1 — Microsoft, "Using antimalware technologies to perform offline scanning of virtual machine images"

  • Filing: 2007-04-17 · Publication: 2008-10-23 · Granted as US 8,011,010 B2 · URL: https://patents.google.com/patent/US20080263658A1/en
  • Description: Stores a VM image by taking a snapshot or checkpoint while the VM is online; renders the VHD to file-system data (mounting it, or via a kernel-mode filter "connected to an anti-malware engine"); an anti-malware engine scans the exposed file system; stores scan results (timestamp, result, infected-component list).
  • §102 analysis: Directly relevant to claim 23 (copying the snapshot and analyzing the copy) and claim 8 (parsing and scanning the snapshot); the explicit "snapshot/checkpoint while online" teaching maps to claim 1's snapshot step. Missing: it performs malware signature scanning, not "matching installed applications with a known list of vulnerable applications" (claim 1.3), and no network-location correlation or risk prioritization.

(D) US 2009/0007100 A1 — Microsoft, "Suspending a Running Operating System to Enable Security Scanning"

  • Filing: 2007-06-28 · Publication: 2009-01-01
  • Description: Suspends/quiesces a running OS so a security scan can run against a consistent state — the classic "scan at rest / VM inactive during scan" teaching.
  • §102 analysis: Relevant to the "at rest / inactive" concept that the '809 family claims emphasize (the sibling '031 patent was allowed on an "inactive" limitation). Peripheral to '809's claimed elements (the '809 independent claims do not recite "at rest"), but a §103 staple for claim 8's snapshot analysis.

(E) US 2010/0017512 A1 — IBM, "Method and System For Improvements In or Relating to Off-Line Virtual Environments"

  • Filing: 2008-07-21 · Publication: 2010-01-01
  • Description: Off-line analysis of virtual environments/image contents.
  • §102 analysis: General §103 support for claim 8 (parsing/scanning an offline snapshot). Not an anticipation of any independent claim.

(F) US 2011/0289584 A1 — CA (Computer Associates), "Systems and methods to secure backup images from viruses"

  • Filing: 2010-05-18 · Publication: 2011-11-24
  • Description: Scanning stored backup images for viruses/malware out-of-band.
  • §102 analysis: Relevant to claim 23 (analyzing a copy) and claim 8. Not an anticipation of claim 1.

(G) US 8,850,512 and family note

See (B) — the McAfee publication and its granted patent are the same disclosure (US 8,850,512 B2 is the grant of US 2013/0247133 A1).

(H) US 9,229,758 B2 — IBM, "Passive monitoring of virtual systems using extensible indexing"

  • Filing: 2011-10-28 · Granted: 2016-01-05 · Inventor Ammons et al.
  • Description: Agent-less, passive monitoring of virtual systems by indexing VM state/data.
  • §102 analysis: Relevant to the agentless architecture the '809 specification stresses ("without using any agent"), and to claim 8's scanning. It does not disclose the vulnerable-application matching or the risk/prioritization pipeline of claim 1.

(I) US 9,519,781 B2 — Cyphort Inc.

  • Filing: 2011-11-03 · Granted: 2016-12-13
  • Description: The title is truncated in the available record ("Systems and metho…"). Cyphort's portfolio centers on network/behavioral threat detection; I could not verify the full title or full text within this session and will not guess at it.
  • §102 analysis: Reported literally as far as the record goes; its likely role is general §103 support for threat detection and alerting, not for the claim-1 snapshot/API/matching pipeline.

3. References relevant to specific dependent claims (§102/§103 support)

# Full citation Filed / Published–Granted Brief description Claims it can support
1 US 2007/0266433 A1 – Moore, "System and Method for Securing Information in a Virtual Computing Environment" 2006-03-03 / 2007-11-15 Securing data in VCE Background art only; not an anticipation of claims 1/16/19
2 US 2008/0189788 A1 – Microsoft, "Dynamic risk management" 2007-02-06 / 2008-08-07 Dynamic risk scoring Claim 1.6 / claims 4–5 (determining "risk"; weighting takeover risk)
3 US 2013/0191643 A1 – Fujitsu, "Establishing a chain of trust within a virtual machine" (third-party cited) 2012-01-25 / 2013-07-25 VM trust attestation Not anticipatory; §103 background
4 US 2014/0096135 A1 – IBM, "Method for authenticated distribution of virtual machine images" 2012-10-01 / 2014-04-03 Auth'd VM image distribution Claim 15-adjacent (image handling) only
5 US 2014/0137190 A1 – Rapid7, "Methods and systems for passively detecting security levels in client devices" 2012-11-09 / 2014-05-15 Passive security-level detection Claim 3 (risk-level filtering); claim 8
6 US 2015/0052520 A1 – IBM, "Method and apparatus for virtual machine trust isolation in a cloud environment" 2013-08-19 / 2015-02-19 Cloud VM isolation Claim 11 (quarantining) background
7 US 9,069,983 B1 – Symantec, "Method and apparatus for protecting sensitive information from disclosure through virtual machine files" 2009-04-29 / 2015-06-30 Sensitive data in VM files Spec's sensitive-data/PII aspects (not separately claimed in 1–23)
8 US 9,177,145 B2 – Sophos, "Modified file tracking on virtual machines" 2009-03-24 / 2015-11-03 File-change tracking in VMs Spec's hash-of-sensitive-areas / integrity feature; claim 3 support
9 US 2016/0004449 A1 – Hedvig, "Storage system with virtual disks" (third-party cited) 2014-07-02 / 2016-01-07 Virtual-disk storage Claim 12 (virtual disk) background
10 US 9,268,689 B1 – Symantec, "Securing virtual machines with optimized anti-virus scan" 2012-03-26 / 2016-02-23 Optimized AV scan of VMs Claim 8; claim 23
11 US 2016/0094568 A1 – IBM, "Automated response to detection of threat to cloud virtual machine" (third-party cited) 2014-09-25 / 2016-03-31 Detect threat → automated response Claims 10–11 (mitigation: blocking, halting, quarantining)
12 US 2016/0241573 A1 – Fisher-Rosemount Systems, "Security event detection through virtual machine introspection" 2015-02-13 / 2016-08-18 VM introspection for security events Claim 8 (analyzing VM state)

(References 1, 3, 4, 9 above are the weaker/peripheral ones; the rest supply identifiable elements.)


4. The prior art that actually drove the '809 challenge — Veselov (not in the face-citations table)

The references cited on the patent's face were not the art Wiz relied on in the IPR. In IPR2024-01109 (Wiz, Inc. v. Orca Security Ltd., U.S. Patent 11,726,809), the grounds — per Orca's expert declaration (Kaeli, Ex. 2001) — were:

  • Ground 1: claims 1–10, 12–23 obvious over Veselov + Mohanty
  • Ground 2: claims 1–10, 12–23 over Veselov + Mohanty + Czarny
  • Ground 3: claim 11 over Veselov + Mohanty + Hutchins
  • Ground 4: claim 11 over Veselov + Mohanty + Czarny + Hutchins

Source: https://www.docketalarm.com/cases/PTAB/IPR2024-01109/WIZ_Inc._v._Orca_Security_Ltd/docs/10-18-2024-Patent_Owner/Exhibit-2001-Ex_2001__Kaeli_Declaration__01109.pdf

Veselov is an Amazon-assigned patent, cited in the briefing as U.S. Patent No. 11,216,563 (first named inventor Veselov, filed ~2017-05-19), described as teaching an "agentless" snapshot-based security assessment (mounting the snapshot as a file-system volume, or instantiating a duplicate VM). Note a naming hazard: the sibling '032 patent's reference list separately cites U.S. 11,176,363 B1 (Veselov et al.). These are two differently numbered Veselov patents; I reproduce both as they appear and do not treat them as the same document.

Two points you should carry forward:

  • Every §103 ground above depends on a combination. Veselov was cited as the primary reference, not as a standalone §102 anticipation — consistent with my finding that no single reference discloses all eight claim-1 limitations.
  • Veselov was in an IDS but never applied by the Examiner (per Orca's §325(d) arguments in the parallel IPR2024-00220 petition), which is why a §102 anticipation theory was not the chosen path.

5. Bottom line

  1. Closest cited prior art to claim 1: US 2012/0323853 A1 (Microsoft, VM snapshotting and analysis) — snapshot capture + installed-software feature extraction + condition ranking. It is the only cited reference that comes near claim 1's snapshot-analysis core, but it lacks the cloud-API location determination, the "known list of vulnerable applications," the network-location correlation, and the risk-based prioritization.
  2. Closest cited prior art for the API/cloud-console limitations (claims 12, 15) and mitigation (claims 10–11): US 2013/0247133 A1 / US 8,850,512 B2 (McAfee).
  3. Best cited art for claims 8 and 23: US 2008/0263658 A1 (Microsoft offline scanning) and US 2012/0323853 A1.
  4. No cited reference is a clean §102 anticipation of any independent claim; they are §103 fodder. The art actually used in the live IPR was Veselov (+Mohanty, Czarny, Hutchins) — which is not on the face of the patent.
  5. Open item: entries 21–47 of the patent's citation list were truncated in the source I was given and are not covered here; verify them directly in PatentCenter if completeness is required.

Generated 9/29/2026, 10:23:31 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll analyze the obviousness of US 11,726,809 using the prior-art references cited on the patent page. Let me research the key references.

I now have the actual IPR grounds. Let me get details on the primary references (Veselov, Mohanty, Czarny, Hutchins) and the key cited prior art.

Obviousness Analysis — U.S. Patent No. 11,726,809 B2

Subject: "Techniques for securing virtual machines by application existence analysis"
Statute: 35 U.S.C. § 103
Analyst date: April 26, 2026
Priority date / critical date: 2019-01-28 (provisional 62/797,718)


0. Scope, sources, and caveats

This memo builds on the prior bibliographic/continuity work already performed and does not repeat it. Two distinct bodies of prior art are relevant, and I separate them explicitly:

  1. The "Prior Art" section of the patent page — i.e., the examiner/third-party citations listed on the Google Patents record for US 11,726,809 (the "Citations (47)" list). These are the references the user directed me to use.
  2. The as-litigated grounds — the references Wiz actually asserted in IPR2024-01109 against this exact patent, which I located in the record (Orca's Patent Owner Preliminary Response and the Kaeli Declaration, Ex. 2001). Ground 1 was Veselov and Mohanty; Grounds 2–4 added Czarny and Hutchins.

Important honesty flags:

  • I could not independently retrieve the full bibliographic identity or disclosure of Mohanty, Czarny, or Hutchins (search limits), so I do not attribute specific disclosures to them and will not guess reference numbers. They should be verified in the IPR2024-01109 Petition (Paper 2).
  • Veselov = U.S. Patent No. 11,216,563 B1, "Security assessment of virtual computing environment using logical volume image," assigned to Amazon Technologies, Inc. (inventors Grajdeanu, Nagargadde, Veselov), filed 2017-05-19. This is not in the page's citation list; I treat it as supplementary but highly probative.
  • All identifiers are reproduced literally; nothing auto-corrected.

A note on contradictions with the earlier section: none. My earlier summary placed IPR2024-01109 at the institution/POPR stage with a later "Settlement" flag; the record I found here (POPR + Kaeli Declaration, Oct. 2024) confirms the case was instituted and these grounds were the asserted ones, which refines (does not contradict) that summary.


1. The claims to be analyzed

Independent claim 1 (method) requires, in substance:

Element Limitation
E1 Determine, using a cloud-provider API/service, a location of a snapshot of a virtual disk of a protected virtual cloud asset instantiated in the cloud
E2 Access the snapshot based on the determined location, using a cloud API/service
E3 Analyze the snapshot by matching installed applications against a known list of vulnerable applications
E4 Determine, based on the matching, existence of a plurality of potential cyber vulnerabilities
E5 Correlate the vulnerabilities with the network location of the asset
E6 Use the vulnerabilities + network location to determine a risk of the asset to the cloud environment
E7 Prioritize the vulnerabilities by the determined risk
E8 Report them as alerts prioritized by the determined risk

Claims 16 (CRM) and 19 (system) are parallel. (Claim 19 as printed omits "and the" before "network location" in the sixth limitation — reported literally, not corrected, per the earlier section.)


2. The page's cited prior art that maps to claim 1

These all predate 2019-01-28 and are in the same field (cloud/VM security assessment):

  • US 2013/0247133 A1 (Price, "Security assessment of virtual machine environments," McAfee; granted US 8,850,512 B2). Interacts with the virtual machine manager via its API; collects a machine image of each VM "via the virtual machine manager"; and assesses security of the offline VMs from the collected images by "reading each image file to identify security characteristics." Also notes firewalls/credentials block direct agent access — the very rationale for snapshot-based (agentless) assessment. → E1, E2, and the E3/E4 core.
  • US 2012/0323853 A1 (Fries, "Virtual machine snapshotting and analysis," Microsoft; granted US 9,286,182 B2). Automatically snapshots executing VMs, reads the snapshots to obtain features including "software installed on the virtual machine," and analyzes the features against predefined rules (its worked example is security — e.g., ranking snapshots by likelihood the VM is "infected with a computer virus"); also can rank/flag snapshots. → E1, E2, E3, E4, E7.
  • US 2008/0189788 A1 (Bahl, "Dynamic risk management," Microsoft; granted US 7,908,660 B2). Assesses a security state, identifies risk factors including vulnerabilities ("attack prone ports being open, missing patches and outdated signature files"), network type (work/private/public), network security profile, software risk profile, and environmental factors (published vulnerabilities and exploits); computes a risk level and triggers alerts/actions. → E5, E6, E7, E8.

Additional cited art supporting secondary limitations: US 2008/0263658 A1 (Microsoft — offline scanning of VM images with antimalware) and US 2011/0289584 A1 (CA — securing backup images from viruses) for snapshot scanning; US 2009/0007100 A1 (Microsoft — suspend running OS to enable scanning); US 9,268,689 B1 (Symantec — securing VMs with optimized AV scan); US 9,069,983 B1 (Symantec — protecting sensitive data in VM files); US 9,229,758 B2 (IBM — passive VM monitoring via extensible indexing); US 2016/0094568 A1 (IBM — automated response to threat to a cloud VM); US 2016/0241573 A1 (Fisher-Rosemount — security event detection via VM introspection).


3. Primary combination (page-cited art): Price + Fries + Bahl

3.1 Claim chart — independent claim 1

Element Price (US 2013/0247133) Fries (US 2012/0323853) Bahl (US 2008/0189788)
E1 cloud API → snapshot/virtual-disk location Query VM manager over its API; collect machine image via VM manager Auto-snapshot running VM; virtual disk image = VHD (risk engine receives host/network data)
E2 access snapshot via API Machine image "sent via an API of the virtual machine manager" Read stored snapshots —
E3 match installed apps vs. known vulnerable-app list "Reading each image file to identify security characteristics"; vuln-assessment tools Feature extractor seeks "a set of software packages to be checked for"; compare files/versions to rules Host security profile accounts for known vulnerabilities
E4 plurality of vulnerabilities Multiple VM-specific security conditions reported Rule weights per snapshot Multiple risk factors
E5 correlate with network location — — Network type / network risk profile combined with host vulnerabilities
E6 determine risk Result data describes security conditions Ranking by condition Risk level computed from combined factors
E7 prioritize Virtual-machine-specific reports "flag or rank snapshot according to weight of rules satisfied" Tiered action thresholds
E8 report prioritized alerts Result data / reports Analysis output "sending alerts externally"

E3's "known list of vulnerable applications" is the element the patent title emphasizes, but it is squarely met by: Fries' "software packages to be checked for" and rules database; Price's vulnerability-assessment tooling; and the universally known CVE-database practice that Veselov later describes expressly ("maintain a database of assessment tasks … associated with particular software applications and versions," and comparing file names to "character patterns representing known … filenames" to identify software/versions).

3.2 Motivation to combine (KSR/Graham)

  • Same field, similar problem. Price, Fries, and Bahl all address securing or assessing computing systems/VMs; Price and Fries both operate on VM images/snapshots. Combining is the combination of prior elements "according to known methods" with no change in their respective principles of operation — the classic KSR scenario.
  • Price→Fries. Price's stated problem is that agents fail (firewalls, missing credentials). Fries supplies a concrete mechanism to extract the software inventory from the snapshot without touching the guest — precisely what an agentless assessor needs. A POSITA improving Price would naturally read the image the way Fries teaches.
  • Price/Fries→Bahl. Once a scan yields many findings, a POSITA is motivated to triage them; Bahl teaches computing a risk level from vulnerabilities plus network exposure and taking tiered action. The patent's own stated goal (reducing reported alert volume via prioritization) is exactly Bahl's teaching. The Federal Circuit repeatedly holds that reducing/prioritizing alerts by combining known risk factors is an "improvement in the nature of the information" that does not render the combination non-obvious.
  • Reasonably pertinent art. Bahl (Microsoft risk management) is from the same industry and addresses the same ultimate security goal; it is not "far afield."

4. The as-litigated, Veselov-based combination

The record shows Wiz's Petition (Ground 1) asserted claims 1–10 and 12–23 obvious over Veselov in view of Mohanty, with Czarny and Hutchins added for mitigation-based claim 11. Based on the portions of the Petition/Declarations I retrieved:

  • Veselov teaches the scanning service obtaining a snapshot of the VM's logical volume (virtual disk), analyzing it either directly as a data file or via a duplicate/assessment VM, without an agent on the target VM (EX1007 at 3:61–67; 8:30–45; 17:10–29), using rules packages such as CVE, CIS benchmarks, "best practices," configuration assessments, matching file/directory names to known software signatures, and keeping a database of scan tasks tied to application versions (18:16–53). It also discusses remediation "if vulnerabilities are identified" (10:17–36). → covers E1–E4 and much of E6/E8.
  • Mohanty (secondary) was cited by Wiz for the remaining limitations (the application-vs-known-vulnerable-list matching and/or the network-location correlation + risk-based prioritization). I could not independently verify its disclosure, so I mark E5–E7 under this ground as "asserted but not independently confirmed."

Corroboration from a parallel FWD: In IPR2024-00863/00864/00865 the PTAB's Final Written Decisions of 2025-12-08 held all claims of the '031, '032, and '685 patents unpatentable — patents that share the '809's common specification and overlapping subject matter, and that were challenged with a Veselov + Price-type grounds set (see the '031 IPR Ground table: "obviousness over Veselov and Price"). That is strong, non-trivial evidence that a POSITA would have found the family's snapshot-based claims obvious; the '809's added "application existence analysis" element is incremental and itself disclosed in Veselov/Fries.


5. Dependent claims

  • Claim 6 (direct binary comparison of application files) and claim 7 (cryptographic-hash match against a database of files in vulnerable applications): taught/suggested by Fries (predefined sets of files and software packages, rule comparison) and by Symantec US 9,069,983 B1 (computing hashes of VM file data) — hash-based file identification was a routine, well-known signature technique (cf. NSRL/file-signature scanning). Predictable result.
  • Claims 8–9 (parse/scan snapshot; check config files, file access times, system logs): Fries (read stored memory, parse for objects) + Price (read image at file-system level) + IBM US 9,229,758 B2 (passive monitoring/indexing). Routine.
  • Claims 10–11 (mitigation: block traffic, halt, quarantine): IBM US 2016/0094568 A1 (automated response to a detected cloud-VM threat), Bahl (terminating a network connection, disabling a component), and Price (remedying a vulnerability before the VM resumes). Under the IPR, Wiz mapped claim 11 to Hutchins.
  • Claims 12–15 (determine virtual disk; use cloud API to take/request a snapshot; obtain its location; query a cloud management console): Price (query the VM manager via API; collect machine image) and Veselov (snapshot generation / API-driven UI). This is the element Orca fought hardest on in the siblings' IPRs, arguing Veselov identifies a VM, not a virtual disk — a genuine, narrow dispute.
  • Claim 23 (copy the snapshot and analyze the copy): Price (collect image) and Veselov (duplicate/assessment VM).

6. Countervailing considerations (must be weighed)

  1. Claim-construction contests. Orca argued (POPRs) that "analyzing the at least one snapshot" means analyzing the snapshot itself, not a VM instantiated from it, and that "reporting results" ≠ "reporting as alerts." To the extent those constructions hold, the Veselov/Price ground weakens only if a reference discloses solely instantiated-VM analysis; Veselov also discloses direct snapshot-as-data-file analysis (3:61–67; 8:30–45), so the ground survives either way.
  2. Objective indicia (Graham factor 4). Orca has asserted copying by Wiz, commercial success, industry praise, and skepticism overcome for its SideScanning™ technology, and moved for additional discovery on exactly those documents (Garmin factors). Objective indicia are "a fundamental part of the overall § 103 inquiry" (Liqwd) and, if substantiated with a nexus to the claimed features, can rebut an otherwise strong prima facie case. I have not verified whether the Board credited them.
  3. § 101 overlay. Wiz's counterclaim asserted Orca's patents (including a related '549 patent) were abstract under Alice; that is a separate validity theory but shows the claims were characterized as conventional cloud-security automation.

7. Conclusion and explicit uncertainties

  • On the page-cited art alone, a facially strong § 103 case exists: Price + Fries + Bahl renders claim 1 (and parallels 16/19) obvious, with routine engineering covering the dependent claims. The motivation is the ordinary, KSR-endorsed desire to (i) avoid agent/credential problems (Price's own rationale) by analyzing snapshots, (ii) inventory installed software from the snapshot (Fries), and (iii) triage/prioritize alerts by risk (Bahl). No reference's principle of operation is changed.
  • On the as-litigated art, Veselov (+Mohanty/Czarny/Hutchins) is the asserted ground; the Veselov primary reference is independently corroborated by the December 2025 FWDs invalidating the sibling '031/'032/'685 claims.
  • Explicit uncertainties I will not paper over: (a) I could not verify the disclosures of Mohanty, Czarny, or Hutchins; (b) I did not retrieve the IPR2024-01109 Final Written Decision or confirm whether that IPR ended in settlement versus a decision on the merits — the page's "Settlement" flag is my only evidence, and the '809's district-court dismissal (with prejudice, SO ORDERED 2026-01-13) means there is no controlling adjudication of these claims; (c) whether objective indicia would have defeated the prima facie case is unverified.

Nothing above should be treated as a legal conclusion of invalidity; it is a technical obviousness assessment grounded in the cited and as-litigated references.

Generated 9/29/2026, 10:23:32 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

More patents asserted by Orca Security Ltd.

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (2)

2 tracked lawsuits name US 11726809.